Privacy Policy

7-Day Gut Reset (7DGR)
Last updated: August 8, 2026
Effective date: August 8, 2026


What this means for you

  • We collect account, wellness, food, symptom, body-context, and program data that you choose to provide so the App can operate, personalize guidance, and preserve your progress.
  • Some data stays on your device and selected data syncs to our service providers. Local encryption is a defense-in-depth measure, not end-to-end encryption.
  • We do not sell consumer health data or use identifiable health data for targeted advertising or to train third-party AI models.
  • You can access, export, correct, or delete your data, subject to the limited retention described below.

1. Who we are

7-Day Gut Reset ("7DGR," the "App," "we," "us," or "our") is operated by Mount Nurture LLC. The App includes the 7-Day Gut Reset progressive web application and mobile app versions, including the Android app with package name com.mountnurture.sevendaygutreset.

7DGR is a consumer wellness and education service. It is not a healthcare provider or medical service. Mount Nurture LLC is generally not a HIPAA covered entity or business associate when you provide information directly to this consumer service. This policy is not a HIPAA Notice of Privacy Practices. Your information may still be protected by consumer health, privacy, breach-notification, and other laws.

Contact
Mount Nurture LLC
1401 21st ST #7109
Sacramento, CA 95811
Phone: 747-777-3149
Email: [email protected]
Website: https://7daygutreset.com

2. Scope

This Privacy Policy covers information processed through:

  • the private member App at app.7daygutreset.com;
  • the 7DGR Android or other mobile app versions;
  • the public website at 7daygutreset.com; and
  • account provisioning, support, and related enrollment interactions that we control.

External checkout pages, app stores, websites, publishers, email services, and apps you choose for exporting or sharing information have their own privacy practices. Their processing is not controlled by this policy, except to the extent they act as our service providers.

3. How we receive information

We receive information:

  • directly from you, when you sign in, complete the quiz, enter a check-in, use an optional tracker, change settings, export data, or contact support;
  • from the enrollment or access process, such as your email address and entitlement or purchase status;
  • automatically from the App and your device, such as authentication, security, diagnostic, usage-event, and notification-delivery data; and
  • from service providers, when needed to authenticate you, provision access, host the App, prevent abuse, or resolve an error.

The App is currently invite-only. Anonymous visitors may still generate ordinary hosting and security logs.

4. Information we collect and how we use it

4.1 Account, enrollment, and communications data

Data Purpose
Email address Account identifier, authentication, invitation, access provisioning, support, and service notices
Password credential Authentication through Supabase Auth; we do not receive or store your plaintext password
Optional display name Personalizes the App
Access and entitlement records Determines whether access is active and records plan, cadence, product, trial, cancellation, and provider status where applicable
Provider customer or subscription identifiers Connects an external enrollment or purchase to App access where applicable
Support communications Responds to your request and keeps a record of the issue

The member App does not require a legal name, phone number, or full payment-card number. An external enrollment or checkout provider may collect name, phone, billing, or payment information under its own notice. We may receive limited order, entitlement, and transaction details, but we do not intentionally receive full payment-card details.

4.2 Profile, quiz, and personalization data

Data Purpose
Quiz and baseline responses Produces a wellness-oriented gut profile and personalizes guidance
Gut profile or type Organizes program content; it is not a diagnosis
Symptom timing and wellness patterns Adjusts educational suggestions and safety messaging
Lifestyle context Tailors pacing, routines, and suggestions
Conditions or medical considerations you choose to disclose, such as IBS, GERD, SIBO, histamine concerns, celiac disease, IBD, autoimmune conditions, pregnancy, postpartum status, or recent antibiotic use Provides context-sensitive educational guidance and cautions; not medical care
Dietary preferences and ingredients to favor or avoid Filters meals and recipes
Motivation and readiness Adjusts program framing and next-step suggestions

4.3 Symptom, food, and wellness logs

You may choose to enter:

  • dates, symptoms, intensity scores, suspected triggers, mood, helpfulness, and free-text notes;
  • meals, foods, hydration, meal timing, plant variety, and food-reaction observations;
  • reintroduction or food-test entries, including foods tested, timing, symptoms, severity, and your own safe/avoid observation;
  • weight, waist measurement, sleep, energy, mood, stress, bowel-movement frequency, and stool consistency; and
  • optional bowel safety context, such as pain, blood, black or tarry stool, vomiting, fever, dehydration, or related notes.

The App may call some optional body and wellness measurements "biometrics." They are not used as face, fingerprint, voice, or other biometric identifiers.

4.4 Optional body-timing and cycle context

If you affirmatively enable this feature, you may provide period-window or cycle context, pregnancy/postpartum context, hormonal-medication changes, peri/menopause context, PMS-like symptoms, cramps, hot flashes, gut shifts, flow burden, and an optional note.

You control separately whether this information may be used for daily gut guidance and whether it may appear in a visit-ready summary. You can turn body-timing guidance off in the App. Turning it off stops future recommendation or summary use, but existing entries remain until you delete them or delete your account.

4.5 Program, planning, and generated-summary data

We process reset start and completion dates, completed days, daily practices, reflections, intentions, readiness, achievements, meal plans, shopping lists, recipe filters, favorites, adaptations, post-reset practices, personal experiments, questions for a healthcare visit, and other program state needed to show and restore your experience.

When you request an export, backup, or visit-ready summary, the App compiles selected information into a CSV, JSON, or text file. You decide where that file is saved or shared.

4.6 Push-notification data

If you opt in, we collect a Web Push subscription endpoint, protocol encryption keys, user-agent information, notification preferences, timezone, program phase, and delivery or failure records. We use these details only to deliver requested reminders, avoid duplicates, troubleshoot failures, and remove invalid subscriptions.

4.7 Usage, diagnostics, and security data

We may process:

  • feature events, such as onboarding, quiz, program, check-in, recipe, warning, notification, or practice interactions;
  • recipe IDs, event timestamps, source screens, program day, session identifiers, and limited allowlisted event metadata;
  • authentication and session data;
  • IP address or an IP-address-based rate-limit key, browser/device type, user agent, request path, timestamp, and response or error details;
  • pseudonymous account ID in diagnostic events; and
  • crash stack traces and technical environment data.

We use this information to operate, secure, debug, measure, and improve the App. The member App does not include Google Analytics, Meta Pixel, TikTok Pixel, or other third-party advertising pixels in its private health-data areas as of the effective date.

4.8 Data we do not intentionally collect through the member App

The member App does not intentionally collect:

  • precise GPS location;
  • contacts, call logs, SMS messages, photos, camera, microphone, or body-sensor data;
  • Android Advertising ID or another advertising identifier;
  • face, fingerprint, or voice templates;
  • social-media account data;
  • formal medical records from a healthcare provider; or
  • full payment-card information.

The Android app currently requests only network access needed to load and use the service. A future feature that collects a new category of sensitive data or uses a new device permission will require an updated disclosure and any consent required by law before collection.

5. Why we process information

We use information to:

  1. create, authenticate, provision, and secure accounts;
  2. provide the program, restore progress, sync devices, and support offline use;
  3. personalize educational content, meals, recipes, safety cautions, and next steps;
  4. generate user-requested exports, backups, and summaries;
  5. deliver optional reminders;
  6. prevent abuse, investigate security events, diagnose errors, and maintain reliability;
  7. provide support and important service or policy notices;
  8. administer access, refunds, entitlements, and purchase verification where applicable;
  9. comply with law, enforce our Terms, and protect rights and safety; and
  10. improve the service using aggregated, de-identified, or limited operational event data.

The App uses rules and user-entered information to classify a gut profile and tailor suggestions. These automated recommendations do not make legal, employment, credit, insurance, medical-treatment, or similarly significant decisions about you.

Where the European Economic Area or United Kingdom data-protection laws apply, our legal bases may include:

  • contract or steps at your request to provide your account and requested App functions;
  • consent for optional notifications, body-timing uses, and other optional processing where consent is required;
  • explicit consent for health-related special-category data where Article 9 or equivalent law requires it, reflected through an affirmative choice to provide and save optional health information after the relevant disclosure or to enable a specific optional health feature;
  • legitimate interests in securing, debugging, and improving the service, provided those interests are not overridden by your rights; and
  • legal obligation or legal claims when we must retain, disclose, or protect information.

You may withdraw consent for future processing at any time. Withdrawal does not affect processing already carried out lawfully. Some core health-personalization features cannot work without the information they require; you may decline those features or delete the relevant information.

7. Storage, encryption, and security

7.1 Data on your device

The App uses browser or app storage, including localStorage, IndexedDB, service-worker caches, and native app storage, to support login, offline use, preferences, recovery, and program state.

Sensitive local records—including many profile, check-in, food-log, body-measurement, reflection, reintroduction, health-trend, and body-timing records—are generally protected with AES-GCM encryption when the Web Crypto API and required account context are available. The App derives local key material from the signed-in account identifier and browser/device characteristics using PBKDF2-SHA-256 with a random salt. Legacy local records are migrated when read where possible.

Important limits:

  • this is not end-to-end encryption; the App can decrypt data in order to display, sync, and process it;
  • the key is not derived from your password;
  • some preferences, progress markers, caches, meal-planning data, and low-sensitivity operational state may be stored without AES encryption;
  • older or fallback environments may use obfuscation rather than AES encryption; and
  • local encryption does not protect against malicious code running in the same App origin, a compromised browser/device, malicious extensions, or someone using your unlocked session.

Clearing browser/app storage, uninstalling the App, using private browsing, or changing devices can remove local data that has not synced. Export files are not automatically encrypted by the App; protect them after saving or sharing.

7.2 Server-side processing

Selected account, profile, health, planning, notification, analytics, and program-state data syncs to Supabase so the App can preserve progress and operate across sessions or devices. Server-side synced data is readable by the App and authorized backend processes; it is not end-to-end encrypted.

We use HTTPS/TLS in transit, provider encryption at rest, Supabase Row Level Security policies, authenticated API checks, restricted service credentials, rate limiting, and production security headers. Administrative or service-role access is limited to operational purposes such as support, delivery jobs, security, and deletion.

No system is completely secure. You are responsible for protecting your password, device, email account, and exported files and for signing out of shared devices.

8. When we disclose information

We do not sell personal data or consumer health data. We disclose only what is reasonably needed for the purposes below.

8.1 Service providers

Provider/category Information processed Purpose
Supabase Email, authentication/session data, synced profile and health data, program state, meal/planning data, usage events, notification settings and subscriptions, and account deletion Authentication, PostgreSQL database, storage, access control, and account administration
Vercel Requests to the hosted App, including IP address, user agent, path, timestamp, technical logs, and data submitted through hosted server routes Hosting, content delivery, server execution, and operational logging
Sentry Sanitized stack traces, browser/server environment, request metadata, and pseudonymous user ID Error and crash monitoring. We configure scrubbing to remove passwords, tokens, email addresses, request bodies, and sensitive fields, and we do not intentionally send health logs. Automated filtering cannot guarantee that an unexpected value will never appear in a diagnostic event.
Upstash Redis Short-lived IP-address-based rate-limit keys, request counters, and public-content cache entries Abuse prevention and performance. We do not intentionally send health-profile or health-log content.
HighLevel and external enrollment/checkout providers Email, optional enrollment details, entitlement, order, or purchase status, and information you provide on an external page Enrollment, payment or order administration, and App provisioning. The current HighLevel provisioning connection sends the App an email address; we do not send HighLevel member-App health logs.
Microlink and JSONLink A public article URL and ordinary network/request information when a preview is requested Producing public-link previews
Email and communications providers Email address and message content Invitations, service notices, and support
Google Play or another app platform Download, purchase, device, account, and diagnostic information determined by that platform Distribution, platform security, and any platform purchase. The platform's privacy policy also applies.

Provider policies include:

If you save or share an export through the Android share sheet, browser download, email, cloud drive, messaging app, clinician portal, or another destination, that destination receives the information you selected and applies its own privacy practices. We do not control what the recipient does with it.

Public news and library feeds are generally fetched server-to-server, without sending publishers member health data. If you open an external article, the publisher receives ordinary browser request information such as your IP address, device/browser data, page request, and potentially a referrer.

We may disclose information when reasonably necessary to comply with law or valid legal process; protect users, rights, property, or safety; investigate fraud or security incidents; establish or defend legal claims; or complete a merger, financing, acquisition, bankruptcy, or sale of assets. A successor must handle personal data consistently with this policy and applicable law.

9. Consumer health data notice

This section is intended to provide the disclosures required by consumer health privacy laws, including Washington's My Health My Data Act where applicable.

9.1 Categories collected

We may collect the following consumer health data that can be linked to you:

  • digestive symptoms, severity, timing, triggers, bowel patterns, and red-flag context;
  • foods, hydration, dietary preferences, restrictions, reactions, and reintroduction results;
  • conditions and medical considerations you choose to disclose;
  • weight, waist, sleep, energy, mood, stress, and related wellness measurements;
  • pregnancy/postpartum, cycle, period-window, hormonal-medication, and peri/menopause context you choose to provide;
  • wellness interests and inferences, including a gut profile, recipe fit, suggested content, and program progress; and
  • information indicating that you sought or used a gut-health and wellness service.

We collect these categories from you, your interactions with the App, and limited enrollment/access records. We use them for the purposes in Sections 4 and 5.

9.2 Consumer health data disclosed

We disclose consumer health data only as needed to provide the product you request, to processors acting under our instructions, at your direction, or as permitted by law. The categories disclosed may include the health and program data you sync through Supabase or submit through a Vercel-hosted route; a selected subset in an export you direct to another app or recipient; and limited information required for a legal, safety, or business transaction.

Categories of recipients are database/authentication providers, hosting providers, user-selected export or share recipients, professional advisers or authorities when legally required, and a successor in a covered business transaction. Current specific processors that may handle synced consumer health data are Supabase and Vercel. We have no affiliate that independently receives consumer health data as of the effective date. We do not intentionally disclose member health logs to advertising platforms, HighLevel, Upstash, link-preview providers, publishers, or Sentry.

9.3 Your consumer health rights

Subject to applicable law, you may:

  • confirm whether we collect, share, or sell your consumer health data;
  • access that data and request a list of third parties and affiliates to which it was disclosed;
  • withdraw consent for future collection or sharing;
  • correct or delete the data; and
  • appeal a refusal to act on a request.

Use the in-App data controls or email [email protected] with the subject Consumer Health Data Request. We may authenticate your request to protect your account. If we deny a request, our response will explain why and how to appeal by replying with the subject Privacy Appeal.

We do not sell consumer health data, use it for targeted advertising, or place geofences around healthcare facilities to identify or target people. If we materially expand the categories or purposes described here, we will update this notice and obtain affirmative consent where required before the new collection, use, or disclosure.

10. Cookies, local storage, analytics, and advertising

10.1 Member App

The member App uses essential Supabase authentication cookies or equivalent browser storage to establish and refresh your session. Authentication cookies are generally set with SameSite=Lax and may persist until their configured expiration, which can extend beyond the current browser session. They may be refreshed during use and are cleared or invalidated through logout, expiration, or account deletion as applicable.

The App also uses localStorage, IndexedDB, and service-worker caches as described in Section 7. These technologies are necessary for core functions, preferences, offline use, and recovery. They are not used by the member App for third-party behavioral advertising.

10.2 Public website, enrollment, and checkout pages

The public website or external enrollment and checkout pages may use analytics or advertising tools, including Google Analytics, Meta Business Tools, or TikTok Business Tools, if enabled on those pages. Those tools may receive page URL, referrer, IP address, browser/device information, cookie or pixel identifiers, and events such as a page view, form submission, checkout start, or purchase.

We do not intentionally send those platforms App health logs, symptom entries, food logs, body-timing data, reflections, passwords, or private member-App activity. Where required, nonessential tools must be consent-gated and opt-out choices, including legally recognized browser signals, must be honored. We will not use enhanced matching, customer lists, or similar advertising features that send personal identifiers unless we update this policy and obtain any consent required by law.

11. Push notifications

Notifications are optional. Your browser or device asks for permission before the App creates a subscription. You can turn reminders off in Settings and revoke device/browser permission at any time. Messages may include program, meal, check-in, practice, or milestone reminders. We do not use health details in the notification body unless the feature clearly shows that content before you opt in.

Turning notifications off stops future sends. The App attempts to remove the server subscription when you disable the feature; browser or device controls can also stop delivery. Notification send records are eligible for cleanup after seven days, and an automated job is designed to remove failure records after 30 days. Actual removal can take longer during an outage, backup cycle, or operational delay.

12. Retention, export, and deletion

12.1 Retention

We retain account and synced program data while your account is active and as reasonably needed to provide the service. Retention may be shorter when you delete an entry or local storage is pruned for space. Local quota management is designed to prune certain older records, such as recipe events after 90 days, check-ins and food logs after one year, body measurements after two years, and some delivery history after 30 days; pruning occurs as part of storage management and is not guaranteed on an exact date.

Diagnostic, hosting, database, and backup retention depends on provider configuration and backup rotation. We keep it only as reasonably necessary for operation, security, continuity, legal compliance, or claims. Aggregated or de-identified information that cannot reasonably be linked to you may be retained longer.

12.2 Access and export

Settings includes tools to export health data as CSV, create a fuller JSON backup, and create a text visit summary. You can also contact us for an access request. Exporting does not delete the source data.

12.3 Account deletion

You may delete your account in Settings → Delete Account. You may also make an external request by emailing [email protected] with the subject Delete My 7DGR Account from the email associated with your account.

After an authenticated deletion request:

  • the App deletes the authentication account and user-owned live database rows through cascading deletion;
  • the App attempts to clear 7DGR local data on the current device; and
  • you must clear other devices, downloaded exports, browser backups, or copies you shared yourself.

We may retain a limited deletion-audit record containing the account email or identifier, deletion date, provisioning source, request source, and deletion reason/status. We may also retain transaction, entitlement, fraud-prevention, security, tax, or legal records when reasonably necessary and permitted by law. We do not retain deleted health logs in the deletion-audit record.

Residual copies may remain temporarily in encrypted backups, immutable logs, or provider systems until their ordinary rotation or deletion process completes. Where Washington consumer health law applies, deletion from archived or backup systems will be completed within the period required by that law and no later than six months after authentication of the request. We will direct applicable processors or other recipients to honor a consumer-health deletion request when required.

Deleting an account is permanent and does not itself create a refund. Refund requests are governed by the Terms of Service and the purchase provider's rules.

13. Your privacy choices and rights

Depending on where you live, you may have rights to:

  • know or access the personal data we hold;
  • correct inaccurate data;
  • delete data;
  • receive portable data;
  • restrict or object to processing;
  • withdraw consent;
  • opt out of sale, targeted advertising, or certain profiling;
  • limit certain uses of sensitive personal information; and
  • appeal a decision or complain to a regulator.

The App provides direct controls for editing profile data, exporting data, managing notifications and body-timing uses, clearing progress, and deleting the account. Clear Progress is not account deletion and may preserve your profile, authentication, or selected settings.

To exercise a right, email [email protected] and identify the request. We may verify your identity and authority. An authorized agent may submit a request where local law permits, but we may require proof of authorization and direct identity verification. We will not unlawfully discriminate against you for exercising a privacy right.

California and other U.S. state notices

In the preceding 12 months, we may have collected the categories described in Section 4: identifiers; customer/transaction records; internet or electronic activity; account credentials; inferences/preferences; and sensitive personal information, including health, body-timing, and account-login information. Sources, purposes, and recipients are described in Sections 3, 5, and 8.

We do not sell personal information or share member-App personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of anyone under 18. Where the CCPA/CPRA or another state law applies, residents may exercise the applicable access, correction, deletion, opt-out, limitation, portability, and appeal rights described above. Even when a particular statute does not apply to Mount Nurture LLC, we will make reasonable efforts to honor comparable requests.

14. International transfers

Mount Nurture LLC is based in the United States. Our providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual or other lawful transfer safeguards and make information about them available upon request.

If you are in the EEA or UK, you may contact us to exercise your rights and may lodge a complaint with your local supervisory authority. You may also contact us to request information about the applicable international-transfer safeguard.

15. Children

7DGR is intended only for adults 18 years of age or older. We do not knowingly collect personal information from children. If you believe a person under 18 has provided information, contact [email protected]. We will investigate and delete it as required.

16. Health and emergency notice

7DGR is for education and general wellness. It does not diagnose, treat, cure, or prevent disease and does not create a healthcare-provider relationship. Do not use the App for emergencies. Seek immediate professional or emergency help for severe, unusual, persistent, or worsening symptoms, including severe pain, blood or black/tarry stool, persistent vomiting, fever with digestive symptoms, dehydration, or another urgent concern.

Information entered into a visit-ready summary is not automatically sent to a clinician. You decide whether to export or share it.

17. Security incidents

We monitor and respond to suspected security incidents. If an incident triggers a legal notification duty, we will notify affected individuals and regulators in the manner and timeframe required by applicable law, including applicable consumer health breach-notification rules.

18. Changes to this policy

We may update this policy when the App, providers, data practices, or law changes. We will post the revised policy, update the date above, and provide additional notice or obtain consent when required for a material new use of sensitive data. Prior versions may be requested by email.

19. Contact us

For privacy questions, rights requests, appeals, or account deletion:

Mount Nurture LLC
1401 21st ST #7109
Sacramento, CA 95811
Phone: 747-777-3149
Email: [email protected]
Privacy Policy URL: https://7daygutreset.com/privacy-policy

We will respond within the timeframe required by applicable law.


This policy describes the current 7-Day Gut Reset codebase and operational design as of the effective date. It should be reviewed whenever data collection, service providers, checkout, mobile permissions, analytics, or health features change.