1. Quick summary
The short version, in plain English:
- You take photos of your stool. We send them to our AI to analyse — and only for that.
- Your photos and analysis results are stored in Google Firebase (Google Cloud), encrypted, tied to your account.
- We do not share your data with third parties for advertising, marketing, profiling, or sale.
- You can delete any entry, or your entire account and all data, at any time from inside the app.
- PoopID is a wellness tool, not a medical device. AI results are informational only and may contain errors.
The rest of this document explains every part of that in detail. If anything is unclear, write to mobixoftapps@gmail.com.
2. Who we are
PoopID ("PoopID", "the app", "we", "us", "our") is operated by Mint Wellness. PoopID is an iOS application (App Store ID: 6765519694) that uses artificial intelligence to analyse photos of stool, classify them on the Bristol Stool Scale, and produce a 0–100 gut health score with optional red-flag detection.
You can reach us at mobixoftapps@gmail.com for any privacy question, deletion request, complaint, or general inquiry.
3. Scope of this policy
This Privacy Policy applies to:
- The PoopID iOS application available on the Apple App Store.
- The website at https://poopid.app/ and its language subpaths.
- All communications between you and Mint Wellness regarding PoopID.
It does not apply to third-party services or websites that we link to — those are governed by their own privacy practices.
4. Information we collect
We collect only what we genuinely need to make the app work, improve reliability, and comply with the law. Specifically:
| Category | Examples | Source |
|---|---|---|
| Photos | The photos you take of your stool inside PoopID. | You, when you take a scan. |
| AI analysis output | Bristol Stool type, 0–100 health score, four-dimension scoring (consistency, hydration, comfort, safety), red-flag detection results, recommendations, educational notes. | Generated by our AI from your photo. |
| Account data | Apple Sign In identifier, optional display name, optional profile photo, optional health context you choose to enter (antibiotics history, baseline preferences, goals, triggers). | You, during onboarding or in settings. |
| Subscription data | Subscription status, plan type, trial status, transaction identifiers (anonymous), restore-purchase events. Apple processes the actual payment — we never see your card. | Apple App Store via RevenueCat (our subscription processor). |
| Device & technical data | Device model, iOS version, app version, language and region, time-zone, anonymous device identifier (Apple-issued, reset by user), crash reports, performance traces. | Your device. |
| Usage analytics | Anonymous events such as "scan started", "paywall viewed", "report exported", along with screen names and durations. Used in aggregate to improve the app. | Your interactions with the app. |
| Support correspondence | Email address and message content if you contact mobixoftapps@gmail.com. | You, when you write to us. |
We do not collect: precise GPS location, contacts, calendar, microphone, camera roll outside of the photo you actively take, advertising identifiers, browsing history, or any biometric data beyond what Apple Sign In provides as authentication.
5. Photos & AI processing
Photos are the most sensitive data PoopID handles, so we explain this in detail.
5.1 What happens when you take a scan
- You open PoopID and tap the camera button. The photo is captured locally on your device using Apple's standard camera APIs.
- The photo is uploaded over an encrypted TLS connection to Google Firebase Storage (Google Cloud).
- Our AI processing service reads the photo from Firebase Storage and produces an analysis: Bristol type, four-dimension score, red-flag flags, insights, recommendations.
- The analysis result is written back to Cloud Firestore, linked to your account.
- The photo remains in Firebase Storage so you can revisit past scans, until you delete it.
5.2 What we do NOT do with your photos
- We do not use your personal photos to train AI models. Our AI is improved using properly licensed and de-identified clinical imagery, never on user uploads.
- We do not share, sell, or licence your photos to anyone.
- We do not let advertising networks see them. PoopID has no ad SDK installed.
- We do not use them for face/identity recognition or any kind of profiling.
5.3 BlurShield privacy
Inside the app, PoopID's BlurShield feature blurs photos by default in your scan history and in the iOS app switcher, so a passing glance never reveals their content. You can tap to reveal individual photos. Photos remain encrypted at rest and in transit at all times — BlurShield is a visual privacy layer on top of that.
6. How we use your information
We use the data above strictly for the following purposes:
- To run the core service: upload, analyse, classify, and return results for the photos you submit.
- To track your progress: show your 30-day trends, streaks, history, and Bristol distribution.
- To localise the experience: render text and PDF reports in your chosen language.
- To process subscriptions: grant or revoke premium features through RevenueCat and Apple.
- To improve reliability: diagnose crashes and fix bugs, using anonymised performance data.
- To improve the app over time: aggregate, anonymous usage analytics tells us which features are valuable, never tied to individual users in marketing-readable form.
- To respond to you: answer your support emails or feedback.
- To meet legal obligations: tax records, fraud prevention, lawful requests.
7. Legal basis for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or any other GDPR-equivalent jurisdiction, our legal bases are:
- Contract performance — to provide the analysis and history features you signed up for.
- Explicit consent — for photo uploads (you give consent each time by tapping the scan button), for any optional health context you choose to enter, and for marketing communications (separate opt-in).
- Legitimate interests — to keep the service secure, prevent fraud, and improve reliability through anonymised analytics. We balance these against your privacy rights.
- Legal obligation — to retain transactional records as required by tax law and to respond to lawful requests from authorities.
You may withdraw consent at any time by deleting the relevant data inside the app, or by emailing us.
9. Service providers
We use carefully selected providers to make PoopID work. Each is bound by a Data Processing Agreement and processes your data only on our instructions.
| Provider | Purpose | Data accessed |
|---|---|---|
| Google (Firebase) | Photo storage, scan history, account data storage, AI inference orchestration, crash reporting, anonymous analytics. | Photos, account identifier, analysis results, device metadata, crash reports. |
| Apple | App distribution, Apple Sign In, App Store payments, subscription receipts. | Apple Sign In identifier, transaction records. |
| RevenueCat | Subscription management and entitlement checks. | Anonymous subscriber identifier, plan status, purchase events. |
If we ever add a new service provider that processes personal data, we will update this list and disclose it before activation.
10. Storage & security
We take security seriously because the data is sensitive. Our measures include:
- Encryption in transit. All data is sent over TLS 1.2+ between your device and our cloud.
- Encryption at rest. Firebase Storage and Cloud Firestore encrypt all data at rest using AES-256.
- Access controls. Only Mint Wellness staff who genuinely need access for support, maintenance, or debugging can reach production data, and only through audited, multi-factor-protected channels.
- BlurShield. Photos in your in-app history are visually blurred by default to prevent shoulder-surfing and accidental exposure.
- Authentication. Apple Sign In with secure tokens. We never store passwords because we don't ask for any.
- Data minimisation. We collect only what's needed and immediately remove anything that's no longer relevant.
No system is perfectly secure, and we do not guarantee absolute security. If a data breach occurs that affects your data, we will notify you and the relevant authorities within the timeframes required by applicable law.
11. Data retention
We keep data only as long as needed for the purposes for which it was collected:
- Photos & analysis results: until you delete them, or until you delete your account. There is no automatic expiry — you decide.
- Account data: until you delete your account.
- Subscription & transaction records: retained for up to 7 years after the last transaction to comply with tax and accounting law.
- Crash reports: retained for up to 90 days, then anonymised or deleted.
- Anonymous analytics: retained in aggregated form indefinitely; cannot be tied back to you.
- Support emails: retained for up to 24 months unless you ask earlier deletion.
12. Your rights
Depending on where you live, you have some or all of the following rights:
- Access. Get a copy of the personal data we hold about you.
- Rectification. Correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"). Delete any or all of your data.
- Restriction. Limit how we process your data.
- Portability. Receive your data in a machine-readable format.
- Objection. Object to processing based on legitimate interests.
- Withdraw consent. At any time, with no effect on processing already done.
- Lodge a complaint with your local data protection authority. EU residents: see edpb.europa.eu. UK residents: ico.org.uk. California residents: California Attorney General.
To exercise any of these rights, write to mobixoftapps@gmail.com. We will respond within 30 days (60 days in complex cases). We may need to verify your identity to protect against fraudulent requests.
12.1 California residents (CCPA / CPRA)
You have the right to know what personal information we collect, to delete it, to correct it, to opt out of any sale or sharing of your personal information (we do not sell or share), to limit use of sensitive personal information, and to non-discrimination for exercising your rights. PoopID does not sell your personal information.
13. How to delete your data
You can delete your data at any time without contacting us:
- Single scan. Open the entry in History → tap the menu → Delete. The photo and its analysis are removed from Firebase immediately.
- All scans. Settings → History → Clear all entries.
- Whole account. Settings → Account → Delete account. This removes all photos, scans, history, profile data, and your authentication record. Subscription auto-renewal must be cancelled separately in iPhone Settings → your name → Subscriptions, since Apple controls billing.
If you'd rather we delete your data on your behalf, email mobixoftapps@gmail.com from the address tied to your account and we'll handle it within 30 days.
Note: Deletion is permanent. We do not retain a hidden copy. Subscription receipts may persist for up to 7 years for tax compliance, but they are not linked to your photos or analysis history after account deletion.
14. International data transfers
PoopID's primary data store is Google Firebase, which operates globally. Your data may be processed in data centres outside your country of residence, including in the United States and the European Union. When we transfer personal data outside the European Economic Area or the United Kingdom, we rely on:
- European Commission adequacy decisions where available.
- Standard Contractual Clauses (2021) approved by the European Commission, supplemented by additional technical and organisational measures.
- The UK International Data Transfer Addendum to the SCCs.
Google Firebase complies with these safeguards as part of Google Cloud's Data Processing and Security Terms.
15. Children
PoopID is rated 12+ in the App Store and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created a PoopID account, please email mobixoftapps@gmail.com and we will delete the account and associated data promptly.
Parents who track a child's digestive health using their own account remain responsible for the data they upload about the child.
16. Health data sensitivity
PoopID processes information about your digestion, which may be considered "special category" or "sensitive personal data" under GDPR, CCPA, and similar laws. We treat this data with the highest care:
- We process it only with your explicit consent (each photo you submit is an explicit act of consent).
- We never use it to make automated decisions that produce legal or similarly significant effects on you.
- We never share it with insurers, employers, advertisers, or any other third parties.
- You can withdraw consent at any time by deleting the data.
PoopID is not covered by HIPAA because we are not a "covered entity" or "business associate" under that law. We follow comparable security and confidentiality practices regardless.
17. Advertising & tracking
PoopID does not display advertising. We do not embed advertising SDKs. We do not track you across other apps or websites. We do not request the App Tracking Transparency permission because we have no need for the IDFA. We are committed to keeping it that way.
18. Links to other sites
The PoopID app and website may link to external sites (for example, the App Store, your healthcare provider's portal, or external educational content). We are not responsible for the privacy practices of those external sites. Read their privacy notices before sharing personal information with them.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the app's features. When we make a material change, we will:
- Update the "Last updated" date at the top of this page.
- Notify you in the app via an in-app notice on next launch.
- If the change is significant, request your acknowledgment before continuing to use PoopID.
We will never reduce your rights under this policy without your explicit consent.
20. Contact
For privacy questions, deletion requests, complaints, or any other matter regarding your data, write to:
- Email: mobixoftapps@gmail.com
- Operator: Mint Wellness
- Subject of app: PoopID iOS (App Store ID 6765519694)
We aim to acknowledge every email within 5 business days and resolve substantive matters within 30 days.
This Privacy Policy is the only privacy policy that applies to PoopID. The version dated at the top is the current version.