Privacy Policy
Last updated: 2026-06-24
1. Summary
BellySignal is a privacy-first gut health tracker.
- The health data you record (stool, urine, water, food triggers, notes, and similar) is stored on your device.
- Some data may be copied or sent off your device only for (1) anonymous usage analytics and (2) optional account sync if and when we introduce it. We will update this policy and tell you before such changes take effect.
- We collect anonymous usage statistics to improve the App. This does not include the content of your health records, and you can turn it off at any time.
- We do not sell your data.
2. Who we are
The operator named above is the controller responsible for the limited personal data described in this policy. For privacy questions, contact [email protected].
3. Information we process
3.1 Data stored on your device
The following is kept in a local database on your device. Today this health content is not uploaded to our servers, although some data may leave your device as described in sections 3.2 (analytics) and 3.4 (future sync).
- Health records: stool form (Bristol scale), color, blood or mucus flags, urine color and hydration level, abnormal color and foam flags, water intake, food and lifestyle triggers, notes, and timestamps.
- Personalization inputs: sex and body weight used to estimate a water goal (stored on the device only and not transmitted).
- App settings: theme, language, reminder time, and similar.
Because there is no account, this information is not linked to any external identifier.
3.2 Anonymous usage analytics (PostHog)
We collect anonymous usage statistics to improve the App.
- What we collect: the fact that events occur (event names such as opening a screen or using a feature) together with standard technical information such as App version, device type, and operating system, and an anonymous, device-level identifier that does not identify you.
- What we do not collect: the content of your health records is never sent as part of analytics. We do not collect direct identifiers such as name, email, or phone number. Autocapture and session replay are turned off.
- Processor and location: we use PostHog as our analytics processor. Analytics data is processed on PostHog cloud infrastructure located in the United States (see section 6, International transfers).
- Control: you can turn analytics off at any time in Settings. Where your local law requires prior consent before such analytics (for example in the EEA and the UK), analytics will not run until you have given that consent.
3.3 Device and app infrastructure
- Local notifications: reminders are scheduled and shown on your device only. Notification text contains no health data, and no external push server is used.
- App rating prompts: in-app rating prompts are handled by the standard Apple App Store and Google Play features. We do not collect separate information through them.
- Firebase: currently included only for app-level initialization. No active data-collection feature is used. If we later enable any data-collection feature (for example analytics or messaging), we will update this policy in advance and obtain consent where required.
3.4 Future: accounts and sync (not active today)
We plan to introduce optional accounts (login) and cross-device sync. If and when this is enabled, account information such as an email address and your health records may be sent to and stored on a server for that purpose. At launch of that feature we will:
- update this policy to specify the data collected, the processors used, the storage location, and the retention period; and
- where applicable, apply it only after you activate the feature and provide any required consent.
On-device storage always remains. Sync is designed as an optional layer that places a copy on a server on top of the local data.
4. Legal bases for processing
Where data protection law (such as the GDPR) applies, we rely on the following legal bases:
- For providing core App features that run on your device, our legitimate interest in delivering the service you requested and, where applicable, performance of our agreement with you.
- For anonymous usage analytics, your consent where local law requires it, and otherwise our legitimate interest in improving the App. You may withdraw consent or object at any time by turning analytics off.
5. Sharing and processors
- We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are used under the US CCPA.
- Processor: PostHog (anonymous usage analytics only).
- We may disclose information where required by a valid legal request, to the extent required by applicable law.
6. International transfers
Anonymous analytics is processed by PostHog on infrastructure in the United States. Where your data is transferred across borders, we rely on appropriate safeguards offered by our processor, such as standard contractual clauses or an equivalent mechanism, to the extent required by applicable law. If you turn analytics off, no such transfer takes place.
7. Retention and deletion
- Your health records stay on your device. Today we hold no copy on our servers (subject to change if sync is introduced, see 3.4).
- You can erase your on-device records immediately using “Delete all data” in Settings.
- Deleting the App removes the records stored on your device (not recoverable unless you separately backed up or synced them).
- Anonymous analytics events are kept for as long as needed for the purpose described above, or in line with the processor’s retention policy, and then deleted.
8. Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR, the US CCPA, and similar regimes, including the right to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent.
- You can view, edit, and delete all of your health records directly in the App, since they are on your device.
- To exercise rights regarding the limited data we hold (anonymous analytics), or to ask a question, contact [email protected]. We will respond within the period required by applicable law.
- If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
- If you are a California resident, we do not sell or share your personal information, and we will not discriminate against you for exercising your privacy rights.
9. Analytics consent and withdrawal
You can turn analytics on or off in Settings. When off, no further analytics events are sent. Where local law requires prior consent (such as in the EEA and the UK), analytics stays off until you allow it.
10. Children
The App is not directed to children. We do not knowingly collect personal data from children under 16, or under the minimum age set by the law of your country (for example, under 13 under the US COPPA). If we learn that we have collected such data, we will delete it promptly.
11. Security
Health records stay on your device and are protected by your operating system’s app sandbox. No method is completely secure, and we recommend that you keep your device protected with a screen lock and encryption.
12. Medical disclaimer
BellySignal is a tool that helps you notice patterns. It is not a medical device, diagnosis, or treatment service, and it does not replace professional medical advice. If you have a health concern, consult a qualified health professional.
13. Changes to this policy
We may update this policy. When we do, we will post the new effective date here, and for changes that materially affect you we will give reasonable notice in the App or on this page in advance.
14. Contact
Privacy questions and data protection contact: [email protected]
Business information
- Operator
- 픽코 (Picko)
- Representative
- 유정현
- Business registration no.
- 824-17-02362
- Mail-order sales no.
- 2025-경기이천-0249
- Address
- 39-19 Gyeongchung-daero 2092beon-gil, Bubal-eup, Icheon-si, Gyeonggi-do, Republic of Korea
- [email protected]
- Phone
- +82 10-3962-2523