Legal
Privacy Policy
We believe your health data is deeply personal. Here's exactly what we collect, why, and what we never do with it.
Last updated: April 10, 2026
1 Who we are
Belly-Well is a gut health and wellness tracking app published by Belly-Well ("we," "us," or "our"). This Privacy Policy explains how we collect, use, and protect information when you use the Belly-Well mobile application and this support website.
By using Belly-Well, you agree to the practices described in this policy.
2 What data we collect
We collect only what's needed to make the app useful for you. Here's a complete list:
- Meal logs — what you ate, meal type, description, photos you choose to attach, whether a meal is saved as a favorite, and any notes.
- Symptom logs — symptom descriptions, severity ratings, notes, and timestamps of when symptoms occurred.
- Mood and energy check-ins — your daily mood rating (great / okay / not great) and energy levels entered via the app.
- Food preferences — dietary restrictions, trigger foods, and preferences you set during onboarding or in settings.
- Daily reflections — free-text notes you write in the Daily Reflection feature.
- Journal ideas — meal ideas you save from the AI-generated suggestions.
- Account email address — only if you create an account or sign in with Apple. Anonymous use does not require an email.
- Device and session information — basic device type, operating system version, and app version, used only for crash reporting and debugging. No persistent device identifiers are stored.
3 How your data is stored
On-device by default. All health and journal data is stored locally on your device. If you do not create an account, nothing is sent to our servers.
Cloud sync when signed in. If you create a Belly-Well account or sign in with Apple, your data is synced to our cloud database (Supabase) so you can access it across devices or restore it if you switch phones. All data in transit uses TLS encryption. Data at rest is encrypted by our database provider.
Photos. If you attach photos to a journal entry, they are uploaded to secure cloud storage (Supabase Storage). Photos are not processed, analyzed, or shared with any AI service.
4 AI-generated content
When generating suggestions, we send a limited, anonymized summary of your food preferences and dietary restrictions to an AI service. We never send personally identifiable information — your name, email address, account ID, specific past meal entries, or symptom history are not included in these requests.
AI-generated suggestions are for general wellness inspiration only. They are not medical advice, diagnoses, or treatment recommendations. Always consult a qualified healthcare professional regarding your specific health conditions.
5 Third-party services
Belly-Well uses the following third-party services. Each operates under its own privacy policy.
- Supabase — database and file storage for cloud-synced accounts. Data is stored on servers in the United States.
- Apple Sign In — optional authentication. If you sign in with Apple, your email address may be shared with us by Apple per Apple's privacy policy. You may choose to hide your email using Apple's relay feature.
- AI API provider — anonymized preference data only (see Section 4 above).
- Crash reporting — device type, OS version, app version, and anonymized stack traces. No health data is included.
We do not use Google Analytics, Facebook SDK, advertising networks, or any other tracking SDK.
6 Data sharing and selling
We do not sell your data. Ever. We do not share your personal health information with advertisers, data brokers, employers, insurers, or any third party for commercial purposes.
We may share anonymized, aggregated, non-identifiable statistical data (for example: "X% of users track breakfast") for product improvement purposes only. This data cannot be traced back to you.
We may disclose information if required by law, court order, or to protect the rights and safety of users, but we will always use our best efforts to notify you first where legally permitted.
7 Data retention
We keep your data for as long as your account is active or until you request deletion.
- Active accounts — data is retained to provide the service.
- Inactive accounts — accounts with no activity for 24 consecutive months may be flagged for deletion. We will email you 30 days before taking any action.
- After deletion request — all personal data is permanently deleted within 30 days of a confirmed deletion request. See Section 10 for how to request deletion.
- Backups — encrypted database backups may retain data for up to 90 days before being fully purged. These backups are inaccessible except for disaster recovery.
8 Your rights under GDPR
If you are located in the European Economic Area, the UK, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access — you can request a copy of all personal data we hold about you.
- Right to rectification — you can ask us to correct inaccurate or incomplete data.
- Right to erasure — you can request deletion of all your personal data (see Section 10).
- Right to data portability — you can request your data in a machine-readable format.
- Right to restrict processing — you can ask us to pause processing your data in certain circumstances.
- Right to object — you can object to certain uses of your data.
- Right to lodge a complaint — you have the right to complain to your local data protection authority.
To exercise any of these rights, email support@belly-well.app.
9 Your rights under CCPA
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to:
- Know what personal information is collected about you.
- Know whether your personal information is sold or disclosed and to whom.
- Opt out of the sale of personal information. (We do not sell personal information.)
- Access your personal information.
- Request deletion of your personal information.
- Equal service and price, even if you exercise your privacy rights.
To submit a verifiable consumer request, email support@belly-well.app or use our data deletion form.
10 How to request data deletion
You can request complete deletion of your account and all associated data at any time:
- Online form — use our Data Deletion Request page.
- By email — send an email to support@belly-well.app with the subject line "Delete My Account".
We will confirm receipt within 5 business days and complete the deletion within 30 days. A confirmation email will be sent when deletion is complete.
11 Children's privacy
Belly-Well is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact us and we will delete it promptly.
12 Changes to this policy
We may update this Privacy Policy occasionally. When we make significant changes, we will notify you via in-app notification and/or email, and update the "Last updated" date at the top of this page. Your continued use of the app after changes constitutes acceptance of the updated policy.
13 Contact
Questions about this policy or how your data is handled? We're happy to talk.