GoutTracker.com

Privacy Policy

Last updated: 3/25/2026

This Privacy Policy complies with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Data Controller Information

The data controller responsible for your personal information is:

Alex Casteleiro

Operating as: NUCONET USA

Service: GoutTracker.com (provided via NucoAI.com)

Contact:

Our Commitment to Your Privacy

We take your privacy seriously. This privacy policy explains how we collect, use, protect, and share your personal health information.

We are not a covered entity under HIPAA, but we follow HIPAA-aligned best practices to protect your health data.

What Personal Information We Collect

We collect the following categories of personal information as defined by CCPA:

1. Identifiers

  • Email address (required)
  • Name (optional)
  • Unique user ID (automatically generated)

2. Health Information

  • Meals logged and food items consumed
  • Foot pain entries and pain levels (0-10 scale)
  • Optional notes about symptoms and triggers

3. Internet or Network Activity

  • Login times and session duration
  • Features used and pages viewed
  • Device type and browser information

4. Commercial Information

  • Subscription plan type (free or premium)
  • Payment transaction records (processed by Stripe)

We do NOT collect: Social Security numbers, medical record numbers, insurance information, precise geolocation, biometric data, or any sensitive personal information beyond what you voluntarily provide.

Sources of Personal Information

We collect personal information from the following sources:

  • Directly from you: When you create an account, log meals, track pain, or contact support
  • Automatically: Through cookies and analytics when you use the Service
  • Third-party authentication: Via Manus OAuth when you sign in
  • Payment processor: Transaction data from Stripe (we do not store credit card details)
Legal Basis for Processing (GDPR)

Under GDPR Article 6, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing is necessary to provide the tracking and analytics services you requested
  • Consent: You explicitly consent to us processing your health data when you create an account and log information
  • Legitimate Interest: We have a legitimate interest in improving our service through anonymized analytics and preventing fraud

You may withdraw your consent at any time by deleting your account. This will not affect the lawfulness of processing based on consent before its withdrawal.

How We Use Your Personal Information

We use your personal information for the following business and commercial purposes:

  • Service Delivery: Provide meal tracking, pain logging, and analytics features
  • Report Generation: Create printable reports and AI-generated summaries for healthcare discussions
  • Account Management: Manage your account, authentication, and subscription
  • Service Improvement: Analyze aggregated, anonymized data to improve features and user experience
  • Communication: Send service updates, security alerts, and respond to support requests
  • Legal Compliance: Comply with applicable laws and regulations
  • Fraud Prevention: Detect and prevent fraudulent activity and security threats

We do NOT use your personal health data for advertising, marketing to third parties, or any purpose unrelated to providing the Service.

How We Protect Your Data

We implement industry-standard security measures to protect your personal information:

  • Encryption in Transit: All data is encrypted using HTTPS/TLS (256-bit encryption) when transmitted between your device and our servers
  • Encryption at Rest: Your data is stored in encrypted databases with AES-256 encryption
  • Secure Authentication: We use secure session management with HTTP-only, secure cookies
  • Access Controls: Strict role-based access controls ensure only authorized personnel can access systems
  • Regular Security Audits: We conduct regular security assessments and vulnerability scans
  • Data Minimization: We collect only the minimum data necessary to provide the Service
Third-Party Disclosures and Data Sharing

We share personal information with the following categories of third parties:

  • Service Providers: Manus platform (hosting, authentication), Stripe (payment processing)
  • Analytics Providers: Google Analytics, Meta Pixel (Facebook), StatCounter, and Manus analytics (aggregated, non-PHI data only)
  • AI Service Providers: For generating report summaries (anonymized data only, no names or emails)

We do NOT sell, rent, or share your personal information for monetary or other valuable consideration. We do NOT sell your personal information to third parties.

All third-party service providers are contractually obligated to protect your data and use it only for the purposes we specify.

International Data Transfers

Your personal data may be transferred to and processed in countries outside your country of residence, including the United States.

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequate security measures equivalent to GDPR standards
  • Compliance with applicable data protection laws
Data Retention
  • Free Plan: Data older than today is automatically deleted daily to comply with free tier limitations
  • Premium Plan: Historical data is retained for one year (365 days). Data older than 365 days is automatically deleted to manage storage and comply with our retention policy
  • Account Data: Account information is retained until you delete your account
  • Billing Records: Transaction records are retained for 7 years as required by law
  • Anonymized Data: Aggregated, anonymized analytics data may be retained indefinitely for research and service improvement
Analytics, Cookies, and Tracking

We use multiple analytics services to understand how users interact with our Service and improve features:

  • Google Analytics: Tracks page views, user behavior, and traffic sources. Uses cookies to collect anonymous usage data. Google Privacy Policy
  • Meta Pixel (Facebook): Tracks conversions, user behavior, and enables targeted advertising. Uses cookies and browser fingerprinting. Meta Privacy Policy
  • StatCounter: Provides visitor statistics and web analytics. Uses cookies to track page views and user sessions. StatCounter Privacy Policy
  • Manus Analytics: Internal analytics for feature usage and performance monitoring (aggregated, non-PHI data only)

Important: No personally identifiable health information (PHI) is sent to external analytics services.

Analytics data includes: page views, button clicks, feature usage, traffic sources, device type, and browser information. It does NOT include: specific foods you log, pain levels, or any health details.

Cookies: We use both essential and analytics cookies:

  • Essential Cookies: Required for authentication and session management. Cannot be disabled.
  • Analytics Cookies: Used by Google Analytics, Meta Pixel, and StatCounter to track usage patterns. These help us improve the Service but are not strictly necessary for functionality.

Opting Out: You can opt out of analytics tracking by:

  • Using browser settings to block third-party cookies
  • Installing the Google Analytics Opt-out Browser Add-on
  • Enabling "Do Not Track" in your browser settings
  • Using privacy-focused browsers or extensions that block tracking scripts
Automated Decision-Making and Profiling

We use AI to generate report summaries for premium users. This is NOT automated decision-making that produces legal or similarly significant effects.

The AI summaries are:

  • Generated from anonymized data (no names or emails)
  • Used only to help you discuss patterns with your healthcare provider
  • Not used to make decisions about your health, eligibility, or access to services
  • Subject to your review and interpretation

We do NOT use profiling or automated decision-making for any other purposes.

Your Privacy Rights

Under GDPR (for EU/EEA residents) and CCPA (for California residents), you have the following rights:

1. Right to Access (GDPR Article 15 / CCPA Right to Know)

View all your personal data at any time through the app. Request a copy of your data in a portable format.

2. Right to Rectification (GDPR Article 16)

Correct or update any inaccurate or incomplete personal information.

3. Right to Erasure / Right to Delete (GDPR Article 17 / CCPA)

Request deletion of your personal data. When you delete your account, all your data is permanently removed within 30 days.

4. Right to Restriction of Processing (GDPR Article 18)

Request that we limit how we use your personal data in certain circumstances.

5. Right to Data Portability (GDPR Article 20)

Export your data in a machine-readable format (JSON/CSV) to transfer to another service (premium feature).

6. Right to Object (GDPR Article 21)

Object to processing of your personal data based on legitimate interests or for direct marketing purposes.

7. Right to Withdraw Consent (GDPR Article 7)

Withdraw your consent at any time by deleting your account or contacting us.

8. Right to Lodge a Complaint (GDPR Article 77)

EU/EEA residents have the right to lodge a complaint with their local supervisory authority if you believe we have violated your privacy rights.

9. Right to Non-Discrimination (CCPA)

We will not discriminate against you for exercising your CCPA rights. You will receive the same service quality regardless of whether you exercise your rights.

How to Exercise Your Rights:

  • Visit your account settings in the app
  • Contact us at nuconet.com/support
  • California residents: Use the "Do Not Sell My Personal Information" link below
Do Not Sell My Personal Information (CCPA)

We do NOT sell your personal information to third parties, and we have not sold personal information in the past 12 months.

Under CCPA, "sale" means disclosing personal information to third parties for monetary or other valuable consideration. We do not engage in this practice.

If our practices change in the future, we will update this policy and provide California residents with a clear "Do Not Sell My Personal Information" opt-out mechanism.

Authorized Agents (CCPA)

California residents may designate an authorized agent to make privacy requests on their behalf.

To use an authorized agent:

  • Provide written authorization signed by you (the consumer)
  • The agent must provide proof of their authority
  • We may require you to verify your identity directly with us
  • We may require you to confirm you gave the agent permission to submit the request
Identity Verification Process

To protect your privacy, we verify your identity before fulfilling data requests:

  • For access requests: We verify your email address and require you to log in to your account
  • For deletion requests: We require email verification plus additional confirmation to prevent accidental deletion
  • For sensitive data requests: We may require additional verification steps

If we cannot verify your identity, we will not be able to fulfill your request and will notify you of the reason.

Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours of becoming aware of the breach (GDPR requirement)
  • Notify relevant supervisory authorities as required by law
  • Provide details about what data was affected and steps we are taking
  • Offer guidance on how you can protect yourself

We maintain an incident response plan and conduct regular security assessments to minimize the risk of breaches.

Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information immediately.

Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements.

When we make material changes:

  • We will update the "Last updated" date at the top of this page
  • We will notify you via email or in-app notification
  • For significant changes, we may require you to review and accept the updated policy

Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy, want to exercise your rights, or have privacy concerns, please contact us:

Data Controller:

Alex Casteleiro / NUCONET USA

Contact Methods:

For GDPR-related inquiries, please include "GDPR Request" in your subject line.
For CCPA-related inquiries, please include "CCPA Request" in your subject line.

EU Representative (GDPR Article 27)

If you are located in the European Union and have questions about your data protection rights, you may contact us using the information above.

Note: As a small business operator, we may not be required to appoint a formal EU representative under GDPR Article 27(2). However, we are committed to responding to all EU data subject requests promptly.

Important: We are not a medical provider and this app is not a medical device. This privacy policy applies to the tracking tool only. Always consult with a qualified healthcare professional for medical advice.