Privacy Policy
Effective date: 26 September 2026
Applies to: the figuremytrigger.com website and the Figure My Trigger mobile app.
1. Who we are
Figure My Trigger ("FMT", "we", "us", "our") is run by Nicola Hall, an individual based in Italy, who is the data controller for the personal data described in this policy. You can contact us at hello@figuremytrigger.com.
2. What we collect
2a. On the website
If you sign up to the waitlist or visit figuremytrigger.com, we collect:
- Your first name and email address, via MailerLite, if you sign up to the waitlist
- General visitor analytics via Google Analytics (pages viewed, general location and device information — not tied to your identity beyond what Google Analytics itself collects). Google Analytics uses cookies to do this, and we only turn it on if you click Accept in our cookie banner. You can change your choice at any time using Cookie settings at the bottom of our homepage
We don't collect payment details, phone numbers, or health information through the website.
2b. In the app
Because FMT is a self-guided food-trigger tracking tool, most of what the app stores is your digestive health data. Specifically:
Account
- Your first name and email address (email is used for passwordless "magic link" sign-in via Supabase Auth — we never see or store a password)
- Sign-in records kept by our authentication provider for security: your IP address, device/browser type, and sign-in times. Session records are kept while you're signed in and deleted with your account; technical sign-in logs are kept for up to 1 day
Profile
- Diet preference (e.g. vegan/vegetarian/omnivore)
- Gut-sensitivity mode (Standard / Sensitive)
- Your reason for using the app, and typical symptoms you tell us about
- Reminder times and notification preferences (see Section 7)
Daily symptom logs — for each morning/evening/post-meal check-in you complete:
- Gut feeling, bloating, cramping, gas, and urgency ratings
- Energy level
- Bowel movement occurrence and time, and stool type (Bristol Stool Scale)
- Any confounders you flag (e.g. stress, poor sleep, alcohol, caffeine, illness, hormonal changes, eating outside the meal plan)
- Symptom onset timing and overnight symptoms, during trigger testing
Trigger test records
- Which foods you've tested, the doses and dates involved, and your results
- Your rest periods between tests (when they started, and whether you chose to pause)
Recipes
- Which recipes you've saved (the recipe content itself is not personal data — it's a shared reference database)
Consent record
- When you gave consent to us processing your health data, and which version of this policy you agreed to
We do not collect: payment details (the app doesn't currently process payments), precise location, contacts, photos from your device, or any data beyond what's listed above.
3. Why we collect it, and our legal basis
We process this data to provide the app's core function: helping you identify personal food triggers through structured self-testing, and computing your baseline and test results.
Because this includes health data, it is a "special category" of data under UK and EU GDPR (Article 9). We only process it with your explicit consent, which you give by ticking a separate consent box when you create your account. The box is not pre-ticked, and you cannot use the tracking features without it. You can withdraw consent at any time by deleting your account (Section 8).
We process your email address and sign-in records to provide your account and keep it secure (performance of our agreement with you, and our legitimate interest in security).
We do not use your data for advertising, and we do not sell it to anyone.
4. Where it's stored
Your app data is stored in a Supabase-hosted PostgreSQL database in AWS region eu-west-1 (Ireland). Supabase encrypts data both at rest and in transit. Supabase acts as our data processor under a data processing agreement; we remain the data controller.
Some of our providers are based outside the UK and EU. Where your data may be accessed from outside the UK/EU, we rely on the safeguards provided by those providers, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
5. Other services we use
- Supabase — database and authentication for the app, and hosting of the app's recipe images. None of your own files are stored there.
- Google Fonts — the app loads typefaces at runtime, which involves a request to Google's font servers. This shares your device's IP address with Google but none of your account or health data.
- Resend — sends the app's sign-in emails (your "magic links"). It receives your email address only, never your health data, and sends from its EU (Ireland) region.
- MailerLite — website waitlist email signups only.
- Google Analytics — website visitor analytics only.
- Netlify — hosts our website.
None of the app's health data reaches MailerLite, Google Analytics or Netlify. We do not currently use any analytics, advertising, or crash-reporting tools inside the app itself.
6. Who we share your data with
We don't share your health data with any third party for their own purposes. It is only accessible to Supabase as our infrastructure provider (Section 4), and to us for the purpose of running and improving the app. We will never share it with insurers, employers, or advertisers. We would only disclose data if required to by law.
7. Notifications
The app can remind you to log your check-ins (for example morning and evening check-ins and post-meal reminders), based on the reminder times and preferences you set. These reminders are scheduled and shown by your phone itself — they are not sent through any outside notification service, and no data leaves your device to send them. You can turn them off in the app's Settings or in your phone's settings. If we ever start using an outside push notification service, we will update this policy first.
8. Your rights
Under UK and EU GDPR you have the right to:
- Access the personal data we hold about you
- Export your data in a portable format
- Correct inaccurate data (most fields are editable directly in Settings)
- Delete your account and all associated data
- Restrict how we process your data in certain circumstances
- Object to processing based on our legitimate interests
- Withdraw consent at any time, which we treat as a request to delete your account and health data
You can export your data as a PDF, or delete your account and all its data, yourself at any time in the app under Settings > Account & data. If you'd like a machine-readable copy of your data (e.g. CSV), or for anything else, or if you can't use the app, email hello@figuremytrigger.com and we will respond within 30 days.
9. Data retention
We keep your data for as long as your account is active. If you delete your account in the app, your data is permanently removed from our live database straight away; if you ask us by email, we do it within 30 days. We may keep something longer only where the law requires it.
Waitlist email addresses are kept until you unsubscribe, using the link in any of our emails.
10. Children
FMT is not intended for anyone under 16. We don't knowingly collect data from anyone under that age. If you believe a child has given us their data, contact us and we will delete it.
11. Changes to this policy
If we make a material change to what we collect or how we use it, we'll update this page and the effective date above and, where appropriate, notify you in the app.
12. Contact and complaints
Questions, requests, or complaints about this policy: hello@figuremytrigger.com.
You also have the right to complain to a data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the authority in the country where you live (in Italy, the Garante per la protezione dei dati personali).