Who controls your data
CoreN Digital Ltd. is responsible for personal data processed through CoreMacros. This policy applies to the CoreMacros mobile app, website, support channels, and related services.
Data we collect
We collect only the information needed to provide, secure, and improve the product.
- Account and profile data, such as email, display name, birth year, body measurements, units, goals, and app preferences.
- Nutrition and wellness data, including macro targets, dietary preferences, allergies, meal and weight logs, custom foods, saved meals, challenge progress, and coaching history.
- Photos you choose for meal analysis, camera or library permissions, barcode values, and any corrections you submit.
- Subscription status, app interactions, device diagnostics, crash and performance data, and push-notification identifiers.
How we use data
- Provide your account, meal log, targets, history, coaching, recipes, challenges, and progress features.
- Personalize nutrition estimates and suggestions using the information you choose to provide.
- Process subscriptions, restore purchases, enforce feature limits, and provide customer support.
- Protect the service, prevent abuse, diagnose failures, and understand which product experiences need improvement.
- Meet legal obligations and establish, exercise, or defend legal claims.
AI meal analysis and coach
When you request an AI feature, CoreMacros may send the meal photo or text you submitted together with limited nutrition context—such as targets, recent logs, dietary preference, allergies, and training context—to OpenAI. AI output is generated automatically and can be incomplete or inaccurate. Always review food, portion, and allergen information before relying on it. OpenAI API data is not used to train OpenAI models by default unless the customer opts in, subject to OpenAI’s platform policies.
Apple Health
Apple Health integration is optional. CoreMacros currently writes the calories, protein, carbohydrates, and fat from meals you log when you enable sync; it does not import Apple Health data. Turning sync off stops future writes. Records already written to Apple Health must be managed in Apple Health. We never use connected health data for advertising or data brokerage.
Service providers and sharing
We share limited data only when needed to operate CoreMacros. Providers may include Supabase for authentication, databases, and storage; OpenAI for AI features you request; Amplitude for product analytics; Google Analytics for optional website analytics; Sentry for diagnostics; OneSignal for notifications; RevenueCat and Apple or Google for subscriptions; and food-data providers for barcode results. We may also disclose data when legally required or as part of a business transaction with appropriate safeguards.
Website analytics and cookies
With your consent, the CoreMacros website uses Google Analytics to understand visits and improve the site. This may include pages viewed, approximate location, referring site, browser and device information, and interactions with key links. We do not enable advertising storage or personalization. You can decline optional analytics or change your choice through Cookie preferences in the website footer.
What we do not do
- We do not sell personal data.
- We do not use meal, body, allergy, or Apple Health data for third-party advertising.
- We do not share personal data with data brokers or use it for cross-app behavioral tracking.
- Analytics events are designed not to include raw meal text, barcode values, photo paths, or direct account identifiers.
Legal bases and international transfers
Depending on your location, we process data to perform our contract with you, with your consent for optional permissions, for legitimate interests such as security and product quality, and to meet legal obligations. CoreN Digital Ltd. and its providers may process data outside your country. Where required, we rely on recognized safeguards such as adequacy decisions, the UK IDTA or Addendum, and EU Standard Contractual Clauses.
Retention and security
We retain account and nutrition data while your account is active and as reasonably needed for support, security, and legal obligations. Meal photos and related analysis records are removed when their associated data is deleted, subject to short backup and operational retention cycles. Billing, audit, analytics, and diagnostic records may be retained for the period required by law or legitimate operational need. We use encrypted transport, secure authentication, row-level database controls, and private signed media access, but no system can guarantee absolute security.
Your choices and rights
You can correct profile and nutrition information, manage optional permissions, and delete your account from Settings. Depending on applicable law—including UK GDPR, EU GDPR, KVKK, and similar laws—you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a regulator. We may need to verify your identity before completing a formal request. Contact hello@corendigital.com for a privacy or data-rights request.
Children
CoreMacros is not intended for children under 16. We do not knowingly collect personal data from children under 16. Contact us if you believe a child has provided personal data so we can take appropriate action.
Updates and questions
We may update this policy as CoreMacros evolves. Material changes will be reflected by a new effective date and may also be communicated in the app or by email. For privacy questions, data-rights requests, or complaints, email hello@corendigital.com.