This English version is provided for convenience. The Spanish version prevails in case of discrepancy.
This policy describes how we process your personal data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
- Controller: Fernando Ferro González (self-employed individual), NIF 06029542T.
- Privacy contact: privacy@macrolume.com
2. What data we process and why
a) Access request (waitlist)
Data: email address, preferred language, and the point on the site from which you requested access. Purpose: managing the private-beta waitlist and informing you of the outcome. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time by writing to privacy@macrolume.com.
b) User account
Data: email, name and profile picture provided through our identity provider (Clerk), and language. Purpose: creating and managing your account and giving you access to the Service. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
c) Health and habits data (when you use the app)
The application will process data that may reveal information about your health: meals and meal photos, macronutrients, weight, training, hydration and goals, as well as your conversations with the assistant. Purpose: providing the tracking and planning features that constitute the Service itself. Legal basis: your explicit consent (Art. 9(2)(a) GDPR), requested separately inside the application before any such processing, and withdrawable at any time in the app or by writing to privacy@macrolume.com. Withdrawal does not affect the lawfulness of prior processing.
d) Technical data
Connection and usage data strictly necessary for the security and operation of the Service (e.g. access logs). Legal basis: legitimate interest in keeping the Service secure (Art. 6(1)(f) GDPR).
3. Automated decision-making and profiling
MacroLume uses artificial intelligence to estimate the composition of your meals and to propose personalized nutrition and training plans. These proposals are informational, can be corrected by you, and do not produce legal effects or similarly significant effects within the meaning of Art. 22 GDPR. We do not use your data for advertising and we never sell it.
4. Recipients and processors
We do not share your data with third parties except where legally required. To provide the Service we rely on processors bound by Art. 28 GDPR agreements:
- Convex, Inc. (database and backend; hosted in the EU region — eu-west-1).
- Clerk, Inc. (authentication and identity management, USA).
- AI model providers for meal analysis and the conversational assistant (they will be identified in this policy before being enabled in the application).
Where a provider is located outside the European Economic Area (e.g. Clerk in the USA), transfers rely on the EU-U.S. Data Privacy Framework or on the European Commission’s Standard Contractual Clauses, with supplementary measures where appropriate.
5. Retention
- Access requests: until the request is resolved and at most 24 months after submission if no invitation is issued, or until you withdraw consent.
- Account and app data: for as long as you keep your account. Upon deletion, we will erase or anonymize your data within 30 days, except data we must keep blocked to meet legal obligations.
6. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consents, by writing to privacy@macrolume.com from the email address linked to your request or account. We will reply within one month. If you believe we have not handled your rights correctly, you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es).
7. Security
We apply technical and organizational measures appropriate to the risk: encryption in transit and at rest, access controls, data minimization, and providers with recognized security certifications. No system is infallible; should a breach occur that poses a high risk to your rights, we will notify you as required by Arts. 33-34 GDPR.
8. Minors
The Service is intended for people aged 18 or over. We do not knowingly process minors’ data; accounts identified as belonging to minors will be deleted.
9. Changes to this policy
Updates will be published here with their date. If a change affects purposes or legal bases, we will notify you and, where required, request your consent again.