Back to Gut Friendly

Privacy Policy

Last updated 23 July 2026

1. About this policy

This Privacy Policy explains how Gut Friendly ("Gut Friendly", "we", "us" or "our") handles personal information when you use the Gut Friendly mobile application, website, and related services (together, the "Service").

Some information you provide may reveal details about your health. We treat that information as sensitive and use it only to provide, personalise, protect, and improve the Service as described below.

2. Information we collect

Account and profile information

Your email address, display name, password credentials managed by our authentication provider, profile photo, account identifier, and account settings.

Health and preference information

Your digestive symptoms and their severity, symptom history, diagnosis status, known or suspected triggers, dietary restrictions, goals, obstacles, program stage, and the onboarding answers you choose to provide.

Meals, photos, and app activity

Food and meal logs, dates and times, ingredients, serving estimates, food ratings, barcode lookups, meal photos, symptom check-ins, program progress, milestones, reminder preferences, and data exports you initiate.

Device, usage, and diagnostic information

App version, device and operating-system information, IP address, approximate region derived from network information, interaction events, feature usage, and error or diagnostic information. When analytics is enabled, events may include details such as the type and severity of a symptom you logged or high-level information about a meal entry.

Communications

Information you include when you contact us for support, make a privacy request, or otherwise communicate with us.

3. How we collect information

We collect information directly from you when you create an account, complete onboarding, log meals or symptoms, upload photos, change settings, or contact us.

We also collect information automatically from the app and your device, and receive limited information from service providers that support authentication, hosting, analytics, content, and product lookups.

4. How we use information

  • create and secure your account;
  • sync your profile, meal logs, symptoms, and progress;
  • provide personalised food information, reminders, trends, and program features;
  • analyse meal photos and match visible foods to our food catalogue;
  • provide support and respond to requests;
  • understand feature use, diagnose problems, and improve the reliability and usability of the Service;
  • detect misuse, enforce our Terms of Service, and protect users and the Service; and
  • comply with law and exercise or defend legal rights.

Where applicable law requires it, we rely on your consent to collect and use health information and photos. We may also process other information to perform our agreement with you, operate and secure the Service, and comply with legal obligations.

5. Meal-photo analysis

If you choose to analyse a meal photo, the image is sent through an authenticated Supabase function to OpenRouter and the selected artificial-intelligence model provider, currently a Google model, so visible foods can be identified. Do not include people, documents, addresses, or other unnecessary personal information in meal photos.

Our analysis system stores a cryptographic fingerprint of the image and a sanitised analysis result for up to 24 hours to prevent duplicate processing and manage service limits. It does not store the source image in that temporary analysis record.

If you save the analysed meal to your log, the photo may be stored in private cloud storage linked to your account until you delete the meal, remove the photo, or delete your account. AI-generated results may be inaccurate and should always be reviewed.

6. When we share information

We share information only as needed to operate the Service, including with:

  • Supabase for account authentication, database hosting, private file storage, and server-side functions;
  • OpenRouter and its selected AI model providers for meal-photo analysis;
  • PostHog for product analytics when analytics is enabled;
  • Open Food Facts when you look up a product barcode;
  • Sanity to deliver editorial stories and other app content; and
  • professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or complete a business transfer.

We do not sell your personal information or use your health information for third-party advertising.

7. Device permissions and local data

The app asks for camera or photo-library access only when you use a photo feature, and for notification permission when you enable reminders. You can change these permissions in your device settings.

Some account sessions, onboarding answers, meal and symptom data, catalogue information, reminders, and preferences are also stored locally on your device so the app can work reliably. Deleting the app or clearing its storage removes those local copies, subject to your device's backup settings.

8. International processing

Our service providers may process information in Australia and in other countries where they or their subprocessors operate, which may include the United States and countries in the European Union. Those countries may have different privacy laws. We take reasonable steps to use reputable providers and appropriate contractual or technical safeguards.

9. Security

We use reasonable technical and organisational measures designed to protect personal information. These include encrypted network connections, protected account sessions, private storage buckets, and access controls that restrict signed-in users to their own records. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

10. How long we keep information

We generally retain account information and synced app data while your account is active and for as long as reasonably needed to provide the Service, resolve disputes, maintain security, and meet legal obligations.

Temporary meal-photo analysis records expire after approximately 24 hours. When you delete an individual meal log, its associated cloud photo is scheduled for deletion. After an account-deletion request is completed, we delete or de-identify associated personal information unless we must retain limited information by law or in secure backups for a short period.

11. Your choices and rights

  • Update your name, email address, password, meal logs, symptom entries, and reminder settings in the app.
  • Use the app's export tool to create a copy of selected profile, meal, symptom, program, and reminder data.
  • Delete individual meal logs and symptom entries from the app.
  • Revoke camera, photo-library, or notification permissions in your device settings.
  • Request access, correction, or deletion of your account and personal information by contacting us.

Privacy rights vary by location. We may need to verify your identity before completing a request, and lawful exceptions may apply.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information without appropriate consent, please contact us so we can investigate and delete it where required.

13. Questions and complaints

For privacy questions, requests, or complaints, email care@getgutfriendly.com. Please include enough detail for us to understand your request. We aim to acknowledge privacy complaints promptly and respond within 30 days where practicable.

If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner. You may also have the right to complain to a privacy regulator in your country.

14. Changes to this policy

We may update this Privacy Policy as the Service or applicable law changes. We will post the revised version here, update the date above, and provide additional notice in the app when a change is material.