Legal Documentation

Privacy Policy

At PenPal, your privacy is our priority. This policy explains how we handle your data with transparency and integrity.

calendar_today Last Updated: August 23, 2026

01 Information We Collect

We collect information to provide core features of the App, improve user experience, and operate the service. Types of information we collect include:

Personal and Account Information

  • Name and email address provided during account creation or support.
  • Account metadata (creation date, subscription status, preferences).

Health, Medical and Wellness Data

  • Medication schedules, doses, and reminders.
  • Side-effect logs, symptoms, and weight-management related notes.
  • Water intake and exercise logs.

Photos and Media

  • Photos taken for AI-powered nutrition analysis or attached to logs.
  • Media metadata (e.g., capture time).

Platform & Integration Data

  • Device model, OS version, and app diagnostic data (crash reports).
  • Data from Apple Sign-In (AuthenticationServices) if authorized.
  • Subscription status via Apple App Store.
  • For marketing measurement: a pseudonymous AppsFlyer ID and attribution signals. We do not send your name, email, phone number, PenID, Firebase UID, or hashed personal information to AppsFlyer.
  • If you choose to connect Apple Health: step count, active energy, workouts, body mass, and dietary water. Apple Health access is optional and remains off until you enable it.

Apple Health Data Boundaries

  • Apple Health imports, permission state, query checkpoints, and cached Health samples stay on your device and are not uploaded to PenPal cloud storage.
  • Manual workouts you create in PenPal may sync to your PenPal account like other manual logs. Their Apple Health origin or Health sample metadata is not uploaded.
  • After you connect Apple Health, PenPal may write new or changed workouts, weight entries, and water entries that you create in PenPal. PenPal does not bulk-export entries created before you connected.

02 How We Use Your Information

We use your information for the following purposes:

  • Core Operations: Provide reminders, logging, real-time syncing, and PDF report generation.
  • AI Nutrition Analysis: Process photos and text to identify nutritional intake (see AI Disclosure).
  • Communication: Update you on account status, subscriptions, and security notices.
  • Support: Provide in-app customer support and respond to inquiries.
  • Improvement: Analyze performance metrics to diagnose problems and monitor usage trends.
  • Marketing measurement: Use AppsFlyer and, where applicable, App Tracking Transparency permission to measure which campaigns lead to installs, onboarding completion, checkout, and subscriptions. This is an attribution signal only; health, medication, nutrition, exercise, and Apple Health data are never used for advertising, profiling, or campaign optimization.
  • Compliance: Enforce our terms and comply with legal obligations.

We do not use Apple Health or other health and sensitive data for advertising, marketing, profiling, data mining, or sale to third parties.

03 Sharing and Third Parties

We may share information with trusted third parties only to operate our services:

  • AppsFlyer: If marketing measurement is enabled, AppsFlyer receives only the allowlisted attribution events needed to measure installs, onboarding completion, registration, paywall views, checkout, and retention. AppsFlyer does not receive PenPal health or medication events, onboarding answers, PII, or client-side purchase revenue.
  • Advertising partners: AppsFlyer may share the same limited conversion signals with configured Apple Ads, Meta, Google Ads, and TikTok integrations for campaign measurement and optimization. If App Tracking Transparency is denied, the AppsFlyer SDK does not use the IDFA.
  • RevenueCat: RevenueCat processes App Store subscription status and is the sole source for subscription revenue and lifecycle events sent server-to-server to AppsFlyer. PenPal does not send a duplicate client-side revenue event.
  • Service Providers: We engage vendors for authentication, push notifications, secure cloud storage, and product analytics. They are contractually limited to using your data only for these services.
  • Apple: Platform services (App Store billing, Sign-In with Apple, and Apple Health when you enable it) are subject to Apple's privacy policies. PenPal exchanges only the Health data types described above and only according to the permissions you select in Apple’s system sheet.
  • Website support: If you use the website contact form, we receive the name, email address, subject, and message you submit so we can respond. The form routes support messages through our configured support provider. Please do not include medication details, symptoms, or other sensitive health information in that form.
  • Legal Requirements: We may disclose information if required by law or to protect safety and security.

No Third-Party Ads or Health Data Sharing: We do not serve third-party ads and do not sell or share health, medication, nutrition, exercise, or Apple Health data for advertising.

04 Data Retention

  • Active Data: Retained while your account is active.
  • Deletion Requests: Personal data is deleted from active systems within 90 days of request. Backups may remain for up to 12 months.
  • Subscription Records: Retained as required for legal and recordkeeping purposes.
  • Attribution records: One or more pseudonymous AppsFlyer IDs may be linked to your Firebase account only on our backend to answer deletion requests across your devices. We do not set an AppsFlyer customer user ID. When you delete your account, PenPal submits an AppsFlyer OpenDSR erasure request for each ID and removes the mappings after AppsFlyer accepts them.
  • Apple Health Copies: Turning off PenPal’s Apple Health sync removes imported Health copies, synchronization checkpoints, and unfinished Apple Health reward progress from PenPal on that device. Achievements and completed objectives already earned remain. This does not delete original data in Apple Health or PenPal entries previously written there.

05 Security Measures

We implement professional administrative and technical safeguards:

  • Encryption in transit (TLS) and at rest where feasible.
  • Access controls based on least-privilege practices.
  • Regular security assessments and system monitoring.
  • Secure session management for user accounts.

06 Children's Privacy

PenPal is not intended for children under 13. We do not knowingly collect data from children under this age. If we learn such data has been collected without consent, we will delete it immediately. Contact support@trypenpal.app for concerns.

07 Your Legal Rights

Depending on your location (GDPR/CCPA), you have rights including:

  • Access & Portability: Request a copy of your data in a machine-readable format.
  • Rectification & Deletion: Correct inaccurate data or request deletion.
  • Withdraw Consent: Revoke permissions at any time for future processing.

You can withdraw App Tracking Transparency permission in iOS Settings and turn off PenPal’s automatic Apple Health sync in the App. Apple Health permissions themselves are managed in Apple’s Settings or Health app. Exercise other rights via in-app settings or by emailing support@trypenpal.app.

08 AI & Automated Processing

The App uses AI-powered analysis for nutrition logging and convenience features:

  • Purpose: Estimates nutritional intake from photos and text.
  • Processing: Where possible, AI processing is performed on-device. Advanced tasks may use secure cloud-based services.
  • No Legal Effect: AI does not make legally binding decisions or substitute for medical advice.
  • Opt-out: You can disable AI features by revoking media permissions or in settings.

09 Purchases & Subscriptions

  • Billing: Handled entirely by Apple App Store. We do not store payment details.
  • Revenue measurement: RevenueCat is the subscription lifecycle authority. After marketing measurement and attribution are enabled, RevenueCat sends the configured subscription lifecycle events to AppsFlyer server-to-server using the paid gross amount selected in the integration settings.
  • Auto-Renewal: Subscriptions renew unless cancelled in Apple ID settings 24 hours before expiration.
  • Refunds: Managed exclusively by Apple Support.

10 Policy Changes

We may update this Policy to reflect practice or legal changes. Material changes will be notified via the App or website. Continued use constitutes acceptance of the revised terms.

11 Contact Us

For questions or rights requests:

PenPal Support

Email: support@trypenpal.app

Website: https://www.trypenpal.app

Any other questions?

Our support team is here to help you understand how your health data is protected.