Privacy Policy
Who we are
GutStamp is built and operated by Srikumar Ramanan, trading as Zoryvix, a sole trader in Australia, ABN 16350546513. Postal address for privacy correspondence: Melbourne, Victoria, Australia — email hello@gutstamp.com.
In this policy, "we", "us" and "our" mean that sole trader. "You" means the person using the app.
The short version
- You do not create an account. We never ask for your name, email address or date of birth.
- Your diary, symptoms, program progress, challenge results and quiz answers are stored on your device. They are not uploaded to us.
- When you scan a meal, menu or label, the photo or the text you typed is sent to our server and on to our AI provider, used once to work out what the food is, and then discarded. Photos are never saved to any database of ours.
- We use a small number of named service providers for payments, analytics, crash reporting and hosting. They are all listed below.
- We do not sell your data, we run no advertising or ad-attribution software, and we do not use your data to track you across other companies' apps or websites.
- You can wipe everything the app holds on your device from Settings, at any time, without asking us.
The rest of this policy is the detail behind those points.
No account, no sign-in
GutStamp version 1 has no user accounts, no sign-in and no password. We cannot look you up, because we hold nothing to look you up by.
The only identifier attached to your subscription is an anonymous device identifier generated by our payments provider. It is a random string. It is not your name, your email address, or any Apple identifier that we can read.
What stays on your device
The following are written only to storage on your iPhone. They are not sent to us, and we hold no copy of them.
- Your diary — meals, symptom entries and their severity scores, stool entries and their Bristol scores, stress ratings, and the times you logged them.
- Your program state — which phase you are in, which day, which FODMAP group you are currently challenging, the dose you reached, whether you reacted, your result for each group, and your check-in streak.
- Your quiz answers — the symptoms, history, diagnosis status, suspected trigger foods and goals you entered during onboarding.
- Your preferences — your strict, moderate or relaxed diet mode, and any sensitivity toggles you set by hand.
- Your check-in reminder — scheduled by iOS on the device itself. Its text mentions your program day and phase, and is never sent to us.
If you delete the app, iOS deletes all of the above with it.
What leaves your device, and when
When you scan. Tapping scan sends our server the photo you took, or the text you typed, plus the app version and the anonymous device identifier described above. Photos are shrunk on your device before they are sent. Our server passes the photo or text to our AI provider to identify what the food is. We do not send the device identifier, or anything else about you, to the AI provider — it receives only the image or text and our own instructions. We then score the identified ingredients against our own food database and send the result back to your phone.
When you subscribe or restore a purchase. Our payments provider receives your purchase, trial and subscription-status events, tied to the anonymous device identifier. Apple separately processes the payment itself. We never see your card details, and we never receive your name or billing address.
When you use the app, if analytics are enabled. We send product-usage events — for example that a paywall was viewed, that a scan completed, that a diary entry was made, or that a FODMAP challenge started, paused or finished. These events carry an anonymous analytics identifier that is never linked to your subscription identifier, and none of them carry health information: no symptom scores, Bristol scores, stress ratings, diary contents, quiz answers, FODMAP group names or challenge results.
When the app crashes. Our crash-reporting provider receives a crash or performance report containing the device model, operating system version, app version and a stack trace. We do not attach your identity to these reports, and the app captures no screenshots and no session replays.
When you ask us to add a food. If you report a food our database does not know, we receive the food name and the scan context you were in. This request carries no device identifier at all — we cannot tell who sent it.
When the app checks for updates. Release builds contact our app-delivery provider on launch to see whether an over-the-air update is available. That request discloses your IP address and basic build information such as platform, app version and release channel.
What our servers store, and for how long
Our backend runs on Cloudflare Workers, using Cloudflare KV storage. It holds:
- Subscription status — whether the anonymous device identifier is entitled, which entitlement, and when it last changed. Kept for up to 400 days after the last update.
- Scan cache: identifications — the text description our AI provider produced from a photo, meaning the dish name and the list of ingredients it saw. Stored under a key derived from the photo's own contents, not from any identifier of yours. Kept for 90 days.
- Scan cache: results — the scored verdict for a given dish or typed description. Stored under a key derived from that text, not from any identifier of yours. Kept for 90 days.
- Rate-limit counters — how many scans the anonymous device identifier has run this hour and today. Kept for 1 hour and 24 hours respectively.
- Performance samples — a rolling window of the 500 most recent scans, each recording the time, the scan mode, how long it took, and whether it was served from cache. No identifier of any kind is stored with these.
- Food requests — the food name and context you sent, with no identifier. Kept for 30 days.
- Server logs — our server logs each request's method, path and size. When a scan is refused because there is no active subscription, or when the AI provider cannot identify a photo, the log line includes the anonymous device identifier. Retention follows Cloudflare's log retention for our plan.
Photos and typed text are not in that list, and that is deliberate. A scan photo exists only in memory while the request is being handled. It is never written to a database, a file store or a backup. There is no retain-then-delete step, because nothing is retained in the first place. What survives a photo scan is the text description of what was in it, described above.
Who processes your data
These are the only third parties that receive data from GutStamp. Each is used for one stated purpose and nothing else.
- Apple — processes your subscription payment and runs the App Store. Apple is the seller of record for in-app purchases.
- Anthropic (United States) — identifies what is in a scan photo or typed description. Receives the image or text only, never an identifier.
- Cloudflare — hosts our server and stores everything listed in the section above.
- RevenueCat (United States) — manages subscription and entitlement state against the anonymous device identifier.
- PostHog (European Union region) — product analytics. The app is configured to send analytics to PostHog's EU-hosted service.
- Sentry (European Union region) — crash and performance reporting. The app is configured to send reports to Sentry's EU-hosted service.
- Expo (United States) — delivers over-the-air app updates.
We have no advertising, marketing-attribution, data-broker or social-media software development kit in the app. We do not sell personal information, and we do not disclose it for advertising purposes.
Health information
Some of what GutStamp holds — your symptoms, your stool records, and which foods your body reacts to — is health information, and we treat it as such.
Health information collected by the app stays on your device, with one exception, stated above: the content of a scan you choose to run, which is sent for analysis once and never stored. We do not combine health information with your subscription identifier, and we do not disclose it to anyone outside the providers named above.
Deleting your data
Settings has a "Delete all my data" option that wipes everything GutStamp holds on your device. Exactly what it covers, and what it does not, is set out in our Data Deletion document, which forms part of this policy.
Children
GutStamp is for adults. It is not directed at children, and we do not knowingly collect information from anyone under 17. You must be at least 17 to use it.
Security
Data on your device is protected by iOS and by your device passcode. Traffic between the app, our server and every provider listed above uses encrypted connections. Our server-side keys are held as secrets and are never included in the app itself.
No system is perfectly secure. If we become aware of a data breach likely to cause you serious harm, we will notify you and the relevant regulator as required by law.
Changes to this policy
If we change this policy we will update the date at the top and publish the new version. The current version is always available in the app under Settings, and on our website.
Contact us, and how to complain
For any privacy question or request, email hello@gutstamp.com, or use the form at gutstamp.com/support.
To make a privacy complaint, email us first with "Privacy complaint" in the subject line. We will acknowledge it and respond.
If you are not satisfied with our response, you can escalate:
- In Australia — the Office of the Australian Information Commissioner, at oaic.gov.au, or by phone on 1300 363 992.
- In New Zealand — the Office of the Privacy Commissioner, at privacy.org.nz, or by phone on 0800 803 909.