Privacy
Privacy Policy
Last updated August 2, 2026
Gout Radar is designed so health, medication, flare, hydration, meal, and laboratory records stay on your device by default. A scan necessarily sends the image you select for analysis; the details are below.
1. Who we are
Gout Radar is the data controller for the app and this website. Privacy questions and requests can be sent to support@goutradar.com.
2. Data we process
Records kept on your device
Uric-acid laboratory readings, flare and medication records, hydration, meals, reports, and reminder settings are stored locally by default. They are not synced to CloudKit. You decide when to export or share a report.
Food, label, and menu scans
When you start a scan, the selected image is uploaded to our Cloudflare service and passed to an AI model provider for that scan. The AI request contains the image, scan type, locale, and instructions needed to extract an editable estimate. It does not contain your health profile, laboratory values, symptoms, flare records, medication records, hydration records, or HealthKit data. Pseudonymous device or account identifiers, app/build information, and authorization data are handled by our service to authorize and operate the task, but are not added to the AI prompt. We delete the image after the task reaches success or failure. A scheduled cleanup handles abandoned processing, with a maximum image-retention target of 24 hours. The authorized task and structured result—including recognized ingredients, portion estimates, purine-related estimates, confidence, and technical status—may remain in Cloudflare D1 for up to 90 days so the app can recover an interrupted result and operate the service.
Optional scan feedback
If you explicitly submit quality feedback, we store the helpful rating or fixed correction categories and your consent record for up to 90 days. We use this linked feedback to evaluate scan quality and plan feature improvements. The 1.1 feedback request does not accept free text, a health value, or an image.
Accounts and device identifiers
We process a random app-device identifier and authentication credentials to authorize requests, apply scan limits, prevent account crossover, and complete deletion. If you choose Sign in with Apple, we process the Apple user identifier and any name or relay email Apple provides. Signing out is not account deletion and does not by itself complete the server-deletion workflow described below.
Notifications and Apple Push Notification service
If you enable notifications, the app registers with Apple Push Notification service (APNs) and sends the resulting device token to our Cloudflare service. The token is used only to address notifications for the app. Gout Radar notification delivery does not include health records, scanned food names, meal images, or laboratory values in the APNs payload. We remove or invalidate the token when the app installation is deleted, notifications are disabled through the supported app flow, APNs reports the token invalid, or a completed deletion covers that installation.
Purchases
Apple provides transaction and subscription records needed to verify access, restore purchases, handle support, and meet accounting or legal obligations. StoreKit on your device is the authority for paid access. We also retain allow-listed purchase or restore outcomes and the StoreKit product ID for up to 90 days to evaluate conversion and reliability; those product events never contain receipt content.
Product events and diagnostics
We use an allow-list of pseudonymous events and coarse error or latency categories to understand reliability and product flow. Event properties must not contain food names, health values, images, contact details, tokens, or receipts. Raw product-interaction events are retained for up to 90 days; diagnostic events for up to 30 days; minimized AI-usage metrics for up to 400 days.
HealthKit
HealthKit access is optional and requested in context for named data types. HealthKit data is used only for the feature you select, is not included in food-scan requests, and is not used for advertising.
3. Why we process data
We process data to provide requested app functions, authenticate requests, verify purchases, answer support requests, secure the service, measure reliability, and comply with law. Where consent is the basis—such as optional HealthKit access, notifications, or quality feedback—you can decline or withdraw it without losing unrelated local recording features.
4. Sharing, AI providers, and subprocessors
We do not sell personal data, use it for third-party advertising, or track you across other companies’ apps or websites. We use the following service providers to operate Gout Radar:
- Apple Inc. — App Store distribution and purchases, Sign in with Apple, optional HealthKit access, and APNs notification delivery.
- Cloudflare, Inc. — Workers, Durable Objects, Queues, D1, and R2 infrastructure for API authorization, task processing, structured scan results, telemetry, and transient scan-image storage.
- Google LLC (Gemini) — the primary AI model provider for a scan. It receives the selected image, scan instructions, scan type, and locale.
- Replicate, Inc. — a fallback host for a Google Gemini model when the primary model call is unavailable. It receives the same scan inputs needed for that request.
- OpenAI, L.L.C. — a final fallback AI model provider when the preceding model calls are unavailable. It receives the same scan inputs needed for that request.
The AI providers do not receive the local health profile or long-term health records listed above as part of the 1.1 scan request. Providers may process data in other countries under their own contractual, security, and legal obligations.
5. Account deletion, local deletion, and your choices
Signing out or deleting the app is not the same as requesting account deletion. To request deletion, open Settings in Gout Radar and choose Delete Account & Data. The app sends an authenticated deletion request, receives a one-time status receipt, and reports completion only after the covered server records and temporary images are removed. Local records, local media, and app credentials are then cleared. If the service is unreachable or deletion cannot be verified, the request remains visibly pending or failed rather than being reported as complete. A one-time deletion receipt may remain for up to 30 days so the app can read back the outcome. You may also contact support@goutradar.com.
6. Security, transfers, and retention
We use transport encryption, scoped authorization, owner isolation, bounded retention, and deletion verification. No system can guarantee absolute security. Service providers may process data in countries other than yours with safeguards required by applicable law. Retention periods above are maximum operational targets; purchase records may be retained longer where law requires.
7. Children
Gout Radar is not directed to children under 13, or a higher minimum age where local law requires it. Contact us if you believe a child provided personal data.
8. Changes and contact
We will update the date and policy when material practices change. Questions, access requests, corrections, objections, or deletion requests can be sent to support@goutradar.com.