MakroFit MASW Engineering S.R.L.

Legal record

Privacy Policy

Review status: this text is a release candidate prepared from the application's implemented data flows. It has not yet been confirmed by qualified Romanian/EU counsel and is published here for transparency, not as a final legally approved policy.

Effective date
Controller MASW Engineering S.R.L.
Applies to MakroFit mobile application

1Who we are and scope

This policy explains how MASW Engineering S.R.L. (“MASW”, “we”, “us”) processes personal data when you use the MakroFit mobile application and contact us about it.

The controller is MASW Engineering S.R.L., Str. Pictor Dimitrie Hîrlescu, Bl. 3, Sc. B, Ap. 12, Fălticeni, Suceava County, Romania, CUI 49634604. Privacy enquiries may be sent to info@ma-swengineering.com.

2Data we process

Depending on the features you use, we process:

  • account and authentication data, principally your email address, account identifier, authentication tokens and security logs;
  • profile and nutrition data, including age, biological sex used for the selected metabolic formula, height, weight, activity level, goal, calculated calorie and macronutrient targets, and target weight;
  • food-log data, including foods, portions, meal types, timestamps, calories and macronutrients;
  • weight history and notification preferences;
  • if you use the fasting feature, fasting sessions (when a fast started and ended, its target duration, and whether it was started by you or opened by a plan) and fasting plans (the daily start and end times of your eating window, the chosen interval and whether it repeats);
  • technical and operational data needed to secure, diagnose and rate-limit the service;
  • barcode values and product information returned by, or contributed following a miss from, Open Food Facts;
  • if you choose an AI feature, a food description or food photo, model output and related technical request data; and
  • if you report an AI estimate, the reported estimate, your account identifier and submission time.

Nutrition, weight, fasting and activity information may reveal information concerning health and is treated as special-category data where Article 9 GDPR applies. Fasting times describe eating behaviour and are treated the same way as food-log and weight data for this purpose.

MakroFit does not sell personal data, serve advertising or include third-party analytics SDKs.

3Why we process data and our legal bases

Article 6(1)(b) GDPR may support processing account, profile, goal, food-log, weight and preference data needed to provide the service you request. Information concerning health also requires a separate Article 9 condition. MakroFit does not currently provide a GDPR-specific Article 9 consent and withdrawal mechanism. The applicable Article 9 condition and any required granular, informed consent and withdrawal controls must be approved and implemented before special-category processing is released.

The candidate purpose-and-basis analysis, which remains subject to counsel confirmation, is:

  • processing a barcode to perform the requested product lookup, and processing an AI description or photo to return a requested estimate, may be necessary to provide that requested function under Article 6(1)(b);
  • maintaining shared product and AI-estimate caches may be based on Article 6(1)(f), for the legitimate interests of reducing provider requests, latency and operating cost;
  • receiving and reviewing an account-linked AI estimate report may be based on Article 6(1)(f), for the legitimate interests of identifying inaccurate or inappropriate output and improving service safety;
  • security, abuse prevention, troubleshooting and service integrity may be based on Article 6(1)(f); and
  • processing needed to meet a legal obligation may be based on Article 6(1)(c).

You may object to processing based on legitimate interests as explained in section 12. A text query, photo or report may itself reveal health information; if so, an Article 6 basis alone is insufficient and a separate approved Article 9 condition is required. Health-platform permission is an operating-system access control and is not, by itself, a determination that GDPR consent requirements have been satisfied.

We do not use automated decision-making that produces legal or similarly significant effects. Nutrition calculations and AI outputs are estimates for your review.

4Information you must or may choose to provide

To create and use an authenticated MakroFit account, you must provide an email address for passwordless sign-in. Without it, MakroFit cannot create or authenticate your account or provide server synchronisation.

To complete the current onboarding flow and create your personal nutrition goal, you must provide the minimum inputs accepted by the app: age, biological sex for the metabolic formula, height, current weight, a daily-step baseline used to derive activity level, and a goal type. You must also provide a target weight when you choose a weight-loss or weight-gain goal. If you withhold a required input, onboarding cannot be completed and MakroFit cannot calculate or create that personal goal.

Authentication, technical and security data arise when you use the authenticated service and are necessary to operate, protect and troubleshoot it. If those data cannot be processed, authenticated or synchronised functions may not work.

Food-log entries, weight-history entries, notification preferences, barcode scans, AI descriptions, AI photos, AI estimate reports, fasting sessions and plans, and Health permissions and data are voluntary and feature-specific. You can withhold them. Doing so means MakroFit cannot provide the corresponding log or history, reminder settings, lookup, AI estimate or report, fasting tracker, or activity-based suggestion, but does not by itself prevent use of other available core functions for which you supplied the required account and onboarding data.

No personal data used in ordinary MakroFit use is required by statute unless we separately tell you that it is needed to comply with a specific legal request or obligation. Whether the required and optional mapping, and its contractual or legal characterization, is correct must be confirmed before this policy is published.

5Accounts, storage and synchronisation

MakroFit uses passwordless email authentication. Supabase provides authentication, database, Edge Function and synchronisation infrastructure. Profile, nutrition-goal, food-log, weight, notification-preference, fasting-session, fasting-plan and account-linked AI-report data can be stored in Supabase and synchronised across signed-in devices.

MakroFit also stores data on your device so entries can be created and used offline. This includes a local SQLite database for food entries and local preferences. Device operating systems may include app data in device backups according to your device and backup settings.

6Optional health-platform data

MakroFit offers an optional, read-only integration with Apple Health on iOS and Health Connect on Android. It is off until you enable it: you connect it yourself from the activity card in the app, and connecting is recorded per MakroFit account, so signing in with a different account on the same device starts disconnected even though the operating-system permission persists on that device. When enabled, MakroFit reads only active-energy, total-energy, step, distance and workout data for which you grant permission. Raw activity records are cached only on your device and are not written by MakroFit to Supabase. MakroFit does not write data to Apple Health or Health Connect.

MakroFit may use that local activity data to suggest a derived nutrition-goal adjustment. Only an adjustment you explicitly confirm may be synchronised to Supabase as part of your nutrition-goal history.

You can withdraw this at any time, and as easily as you gave it: in the app, open Profile and tap Disconnect under “Activity & Health”. That stops MakroFit reading your activity and deletes the activity data cached on that device for your account, without leaving the app. You can additionally revoke the underlying permission at the operating-system level in Health Connect or the Health app. Core manual food logging remains available either way.

Apple and Google govern their respective platforms. See Apple’s privacy information and Health Connect information.

7Barcode lookup

When you scan a barcode, MakroFit checks its product cache and may send the barcode to the community-maintained Open Food Facts service. Returned product and nutrition information may be cached to improve later lookups. Open Food Facts data can be incomplete or inaccurate; see its privacy policy.

8Optional AI estimation

If you choose text or photo estimation, MakroFit sends the submitted description or photo through a Supabase Edge Function to OpenRouter. OpenRouter routes the request to a selected model provider. Provider selection and provider practices can vary. MakroFit’s current requests do not enforce OpenRouter’s Zero Data Retention setting, so neither OpenRouter nor the routed model provider should be assumed to process every input transiently or without retention. Review OpenRouter’s privacy policy and provider-logging guide for its current terms.

MakroFit does not store submitted photo bytes in its application database. A normalized version of a text query and the returned nutrition estimate may be stored in the server-side ai_food_estimate_cache. That cache is shared across queries, contains no MakroFit user identifier, and currently has no automatic expiry period. An AI estimate you apply to a food entry becomes part of that account-linked entry. Reports of inaccurate or inappropriate estimates are account-linked and retained for review.

Do not include names, contact details or other unnecessary personal information in an AI food description or photo.

9Recipients, processors and transfers

We disclose data only as needed to operate MakroFit, comply with law, protect rights and security, or complete a corporate transaction subject to appropriate safeguards. Service providers may include:

  • Supabase, for authentication, hosted database, server functions and synchronisation;
  • OpenRouter and the model provider it routes to, when you use an optional AI feature;
  • Open Food Facts, when an external barcode lookup is required; and
  • Apple or Google as platform providers when you use their operating systems, backup services or optional health stores.

These providers may use subprocessors and may process data outside Romania or the European Economic Area. Before enabling a feature that makes such a transfer, MASW must verify the production locations and contracts and, where required, put an applicable transfer mechanism and supplementary safeguards in place. The mechanism and safeguards depend on the verified production configuration and provider terms and must be confirmed before the relevant transfer occurs. Provider documentation includes the Supabase Data Processing Addendum and OpenRouter links above.

10Retention and deletion

We retain account-linked data while your account is active and afterwards only as needed for the purposes described here, legal obligations, dispute handling, security and backups. Retention depends on the data type and applicable provider configuration. AI text-cache entries currently have no automatic expiry and are not linked to a user identifier.

You can delete your account in the app, under Profile, and you can also request deletion on this website without installing it. Deletion removes the server-side account and the account-linked application data that hangs off it, including your profile, nutrition goals, food log, weight history, notification preferences, fasting sessions and plans, and AI estimate reports — subject to temporary residual copies in provider backups and data we must retain by law.

Deleting the account from the app additionally erases that account’s data held on the device itself: its local food entries, including entries not yet synchronised, its cached activity data, and its record of the health-platform connection. Data belonging to other accounts on the same device is left untouched. Signing out deliberately does less — it clears the device-scoped activity data and connection but keeps your local food entries, because an entry that has not synchronised yet exists only on that device and you would expect to find it again after signing back in. To remove every trace of the app from a device, clear MakroFit’s app data or uninstall it; manage operating-system backups separately through your platform settings.

Because the shared AI text cache has no user identifier, account deletion does not automatically identify or delete a cache entry derived from your query. Contact us if you believe a cached query contains personal data.

11Security

We use technical and organisational safeguards appropriate to the risk, including authenticated access, database row-level access controls, encrypted transport and restricted server credentials. No system is completely secure. Protect access to your email account and device, and contact us if you suspect misuse.

12Your rights

Subject to GDPR conditions and exceptions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing lawfully relies on your consent, you may withdraw that consent at any time without affecting earlier lawful processing. You may lodge a complaint with a supervisory authority. Contact us at info@ma-swengineering.com; we may need to verify your identity.

In Romania, you may complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP). Its complaints page explains the procedure. You may also contact the authority in the EU or EEA country of your habitual residence, workplace or the alleged infringement.

13Children

MakroFit is intended only for people aged 16 or older. We do not knowingly offer it to or collect data from children under 16. If you believe a child under 16 has provided data, contact us so we can investigate and delete it where required.

14Changes

We may update this policy when MakroFit, its providers or legal requirements change. We will publish the revised policy with a new effective date and provide additional notice where required. Material changes will not retroactively reduce your rights.

15Contact

MASW Engineering S.R.L.
Str. Pictor Dimitrie Hîrlescu, Bl. 3, Sc. B, Ap. 12
Fălticeni, Suceava County, Romania
CUI 49634604
info@ma-swengineering.com