1. What we collect
| Data | Why |
|---|---|
| Username & password (hashed, never stored in plain text) | Account login |
| Email address (optional) | Password reset, account notices |
| Profile info you enter (age, weight, goals, dietary preferences) | Generating your meal plans and macro targets |
| Meals, plans, and foods you save | Letting you come back to your own plans |
| Payment & billing status | Managing your subscription — actual card details are handled entirely by Stripe, we never see or store them |
2. How it's used
Your data is used to run the app for you: calculating targets, generating and saving plans, and managing your subscription. We don't sell your personal data.
3. Foods you add may be shared
If you manually add a food or scan a barcode, it may be cross-referenced against a public nutrition database (Open Food Facts) to confirm accuracy. If confirmed, that specific food item (name, brand, and nutrition values only — not linked to your account in the shared copy beyond an internal "added by" record visible to site admins) may be added to the shared food database used by all accounts. Your personal meal plans and saved data are never shared with other accounts.
4. Cookies & sessions
We use a session cookie to keep you logged in. It's required for the app to function and isn't used for advertising or cross-site tracking.
5. Third parties
- Stripe — processes payments and stores your payment method securely; see Stripe's own privacy policy.
- Open Food Facts — a public database we query to verify foods you add (see above); we don't send it any personal information about you.
- Email delivery (if configured by the site operator) — used only to send password-reset and account-verification emails to the address you provide.
6. Data retention & deletion
We keep your account data for as long as your account exists. You can export a copy of your data or permanently delete your account and all associated data yourself, any time, from the Change Password screen once logged in — no need to contact anyone. Deleting your account also cancels any active subscription.
7. Security
Passwords are hashed (never stored in plain text), password-reset links are single-use and expire quickly, and only a cryptographic hash of any reset token is ever stored — not the token itself.
8. Changes
We may update this policy from time to time; the "last updated" date at the top will reflect the most recent change.
9. Contact
Questions about this policy or your data? Email regan.hartley@themacromeal.com, or use the "Contact Admin" link in your account sidebar once logged in.