Privacy Policy
Last updated: August 27, 2026
Bellynote ("Bellynote," "we," "us," or "our") is a food, symptom, and activity tracking app operated by Kyrsten Horvath, an individual developer, as a sole proprietorship (not yet a registered legal entity). This Privacy Policy explains what information Bellynote collects through the mobile app and the bellynote.app website, how we use and share it, and the choices you have.
By using Bellynote, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the app.
In short: Bellynote stores the meals, symptoms, activities, and photos you log so it can show you your history and run AI-powered correlation analysis. Meal photos, label photos, and chat messages are sent to our AI provider (OpenAI) to generate the analysis you see. We don't sell your personal information, and you can permanently delete your account and data at any time from the app.
1. Information We Collect
1.1 Account information
- Email address and password, used to create and authenticate your account.
- First name, last name, and birthday (optional), stored on your profile.
- A profile photo, if you choose to upload one from your camera or photo library.
1.2 Health and wellness data you log
The core of Bellynote is data you actively choose to record, including:
- Meal logs: foods eaten, food group classifications, ingredients, additives, and any notes or photos you attach.
- Symptom logs: the symptom, its severity (on a 0 to 10 scale), and timestamps.
- Activity logs: activities you record and when they occurred.
- Photos: photos of meals or ingredient labels you capture or upload for AI analysis, and photos of barcodes you scan.
- Chat messages: questions and messages you send to Bellynote's in-app AI assistant about your logged data, and the assistant's responses.
This information can reveal sensitive details about your health, including gastrointestinal or other physical symptoms and dietary patterns. See Section 4 (Health Information) below for how we treat it.
1.3 Health platform sync (optional)
If you turn on health syncing, Bellynote performs a read-only import of the period and menstrual-flow entries you authorize through Apple Health (on iOS) or Health Connect (on Android) and stores them as period logs in your account, so they appear alongside the data you log directly. Bellynote never writes data back to Apple Health or Health Connect. This access is governed by your device's health permissions. You can turn syncing off in the app, or revoke the permission in your device settings, at any time.
1.4 Device and usage information
- Camera and photo library access, used only when you actively scan a meal, a label, a barcode, or set a profile photo.
- Push notification tokens, if you enable notifications.
- Basic technical data such as device type, operating system, app version, and crash/error diagnostics, collected automatically to keep the app working correctly.
- Limited session-replay recordings, meaning a sample of app sessions plus sessions in which an error occurs, used to reproduce and fix bugs. All text and images are masked on your device before the recording is sent, so the meals, symptoms, and notes you log are not captured. See Section 3.
Bellynote does not use your location. A location permission may appear in system dialogs only because it is required by an underlying camera library dependency (react-native-vision-camera). Bellynote never requests or reads your location.
1.5 Purchase information
If you buy a Bellynote subscription, the purchase is processed by the Apple App Store or Google Play and by our subscription-management provider, RevenueCat. Bellynote receives your subscription status, purchase history, and the identifiers needed to restore your purchase on another device. Bellynote never receives your full payment card number.
2. How We Use Your Information
- To provide core app functionality: storing and displaying your logs, timeline, and calendar history.
- To generate AI-powered features: identifying foods from meal photos, extracting ingredients from label photos, and producing food/symptom correlation analysis, heatmaps, and trend views.
- To power the in-app AI chat assistant, which can reference your own logged data to answer your questions.
- To import menstrual-flow data from Apple Health or Health Connect when you enable syncing.
- To send push notifications you've opted into (e.g. logging reminders).
- To process subscription purchases and unlock premium features.
- To maintain, secure, debug, and improve the app, including through crash diagnostics and masked session-replay recordings.
- To communicate with you about your account or respond to support requests.
- To comply with legal obligations and enforce our Terms of Service.
We do not use your data to train third-party AI models, and we do not sell your personal information to anyone.
3. AI Processing & Service Providers
Bellynote is built on top of a small number of infrastructure and AI providers who process data on our behalf, solely to deliver the app's features:
| Provider | Purpose | Data involved |
|---|---|---|
| OpenAI | AI meal-photo recognition, ingredient label OCR, and the in-app AI chat assistant | Meal/label photos and chat messages, transmitted via our server-side integration, and never stored by us on OpenAI's systems beyond what's needed to return a response |
| Supabase | Database, authentication, file storage, and the server-side functions that talk to OpenAI | All account and log data described above |
| Sentry | Crash, error, and performance diagnostics, and session replay | Device and app information, crash and error reports, a user identifier and IP address, and session-replay recordings in which all text and images are masked |
| RevenueCat | Subscription management and purchase restoration | Your user identifier, email address, name, and purchase/subscription history |
| Expo / EAS | Building and delivering app updates, and routing push notifications | Device identifiers, push tokens, app version |
| Apple App Store / Google Play | App distribution | Information required by those platforms for install and updates |
These providers are contractually and technically restricted to using your data only to provide their service to us, and are not permitted to use it for their own independent purposes.
4. Health Information & Sensitive Personal Information
Bellynote is a personal wellness and self-tracking tool. It is not a medical device, and Bellynote is not a healthcare provider, health plan, or "covered entity" under HIPAA, so the data you log is not "protected health information" under that law. That said, we recognize that symptom and dietary data can be sensitive, and several state privacy laws (e.g. California's CCPA/CPRA) classify health-related information as "sensitive personal information" warranting extra care. We treat all health and symptom data you provide with that heightened care: we don't sell it, we don't use it for advertising, and we limit who can access it to the service providers described above. Session-replay recordings are masked so they do not capture the health data you log, and period data you import from Apple Health or Health Connect is treated exactly like data you enter directly.
5. How We Share Information
We share personal information only in these limited circumstances:
- Service providers: the infrastructure and AI providers listed in Section 3, strictly to operate the app.
- Health platform sync: when you enable syncing, Bellynote reads period and menstrual-flow data from Apple Health or Health Connect into your account as a direct result of your action. The data flows one way only; Bellynote does not send anything back to those platforms.
- Legal reasons: if required by law, subpoena, or legal process, or to protect the rights, safety, or property of Bellynote, our users, or others.
- Business transfer: if Bellynote is ever involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction, subject to this policy (or a materially equivalent one).
- With your consent: for any other purpose we've disclosed to you and you've agreed to.
We do not sell or "share" your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.
6. Your Rights & Choices
- Access & export: your logs, profile, and history are visible in-app at any time.
- Correction: you can edit or delete any log, tag, or profile detail directly in the app.
- Deletion: you can permanently delete your account from within the app's settings. This triggers a hard deletion of your authentication record, and your profile, logs, tags, chat history, photos, and any synced health data are all removed as a result. This action cannot be undone. Our Delete your account or data page has step by step instructions, covers removing specific data without closing your account, and includes a way to request either by email if you can't sign in.
- Notifications: you can disable push notifications at any time in your device settings.
- Health sync: you can turn off Apple Health / Health Connect syncing in the app, or revoke the health permission in your device settings, at any time.
- Subscriptions: you can manage or cancel a subscription at any time through the App Store or Google Play.
If you'd rather not use the in-app controls, you can exercise any of these rights by emailing us at support@bellynote.app. We will verify your identity (typically by confirming the request from your account's registered email) before acting on it.
California & other US state privacy rights
If you are a resident of California or another state with a comprehensive privacy law, you may have additional rights, including the right to know what personal information we've collected about you, the right to delete it, the right to correct inaccurate information, the right to receive a portable copy of it, and the right not to be discriminated against for exercising these rights. As noted above, we do not sell or share personal information, so there is no sale/share opt-out to exercise. You can submit a verifiable request via the in-app deletion tool or by emailing support@bellynote.app.
Users outside the United States
Bellynote is operated from, and its data is stored in, the United States. If you use Bellynote from the EEA, UK, or elsewhere outside the US, you understand that your information will be transferred to and processed in the United States, which may have different data protection laws than your country. Where local law grants you rights equivalent to those above (e.g. access, correction, deletion, portability, or objection to processing), we will honor requests sent to support@bellynote.app to the extent required.
7. Data Retention
We retain your account and log data for as long as your account remains active, so that Bellynote can keep showing you your history and running correlation analysis. If you delete your account, your data is permanently and irrecoverably deleted from our production database and storage as described in Section 6; residual copies in encrypted backups are purged on our normal backup rotation, typically within 30 days. Diagnostic data held by Sentry is retained on a rolling basis of roughly 90 days; subscription records held by RevenueCat are retained for the life of your account and as needed to meet tax and audit requirements. We may retain limited information where required by law or to resolve disputes and enforce our agreements.
8. Children's Privacy
Bellynote is not directed to, and is not intended for use by, children under the age of 13, and generally requires users to be at least 17 (see our Terms of Service). We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child has provided us information, contact us at support@bellynote.app.
9. Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit, row-level access controls on our database, and secure on-device storage for authentication tokens. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of Bellynote after a change takes effect constitutes acceptance of the revised policy.
11. Contact Us
Questions about this Privacy Policy or your data? Email us at support@bellynote.app.