Consumer health data
Consumer Health Data Privacy Policy
This separate policy provides the disclosures required for consumer health data handled by Macro Tracker.
Effective August 12, 2026
Consumer health data collected and why
Macro Tracker collects the following categories of consumer health data only when needed to provide the nutrition-ledger product or service you request:
- Food and intake records: foods and beverages, amounts, serving bases, meal names, notes, consumption times and dates, clarifications, corrections, and void or restore history. Macro Tracker uses this data to create, categorize, organize, revise, display, export, and delete the private nutrition records you direct it to handle.
- Account, session, and authorization linkage: your name and email address; internal account, user, session, and request identifiers; IP address and user-agent information when recorded during authentication; and OAuth client, pseudonymous subject, consent, grant, scope, and revocation identifiers. These identifiers are consumer health data only when linked or reasonably linkable to your nutrition data. Macro Tracker uses them to authenticate you, assign private records to the correct account, enforce private account boundaries, authorize and revoke connected hosts, prevent unauthorized access and duplicate writes, and fulfill privacy requests.
- Nutrition and source facts: calories, macronutrients, fiber, sugar alcohols, label and source facts, quantities, quality flags, assumptions, immutable fact versions, and researched-estimate food, nutrient, quantity, source-title, and public-URL details. Macro Tracker uses this data to resolve foods, scale servings, preserve provenance and uncertainty, and calculate the nutrition results you request.
- Goals and nutrition preferences: effective-dated nutrient targets, timezone, units, carbohydrate display, logging mode, food aliases and saved meals. Macro Tracker uses this data to apply your chosen settings, prepare requested records, and compare intake with your targets.
- Derived nutrition results: daily totals, goal progress, rolling averages, coverage and completeness, trends, contributors, and other reports derived from the categories above. Macro Tracker uses this data to produce the summaries and reports you request.
- Health-linked global catalog activity: food facts or factual corrections you submit, immutable nutrition versions, source classifications and provenance. Shared catalog versions are not linked to the account that created them. Macro Tracker uses this data to deduplicate global foods and preserve facts relied on by historical records. Normalized identity, identifiers, serving bases, source quality, and nutrient values may appear to signed-in users without source references.
Macro Tracker is not designed to collect diagnoses, medications, genetic or biometric identifiers, reproductive or sexual-health information, or precise location. Do not place those details in food names or support reports. Macro Tracker does not collect consumer health data for advertising or unrelated profiling and does not use it to train machine-learning models.
Sources of consumer health data
- You, when you create or recover an account or ask the website, API, or a connected host to handle a nutrition record or global food submission.
- Your browser and network, and Macro Tracker's authentication and authorization systems, which create limited session, request, security, account-linkage, and OAuth grant information while signing you in and keeping access scoped and revocable.
- A host you connect, such as ChatGPT, Codex, or Claude, when it sends the structured arguments for the tool you chose. Nutrition Facts images remain with that host; Macro Tracker receives the structured nutrition fields, not the image or raw text.
- Other users, when they submit food facts to the global catalog.
- USDA FoodData Central for public food facts returned from a narrow food search, and public web sources cross-checked by a connected host for a researched intake you ask it to log. Macro Tracker does not fetch the researched source URLs itself.
- Macro Tracker's server calculations, which derive totals, progress, completeness, trends, contributors, and other requested reports from the records above.
How consumer health data is processed
Macro Tracker processes private consumer health data through authenticated, account-scoped website, API, and connected-host requests. Its server validates the structured fields, resolves food facts and serving bases, stores current private records, and calculates totals, progress, completeness, trends, and other requested reports. It returns only the scoped result needed for the request to the website or host you chose. Authenticated website requests may separately return the sanitized global ingredient directory described below.
For account and authorization linkage, the server derives the account subject from the authenticated session or OAuth grant, checks the client, scope, session, and revocation state, and uses the resulting internal user identifier to isolate each private record. Macro Tracker does not use your name, email address, IP address, or user-agent information to infer nutrition or health status.
Cloudflare processes the records in Macro Tracker's hosted database and infrastructure. When scheduled backups are enabled, the database is independently encrypted before the encrypted artifact is stored with GitHub. Macro Tracker does not process Nutrition Facts image bytes and does not collect consumer health data in the background.
Consumer health data shared
Macro Tracker shares the following categories of consumer health data:
- With a host you connect: a pseudonymous account subject and the OAuth client, scope, grant, and connection status needed to bind and control its access; plus the nutrition fields or requested records needed for the tool call, derived results, and receipts. The host's privacy terms govern the copy it receives in your conversation or account.
- With other authenticated Macro Tracker users: sanitized normalized ingredient identity such as name and brand, primary serving basis, source-quality classification, and nutrient values from the global catalog. The directory excludes private foods and intake, usage, private aliases, and source references.
Macro Tracker does not send your account identity, private ledger, goals, or report to USDA. It does not receive or share Nutrition Facts image bytes, file identifiers, or URLs.
Macro Tracker does not disclose your name, email address, session identifier, IP address, user-agent information, or password verifier to a connected host or another authenticated user. A connected host receives only the OAuth credential issued to that host; credentials are not shown to other authenticated users or other hosts.
Processor handling needed to provide a service you request and a qualifying transfer to a successor that assumes the applicable obligations are not treated as sharing under the Washington My Health My Data Act when its statutory conditions are satisfied. Those recipients remain identified below for transparency.
Recipients and processors
- Connected-host providers: OpenAI for ChatGPT and Anthropic for Claude, only after a requested tool call returns a successful result through a hosted callback on that provider's verified domain. A native Codex or Claude loopback grant may still appear Connected when its recognized client name is present in self-declared OAuth metadata. That status does not verify OpenAI or Anthropic as the publisher or recipient.
- Other authenticated Macro Tracker users: signed-in users, limited to the global ingredient-directory fields and exclusions described above.
- Infrastructure processors: Cloudflare processes account, session, authorization, and account-linked nutrition data as needed to provide hosting, database, rate-limiting, backup-recovery, security, and transactional email infrastructure. When scheduled encrypted backups are enabled, GitHub stores the independently encrypted database artifact and workflow metadata; the decryption identity is retained separately. Processor handling is limited to providing these services under instructions consistent with this policy.
- Authorities or a successor: an authority receiving data when legally required, or a successor in a qualifying transaction that assumes the obligations applicable to the data.
No Macro Tracker affiliate currently receives consumer health data.
Macro Tracker does not embed third-party advertising, cross-site analytics, tracking pixels, or similar technology that lets a third party collect consumer health data over time and across different Internet websites or online services from the Macro Tracker website. A host you intentionally connect may retain tool inputs and results over time alongside your activity in that host; its privacy terms and settings govern that copy.
Your consumer health data rights
You may:
- Confirm whether Macro Tracker collects, shares, or sells your consumer health data and access that data, including a list of recipients and available contact information.
- Withdraw consent from future collection or sharing of your consumer health data.
- Request deletion of your consumer health data from Macro Tracker's active systems and notification of the request to applicable affiliates, processors, contractors, and third parties. Deletion from archived or backup systems will be completed within the period allowed by applicable law and no later than six months after authentication.
- Appeal a refusal to act on a request.
Use authenticated Settings to export your data or review active agent connections. To stop future sharing through Codex, Claude, or the ChatGPT MCP app, revoke or disconnect Macro Tracker in that host. Macro Tracker performs no background nutrition collection, so you can stop new collection while retaining your account by not sending new nutrition requests. You do not need to create a new account to exercise these rights.
Review your consumer health data in the authenticated journal and report pages or by using the account export. Request changes to an intake with the correction, void, or restore controls, and change goals in Goals or nutrition preferences in Settings. If those controls do not cover the change you need, use the privacy email process below. Intake corrections atomically replace the current entry; source, serving-basis, assumption, and quality details remain attached to the current items.
If you cannot use the authenticated controls, need a recipient list, want to withdraw consent while keeping your account, or want to appeal a refusal, email privacy@jpamorgan.com from your account address when possible. Put only the request type in the first message; Macro Tracker will reply with secure identity-verification steps. Mark an appeal as “Consumer health data appeal.”
Information provided in response to a request is free up to twice annually. Only a request that is manifestly unfounded, excessive, or repetitive may be charged a reasonable administrative fee or declined, as applicable law permits. For a Washington request, Macro Tracker will authenticate promptly and respond without undue delay and within 45 days after receiving the request; authentication does not extend that initial period. For a Nevada request, Macro Tracker will respond within 45 days after authenticating the request. In either state, one additional 45-day extension may be used when reasonably necessary and explained during the initial response period. For a Nevada deletion request, deletion from active systems and notice to applicable affiliates, processors, contractors, and third parties will be completed within 30 days after authentication. Appeals receive a written response within 45 days. If an appeal is denied, the response will provide contact information for the applicable state attorney general, including the Washington State Attorney General or Nevada Office of the Attorney General. Macro Tracker does not unlawfully discriminate against you for exercising these rights.
Changes to health-data practices
Macro Tracker will not collect, use, or share an additional category of consumer health data, or use consumer health data for an additional purpose, without first updating this policy and obtaining affirmative consent when required. Macro Tracker requires processors to handle consumer health data consistently with this policy.
Macro Tracker will post a material change at this same URL with a new effective date, display a conspicuous notice to affected signed-in account holders, and send notice to their account email before the material change takes effect. When consent is required, the notice will provide a way to make an affirmative choice before the additional collection, use, or sharing begins.
For consumer health data questions, requests, withdrawal, or appeals, email privacy@jpamorgan.com. Never send a password, OAuth token, reset token, Nutrition Facts image, or full meal history by email. Macro Tracker may ask you to verify control of the account before acting on account-specific data.