Privacy Policy
This Privacy Policy explains what personal information GutLedger (“we”, “us”) collects, how long we keep it, and how you can delete it. GutLedger is operated by Chris Jackson, United Kingdom. Contact: privacy@cyber-jack.uk.
1. Data we collect
The GutLedger mobile app and related services collect the following categories of data:
- In-app data (stays on your device): food logs, symptom entries, notes, preferences, and any attachments you add inside the app.
- Newsletter data: email address and first name (if provided) — only if you voluntarily subscribe.
- TikTok / YouTube linked accounts (optional, publisher tool only): OAuth access token, refresh token, open ID, and public profile display name — only if you connect those accounts.
- Website analytics: anonymous page views and approximate country, collected by Google Analytics 4.
- Support emails: the content of any email you send us.
GutLedger does not collect advertising IDs, precise location, contacts, SMS, call logs, microphone data, or camera data.
2. How long we retain your data
Each data category has a clear retention period:
- In-app data (food logs, symptoms, notes): stored locally on your device for as long as the app is installed. We do not receive or store a copy on our servers. Data is deleted the moment you uninstall the app or use the in-app “Delete all data” option.
- Newsletter subscription: stored on our servers only while you remain subscribed. When you unsubscribe, your record is deleted within 30 days. Unopened subscriptions inactive for 12 months are deleted automatically.
- TikTok / YouTube tokens: stored only while the account remains connected in the app. Tokens are deleted immediately when you disconnect the account, revoke access from TikTok’s or Google’s account settings, or when a refresh token expires.
- Website analytics: Google Analytics retains anonymised event data for 14 months, after which it is automatically deleted by Google.
- Support emails: retained for up to 24 months to help us answer follow-up questions, then deleted.
3. How to delete your data
You can delete every category of data at any time. We never charge a fee and never require proof of identity beyond verifying the email address on record.
- In-app data: open GutLedger → Settings → “Delete all data”, or simply uninstall the app. Both actions wipe the local database immediately. No server-side copy exists.
- Newsletter subscription: click the unsubscribe link at the bottom of any newsletter email. Your email address is removed from our list and deleted from our database within 30 days. You can also email privacy@cyber-jack.uk with the subject “Delete newsletter data” and we will confirm deletion within 7 days.
- TikTok / YouTube tokens: tap “Disconnect” on the account in the app, or revoke access directly from TikTok (Settings → Manage app permissions) or Google (myaccount.google.com/permissions). Tokens are deleted from our server on the next request cycle, and within 24 hours at latest.
- Website analytics: we cannot identify you in analytics data, so there is nothing account-level to delete. You may block GA4 entirely using your browser’s Do Not Track setting or a content blocker.
- Support emails / any other personal data: email privacy@cyber-jack.uk with the subject “Delete my data”. We will permanently delete everything linked to your email address and confirm within 7 days.
4. How we use your data
We use the data listed above only to:
- Provide the food diary, symptom tracking, and other app features.
- Send the newsletter if you have subscribed.
- Publish content to TikTok / YouTube if you have connected those accounts.
- Understand aggregate website usage to improve the site.
- Reply to your support emails.
We do not sell, rent, or share your personal data with third-party advertisers. We do not use your data for automated decision-making or profiling.
5. Data storage and security
In-app data never leaves your device. Newsletter and token data are stored on servers located in the United Kingdom and European Union, protected by TLS 1.2+ in transit and at-rest encryption. Access to our servers is restricted to the app operator and uses multi-factor authentication.
6. Third-party processors
We use the minimum necessary third-party processors to run the service:
- Google (Analytics 4): anonymous website analytics only.
- TikTok & YouTube APIs: only used if you explicitly connect those accounts to publish your own content.
- Web host (cPanel / Cloudflare): serves this website and handles DNS.
7. Children
GutLedger is not directed at children under 13 and does not knowingly collect data from them. If you believe a child has provided us with personal data, email privacy@cyber-jack.uk and we will delete it immediately.
8. Your rights under UK GDPR
If you are in the UK, EU, or EEA, you have the right to access, correct, erase, export, restrict, or object to processing of your personal data. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk). Send any such request to privacy@cyber-jack.uk and we will respond within one calendar month.
9. Changes to this policy
If we materially change this policy we will update the “Last updated” date at the top of this page and — if you are a newsletter subscriber — notify you by email before the change takes effect.
10. Contact
For any privacy question, or to exercise any right above, email privacy@cyber-jack.uk. Data controller: Chris Jackson, United Kingdom.