Privacy policy
FODMAP Tracker helps you log your meals and digestive symptoms. Your symptoms are health information: this page explains what stays on your device, what leaves it, why, and your rights. Version française.
Person responsible for the protection of personal information
The developer of FODMAP Tracker is responsible for the protection of personal information. For any question or request: cp.sauve1@gmail.com.
Data kept on your device
- Meals, ingredients, photos, symptoms, stress, supplements and reintroduction challenges are stored on your device, with the consent you give at first launch.
- Your profile also stays on your device: first name, profile photo (optional, never sent), intolerances or diet, diet phase and whether a dietitian follows you. You can edit it by tapping your photo, top right.
- No cloud sync (neither iCloud nor Google backup). On iPhone, your journal is only copied into the device backups you make yourself; on Android, it is excluded from automatic backup. You can also export a backup file from Settings.
- Apple Health (iPhone) or Health Connect (Android): sleep, menstrual cycle and steps, read only if you allow it, used in memory for the analysis, never stored, never sent. This data is used only to show its link with your symptoms: it is never sold, transferred to third parties or used for advertising. You can revoke access at any time in Apple Health or Health Connect.
- The free analysis runs on your device: Apple Intelligence on iPhone, Gemini Nano on compatible Android phones.
FODMAP+: analysis by Gemini (with your consent)
Only if you subscribe and have allowed sending (can be withdrawn at any time in Settings → FODMAP+):
- What is sent: the photo or description of the analyzed meal, and proof of subscription (App Store transaction ID or Google Play purchase token, and a random token created by the app). Never your symptoms, your journal or your Apple Health or Health Connect data. Avoid putting personal information in a photo or description.
- Where it goes: our relay on Cloudflare, then Google's Gemini API. These services may process data outside Quebec, notably in the United States.
- What our relay keeps: no photo or description. It keeps an analysis counter per subscription (40 days at most) and, for 1 hour at most, the subscription status (transaction ID, token, product, expiration date, environment), to avoid querying Apple or Google Play for every analysis. Technical logs (kept a few days by Cloudflare) contain no photo or description: only error codes, the model used and the number of tokens of each analysis. The counter and status are linked to your App Store subscription ID or to a fingerprint of your Google Play token (never the token itself); the Gemini API receives neither this ID nor the token.
- App Store offer codes: a subscription obtained with an offer code does not carry the app's token. Our relay then keeps a link between that subscription's ID and the random token of the first device that uses it, so it cannot be used on other devices. This link does not expire automatically; write to us to have it deleted.
- Google: the request is processed under the paid Gemini API terms, which exclude using requests to improve its products. Google may keep requests for a limited time to detect abuse.
FODMAP+ recipes and tools
Only if you ask for them and after separate consent: for recipes, the week of meals, the restaurant menu check, recipe adaptation and the grocery product check, the app sends to Gemini (Google), through our relay, your FODMAP diet phase, the current reintroduction challenge, your foods to avoid, your successful reintroductions, your intolerances or dietary needs and your request (type of meal, wishes, menu photo, recipe to adapt, or the scanned product's name and ingredient list). The monthly summary and the reintroduction plan are computed on your device: nothing is sent. This is health-related information. Your journal, symptom entries and Apple Health or Health Connect data are never sent. Our relay keeps nothing from this request (only the analysis counter). You can withdraw this consent in Settings → FODMAP+.
Barcode scanning (Open Food Facts)
When you scan a product, the barcode number is sent to Open Food Facts, an open database, to get the ingredient list. No account or identifier is sent; as with any website, Open Food Facts receives the connection's IP address. Open Food Facts policy.
Subscription
Payment is handled by Apple (App Store) or Google (Google Play). We receive neither your name, your email nor your payment information: our relay only checks with Apple or Google Play that the subscription is active.
Your rights
- Access and portability: Settings → Export my data.
- Correction: edit or delete any meal or entry in the app.
- Deletion: Settings → Delete all my data. For the relay counters, write to us.
- Withdrawal of consent: turn off sending to Gemini in Settings, at any time.
- Complaint: you can contact the Commission d'accès à l'information du Québec.
Security and incidents
Exchanges are encrypted (HTTPS) and access keys stay on the server, never in the app. In the event of a confidentiality incident presenting a risk of serious harm, we will notify the Commission d'accès à l'information and the people concerned.
Age and child profiles
The app is intended for adults. A parent or guardian can create a child profile (simplified, game-like mode for ages 8 to 12) on their device or their child's. The profile only opens after the parent's explicit consent, as Québec's Law 25 requires for children under 14.
- The child's journal is a separate file that stays on the device; Apple Health and Health Connect are never used in a child profile.
- Meal photos: off by default. The parent can allow analysis by the device's on-device AI only, or also by FODMAP+ (Gemini, through our relay, not kept) if the subscription is active.
- No account, no ads, no tracking. Settings and the full interface are protected by Face ID, fingerprint or the device passcode.
- The parent can withdraw consent or delete the profile and its journal at any time (tap your photo, top right → Profiles and kid mode).
Not medical advice
The app shows associations observed in your journal, not diagnoses. See a health professional for any medical decision.
Contact
cp.sauve1@gmail.com
Last updated: September 29, 2026