Privacy

Macro Tracker Privacy Policy

This general policy describes how the Macro Tracker website, private nutrition ledger, global food catalog, API, and connected plugin tools handle personal information.

Last updated August 12, 2026

Consumer health data

Nutrition information linked to your account may be consumer health data. The separate, specific Consumer Health Data Privacy Policy discloses the health-data categories Macro Tracker collects and why, their sources, the categories disclosed and their recipients, and how to exercise your consumer health data rights. That notice is separate from this general privacy policy.

Other personal information

  • Account and security: name, email address, verification state, a one-way password verifier rather than your readable password, sessions, password-reset records, OAuth clients, consents, grants, and revocation state.
  • Operations: redacted route shape, response status, duration, rate-limit keys, random request or workflow identifiers, idempotency state, and security events needed to run and protect the service.
  • Global catalog records: food identity, immutable nutrition versions, source classifications, and provenance. Catalog versions are not linked to the account that created them. Other users do not receive your private intake, goals, aliases, saved records, or reports.
  • Authenticated ingredient directory: sanitized normalized ingredient identity such as name and brand, primary serving basis, source-quality classification, and nutrient values from the global catalog. The directory excludes private foods and intake, usage, private aliases, and source references.

Sources of information

  • You, when you create an account or use the website, API, or a connected plugin.
  • A connected host such as ChatGPT or Codex, when it sends the arguments for the tool you chose and returns that tool's result to you.
  • Other users, when they submit food facts to the global catalog.
  • USDA FoodData Central for public food facts returned from a food search, and Macro Tracker's server calculations for derived totals and reports.
  • Your browser and Cloudflare's network for limited request, device, and security data created while operating the service.

Why and how information is processed

  • Authenticate you, protect the service, and enforce private account boundaries.
  • Resolve and record the nutrition actions you request; preserve revisions, sources, and uncertainty; and calculate authoritative totals and reports.
  • Remember your settings and saved records, deduplicate global food submissions, and keep connected-host access scoped and revocable.
  • Deliver verification and password-reset messages, prevent duplicate writes, respond to errors, and maintain backups and service reliability.
  • Comply with law and investigate fraud, abuse, security incidents, or data breaches.

Macro Tracker does not sell personal or consumer health data, serve advertising, or use private nutrition records to train machine-learning models. It will not add a new health data category, recipient, or purpose without updating this notice and obtaining consent when applicable law requires it.

What is disclosed, and to whom

  • Cloudflare: account, nutrition, catalog, and limited operations data as needed to provide hosting, database, rate-limiting, logging, backup-recovery, security, and transactional email services. Cloudflare acts as Macro Tracker's infrastructure processor.
  • GitHub: an independently encrypted production-database backup artifact when the optional scheduled backup is enabled. GitHub hosts the encrypted artifact and workflow metadata for up to 90 days; the decryption identity is kept outside GitHub.
  • A host you connect: the pseudonymous account subject identifier needed to bind its OAuth grant. The host also receives the nutrition fields, derived report results, receipts, and account-scoped status needed to complete the tool call you requested. Macro Tracker does not grant the host your name, profile, or email through OAuth. The host's own privacy terms govern its copy of the conversation, account identifier, and tool result.
  • USDA FoodData Central: a narrow food-search query when public food matching is needed. Macro Tracker does not send your account identity, private ledger, or report to USDA.
  • Other authenticated Macro Tracker users: the sanitized ingredient directory described above, drawn from the global catalog. It does not disclose private foods or intake, usage, private aliases, or source references. Source quality and normalized nutrition facts may be visible.
  • Authorities or a successor: only when legally required, needed to protect rights and safety, or part of a lawful reorganization in which the recipient assumes this policy's obligations.

No affiliate currently receives consumer health data. Macro Tracker does not embed ad networks or cross-site analytics. A host you intentionally connect may retain tool inputs and results over time alongside your activity on that host; consult that host's privacy settings before connecting it.

Nutrition Facts images

Nutrition Facts images remain in the connected host. The host may transcribe clearly printed nutrition values, but Macro Tracker receives only the structured fields needed for the requested write. It does not receive or store the image, image bytes, file identifier, URL, or raw text dump.

Sale and geofencing

Macro Tracker does not sell personal or consumer health data for money or other valuable consideration. If that practice ever changes, Macro Tracker will first obtain a separate, legally valid authorization that satisfies applicable consumer health data law. Providing the service will not be conditioned on signing an authorization to sell consumer health data.

Macro Tracker does not implement a geofence around an entity that provides in-person health care services to identify or track consumers, collect consumer health data, or send health-related notifications, messages, or advertisements.

Researched intake

When a logging request identifies a food through USDA, a Nutrition Facts label, or corroborated public research, its facts automatically reuse or enter the shared catalog as an immutable provenance-labeled version. Exact facts reuse their existing provenance; new USDA, label, and researched facts retain their source classification. Unidentified labels and complete unconfirmed facts you explicitly supply remain private.

If Macro Tracker's catalog and USDA search cannot resolve a food, a connected host may research public web sources only when you ask it to log that food. The host sends Macro Tracker the structured food name, nutrition basis and nutrients, consumed amount, quantity-quality flag, and the titles and public HTTPS URLs of the sources it cross-checked. For a newly created shared version, Macro Tracker stores that source metadata with the catalog facts; exact-version reuse preserves the existing provenance instead. The server does not open, fetch, publish to, or otherwise contact those URLs.

A researched intake is private and marked as estimated. Its corroborated food facts reuse or enter the shared catalog as an immutable provenance-labeled version. Later corrections do not rewrite the intake's original facts. The connected host and source sites govern any web access and copies they handle outside Macro Tracker. Review the sources, serving basis, quantity, and estimate before relying on the record.

Retention

  • Account and current nutrition records are kept while your account exists so your tracker, settings, reports, and correction controls remain available.
  • MCP and API OAuth access tokens expire after one hour, with refresh tokens expiring after 30 days. Every token is checked against its active session, client, and revocation record on each request and may stop working sooner. A connected host may periodically ask you to authorize it again.
  • Sampled Cloudflare Workers logs are kept for no more than seven days. Request logging is designed to omit raw meal text, credentials, access tokens, reset tokens, and full label payloads.
  • The production database is recoverable through Cloudflare D1 point-in-time recovery. Independently encrypted backup artifacts, when enabled, expire after 90 days. These recovery copies are not used for ordinary product processing.

Your privacy choices

Use the authenticated controls below to manage your account and connected services. For the rights that apply specifically to consumer health data—including confirmation, access, recipient information, withdrawal, deletion, and appeals—read the Consumer Health Data Privacy Policy.

  • Use authenticated Settings to export your account or review active agent connections.
  • Correct an intake with the correction tools. The current entry is replaced atomically, while its nutrition sources and assumptions remain attached. Update goals in Goals and preferences in Settings.
  • Stop future host disclosure by revoking or disconnecting Macro Tracker in that host. Macro Tracker performs no background nutrition collection; stop sending tool requests to stop new collection while keeping your existing account.
  • If you cannot use the authenticated controls or have a general privacy request, email privacy@jpamorgan.com from your account address when possible. Put only the request type in the first message; Macro Tracker will reply with identity-verification steps.

Young users

Macro Tracker is intended for people age 13 and older and is not directed to children under 13. If you are under the age of legal majority where you live, use the service only with permission from a parent or legal guardian. Macro Tracker does not ask for a birth date; creating an account is your representation that you meet these requirements.

If Macro Tracker learns that it collected personal or consumer health data from a child under 13, it will take reasonable steps to delete that data. A parent or guardian can use the contact method below without placing the child's information in a public report.

Security, incidents, and changes

Macro Tracker uses HTTPS, scoped OAuth permissions, PKCE where the connected client supports it, account-scoped authorization, revocable sessions, rate limits, redacted logs, and private-by-default records. Access to consumer health data is limited to what is needed to operate the requested service. No internet service can promise perfect security.

If an incident triggers a legal notification duty, Macro Tracker will notify affected people and regulators as required. Material policy changes will be posted here with a new effective date and, when required, shown to affected account holders before new collection or disclosure begins.

Contact

Macro Tracker is operated by John Philip Morgan. For general privacy questions or parental requests, email privacy@jpamorgan.com. Consumer health data requests and appeals use the same address and are described in the separate Consumer Health Data Privacy Policy. Never send passwords, OAuth tokens, reset tokens, Nutrition Facts images, or a full meal history. Macro Tracker may ask you to verify control of the account email before disclosing, correcting, or deleting account-specific information.