Privacy Policy
Last updated October 2026
Who we are
SafeBelly is made by New Day Industries LLC, which is responsible for your data under this policy. Questions, or a request to see, correct or delete your data: support@newdayapps.com.
Your health data is special-category data
Your conditions, triggers, diary and symptoms are health data — special-category data under UK/EU GDPR (Article 9). We collect it only with your explicit consent, captured in plain language when you set up your condition profile, and we use it for exactly one purpose: answering “can I eat this?” for you.
Encrypted, always
Your data is encrypted on your device (AES-256) and in transit (TLS 1.3), and kept with your account on servers we run in the EU, so your profile, diary and safe list follow you to any device you sign in to. Analytics run on infrastructure we host ourselves — your health data is never sent to third-party analytics, advertisers, or data brokers, and it is never sold. Period.
What we collect
Your account email, your condition profile, your safe list and saved meals, and the foods and symptoms you choose to log, plus the minimum operational signals needed to keep the service running (app version, crash reports). Crash reports never contain your health data.
Who else handles it, and why
A few services help us run SafeBelly, each seeing only what its job needs. When you photograph a meal, the photo goes to our AI provider, Anthropic, only to name the foods in it — your conditions are never sent with it. Sign-in is handled by Supabase (your email, never your health data). Subscriptions are handled by Apple or Google through RevenueCat (purchase records, never your health data).
Export and erasure
Your data is yours. Export your diary and symptom history at any time from the app. Delete your account and your health data is erased straight away; your sign-in email is removed within 30 days — permanently.