Legal
Privacy policy
Last updated . Applies to the Crohn’s Food Tracker app for iOS and Android and to this website, operated by Elco Dev, LLC.
The short version
- Your health entries belong to you. We never sell them and never share them with advertisers.
- Everything you log is stored in your own account and used to show you your own patterns and reports.
- The community is pseudonymous by default. Other users see your handle, not your name or email.
- You can export all of your data and delete your account, with all of its data, from inside the app.
- Health-platform sync (Apple Health, Health Connect) is off unless you turn it on, and reads only weight, sleep, water and steps.
What we collect
Account
An email address and, if you use Sign in with Apple or Google, the identifier those services provide. A display name or username you choose. An optional profile photo. Authentication is handled by Firebase Authentication (Google LLC).
Health and tracking data you enter
Meals and how they sat; symptoms, their severity and timing; stool form; medications and when you took them; hydration; weight; sleep, stress and activity; notes; barcode scans of packaged foods; answers to the intake survey (for example whether you are in remission or a flare, and known intolerances). This is sensitive health information and is the reason the app exists. It is used only to show you your own history, insights and reports, and to send you reminders you have asked for.
Health-platform data (optional)
If you turn on Health sync, the app reads weight, sleep hours, water intake and step count from Apple Health or Health Connect, and writes back the weight and hydration you log in the app. Nothing else is requested. Health-platform data is used for the same purposes as data you enter directly and is never used for advertising or shared with third parties.
Community content
Posts, comments and votes you make in the community, under the pseudonymous handle you chose. Reports you file against other content. If you delete your account, your posts and comments are anonymised rather than removed, so other people’s threads stay intact; their content and any identifying information are scrubbed.
Subscription
Purchases are processed by Apple or Google. We receive a subscription status (for example trial, active, expired) through RevenueCat, Inc. so the app can unlock Premium. We do not receive your payment details.
Diagnostics and usage
Crash reports (via Firebase Crashlytics) and in-app usage events such as which screens are opened and whether a paywall was shown (via Firebase Analytics). These are used to fix bugs and improve the app. Usage analytics are associated with your account so we can understand how features are used; they do not include the content of your health entries.
Push notifications
If you enable notifications, a device token is stored so we can send the reminders and pattern alerts you turned on. You can turn them off in the app or in your phone’s settings.
Website
This website does not set cookies and does not run advertising trackers. It uses Vercel Web Analytics, which counts page views and referrers without cookies or persistent identifiers; a visitor hash is discarded daily. Our hosting provider also records standard server logs (IP address, user agent, requested page) for security and capacity purposes.
How we use it
- To operate the app: store your entries, compute your insights and reports, sync across your devices.
- To send the reminders, alerts and occasional recaps you have opted into.
- To run the community and moderate it.
- To unlock Premium features when you subscribe.
- To find and fix bugs and understand which features are used.
- To respond when you contact support.
We do not use your data for advertising, and we do not sell it.
Who can see it
- You. Everything you log is visible to you in the app.
- Service providers acting on our behalf: Google (Firebase: authentication, database, storage, functions, crash reporting, analytics, push messaging), RevenueCat (subscription status), Apple and Google (app distribution and payments). They process data under their own privacy commitments and our instructions.
- Other community members see your posts, comments and handle — nothing from your health log.
- A care partner, only if you invite one, and only the panels you grant: hydration and medication adherence. Symptom, stool and meal data are never included and cannot be added.
- Your clinician, only when you choose to share a report yourself.
- Authorities, if required by law.
Where it is stored and for how long
Data is stored in Google Cloud (Firebase) data centres in the United States, encrypted in transit and at rest. We keep it while your account exists. When you delete your account, your entries, profile, device tokens and uploaded images are deleted, your community content is anonymised, and your subscription record is removed from RevenueCat where possible. Backups and logs age out on our providers’ schedules.
Your choices and rights
- Export: Profile → Export my data downloads everything you have logged, as JSON.
- Delete: Profile → Delete account removes your account and all of its data. This is immediate and cannot be undone.
- Notifications: turn each reminder on or off in Reminders, or disable all in your phone’s settings.
- Health sync: turn it off in Profile at any time; permissions can also be revoked in Apple Health or Health Connect.
- Community: change your handle, block users, or report content from within the app.
If you are in the European Economic Area, the United Kingdom, California or another jurisdiction with data-protection rights, the controls above are how you exercise access, portability and erasure. For anything else, email us.
Children
The app is not directed at children under 13 (or the age of digital consent where you live) and we do not knowingly collect their data.
Changes
We will post changes here and update the date above. Material changes will also be announced in the app.
Contact
Elco Dev, LLC
austin@elcodev.com