Medical disclaimer: Tumly is a personal symptom-tracking diary for IBS/gut health. It is not a medical device, and it does not diagnose, treat, or provide medical advice. Any pattern detection, correlation insight, or "red-flag" screening in the app is informational only. Always consult a qualified clinician about your health.
Tumly is designed around a simple principle: your health data belongs on your device, not on our servers. Tumly has no user accounts and no server-side database of your health information. All symptom logs, meals, bowel movement entries, medications, and daily check-ins are stored locally on your device using Apple's SwiftData framework. We do not have a copy of this data, and we cannot see it unless you explicitly choose to share an anonymized snapshot with our AI features (see below).
Our backend is a stateless AI proxy. When you opt in to AI features, the specific data needed for that request is sent to our server, forwarded to our AI provider, and the response is returned to your device. Requests are held in an in-process cache for up to 24 hours purely to avoid duplicate AI calls, and that cache is wiped whenever the server restarts. We do not maintain a database of your requests or their contents.
The following categories of health data are collected and stored exclusively on your device, and are never transmitted to our servers unless you have opted in to AI features (in which case only an anonymized subset is sent, as described below):
Tumly includes several AI-assisted features: Ask Tumly, the Weekly Digest, Trigger Detective narrative, the Doctor Report AI section, Appointment Prep AI polish, and meal-photo AI extraction. These features are off by default. The first time you use any of them, Tumly shows a plain-language consent prompt explaining exactly what will be sent. You must explicitly tap "Allow & Continue" before any data leaves your device for AI processing, and you can revoke this consent at any time in Settings → "Share data with AI features" — doing so immediately stops all six AI surfaces from making network calls, and each falls back to its existing offline behavior.
When AI consent is granted, only the following anonymized data is sent, and only for the specific feature you are using:
We never send your name, account identifiers (Tumly has no accounts), free-text notes, or any other photo besides the one you are actively logging. AI processing for these features is performed by OpenAI (model: gpt-4o-mini) via our backend proxy. Nothing you send is stored server-side beyond the short-lived, in-memory cache described above — there is no database of your AI requests.
With your permission, Tumly reads sleep, water intake, workouts, mindful minutes, and menstrual cycle data from Apple HealthKit. This data is used only to pre-fill your daily check-ins inside the app. It is never transmitted to our servers.
Meal photos you capture or attach are stored on your device. A photo is only ever sent off-device if you have granted AI consent and you use the meal-photo AI extraction feature, in which case a downscaled copy is sent to our AI proxy as described above.
Tumly's toilet finder uses your precise location to show nearby public restrooms. Location is requested one-shot, only while the app is in use, and only when you open the toilet finder. It is used to query an offline OpenStreetMap-based restroom dataset bundled with the app and, when needed, Apple's MKLocalSearch. Your location is never sent to our servers and is never persisted beyond that single lookup.
Restroom location data is sourced from OpenStreetMap: © OpenStreetMap contributors, available under the Open Database License (ODbL).
Tumly uses Firebase Analytics and the Meta (Facebook) SDK to understand product usage, measure funnels, and (with your permission) attribute installs. This includes your device identifier (IDFA), and Tumly requests App Tracking Transparency (ATT) permission before this identifier is used for tracking. If you decline the ATT prompt, your device is not tracked for advertising purposes. Analytics data does not include your health data, meal photos, symptom logs, or any personally identifying information beyond the device identifier.
We may disclose information if required by law, court order, or government request, or to prevent fraud or protect the security of our service. Because we do not store your health data server-side, there is generally nothing for us to disclose beyond the limited analytics and transient AI-proxy data described above.
Because your health data lives entirely on your device and we keep no server-side copy, you already have full access to it inside the app, and you can correct or delete any entry directly in Tumly. Deleting the app removes all locally stored health data. If you have used an AI feature, that specific request may still exist in our transient cache for up to 24 hours before it is automatically discarded; you do not need to contact us for this to happen, but you may email us with questions at [email protected].
You can disable AI features at any time in Settings → "Share data with AI features". This immediately stops Tumly from sending any data to our AI proxy.
You can decline the App Tracking Transparency prompt to prevent your device identifier from being used for tracking. iOS lets you change this decision later in Settings → Privacy & Security → Tracking.
Tumly is operated in the United States. Any data you send via an opted-in AI feature is processed in the US. If you are located outside the US, by using Tumly's AI features you consent to the transfer of that limited, anonymized data to the US for processing under US law.
We implement reasonable security measures, including encryption in transit (HTTPS), to protect any data that is sent to our AI proxy. However, no security measure is 100% guaranteed. If you have security concerns, please contact us at [email protected].
Tumly is a general-audience app and is not directed at children. We do not knowingly collect data from children. Tumly has no accounts, so there is no account-based data collection from any user, child or adult.
We may update this Privacy Policy at any time. We will notify you of material changes by updating the "Last updated" date above and, if required by law, via an in-app notification.
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Scriptstash
Email: [email protected]