Macrofy LLC

    Macrofy LLC Privacy Policy

    Last updated: September 11, 2026 | Effective: August 8, 2026

    Privacy Policy

    Effective Date: August 8, 2026

    Last Updated: September 10, 2026

    (Previous versions of this Privacy Policy are available upon request.)

    SUMMARY OF KEY POINTS

    At a Glance:

    • What personal information do we collect? We collect your name, email, device information, usage analytics, technical logs, photos/camera input for food recognition, and physical metrics or dietary logs.
    • Do we process any sensitive personal information? Yes, physical metrics and dietary logs may be considered sensitive health-related information under certain privacy laws. We only use this data to provide our core services.
    • Do we collect information from third parties? We primarily collect information directly from you or automatically through your use of our services, though we may receive basic analytics from our service providers.
    • How do we use your information? We use your data to power our nutrition infrastructure platform, improve our food recognition models, secure our services, and communicate with you.
    • Who do we share your personal information with? We share data only with essential service providers like hosting and payment processors, or when legally required. We never sell your personal data.
    • What are your privacy rights? You have the right to access, correct, delete, and port your data, as well as the right to opt out of marketing and limit the use of sensitive data.
    • How can you contact us? You can reach our privacy team anytime at legal@macrofy.com.

    1. INTRODUCTION

    Welcome to Macrofy LLC. We provide a developer-first nutrition infrastructure platform that offers APIs and mobile SDKs for food recognition, barcode scanning, and nutrition intelligence. Whether you are building the next great health, fitness, or wellness application, or using an app powered by our technology, we believe that understanding your nutrition shouldn't require sacrificing your privacy.

    We know privacy policies can be dense and difficult to read. We wrote this document to clearly explain how we handle your data, why we need it, and how we protect it. Our commitment to you is simple: we only collect what we need to make our services work beautifully, we secure it rigorously, and we never sell it.

    This Privacy Policy applies to all users of our website (https://macrofy.com), our APIs, our mobile SDKs, and any related services we provide. If you have any questions after reading this policy, please reach out to us at legal@macrofy.com.

    2. WHAT WE COLLECT & WHY

    To provide our food recognition and nutrition intelligence services, we need to process certain types of information. We organize our data collection by what we need to accomplish for you.

    Information You Give Us Directly

    When you register for an account or use our services, you voluntarily share specific information with us. We collect this data based on the legal basis of fulfilling our contract with you, or with your explicit consent.

    • Account Information: We collect your name and email address to create and manage your developer or user account, send important updates, and provide support.
    • Photos & Camera Input: When you use our food recognition features, we process the images you capture or upload. We need this to identify food items and return accurate nutritional data.
    • Physical Metrics & Dietary Logs: If you input physical metrics or log your meals, we collect this data to provide personalized nutrition intelligence and historical tracking.

    Information Collected Automatically

    As you interact with our platform, we automatically gather certain technical data. We rely on our legitimate interest in maintaining, securing, and improving our services to collect this information.

    • Device Information: We collect data about the device you use to access our services, including hardware models, operating systems, and unique device identifiers. This helps us ensure our SDKs run smoothly across different platforms.
    • Usage Analytics: We track how you interact with our APIs and SDKs—such as which endpoints you call and how often. This allows us to optimize performance and identify bugs.
    • Technical Logs: We record server logs, IP addresses, and crash reports to monitor system health and troubleshoot issues.

    Information from Third Parties

    We generally do not buy or collect personal data from third-party data brokers. We may receive basic technical or payment confirmation details from our essential service providers (like our payment processor) to confirm your subscription status. This processing is based on our contract with you.

    3. HOW WE USE YOUR INFORMATION

    We are purposeful about how we use your data. Every piece of information we collect serves a specific function in delivering or improving Macrofy.

    • Core Service Delivery: We use your photos, dietary logs, and account details to make our APIs and SDKs function. When you scan a barcode or snap a picture of a meal, we process that data to instantly return the nutrition intelligence you requested. (Legal basis: Contract)
    • Service Improvement: We analyze usage analytics and anonymized food images to train our machine learning models, making our food recognition faster and more accurate for everyone. (Legal basis: Legitimate Interest)
    • Communication: We use your email to send technical notices, security alerts, and administrative messages. (Legal basis: Contract/Legitimate Interest)
    • Security and Fraud Prevention: We monitor technical logs and device information to detect suspicious activity, prevent abuse of our APIs, and protect our infrastructure. (Legal basis: Legitimate Interest)
    • Legal Compliance: We may process your information to comply with tax laws, financial regulations, or valid legal requests. (Legal basis: Legal Obligation)
    • Marketing: With your permission, we may send you newsletters or promotional content about new Macrofy features. You can opt out of these communications at any time. (Legal basis: Consent)

    4. WHEN WE SHARE YOUR INFORMATION

    We treat your personal data with respect and limit sharing to the absolute minimum necessary. We never sell your personal data.

    We only share your information in the following specific circumstances:

    • Essential Service Providers: We share data with trusted vendors who help us run our business. This includes our cloud hosting providers who store our databases and payment processors who handle billing. We require these providers to protect your data and only use it for the services they provide to us.
    • Legal Requirements: We will disclose your information if we are legally required to do so by a court order, subpoena, or other lawful request from public authorities.
    • Business Transitions: If Macrofy LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
    • With Your Consent: We may share your information for other purposes if you give us explicit permission to do so.

    5. YOUR PRIVACY RIGHTS

    Depending on where you live (including the EU/EEA, California, Virginia, Colorado, Connecticut, Texas, Montana, and other US states), you have specific rights regarding your personal information. We believe in providing these rights to all our users, regardless of location.

    You have the right to:

    • Access Your Data: Request a copy of the personal information we hold about you. We will provide this within 30 days.
    • Correct Inaccuracies: Ask us to update or fix any incorrect information in your profile.
    • Delete Your Data: Request that we erase your personal information, subject to certain legal exceptions (like maintaining financial records).
    • Port Your Data: Receive your data in a structured, commonly used, and machine-readable format so you can transfer it to another service.
    • Opt Out of Marketing: Unsubscribe from our promotional emails using the "unsubscribe" link at the bottom of any marketing message.
    • Withdraw Consent: If you previously gave us consent to process your data, you can withdraw it at any time. This will not affect the lawfulness of any processing that happened before you withdrew consent.
    • Lodge Complaints: File a complaint with your local data protection authority if you believe we have violated your privacy rights.
    To exercise any of these rights, please email us at legal@macrofy.com. We will verify your identity before processing your request to ensure your data remains secure.

    6. DATA SECURITY

    We take the security of your data seriously and have built our infrastructure to meet rigorous industry standards, including SOC 2 compliance.

    We protect your information by using industry-standard encryption (both in transit and at rest), implementing strict role-based access controls for our employees, and continuously monitoring our systems for vulnerabilities.

    However, we want to be honest with you: no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

    You also play a role in keeping your data safe. We encourage you to use strong, unique passwords for your Macrofy account and keep your devices secure. In the unlikely event of a data breach that compromises your personal information, we commit to notifying you and the relevant regulatory bodies within the timeframes required by law (typically within 72 hours of discovery).

    7. DATA RETENTION

    We only keep your personal information for as long as necessary to fulfill the purposes outlined in this policy.

    • Active Account Data: We retain your profile, physical metrics, and dietary logs for the duration of our relationship, plus a reasonable 30-day buffer after account deletion to ensure complete removal from our backup systems.
    • Financial Records: We keep billing and payment history for 7 years to comply with US tax and accounting laws.
    • Marketing Preferences: We retain your consent records until you withdraw them or opt out.
    • Technical Logs: We routinely delete or anonymize server and technical logs after 12 months, as this provides enough historical data to identify long-term performance trends without hoarding unnecessary information.

    8. COOKIES & TRACKING

    Our website uses cookies and similar tracking technologies to function properly and help us understand how visitors use our site.

    We use essential cookies to keep you logged in and secure your session. We also use analytics cookies to see which pages are most popular and how users navigate our documentation.

    You have control over these trackers. You can instruct your browser to refuse all non-essential cookies or to indicate when a cookie is being sent. If you choose to disable cookies, some portions of our website may not function properly.

    9. CHILDREN'S PRIVACY

    Our platform is designed for developers and adult users. We do not knowingly collect personal information from children under the age of 13 (or under 16 in the EU/EEA) in compliance with the Children's Online Privacy Protection Act (COPPA) and the GDPR.

    If you are a parent or guardian and believe your child has provided us with personal information, please contact us at legal@macrofy.com. If we become aware that we have collected personal data from a child without parental consent, we will take immediate steps to delete that information from our servers.

    10. INTERNATIONAL TRANSFERS

    Macrofy LLC is headquartered in the United States. Because we serve an international customer base, your personal information may be transferred to, stored, and processed in the US or other countries where our essential service providers operate.

    When we transfer data from the European Union, the European Economic Area (EEA), or the UK to the US, we ensure your data remains protected. We rely on legally recognized transfer mechanisms, specifically Standard Contractual Clauses (SCCs) approved by the European Commission, and your explicit consent where applicable. This ensures that your privacy rights travel with your data, regardless of where it is processed.

    11. CHANGES TO THIS POLICY

    Technology and privacy laws evolve, and our Privacy Policy will occasionally change to reflect new legal requirements or updates to our services.

    When we make significant changes, we will notify you by sending an email to the address associated with your account and by posting a prominent notice on our website before the changes take effect. Your continued use of Macrofy after the effective date of the updated policy constitutes your understanding of the changes. You can always find the most current version of this policy at https://macrofy.com.

    12. CONTACT US

    If you have questions, concerns, or feedback about this Privacy Policy or how we handle your data, we want to hear from you.

    • Website: https://macrofy.com
    We aim to respond to all privacy-related inquiries within 7 business days.

    13. CATEGORIES TABLE (CCPA/CPRA)

    For residents of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) require us to provide a detailed mapping of the personal information we have collected over the past 12 months.

    Sensitive Personal Information: We collect physical metrics and dietary logs, which may be classified as sensitive health-related information under the CPRA. You have the right to limit the use and disclosure of your sensitive personal information to only what is necessary to perform the services reasonably expected by an average consumer. To exercise this right, contact legal@macrofy.com.

    Category of Personal Information

    Sources

    Business Purpose

    Categories of Third Parties Disclosed To

    Retention Period

    Identifiers (Name, email address, IP address, account ID)

    Directly from you; Automatically collected

    Account creation, service delivery, security, communication

    Cloud hosting providers, customer support tools

    Duration of account + 30 days

    Commercial Information (Subscription status, payment history)

    Directly from you; Payment processors

    Billing, accounting, legal compliance

    Payment processors, accounting firms

    7 years (legal requirement)

    Internet / Network Activity (Device info, usage analytics, technical logs)

    Automatically collected

    Service improvement, debugging, security monitoring

    Cloud hosting providers, analytics providers

    12 months

    Sensory Data (Photos and camera input)

    Directly from you

    Food recognition, machine learning model training

    Cloud hosting providers

    Duration of account + 30 days

    Sensitive Personal Information (Physical metrics, dietary logs)

    Directly from you

    Personalized nutrition intelligence, historical tracking

    Cloud hosting providers

    Duration of account + 30 days

    ## 14. AUTOMATED DECISION-MAKING

    Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

    Macrofy LLC does not engage in any automated decision-making or profiling that produces legal or similarly significant effects. While we use machine learning to recognize food items and return nutritional data, these automated processes are strictly informational and do not impact your legal rights, access to services, or financial status.

    15. PRIVACY SIGNALS

    We respect your choice to opt out of tracking. Macrofy LLC honors the Global Privacy Control (GPC) browser signal. If your browser or extension transmits a GPC signal, our website will automatically recognize it and opt you out of any applicable tracking or non-essential cookies, in compliance with privacy laws in California, Colorado, Connecticut, Montana, Texas, and other applicable jurisdictions.

    16. SUB-PROCESSORS

    To provide our platform, we engage third-party sub-processors to assist with data storage, payment processing, and analytics (such as AWS for cloud hosting and Stripe for payments).

    We maintain a current, comprehensive list of all active sub-processors. You can view this list at any time by visiting our website's Trust Center. Furthermore, customers can subscribe to receive email notifications at least 30 days before we add or change any sub-processor, giving you time to review the changes. To subscribe to these updates, please email legal@macrofy.com.

    17. EU/UK REPRESENTATIVE

    Under Article 27 of the GDPR, businesses established outside the EU/UK that offer services to individuals within those regions must appoint a representative.

    Name: ________________________________________________________

    Address: ______________________________________________________

    Email: ________________________________________________________

    (Note: We are currently in the process of finalizing our designated representative. In the interim, all EU/UK inquiries should be directed to legal@macrofy.com).

    18. SUPERVISORY AUTHORITY

    If you are located in the European Economic Area (EEA) and believe we have not adequately resolved a privacy concern, you have the right to lodge a complaint with a supervisory authority. While you may contact the data protection authority in your country of residence, our primary supervisory contact for EU matters is the Irish Data Protection Commission (DPC).

    If you are a resident of California, you may direct complaints to the California Privacy Protection Agency (CPPA).

    Consent Required

    By clicking "I Agree", you acknowledge that you have read and understood this policy.

    Powered by PolicyForge