7-Day Gut Reset (7DGR)
Last updated: August 8, 2026
Effective date: August 8, 2026
What this means for you
- We collect account, wellness, food, symptom, body-context, and program data that you choose to provide so the App can operate, personalize guidance, and preserve your progress.
- Some data stays on your device and selected data syncs to our service providers. Local encryption is a defense-in-depth measure, not end-to-end encryption.
- We do not sell consumer health data or use identifiable health data for targeted advertising or to train third-party AI models.
- You can access, export, correct, or delete your data, subject to the limited retention described below.
7-Day Gut Reset ("7DGR," the "App," "we," "us," or "our") is operated by Mount Nurture LLC. The App includes the 7-Day Gut Reset progressive web application and mobile app versions, including the Android app with package name com.mountnurture.sevendaygutreset.
7DGR is a consumer wellness and education service. It is not a healthcare provider or medical service. Mount Nurture LLC is generally not a HIPAA covered entity or business associate when you provide information directly to this consumer service. This policy is not a HIPAA Notice of Privacy Practices. Your information may still be protected by consumer health, privacy, breach-notification, and other laws.
Contact
Mount Nurture LLC
1401 21st ST #7109
Sacramento, CA 95811
Phone: 747-777-3149
Email: [email protected]
Website: https://7daygutreset.com
This Privacy Policy covers information processed through:
app.7daygutreset.com;7daygutreset.com; andExternal checkout pages, app stores, websites, publishers, email services, and apps you choose for exporting or sharing information have their own privacy practices. Their processing is not controlled by this policy, except to the extent they act as our service providers.
We receive information:
The App is currently invite-only. Anonymous visitors may still generate ordinary hosting and security logs.
| Data | Purpose |
|---|---|
| Email address | Account identifier, authentication, invitation, access provisioning, support, and service notices |
| Password credential | Authentication through Supabase Auth; we do not receive or store your plaintext password |
| Optional display name | Personalizes the App |
| Access and entitlement records | Determines whether access is active and records plan, cadence, product, trial, cancellation, and provider status where applicable |
| Provider customer or subscription identifiers | Connects an external enrollment or purchase to App access where applicable |
| Support communications | Responds to your request and keeps a record of the issue |
The member App does not require a legal name, phone number, or full payment-card number. An external enrollment or checkout provider may collect name, phone, billing, or payment information under its own notice. We may receive limited order, entitlement, and transaction details, but we do not intentionally receive full payment-card details.
| Data | Purpose |
|---|---|
| Quiz and baseline responses | Produces a wellness-oriented gut profile and personalizes guidance |
| Gut profile or type | Organizes program content; it is not a diagnosis |
| Symptom timing and wellness patterns | Adjusts educational suggestions and safety messaging |
| Lifestyle context | Tailors pacing, routines, and suggestions |
| Conditions or medical considerations you choose to disclose, such as IBS, GERD, SIBO, histamine concerns, celiac disease, IBD, autoimmune conditions, pregnancy, postpartum status, or recent antibiotic use | Provides context-sensitive educational guidance and cautions; not medical care |
| Dietary preferences and ingredients to favor or avoid | Filters meals and recipes |
| Motivation and readiness | Adjusts program framing and next-step suggestions |
You may choose to enter:
The App may call some optional body and wellness measurements "biometrics." They are not used as face, fingerprint, voice, or other biometric identifiers.
If you affirmatively enable this feature, you may provide period-window or cycle context, pregnancy/postpartum context, hormonal-medication changes, peri/menopause context, PMS-like symptoms, cramps, hot flashes, gut shifts, flow burden, and an optional note.
You control separately whether this information may be used for daily gut guidance and whether it may appear in a visit-ready summary. You can turn body-timing guidance off in the App. Turning it off stops future recommendation or summary use, but existing entries remain until you delete them or delete your account.
We process reset start and completion dates, completed days, daily practices, reflections, intentions, readiness, achievements, meal plans, shopping lists, recipe filters, favorites, adaptations, post-reset practices, personal experiments, questions for a healthcare visit, and other program state needed to show and restore your experience.
When you request an export, backup, or visit-ready summary, the App compiles selected information into a CSV, JSON, or text file. You decide where that file is saved or shared.
If you opt in, we collect a Web Push subscription endpoint, protocol encryption keys, user-agent information, notification preferences, timezone, program phase, and delivery or failure records. We use these details only to deliver requested reminders, avoid duplicates, troubleshoot failures, and remove invalid subscriptions.
We may process:
We use this information to operate, secure, debug, measure, and improve the App. The member App does not include Google Analytics, Meta Pixel, TikTok Pixel, or other third-party advertising pixels in its private health-data areas as of the effective date.
The member App does not intentionally collect:
The Android app currently requests only network access needed to load and use the service. A future feature that collects a new category of sensitive data or uses a new device permission will require an updated disclosure and any consent required by law before collection.
We use information to:
The App uses rules and user-entered information to classify a gut profile and tailor suggestions. These automated recommendations do not make legal, employment, credit, insurance, medical-treatment, or similarly significant decisions about you.
Where the European Economic Area or United Kingdom data-protection laws apply, our legal bases may include:
You may withdraw consent for future processing at any time. Withdrawal does not affect processing already carried out lawfully. Some core health-personalization features cannot work without the information they require; you may decline those features or delete the relevant information.
The App uses browser or app storage, including localStorage, IndexedDB, service-worker caches, and native app storage, to support login, offline use, preferences, recovery, and program state.
Sensitive local records—including many profile, check-in, food-log, body-measurement, reflection, reintroduction, health-trend, and body-timing records—are generally protected with AES-GCM encryption when the Web Crypto API and required account context are available. The App derives local key material from the signed-in account identifier and browser/device characteristics using PBKDF2-SHA-256 with a random salt. Legacy local records are migrated when read where possible.
Important limits:
Clearing browser/app storage, uninstalling the App, using private browsing, or changing devices can remove local data that has not synced. Export files are not automatically encrypted by the App; protect them after saving or sharing.
Selected account, profile, health, planning, notification, analytics, and program-state data syncs to Supabase so the App can preserve progress and operate across sessions or devices. Server-side synced data is readable by the App and authorized backend processes; it is not end-to-end encrypted.
We use HTTPS/TLS in transit, provider encryption at rest, Supabase Row Level Security policies, authenticated API checks, restricted service credentials, rate limiting, and production security headers. Administrative or service-role access is limited to operational purposes such as support, delivery jobs, security, and deletion.
No system is completely secure. You are responsible for protecting your password, device, email account, and exported files and for signing out of shared devices.
We do not sell personal data or consumer health data. We disclose only what is reasonably needed for the purposes below.
| Provider/category | Information processed | Purpose |
|---|---|---|
| Supabase | Email, authentication/session data, synced profile and health data, program state, meal/planning data, usage events, notification settings and subscriptions, and account deletion | Authentication, PostgreSQL database, storage, access control, and account administration |
| Vercel | Requests to the hosted App, including IP address, user agent, path, timestamp, technical logs, and data submitted through hosted server routes | Hosting, content delivery, server execution, and operational logging |
| Sentry | Sanitized stack traces, browser/server environment, request metadata, and pseudonymous user ID | Error and crash monitoring. We configure scrubbing to remove passwords, tokens, email addresses, request bodies, and sensitive fields, and we do not intentionally send health logs. Automated filtering cannot guarantee that an unexpected value will never appear in a diagnostic event. |
| Upstash Redis | Short-lived IP-address-based rate-limit keys, request counters, and public-content cache entries | Abuse prevention and performance. We do not intentionally send health-profile or health-log content. |
| HighLevel and external enrollment/checkout providers | Email, optional enrollment details, entitlement, order, or purchase status, and information you provide on an external page | Enrollment, payment or order administration, and App provisioning. The current HighLevel provisioning connection sends the App an email address; we do not send HighLevel member-App health logs. |
| Microlink and JSONLink | A public article URL and ordinary network/request information when a preview is requested | Producing public-link previews |
| Email and communications providers | Email address and message content | Invitations, service notices, and support |
| Google Play or another app platform | Download, purchase, device, account, and diagnostic information determined by that platform | Distribution, platform security, and any platform purchase. The platform's privacy policy also applies. |
Provider policies include:
If you save or share an export through the Android share sheet, browser download, email, cloud drive, messaging app, clinician portal, or another destination, that destination receives the information you selected and applies its own privacy practices. We do not control what the recipient does with it.
Public news and library feeds are generally fetched server-to-server, without sending publishers member health data. If you open an external article, the publisher receives ordinary browser request information such as your IP address, device/browser data, page request, and potentially a referrer.
We may disclose information when reasonably necessary to comply with law or valid legal process; protect users, rights, property, or safety; investigate fraud or security incidents; establish or defend legal claims; or complete a merger, financing, acquisition, bankruptcy, or sale of assets. A successor must handle personal data consistently with this policy and applicable law.
This section is intended to provide the disclosures required by consumer health privacy laws, including Washington's My Health My Data Act where applicable.
We may collect the following consumer health data that can be linked to you:
We collect these categories from you, your interactions with the App, and limited enrollment/access records. We use them for the purposes in Sections 4 and 5.
We disclose consumer health data only as needed to provide the product you request, to processors acting under our instructions, at your direction, or as permitted by law. The categories disclosed may include the health and program data you sync through Supabase or submit through a Vercel-hosted route; a selected subset in an export you direct to another app or recipient; and limited information required for a legal, safety, or business transaction.
Categories of recipients are database/authentication providers, hosting providers, user-selected export or share recipients, professional advisers or authorities when legally required, and a successor in a covered business transaction. Current specific processors that may handle synced consumer health data are Supabase and Vercel. We have no affiliate that independently receives consumer health data as of the effective date. We do not intentionally disclose member health logs to advertising platforms, HighLevel, Upstash, link-preview providers, publishers, or Sentry.
Subject to applicable law, you may:
Use the in-App data controls or email [email protected] with the subject Consumer Health Data Request. We may authenticate your request to protect your account. If we deny a request, our response will explain why and how to appeal by replying with the subject Privacy Appeal.
We do not sell consumer health data, use it for targeted advertising, or place geofences around healthcare facilities to identify or target people. If we materially expand the categories or purposes described here, we will update this notice and obtain affirmative consent where required before the new collection, use, or disclosure.
The member App uses essential Supabase authentication cookies or equivalent browser storage to establish and refresh your session. Authentication cookies are generally set with SameSite=Lax and may persist until their configured expiration, which can extend beyond the current browser session. They may be refreshed during use and are cleared or invalidated through logout, expiration, or account deletion as applicable.
The App also uses localStorage, IndexedDB, and service-worker caches as described in Section 7. These technologies are necessary for core functions, preferences, offline use, and recovery. They are not used by the member App for third-party behavioral advertising.
The public website or external enrollment and checkout pages may use analytics or advertising tools, including Google Analytics, Meta Business Tools, or TikTok Business Tools, if enabled on those pages. Those tools may receive page URL, referrer, IP address, browser/device information, cookie or pixel identifiers, and events such as a page view, form submission, checkout start, or purchase.
We do not intentionally send those platforms App health logs, symptom entries, food logs, body-timing data, reflections, passwords, or private member-App activity. Where required, nonessential tools must be consent-gated and opt-out choices, including legally recognized browser signals, must be honored. We will not use enhanced matching, customer lists, or similar advertising features that send personal identifiers unless we update this policy and obtain any consent required by law.
Notifications are optional. Your browser or device asks for permission before the App creates a subscription. You can turn reminders off in Settings and revoke device/browser permission at any time. Messages may include program, meal, check-in, practice, or milestone reminders. We do not use health details in the notification body unless the feature clearly shows that content before you opt in.
Turning notifications off stops future sends. The App attempts to remove the server subscription when you disable the feature; browser or device controls can also stop delivery. Notification send records are eligible for cleanup after seven days, and an automated job is designed to remove failure records after 30 days. Actual removal can take longer during an outage, backup cycle, or operational delay.
We retain account and synced program data while your account is active and as reasonably needed to provide the service. Retention may be shorter when you delete an entry or local storage is pruned for space. Local quota management is designed to prune certain older records, such as recipe events after 90 days, check-ins and food logs after one year, body measurements after two years, and some delivery history after 30 days; pruning occurs as part of storage management and is not guaranteed on an exact date.
Diagnostic, hosting, database, and backup retention depends on provider configuration and backup rotation. We keep it only as reasonably necessary for operation, security, continuity, legal compliance, or claims. Aggregated or de-identified information that cannot reasonably be linked to you may be retained longer.
Settings includes tools to export health data as CSV, create a fuller JSON backup, and create a text visit summary. You can also contact us for an access request. Exporting does not delete the source data.
You may delete your account in Settings → Delete Account. You may also make an external request by emailing [email protected] with the subject Delete My 7DGR Account from the email associated with your account.
After an authenticated deletion request:
We may retain a limited deletion-audit record containing the account email or identifier, deletion date, provisioning source, request source, and deletion reason/status. We may also retain transaction, entitlement, fraud-prevention, security, tax, or legal records when reasonably necessary and permitted by law. We do not retain deleted health logs in the deletion-audit record.
Residual copies may remain temporarily in encrypted backups, immutable logs, or provider systems until their ordinary rotation or deletion process completes. Where Washington consumer health law applies, deletion from archived or backup systems will be completed within the period required by that law and no later than six months after authentication of the request. We will direct applicable processors or other recipients to honor a consumer-health deletion request when required.
Deleting an account is permanent and does not itself create a refund. Refund requests are governed by the Terms of Service and the purchase provider's rules.
Depending on where you live, you may have rights to:
The App provides direct controls for editing profile data, exporting data, managing notifications and body-timing uses, clearing progress, and deleting the account. Clear Progress is not account deletion and may preserve your profile, authentication, or selected settings.
To exercise a right, email [email protected] and identify the request. We may verify your identity and authority. An authorized agent may submit a request where local law permits, but we may require proof of authorization and direct identity verification. We will not unlawfully discriminate against you for exercising a privacy right.
In the preceding 12 months, we may have collected the categories described in Section 4: identifiers; customer/transaction records; internet or electronic activity; account credentials; inferences/preferences; and sensitive personal information, including health, body-timing, and account-login information. Sources, purposes, and recipients are described in Sections 3, 5, and 8.
We do not sell personal information or share member-App personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of anyone under 18. Where the CCPA/CPRA or another state law applies, residents may exercise the applicable access, correction, deletion, opt-out, limitation, portability, and appeal rights described above. Even when a particular statute does not apply to Mount Nurture LLC, we will make reasonable efforts to honor comparable requests.
Mount Nurture LLC is based in the United States. Our providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual or other lawful transfer safeguards and make information about them available upon request.
If you are in the EEA or UK, you may contact us to exercise your rights and may lodge a complaint with your local supervisory authority. You may also contact us to request information about the applicable international-transfer safeguard.
7DGR is intended only for adults 18 years of age or older. We do not knowingly collect personal information from children. If you believe a person under 18 has provided information, contact [email protected]. We will investigate and delete it as required.
7DGR is for education and general wellness. It does not diagnose, treat, cure, or prevent disease and does not create a healthcare-provider relationship. Do not use the App for emergencies. Seek immediate professional or emergency help for severe, unusual, persistent, or worsening symptoms, including severe pain, blood or black/tarry stool, persistent vomiting, fever with digestive symptoms, dehydration, or another urgent concern.
Information entered into a visit-ready summary is not automatically sent to a clinician. You decide whether to export or share it.
We monitor and respond to suspected security incidents. If an incident triggers a legal notification duty, we will notify affected individuals and regulators in the manner and timeframe required by applicable law, including applicable consumer health breach-notification rules.
We may update this policy when the App, providers, data practices, or law changes. We will post the revised policy, update the date above, and provide additional notice or obtain consent when required for a material new use of sensitive data. Prior versions may be requested by email.
For privacy questions, rights requests, appeals, or account deletion:
Mount Nurture LLC
1401 21st ST #7109
Sacramento, CA 95811
Phone: 747-777-3149
Email: [email protected]
Privacy Policy URL: https://7daygutreset.com/privacy-policy
We will respond within the timeframe required by applicable law.
This policy describes the current 7-Day Gut Reset codebase and operational design as of the effective date. It should be reviewed whenever data collection, service providers, checkout, mobile permissions, analytics, or health features change.