GutMate Privacy Policy

How GutMate processes information and the privacy controls available to you.

Last updated August 24, 2026

GutMate: IBS and FODMAP diet (formerly FODMAP Scanner) (“GutMate,” “we,” “our,” or “us”) is a food-reference and self-tracking application for iOS and Android. This policy explains what information GutMate processes, why it is processed, when it is shared with service providers, and the controls available to you.

Effective date: August 24, 2026.

GutMate provides educational information and is not a medical device or a substitute for professional medical advice, diagnosis, or treatment.

Summary

  • The food and recipe catalogs and their search features work on your device.
  • Account creation is optional for offline catalog use. An account is required for features that use the shared backend, including AI scanning and cross-device synchronization where available.
  • Menu and plate images leave your device only after an in-app disclosure and your explicit image-processing consent.
  • GutMate does not sell personal information or use health-related entries or images for advertising.
  • You can export your data, revoke optional consent, and request deletion in the app or by contacting us.

Information we process

Account and authentication information

If you use an anonymous account, Firebase assigns a random user identifier. If you create or link an email/password account, Firebase Authentication processes your email address and authentication credentials. Firebase may also process IP address, user-agent, and security signals to provide authentication and prevent abuse.

We use the Firebase user identifier to isolate your records and to link your subscription entitlement across supported devices. We do not store your password in GutMate's application database.

Food, symptom, favorite, recipe, and scan information

Depending on the features you choose, GutMate may process:

  • favorite food and recipe identifiers;
  • recent searches stored on your device;
  • food-log entries, amounts, meal types, dates, and notes;
  • symptom entries, severity, duration, dates, triggers, and notes;
  • barcode values and returned product information;
  • menu, ingredient, and plate scan results;
  • images you capture or select for AI analysis or attach to supported records; and
  • preferences such as language, appearance, onboarding state, dietary profile, and consent choices.

These records are stored locally. When cross-device synchronization is enabled, supported records are also stored under your Firebase user identifier in Cloud Firestore. Images you choose to retain or synchronize are stored under your private user path in Cloud Storage for Firebase.

Because food and symptom logs may reveal information about your health or wellbeing, treat shared devices and exported files with care.

AI image and text analysis

For menu and plate scanning, GutMate minimizes the image before transfer by resizing it, removing unnecessary metadata, compressing it, and enforcing a size limit. The image or extracted ingredient text is sent through an authenticated Firebase Cloud Function and then to the configured AI inference provider through OpenRouter. The response contains detected foods, ingredients, portion estimates, FODMAP ratings, warnings, and recommendations.

OpenRouter documents that prompt and response content is not stored unless the customer opts into logging, and it provides Zero Data Retention routing controls. GutMate's production configuration must keep content logging disabled and use Zero Data Retention routing for image and health-related requests. OpenRouter may retain non-content request metadata such as token counts and latency. See OpenRouter data collection and Zero Data Retention.

Temporary Cloud Storage uploads use a dedicated private path and are automatically deleted after 24 hours. A retained image linked to your history or food log remains until you delete the record or account, subject to backup, security, and legal requirements described below.

Barcode lookups

When you scan a packaged-food barcode, GutMate sends the barcode value to Open Food Facts to request product and ingredient information. Open Food Facts receives the request and your network address as part of normal internet communication. See the Open Food Facts privacy policy.

Subscription and purchase information

Apple or Google processes your payment. GutMate uses RevenueCat to validate purchase receipts or tokens and determine whether the premium entitlement is active. RevenueCat may process the Firebase user identifier, app and device information, product identifier, purchase status, renewal or expiration state, and store receipt/token information. GutMate does not receive your full payment-card details. See RevenueCat's privacy policy.

Security, reliability, and diagnostics

Firebase App Check and, on Android, Play Integrity process application/device integrity signals to protect the backend from abuse. Google Play may provide aggregated crash, ANR, and device-compatibility information through Play Vitals. GutMate may record operational logs needed to diagnose failures, but logs must not include images, ingredient lists, symptom notes, email addresses, authentication tokens, or payment credentials.

If product analytics is enabled in a release, its in-app disclosure and the store Data Safety declaration must identify the provider and the exact fields sent. Analytics events must not contain food names, raw search queries, barcodes, images, health notes, or other user-authored content.

How we use information

We process information to:

  • authenticate users and isolate their data;
  • provide catalog, search, favorite, recipe, scan, and tracking features;
  • synchronize data at the user's request;
  • analyze menu, ingredient, and plate images after consent;
  • look up packaged foods by barcode;
  • validate subscriptions, restore purchases, and prevent fraud;
  • enforce service limits and protect the backend;
  • provide support, investigate errors, and improve reliability; and
  • comply with legal obligations and enforce our terms.

Where applicable law requires a legal basis, we rely on performance of a contract to provide requested app and subscription features, consent for optional image processing and any optional analytics, legitimate interests in security and reliability, and legal obligations where required. You may revoke optional image-processing consent in the app. Revocation prevents new image uploads but does not undo processing already completed or records you chose to retain.

Service providers and international processing

We disclose information only as needed to operate GutMate, comply with law, or protect users and the service. Current service providers may include:

  • Google Firebase and Google Cloud: authentication, App Check, Firestore, Cloud Storage, Cloud Functions, and backend security. See Firebase privacy and security.
  • OpenRouter and its selected model provider: AI inference for menu and plate analysis, subject to the production Zero Data Retention configuration described above.
  • RevenueCat: subscription validation and entitlement management.
  • Open Food Facts: barcode product lookup.
  • Apple: iOS distribution, purchases, and iCloud synchronization for iOS features that still use CloudKit.
  • Google: Android distribution, Google Play Billing, Play Integrity, and Play Vitals.

These providers may process data in the United States, European Union, or other locations where they or their subprocessors operate. Their contractual and legal transfer mechanisms apply to their processing. Firebase states that Firebase customers generally act as controllers/businesses and Google generally acts as a processor/service provider for customer data; GutMate remains responsible for its configuration and user-rights obligations.

We do not sell personal information. We do not share health-related entries or images for cross-context behavioral advertising.

Storage, security, and retention

GutMate uses transport encryption, Firebase Authentication, per-user database and Storage rules, App Check, server-authoritative subscription checks, and restricted backend credentials. No system is perfectly secure, so we cannot guarantee absolute security.

Retention is based on purpose rather than unsupported fixed promises:

  • local records remain until you delete them, reset the app, or uninstall it;
  • synchronized records and retained images remain until you delete the record or account, unless retention is required for security, dispute resolution, fraud prevention, or law;
  • temporary image uploads are deleted automatically after 24 hours;
  • Firebase authentication records remain until account deletion;
  • subscription and transaction records are retained by Apple, Google, RevenueCat, and GutMate as needed for purchase restoration, accounting, fraud prevention, support, and legal requirements; and
  • security and operational records are retained only as long as reasonably needed for those purposes.

Deleted data may remain for a limited period in encrypted backups or processor systems before normal rotation, and may be retained when legally required. We will not state a processor-specific deletion deadline unless it is contractually supported and operationally verified.

Your choices and rights

Subject to applicable law, you may have the right to access, correct, export, restrict, object to, or delete personal information, and to withdraw consent. GutMate provides these controls where applicable:

  • change image-processing consent in Profile;
  • restore or manage subscriptions through the relevant app store;
  • export supported user data in a portable format;
  • delete individual records; and
  • delete the GutMate account and associated application data.

Account deletion removes device-local GutMate data, calls the authenticated backend deletion flow for Firestore and Cloud Storage records, and deletes the Firebase Authentication account. Store transaction records and processor records that must be retained for legal, fraud-prevention, or accounting reasons may not be erased immediately. On iOS, CloudKit data remains subject to Apple's account and synchronization behavior; the app will remove GutMate-managed records it can access.

You may also request account and data deletion without the app by following the instructions on the public GutMate account-deletion page or emailing contato@2xm.com.br with the subject GutMate account deletion. We may need to verify that you control the account before acting on the request.

If you are in the EEA, United Kingdom, Switzerland, Brazil, California, or another jurisdiction with privacy rights, you may also contact your local data-protection authority. We will not discriminate against you for exercising applicable privacy rights.

Children

GutMate is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The final Google Play target-audience declaration and all age-related wording must match the released onboarding, store listing, and applicable regional requirements.

Changes to this policy

We may update this policy to reflect changes in the app, providers, law, or security practices. We will update the date above and provide additional notice where required. Material changes do not retroactively expand optional processing without any consent required by law.

Contact

Better Studio / 2XM
Email: contato@2xm.com.br
Privacy policy: https://janchristian.com.br/fodmap-app/privacy