Privacy Policy for CrohnOlogy

Last Updated: 12 July 2026

CrohnOlogy is a private symptom tracker that encrypts your family’s health data on the device before it is uploaded. This policy explains what we collect, how we use it, and the choices you have.

In short

  • Encrypted on your device: symptoms, notes, and photos are encrypted before they leave your phone
  • Family-only access: only authorised family members can see your data
  • No selling, no sharing: your data is never sold or shared with third parties
  • No tracking cookies: this website uses cookieless analytics only

Read how the encryption works →

1. Introduction

CrohnOlogy is a private medical symptom tracking application designed to help families monitor and manage Crohn’s disease symptoms. This Privacy Policy explains how we collect, use, store, and protect your personal information.

2. Information We Collect

2.1 Personal Information

  • Google Account Email: Used for authentication and access control
  • Family Identification: Your account is associated with your family’s authorised users

2.2 Health Data

  • Food Logs: Meal descriptions, meal types, and optional photos
  • Stool Logs: Bristol Stool Scale types, urgency levels, blood presence indicators, notes, and optional photos
  • Pain Logs: Pain intensity (1-10), pain types, and anatomical locations
  • Weight Measurements: Numerical weight entries with unit preferences

2.3 Media

  • Photos: Images captured by camera or selected from gallery for food and stool entries

2.4 Metadata

  • Timestamps: Entry creation times and manually adjusted entry times
  • Device Information: Basic device identifier for Firebase services

3. How We Use Your Information

3.1 Primary Purpose

  • Track and monitor Crohn’s disease symptoms
  • Maintain a comprehensive health history
  • Facilitate communication between family members about health status
  • Analyse trends and patterns in symptoms

3.2 Data Access

  • Authorised Family Members Only: Only pre-authorised family members invited by the family Administrator can access your health data
  • No Third-Party Sharing: We do not share your data with third parties for marketing or advertising purposes
  • No Selling: We never sell your personal or health information

4. Data Storage and Security

4.1 Storage Location

  • All data is stored on Firebase (Google Cloud Platform) servers located in secure data centres
  • Photos are stored in Firebase Storage
  • Health data is stored in Cloud Firestore

4.2 Security Measures

  • Authentication: Google Sign-In with email-based access control
  • Zero-Knowledge Encryption: All health data and photos are encrypted using AES-256-GCM before being stored. Encryption keys never leave the device and are never accessible to Firebase or the app developer.
  • Encrypted Transmission: All data is transmitted over secure HTTPS connections
  • Server-Side Rules: Firestore security rules enforce strict access controls based on family ID
  • Private Access: Only authorised family members can read or write data

4.3 Access Control

  • Your account email must be on the authorised family list
  • Each data document includes a familyId field that must match your account
  • Unauthorised access attempts are blocked by Firebase security rules

5. Photo Handling

5.1 Camera Usage

  • The app requests camera permission to capture photos of food and stool samples
  • Photos are automatically compressed and optimised before upload (max 1024px resolution)
  • Stool photos are blurred by default in the app’s timeline view for privacy
  • The app can access your device gallery to select photos for health entries
  • Selected photos are compressed and optimised before upload

5.3 Photo Storage

  • Photos are stored securely in Firebase Storage
  • Photos are associated with your health entries and protected by the same access controls
  • When you delete an entry, the associated photos are also deleted from Firebase Storage

6. Data Retention

6.1 Retention Period

  • Health data is retained indefinitely unless you delete it
  • You may delete individual entries at any time through the app
  • Deleting an entry removes it from both Firestore and Firebase Storage

6.2 Account Deletion

  • You can delete your account and all associated data directly from within the app via Settings → Danger zone → Delete account
  • Account deletion requires biometric re-authentication and a confirmation step
  • Deletion removes your encrypted key backups, device keys, family membership, and Firebase Authentication account
  • Your health entries remain in the family timeline for medical continuity, but your identity is removed from them and they are labelled as logged by “Past member”
  • If you are the family Admin with other members, you must transfer the Admin role before deleting your account
  • If you are the sole family member, deleting your account permanently removes the entire family and all its data
  • Web request: see our Delete your account / data page
  • This action is permanent and cannot be undone

7. Your Rights

7.1 Access and Control

  • View: You can view all your stored health data in the app
  • Edit: You can edit any entry to correct mistakes
  • Delete: You can delete any entry and its associated photos
  • Export: Not yet available (data is encrypted on-device; export is on the backlog)

7.2 Data Security

  • Your data is accessible only to you and authorised family members
  • You control what data you enter and when you delete it
  • No data is shared with third parties without your explicit consent

8. Children’s Privacy

  • This app is designed for family use with parental supervision
  • Parents are responsible for managing their child’s account and data
  • Authorised family members include parents and the child patient

8.2 Data Collection from Minors

  • The app may collect health data from minors with parental consent
  • Parents have full access to and control over their child’s health data

9. Third-Party Services

9.1 Google Firebase

  • We use Google Firebase for authentication, database, and storage services
  • Google’s privacy policy applies to data processed through Firebase services
  • View Google’s privacy policy: https://policies.google.com/privacy

9.2 Google Sign-In

  • We use Google Sign-In for authentication
  • Your Google account information is used solely for authentication
  • We do not access or store your Google password

10. Changes to This Privacy Policy

10.1 Updates

  • We may update this Privacy Policy from time to time
  • Significant changes will be communicated through the app
  • The “Last Updated” date will be revised with any changes

10.2 Continued Use

  • Your continued use of the app after changes constitutes acceptance of the updated policy

11. Contact Information

11.1 Questions and Concerns

If you have questions about this Privacy Policy or our data practices, please contact:

App Developer:

  • Email: hello@crohnology.net
  • App Name: CrohnOlogy
  • Package Name: com.brusulaf.crohnology

11.2 Data Subject Rights

Under data protection principles (such as the UK GDPR), you have the following rights over your personal and health data. Because CrohnOlogy stores everything in your private, encrypted family timeline, most of these rights are exercised directly within the app.

  • Right of access: You can view all of your stored health data at any time in the app’s Journal timeline.
  • Right to rectification: You can edit any entry to correct mistakes. Tap an entry in the timeline to update its details.
  • Right to erasure: You can delete individual entries (and their associated photos) at any time, or delete your account and associated data entirely via Settings → Danger zone → Delete account. See Section 6.2 for details of what account deletion removes.
  • Right to data portability: Secure data export is not yet available. Because your data is encrypted on-device, we are designing a client-side export feature for a future update so you can safely download your history without exposing your keys.
  • Right to object: You can stop using the app at any time and delete your data as described above.

To exercise any of these rights, or if you have difficulty doing so within the app, contact hello@crohnology.net.