Founding beta sign-ups are open · Help shape a calmer way to navigate food

Privacy notice

Last updated: 3 September 2026

1. Who we are

Gutward is a trading name of Tibbles Labs Ltd. Tibbles Labs Ltd (company number 17399411, registered in England and Wales) is the data controller for the personal data described in this notice. We are registered with the UK Information Commissioner's Office, registration number CSN4406290.

For any privacy question, or to exercise any of the rights below, contact hello@gutward.com.

2. What we collect

Gutward is built to record structured, health-related information you choose to enter. As implemented today, that includes:

  • Account and profile information — your email address, encrypted password (never visible to us in plain text), display name and weight-unit preference.
  • Meals, symptoms, bowel records and food trials — what you log as eaten, symptom entries, bowel-pattern entries, and the staged food-reintroduction trials you run, including your recorded outcomes.
  • Health-related and dietary information — your chosen protocol and stage (e.g. AIP), and your personal food statuses (tolerated, not tolerated, monitoring, self-challenge blocked). This is special category health data under UK GDPR.
  • Weight check-ins — weight measurements you enter yourself, or that a connected professional records for you (clearly attributed either way).
  • Recipes, ingredients and uploaded photographs — recipes you create or import, including photographs you upload for AI-assisted ingredient extraction (see section 7 for exactly what happens to those photos).
  • Professional identities and profiles — if you declare a professional identity, the practice details, qualifications and contact information you provide.
  • Client/professional connections and consent — invitations, acceptances, declines and revocations between a client and a professional, and the timestamped record of those actions.
  • Appointments — appointment times, status and any note a professional marks as visible to the client, where a professional connection is active.
  • Private professional notes — a connected professional can write private working notes, which may contain information about you. Under Gutward's current permissions model these are visible only to the professional who wrote them — not to you, and not to any other professional. Hiding a note from your view in the app is a product permissions setting, not a legal position: it does not remove any right you otherwise have under UK GDPR to request access to personal data we hold about you (section 10). If you delete your whole Gutward account, these notes about you are deleted too (section 10).
  • Messages between you and a connected professional — the text of messages you or a connected professional send, plus metadata (who sent it, when, and when it was read). Messages can't be edited or deleted once sent. A professional's access to send or read messages depends on your current health-data consent staying in place, the same as their access to notes and plans — if you withdraw consent, their message access is blocked until you consent again; your own access to the conversation is never consent-gated. We don't monitor or read message content as a matter of course; access is limited to what the product needs to deliver and display messages, and to what's needed to investigate a specific report of misuse. Messaging is not suitable for emergencies or urgent, time-critical communication — see our Medical disclaimer.
  • Billing and subscription records — if you subscribe to Gutward+, we store the minimum needed to run your subscription: a link between your account and your Stripe customer ID, your subscription's identifier and status, and the entitlement (plan) it grants. Your payment card details are entered on and handled by Stripe, our payment provider — Gutward never sees or stores your card number (see section 11).
  • In-app notifications — a small notification record when, for example, a clinic or professional invites you to connect or a practitioner is assigned to a care team. By design these store only a fixed event type, who the notification is for, the identifiers needed to open the right screen, and read status — never names, email addresses, message text or any free-text content.
  • Technical, security and usage information — sign-in session cookies, IP address and timestamps captured by our infrastructure providers for security and abuse prevention (see section 6).

Some information described elsewhere on this site — self-service exportable reports — is not yet built, and we do not collect that data because the feature does not exist yet; this notice will be updated before it goes live. Professional-authored plans and professional/client messaging, however, are now available: where you have an active professional connection, a connected professional can create dietary plans (with dates, meals and notes) that you can view in the app, and either of you can message the other, subject to the consent rules above.

3. Why we process it, and our legal basis

We use this information to:

  • — provide the core service: recording, organising and displaying your food, symptom, bowel and trial history;
  • — operate connected-professional features, only where you have actively consented to a specific connection;
  • — maintain account security and prevent abuse (including rate-limiting AI recipe-photo processing);
  • — respond to support requests you send us.

For account and technical data, our lawful basis is performance of a contract with you (UK GDPR Article 6(1)(b)) and, for security/abuse prevention, our legitimate interests (Article 6(1)(f)), balanced against your rights.

For health-related information — meals, symptoms, bowel records, food trials, protocol/stage, personal food status, weight, and information a connected professional records about you — this is special category data under Article 9. Our condition for processing it is your explicit consent (Article 9(2)(a)), given through a dedicated consent step in the app before any health feature can be used (section 4).

This covers the health information a connected professional authors about you as well as what you record yourself: the dietary plans they assign you, any private working notes they keep, any message they exchange with you, and any note they mark as visible to you on an appointment. Gutward only lets a professional create or view this health content while your health-data consent is current — if it is not, these professional health features are blocked until you consent again. Ordinary appointment scheduling (times and status) does not depend on it.

If a professional's account is suspended, the same enforcement applies to every one of these professional health features — notes, plans, messaging, appointments and weight entries — not just to new client invitations.

4. Consent, and how to withdraw it

Creating an account is not, by itself, consent to health-data processing. After you create and verify your account, Gutward presents a dedicated Health Data Consent step with its own unticked checkbox, separate from agreeing to the Terms of Use. You cannot use Gutward's health features until you have actively given this consent. When you do, we record the evidence: who consented, when, and the exact wording and version you agreed to — so we can always demonstrate what you consented to.

You can withdraw this consent at any time. Because Gutward's consumer features fundamentally depend on processing your health information, withdrawing consent means deleting your Gutward account and its data — self-service in the app (section 10) or by emailing us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Professional access is a second, separate layer of consent on top of your account. A professional cannot see any of your information until you accept their invitation, and the relationship only remains active while you keep it so. You can revoke a professional's access at any time from the app, which immediately ends their ability to view your records. A professional can never browse or search for arbitrary Gutward users — access only exists where you have explicitly accepted a specific invitation. Direct connections and clinic relationships are separate consents: revoking one does not touch the other (section 5 explains the difference).

5. Professionals and clinics using Gutward

If you declare a professional identity, we hold that as a separate profile linked to your account. A declared profile does not automatically grant access to any client data — during the current controlled beta it is manually reviewed by us before it can be used to invite clients: we check the identity behind the profile, and where someone uses the protected title “dietitian” we check their registration against the HCPC register before activation. We do not claim to externally verify every kind of professional credential. Everything a professional can see about a client comes from that client's own explicit acceptance of an invitation, and is limited to what the client has recorded in Gutward (not a full clinical record held anywhere else).

Direct connections and clinic relationships are separate things. A direct connection links you with one professional. A clinic relationship links you with a clinic — a team workspace that a group of professionals share. You can hold both at the same time, each rests on its own invitation and acceptance, and ending one never automatically ends the other.

When you accept a clinic invitation, the practitioners assigned to your care team — possibly more than one person — can view the health information you share, read-only, while everything below stays true at the moment they look: your health-data consent is current, your clinic relationship is active, their care-team assignment on your relationship is active, their own professional account is active, and they are still an active member of that clinic. If any one of those stops being true — you withdraw consent, the relationship is revoked, they are unassigned, suspended, or leave the clinic — their access closes from the next request. Clinic owners and admins manage membership and care-team assignments, but a clinic role by itself gives no access to your health record: only currently assigned practitioners can see it.

Clinics also keep an organisational audit trail (who invited, assigned, or removed whom, and when). By database rule that trail can only hold a fixed set of non-clinical event details — it never contains health information, message content or notes.

6. Who we share data with

We do not sell your data. We use the following processors, confirmed against our current setup — no others:

  • Supabase — our database, authentication and backend infrastructure provider. Supabase hosts our production database in the EU (Ireland). Signing in sets an essential Supabase authentication cookie (see our Cookie notice).
  • OpenAI — used only when you choose to import a recipe from a photo, to extract structured ingredients from the image you upload. See section 7 for exactly what is sent and retained.
  • Open Food Facts — an external, open product database we query server-side when you scan a barcode. Only the barcode number is sent; no personal or account information is included in that request, and the result is not stored by Gutward.
  • Stripe — our payment provider for Gutward+ subscriptions. Checkout and billing management happen on Stripe-hosted pages, on Stripe's own domain: your card details go directly to Stripe and are never seen or stored by Gutward. Stripe tells us the state of your subscription (via signed webhooks), and we store only the identifiers and status described in section 2. No health information is ever sent to Stripe.
  • Vercel — the hosting and delivery provider that serves the Gutward website and app.

We do not currently use HubSpot, Google Analytics, Vercel Analytics, advertising pixels or any other analytics, marketing or tracking tool. If that changes, this notice and our Cookie notice will be updated first, and any non-essential tracking will require your consent before it loads.

7. Recipe-photo AI processing

When you photograph a recipe for import, the image is sent directly, over an encrypted connection, to OpenAI's API to extract a structured ingredient list. Gutward does not have a storage bucket for uploaded recipe photos — the photo itself is not retained by Gutward after the extraction request completes. We keep a metadata-only usage record (that an extraction happened, and when) for rate-limiting and abuse prevention; we do not log the image content or the extracted recipe text alongside it. The structured recipe you then choose to save is stored as a normal recipe in your account, exactly like a recipe you typed in by hand.

OpenAI processes the image under its own API data-handling terms. We have not independently confirmed OpenAI's exact retention window for API requests, so we won't state a specific period here until that's verified — we'll update this section once it is.

8. International transfers

Our Supabase database is hosted in the EU (Ireland), inside the UK/EEA adequacy framework. Recipe-photo extraction requests are sent to OpenAI, which processes data in the United States — a transfer outside the UK/EEA. Where we transfer personal data outside the UK or EEA, we rely on an appropriate safeguard, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, as provided under our processor's terms.

9. How long we keep it

We have not yet finalised fixed retention periods for every data category, and we won't claim a specific number of days or years until that review is complete. Our current, defensible approach is: your account data is retained for as long as your account is active, and deleted immediately and permanently when you delete your account (section 10). AI recipe-extraction usage metadata is kept only as long as needed for rate-limiting and abuse prevention, and is deleted with your account. We will publish fixed retention periods here once they are formally confirmed.

10. Your rights, account closure and deletion

Under UK GDPR, you have the right to:

  • — access the personal data we hold about you;
  • — have inaccurate data corrected;
  • — receive your data in a portable format;
  • — restrict or object to certain processing;
  • — have your data deleted (the “right to be forgotten”).

You can delete your Gutward account yourself, directly in the app: Settings → Account → Delete account, and also straight from the consent screen itself, so declining consent is never a dead end. You'll be asked to re-enter your password and give a final confirmation. Deletion is immediate and permanent, with no recovery period, and removes your entire account record: your profile and sign-in, all health tracking (protocols, food statuses and safety flags, meals, symptoms, bowel logs, daily health, food tests, and weight check-ins, including any entered by a connected professional), your recipes, meal plans, shopping lists and supplier records, your AI-import usage records, and your connections with professionals — including their appointments with you, any private notes they hold about you, any dietary plans assigned to you, and your message history with them, all in Gutward. Professional accounts cannot yet be deleted self-service and are refused by the in-app flow.

Gutward does not yet have a self-service “export my data” button. You can request any of the following by emailing hello@gutward.com from the address on your account:

  • — account closure;
  • — deletion of your data;
  • — access to the information we hold about you;
  • — a portable copy of your data, where applicable.

We will verify your identity and handle your request in accordance with applicable data-protection requirements. The email route remains fully honoured alongside the in-app deletion flow, including for professional accounts.

11. Payment information

Gutward+ subscriptions are processed by Stripe. When you subscribe, you are taken to a Stripe-hosted checkout page where you enter your payment details directly with Stripe; managing or cancelling a subscription happens on Stripe's hosted billing portal in the same way. Gutward never sees or stores your card number. What Gutward keeps is the minimum needed to know what your account is entitled to: your Stripe customer ID, your subscription identifier and its current status, and the plan it grants — used only to run your subscription and unlock Gutward+ features. Stripe processes your payment data under its own terms as a payment provider; where Stripe processes personal data outside the UK or EEA, that transfer is governed by Stripe's own documented safeguards. See our Terms of Use for the subscription, cancellation and refund terms.

12. Complaints

If you're unhappy with how we've handled your data, please contact us first at hello@gutward.com so we can try to resolve it. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk at any time.

13. Changes to this notice

We'll update this notice as Gutward's features change — in particular as billing, self-service data export and reports are built. We will update the effective date above whenever we make a material change, and for significant changes affecting how your health data is used, we'll aim to let you know directly, not just update this page silently.