GutLog
ProductFind carePricingAboutChangelogSupport
Get startedDownload ↗
Privacy · Last updated August 2026

Privacy Policy

Your journal is local by default. Here's exactly what GutLog stores, what can leave your phone, and why.

Overview

GutLog ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how information is handled when you use our iOS and watchOS application.

Your On-Device Journal

GutLog does not require an account. Most journal information you choose to enter stays on your device:

  • Health Data:Bowel movement logs, symptoms, meal data, mood entries, notes, and habit tracking data are stored locally using Apple's SwiftData framework.
  • Photos: Meal and stool photos you choose to capture. All photos are encrypted using AES-GCM before local storage, with the encryption key protected by the iOS Keychain. Photos stay on your device unless you turn on photo food estimates and ask for a specific meal photo to be analyzed, described below.
  • Preferences: Reminders, display choices, and app settings are stored locally.

Optional Independent Watch Sync

If you turn on Settings > Watch check-ins > Sync Watch check-ins with iCloud, GutLog uses your private iCloud database to move Watch check-ins to the iPhone when the phone app is closed or the devices are apart. This is an explicit opt-in; it is off by default. The sync record contains operation identifiers and status, the check-in event type, Bristol type when applicable, timestamp, service day, captured time-zone identifier, and an opaque notification-routing identifier when one exists. It does not include notes, photos, meal names, or your local journal database. Apple controls the iCloud account and its storage protections; GutLog does not use these records for analytics or advertising.

Turning the setting off stops new independent sync work on the Watch. Use Settings > Reset All Data to request removal of local data and GutLog Watch operation records in this private iCloud container. CloudKit delivery can be delayed while a device is offline; the iPhone remains the journal of record and will retry when it can connect.

How We Use Your Information

  • To show your journal, history, habits, and trends
  • To calculate rule-based insights and correlations on your device
  • To deliver reminders you choose to enable

On-Device Insights

GutLog's insights are calculated locally from the entries in your journal using rule-based analysis. Those charts and correlations work without sending your journal off your device.

Optional AI Summaries

GutLog Plus can create an optional plain-language summary after you turn this feature on and tap Create AI Summary. GutLog sends only bounded aggregate statistics from the previous 30 days: days logged; bowel-movement days and totals; distinct no-movement days; meal totals; Bristol-type, allowlisted symptom, stress-level, and time-of-day counts; average session time and its sample count; and fiber total and its sample count. GutLog does not send notes, photos, meal names, exact dates, location, contact information, or journal identifiers. The request also carries a pseudonymous RevenueCat app identifier to the GutLog server solely to verify your Plus entitlement; it is not used as a journal identifier.

The request is processed by OpenRouter using DeepSeek V4 Flash. GutLog requests only zero-data-retention providers, denies providers that collect prompts, and requires a structured response. DeepSeek may select only from fact identifiers created by GutLog; GutLog writes every sentence shown in the result from fixed templates. The feature is off by default and remains separate from GutLog's on-device charts and safety notices.

Photo Food Estimates

GutLog Plus can estimate what is on your plate from a meal photo after you turn this feature on and tap Identify Food. This is the one case where a photo leaves your device, and only the single photo you are looking at is sent. GutLog makes a smaller copy for the request; the photo saved with your journal stays encrypted on your device. The request carries no notes, no symptoms, no other journal entries, no dates, and no journal identifiers, alongside the same pseudonymous RevenueCat app identifier used to verify your Plus entitlement.

The photo is processed by OpenRouter using a vision model. GutLog requests only zero-data-retention providers, denies providers that collect prompts, and requires a structured response. Neither GutLog nor its server stores the photo: it is held in memory for the length of the request and never written to disk or to a log. The model may return only food names, portion sizes, and nutrition numbers, all of which GutLog validates before display; allergen wording comes from a fixed Gutlog list, not the model.

Estimates are approximate and are never saved until you add them to a meal, where you can edit or discard every value. Meals keep a record of whether their numbers were estimated from a photo or entered by you, and exports and doctor visit packs show that distinction. Possible allergens are guesses from an image and are not an allergy-safety check. The feature is off by default.

Data Storage & Security

  • Local Storage: Journal data is stored locally using Apple's SwiftData framework and iOS data protection.
  • Photo Encryption: Photos are encrypted with AES-GCM using a key stored in the iOS Keychain.
  • No Account: The GutLog app does not ask for an email address, password, or Sign in with Apple. This website offers a separate, optional newsletter; see Website Email below.

Third-Party Services

GutLog uses the following services for purchases and optional features:

  • Apple App Store: Processes purchases, renewals, cancellations, and refunds. Apple Privacy Policy
  • Website Email (Resend): If you voluntarily subscribe to the GutLog Journal or release notes on this website, your email address is kept in a consent ledger and email is delivered through Resend. Signup is double opt-in, nothing is sent until you confirm, every email carries an unsubscribe link, and unsubscribing stops all future sends. Journal data never leaves your device because of a newsletter. Resend Privacy Policy
  • iCloud / CloudKit: Stores limited Watch operation metadata only when you explicitly enable independent Watch sync. This optional sync is available separately from GutLog Plus; it does not receive your local notes, photos, meal names, or full journal database.
  • RevenueCat: Confirms subscription status using an app identifier and purchase information. It does not receive your GutLog journal statistics, notes, or photos. RevenueCat Privacy Policy
  • GutLog server, OpenRouter, and its eligible model provider: Verify Plus access and process the minimized aggregate payload when you request an optional AI summary, or the single meal photo when you request a photo food estimate. GutLog requires zero-data-retention routing and denies data-collecting providers, and neither payload is stored by the GutLog server. OpenRouter Privacy Policy

Data Sharing

We do not sell or rent your information and do not share journal data for marketing, advertising, or analytics. Purchase information is processed by Apple and RevenueCat to manage GutLog Plus. If you explicitly request an optional AI summary, the minimized aggregate payload described above is processed by OpenRouter and an eligible zero-retention model provider. If you explicitly request a photo food estimate, the single meal photo described above is processed the same way.

Data Retention

Your local journal remains on your device until you remove individual entries, use Settings > Reset All Data, or delete the app. Reset All Data removes the local journal, encrypted photos, preferences, reminders, both AI permissions, and derived insights from that device, and requests removal of the optional Watch operation ledger. CloudKit deletion may wait for the device to regain connectivity. Optional AI requests, including photo food estimates, are routed only through providers marked for zero data retention, and no photo is retained after the request completes. Deleting local data does not cancel an App Store subscription.

Your Rights

  • Access your data at any time through the app
  • Delete local data through Settings > Reset All Data
  • Manage a Plus subscription through your Apple Account subscription settings

Children's Privacy

GutLog is not intended for children under 13. We do not knowingly collect data from children.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above.

Contact Us

If you have questions about this Privacy Policy, contact us at support@mygutlog.com.

The app never asks for your email. This newsletter is optional. Leave anytime.

GutLog
A quiet gut-health journal. Built in San Francisco, stored on your phone.

Product

  • Features
  • Find care
  • Pricing
  • Changelog
  • Status

Company

  • About
  • Press
  • Careers

Support

  • FAQ
  • Contact
  • Data & deletion

Legal

  • Privacy
  • Terms
  • DMCA
© 2026 GutLog · mygutlog.comSystem status · all green