Privacy Policy

Last updated: May 13, 2026

This Privacy Policy describes how Elyon Tech LLC ("we", "our", "us"), operating the mobile application Poo Poo (the "app", "our service"), collects, uses, and protects your information.

Who we are

The data controller for your personal data under this Policy is:

Elyon Tech LLC
75 E 3rd St
Sheridan, WY 82801
United States
Email: hello@poopoo.app

EU/EEA representative (GDPR Article 27):
Theodosios Kaxiras
Plateon 44
54249 Thessaloniki
Greece
Email: hello@poopoo.app

TL;DR โ€” The short version

1. Data we collect

1.1 Account data

1.2 Health and lifestyle data (special category โ€” GDPR Article 9)

Everything you log in the app is stored on your device. This includes:

This data is used to personalize the app and the analyses you request. It stays on your device unless you explicitly export it.

1.3 Photos

Photos you capture inside the app are stored locally. When you log a meal / poo / drink / pill / menu, the photo is sent once to Google's Gemini AI service (Google LLC) via our own Firebase Cloud Function over HTTPS for analysis. The analysis is returned as text and stored locally. Under the paid Gemini API agreement, Google does not retain photos after analysis completes and does not use them to train any AI model. We never store photos on our own servers. We do not transmit your name, email, account identifier, device ID, or IP address along with the photo — only the photo bytes and a brief textual prompt are sent to Gemini.

1.4 Crash diagnostics

Unless you opt out in Settings โ†’ Privacy, the app sends anonymized crash reports to our error monitoring provider, tagged with your Firebase user ID. We do not collect IP addresses (explicitly suppressed), advertising IDs, location, contacts, or browsing history.

2. Lawful basis for processing (GDPR)

Under the EU GDPR we process your data on the following lawful bases:

3. Named third-party processors

We share data only with the specific processors listed below. Each is contractually bound (via Data Processing Agreement, EU Standard Contractual Clauses, or equivalent) to safeguards equal to those in this policy.

We do not sell your data, do not share with advertising networks, and do not profile you for any purpose other than personalising the analyses you request.

4. International data transfers

Our processors are located outside the EEA, principally in the United States. Where personal data is transferred outside the EEA we rely on:

You can request a copy of the safeguards by emailing hello@poopoo.app.

5. How long we keep your data

6. Your rights under GDPR

If you are in the EU, EEA, UK, or Switzerland, you have the rights below. We respond within one calendar month. Email hello@poopoo.app with "GDPR request" in the subject. We do not charge a fee.

7. Automated decision-making and AI

The AI features (photo analysis, "Analyze My Patterns", "Generate AI Statistics", "Ask Tummy", "Can I Eat This?", "Menu Analyzer") use Google's Gemini AI service (Google LLC), accessed via our own Firebase Cloud Function. Each request sends only the photo or text you submitted plus a brief textual prompt — never your name, email, or account identifier. The AI is located in the United States and is not designed for medical use.

These features do not produce decisions with legal or similarly significant effects on you within the meaning of GDPR Article 22. The output is informational and always reviewable, editable, and deletable by you. Each AI screen provides a "Report this response" link to flag inappropriate output (EU AI Act Article 50 transparency obligation).

AI output may be inaccurate, incomplete, or misleading. It is not medical advice. Google Gemini is a general-purpose AI model, not designed for medical use. We do not use it to diagnose, treat, monitor, prevent, or predict any disease.

8. Children

Poo Poo is intended for users aged 16 and older. For users in the EU, EEA, UK, and Switzerland we apply a 16+ minimum age regardless of any lower digital-consent age set by your country. The same minimum applies elsewhere.

We do not knowingly collect data from children under 16. If you believe a child under 16 has provided us with information, email hello@poopoo.app and we will delete it without delay.

9. Data security

All network communication uses TLS encryption. Authentication tokens are stored in the device's secure storage. Local data is protected by the device's own encryption. Server secrets are kept in Google Secret Manager. No system is 100% secure, but we take reasonable steps to protect your information.

If we ever discover a personal data breach affecting your rights, we will notify you and the competent supervisory authority within 72 hours of becoming aware (GDPR Article 33).

10. Not a medical device

Poo Poo is a wellness and lifestyle journal. It is not a medical device and is not intended to diagnose, treat, monitor, prevent, or predict any disease or medical condition. AI-generated insights are for informational purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical concerns.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the app or email. The "Last updated" date at the top reflects the most recent version.

12. Contact us

Questions about this policy or your data rights:

Elyon Tech LLC
Attn: Privacy
75 E 3rd St
Sheridan, WY 82801
United States
Email: hello@poopoo.app

EU/EEA representative (GDPR Article 27):
Theodosios Kaxiras
Plateon 44
54249 Thessaloniki
Greece
Email: hello@poopoo.app