IBDHealth
How it worksLabs
Log inGet started

Privacy

What we do with your health data

You are handing a piece of software the most private record you keep. This page says exactly what happens to it — in plain words, because a notice nobody finishes is not a disclosure.

Version 2026-08-30 · in effect since 30 August 2026

  • We do not sell your data, and we never will. There is no advertising on this product and no plan for any.
  • There are no trackers, no analytics and no advertising pixels anywhere on this site. Nothing you do here is reported to anyone.
  • Nothing is switched on by default. Processing your health data at all, and having a model read an uploaded report, are separate agreements you make one at a time and can withdraw one at a time.
  • Your data is stored in Belgium (Google Cloud europe-west1) — the same country this company is registered in.
  • You can export everything, and you can delete everything, from your account page, without asking us and without waiting for anyone.

Who holds your data

The data controller — the company legally responsible for your data — is:

IBDHealthKernenergiestraat 19 box W102610 Antwerpen-WilrijkBelgium

You can reach us at contact@ibdhealth.io. A person reads it. There is no contact form and no ticket queue.

What we collect, and why

Everything here is data you gave us. We do not buy data about you, we do not enrich your profile from other sources, and we do not track you across other websites.

Your account

Your email address, and the name and condition you enter when you sign up. Your email is health data here, not just contact details — “this address belongs to someone with ulcerative colitis” is itself a disclosure about you, and we treat it that way.

We never see your password. Sign-in is handled by Google Identity Platform, and there is no password column in our database at all. If our database were ever breached, there would be no credentials in it to steal.

What you log

Bowel movements, meals, medications, symptoms, sleep, daily check-ins, and anything you add a custom tracker for. The date and time each thing happened, and your time zone at the time — a trip abroad should not make it look like you stopped eating breakfast.

Reports you upload

If you upload a lab result or an examination report, we store the file and the values read off it. The file itself is kept in encrypted storage, never inside our database — so a routine database backup is never a pile of photographed medical records.

Records of access

Every read and write of your health data is written to an audit log, along with the time and the network address it came from. This is a security measure and it is not optional: it is how we could tell you what happened if something ever went wrong. That log cannot be edited or deleted, by us or by anyone who broke in.

Our legal basis

Health data is a “special category” under the GDPR, and processing it requires your explicit consent, given separately for each purpose. That is exactly how it works here: each purpose is its own switch, each one is recorded with the date and the exact wording you were shown, and each one can be withdrawn on its own from your account page.

When you withdraw a consent, we stop that processing. Withdrawing consent is not the same as deleting your data, and we deliberately do not treat it as such — turning off report reading should not silently destroy the results you already confirmed. Deleting is its own action, below.

Reading uploaded reports with AI

If — and only if — you switch it on, an uploaded lab or examination report is sent to a Google Cloud AI model running in the same Belgian data centre as the rest of our system, so that its contents can be transcribed into a structured record. It is not sent to a public AI service, and it does not leave that environment.

What the model produces is a draft you confirm, never a result. Nothing it reads appears in your trends or your report until you have checked it against the page yourself. It transcribes what is printed; it does not decide whether a value is good or bad, and it does not diagnose anything.

Consent for lab results and consent for examination reports are separate, because agreeing to have your bloods read is not agreeing to have a colonoscopy report read.

Who else touches it

These are the only companies involved. Each one is bound by a data processing agreement and may use your data only to provide the service to us.

CompanyWhat they doWhere
Google CloudRuns the database, the file storage and the API. Also issues your sign-in.Belgium (europe-west1)
Google Cloud Vertex AIReads an uploaded lab or examination report to draft what it says — only if you have switched that on.Belgium (europe-west1)
VercelServes the website itself. Sees which pages you request, not what you log.Global edge network, US company
Google AnalyticsCounts visits to our public pages, and only if you accepted the banner. Never loaded once you are signed in, so it never sees anything you log.Global, US company

Google is a US company, so although your data is stored and processed in Belgium, the arrangement relies on the European Commission’s standard contractual clauses for the transfers that regulation treats as international. We will not add a company to this list quietly: it changes with a new version of this page.

Cookies, and counting visits

We use Google Analytics to count visits to our public pages — this one, the home page, the blog, the diet and centre directories. It is the only third-party script on this website, and it is loaded only after you accept the banner. Decline and nothing is set: no cookie, no request to Google, nothing.

It is never loaded on a page you have to sign in to see. Not your timeline, your trends, your lab reports or your account. That is not a setting we chose in Google’s console; it is a list of permitted pages in our own code, and a new screen is excluded from it until somebody adds it deliberately. So nothing you log, upload or record is ever part of this, and the URL of a page about your own health is never sent anywhere.

What it does see, on those public pages: which page you read, roughly where in the world the request came from, and what kind of browser and device you used. We never send your name, your email address or your account — Analytics has no way to tell that a reader of the blog is also someone with an account here. Google’s advertising features are switched off for this property, so it cannot be used to build an advertising audience or follow you across other sites. We do not receive a copy of any of it; it stays in Google Analytics.

You can change your mind at any moment, and it takes effect immediately rather than at your next visit — turning it off stops collection on the page you are reading and deletes the identifier Analytics set.

How long we keep it

While your account is open, we keep what you logged — that is the point of a health log, and a tracker that quietly forgot last year is useless to you and to your clinician.

When you delete your account, you are locked out immediately and your data is erased 7 days later by a job that removes your logs, your profile, and every report you uploaded. The delay is deliberate and it is for your protection: if erasure were instant and irreversible, then anyone who got into your account could destroy your entire medical history in one click, with no way back. If you want it gone sooner, email us.

Two things survive that erasure, and we would rather say so than let you find out. The record of what you consented to and when is kept, because being able to prove we had your agreement is itself a legal obligation. The audit log is kept, because a security record that a deletion request can wipe is one an attacker can wipe too. Neither still identifies you: your email address, your name and your sign-in identity are gone, and what remains cannot be traced back to you by us.

Our database backups are kept for 7 days, so an erased record can still exist in a backup for up to that long afterwards. Editing backups to remove individual records would destroy the thing that makes them trustworthy, so we tell you the window instead.

Your rights

Under the GDPR — and, if you are in the UK, the UK GDPR — you have the following rights. The first four are buttons in the product; you never have to ask us.

  • See what we hold. Your log is on screen, and the export gives you the whole record.
  • Take it with you. The export on your account page is a machine-readable file of everything: every entry with its detail, every lab value, your full consent history, and a list of your uploaded documents.
  • Correct it. Anything you logged can be edited or deleted from the log itself.
  • Delete it. One button, on the same page.
  • See who else has had it. The export includes a disclosure record: the companies that run the service, and a dated list of every report of yours that was sent to a model to be read. If nothing was ever sent, that list is empty.
  • Withdraw a consent at any time, for any purpose, without affecting anything you agreed to before.
  • Object, or ask us to restrict what we do — email us and say what you want restricted.

We do not make automated decisions about you that have legal or similarly significant effects. Nothing in this product predicts, diagnoses, or scores you.

If we refuse a request, you can appeal it. Reply to the response we send you and say so, and a person will look at it again and give you a written answer with reasons. You do not have to accept the first no, and you do not need a lawyer to ask twice.

If you think we have got this wrong, please tell us first — but you have every right to go straight to a regulator instead. Ours is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), and you may also complain to the data protection authority where you live.

Keeping it safe

Your data is encrypted in transit and at rest. Access is limited to the small number of people who run the service, every access is logged, and the database is not reachable from the public internet. We hold no passwords, so there are none to lose.

If there is ever a breach affecting your data, we will tell the relevant authority within 72 hours and tell you without undue delay where there is a real risk to you. We would rather write an uncomfortable email than have you read about it somewhere else.

Children

IBDHealth is for people aged 16 and over. We do not knowingly hold data about anyone younger; if you believe we do, email us and we will remove it.

Changes to this page

This page has a version number, and every consent you give is stored against the version you were shown. If we change anything that matters, the version changes and we ask for your agreement again rather than assuming it. We will not quietly widen what we do with your data and rely on you not re-reading.

One thing this page is not

IBDHealth is a wellness tool. It records what you tell it and shows it back to you and your clinician. It does not diagnose, it does not treat, and it does not predict flares. If you are unwell right now, contact your IBD team or your local emergency number — not us.

The terms you agree to when you use it are on the terms page.

IBD centresDietsResearchBlog
IBDHealth

IBDHealth is a wellness tool and does not provide medical diagnosis or treatment.

ContactPrivacyConsumer health dataTerms