Macrotrack · Legal
Privacy Policy
How we collect, use, store and protect your personal information.
Last updated: 11 July 2026
Effective date: 11 July 2026
This Privacy Policy explains how Emberry Pty Ltd (ACN 700 020 202) ("Macrotrack", "we", "us") collects, uses, stores and discloses your personal information when you use the Macrotrack Progressive Web App at macrotrack.com.au (the "Service").
We are bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). If you access the Service from outside Australia, additional rights may apply to you. See section 12.
Notification of collection
We collect the personal information described in section 1, for the purposes set out in section 2, and we disclose it to the recipients named in section 4. Some of it we need and some of it we do not:
- Your email address is required. It is how you sign in and how we contact you about your account. Without it we cannot open an account for you.
- Your sex, age, height, weight, activity level and goal are required for the Service to do its job. Your daily energy and macronutrient targets are calculated from them. If you do not provide them we cannot calculate targets, and the app cannot do the main thing it exists to do.
- The rest is optional. A PIN, reminders, photos, contributed product entries, water and weight logs, and payment details for Macrotrack Pro are all yours to skip. If you skip one, the rest of the Service still works and you simply do not get that feature: no payment details means you stay on the free tier, no photo means you enter the food by hand.
- Your food, weight and body information is health information and we collect it only with your consent. That is explained in the note under section 1.3, together with how to withdraw it.
This Policy is also where we explain what happens afterwards. Section 8 sets out how to ask us for a copy of the personal information we hold about you, how to have it corrected, how to have it deleted, and how to complain to us or to the Office of the Australian Information Commissioner if you believe we have mishandled it.
1. What we collect
1.1 Information you give us when you sign up
- Email address
- A password you choose (stored only as a salted hash by AWS Cognito; we never see the plaintext)
- A 4 to 6 digit PIN you optionally set for fast re-authentication (stored only as a salted HMAC-SHA256 hash in your Cognito user attributes; we cannot recover or read the plaintext)
1.2 Profile information you enter during onboarding and afterwards
- Display name (username)
- Sex (M/F/X), age, optional birth month/year
- Height (cm), current weight (kg), activity level, weight goal (kg/week)
- Australian state (used to infer your timezone)
- Optional daily macro targets and water target
1.3 Logs you record while using the Service
- Food entries: name, time, source (barcode / manual / OCR / AI photo / AI describe), servings, serving size, per-100g macronutrients, totals
- Weight readings (date + kg)
- Water entries (date + millilitres) and individual water events (time + ml)
- Meal templates you save and food favourites you mark
Sensitive health information: important.
The information in sections 1.2 and 1.3 (body metrics, dietary intake, weight history, water intake) constitutes "health information" and "sensitive information" under Australian Privacy Principle 3. Australian Privacy Principle 3.3 requires us to obtain your consent before collecting this category of information. When you create your account you expressly agree to this Privacy Policy, including the collection and processing of your health information, and confirm you are at least 16 years old; this constitutes your express consent under APP 3 for the collection, storage, and use of this sensitive health information for the purposes described in section 2. You may withdraw consent at any time by closing your account; on closure we will delete this information in accordance with section 6.
1.4 Reminder and notification settings
- Whether you have reminders enabled
- Your preferred water-reminder interval
- For Web Push: the push subscription endpoint and associated keys issued by your browser
1.5 If you subscribe to Macrotrack Pro
- A Stripe customer ID, subscription ID, subscription status, and current billing period end date. Stripe handles all payment card information; we never see your full card number.
1.6 Photos and text you submit to the AI features
- When you use AI photo estimation, the image you capture is resized on your device and uploaded to our own private storage in AWS Sydney (
ap-southeast-2), into a folder keyed to your account. Our server reads it back from there and sends it to Anthropic's Claude model hosted on Amazon Bedrock in the same region, and the nutritional data the model returns is saved to your diary. The image itself is kept. It stays in our storage after the estimate is returned and it has no automatic expiry, so it remains there until you delete your account. It is readable by you, and by our administrator through a restricted internal review tool. Every stored image is permanently deleted when you delete your account (see section 6). - When you use AI describe, your text description is sent to the same model in the same region. The original text is not retained after the response is generated.
- When you use Label OCR (nutrition panel reading), the photo of the panel takes the same path: it is uploaded to our storage in AWS Sydney (
ap-southeast-2) under the same account folder, then read back and sent to Anthropic's Claude model hosted on Amazon Bedrock in AWS Sydney (ap-southeast-2), the same vendor used for AI photo and AI describe for text extraction. These photos are kept on the same terms as the photos above, and are deleted when you delete your account. - Model training. Anthropic does not use Bedrock customer inputs (your photo, your text, our prompts) to train, fine-tune, or improve its foundation models. This is contractually guaranteed under the AWS Bedrock Service Terms. We do not train any AI models on your data either.
- When you ask for a week review (“Review my week”), we send the same model a SUMMARY of that week, never your diary itself: daily energy and macro totals, the foods that contributed most, how often you met your own target, and whether your goal is to lose, maintain or gain. It does not include your name, your email, your account identifier, your weight, your height, your age, or any calendar date. Days are sent as weekdays.
- AI output is an estimate, not a measurement. AI-generated macros and portion sizes may contain errors and can reflect biases in the underlying training data. They are starting points for your review. Always confirm before logging. See clause 2.6 of the Terms of Service for the full AI disclaimer.
- A week review is general guidance, not advice. It comments on the food you logged. It does not diagnose, screen for, or refer to any medical condition, and it does not comment on your body. It is not a substitute for a dietitian or a doctor.
1.7 Information collected automatically
- Standard web-server logs (IP address, user agent, request paths, response codes, timestamps) retained by AWS for operational and security purposes for up to 90 days.
- We use Google Analytics 4 to understand aggregate site usage (pages viewed, approximate location at country level, device type, referring site, session duration, and two milestone counts, that an account was verified and that a first food item was logged, each sent as a bare count with no accompanying data). Google receives an anonymised IP address, because we have IP anonymisation enabled. We do not use Google Analytics for advertising or remarketing. Beyond GA4 we do not use any third-party analytics SDK (no PostHog, no Mixpanel, no Segment, no Meta Pixel) and we do not use advertising trackers. We do keep our own activity log on our own servers, which is a different thing and is described in section 1.10. Nothing in it goes to Google.
1.8 Information stored on your device (not on our servers)
- localStorage keys (
macrotrack-logs,macrotrack-profile,macrotrack-meals,macrotrack-private-foods,macrotrack-last-email). These are an offline-friendly cache of your synced data, plus a convenience copy of the last email you signed in with. - Service worker caches of app assets, to make the PWA work offline.
1.9 Product photos and details you contribute to the shared food database
- When you photograph the nutrition panel of a product we do not have and choose to contribute it, we record the barcode, the product name, the nutrition figures read from the panel, and any ingredients and allergens listed on it. The photo of the panel is uploaded to our storage in AWS Sydney (
ap-southeast-2), in a folder keyed to your account. - We keep the photo as the evidence behind the entry. It is what our administrator looks at when reviewing your submission, and what lets us re-check a figure that later looks wrong. It is readable by you, and by our administrator through a restricted internal review tool. It is never published and it is never shown to other members.
- If your submission is approved, the product entry itself (barcode, name and nutrition figures) joins the shared food database that all members can search. That published entry carries no link back to you. Your submission record and your photo remain yours, and both are deleted when you delete your account. See clause 2.9 of the Terms of Service.
1.10 What you do in the app (our own activity log)
- We keep our own record of how you move through the app: each screen you open, each button we have tagged, and about twenty named steps along the way (account created, email confirmed, first food logged, and similar).
- Each record holds a short fixed event name, the time, a session identifier, the position of the event within that session, the screen address with any changing part removed and the query string dropped, whether your account is on the free tier or Pro, whether you are using the installed app or a browser tab, a short qualifier or failure code where one applies, and your account identifier. It is linked to your account, not anonymous.
- It holds no free text at all. Event names are checked against a fixed list of permitted values and anything outside that list is discarded before a record is written, so food names, descriptions, search terms, anything you type into a form and your email address cannot reach it.
- It is stored in our own database in AWS Sydney. It is not sent to Google, and not to any other third party. Each record is deleted automatically 90 days after it is written.
- We use it to see where new members get stuck between signing up and logging their first food, and to reconstruct a problem you report to us.
- It is on by default. You can turn it off for a browser: see section 8.
1.11 Device and session information
- Once per browser session we record against your account the time you were last seen, whether you launched the installed app or opened a browser tab, and the browser user-agent string your device sends (which names your browser, its version and your operating system). There is one such record per account and each session overwrites it.
- We use it to see how many members are active and how many have installed the app, and to reproduce a display problem on a device we do not have in front of us.
1.12 Referral codes
- Your account is issued a referral code so that you can invite someone to the Service.
- If you arrive through another member's invitation link, we store that member's code on your account along with the date it was recorded. This is a lasting link between your account and theirs. It is written once and not changed afterwards.
- We use it only to attribute an invitation to the member who sent it. It is deleted when you delete your account.
2. Why we collect it
We collect the information above to:
- (a) provide the Service to you (operate your account, store your diary, sync across your devices, calculate your daily totals);
- (b) compute your nutrition targets from the body and goal information you provide;
- (c) deliver reminder notifications if you ask us to;
- (d) operate the AI features if you choose to use them;
- (e) process payment for Macrotrack Pro (via Stripe);
- (f) respond to your support enquiries;
- (g) detect, prevent and respond to security incidents and misuse;
- (h) comply with our legal obligations.
We do not use your information for advertising or for profile-based marketing.
3. Legal bases (for users in the EU/UK)
Where the GDPR or UK GDPR applies to you, we rely on these legal bases:
- Contract performance: to operate the Service for you (sections 2(a), (b), (d), (e))
- Legitimate interests: security, fraud prevention, service improvement (section 2(g))
- Consent: for push notification reminders and any future marketing emails (you can withdraw at any time)
- Legal obligation: where we are required by law to retain or disclose (section 2(h))
4. Who we share it with
We share personal information only with the following categories of recipient:
4.1 Service providers acting on our behalf
- Amazon Web Services (AWS): hosting, database (DynamoDB), authentication (Cognito User Pools), AI model invocation (Bedrock), file storage. All processing occurs in AWS Sydney (
ap-southeast-2). AWS is bound by its Data Processing Addendum. - Anthropic (via Amazon Bedrock): AI inference only. Anthropic does NOT use Bedrock customer inputs to train its models.
- Stripe Payments Australia Pty Ltd: subscription billing. Stripe receives your email and (when you pay) your card details; we receive only the resulting customer/subscription identifiers and billing status.
- Web Push providers (Apple Push Notification Service, Google Firebase Cloud Messaging, Mozilla autopush), to deliver reminder notifications you have enabled. Only the notification payload and your browser-issued endpoint are involved.
- Google LLC (Google Analytics 4): aggregate site usage data only (anonymised IP, pages viewed, device type, session metadata, and two milestone counts: account verified, and first food item logged). Those two are sent as counts alone, with no user identifier, no email, no food or health data accompanies them. We use them to understand which referring sites bring people who go on to use the Service. No personal identifiers are passed to Google. Subject to Google's privacy policy and Standard Contractual Clauses for non-EU transfers.
4.2 The Open Food Facts public product database
When you scan a barcode, we send the barcode digits only (no user identity, no IP-linkable data, because the request is proxied through our server) to Open Food Facts' public API. The product data we display is licensed under the Open Database License (ODbL) with database contents under the Database Contents License; we attribute Open Food Facts as the source on every product confirmation screen. Open Food Facts has its own privacy practices governing its database.
4.3 Where required by law
For example, in response to a valid court order or law enforcement request, where we have a good-faith belief the disclosure is required.
4.4 In a business transfer
If Macrotrack is acquired, merged, or sells substantially all of its assets, your information may be transferred to the acquirer subject to this Policy continuing to apply.
We do NOT sell your personal information, and we do NOT share it for cross-context behavioural advertising.
5. Cross-border data transfers
The Service is hosted in AWS Sydney (ap-southeast-2). Most of your personal information stays in Australia. The following limited categories may be processed overseas:
- Stripe's processing may involve servers in the United States (subject to Stripe's standard contractual clauses and certifications).
- Web Push delivery is routed through the operator of your browser's push service (Apple, Google, or Mozilla), which may process the push endpoint and notification payload in the United States, or in another country where that operator runs push infrastructure. Those operators do not publish a fixed list of the countries a push notification may be routed through, so we are not able to name every one of them in advance.
- Google Analytics 4 processes aggregated session data on Google's global infrastructure, primarily in the United States. IP anonymisation is enabled so Google never receives a complete IP address.
By using the Service you consent to these overseas processings.
6. How long we keep it
- Account data and your diary: for as long as your account is open. When you close your account from the Profile screen, your sign-in, profile, food logs, weight entries, water entries, saved meals, and favourites are permanently deleted from our active databases within minutes. Deletion is irreversible. We do not maintain a recovery window. Backups containing your data are retained by AWS for up to 35 days as part of standard infrastructure resilience and then expire; we do not restore from these backups for account-recovery requests.
- Stripe payment records: retained by Stripe and by us for at least 7 years for Australian tax law compliance.
- Web server logs: up to 90 days.
- Your in-app activity log (section 1.10): each record is deleted automatically 90 days after it is written. When you delete your account they are all deleted immediately, rather than left to expire.
- Device and session information and referral codes (sections 1.11 and 1.12): kept for as long as your account is open, and deleted with it.
- Photos you take for the AI features and for product submissions: kept. Every AI photo estimate, nutrition-panel reading and contributed product photo is stored in our AWS Sydney storage in a folder keyed to your account. There is currently no automatic expiry on these objects, so they stay until your account is deleted. When you delete your account, every object under both of your photo folders is permanently erased before anything else is removed, and if any object cannot be erased we stop and leave your account intact rather than report a deletion we did not complete.
- Text you send to the AI features: not retained. Your AI describe text and the week-review summary are used to generate the response and are not stored afterwards.
- Week reviews: the twelve most recent are kept so you can look back at them; older ones are deleted automatically as new ones are written. You can download all of them as a spreadsheet at any time from Profile, and they are deleted with your account.
7. Security
- All traffic to the Service is encrypted in transit using HTTPS (TLS 1.2+).
- Data at rest is encrypted using AWS-managed keys (DynamoDB, Cognito).
- Passwords and PINs are stored only as salted, irreversible hashes. We cannot recover them, so you must reset.
- Access to production systems is restricted to authorised personnel via IAM and multi-factor authentication.
- We follow the principle of least privilege for all service-to-service access.
No system is perfectly secure. We will notify you and the Office of the Australian Information Commissioner (OAIC) of any data breach that is likely to result in serious harm, in accordance with the Notifiable Data Breaches scheme.
8. Your rights
Under the APPs (and similar rights under the GDPR / UK GDPR / CCPA), you can:
- Access: request a copy of the personal information we hold about you.
- Correct: ask us to correct information that is wrong, out of date, or incomplete. You can edit most fields yourself in the app.
- Delete: close your account from Profile, or email us. Deletion is permanent.
- Export: export your diary data at any time as JSON or CSV from the Profile screen.
- Withdraw consent and turn things off: you can turn reminders off in Settings at any time. You can turn off the in-app activity log described in section 1.10 by opening the app with
?mttrack=0added to the address (for examplehttps://www.macrotrack.com.au/today?mttrack=0). The setting is remembered for that browser until you clear its stored data, and?mttrack=1turns it back on. It is set per browser, so repeat it on each device you use. You can limit Google Analytics through your browser's own privacy settings or Google's opt-out add-on. Withdrawing consent to our collection of your health information means closing your account, because the Service cannot operate without it. - Complain: if you believe we have mishandled your information, email us first (support@macrotrack.com.au). If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au. EU/UK users can complain to their local supervisory authority.
We will respond to your request within 30 days.
9. Children
Macrotrack is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, please email us so we can delete it.
10. Cookies and similar technologies
The Service uses the following cookies and local storage:
- Google Analytics 4 cookies (
_ga,_ga_<ID>), set by Google's gtag.js to distinguish unique users and sessions for aggregate analytics. First-party (set on macrotrack.com.au), 13-month expiry. No cross-site behavioural tracking.
Beyond GA4 we do not use third-party tracking or advertising cookies. The Service also uses:
- First-party cookies set by AWS Cognito to keep you signed in.
- localStorage on your browser to cache your diary so the Service works offline (see 1.8).
- Service worker caching of static assets, for the PWA experience.
You can clear these at any time via your browser's privacy settings. Clearing them will sign you out and discard your offline cache; your data on our servers is unaffected.
11. Changes to this Policy
We will update this Policy from time to time. Material changes will be notified by email to your account address or via an in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this Policy will always reflect the most recent revision.
12. Contact
Macrotrack: Emberry Pty Ltd
Email: support@macrotrack.com.au
ACN 700 020 202
Address: Western Australia 6028, Australia
For users in the EU or UK, we do not have an EU/UK representative because our activities are not directed at the EU/UK market. If you are an EU/UK data subject and wish to exercise your rights, please contact us using the details above.
For California residents: we do not sell or share personal information as those terms are defined in the CCPA/CPRA. You may exercise your rights to know, delete, correct and opt-out via the same contact details above.