Privacy Policy
Last updated: October 1, 2026
This Privacy Policy explains what personal information Speed Macros collects, how we use and share it, how long we keep it, and the choices and rights you have. It applies to the Speed Macros website, web app, and iOS and Android apps (together, the "Service"). The Service accepts new accounts only from the United States, the United Kingdom, Canada (except Québec, where new signups are currently paused), Australia, New Zealand, Singapore, and South Africa. We use a network-based country signal to check availability at sign-up; it can be inaccurate and does not verify where you live. Availability rules do not remove any rights you have under the law that applies to you.
Health information has its own standalone policy: our Consumer Health Data Privacy Policy. If the two policies differ on consumer health data, the Consumer Health Data Privacy Policy controls.
In short: we collect what you enter to track your nutrition, training, and body metrics; we send a submission to our AI provider only if you turn on AI sharing and ask for an AI feature; we do not sell your information, use it for advertising, or use third-party analytics or ad trackers; and you can export your data or delete your account in the app.
1. Who We Are and How to Contact Us
Speed Macros is operated by Aariz Noorani, an individual doing business as Speed Macros ("Speed Macros", "we", "us"), based in the State of Georgia, United States. We are the controller (or "responsible party" or "organization", depending on local law) of the personal information described in this policy.
Privacy contact: nooraniaaariz@gmail.com. Our designated privacy contact is Aariz Noorani. This person serves as our privacy officer and as the accountable individual under Canada's PIPEDA, the person in charge of the protection of personal information under Québec law, our Data Protection Officer under Singapore's PDPA, and our Information Officer under South Africa's POPIA. Section 16 explains how UK users can contact us.
2. Information We Collect
Information you give us
- Account information: your email address and an internal account identifier. You can sign in with an emailed link or one-time code or, where enabled, with Google or Apple.
- Profile information: sex, birth date, height, current and target weight, current and target body-fat percentage and how you measured it, activity level, training frequency and cardio type, goal, units preference, time zone, food allergens, supplements you are open to, and, if you choose them, dietary preferences (for example halal, kosher, vegetarian, or intolerances) and a rough daily outdoor-time range.
- Health and fitness records: food and drink logs (descriptions, portions, nutrients, water intake), saved recipes, remembered ingredients you have confirmed before, weigh-ins and body measurements (such as waist, neck, and hip), sleep hours and notes you log, workout sessions, exercises, and sets, bloodwork values you save with any notes, and progress check-in photos and videos you upload. Your calculated nutrition targets and daily summaries are derived from these records.
- Images and text you submit for AI features: food photos, nutrition-label photos, bloodwork-report photos, and descriptions you type. See Section 5.
- Consent records: the dates you accepted the Terms, gave health-data consent, gave or withdrew AI-sharing consent, acknowledged the health disclaimer, and completed onboarding or the product tour.
- Purchase and subscription information: if you buy credit packs or subscribe to Speed Macros Plus, we store your credit balances, the Stripe customer and subscription identifiers, plan, status, trial and renewal dates, and the time you agreed to automatic renewal. Stripe collects your payment card and billing details directly. We never receive or store your full card number.
- Referral information: if the referral program is available to you, your referral code, any code you used to sign up, and the resulting reward records.
- Feedback: messages you send using "Send a suggestion or feedback" in Settings, linked to your account.
- Messages to us: anything you include when you email us.
Information collected automatically
- Usage and billing records: the number of AI requests you make each day and, for each AI request, the feature used, the AI model, token counts, and credits charged; also the number of checkout attempts each day. We use these to enforce fair-use limits, bill credits accurately, and prevent abuse.
- Network and security information: our hosting, authentication, and email providers receive technical request data such as IP address, browser and device headers, request times, and sign-in events. We read a country signal derived from your IP address at login and sign-up to enforce regional availability. We do not store that signal in your profile.
- Cookies and on-device storage: see Section 8.
We do not collect precise location, contacts, or data from Health Connect or wearables. We collect data from Apple Health only if you turn on the optional Apple Health link in our iPhone app (Section 3A). We do not use advertising identifiers, third-party analytics, tracking pixels, or advertising SDKs.
3. Where Information Comes From
Almost all information comes directly from you. Some information is generated by the Service from what you provide: calculated targets, daily summaries, and AI-generated nutrition or bloodwork estimates that you review before saving. We also receive limited information from service providers: sign-in confirmation from Google or Apple if you use them, payment and subscription status from Stripe, and the network country signal from our hosting provider. If you turn on the optional Apple Health link in our iPhone app, we also receive the weight and body-fat measurements you allow from Apple Health (Section 3A). When you name a restaurant or packaged food, we look up its published nutrition facts on MyFoodDiary. Only the food name is used in that lookup.
3A. Apple Health (iPhone app only, optional)
If you turn on Connect Apple Health in Settings in our iPhone app, and allow it in Apple's permission screen, we:
- Read your weight and body-fat percentage from Apple Health. We use them only to fill in days on which you have not logged a weigh-in yourself (your own entries are never overwritten), and they are stored in your Speed Macros account like any other weigh-in, where they count toward your weekly target recalibration.
- Write each day's logged calories, protein, carbohydrate, fat, fiber, and water to Apple Health, so they appear in your Health app. Changing a day's log updates that day's entry.
Information from Apple Health (HealthKit) is used only to provide these tracking features to you. We never use it for advertising or marketing, never sell it, never use it for data mining or profiling, never send it to our AI provider or include it in AI requests, and never share it with anyone except the service providers that store and run the Service for us under contract (Section 6). We do not store it in iCloud. You can choose exactly which types to share in Apple's permission screen, turn the link off in Settings at any time, and remove our access in the Health app (Profile, then Apps, then Speed Macros). Turning the link off stops future syncing; weigh-ins already imported stay in your account until you delete them or your account. Data we wrote to Apple Health stays in your Health app under Apple's control and can be deleted there.
4. How We Use Information
- Providing the Service: creating your account, calculating nutrition, macro, and micronutrient targets, recording your logs, and showing your trends. Legal basis where required: performance of our contract with you, and your explicit consent for health information.
- AI features, if you turn them on: producing estimates from the photos and text you submit and, if offered, answering AI Nutrition Chat questions. Legal basis: your explicit consent.
- Payments, credits, and subscriptions: processing purchases, granting and deducting credits, managing renewals and cancellations, and meeting tax and accounting obligations. Legal basis: contract and legal obligation.
- Referral rewards: applying signup bonuses and referrer rewards. Legal basis: contract.
- Security, fair use, and abuse prevention: enforcing daily limits, rate-limiting checkout and feedback, regional availability checks, troubleshooting, and protecting accounts. Legal basis: our legitimate interest in keeping the Service secure and available, and legal obligation.
- Communicating with you: sign-in emails, service and billing notices, responses to feedback and requests, and notice of material policy changes. Legal basis: contract and legitimate interest.
- Legal compliance: responding to lawful requests, enforcing our Terms, and establishing or defending legal claims.
We do not use your information for advertising, marketing profiles, or cross-context behavioral advertising. We do not use it to make decisions that produce legal or similarly significant effects about you. AI output in Speed Macros is an estimate you review, edit, or discard. The AI never sets or changes your nutrition targets. We do not use your personal information to train AI models, and neither does our AI provider (Section 5).
5. AI Processing (Anthropic)
Speed Macros's AI features use Anthropic's Claude models. Before any of your submissions go to Anthropic, you must give a separate, optional consent to AI sharing, distinct from accepting the Terms and this Policy. You can leave it off and use manual entry, and you can turn it off at any time in Settings, under Legal & Privacy. Turning it off stops future AI requests. It does not undo requests already processed.
When you request an AI feature with AI sharing on, Anthropic receives only what that request needs:
- Food estimates and edits: your description and any food photo, plus supporting context such as your allergens, dietary preferences, and ingredients you have confirmed before.
- Label scans: the label photo and the amount you ate.
- Bloodwork scans: the lab-report photo. Lab reports often show your name, date of birth, and other identifiers. Crop or cover those before scanning, and do not upload someone else's report unless you are authorized to.
- AI Nutrition Chat, where offered: your messages and, only if you tick the option to include it, a summary of your age, sex, weight, allergens, halal preference, supplements you are open to, recent intake, and saved targets, as described in the chat's information panel.
We do not intentionally send your email address or account identifier to Anthropic. Speed Macros does not keep the food, label, or bloodwork photos you submit for AI estimates. They are sent for that request and discarded. Only the values you review and save are stored.
Anthropic processes this information as our service provider under its commercial terms. Those terms do not allow it to train its models on our API inputs or outputs. Anthropic states that it deletes API inputs and outputs within 30 days, except where longer retention is needed to enforce its usage policy or to comply with law (Anthropic Privacy Center). AI estimates can be wrong. Always check them, especially for allergens.
6. Who We Share Information With
We share personal information only with the service providers below, which process it on our behalf, and in the limited cases listed after them. We require our providers, through their terms with us, to protect personal information at least as well as this Policy describes and to use it only to provide their services to us.
- Supabase (database, authentication, and private file storage): stores your account and all records and media described above.
- Vercel (web hosting and delivery): processes every request to the Service, including request and security data and the content of your requests.
- Anthropic (AI processing): only with your AI-sharing consent, as described in Section 5.
- Stripe (payments and subscriptions): receives your account identifier and the selected pack or plan. For Speed Macros Plus it also receives your email address and your renewal-consent time. Stripe collects payment details directly and is independently responsible for some payment data under its own privacy policy.
- Brevo (Sendinblue SAS, France; email delivery for sign-in emails): receives your email address and the content of the sign-in and account emails we send through our authentication provider. It receives no health records.
- Google or Apple (optional sign-in, where enabled): if these options are offered and you choose one, the provider processes the information needed to authenticate you under its own privacy terms.
- MyFoodDiary (public nutrition lookup): our servers send the name of a branded or restaurant food you describe. No account or personal identifiers are sent.
We may also disclose information when the law requires it or to respond to valid legal process, to protect the rights, safety, or property of users, Speed Macros, or others, or as part of a merger, acquisition, or sale of assets. In a business transfer, this Policy (or protections at least as strong) will continue to apply to your information, and we will notify you as the law requires.
Referral program: if you join using someone's referral link, that person may be able to tell that you created an account and, later, that you made your first purchase (a credit pack or a paid Speed Macros Plus period), because that purchase triggers their reward. We never show them your name, email, purchase details, meals, or any other records, and no health activity triggers a referral reward.
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising or targeted advertising, as those terms are defined in U.S. state privacy laws. We have not done so in the past 12 months. We do not sell or share information about anyone under 18. We do not disclose personal information to third parties for their own direct marketing.
7. Where Information Is Processed (International Transfers)
Speed Macros and most of its providers operate mainly in the United States. Our email delivery provider, Brevo, processes your email address and sign-in emails in the European Union. Your information is stored in the United States (AWS us-east-1, Virginia), and our providers may process it in the United States and other countries where they or their sub-processors operate. The data protection laws there may differ from those where you live, and courts, law enforcement, and national security authorities there may be able to access the information. We rely on the transfer safeguards available under your local law, such as provider data processing agreements containing standard contractual clauses or the UK International Data Transfer Addendum, and the UK Extension to the EU-U.S. Data Privacy Framework for providers certified under it. Sections 16 to 21 give country-specific details. Contact us for more information about the safeguards we use.
8. Cookies, Device Storage, and Tracking
We use only storage that is needed to run the Service or remember your settings:
- Sign-in session cookies set by Supabase authentication. These keep you signed in and last until you sign out or the session expires.
- "optifuel-has-profile", an HttpOnly cookie that remembers that your account has finished setup. It lasts up to 90 days.
- A color-theme cookie that remembers your theme choice. It lasts up to one year.
- Offline queue: if you log food, weight, or water while offline, the pending entries are saved on your device until they sync or you remove them. Browsers use IndexedDB. The iOS and Android apps encrypt the queue, and the encryption key stays in the device's secure storage and is not synced.
- App cache: the service worker caches only public app files (such as scripts, icons, and the offline page). It does not cache your signed-in pages or data.
We do not use advertising or analytics cookies, and we do not track you across other apps or websites. Clearing site or app storage may sign you out and remove entries that have not synced.
Global Privacy Control and Do Not Track: we do not sell or share personal information or use it for targeted advertising, so there is nothing for these signals to turn off. If that ever changes, we will honor Global Privacy Control as an opt-out where the law requires.
9. How Long We Keep Information
- Account, profile, health and fitness records, progress media, recipes, remembered ingredients, feedback, referral records, consent records, credit balances, and usage and billing records: kept while your account exists and deleted when you delete your account. Speed Macros does not currently delete inactive accounts automatically.
- Photos submitted for AI estimates: not stored by Speed Macros. Anthropic's retention is described in Section 5.
- Records of individual entries you delete: removed from our active database when you delete them.
- Backups and logs: deleted data may remain in provider backups for up to 7 days, and in hosting and authentication logs for as long as each provider's log retention period, after which it is overwritten. We do not restore backups to reverse deletions except to recover from a system failure. If we ever restore one, we will delete your data again.
- Payment records: Stripe keeps transaction and subscription records under its own legal obligations. We keep limited purchase records longer only where tax, accounting, or other laws require.
- On-device data: kept until it syncs or you clear it.
10. How We Protect Information
We use HTTPS encryption in transit, database row-level security that limits each signed-in session to its own records, private account-scoped file storage with short-lived signed links, server-side checks on every AI and billing request, encryption of the native offline queue, and limited administrative access. Only Speed Macros's operator can access account data for support and operations, and only as needed. No online service is perfectly secure. Protect your email account and devices, and contact us promptly if you suspect unauthorized access.
11. Your Rights and Choices
Depending on where you live, you may have the right to know about, access, correct, delete, or obtain a portable copy of your personal information; to withdraw consent; to object to or restrict certain processing; and to appeal our decision about a request. We offer these tools to all users regardless of location:
- Access and portability: download your food logs, body metrics, daily summaries, targets, bloodwork, workout sessions and sets, recipes, progress check-in records, remembered ingredients, workout exercise lists, AI usage, credit and subscription records, and profile at any time (Plan, then Export) as CSV or JSON. For a copy of anything else we hold, including progress media files, custom exercises, feedback, or referral records, email nooraniaaariz@gmail.com.
- Correction: edit or delete your entries and profile directly in the app, or contact us.
- Withdraw AI-sharing consent: Settings, then Legal & Privacy.
- Withdraw health-data consent and delete your account: Settings, then Delete Account. This deletes your account and account records, removes your stored photos and videos, and cancels an active Speed Macros Plus subscription. Tracking health information is the core of the Service, so withdrawing that consent means closing the account.
- Subscription management: cancel or update payment details through the Stripe customer portal in Settings.
Making a request: email nooraniaaariz@gmail.com from the address on your account, or tell us which address it is. We may need to verify your identity before acting, usually by confirming control of that email address. We do not ask for more information than needed. Where the law allows, you may use an authorized agent. We may ask the agent for proof of authority and ask you to confirm your identity directly. We aim to respond within 30 days, and in every case within the deadline your law sets (for example, 45 days under most U.S. state laws, extendable once where the law permits and with notice to you).
Appeals: if we decline your request in whole or in part, you can appeal by replying to our decision or emailing nooraniaaariz@gmail.com with the subject "Privacy appeal". We will respond in writing within the time your law requires (for example, 45 or 60 days in U.S. states that grant appeal rights), explain our reasons, and tell you how to contact your regulator or state Attorney General if you disagree.
We will not deny you service, charge you a different price, or give you a different quality of service because you exercised a privacy right. However, AI features cannot work without AI-sharing consent.
12. Data Breaches
If a security breach affects your personal information, we will notify you and the relevant regulators as the applicable laws require, including the U.S. Federal Trade Commission's Health Breach Notification Rule (notice to affected individuals without unreasonable delay and within 60 calendar days of discovery), U.S. state breach laws, and the laws described in Sections 16 to 21. We will normally notify you by email, and also in the app where practical.
13. Children
Speed Macros is for adults. You must be at least 18 years old to create an account, and we check the birth date you enter. The Service is not directed to children. We do not knowingly collect personal information from anyone under 18, including children under 13 as defined by the U.S. Children's Online Privacy Protection Act. If we learn that we have collected information from someone under 18, we will delete the account and its information. If you believe a minor has created an account, contact nooraniaaariz@gmail.com.
14. Not a Healthcare Provider
Speed Macros is a consumer wellness and tracking service. It is not a healthcare provider, health plan, or medical device, and it does not diagnose, treat, or prevent any condition. HIPAA generally does not apply to the information you give Speed Macros, which is why we describe our health-data protections in this Policy and the Consumer Health Data Privacy Policy.
15. Additional Information for U.S. Residents
- Washington, Nevada, and Connecticut consumer health data: see the Consumer Health Data Privacy Policy for the specific rights, consent rules, and appeal routes under Washington's My Health My Data Act, Nevada's consumer health data law (SB 370), and the Connecticut Data Privacy Act.
- Sensitive data: we collect health information only with your consent, and optional dietary preferences that could reveal religious beliefs only if you choose to provide them. We use them only to provide the features you request, and we never sell them. This follows the sensitive-data rules in Connecticut, Texas, Virginia, Colorado, Oregon, Maryland, and other states where they apply to us.
- Categories disclosed for business purposes in the past 12 months: identifiers (email, account ID, IP address), commercial information (purchases and subscriptions), sensitive personal information (health, and optional dietary preferences), internet activity (request logs), inferences (AI estimates and calculated targets), and user-generated content (photos, videos, descriptions, feedback), disclosed to the service providers in Section 6 for the purposes in Section 4. We do not use sensitive personal information to infer characteristics about you.
- California: Speed Macros does not currently meet the thresholds that make a business subject to the California Consumer Privacy Act. Even so, California residents may use all the rights and tools in Section 11. We do not sell or share personal information, and we do not disclose it to third parties for their direct marketing (California's "Shine the Light" law).
- Other states: Section 11 explains how to exercise the rights your state grants, including appeals. If we deny your appeal, you may contact your state Attorney General.
16. Additional Information for Residents of the United Kingdom
- Controller and representative: Speed Macros is established outside the UK. We have not appointed a UK representative under Article 27 UK GDPR; UK users and the Information Commissioner's Office can contact us directly at nooraniaaariz@gmail.com.
- Legal bases: contract (to provide your account and purchases); explicit consent under Article 9(2)(a) UK GDPR for health data (optional dietary preferences that may reveal religious beliefs are processed only if you choose to provide them, and you can remove them in Settings at any time); separate explicit consent for AI processing; legitimate interests (security, fraud and abuse prevention, service messages); and legal obligation (tax, accounting, and responding to lawful requests).
- Your rights: access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), and withdrawal of consent at any time, which does not affect processing before withdrawal. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
- Transfers: your information is processed mainly in the United States (Section 7). Your email address and sign-in emails are also processed by Brevo in the European Union, which the UK recognizes as providing adequate protection. Where a U.S. provider is certified under the UK Extension to the EU-U.S. Data Privacy Framework, we rely on the UK-US data bridge. Otherwise we rely on the UK International Data Transfer Addendum or equivalent safeguards in the provider's data processing terms.
- Complaints: contact us first at nooraniaaariz@gmail.com. We will acknowledge a data protection complaint within 30 days, investigate it, and tell you the outcome without undue delay. You can also complain to the Information Commissioner's Office at any time (ico.org.uk).
- The Service is not offered in the European Union.
17. Additional Information for Residents of Canada
- Accountability: our privacy officer named in Section 1 is responsible for our compliance with PIPEDA and, for Québec residents, is the person in charge of the protection of personal information.
- Consent: we collect health information only with your express consent, and you may withdraw consent as described in Section 11, subject to legal and contractual limits.
- Processing outside Canada: your information is stored and processed in the United States, your email address and sign-in emails are processed in the European Union, and information may be processed in other countries by the providers in Section 6. While there, it is subject to those countries' laws and may be accessible to their courts, law enforcement, and national security authorities.
- Québec: you have the rights to access, rectify, and have your information de-indexed or deleted, to withdraw consent, and to be informed of these rights. The Service does not use technology to identify, locate, or profile you. Your information is communicated outside Québec to the providers in Section 6 under written agreements that protect it.
- Complaints: contact us first. You may also contact the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), or your provincial privacy regulator.
18. Additional Information for Residents of Australia
- We handle personal information under the Australian Privacy Principles. Health information is sensitive information, and we collect it only with your consent and only as reasonably necessary for the Service.
- Overseas disclosure: your information is disclosed to and held by the providers in Section 6, mainly in the United States. We take reasonable steps, through our provider terms, to ensure they handle it consistently with the Australian Privacy Principles.
- Access and correction: use the in-app tools or contact us. We respond within 30 days. If we refuse a request, we will give our reasons in writing.
- Complaints: contact us first at nooraniaaariz@gmail.com. We aim to resolve complaints within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
- We will notify you and the OAIC of an eligible data breach as the Notifiable Data Breaches scheme requires.
19. Additional Information for Residents of New Zealand
- We handle personal information under the Privacy Act 2020. Our service providers hold information on our behalf as our agents, and we remain responsible for it. Where information is disclosed overseas, we do so only as Information Privacy Principle 12 allows.
- You may request access to and correction of your personal information.
- Complaints: contact us first. You may complain to the Office of the Privacy Commissioner (privacy.org.nz).
- We will notify you and the Privacy Commissioner of a notifiable privacy breach.
20. Additional Information for Residents of Singapore
- Data Protection Officer: contact our Data Protection Officer at nooraniaaariz@gmail.com.
- We collect, use, and disclose personal data with your consent and for the purposes in Section 4. You may withdraw consent by giving us notice, and we will tell you the likely consequences, such as AI features stopping or your account closing.
- You may request access to and correction of your personal data. We will respond within 30 days, or tell you when we can.
- Transfers: personal data transferred outside Singapore is protected by our providers' contractual obligations, providing a standard of protection comparable to the PDPA.
- We will notify you and the Personal Data Protection Commission of a notifiable data breach as required. You may contact the PDPC at pdpc.gov.sg.
21. Additional Information for Residents of South Africa
- Information Officer: our Information Officer can be reached at nooraniaaariz@gmail.com.
- Special personal information: health information and any dietary preference that reveals religious beliefs are special personal information. We process health information with your consent, and optional dietary preferences only if you choose to provide them.
- Cross-border transfers: your information is transferred to the United States and other countries where our providers operate. We rely on your consent, on transfers necessary to perform our contract with you, and on binding provider agreements that give protection substantially similar to POPIA.
- Your rights: access, correction, deletion, objection, and withdrawal of consent. You may lodge a complaint with the Information Regulator (inforegulator.org.za).
22. Changes to This Policy
We will update the "Last updated" date when we change this Policy. For a material change, we will notify you by email or in the app before the change takes effect. We will ask for your consent before using consumer health data in any materially new way.
23. Contact
Questions, requests, appeals, or complaints: nooraniaaariz@gmail.com
For accessibility help or to request this Policy in another format, see our Accessibility statement.
We do not currently publish a postal address; please contact us, including for legal notices, at nooraniaaariz@gmail.com, and we will provide a postal address if the law requires one for your request.