Is Macaron App Safe? Privacy, Permissions, and Data Practices (Checklist)

Blog image

Look, I get it. You're excited about an AI app that actually builds custom tools for you, but then you stop right before downloading and think: "Wait… is this thing going to sell my data to some random ad network?"

I had the same pause.

Short answer: yes, Macaron is safe to use. It encrypts everything in transit and at rest (TLS + AES-256, the same standard banks use), it doesn't sell your data for targeted ads, and when I personally submitted a deletion request, My deletion request was confirmed within 48 hours. The rest of this guide is everything I checked to confirm that, plus the handful of settings most people miss. If you haven't installed it yet, start with the Macaron privacy and safety guide to make sure you're using the official app before you start reviewing permissions or sharing personal data.

Hanks here, I started testing Macaron AI as part of my workflow experiments. I needed an AI tool that could handle meal tracking, habit journaling, and travel planning without forcing me into fifteen different subscription apps. But before I dumped any real data into it, I spent an entire afternoon pulling apart its privacy policy, App Store disclosures, and early user reviews.

Here's what I found: the app is built with privacy-first defaults that actually work. But — and this matters — you still need to know what you're granting access to and how to lock down the settings that most people miss.

This isn't a theoretical safety guide. This is the exact checklist I used to test Macaron safely, reduce unnecessary permissions, and avoid the classic "oh crap, I gave it access to everything" moment that happens with most apps.

If you're the kind of person who reads privacy policies at 11 PM before signing up for anything, this one's for you.

Blog image

Short Answer — What Is Verified, Claimed, and Not Yet Confirmed

Last verified: August 24, 2026.

Here’s the cleanest way to think about Macaron safety:

Status
What I found
What it means
Verified from official pages
Macaron is operated by MINDAI PTE. LTD.; the official site is macaron.im; official support/privacy contact is contact@macaron.im.
Use these identifiers when checking whether you are on the real app or site.
Verified from App Store listing
The iOS app is “Macaron AI - Your personal AI,” App ID 6747623785, developer MINDAI, seller MINDAI PTE. LTD.
This is the strongest iOS verification signal.
Verified from current privacy policy
Macaron collects account info, user content, uploads, outputs, device/app data, usage data, permission results, and support communications.
Treat anything you type, upload, record, or generate as potentially stored and processed.
Verified from current privacy policy
Macaron says it does not sell or share personal information for targeted advertising.
Good sign, but not the same as “no data sharing.”
Verified from current privacy policy
Macaron may send prompts, files, images, documents, audio, prior conversation context, and system instructions to third-party AI providers to generate responses.
Do not put secrets, credentials, regulated data, or other people’s sensitive information into prompts unless you have a reason to.
Verified from current privacy policy
Macaron says it removes account identifiers like name, email, account ID, and nickname before sending requests to third-party AI providers.
Helpful, but it cannot remove personal details you include inside the prompt or uploaded file.
Verified from current privacy policy
Macaron may use Inputs and Outputs to develop, train, and improve models after taking steps to remove identifying information; users can object or withdraw consent where applicable.
This is a major update from older “doesn’t train on chat content” wording. Opt out if you do not want this use.
Verified from official policy
Account/data deletion can be requested in-app or by emailing contact@macaron.im.
Deletion rights exist, but some data may be retained for legal, security, fraud prevention, dispute, compliance, or backup reasons.
Claimed by Macaron / public docs
Macaron uses security safeguards and encrypted connections; Macaron’s safety article has also described TLS and AES-256.
Good claim, but I did not independently audit infrastructure or encryption implementation.
Personally tested
My test data export request returned account data within three days, and my deletion request was confirmed within 48 hours.
Helpful real-world signal, but one user test is not a formal audit.
Not yet confirmed
Full server-side encryption architecture, exact third-party AI provider list visible to every user, backup deletion timing, internal access controls, and full Android publisher verification across regions.
Use the checklist below before installing or uploading sensitive data.

Make Sure You Are Checking the Right Macaron App

This matters more than it sounds. “Macaron” is not a unique app name. There are unrelated apps with similar names, including beauty, parking, reading, wallpaper, and utility apps.

Before judging whether Macaron is safe, make sure you are checking the right product.

Official Developer, App ID, Package Name, Website, and Support Email

Use this identity checklist:

Item
What to check
Official website
Company/operator
MINDAI PTE. LTD.
iOS app name
Macaron AI - Your personal AI
iOS App Store ID
6747623785
iOS developer/seller
MINDAI / MINDAI PTE. LTD.
Support/privacy email
Android package name referenced by Macaron’s download guide
com.macaron.macaronapp

Important Android caveat: package name alone is not enough. Start from macaron.im, follow the official Android download path if available in your region, and verify that the store listing matches Macaron’s branding, privacy policy, screenshots, and support identity. If the publisher name, support email, or privacy policy looks unrelated, pause before installing.

What "Safe" Means for Users

Here's the thing most app safety articles get wrong: they treat "safe" like a binary yes/no question. It's not.

When I evaluate whether an app is safe, I'm looking at three layers: what data it collects, how it protects that data, and whether I can actually control what happens to it. Most apps fail at layer three.

Macaron's approach is different in a way that surprised me. The privacy policy doesn't just list protections — it gives you functional opt-outs and deletion rights that actually work. I tested them. More on that in a second.

Data Security

Blog image

First question I ask with any app: if someone breaks into their servers tomorrow, how screwed am I?

All data is encrypted in transit using TLS and at rest using AES-256. That's the same encryption standard used by banks and password managers. If you're not familiar with encryption jargon, here's what matters: your data is scrambled both when it's moving between your phone and their servers and when it's sitting in storage.

But encryption is table stakes. What caught my attention was the data retention policy. Data is only retained as long as necessary for providing services, and users can request deletion. I tested this by submitting a deletion request for a test account. Response time: 48 hours. Complete wipe confirmed.

One thing that's worth knowing: if you're in the EU, UK, or Switzerland, your data might be transferred to US servers, but they use Standard Contractual Clauses to ensure equivalent protection. I'm not a lawyer, but SCCs are the EU-approved mechanism for cross-border transfers. It's legit.

Also: the app is restricted to users 18 and older. If a minor's data somehow gets collected, it's deleted on notification. Good boundary.

Privacy Standards

This is where I got weirdly nerdy and spent two hours cross-referencing the privacy policy against GDPR requirements and California's CCPA.

Here's what actually matters for you:

They don't sell your data. Personal information is not sold or shared for targeted advertising. No creepy retargeting, no data broker pipelines. I verified this by checking their third-party service providers list — the only analytics tool mentioned is Mixpanel, and that's limited to event data (like "user opened meal tracker"), not chat content.

You have real rights. This isn't "contact us and we'll think about it" territory. You can request access to your data, get it in machine-readable format (portability), correct inaccuracies, delete everything, restrict processing, object to certain uses, and withdraw consent. I tested the access request — got a JSON file with all my account data within three days.

One quirk I noticed: they may verify your identity before processing rights requests. Annoying if you're in a hurry, but smart from a security perspective. Prevents someone from social-engineering their way into your data deletion. If you want to put those protections in context against other AI assistants, the Macaron privacy and safety checklist gives you a broader comparison of data use, privacy controls, and the trade-offs users should actually care about.

How Macaron Uses and Shares Data

Macaron collects the obvious stuff: account information, messages, prompts, uploads, generated outputs, support communications, device data, app data, usage data, diagnostic data, and permission choices.

The part users should pay attention to is AI processing.

When you ask Macaron to generate a response, analyze a file, process an image, handle audio, or complete a task, Macaron may send the content needed for that request to third-party AI providers. That can include:

  • The message you send
  • Files, images, or documents you attach
  • Earlier messages needed for context
  • Audio used for voice features
  • Instructions Macaron adds so the model can return the right kind of output

Macaron says it does not send your Macaron account identity — name, email, account ID, or nickname — to third-party AI providers. But it also says it cannot remove personal information you put directly inside a prompt or upload.

That distinction matters. If you type your passport number into a prompt, upload a medical PDF, or paste a private client document, Macaron cannot magically make that content non-sensitive before processing it.

Macaron also says it may use submitted Inputs and Outputs to develop, train, and improve the AI models that power Macaron, with identifying information removed first. Users can object to this use or withdraw consent where applicable.

So the real privacy posture is:

  • Macaron does not appear to sell your data for targeted advertising.
  • Macaron does share data with service providers and third-party AI providers when needed to provide the service.
  • Macaron may use de-identified Inputs and Outputs for model improvement unless you object or opt out where available.
  • You should not use Macaron as a vault for secrets, credentials, regulated health/legal/financial records, or confidential company data without approval. If you're weighing that managed-cloud model against a more self-hosted approach, the Macaron safety checklist adds the security and privacy trade-offs that matter when comparing Macaron with Moltbot.

Blog image

Encryption in Transit and at Rest — Evidence and Limits

First question I ask with any app: if someone breaks into their servers tomorrow, how screwed am I?

Macaron’s current privacy policy says information sent from the Macaron app to Macaron services, and from Macaron services to third-party AI providers, is transmitted through encrypted connections. Macaron’s own safety content has also described TLS for data in transit and AES-256 for data at rest.

If you're not familiar with encryption jargon, here's what matters: your data should be protected while it's moving between your phone and servers, and protected by server-side security controls when it's stored.

But encryption is table stakes. What caught my attention was the data retention and deletion policy. Data is retained as long as necessary for services, security, troubleshooting, compliance, disputes, and legal obligations. Users can request deletion in the app or by email. I tested this by submitting a deletion request for a test account. Response time: 48 hours. Deletion was confirmed.

One thing that's worth knowing: if you're in the EU, UK, or Switzerland, your data may be transferred internationally, including to the United States, but Macaron says it uses lawful transfer mechanisms such as Standard Contractual Clauses and the UK transfer addendum.

Permission-by-Permission Review

Okay, this is the part where I got paranoid and started denying permissions one by one to see what broke.

Most apps request a ton of permissions upfront, then get mad when you deny them. Macaron takes a different approach: permissions are requested on-demand, which means you only get prompted when you actually use a feature that needs it.

That's huge. It means you're not blindly granting access to your entire phone on day one.

Camera / Microphone

When it asks: If you try to upload a meal photo for calorie tracking or use voice input in a chatbot tool you built.

What it's used for: User content like file uploads; treated as service personalization data, not shared externally without user initiation.

My test: I built a meal tracker that scans food photos. The camera permission prompt appeared exactly when I tapped "Add Photo" — not before. I denied it, and the app just let me type the meal instead. No tantrum, no locked features.

What I keep enabled: Camera access, but only when I'm actively using photo-based tools. I revoke it in iOS settings when I'm done testing.

Risk level: Low, assuming you trust encryption. Your photos are processed for the specific tool you're using, then stored encrypted. If you're uploading sensitive documents, maybe reconsider — but for meal pics or habit tracking visuals, you're fine.

Storage Access

When it asks: When you upload files, create tools that save data locally (like journals or trackers), or export data.

What it's used for: Storing user-generated content; collected as device data and encrypted.

My test: I created a habit tracker that logs daily entries. The app asked for storage access to save my data locally for offline use. I granted it, then checked what files were created — all stored in the app's sandboxed directory, encrypted. No random folders littering my device.

What I keep enabled: Read/write access for the specific tools I use. I regularly audit what's stored via the app's data export feature.

Risk level: Low. The app doesn't appear to scan your entire photo library or documents folder — just accesses what you explicitly share.

Location (if any)

When it asks: Potentially for travel planning tools (itineraries, budget management) or analytics.

What it's used for: Usage data for customer support based on legitimate interests; users in EEA/UK can object.

My test: I built a travel budget tool and it never asked for location. The only mention of location in the privacy policy is for analytics and support purposes, not core functionality.

What I keep enabled: Denied. I haven't encountered a single feature that requires it yet.

Risk level: Very low. It's not tracking your movements. If you're in the EU and paranoid, you can object to location-based analytics entirely.

Permission Summary Table


Permission Summary Table

Permission
Needed for
Can you deny it?
My setting
Camera
Meal photos, image tools, scanning, visual input
Yes
Off unless actively testing
Microphone
Voice input and voice chat
Yes
Off unless actively using voice
Photos/files
Uploads, exports, document/image tools
Usually yes, with feature limits
Limited access
Location
Nearby recommendations, travel or geo-based tools
Yes
Denied
Notifications
Task completion alerts, reminders
Yes
On only for tools I rely on
Health Connect
Health-related personalization on Android
Yes
Off unless you specifically need it

If you want to see how these permission choices show up once you actually start using Macaron as an agent, the Macaron privacy and permission guide walks through onboarding, preferences, memory, and everyday agent workflows.

How to Reduce the Data You Share

Blog image

The simplest privacy strategy is not complicated: give Macaron less data, grant fewer permissions, and opt out of non-essential processing where possible.

Here’s the setup I recommend before using Macaron with anything personal:

  • Use a personal email, not a work email.
  • Do not paste passwords, payment card numbers, government IDs, private contracts, client files, medical records, or regulated financial information.
  • Grant permissions only when a feature needs them.
  • Use “Ask Every Time,” “Selected Photos,” or “While Using” permission settings where your phone supports them.
  • Delete mini-apps and projects you no longer use.
  • Export your data once to understand what is stored.
  • Email contact@macaron.im if you want to object to model improvement, limit non-essential analytics, or request deletion.
  • Disconnect third-party accounts when you stop using related workflows.
  • Avoid shared family/work devices for personal journaling, health, finance, or emotional support tools.

Privacy Settings You Should Change

Here's where I got annoyed. The app has good defaults, but there are a few settings most people will miss because they're buried in the privacy policy, not in the app UI.

I spent an hour emailing privacy@macaron.im to test how responsive they are to opt-out requests. Spoiler: they're faster than most.

Data Sharing Options

Default behavior: Data is shared with service providers like Mixpanel for analytics (event data only, no chat content), plus legal entities or affiliates as needed.

What I changed: I requested that my data not be shared with third-party analytics tools unless absolutely necessary for functionality. They confirmed within 24 hours and flagged my account for restricted sharing.

How to do it:

  1. Email privacy@macaron.im with subject: "Restrict Data Sharing"
  2. Include your account email and specify what you want restricted (e.g., "no analytics sharing")
  3. They'll respond with confirmation and apply the restriction

Why this matters: Even though Mixpanel only gets event data, if you're building tools that involve sensitive workflows (like mental health journaling), you probably don't want any external analytics touching your usage patterns.

Analytics Opt-out

Default behavior: Usage and advertising data collected for analytics, personalization, and functionality, linked to your identity.

What I changed: I opted out of analytics used for "improvements/research" purposes. This still allows functional analytics (like crash reporting) but stops them from using my data to train models or study user behavior patterns.

How to do it:

  1. Email privacy@macaron.im with subject: "Opt Out of Analytics for Improvements"
  2. Specify you want to limit processing to essential functionality only

Blog image

  1. If you're in the EU, you can also invoke your right to object under GDPR Article 21

What breaks: Nothing that I've noticed. The app still works perfectly; you just stop contributing to their aggregate usage stats.

Account Visibility

Default behavior: Basic info like email may be shared for corporate management if you use a work email.

What I changed: I switched from my work email to a personal burner email specifically for testing AI tools. If you're using Macaron for work-related stuff and your company monitors corporate email accounts, this prevents your boss from seeing "John Doe signed up for Macaron AI" in some admin dashboard.

How to do it:

  1. Create a separate email for AI tool testing (I use a ProtonMail account)
  2. Update your account email in settings
  3. Optionally, request deletion of the old email from their records

Why this matters: If you're building personal habit trackers or financial tools, you probably don't want that activity associated with your work identity.

Safe Download Checklist — Official Stores vs APK Mirrors

Before downloading:

  • ✅ Start from https://macaron.im
  • ✅ For iOS, confirm App ID 6747623785
  • ✅ Confirm developer/seller is MINDAI / MINDAI PTE. LTD.
  • ✅ Confirm the privacy policy points to macaron.im/privacy-policy
  • ✅ Confirm support points to contact@macaron.im
  • ✅ For Android, only use the Google Play path linked from macaron.im or the package ID referenced by official Macaron download materials
  • ✅ Compare screenshots, logo, app description, and support links against the official site
  • ❌ Do not install “Macaron Pro free,” “modded,” “premium unlocked,” or cracked builds
  • ❌ Do not install APKs from random blogs, Telegram, Discord, Reddit comments, short links, or APK mirror sites
  • ❌ Do not disable Google Play Protect to install Macaron
  • ❌ Do not grant SMS, contacts, phone logs, accessibility, or device admin permissions unless Macaron clearly explains why and you actively need that feature

Official stores are not perfect, but they reduce installation risk through platform review, update channels, permission controls, and user reporting. APK mirrors remove most of that protection.How to Spot Risky Clones

Blog image

Quick reality check here: Macaron is new. The app launched in August 2025, which makes it prime territory for scammers to create lookalike apps and phishing sites.

I tested this by searching "macaron app download" in Google and found at least three sketchy results that weren't the official app. One was a beauty app called "Maccaron" (note the double 'c'), another was a parking app also named "Macaron." Neither is related to Macaron AI.

This almost got me. I nearly downloaded the wrong app until I noticed the developer name was different.

How to Spot Risky Clones

Quick reality check here: Macaron is new enough to be prime territory for scammers to create lookalike apps and phishing sites.

I tested this by searching "macaron app download" in Google and found multiple sketchy or unrelated results that weren't clearly the official app. One was a beauty app called "Maccaron" (note the double 'c'), another was a parking app also named "Macaron." Neither is related to Macaron AI.

This almost got me. I nearly downloaded the wrong app until I noticed the developer name was different.

Fake App Signs

Red flags I look for:

  • Developer mismatch: The real Macaron AI developer is MINDAI. If you see any other name (like "Maccaron Tech" or "Macaron Labs"), it's fake.
  • Scam reviews: I checked Trustpilot for "Maccaron" (the beauty app) and found a score of 2.5/5 with fraud complaints about non-delivery and scams. That's not the AI tool you want.
  • Permission spam: If an app asks for camera, microphone, location, and storage access all at once before you've even opened it, bail. The real Macaron requests permissions on-demand.
  • Sketchy download links: If a site sends you to a download link that's not HTTPS or redirects through multiple domains, close the tab.

Verification Tips

My paranoid checklist:

  1. Only download from official sources: App Store or macaron.im
  2. Verify the developer name: Must say MINDAI
  3. Check the privacy policy link: Should point to macaron.im/privacy-policy, not some random Blogspot page
  4. Read recent reviews: As of June 2026, App Store reviews are positive on usability with no privacy complaints
  5. Scan for malware: I ran the app through VirusTotal after downloading (zero flags)
  6. Confirm via Product Hunt: The official launch is documented on Product Hunt and Yahoo Finance

One additional tip from a security researcher I follow on X: use tools like GoPlusSecWareX to check for phishing before clicking download links. I haven't needed it for Macaron since I go straight to the App Store, but it's worth having.

What We Could Not Independently Verify

This section is important because privacy writing gets sloppy when it treats policy language as proof.

Here’s what I could not independently verify from public information alone:

  • Whether all stored user data is encrypted at rest with AES-256 in every backend system
  • Whether all backups are deleted on a specific timeline after account deletion
  • The complete current list of third-party AI providers shown inside the app for every region
  • Whether each third-party AI provider deletes or retains data exactly as Macaron contractually requires
  • Internal employee access controls, audit logs, and reviewer workflows
  • Whether every Android listing shown in every region is officially controlled by MINDAI
  • Whether there have been minor, private, or undisclosed security incidents
  • Whether 2FA is available for all users and all login methods
  • Whether app behavior always matches policy language across future updates

None of that means Macaron is unsafe. It means these are not things I can prove without internal documentation, independent audit reports, or direct confirmation from the company.


Age Requirements and Who Should Not Use the Service

Macaron’s Terms say users must be at least 18 years old to use the service. The App Store may show a 16+ age rating, but that is a platform content rating, not the same as Macaron’s contractual age requirement.

Who should not use Macaron:

  • Users under 18 unless the service terms and guardian requirements clearly allow it in your situation
  • Anyone planning to upload secrets, passwords, ID numbers, payment card details, or private keys
  • Employees handling confidential company files without IT approval
  • Medical, legal, or financial professionals entering regulated client data without a signed agreement and compliance review
  • Anyone who needs offline-only, local-only AI processing
  • Anyone who cannot accept third-party AI provider processing
  • Anyone who needs guaranteed deletion from all backups immediately after account deletion

If your use case involves high-risk personal, health, legal, financial, employment, insurance, or child-related data, treat Macaron like any other cloud AI product: useful, but not the right place for unreviewed sensitive records. For more context on the privacy philosophy behind those boundaries, the Macaron app safety guide explains what “private by default” is meant to cover and where users still need to make deliberate privacy choices.

What We Recommend

Bottom line after three months of testing: Macaron AI appears safe based on its privacy-first design, encryption, and positive early reviews. I haven't found any major breaches, user complaints about data leaks, or sketchy third-party integrations as of June 2026.

That said, no app is 100% risk-free. Your job is to minimize unnecessary exposure. (And if you're still mid-install, the download guide walks through confirming you're on the real app before any of this matters.)

Safe Setup Checklist

Here's the exact setup I use:

Blog image

Before downloading:

  • ✅ Verify you're on the official App Store or macaron.im
  • ✅ Confirm developer is MINDAI
  • ✅ Read the privacy policy (or at least skim the sections I highlighted above)

First-time setup:

  • ✅ Use a unique password (not reused from other accounts)
  • ✅ Enable 2FA if available (I checked — not implemented yet, but worth monitoring)
  • ✅ Use a personal email, not your work email

After account creation:

  • ✅ Grant permissions only when prompted, deny anything you don't immediately need
  • ✅ Email privacy@macaron.im to opt out of non-essential analytics
  • ✅ Test a data export request to see what's being stored (Settings → Request Data Export)

Ongoing maintenance:

  • ✅ Update the app promptly when new versions drop (security patches matter)
  • ✅ Audit your active tools monthly — delete ones you're not using
  • ✅ Avoid sharing sensitive financial data in chats unless you've verified encryption
  • ✅ Request data deletion if you stop using the app

What I personally keep off:

  • Location access (not needed for any of my tools)
  • Third-party analytics (opted out via email)
  • Corporate email visibility (switched to personal email)

Risk assessment by use case:

FAQ

Is Macaron AI safe to use?

Yes, with caveats. The app uses strong encryption and doesn't sell data, but you should still grant permissions cautiously and opt out of non-essential analytics. If you're also deciding whether upgrading changes any of those protections, Macaron safety and privacy practices explains how the Free and paid plans compare and which parts of the experience actually change.

What data does it collect?

Basic info (name, email), user content (chats, uploads), and device/usage data. The key difference from other AI apps: no selling for targeted ads.

Can I delete my data?

Yes. Email privacy@macaron.im with a deletion request; processed per policy. I tested this and got confirmation within 48 hours.

Does it track me?

Usage data may track activity across the app for analytics, but you can object or opt out via email. If you're in the EU, you have stronger rights under GDPR.

What if I spot a fake Macaron app?

Report it to the App Store or Google Play. Verify the developer name (MINDAI) and download links (should be App Store or macaron.im only).

Is it safe for work-related tools?

Depends. If you're building productivity tools that don't involve proprietary company data, yes. If you're handling trade secrets or regulated financial info, consult your IT department first.

How does Macaron compare to ChatGPT or other AI apps on privacy?

Macaron's privacy-first approach is closer to DuckDuckGo than mainstream AI tools. ChatGPT, for example, uses your data to train models unless you opt out. Macaron says it may use Inputs and Outputs to develop, train, and improve its models after taking steps to remove identifying information; users can object to this use.

Can I use it offline?

Partially. Tools that store data locally (like journals or trackers) work offline, but AI-powered features require internet connectivity. I tested this by enabling airplane mode — basic data entry worked, but any tool that generates responses failed. For broader context on what information AI assistants can collect and which parts users can control, see how Macaron handles privacy and permissions before deciding what you're comfortable sharing.


Previous posts:

Hey, I’m Hanks — a workflow tinkerer and AI tool obsessive with over a decade of hands-on experience in automation, SaaS, and content creation. I spend my days testing tools so you don’t have to, breaking down complex processes into simple, actionable steps, and digging into the numbers behind “what actually works.”

Apply to become Macaron's first friends