Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains how Elimin8 ("Elimin8", "we", "us", or "our") collects, uses, and protects information when you use our mobile apps, website, and related services (collectively, the "Service"). Elimin8 records information about food and digestive symptoms, which is sensitive personal information, so the short version comes first: your diary is kept in an encrypted database on your device and saved to your Elimin8 account so you can get it back on a new phone; our pattern analysis runs on your device, not on our servers; and we do not read, sell, or train anything on what you log.
The Short Version
- Your food, symptom, bowel, and elimination-plan records live in an encrypted database on your phone, and are saved to your account so that signing out, losing your phone, or reinstalling does not lose your history.
- The pattern engine that finds your possible triggers runs entirely on your device. Your history is not uploaded to be analysed, and the patterns it finds are never sent to us.
- We store your diary so that we can give it back to you. We do not read it, sell it, use it to train AI models, or send it to advertising or analytics services.
- Meal photos are never stored by us. A photo you send for recognition is processed in memory and discarded we keep only a fingerprint of the image and the anonymous food result, which contain no personal information.
- You can delete your account from inside the app at any time. That erases your diary from our servers immediately and permanently.
Information We Collect
We collect the information you give us to run your account, the diary you choose to log, and the minimum needed to make food recognition and subscriptions work.
- Account information: your name, email address, and a hashed password (or an OAuth identifier if you sign in with a third-party provider).
- Subscription information: your plan, status, renewal date, and remaining AI scan allowance. Card details are collected and processed directly by Stripe, Apple, or Google we never see or store full payment card numbers.
- Food resolution requests: when you log a meal by photo or by voice/text, the description or image is sent to our servers so it can be identified and matched to nutrition data. It is processed for that request and not stored against your account.
- Your diary: the meals, symptoms, bowel movements, and elimination-plan entries you log, with the times you gave them. These are stored against your account so you can restore them on any device you sign in to. We ask for your explicit consent before storing any of it.
- Technical data: IP address, app version, device type, and timestamps in server logs, used for security, rate limiting, and diagnosing faults.
- Support communications: anything you choose to send us when you ask for help.
What We Do Not Collect
- The results of your pattern analysis. Your watchlist, the links it finds, and your reintroduction verdicts are worked out on your device and are never uploaded we can rebuild none of them, and do not try to.
- Your meal photos. They are discarded once a meal has been recognised.
- Your voice recordings. Speech is turned into text on your device; the audio never leaves it.
- Any health information in analytics or crash-reporting tools. Diagnostic logs are scrubbed of meal descriptions and record only a request identifier, the endpoint, and an error code.
How We Use Information
- To identify foods you log and return their nutrient and compound breakdown.
- To store your diary and give it back to you when you sign in on a new or reinstalled device.
- To cache anonymous food results (for example, what "two boiled eggs" contains) so the same food is not re-analysed for every user. This cache is not linked to any account.
- To create and secure your account, and to detect fraud, abuse, and automated misuse.
- To process subscriptions and to track your remaining AI scan allowance.
- To send transactional messages such as password resets, billing receipts, and security alerts.
- To comply with our legal obligations and to enforce our Terms of Use.
Legal Bases for Processing (UK/EEA users)
Where UK or EU data protection law applies, we rely on: performance of a contract (running your account and subscription); legitimate interests (keeping the Service secure and working, and controlling our costs through anonymous caching); legal obligation (tax and accounting records); and your explicit consent (Article 9(2)(a)) for storing the health information in your diary. We ask for that consent before any of it is saved to your account, and you can withdraw it at any time by deleting your account, which erases the diary we hold. Withdrawing does not affect processing carried out beforehand.
Cookies & Similar Technologies
The website uses a session cookie to keep you signed in and does not use third-party advertising cookies. The mobile app does not use cookies; it stores a sign-in token in your device's secure storage. Disabling cookies in your browser may prevent you from staying signed in on the web.
How We Share Information
We do not sell your personal information. We share it only with the providers needed to run the Service, and only the minimum each one requires:
- AI providers, to identify the food in a photo or a meal description. They receive the image or text for that request only, with no name, email, or account identifier attached.
- Nutrition databases (USDA FoodData Central and Open Food Facts), which receive a food name or barcode and nothing about you.
- Payment processors Stripe for web subscriptions, Apple and Google for in-app purchases.
- Authentication providers, if you choose to sign in with one.
- Infrastructure and email providers who host our servers and deliver transactional email, under contractual confidentiality obligations.
- Law enforcement or regulators, where required by law or to protect the rights, property, or safety of our users or the public.
International Transfers
Your information may be processed in a country other than the one you live in, including by the AI and infrastructure providers above. Where required, we rely on appropriate safeguards such as UK/EU standard contractual clauses for those transfers.
Data Retention
We keep your diary for as long as your account exists, because its purpose is to still be there when you come back to it. Deleting your account deletes it. We keep account and subscription records for as long as your account is active, and afterwards only where needed to resolve disputes or meet legal obligations such as tax record-keeping. Anonymous food-resolution cache entries contain no personal information and are kept indefinitely. Server logs are kept for a short retention period for security and debugging.
Deleting Your Data
You can delete your account from inside the app, and you do not need to ask us. Doing so permanently erases your diary every meal, symptom, bowel entry, elimination plan, and verdict along with the account itself. It is immediate and cannot be undone, so export anything you want to keep first. Some billing records may be retained where the law requires it. Deleting the app alone only removes the copy on that device; your account keeps your diary until you delete the account.
If you subscribed through the App Store or Google Play, cancel that subscription in the store as well we cannot cancel a store subscription for you, and deleting your account does not stop the store charging you.
Data Security
Your on-device database is encrypted at rest with SQLCipher, and traffic between the app and our servers is encrypted in transit with TLS. The copy saved to your account is not end-to-end encrypted: we hold it in a form we could technically read, so that resetting your password never destroys your history. What protects it is access control and policy rather than cryptography. Every request is scoped to your own account, your diary is never shown in our internal or admin tools, and access to production systems is restricted to the people who need it to run the Service. Passwords are hashed, and sign-in tokens can be revoked instantly by changing your password. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your Rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, to withdraw consent, and to complain to a data protection authority (in the UK, the Information Commissioner's Office). Your diary is covered by those rights: you can export it from the app at any time, and delete it along with your account from inside the app. For anything else, contact us using the details below.
Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with information, contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the date at the top of this page, and significant changes affecting health information will be notified in the app. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
Contact Us
Questions about this Privacy Policy, or want to exercise a data right? Contact us at privacy@elimin8.io.