Privacy Policy
Last updated: June 2026
Unsibo helps you track digestive patterns and daily lifestyle. Because the data you log is sensitive, we've designed the Service to collect only what's necessary and to give you granular control.
1. Who we are
Unsibo (the “Company,” “we,” “us”) is responsible for your personal data. For any privacy question or to exercise your rights, contact our privacy team at privacy@unsibo.com.
2. Your health data and the law
Unsibo is a wellness product, not a medical provider. We are not a HIPAA-covered entity, and the data you log is not “protected health information” under HIPAA. We do not claim to be HIPAA compliant. That does not mean your data is unprotected. It is covered by the US Federal Trade Commission Act and the FTC Health Breach Notification Rule, by US state privacy and consumer-health laws (including California's CCPA/CPRA and Washington's My Health My Data Act), and by the privacy laws of Australia and Canada. This policy explains those protections.
If you are a resident of Washington or Nevada, please also read our separate Consumer Health Data Privacy Policy, which describes how we handle consumer health data under those states' laws.
3. What we collect
Account data
- Email address (for sign-in)
- Display name (optional, your choice)
- Date of birth (used to confirm you are 16 or older; we do not store age)
- Authentication identifier from Apple, Google, or email plus password
Health and wellness data (sensitive personal data)
Only with your explicit, separate consent:
- Meals you log (food items, quantities, timestamps)
- Symptoms you log (severity scores, notes)
- Bowel movements (Bristol scale, urgency, optional notes)
- Medications and supplements you choose to track
- Meal spacing timings
- Phase selections (Reset, Rhythm, Routine)
- Reintroduction challenge results
- Breath-test results (if you choose to enter them)
- Apple Health or Health Connect data you choose to sync (sleep, HRV, weight, menstrual cycle)
We treat as health data not only the entries above but also what they reveal, including the fact that you use Unsibo and how you interact with it.
Quiz responses (web)
If you take the landing-page quiz, your answers are stored client-side in your browser. If we add a server-side quiz response store later, this section will be updated and you will be notified.
Technical data
- Device type, OS version, app version
- Crash logs (with personal data scrubbed)
- Anonymous product analytics (only with your separate, opt-in consent, disabled by default)
App install attribution (iOS)
On iPhone and iPad we ask Apple for an attribution token that tells us which App Store search or advert an install came from, and we pass it to our subscription processor so we can tell which of our own ads are worth running. It is Apple’s own first-party system: it needs no tracking permission, it carries campaign and keyword identifiers only, and it is never joined to anything you log. Nothing you record in the app is involved, and none of it goes to an advertising network.
What we do not collect
- Precise location
- Contacts, photos, or files beyond what you explicitly upload
- Browser history
- Advertising identifiers used to track you across other companies’ apps and sites (such as Apple’s IDFA), which is why we never show the tracking-permission prompt. The one exception is the first-party install attribution above.
- Cross-site tracking
4. Why we process your data
We process your data only for these purposes:
- Provide the core Service (logging, sync, history, on-device pattern insights), based on your explicit consent.
- Anonymous product analytics, only if you separately opt in. Never includes health data.
- Crash reporting to debug errors, with personal data scrubbed.
- Service and product emails, such as a verification link, a notice when your subscription ends, and the occasional note asking what we should improve. Every one of those notes carries a one-click unsubscribe. Emails never contain your health data.
- Legal compliance, such as keeping consent records.
5. Your two consents
When you create an account, you will see two separate, unchecked switches. Each is independent. You can change either anytime in Settings.
- Health-data tracking. Required for the app to do anything useful. Insights you see in the You tab are computed on-device from data you have already consented to store, so no separate consent applies.
- Anonymous product analytics. Opt-in only, never includes your health entries.
Revoking #1 will trigger account-deletion confirmation, because the app cannot function without it.
A third consent is asked for in context rather than at sign-up: sending a meal photo to the vision provider, described in section 7. Most people never use that feature, so putting it on the sign-up screen would ask for something they will not do. We ask the first time you open the photo check, and our server refuses to process a photo without it.
There is no switch for that one, because there is nothing running to switch off. A photo is only ever sent when you open the photo check and then take or pick one yourself, and we keep no copy of it afterwards. You control it by choosing whether to use the feature.
Any further server-side AI feature (for example weekly LLM-generated reflections) will ship behind its own separately-toggled consent at the time of launch, and this policy will be updated to describe it before it runs.
6. How we share your data
We never sell your personal information or your health data. We never share your health data for advertising, marketing, or targeted advertising, and there are no advertising or marketing SDKs on any screen where you log health information. We will not disclose your health data to a third party for a new purpose without your affirmative, express consent.
We share data only with the limited set of service providers we need to run the Service, each bound by contract to protect it to the same standard:
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase (database and auth) | Storage of your account and logs | All app data, encrypted at rest | United States |
| RevenueCat (subscriptions) | Manage your subscription, and measure our own App Store ads | Billing metadata, purchase receipts, and the iOS install attribution token described above. No health data | United States |
| Vercel (web hosting and AI Gateway) | Landing site; routes the meal photo to the vision model | Quiz answers stay in your browser. From the app, the meal photo you submit, in transit. No symptoms, notes, or other logs | United States |
| Google Gemini (vision, via Vercel AI Gateway / Vertex AI) | Identifying the foods in a meal photo you choose to check | The single meal photo you submit, taken or picked. Never your symptoms, notes, or other logs | United States |
| Sentry (crash reporting) | Debug app errors | Scrubbed crash logs only, no health data | United States |
| PostHog (product analytics) | Opt-in analytics | Allowlisted events only, never includes health data | United States |
| Resend (email delivery) | Sending account, verification, and product emails | Your email address. No health data | United States |
| Apple and Google (auth and IAP) | Sign-in and subscriptions | Auth identifiers, purchase receipts | per platform terms |
7. AI features
One feature sends data to an AI provider, and only when you ask it to: the photo meal check. It is a Pro feature behind its own separate consent, which we take the first time you use it. When you take a meal photo, or pick one from your own library, that single image is sent to Google Gemini (via the Vercel AI Gateway, running on Google Vertex AI) for one purpose: listing the foods it can see. We require that the provider does not train its models on it, and we configure the gateway to request zero data retention. The FODMAP rating you then see comes from our own food catalog, not from the model. The vision provider receives that one image, and none of your symptoms, notes, or other logs travel with it.
The insights you see in the You tab (trigger ranking, symptom trends, meal-spacing summary) work differently: they are computed on your device from your own logs, then displayed, so no AI provider is involved in them. No automated process makes a decision that produces a legal or similarly significant effect about you.
Picking a photo does not give us access to your photo library. Your device shows you its own picker and hands us only the image you choose; we never browse, read, or store the rest of your photos. If that image carries a timestamp, we read it on your device to suggest when the meal happened, and you can change it before saving.
If we add further server-side AI features in the future (for example weekly LLM-generated reflections), they will ship behind their own separately-toggled consent and this section will be updated to describe exactly what is sent, to whom, and for how long.
8. Where your data is stored
Your data is stored and processed in the United States by the providers listed above. If you use Unsibo from Australia, Canada, or another country, you are asking us to transfer your data to the United States, where it may be accessible to US courts and authorities. We protect every such transfer with a written data processing agreement with each provider.
9. How long we keep your data
- Account and health data: as long as your account exists
- Backups: purged within 30 days of deletion
- Consent records: retained for the lifetime of the account plus the period required by applicable law (up to 6 years where consumer-health-data law requires it)
- Anonymous analytics: aggregated and not personally identifiable after rollup
- Crash logs: 90 days
10. Your rights
Depending on where you live (including California, Washington, other US states, Australia, and Canada), you have some or all of these rights:
- Access: get a copy of your data, and, for health data, a list of any third parties it was shared with
- Correct: fix inaccurate data
- Delete: erase your data (in-app: Settings, then Delete account; or at unsibo.com/data-deletion)
- Data portability: export your data in a machine-readable format (in-app: Settings, then Export data)
- Withdraw consent: anytime, as easily as you gave it (in-app: Settings, then Privacy)
- Opt out of sale, sharing, targeted advertising, and profiling: we do none of these with your data, so there is nothing to opt out of
- Limit use of sensitive data: we use sensitive data only to provide the Service you asked for
- Non-discrimination: we will not treat you differently for exercising any right
Because we do not sell or share your personal information, an opt-out preference signal such as Global Privacy Control has nothing to act on and is already satisfied. To exercise any right, email privacy@unsibo.comfrom the address on your account (this is how we verify the request). We respond within 45 days. If we decline a request, you may appeal by replying to our response, and you may also complain to your state Attorney General or your country's privacy regulator.
11. Security
We use:
- TLS in transit for all data
- Encryption at rest (Supabase-managed disk encryption on our database)
- Row-level security on every database table, only you can read your own data
- Authentication tokens stored in the device Keychain (iOS) or Keystore (Android), never in plaintext
- Strict third-party SDK isolation, no advertising or marketing pixels on health screens
No system is perfectly secure, and we do not promise that it is.
12. Data breaches
If a breach affecting your data occurs, we will notify you and the relevant authorities without undue delay and within the timeframes required by applicable law. For breaches subject to the US FTC Health Breach Notification Rule, that means notifying affected individuals (and the FTC where 500 or more people are affected) within 60 days of discovery. We also follow Australia's Notifiable Data Breaches scheme and Canada's PIPEDA breach-reporting duties where they apply.
13. Children
Unsibo is not directed at children under 16. At sign-up we ask for your date of birth and block account creation if it indicates an age under 16. We do not knowingly collect data from children under 16. If you become aware that a child has provided us with data, contact privacy@unsibo.com so we can delete it.
14. Changes
If we make material changes to this Privacy Policy, we will notify you in the Service before they take effect, and for genuinely new uses of your data we will ask for fresh consent rather than rely on your continued use. The “Last updated” date above always reflects the current version.
15. Contact
- Privacy and data requests: privacy@unsibo.com
- Legal: legal@unsibo.com
Questions? Email privacy@unsibo.com.
