Legal

Privacy Policy

Your privacy matters. Here's exactly how we handle your data.

Last updated: February 2026

1Information We Collect

Personal Information

When you create an account, we collect your name, email address, date of birth, gender, and timezone.

Health & Symptom Data

Tummie collects health data you voluntarily log, including: digestive symptoms (bloating, gas, cramping, nausea, heartburn, constipation, diarrhea, stomach pain), energy and fatigue levels, mood and mental clarity, sleep quality and duration, skin condition, headaches, joint and muscle pain, and bowel movement type and frequency. Symptoms are logged with severity levels and time of day.

Food & Nutrition Data

We collect meal logs including meal type (breakfast, lunch, dinner, snack), food descriptions, food tags, portion sizes, and timing. You may also record known food sensitivities.

Menstrual Cycle Data

If you opt in, Tummie tracks your last period start date, cycle length, period flow intensity, and calculates your current cycle day and phase (menstrual, follicular, ovulatory, luteal). This data is used to provide cycle-aware gut health insights.

Device & Usage Information

We collect device platform (iOS/Android), device type, operating system version, app version, and general usage data such as logging activity, feature engagement, and last active timestamps.

2How We Use Your Data

Core App Functionality

Your health data is used to calculate your daily Gut Score (0–100), track symptom patterns and trends, generate predictions about upcoming symptoms, create personalized health plans and protocols, and provide cycle-aware insights.

AI-Powered Features

We use AI (via OpenRouter, a third-party LLM provider) to generate personalized insights, detect patterns in your symptoms, create adaptive questions based on your logs, and produce "What to Expect Today" predictions. To do this, your recent health data (symptoms, food logs, sleep, mood, and cycle information from the past 7 days) is sent to this AI service for processing.

Notifications

With your permission, we send push notifications for daily log reminders, plan action reminders, period predictions, AI-generated daily insights, weekly summary reports, and achievement milestones. You can customize or disable each notification type individually.

3Data Storage & Security

Where Your Data Lives

Your data is stored in a Supabase PostgreSQL cloud database. Our backend is hosted on Railway.app. Authentication tokens and session credentials are stored locally on your device using Expo Secure Store (encrypted storage on iOS and Android). Cached app data is stored locally via AsyncStorage.

Security Measures

All data is transmitted over HTTPS. Sensitive credentials (auth tokens, session keys) are encrypted on-device using platform-native secure storage. API requests are authenticated with Bearer tokens that auto-refresh.

4Third-Party Services

Services That Receive Your Data

Supabase — database hosting and user authentication. OpenRouter — receives recent health data to generate AI-powered insights and predictions. Superwall — manages in-app subscriptions and paywalls; receives user attributes including name, gender, age, primary symptoms, and health goals to personalize offers. Apple App Store / Google Play Store — processes subscription payments. Railway.app — hosts our backend API. Expo — delivers push notifications and over-the-air app updates.

What We Don't Do

We do not sell your personal or health data. We do not use advertising SDKs or ad trackers. We do not share your data with data brokers. We do not use your health data for purposes unrelated to providing the Tummie service.

5Your Rights & Control

What You Can Control

You can customize which symptoms you track, enable or disable individual notification types and set their timing, choose whether to use cycle tracking features, sign out at any time to remove your local session, and manage subscription preferences through your app store account. Subscription automatically renews unless cancelled at least 24 hours before the end of the current period. You can manage or cancel your subscription at any time through your Apple App Store or Google Play Store account settings.

Data Deletion

To request deletion of your account and all associated data, please contact us at support@tummie.app. We will process deletion requests within 30 days. Note that data already processed by third-party AI services cannot be retroactively removed from those providers' systems.

6Children's Privacy

Tummie is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child under 13 has provided us data, please contact us at support@tummie.app and we will promptly delete it.

7Changes to This Policy

We may update this Privacy Policy as our app evolves. We will notify you of significant changes via email or in-app notification. Continued use of Tummie after changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.

8Contact Us

If you have questions or concerns about this Privacy Policy or how your data is handled, contact us at support@tummie.app. We aim to respond to all privacy-related inquiries within 48 hours.