Privacy Policy
Effective date: 26 July 2026 Last updated: 26 July 2026
This policy explains what personal data Macroutine collects, why, who we share it with, and the control you have over it. We have tried to write it in plain language rather than legal boilerplate.
1. Who is responsible for your data
Macroutine, a service operated by Rayene Kanoun (an individual sole trader) based in Djerba, Houmt Souk, Tunisia, is the data controller for the personal data described here.
Contact us about anything in this policy at support@macroutine.app.
2. What we collect
2.1 Information you give us
| What | Examples | Why we need it |
|---|---|---|
| Identity & contact | Name, phone number, email address | To create your account, identify you at delivery, and contact you about your subscription |
| Health & dietary | Height, weight, date of birth, sex, activity level, goal, calorie target, macro preferences, allergies and intolerances | To calculate your nutrition targets and to plan and filter your meals |
| Delivery address | Street address, building/flat details, delivery notes, and the GPS coordinates of the pin you place | To deliver to you and to check the address is inside a zone we serve |
| Preferences | Favourite meals, meal ratings, ingredient removals, portion sizes, skipped days, language | To personalise your meal plan |
| Support | Messages you send us and any images you attach | To answer you and resolve issues |
2.2 Information collected automatically
| What | Why |
|---|---|
| Device push token (Expo/Firebase identifier), platform, device name | To send you delivery and account notifications |
| App version, device model, OS version | To diagnose crashes and support you |
| Crash reports and error diagnostics | To find and fix bugs |
| Usage events (screens viewed, key actions such as completing signup) | To understand where the app is confusing and improve it |
We do not collect your location in the background, we do not track you across other apps or websites, and we do not use advertising identifiers.
2.3 Sensitive data
Your allergies, body measurements and dietary goals are health-related data. We treat them as sensitive: they are used only to plan your meals and are never shared for marketing or sold to anyone.
We ask for this information because the service cannot work without it. You provide it, and you can change or remove it at any time in the app.
3. Why we process your data, and on what basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Planning, preparing and delivering your meals | Performance of a contract |
| Filtering meals against your allergies | Your explicit consent, given when you enter your allergies |
| Calculating nutrition targets from your body data | Your explicit consent, given when you enter your measurements |
| Sending delivery and account notifications | Performance of a contract |
| Sending marketing or promotional messages | Your consent — off unless you turn it on, withdrawable at any time |
| Answering support requests | Performance of a contract / legitimate interest |
| Diagnosing crashes and improving the app | Legitimate interest in a working product |
| Preventing fraud and abuse | Legitimate interest |
| Keeping records required by law | Legal obligation |
You can withdraw consent at any time by editing your data in the app, changing your notification settings, or deleting your account. Withdrawing consent for allergy or body data means we can no longer provide the service.
4. Notifications
We send two different kinds of message, and they are controlled separately:
- Service messages — your subscription was approved, your box locks tomorrow, a meal was substituted, a reply to your support request. These are part of the service. You can turn them off in the app or in your device settings, but you may then miss the chance to change an order before cutoff.
- Marketing messages — offers, referral rewards, seasonal promotions. These are off by default and only sent if you turn them on. You can turn them off again at any time in Settings → Notifications.
5. Who we share data with
We do not sell your personal data. We never share it for third-party advertising.
We share the minimum necessary with the following processors, who act on our instructions:
| Who | What they receive | Where | Why |
|---|---|---|---|
| Supabase (database, authentication, storage) | All account data | EU (Stockholm — eu-north-1) | Hosts our database and handles sign-in |
| Twilio (via Supabase Auth) | Your phone number | International | Sends your one-time sign-in codes |
| Expo (push notification relay) + Google Firebase Cloud Messaging | Device push token, notification content | USA | Delivers push notifications to your device |
| Google Maps Platform | Coordinates you look up | USA | Displays maps and resolves addresses |
| Resend | Your email address and email content | USA/EU | Sends transactional email |
| Sentry | Crash diagnostics, app version, device model, and your user ID | EU | Crash reporting |
| PostHog | Pseudonymous usage events and your user ID | EU | Product analytics |
| Telegram | A subscription reference number only — no name, address or contact details | International | Alerts our team that a request needs review |
We also share data with our own delivery staff — your name, address, phone number and delivery notes — so they can deliver to you.
We may disclose data if legally required, or to establish or defend legal claims.
International transfers
Some processors above store data outside Tunisia. Where that happens, we rely on the provider's contractual data protection commitments. You can ask us for details.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | While your account is open |
| After you request deletion | 30 days, then permanently deleted (see section 8) |
| Delivery and order records | Retained as long as required by Tunisian tax and accounting law, anonymised so they are no longer linked to you |
| Support conversations | 2 years after resolution |
| Crash and analytics data | 90 days |
| Push tokens | Deleted when you sign out, delete your account, or the token expires |
7. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate — most of it is directly editable in the app
- Delete your account and data (section 8)
- Object to or restrict processing based on legitimate interest
- Withdraw consent for allergy data, body data, or marketing
- Portability — receive your data in a machine-readable format
- Complain to the Tunisian data protection authority (INPDP)
To exercise any of these, email support@macroutine.app. We will respond within 30 days. We may need to verify your identity first.
8. Deleting your account
You can delete your account at any time:
- In the app — Profile → Help & legal → Delete my account
- Without the app — see our account deletion page
When you delete:
- Your subscription is cancelled immediately and future deliveries are removed.
- Push tokens and queued notifications are deleted immediately.
- Your account is deactivated and you are signed out — you cannot sign back in.
- After 30 days, your profile and all associated personal data are permanently deleted.
The 30-day window exists so an accidental deletion can be reversed by contacting support, and so any outstanding payment can be resolved. Records we are legally obliged to keep are anonymised rather than deleted.
9. Security
We protect your data with: encryption in transit (HTTPS/TLS everywhere); row-level database security so one user's data is inaccessible to another; one-time-code sign-in with no stored passwords; and restricted, role-based staff access.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
10. Children
Macroutine is not intended for anyone under 16 and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us at support@macroutine.app and we will delete it.
11. Cookies
The Macroutine mobile app does not use cookies. It stores your sign-in session locally on your device so you stay logged in; this is required for the app to work and is deleted when you sign out.
If you use a web version of Macroutine, it stores the same sign-in session in browser local storage. This is strictly necessary and is not used for tracking or advertising.
12. Changes to this policy
We may update this policy. If a change materially affects how we use your data, we will notify you in the app before it takes effect. The "last updated" date at the top always reflects the current version.
13. Contact
Macroutine — operated by Rayene Kanoun Djerba, Houmt Souk, Tunisia Email: support@macroutine.app Phone: +216 28432711
If you are unhappy with how we handle your data, you may complain to the Instance Nationale de Protection des Données Personnelles (INPDP), Tunisia.