Legal
Privacy Policy
Last updated: September 10, 2026
Find My Triggers ("we", "us", or "our") is committed to protecting your privacy. This policy explains what information we collect through our website (findmytriggers.com) and our web application ("the App"), how we use it, and your rights.
1. Information we collect
Account information
When you create an account in the App, we collect your email address. We use passwordless authentication (magic links) — we do not collect or store passwords.
Health and wellness data
When you use the App to track your food sensitivities, you may provide:
- Food and drink entries
- Symptom descriptions and severity
- Bowel movement details
- Medications and supplements
- Daily check-ins (sleep, stress, hydration scores)
- Menstrual cycle dates (if you enable cycle tracking)
- Your gut health profile (conditions, allergies, medications, health goals)
This data is yours. We store it to provide you with the tracking and analysis features of the App.
Voice input
If you use the voice input feature, your audio is sent directly to our AI processing service for transcription and structuring. Audio recordings are not stored on our servers. Only the structured text result is saved.
Purchase information
App Pro upgrades are processed by Dodo Payments. If you purchase the FMT Pro product through Gumroad, Gumroad may also create an app user and activate Pro access. Separate manual Gumroad products do not activate Pro access. We receive your email address and confirmation of purchase. We do not receive or store your payment card details.
Website analytics and advertising
Our marketing website uses Google Tag Manager, Google Analytics, Google Ads, and related DoubleClick services to understand how visitors find and use our site and to measure advertising. This may include IP address, browser and device information, page URL and title, pages visited, referral sources, campaign information, and interactions with the site.
When you follow a campaign link to the App, we may store coarse source and campaign identifiers in a secure first-party cookie for up to seven days. If you request a sign-in link, this attribution is bound to that specific sign-in attempt and used to record which source led to account creation. Campaign and creative identifiers are converted to keyed, non-readable IDs before being stored with the account event. We do not store referral URLs, email addresses, or health information in attribution events.
Marketing and contact forms
If you subscribe to a free resource, challenge, or marketing list, your email address and any form details you provide are processed by MailerLite. If you use our contact form, your contact details and message are processed by Tally so we can receive and respond to it. Please do not submit sensitive health information through the contact form.
The App itself does not contain any third-party analytics or tracking scripts. It records limited first-party product events, such as signup and onboarding completion, so we can measure activation and improve the service.
2. How we use your information
- To provide the service: Your health and wellness entries are used to generate insights, trigger analysis, and reports within your account.
- AI processing: Your entries are processed by AI to structure natural-language input into structured data, and to generate analysis reports. See Section 3 for details.
- To send transactional emails: We use your email to send sign-in links and important account notifications.
- To send requested marketing emails: If you subscribe to a free resource, challenge, or email list, we use your email address to deliver it and send related updates. You can unsubscribe at any time.
- To provide customer support: If you contact us, we may reference your account information to help resolve issues.
- To improve our service: We use limited first-party product events and aggregate statistics (such as signup source, onboarding completion, total users, entry counts, and feature usage patterns) to improve the product. Event metadata does not include your email address or health content.
3. AI processing and data privacy
Your entries are processed by AI models to structure your input and generate analysis. Here's exactly how that works:
- AI processing is handled via OpenRouter, which routes requests to AI model providers (currently Google Gemini and Mistral).
- We enforce Zero Data Retention (ZDR) on all AI requests. This means AI providers do not store your prompts or responses.
- OpenRouter does not store your prompts or responses by default. They store only metadata (token counts, latency) for billing purposes.
- Google's Gemini API terms state that paid API data is not used to train their models.
- Your data is sent to AI providers over encrypted connections (TLS) and is processed only to generate your results — it is not retained, shared, or used for training.
4. Data storage and security
- Encryption at rest: Your data is stored on servers with infrastructure-level AES-256 encryption. All storage volumes are encrypted by default.
- Encryption in transit: All connections to the App use HTTPS/TLS encryption.
- Access controls: Access to user data is restricted to authorised administrators for the purposes of customer support, troubleshooting, and service operation.
- No third-party data sharing: We do not sell, rent, or share your personal health data with third parties for marketing, advertising, or any purpose beyond providing the service.
What administrators can see
To operate the service and provide support, administrators may view: your email address, account status (free or paid), entry counts, activity timestamps, and system usage metrics. We do not routinely access the content of your individual diary entries.
5. Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| OpenRouter (Google Gemini for the analysis tool; Google Gemini or Mistral for tracking-app features) | AI processing (entry parsing, analysis) | Entry text/audio, gut profile (for analysis). ZDR enforced — not retained. |
| Brevo | Transactional email | Email address only (for sign-in links) |
| Dodo Payments | App Pro upgrade payment processing | Email, payment details (handled by Dodo Payments) |
| Gumroad | Manual product payment processing and FMT Pro purchase handling | Email, payment details (handled by Gumroad) |
| MailerLite | Free-resource delivery and marketing email | Email address and form details you submit |
| Tally | Contact form processing | Contact details and message you submit |
| Google Analytics, Google Ads, and DoubleClick | Website analytics, advertising, and conversion measurement (marketing site only) | IP address, device/browser details, page URLs and titles, referrals, campaign data, and site interactions. Not intentionally linked to App health data. |
| Cloudflare | Content delivery and security | Standard web request data |
6. Your rights and controls
You have full control over your data:
- Export your data: Download all your entries, check-ins, and profile as a JSON file from Settings — available to all users (free and paid).
- Delete your data: Permanently delete all your tracking data from Settings at any time.
- Delete your account: Permanently delete your entire account, including all data, profile, and login information from Settings. This is irreversible.
- Correct your data: You can edit or remove individual entries within the App.
- Withdraw consent: You can stop using the service and delete your account at any time.
If you are located in the EU/EEA, you may also have additional rights under GDPR, including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority. To exercise any right not available through the App's self-service tools, please contact us.
7. Data retention
- Account data: Retained while your account is active. Deleted when you delete your account.
- Health and wellness data: Retained while your account is active. You can delete it at any time via Settings.
- Email marketing: If you subscribe to our email list (separate from the App), your email is retained until you unsubscribe.
- Purchase records: Retained as required by applicable tax and accounting law.
Connected Notion and Google Sheets analyzer
The optional tool at /analyze/ is separate from the tracking App. It fetches the data you connect, processes it on our server, and sends selected diary and profile context to OpenRouter for AI report generation. The provider zero-data-retention setting concerns AI processing, not the server storage described here.
- Server-side session: Depending on your connection, a session file stores your Notion access token and workspace details or Google Sheets URL, plus your generated report and its supporting summary data. This supports report viewing and PDF download. It is not memory-only processing.
- Session expiry: Sessions expire after 24 hours without activity. Activity refreshes this period. Expired session files are removed by periodic cleanup, which normally runs hourly while the service is running, rather than exactly at expiry. Disconnecting requests deletion of the active session file; it does not revoke Notion access or change Google sharing permissions.
- Backups: Session files, including saved reports and connection details, can be included in server backups on Cloudflare R2, which use client-side encryption. From September 11, 2026, analyzer session files are excluded from new Google Drive archives. Historical Google Drive archives may still contain session files and are not separately encrypted by our backup tool. Backup copies can outlast session expiry or disconnect. Existing backup schedules do not provide a verified per-file deletion deadline, so there is no fixed maximum retention period we can currently guarantee for these copies.
- Diagnostics and request logs: From September 9, 2026, new per-run diagnostic copies of diary data, profiles, prompts and AI responses are disabled. Application diagnostics retain limited operational counters and status information instead. From September 10, 2026, a new Google Sheets connection sends the link in a bounded POST body rather than the requested URL. Infrastructure request logs can still record the connection endpoint and request metadata, and historical infrastructure request logs may retain full Google Sheets links submitted before this change. Historical diagnostic files may remain. Operational logs and archived backups do not all share a fixed deletion deadline.
- Your controls: Disconnect when finished, revoke the integration in Notion if you no longer want it connected, and restore Google Sheets sharing to Restricted after generating a report. For questions or deletion requests involving historical files or backups, contact us without including diary entries or a private sheet link in the message.
8. Cookies
The App uses a single session cookie for authentication. No tracking or advertising cookies are used in the App.
The marketing website may use cookies and similar technologies through Google Tag Manager, Google Analytics, Google Ads, and DoubleClick for analytics, advertising, and conversion measurement. You can delete or block these through your browser settings. These technologies are not used inside the App.
9. Children's privacy
Our services are not directed at children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. If we make significant changes that affect how your health data is handled, we will notify you via email.
11. Contact
If you have any questions about this privacy policy or how your data is handled, please get in touch.
