Privacy Policy
Last updated: 4 September 2026
This policy describes how the operator of MakeMe (“MakeMe”, “we”, “us”) collects, uses, stores, and shares information when you use the MakeMe iOS app and the website at makeme.one (together, the “Service”). It is written to match how the product actually works. It is not medical or legal advice.
Questions or deletion requests: support@makeme.app.
1. Who we are
MakeMe is a health and fitness tracking app (food, workouts, weight) with optional Apple Health sync and optional AI help to identify food. We operate from Israel. We do not currently publish a separate company registration on this site; the controller of personal data for the Service is the operator of MakeMe, reachable at the email above.
2. What we do not do
- We do not sell your personal information.
- We do not show third-party advertising in the app or on this website.
- We do not use your meal photos or diary to train public AI models for unrelated products (see AI below).
- We do not require Google, Apple, or email sign-in to browse this marketing website.
3. Accounts and identifiers
To use the app you create an account with one of:
- Sign in with Google — we receive the identifiers Google provides to the app, typically name, email address, Google user id, and profile photo URL.
- Sign in with Apple — we receive the identifiers Apple provides, which may include a name and a real or hiding (“Hide My Email”) address.
- Email and password — we store the email you register, via Firebase Authentication.
Firebase Authentication then issues a user id that we use to attach your synced data. Analytics and crash reports may use that same user id so we can debug issues for a signed-in session. We also store a display alias used in community features (you can set it, or one is generated).
4. Health, food, and training data (the diary)
The core of MakeMe is a diary you create: meals and foods (names, amounts, nutrients, scores, barcodes, combos), workouts (exercises, sets, personal records, templates), body measurements and nutrition goals (including information you enter such as sex, year of birth, height, weight, activity, and goal type), weight logs, supplements, and related notes. This is stored on your device (Core Data) and, when you are signed in, synced to Google Firebase (Firestore) so it can restore across devices and survive reinstalls.
Some of this is health-related data. We process it only to provide the Service you asked for (tracking, goals, insights, sync, backup you export). We do not use it for advertising.
5. Apple Health (HealthKit)
If you grant access, MakeMe may read weight, body fat percentage, dietary energy, protein, carbs, fat, sugar, sodium, steps, and flights climbed, and may write weight and nutrition samples back to Apple Health so other Apple apps can see what you logged. You can revoke Health access in iOS Settings. HealthKit data on the iPhone is governed by Apple; copies of meals and weight that you log in MakeMe still live in our diary sync described above.
6. Camera, meal photos, and barcodes
With permission, the camera is used to photograph meals and to scan product barcodes. Meal photos are sent to AI providers (see below) so we can suggest foods and portions. Barcodes are looked up in the Open Food Facts public product database and may also be sent to AI to complete missing nutrition. Photos can include faces, surroundings, or other people. Do not photograph others without their consent. We process images to run the feature, not to build a public photo gallery.
7. Location
If you allow Location When In Use, we may tag meals and workouts with where they happened (coordinates and a reverse-geocoded place name). That can be stored in your diary and synced with your account. We do not use location for ads. You can refuse or later disable location; tagging will stop.
8. Artificial intelligence
Food analysis, portion suggestions, some catalog enrichment, and similar features send the minimum needed content (for example a meal photo, a food description, or a barcode product payload) to:
- OpenAI (API), and/or
- Apple Intelligence together with ChatGPT when you enable that option on a supported device.
Those providers process the content under their own terms and privacy policies. Output can be wrong. Do not rely on it as medical, allergen, or professional nutrition advice. We may log technical errors related to these calls (not as a marketing profile).
9. Community catalog
You can pick foods and exercises from a shared catalog and, in some flows, publish or update a shared listing (name, nutrition per 100g, emoji, and similar catalog fields). Catalog entries are visible to other MakeMe users. Do not put information in a shared listing that you do not want others to see. Your private diary (what you ate today, your weight trend, exact GPS of a meal) is not the catalog. If you delete your account, we may keep or anonymize catalog items other people already rely on.
10. Analytics, crashes, and product telemetry
We use Firebase Analytics and Firebase Crashlytics (Google). Typical data: events (screens opened, features used, errors), device/app version, language, sign-in method, whether onboarding finished, coarse profile properties derived from a nutrition goal you saved (for example age group, goal type, workout frequency, gender as you entered it), and crash stacks. Firebase Performance collection is turned off in the app. We do not run Google Ads conversion measurement in the app.
Signed-in clients also send limited usage / platform statistics to our Google Cloud Functions (for example activity heartbeats and preference snapshots) so we can operate the product.
11. Notifications, widgets, and Live Activities
Optional local notifications (reminders) are scheduled on your device. Home-screen widgets and Live Activities read data already on the device (including an App Group). They are not a separate cloud profile.
12. Backups you export
You can export or import a backup file of your diary. Treat that file as sensitive. Anyone who obtains it can read your health and location history. We are not responsible for copies you store in email, Files, or another phone.
13. This website
makeme.one is a static site. We store a language preference in your browser (localStorage) if you toggle English/Hebrew. We do not run a user database on the website itself. Hosting and logs may be processed by our site host (currently Vercel) in the ordinary course of delivering the pages.
14. Processors and where data goes
Depending on the feature, personal data may be processed by:
- Google (Firebase Authentication, Firestore, Analytics, Crashlytics, Cloud Functions, and Sign in with Google);
- Apple (Sign in with Apple, HealthKit, App Store, Apple Intelligence / ChatGPT path if you enable it);
- OpenAI (food and related AI);
- Open Food Facts (barcode product lookup);
- Vercel (website hosting).
Servers may be outside Israel, including the United States and other countries. Those countries may have different data-protection laws. We use these providers because the Service cannot run without them.
15. Retention
We keep account and synced diary data while the account exists and for a short period afterward as needed to complete deletion, backups, or legal obligations. Analytics and crash logs follow the retention of those Google products. Device copies remain until you delete the app or the data in the app.
16. Your choices and deletion
You can:
- sign out;
- revoke camera, location, notifications, or Health in iOS Settings;
- turn off Apple Intelligence + ChatGPT in MakeMe settings (the app then uses the OpenAI API path instead);
- delete individual diary entries in the app;
- delete the app (removes the on-device store; it does not by itself erase the cloud account).
To delete your MakeMe account and synced cloud data, email support@makeme.app from the same email address attached to the account (or tell us the Sign in with Apple relay address). We will delete or anonymize the Firebase account and associated Firestore diary within 30 days, except data we must keep (for example a legal hold) or community catalog records as described above. Google and Apple may keep their own sign-in records under their policies. After deletion you cannot recover the diary from us.
If you are in the EEA, UK, or a similar regime, you may also have rights to access, correct, erase, restrict, or port personal data, and to object to certain processing, and to complain to a supervisory authority. We will respond to valid requests sent to the email above.
17. Children
The Service is not directed at children. You must be at least 16 years old. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
18. Security
We use industry-standard provider security (TLS, authenticated APIs, per-user cloud documents). No method of transmission or storage is completely secure. You are responsible for the security of your device and sign-in.
19. Changes
We may update this policy. The “Last updated” date will change. Continued use after an update means you accept the revised policy, except where applicable law requires another form of notice or consent. Material changes will be posted on this page; we may also notify in the app when we can.