Privacy Policy

Effective date: 26 July 2026 Last updated: 26 July 2026

This policy explains what personal data Macroutine collects, why, who we share it with, and the control you have over it. We have tried to write it in plain language rather than legal boilerplate.


1. Who is responsible for your data

Macroutine, a service operated by Rayene Kanoun (an individual sole trader) based in Djerba, Houmt Souk, Tunisia, is the data controller for the personal data described here.

Contact us about anything in this policy at support@macroutine.app.

2. What we collect

2.1 Information you give us

WhatExamplesWhy we need it
Identity & contactName, phone number, email addressTo create your account, identify you at delivery, and contact you about your subscription
Health & dietaryHeight, weight, date of birth, sex, activity level, goal, calorie target, macro preferences, allergies and intolerancesTo calculate your nutrition targets and to plan and filter your meals
Delivery addressStreet address, building/flat details, delivery notes, and the GPS coordinates of the pin you placeTo deliver to you and to check the address is inside a zone we serve
PreferencesFavourite meals, meal ratings, ingredient removals, portion sizes, skipped days, languageTo personalise your meal plan
SupportMessages you send us and any images you attachTo answer you and resolve issues

2.2 Information collected automatically

WhatWhy
Device push token (Expo/Firebase identifier), platform, device nameTo send you delivery and account notifications
App version, device model, OS versionTo diagnose crashes and support you
Crash reports and error diagnosticsTo find and fix bugs
Usage events (screens viewed, key actions such as completing signup)To understand where the app is confusing and improve it

We do not collect your location in the background, we do not track you across other apps or websites, and we do not use advertising identifiers.

2.3 Sensitive data

Your allergies, body measurements and dietary goals are health-related data. We treat them as sensitive: they are used only to plan your meals and are never shared for marketing or sold to anyone.

We ask for this information because the service cannot work without it. You provide it, and you can change or remove it at any time in the app.

3. Why we process your data, and on what basis

PurposeLegal basis
Creating and running your accountPerformance of a contract
Planning, preparing and delivering your mealsPerformance of a contract
Filtering meals against your allergiesYour explicit consent, given when you enter your allergies
Calculating nutrition targets from your body dataYour explicit consent, given when you enter your measurements
Sending delivery and account notificationsPerformance of a contract
Sending marketing or promotional messagesYour consent — off unless you turn it on, withdrawable at any time
Answering support requestsPerformance of a contract / legitimate interest
Diagnosing crashes and improving the appLegitimate interest in a working product
Preventing fraud and abuseLegitimate interest
Keeping records required by lawLegal obligation

You can withdraw consent at any time by editing your data in the app, changing your notification settings, or deleting your account. Withdrawing consent for allergy or body data means we can no longer provide the service.

4. Notifications

We send two different kinds of message, and they are controlled separately:

5. Who we share data with

We do not sell your personal data. We never share it for third-party advertising.

We share the minimum necessary with the following processors, who act on our instructions:

WhoWhat they receiveWhereWhy
Supabase (database, authentication, storage)All account dataEU (Stockholm — eu-north-1)Hosts our database and handles sign-in
Twilio (via Supabase Auth)Your phone numberInternationalSends your one-time sign-in codes
Expo (push notification relay) + Google Firebase Cloud MessagingDevice push token, notification contentUSADelivers push notifications to your device
Google Maps PlatformCoordinates you look upUSADisplays maps and resolves addresses
ResendYour email address and email contentUSA/EUSends transactional email
SentryCrash diagnostics, app version, device model, and your user IDEUCrash reporting
PostHogPseudonymous usage events and your user IDEUProduct analytics
TelegramA subscription reference number only — no name, address or contact detailsInternationalAlerts our team that a request needs review

We also share data with our own delivery staff — your name, address, phone number and delivery notes — so they can deliver to you.

We may disclose data if legally required, or to establish or defend legal claims.

International transfers

Some processors above store data outside Tunisia. Where that happens, we rely on the provider's contractual data protection commitments. You can ask us for details.

6. How long we keep data

DataRetention
Account and profile dataWhile your account is open
After you request deletion30 days, then permanently deleted (see section 8)
Delivery and order recordsRetained as long as required by Tunisian tax and accounting law, anonymised so they are no longer linked to you
Support conversations2 years after resolution
Crash and analytics data90 days
Push tokensDeleted when you sign out, delete your account, or the token expires

7. Your rights

You have the right to:

To exercise any of these, email support@macroutine.app. We will respond within 30 days. We may need to verify your identity first.

8. Deleting your account

You can delete your account at any time:

When you delete:

  1. Your subscription is cancelled immediately and future deliveries are removed.
  2. Push tokens and queued notifications are deleted immediately.
  3. Your account is deactivated and you are signed out — you cannot sign back in.
  4. After 30 days, your profile and all associated personal data are permanently deleted.

The 30-day window exists so an accidental deletion can be reversed by contacting support, and so any outstanding payment can be resolved. Records we are legally obliged to keep are anonymised rather than deleted.

9. Security

We protect your data with: encryption in transit (HTTPS/TLS everywhere); row-level database security so one user's data is inaccessible to another; one-time-code sign-in with no stored passwords; and restricted, role-based staff access.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.

10. Children

Macroutine is not intended for anyone under 16 and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us at support@macroutine.app and we will delete it.

11. Cookies

The Macroutine mobile app does not use cookies. It stores your sign-in session locally on your device so you stay logged in; this is required for the app to work and is deleted when you sign out.

If you use a web version of Macroutine, it stores the same sign-in session in browser local storage. This is strictly necessary and is not used for tracking or advertising.

12. Changes to this policy

We may update this policy. If a change materially affects how we use your data, we will notify you in the app before it takes effect. The "last updated" date at the top always reflects the current version.

13. Contact

Macroutine — operated by Rayene Kanoun Djerba, Houmt Souk, Tunisia Email: support@macroutine.app Phone: +216 28432711

If you are unhappy with how we handle your data, you may complain to the Instance Nationale de Protection des Données Personnelles (INPDP), Tunisia.