Your check-ins stay private by default.

This notice describes the BloatFree iPhone app and this support site during private testing.

BloatFree is currently in private testing. Public-release privacy and seller details are not final. Last updated September 5, 2026.

What the app stores

The app can store practice history, reminder settings, a No bloating or experienced level, notes, and optional context tags on your iPhone. These are used to show the app’s history and factual pattern views. The app-owned container is marked to be excluded from iCloud backup where Apple honors that setting; BloatFree does not operate a cloud journal backup or sync service. Check-in content is not sent to BloatFree’s analytics, subscription, or support services in the baseline configuration.

Legacy photos

New BloatFree check-ins do not request a photo and the app does not perform face analysis. A prior private-development product could store local photos. This version retains read, delete, and recovery behavior only so those files are not stranded; Settings can remove legacy photos while preserving authored notes and context.

Network requests

RevenueCat may receive purchase and entitlement requests when its release configuration is present. If you separately opt in to anonymous product analytics, PostHog receives the allowlisted events described below and evaluates the governed rating-prompt flag. Neither path receives symptom intensity, context, a check-in note, a legacy photo, a health field, or an advertising identifier from BloatFree.

Purchases

Apple and RevenueCat process subscription transactions when Plus is connected in a release build. They may receive the app/user and transaction metadata required to validate, restore, renew, and manage a purchase, under their own policies. They do not receive BloatFree symptom intensity, context, or notes from this app. Deleting local app data does not cancel an Apple subscription or erase Apple/RevenueCat transaction records; manage those records through Apple and the provider’s controls.

Analytics

PostHog transport is off unless you opt in. Before opt-in, at most 100 allowlisted interaction events can be held in memory for the current app process only. Opting in sends that current-session buffer and future eligible events with one random app-scoped identifier used for event delivery and flag evaluation. The allowlist contains fixed product interactions and closed aggregate buckets such as practice completion, check-in creation, paywall viewing, purchase result, return-day bucket, and feature-flag exposure. It structurally excludes symptom intensity, context, legacy photos, notes, free text, RevenueCat identifiers, advertising identifiers, and health inferences. Automatic screen, element, push, lifecycle, crash, survey, profile, and session-replay capture are disabled.

Configuration and service metadata

The rating-prompt flag is evaluated through PostHog only after analytics opt-in. It starts off on every app launch and accepts only the governed control or rating_prompt assignment with the expected owner, schema, and a future expiry no later than October 31, 2026. Missing configuration, network or provider failure, unknown values, malformed payloads, and expiry leave the flag off. Local value and safety gates cannot be lowered remotely. Every event disables PostHog's IP-derived geolocation enrichment, although PostHog and ordinary network infrastructure necessarily process connection metadata such as an IP address under their own operations and retention practices.

Deletion and support

Journal-only deletion removes all check-in intensity, notes, context tags, and any legacy photos while keeping the rest of the app. Turning analytics sharing off stops PostHog transport, clears the in-memory buffer, rotates the local analytics identity, and removes queued PostHog data from this iPhone. The full app-owned reset additionally removes reminder requests, custom plan, feature-flag cache, onboarding state, practice history, the local RevenueCat entitlement/account cache, and the first-open analytics marker. These local controls do not erase events already delivered to PostHog or Apple/RevenueCat transaction records. Those records remain subject to the providers’ policies. The support page lists the current feedback options. This website does not collect support messages.

Changes

We will update this notice when the data practices change and identify the effective date above. A release may add a new provider only after its data flow is evaluated and disclosed. The App Store privacy answers will describe those changes before they ship.