GutPilot Privacy Policy
Effective date: August 14, 2026
GutPilot ("we", "the app") is built on a simple principle: your health data belongs to you.
What we process
Your GutPilot account. Sign in with Apple is required to use GutPilot. We ask Apple only for a secure, app-specific user identifier; GutPilot does not request your name or email address. We store that identifier, a random GutPilot account ID, and security session records so you can sign in, use the same quota across devices, sign out, and delete your account. Refresh tokens are stored only as cryptographic hashes and expire after 60 days if not revoked earlier.
Menu photos and food queries. When you scan a menu or ask about a food, your photo or text, GutPilot account ID, and an App Attest-protected device identifier are sent to our server. The content is analyzed by an AI model (Anthropic Claude), and the result is returned to you. Photos are processed in memory and are not stored by GutPilot's server. Text queries are not stored by GutPilot's server.
Your food & symptom diary. Diary entries live on your device and, if you enable iCloud, in your private iCloud database. GutPilot's analysis server does not receive these diary entries. You can delete diary data in the app; iCloud data is managed through your Apple account.
Pseudonymous usage counters. To prevent abuse and enforce plan limits across devices, request counters are keyed to your random GutPilot account ID. App Attest device data is also processed to verify that requests came from a genuine instance of GutPilot. We do not use an advertising ID.
First-party product analytics. To understand where the app is difficult to use, GutPilot records a limited set of predefined events such as screens viewed, time spent on a screen, onboarding progress, feature starts and outcomes, retry/error categories, paywall choices, and purchase outcomes. Events include app version, build number, and language/locale. They use a new random session ID each time the app starts and are not linked to your GutPilot account, Apple identifier, advertising identifier, or a stable device identifier. Analytics never include menu photos, food names or queries, AI results, diary entries, symptoms, notes, or other free-form content. They are processed in our Cloudflare account and retained for up to three months. App Attest verifies the request before acceptance, but its device/key identifiers are not written into the analytics dataset.
Optional feedback. If you tap 👍/👎 on a result, we store the rating, dish name, verdict, timestamp, and random GutPilot account ID for up to 90 days to improve accuracy. We do not attach the menu photo to feedback.
What we DON'T do
- We do not request your Apple name, email address, or phone number
- We do not sell or rent your data, and we do not use it for advertising or marketing.
- No advertising, no ad trackers, and no third-party analytics SDK embedded in the app
- No storage of menu photos by GutPilot's server
Third parties
Analysis is performed via the Anthropic API under their commercial data policies. Anthropic states that commercial API inputs and outputs are not used for model training by default unless the customer explicitly opts in or submits provider feedback. Our infrastructure runs on Cloudflare. Subscriptions are processed entirely by Apple — we never see your payment details.
Health disclaimer
GutPilot provides dietary information based on published FODMAP research. It is not medical advice and is not a substitute for consultation with a qualified healthcare provider.
Your rights (GDPR / KVKK)
Use in-app Export to retrieve diary data and the in-app diary controls to remove it. Use Settings → Account → Delete account to permanently delete your GutPilot account, provider link, active sessions, and account usage counters. Account deletion does not delete the separate diary database on your device/private iCloud or cancel an App Store subscription; those controls remain available separately. You can also manage GutPilot's iCloud data through your Apple account. For privacy requests or questions: support@gutpilot.app
Changes
We will post any changes to this page with an updated effective date.