DailyMacros Privacy Policy
Last updated July 31, 2026
Optional progress check-in notes and dates are stored with your account. Progress photos are stored privately in Amazon S3 after location metadata is removed and the image is resized. Photos are not sent to AI services. Authenticated access provides short-lived download links. Export photos from their check-in; account exports include check-in records and photo identifiers. Deleting a photo, check-in, or account deletes its stored photo files.
DailyMacros is a private friends and family beta for nutrition, workout, weight, waist measurements, sleep, and wellness tracking. This policy explains what the app collects, why it is collected, and the controls available to you.
Data We Collect
- Account details from sign-in providers, such as name, email address, provider identifiers, and profile image when provided.
- Nutrition data, saved foods, meal groups, macro targets, meal text, barcode lookups, and meal photos you submit for parsing.
- Workout, weight, waist measurements, sleep, and wellness entries. If you connect Oura, this includes Oura sleep, readiness, activity, stress, resilience, bedtime-guidance, and optional workout aggregates. Sexual activity entries are available only when enabled for an account.
- Subscription and billing state from Stripe when paid features are enabled.
- Authentication and security records such as API credential metadata, browser-session metadata, audit events, and request references needed to secure and support the service.
- Operational usage records such as per-feature daily usage limits and replay-safe mutation metadata needed to run the service.
- Optional diagnostics linked to your account for support and beta reliability. Automatic browser diagnostics use a strict allowlist: generic error category, relative route template, HTTP status, request reference, app platform/version, timestamp, and script filename/line/column when applicable. They do not include raw URLs or query strings, request or response bodies, typed meal or workout text, health values, tokens, cookies, secrets, stack traces, full user agents, or user/device identifiers in the submitted payload. The iOS diagnostic export remains stored locally until you choose to share it.
Apple Health
HealthKit permissions are optional. Before DailyMacros requests HealthKit access, you choose Read and Write separately for each supported data type: weight, workouts, sleep, and sexual activity where enabled. A missing choice defaults to no access. These in-app choices control whether DailyMacros imports from or adds new entries to Apple Health; Apple's system permission remains an additional device-level control. Turning a direction off stops future transfers in that direction and does not delete records already imported or samples already written. You can change both the in-app choices and Apple's Health permissions at any time.
Oura
Connecting Oura is optional and uses Oura's authorization screen. DailyMacros requests daily-data access plus the minimum personal scope needed to obtain Oura's opaque user identifier and route signed webhook updates to your account. After connection, you choose which supported Oura aggregate categories DailyMacros may read. No aggregate backfill, reconciliation, or webhook document fetch begins until those choices are saved, and a missing choice defaults to no access. Oura does not support writes from this integration. Oura profile fields such as age, height, weight, biological sex, and Oura email are discarded.
Oura access and refresh tokens are encrypted on the DailyMacros server. DailyMacros stores allowlisted aggregate Oura metrics and does not retain raw heart-rate, HRV, movement, sleep-phase, or MET sample arrays. Imported aggregates remain stored until you choose Disconnect & Delete or delete your DailyMacros account. A minimal record of covered provider days and ignored record identifiers is retained after disconnect to prevent deleted history from being reimported through Apple Health; account deletion removes these markers. Sleep quality, perceived wake-ups, and notes are separate user annotations. Signed webhooks deliver Oura cloud updates after your ring syncs to Oura, with scheduled reconciliation for missed events.
DailyMacros may combine Oura aggregates with other app history for deterministic in-app trends and coaching. Oura API data and values derived from it are not provided to OpenAI, Apple Foundation Models, or any other AI or machine-learning model.
AI Processing
When you ask DailyMacros to parse or analyze a meal, workout, meal photo, report, or eligible connected health data, relevant content may be sent to OpenAI to produce estimates or analysis. Oura API data and values derived from it are always excluded. DailyMacros does not send other eligible content to OpenAI unless you use those AI features. OpenAI publishes its API data controls at platform.openai.com/docs/guides/your-data.
Barcode Data
Barcode lookups use Open Food Facts product data. DailyMacros sends the barcode value needed to look up the product and stores the nutrition entry only when you save it.
How We Use Data
Data is used for app functionality, account authentication, syncing across web and iOS, support, security, abuse prevention, beta reliability, billing when enabled, and account export or deletion. DailyMacros does not sell personal data and does not use third-party advertising or cross-app tracking.
Backups And Retention
Production data is backed up for operational recovery. Account data remains in the active database until you delete your account or request help deleting it, except for operational records with shorter limits. Optional browser diagnostics are retained for 30 days, operational usage counters for 90 days, and account audit events for 365 days. A scheduled server cleanup enforces those limits. Deleted account data is removed from the active database; encrypted production backup snapshots currently age out after 7 days, while transport or provider logs follow their providers' limited operational windows.
Your Controls
You can turn future optional browser diagnostic uploads on or off from Account & Privacy on the web or Settings on iOS. Turning them off does not disable essential server-side security records, audit events, abuse controls, or request references. You can manage per-source, per-data-type Read and Write choices from those settings, and explicit off choices are retained so they are not treated as missing consent. You can export a JSON copy of your account data, including these integration choices and safe diagnostic metadata, or permanently delete your account from those same settings. You can disconnect Oura and delete imported Oura data from either Settings surface, change or revoke HealthKit access, and sign out from the app.
Support
For support or privacy requests, contact the person who invited you. Include the request reference shown in any error message and the build information from Settings or Account & Privacy.