Privacy policy
Last updated: 30 July 2026
At MacroDash we take your privacy seriously. This page explains what personal data we process, on what legal basis, for how long, who we share it with and how to exercise your rights. This policy follows Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
This English text is a translation provided for convenience. The binding version is the Spanish one; if the two differ, the Spanish version prevails.
1. Data controller
Controller: Jesús Márquez Gallardo (individual).
- Contact email: soporte@macrodash.es
- Website: https://macrodash.es
2. What data we process
- Account data: email address and name. If you sign in with Google or Apple, we also receive the associated profile picture and a provider identifier so we can recognise you on future sign-ins. Your password, when you use one, is always stored hashed, never in plain text.
- Physical profile and goals: sex, age, height, weight, target and starting weight, activity level, goal (deficit, maintenance or surplus) and, if you adjust them, your macro values. These are used to calculate your basal metabolic rate and your targets.
- Nutrition diary: the meals and water you log, plus the custom foods (including the image you optionally add to a custom food), recipes and collections you create.
- Workouts: the routines you save, the sessions you complete, exercises and sets (reps, weight, rest) and their duration and intensity, used to estimate the energy expenditure of the workout.
- Daily activity: steps, streaks and your daily totals.
- Health data (optional): if you enable the feature, the app reads from Apple Health (on iOS) or Health Connect (on Android) the following data to refine your energy expenditure and show your wellness metrics: active energy, steps, heart rate, workouts, sleep and its stages, resting heart rate and heart-rate variability (HRV). Access is read-only: we never write to Apple Health or Health Connect. It is optional, you enable it yourself, it requires your explicit permission and you can revoke it whenever you want from the system or app settings.
- AI chat (optional): if you use the chat with the assistant, we store the conversations and the messages you send and receive so that you can consult them later. Section 5 describes this in detail.
- Minimal technical data: your IP address is processed transiently so the service can work, for example to rate-limit sign-in and password-reset attempts. We also record per-user technical events (timestamps, no content) needed to enforce usage quotas, such as the monthly chat message limit.
- Diagnostic data: if the app hits an error, a technical report (error type, app version, operating system, stack trace) is sent to our monitoring provider so we can fix it. No tokens, passwords or your email address are sent, and transient network errors are discarded.
3. What we use it for and on what legal basis
- Providing the service (account, diary, workouts, calculation of targets and expenditure): performance of the contract (Art. 6(1)(b) GDPR).
- Reading Apple Health (iOS) or Health Connect (Android) data: your consent (Art. 6(1)(a) and Art. 9(2)(a) for health data), which you give when enabling the feature and can withdraw at any time.
- Using the AI chat: your consent (Art. 6(1)(a) and Art. 9(2)(a), because the context includes data related to your health), which you give when you send your first message. You can stop using it whenever you want, and delete your conversations at any time.
- Sending you the password-reset email: performance of the contract.
- Security, abuse prevention, enforcement of usage quotas and error monitoring: legitimate interest (Art. 6(1)(f)) in keeping the service stable and secure.
We do not use your data for advertising and we do not sell it. We do not carry out profiling with legal effects or automated decision-making that significantly affects you.
4. Health data (Apple Health and Health Connect)
On iOS this data comes from Apple Health (HealthKit) and on Android from Health Connect. In both cases access is read-only, limited to the data types listed in section 2, and only happens if you enable the feature.
We use it solely to calculate your energy expenditure and to show your wellness metrics (sleep, resting heart rate and HRV) with their history and trends. To be able to show you that history, those wellness metrics are stored on our servers (see section 6) and are deleted if you delete your account. They are not used for advertising or marketing purposes, are not disclosed or sold to third parties, and are not used for anything other than providing you the service, in line with Apple’s HealthKit policies and Google Play’s requirements for Health Connect (including the prohibition on sharing Health Connect data with third parties or using it for advertising). You can withdraw access at any time from your Apple Health or Health Connect settings, or by turning the feature off in the app.
5. AI chat (nutrition assistant)
The AI chat is an optional feature. It only activates if you send a message. When you do, we transmit to our AI provider the information the assistant needs in order to answer with context:
- Your profile (sex, age, height, weight, goal and macros) and a summary of your last 7 days (calories and macros consumed, hydration, steps and workouts). This forms part of the instructions we give the model with every message so that its answers refer to your real data rather than to invented estimates.
- Your messages and the most recent messages of the ongoing conversation, so the model can follow the thread.
We do not send your email address, your name, or any account or device identifier. The provider receives only the data listed above and returns the text response.
Provider: Anthropic PBC (United States). Anthropic acts as a data processor. Under its commercial terms, data submitted through its API is not used to train its models.
Retention: we keep your conversations and messages for as long as you keep your account, or until you delete them. You can delete any conversation at any time from the chat screen itself. For security we also record a technical event for each message sent (without content) in order to enforce the monthly usage limit.
Limitations: the responses are generated by a statistical model and may contain errors. They are not medical or professional nutritional advice (see the terms of use).
6. Who we share it with
To operate the service we work with providers that process data on our behalf (data processors):
- Railway: hosting of the application (backend), in the United States (California).
- Neon: hosting of the database, in the European Union (Frankfurt, Germany). This is where your account and your activity are stored.
- RevenueCat: subscription management (purchase validation and subscription status), in the United States. It receives an app user identifier and the transaction data (product, purchase and renewal dates, store country) provided by the App Store and Google Play. It does not receive your diary, your physical profile or your health data.
- Anthropic PBC: provider of the AI model that answers in the chat, in the United States. It only receives what is described in section 5, and only when you choose to use the feature.
- Sentry:monitoring of the application’s technical errors, in the United States. It receives the diagnostic reports described in section 2.
- Resend: delivery of the password-reset email, from the macrodash.es domain.
- Google and Apple: only if you choose to sign in with those accounts. We receive your email address, your name and, if it exists, your profile picture.
- Open Food Facts: when you search for or scan a product that is not in our database, we query their open database. Only the search term or the barcode is sent, never your personal data.
We do not share your data with anyone else, nor for advertising purposes.
7. International transfers
The main database, where your account and your activity are stored, is hosted in the European Union (Frankfurt, Germany) through Neon. Other providers (Railway, Anthropic, Sentry and RevenueCat) process data in the United States, outside the European Economic Area. These transfers to the United States rely on the safeguards provided for by the GDPR, such as the standard contractual clauses approved by the European Commission. If we move any of this processing in the future, we will update this section.
8. How long we keep it
- Your account data and your activity, for as long as you keep your account.
- AI chat conversations, for as long as you keep your account or until you delete them from the app.
- If you delete your account from the app, we delete your data permanently.
- Records of password-reset attempts are purged automatically after 7 days.
- Diagnostic reports sent to Sentry are kept according to their retention policy (90 days by default on their standard plan).
9. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time, as well as withdraw your consent, by writing to soporte@macrodash.es. You can also delete your account directly from the app, and delete your AI chat conversations at any time. If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
10. Security
We encrypt communications in transit (HTTPS/TLS) and store passwords using hash functions. No system is infallible, but we apply reasonable measures to protect your information.
11. Minors
MacroDash is not directed at people under 16. If you are under that age, do not use the app and do not provide us with personal data.
12. Changes to this policy
We may update this policy to reflect changes in the app or in the applicable law. The version in force will be published here together with its update date.
13. Contact
For any privacy question, write to us at soporte@macrodash.es.