Privacy Policy
Effective date: 29 June 2026 · Last updated: 29 June 2026
1. Who we are
This Privacy Policy explains how Emriv Ltd, a company registered in England and Wales (company number 16988910), registered office 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, trading as "Maclo" ("we", "us", "our"), collects and uses your personal data when you use the Maclo mobile app, our websites, and related services (the "Service").
We are the data controller of your personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Contact (general / privacy): business@maclo.app
Data protection contact: our privacy team — business@maclo.app
This policy should be read together with our Terms & Conditions.
2. The personal data we collect
We collect the following categories of personal data:
- Account & identity — email address, display name, authentication identifiers, and the sign-in method you use (email, Sign in with Apple, Google Sign-In).
- Profile & goals — your nutritional targets (calories, protein, carbohydrate, fat), goal direction (cut / maintain / bulk), budget and distance preferences.
- Dietary preferences & requirements — vegetarian, vegan, halal, pescatarian, gluten-free, dairy-free, or none.
- Body metrics — age (or date of birth), sex/gender, height, weight, and activity level, used to calculate your calorie and macro goals.
- Camera & photos (Scan feature) — when you use the in-app Scan feature, the App accesses your camera and/or photo library to capture a menu/item image.
- Location — your device's precise GPS location when you search "near me", or a location you enter manually.
- Usage & activity — searches you run, results shown, meals you save, search history, streaks, features used, and in-app interactions.
- Subscription & transaction — subscription status, plan, entitlements, purchase/restore events, and transaction identifiers. We do not collect or store your full payment-card details — payments are handled by the App Store.
- Device & technical — device model, OS and version, app version, language/region, IP address, device/advertising identifiers, push-notification token, and diagnostic/crash logs.
- Communications — messages you send us (e.g. support requests, feedback) and our responses.
How Scan images are handled: when you scan a menu, the captured image is uploaded to our backend and sent to Anthropic ("Claude Vision") to extract the restaurant name and menu items. We use the image only to perform this recognition. We do not store the image itself — only the extracted menu text is saved (which lets other users benefit from that menu).
We do not intentionally collect more data than we need to provide the Service.
3. How and why we use your data, and our legal bases
Under the UK GDPR we must have a "lawful basis" for each use:
- Create and manage your Account; authenticate you — contract (Art. 6(1)(b)).
- Provide the core Service (find food near you that matches your goals; the Scan feature) — contract (Art. 6(1)(b)); for dietary data revealing religion/health and body metrics, explicit consent (Art. 9(2)(a)) — see section 4.
- Use your location to return nearby results — contract, enabled by the device permission you grant.
- Process and manage Pro subscriptions and entitlements — contract (Art. 6(1)(b)).
- Tax, accounting, and legal compliance — legal obligation (Art. 6(1)(c)).
- Maintain, secure, debug, and improve the Service; prevent fraud and abuse — legitimate interests (Art. 6(1)(f)).
- Analytics and product insights — legitimate interests, or consent where required.
- Service / transactional messages (account, security, subscription notices) — contract / legitimate interests.
- Marketing communications (if any) — consent (Art. 6(1)(a)); withdraw any time.
- Push notifications you've enabled — consent (device permission).
- Respond to your enquiries and provide support — legitimate interests / contract.
- Establish, exercise, or defend legal claims — legitimate interests / legal obligation.
Where we rely on legitimate interests, we have carried out (and can provide) a balancing assessment to ensure your rights are not overridden.
4. Special category data (health and religious data)
4.1. Some information you choose to provide may be "special category data" under Art. 9 UK GDPR — for example, dietary requirements that reveal a health condition (e.g. a medical gluten-free need) or a religious belief (e.g. halal), and body metrics or weight-management goals that relate to health.
4.2. We process this data only to provide the features you ask for (filtering and matching food to your needs), and our condition for processing it is your explicit consent (Art. 9(2)(a)), which you give by entering this information and using the related features.
4.3. You can withdraw consent at any time by removing the information in the App or contacting us; this won't affect processing already carried out. If you withdraw it, some features may no longer work.
5. Location data
5.1. Core features need your precise location to find food near you. We request location access through your device; you can grant, limit (e.g. "while using the app"), or revoke it at any time in your device settings.
5.2. We use location only to return relevant nearby results and distances and do not use it to track you in the background.
5.3. We do not sell your location data.
6. Who we share your data with
We do not sell your personal data. We share it only with the following categories of recipients, who act as our processors (handling data on our instructions) or as independent controllers where stated:
- Supabase — database, authentication, and backend hosting (processor).
- RevenueCat — subscription management and entitlement tracking (processor).
- Apple — App Store distribution, in-app purchases/payments, Sign in with Apple, push delivery (APNs).
- Google — Google Sign-In, only if you choose to sign in with Google.
- Apple Maps / MapKit — displaying maps and place information for your results.
- Anthropic — processes Scan menu photos (Claude Vision) to extract restaurant/menu data; the image is processed transiently and not stored by us.
- Expo / EAS — app delivery and/or over-the-air updates and push infrastructure.
- Professional advisers & authorities — legal, accounting, audit; and where required by law, regulators, courts, or law enforcement.
- Business transfers — a buyer or successor in the event of a merger, acquisition, or reorganisation (subject to this policy).
We require our processors to protect your data, use it only as instructed, and act under a written contract that meets Art. 28 UK GDPR.
7. International data transfers
Some recipients (e.g. RevenueCat, Apple, Google, and possibly Supabase) may process your data outside the UK, including in the United States. Where we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, such as:
- transfer to a country covered by UK "adequacy" regulations;
- the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum; and/or
- a recognised certification (e.g. the UK extension to the EU–US Data Privacy Framework, where the recipient is certified).
You can request details of the safeguards we use by contacting business@maclo.app.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes we collected it for:
- Account, profile, goals, dietary data, saved meals: for as long as your Account is active, and then deleted or anonymised within 90 days after you delete your Account, unless we must keep it longer.
- Subscription & transaction records: retained for up to 6 years to meet UK tax/accounting obligations.
- Diagnostics / logs: typically up to 90 days.
- Support communications: for as long as needed to handle your query and a reasonable period after.
When we no longer need data, we securely delete or anonymise it.
9. How we protect your data
We use appropriate technical and organisational measures to protect your data, including: encryption in transit (HTTPS/TLS); access controls and authentication; row-level security on our database so users can only access their own data; least-privilege access for staff; and secure, reputable infrastructure providers. No system is 100% secure, but we work to protect your data and will notify you and the ICO of any breach where legally required.
10. Your rights
Under UK data protection law you have the right to:
- be informed about how we use your data (this policy);
- access a copy of your personal data;
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten") in certain circumstances;
- restrict processing in certain circumstances;
- data portability — receive certain data in a structured, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time where we rely on consent (including special category data); and
- not be subject to solely automated decisions that have a legal or similarly significant effect (see section 12).
To exercise any right, contact business@maclo.app, or use the in-app account/delete options where available. We will respond within one month (extendable for complex requests). We may need to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
You can delete your Account and associated data from within the App or by emailing us.
11. Marketing communications
We will only send you marketing if you have opted in, and you can unsubscribe at any time via the link in the message, your settings, or by contacting us. We will still send essential service messages (e.g. security, billing, important changes).
12. Automated decision-making and AI
The Service uses automated processing and AI-assisted techniques to estimate nutritional values and to rank and match food items to the preferences and goals you set. These features help generate your results but do not make decisions that produce legal or similarly significant effects on you. The food choices you make are always your own. The accuracy limits of these estimates are explained in our Terms & Conditions (dietary/health disclaimer).
13. Children's privacy
The Service is not intended for children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with data, contact business@maclo.app and we will delete it.
14. Third-party links and services
The Service references third parties (restaurants, retailers, mapping providers, etc.) and may contain links to their content. We are not responsible for their privacy practices. Please review their privacy policies.
15. Cookies and similar technologies
The App uses device identifiers and SDKs (rather than browser cookies) for authentication, functionality, security, and (where applicable) analytics. On our websites we use only essential cookies required to operate the site.
16. Changes to this policy
We may update this policy from time to time. The "Last updated" date shows when. For material changes we will take reasonable steps to notify you (e.g. in-app or by email). Your continued use after changes take effect means you accept the updated policy.
17. How to contact us and complain
Emriv Ltd (trading as Maclo)
Registered office: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Privacy / data protection: business@maclo.app
General / support: hello@maclo.app
If you have a concern, please contact us first — we'll do our best to resolve it. You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk · Helpline: 0303 123 1113
© 2026 Emriv Ltd (trading as Maclo). All rights reserved.
