Privacy Policy
Effective July 21, 2026 · Applies to the MacroPair iOS app and macropair.com
1. Who we are
MacroPair is made by HarbingerScope LLC, doing business as WhiteBoxForge, in Richmond, Texas, USA ("we", "us"). We are the data controller for the personal information described here. You can reach us at [email protected].
The short version: MacroPair is a paid product. We make money from subscriptions — not from advertising, and not from your data. We collect what the coaching needs, we share it with no one beyond the service providers who run the app, and you can delete all of it yourself, in the app, at any time.
2. What we collect
Account information
- Email address and name — to create and secure your account.
- Password — stored only as a one-way cryptographic hash (scrypt). We cannot read it.
- Sign in with Apple or Google identifiers — if you choose a provider sign-in, we store the provider's stable account identifier and the email it shares. We never receive your Apple or Google password.
Health and wellness data you log
- Biometrics — age, height, weight entries and sex as used by the energy equations, with your chosen units in lb or kg.
- Food diary — the foods, portions in g or oz, recipes and meals you log, including entries a household partner logs for you (always attributed).
- Goals and plan data — goal weight, pace, macro split, training days and the targets the engine computes.
- Photos and descriptions you choose to submit — barcode frames are processed on-device. Nutrition-label photos, photos of a plated meal, and typed meal descriptions are sent to our server and on to our AI provider to estimate what is in them. Each of these is a deliberate action you take, after a one-time consent screen. Two things to be plain about: the nutrition numbers read from a label are also used to improve our food catalog, and where the barcode is one we do not yet hold, that product's name, brand and numbers become a catalog entry other users can see — this is described in full in the Terms. Your photo itself is never stored and never published.
- Your weekly plan adjustment — if you have consented to AI features, the app sends your previous and new calorie targets, its estimate of your energy expenditure, and any note you wrote about that week, so the explanation you read is written in plain language. This one happens automatically as part of the weekly adjustment rather than being a button you press. Turn AI features off in Settings and it stops.
- Progress photos and tape measurements stay on your phone. They are stored in the app's own storage on your device, are never uploaded to us, and are not visible to a household partner. Deleting the app deletes them.
Technical data
- Sync metadata — timestamps and device-generated identifiers that keep offline changes consistent across devices.
- Crash and error reports — if the app crashes, a diagnostic report (device model, OS version, stack trace) may be sent so we can fix it. Crash reports are not linked to your food or weight data.
- Subscription status — whether your subscription is active, via Apple and our subscription processor. We never see your card number.
3. How we use it
- To run the coaching. Your logs and weight trend feed the adaptive engine that computes your targets in kcal and g.
- To operate your household — showing shared meals and partner visibility exactly as you have consented to.
- To provide support when you contact us.
- To secure the service — rate limiting, abuse prevention and account protection.
- To improve MacroPair using usage patterns — never your identifiable diary.
We do not use your personal data to train machine-learning models, and we do not build advertising profiles.
4. Household sharing
MacroPair's defining feature is a two-person household, so we are explicit about what linking means:
- Joining a household is mutual and consent-based — one partner invites, the other accepts.
- While linked, each partner can see the other's diary, weights, targets and progress, and can log entries to the other's day. Every entry records who created it.
- Either partner can leave at any time. Leaving — or removing a partner — immediately severs access in both directions, including access to history.
- Deleting your account removes your data from your former partner's view as part of the same action.
5. Service providers
We use a small number of processors to run MacroPair. Each receives only what its job requires:
| Provider | Role | What it handles |
|---|---|---|
| Railway (USA) | Cloud hosting | The MacroPair server and database — your account and logged data, encrypted in transit |
| Apple | Sign in with Apple; App Store billing | Provider sign-in identifiers; subscription payments (we never see payment details) |
| Google sign-in | Provider sign-in identifiers only | |
| RevenueCat | Subscription management | Subscription status tied to your account identifier, so that a subscription follows your account rather than a single phone. No diary data, no payment details |
| Sentry | Crash and performance diagnostics | Crash reports and performance timings. If the app errors, it also records a short replay of that screen with every piece of text and every image masked out — we see the shape of what broke, never what you logged. No replay is ever recorded when the app is working normally, and none of it is tied to your name or account. |
| Anthropic | AI food analysis and plain-language coaching notes | Nutrition-label photos, meal photos and typed meal descriptions you choose to submit, to extract nutrition facts. Also, when AI features are on: your calorie targets, estimated expenditure and your own note at each weekly adjustment, so the explanation reads like a sentence; and, if you use the dinner picker, each household member's remaining macros for the day plus the candidate recipe names. Household members are pseudonymised before sending, every member must have consented, and none of it is used for AI training |
| Open Food Facts | Food database lookups | When you scan a barcode we do not already hold, that barcode is looked up live. Sent server-to-server — your identity, IP address and diary are never included |
| USDA FoodData Central (USA) | Food database lookups | The same: a food identifier only, server-to-server, with nothing about you attached |
| Expo | App updates and app-open counts | Delivers over-the-air app updates, and counts app opens by version, platform and device model so we can see whether an update actually reached people. Not tied to your account, and it never sees your diary |
| PostHog (USA) | Product analytics | App usage events (screens and feature funnel) tied to your account identifier — never your diary contents, weights or photos |
| Resend (USA) | Transactional email | Your email address and the content of emails we send you (invites, launch updates) |
We do not transfer your data to any party for that party's own purposes.
Refund requests. If you ask Apple for a refund on a MacroPair subscription, Apple may ask us how much of the subscription you actually used, so that it can decide the request fairly. With your consent — given when you accept our Terms of Use — we send Apple a usage summary: how long you have been subscribed and broadly how much you used the app. We never send your diary contents, your weights or your photos. If you would rather we sent nothing, email [email protected] and we will withhold it, with no effect on your refund request.
6. Optional group statistics
If you turn on "Faster first-week coaching" in Settings (off by default), your estimated daily calorie burn joins coarse, anonymous group statistics — grouped only by sex, age decade and 15 kg weight band, and only published when a group holds at least 20 participants. Your diary, weights, photos and identity are never part of these statistics, they never leave our own database, and turning the setting off removes you from the next weekly calculation.
7. Apple Health (HealthKit)
Apple Health is off unless you turn it on in Settings. When you do, MacroPair reads two things: your body weight, so a smart scale's readings become weigh-ins without retyping them, and today's workouts (start time and duration only — never heart rate, route or any other detail), so the app can suggest timing carbohydrates around training. With your permission it also writes back the weigh-ins you enter in MacroPair, so Health stays your single record.
Health data is used only to provide these features. In line with Apple's rules it is never used for advertising, never sold, never shared with data brokers, and never sent to our AI provider or any analytics service. You can revoke access at any time in the Health app under Profile → Apps, or by turning the setting off in MacroPair; deleting your account deletes the weigh-ins we stored.
8. What we never do
- We never sell your personal data, and we never share it with data brokers or advertisers.
- We show no ads and use no third-party advertising or marketing SDKs in the app.
- We do not use your health data for marketing, and we do not "de-identify then monetize" individual-level records.
9. Retention and deletion
- Your data is kept for as long as your account exists, so your history can power your coaching.
- Delete your account in the app — Settings → Account → Delete account. Deletion is immediate: your profile, diary, weights, recipes, household links and provider sign-in links are removed from the production system. Encrypted backups age out on a fixed schedule shortly after.
- If you cannot access the app, email us from your account address and we will complete the deletion for you.
- One thing survives, and it is not about you. If you added a product whose barcode was missing from our catalog, that product's name, brand and nutrition numbers stay in the shared catalog after your account is gone. A published entry carries no link to you — it is a fact about a product on a shelf, and removing it would re-break the database for everyone else. Your own copy of it, and everything else you logged, is deleted. The full rule is in the Terms.
- Support emails are retained as ordinary business correspondence.
10. Security
- All traffic between the app and our servers uses TLS encryption.
- Passwords are hashed with scrypt; provider sign-ins are verified cryptographically against Apple's and Google's published keys.
- Access to any household's data is enforced by server-side authorization checks on every request, and our release process includes an automated cross-tenant isolation audit — a release does not ship if any account can read another's data outside a consented household.
- No system is perfectly secure. If a breach affects your data, we will notify you as required by law.
11. Your rights
Depending on where you live — including under the GDPR, UK GDPR, the California Consumer Privacy Act and the Texas Data Privacy and Security Act — you may have the right to:
- Access the personal data we hold about you, and receive a portable copy;
- Correct inaccurate data (most data is directly editable in the app);
- Delete your data (available in-app, always, to everyone);
- Object to or restrict certain processing;
- Not be discriminated against for exercising any of these rights.
To exercise a right, email [email protected]. We verify requests against the account's email address and respond within the timeframe your law requires. We do not sell or share personal information as defined by the CCPA, so there is nothing to opt out of. If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority.
Washington State residents: our Consumer Health Data Privacy Policy covers the categories, sources and rights specific to the My Health My Data Act.
12. This website
macropair.com sets no cookies unless you opt in. If you choose "Allow analytics" in the consent banner, we use PostHog (US region) to measure visits, page engagement and where visitors come from — first-party only, never for advertising, never sold, no session recording. Choose "Essential only" and nothing is set beyond the stored answer itself; the site works identically. The TDEE calculator runs entirely in your browser — nothing you type in it is transmitted or stored. Standard web-server logs (IP address, request path, timestamp) are kept briefly for security and capacity purposes. Details: Cookie Notice.
13. Children
MacroPair is not for children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it. Anyone aged 13 to 17 may use MacroPair only with a parent or guardian's consent and involvement — see Eligibility in the Terms of Use.
14. Changes
If we change this policy in a way that matters, we will update the date at the top and note the change in the app before it takes effect. We will never quietly weaken the "what we never do" section.
15. Contact
HarbingerScope LLC (WhiteBoxForge) · Richmond, Texas, USA
[email protected]