Privacy notice
Version 2026-09-22. Written in plain English on purpose.
Who we are
Crohnsworld is run by Eightlegged Ltd, Woodend Creative Centre, The Crescent, Scarborough, YO11 2PW, United Kingdom. We are the data controller and we are registered with the Information Commissioner's Office. Contact: privacy@crohnsworld.co.uk.
What we store
- Your email address and a scrambled version of your password. That is all we need to give you an account. We do not ask for your name, date of birth, NHS number or address. A display name is optional.
- What you log. Toilet visits and their details, pain, notes, daily check-ins, medications and test results if you choose to enter them, and your settings. This is information about your health, which the law treats as special category data.
- Technical records. The address your device connected from when you signed up (kept for 30 days to deal with abuse, then deleted), and standard web server logs kept for up to 30 days.
- Push notification subscriptions, if you turn reminders on. A reminder never contains anything you logged.
Why we store it, and our legal basis
We store what you log because you asked us to: that is the whole point of the site. Under UK GDPR our lawful basis is your explicit consent (Article 9(2)(a) for health data, Article 6(1)(a) otherwise), which you give when you create an account and can withdraw at any time by deleting your account. Server logs and abuse records are kept under our legitimate interest in running a secure service (Article 6(1)(f)).
What we do not do
- We do not sell, share, rent or trade your data with anyone.
- We do not use advertising or analytics scripts on any page that shows your data. Nothing on the tracker loads from another company's servers.
- We do not use your data for research, marketing or profiling. If we ever want to ask about research, we will ask, and "no" will cost you nothing.
- We do not put anything you logged into an email or a notification.
Where it lives
On servers in the United Kingdom operated by Eightlegged Ltd. Connections are encrypted (HTTPS). Passwords are stored as one-way hashes that cannot be turned back into your password.
Your rights
- See and take your data: the Settings page has an export button that gives you everything as a spreadsheet file, any time, no questions.
- Delete everything: the Settings page has a delete button. It permanently removes your account and every record. There is no "soft delete" and no 30-day grace period on our side; once it is gone, it is gone.
- Correct anything: every entry can be edited or deleted in the tracker.
- You can also complain to the ICO at ico.org.uk if you think we have got something wrong. We would rather you told us first.
How long we keep it
For as long as you have an account. Accounts that never confirm their email address are removed after 48 hours. If an account is not used for three years we will email you before removing it.
Cookies and storage on your device
One cookie keeps you signed in. The tracker also keeps a copy of your entries in your browser's storage so it works when you have no signal; that copy stays on your device. There are no advertising or tracking cookies.
Changes
If this notice changes in a way that matters, we will tell you when you next sign in and ask you to agree again. The version number at the top changes every time the text does.