Privacy Policy
Version 1.1 · Effective date: 9 July 2026
Pip helps you understand your body by noticing patterns in what you eat and how you feel. We know that's sensitive information, and we treat it that way. This policy explains what we collect, why, and the control you have over it.
Who we are
Pip is provided by Ben Jones, an individual sole trader based in the United Kingdom. For any privacy question or to exercise your rights, contact us at ben@benjonesdesign.com. We are the data controller for the personal data described below. We are registered with the UK Information Commissioner's Office (ICO) under registration reference CSN9910810.
What we collect
- Account details — your email address and name (for example, when you sign in with Google or by email).
- Health & wellbeing data you choose to log — this is special-category data and the heart of the app: meals and food items, symptoms and how you feel, conditions, medications you note, elimination trials, and any notes you add.
- Insights we generate — the personal patterns and correlations Pip calculates from your logs.
- Camera use (on-device only) — when you scan a barcode or a menu, the image is processed on your device to read text/codes. We do not upload or store these photos.
- Waitlist email (this website) — if you join the waitlist here, we store the email address you give us so we can tell you when Pip launches. You can ask us to remove it at any time.
- Limited technical data — basic app/diagnostic information needed to run the service reliably.
We practise data minimisation: we only collect what the app needs to work for you.
How we use your data
- To provide the core service: store your logs and generate your personal insights and summaries.
- To send optional, gentle reminders (only if you enable notifications).
- To let you know when Pip launches, if you joined the waitlist.
- To keep the service secure and working.
We do not sell your data. We do not use your health data for advertising, marketing, or use-based data mining, and we do not share it with third parties for those purposes (consistent with Apple Guidelines 5.1.2–5.1.3). We do not use your data to build a profile of you for anyone else. The only third parties who touch your data today are the processors listed below, who act on our behalf. See Research below for the one optional, consented, de-identified exception we are building toward.
Legal bases (UK GDPR)
- Explicit consent (Art. 9(2)(a)) for processing your health/special-category data — you can withdraw it at any time (see Your rights).
- Performance of a contract (Art. 6(1)(b)) to provide the app you've asked for.
- Consent (Art. 6(1)(a)) for the waitlist — we email you only because you asked us to, and you can unsubscribe any time.
- Legitimate interests (Art. 6(1)(f)) for keeping the service secure and reliable, balanced against your rights.
Who we share it with (processors)
We use a small number of trusted service providers who process data on our behalf, under contract, and who may not use it for their own purposes:
- Supabase — secure database and authentication hosting (your logs, account, and waitlist email).
- Google Sign-In — if you choose to sign in with Google (authentication only).
- Open Food Facts — when you scan a barcode, we look up product info; we send the barcode, not your personal data.
- Vercel — hosts this website and processes the waitlist form request.
We require each to protect your data to the standard set out in this policy, and we'll update this list as the app evolves.
Where your data is stored / international transfers
Your data is hosted by Supabase in the London region (eu-west-2). Where any provider processes data outside the UK/EEA, we rely on appropriate safeguards (such as the UK IDTA or EU Standard Contractual Clauses). We do not store your personal health information in iCloud (consistent with Apple Guideline 5.1.3).
Research (optional, consented, and de-identified)
Pip's mission is to help people understand chronic conditions like IBD, and aggregated learning can help the whole community. You can choose — it's off by default — to let your data contribute to that. Here is exactly what that does, and does not, mean today:
- We share nothing externally yet. Turning "Research" on currently lets us learn from de-identified data inside Pip. No third party receives your data on the basis of this toggle.
- If that ever changes, we will ask you again first — clearly, naming who and why — and you can decline without losing any feature.
- De-identified and never sold. Any future research contribution will use de-identified or aggregate data (so you are not reasonably identifiable), governed by a Data Protection Impact Assessment and written data-sharing agreements that forbid re-identification and onward sale. We will never sell your data.
- Record-level data, if it were ever needed for a specific study, would stay inside a controlled research environment rather than being handed over — and only with your specific, separate consent.
- Withdrawal is forward-looking. You can switch Research off any time; we stop future use. Data that has already been de-identified or aggregated generally cannot be recalled, and we'll always say so before you consent.
Legal basis: your explicit consent (UK GDPR Art. 9(2)(a)); where we rely on scientific-research provisions we apply the Art. 89 safeguards. This section is deliberately conservative — the full programme is subject to a DPIA and legal review before any external sharing begins.
Analytics & cookies
Analytics is optional, and separate from your health record. If — and only if — you turn on analytics, we record that you used a feature, never what you ate or how you felt. Event records carry things like "a meal was logged" and how many items it had; they are technically prevented from carrying food names, notes or symptom detail. Analytics is a separate choice: declining it never reduces the app's features, and never affects any safety feature. We keep analytics records for 13 months, then delete them. Your health record itself is governed by the retention rules below, not by this section.
Analytics events are stored in our own infrastructure — we do not use third-party analytics services, and the app does not serve advertising. This website uses no non-essential cookies and does not track you.
How long we keep it
We keep your data while your account is active. You can export or delete your data at any time from within the app. When you delete your account, we delete your personal data within 30 days, except where we must retain limited records to meet a legal obligation. Waitlist emails are deleted once Pip has launched or when you ask us to remove them, whichever is sooner.
Your rights
Under UK GDPR you have the right to: access your data; correct it; delete it ("right to erasure"); restrict or object to processing; data portability (export); and withdraw consent at any time. Pip provides in-app export and account deletion so you're always in control. You also have the right to complain to the ICO (ico.org.uk) — though we'd appreciate the chance to help first.
Security
We protect your data with encryption in transit, access controls (row-level security so you can only see your own data), and optional device biometric lock. No system is perfectly secure, but we take this seriously and design for privacy first.
Children
Pip is not intended for children. You must be 18 or older to use it. We do not knowingly collect data from children; if you believe a child has used Pip, contact us and we'll delete the data.
Not medical advice
Pip is a wellbeing and self-tracking tool, not a medical device. It notices patterns; it does not diagnose, treat, or replace professional medical care. Always seek advice from a qualified clinician for medical concerns, and seek urgent care for red-flag symptoms.
Changes to this policy
We'll update this policy as Pip evolves and post the new version here with a revised effective date. For material changes affecting your health data, we'll ask for your consent again where required.
Contact
ben@benjonesdesign.com · Ben Jones, United Kingdom