Data Ethics, Privacy and Humans · worked example

What MacroFactor's privacy policy could cost you

A personal harm analysis of MacroFactor's privacy agreement — not a summary of what it says, but a reading of where the flows it authorizes could work against the person on the other end: you. And MacroFactor keeps more of its promises than most, so the harms here live in the residue, not the headline.

Source: MacroFactor Privacy Notice, macrofactor.com/privacy/ (+ Consumer Health Data Privacy Notice)
Read and analyzed: September 2026
Method: the four lenses + the data lifecycle + contextual integrity
Note: privacy policies change. Section names and quotes reflect the version read on the date above.

MacroFactor is a macro, nutrition, and body-weight tracker. You open the relationship to lose fat, gain muscle, or eat with more control, and you feed it the most intimate ledger most people keep: every meal, your weight each morning, your body measurements, photos of yourself. To its credit, the policy is unusually restrained — MacroFactor says plainly, "We do not sell your Personal Data to third parties" and "We do not share your data for cross-behavioral advertising purposes," it honors Global Privacy Control, and it maintains a separate consumer-health-data notice. That removes the most common harm (default ad-sale) up front. But intimate diet and body data is still the crown jewel, and the flows the policy does authorize — indefinite retention, cloud-stored body photos, raw-data research access, legal disclosure, a future sale — can still cut you. Below are the specific places, each tagged with the lifecycle stage the risk lives in and how serious it is.

What it collects about you

Before the harms, the raw material. MacroFactor collects your body — “Body metrics (e.g., weight, height, body fat level, measurements like waist, hips, arms, legs, and ratios like waist-to-height)” — your diet (“Macro and micronutrient intake”), your images (“front, side, and back progress photos”), your reproductive data (“period tracking”), plus lifestyle details, account credentials (email; a password that is “hashed, salted, unencrypted and not accessible to MacroFactor”), device data, and payment/subscription data. It also derives things you didn't type — a “Customized calorie target and macro program” and your inferred “User goals (e.g., weight loss, weight gain, hypertrophy, strength).” Taken together, that is a continuous, dated record of how you eat and how your body changes.

The harms, specifically

01 Your food log and daily weight are a continuous eating-disorder signal

collected → analyzed high

What the policy allows: collection of “Macro and micronutrient intake” and “Body metrics” alongside inferred “User goals (e.g., weight loss…).” Nothing here is neutral. A daily calorie ledger, a morning weigh-in, and a “weight loss” goal are also the exact clinical signals of restriction, obsessive tracking, and rapid loss.

Why it could harm you: a dated diary of eating behavior and body change is a psychiatric record in all but name — one you built voluntarily, entry by entry. It can reveal disordered eating, recovery, or relapse. Even absent any misuse, its existence is the risk: it can be breached, subpoenaed, or read by whoever eventually holds the account.

02 Front, side, and back photos of your body live in the cloud for the life of your account

collected → stored → retained high

What the policy allows: “User-provided progress photos, specifically front, side, and back progress photos” are stored with “Google LLC (Firebase Cloud Firestore).”

“The photos are retained for as long as the user MacroFactor Apps account exists, or until the user chooses to delete their photos.”MacroFactor Apps Progress Photos

Why it could harm you: progress photos are typically near-nude, taken in minimal clothing to show body composition. They sit in a third-party cloud database indefinitely — the record only grows — and the policy names only that its security measures are “reasonably designed,” with no specific claim of encryption for the photos. A breach here isn't a leaked email; it's a leaked body.

03 Period tracking is stored the same as everything else — in a post-Dobbs world

collected → stored high

What the policy allows: “period tracking” is listed among the health data collected, its legal basis given as “The user's consent.”

Why it could harm you: menstrual data can imply pregnancy, miscarriage, or its absence. In the United States, reproductive-health records held by an app are potentially reachable by legal process (see #07). MacroFactor covers this under its consumer-health-data notice — better than most — but the data still exists in a cloud store, and existing data can be compelled.

04 A UK research firm can touch your raw data, not just aggregates

disclosed → analyzed medium

What the policy allows:

“Steele Research may access aggregated datasets and raw data (which does not include your name or email) for research purposes.”Service providers / analytics

Why it could harm you: “raw data” is your individual timeline of weights, macros, and measurements — not a summary. Stripping name and email is not the same as anonymizing a longitudinal body-and-diet series, which is often re-identifiable from its own shape. You entered a diet-tracking relationship, not a research cohort; here you become a study subject by default.

05 Data still flows to ad platforms — as an audience, even without a “sale”

disclosed medium

What the policy allows: MacroFactor shares data with “Meta Platforms, Inc.,” “Microsoft Corp.,” and “reddit Inc.” for its own social-media advertising — while maintaining it does “not sell your Personal Data” and does “not share your data for cross-behavioral advertising purposes.”

Why it could harm you: the protective promises are real and matter — but any signal reaching Meta or Reddit (installs, conversions, matched identifiers) still tells an ad giant that you are a person tracking your weight and diet. That is a sensitive inference in the hands of platforms whose whole business is inference, even when no data is “sold.”

06 “As long as needed” puts no fixed clock on your body history

retained medium

What the policy allows: “We keep your Personal Data for as long as needed for the purpose we collected it.” Some items get hard limits (Google Analytics “two months,” support tickets “within one year”) — but your core diet, weight, and photo history has no stated expiry beyond the life of the account.

Why it could harm you: an open-ended body-and-diet archive is a standing liability. The longer it lives, the more of your life it can be made to testify about — to a breach, a subpoena, or a future owner. Deletion is the only real end to it, and that's on you to trigger.

07 Your health record can be handed over for “official investigations or legal cases”

disclosed medium

What the policy allows:

“We might share your Personal Data when required by law or if we believe it is necessary for official investigations or legal cases.”Sharing your Personal Data

Why it could harm you: combined with indefinite retention (#06) and reproductive data (#03), this means your eating record, weight history, and period log can be pulled into a legal process — potentially one you are not a party to. Data that was deleted cannot be compelled; data MacroFactor still holds can.

08 If the business is sold, your body data goes with it

disclosed medium

What the policy allows: “We may also share your data if we sell part of our business or assets, or during a corporate change.”

Why it could harm you: the company that promised not to sell or ad-share your data is not necessarily the company that ends up holding it. A future owner inherits your weight history, food logs, period data, and body photos under whatever policy they choose. This is the 23andMe problem, transplanted onto diet and body-composition data: consent given to one party, exercised by another.

The lifecycle, in one line

Where the risks concentrate, named in the field's own vocabulary:

collected (diet, weight, photos, period #01–03) → stored → processed → analyzed (goals, and raw-data research #04) → used → retained (life of account, no fixed clock #02, #06) → disclosed (ad platforms #05, legal/investigations #07, a buyer #08)

Because MacroFactor forgoes data sales and cross-context ads, the heat isn't at disclosure the way it is with an ad-funded app. It's at the front and the tail: collection of extraordinarily intimate data, and its indefinite retention. The dossier itself is the exposure.

Contextual integrity: which boundary is crossed

The test

Context you entered: a coaching relationship about food and body — you log meals and weigh-ins, it gives you a calorie target that adapts.

Expected flow: your diet and body data used to compute and adjust your program, and held while you're using it.

Boundaries crossed: near-nude progress photos stored in a third-party cloud for the life of the account (#02); a UK firm accessing your raw individual data for research (#04); signals reaching ad platforms that you track your weight (#05); indefinite retention with no fixed clock (#06); and reachability by legal process (#07) or a future buyer (#08).

“Help me hit my macros” doesn't imply “keep photos of my body forever,” “let researchers study my raw timeline,” or “hold my period data where a subpoena can find it.” That gap — between the flow you expected and the flows the policy authorizes — is where the harm lives.

The four lenses on the sharpest flow (#02, body photos retained indefinitely)

Consequences

Progress photos genuinely help motivation and let the app show change over time — a real benefit. Against it: near-nude images of you sitting in a cloud database with no expiry, exposed to any future breach, sale, or legal demand. The upside is felt now; the downside is a tail risk that only grows.

Duty & rights

Consent to store a photo to track progress is not consent to retain it indefinitely by default. A duty of care to the person would set a short default lifespan and auto-purge, not place the entire burden of deletion on a user who may forget the photos exist.

Virtue

What kind of steward keeps intimate body images “for as long as the account exists” with only “reasonably designed” protection stated? Restraint here — minimizing what is kept and for how long — is the virtue a health app should embody, beyond what it already does well.

Justice

The harm of a leaked body photo falls unequally — heavier on women, on people with eating disorders, on anyone for whom their body is already a site of scrutiny. Those least able to absorb the exposure carry the most risk from indefinite retention.

What you can actually do

The policy grants real, usable controls. In rough order of value:

Bottom line

MacroFactor is, by the standards of health apps, one of the good ones: no data sale, no cross-context advertising, GPC honored, a dedicated health-data notice. That earns real trust — and it means the residual harm isn't a predatory default you must claw back. It's the dossier itself: a continuous, intimate record of your eating, your weight, your period, and your body — kept indefinitely, studied in raw form, and reachable by legal process or a future owner. The most protective thing MacroFactor can't do for you is hold less. That part is yours: log less than you're asked to, prune what you don't need, and delete when you're done.