Legal
Privacy Policy
Version 1.0, in effect since September 7, 2026
1. The short version
Our commitments
- Your health data is yours. We never sell it, and we never rent or share it for anyone’s advertising.
- We do not use it to train models, ours or anyone else’s.
- We collect as little as we can to make the Service work, and we do not ask for your real name to use the app.
- It is protected in transit and at rest, and access inside our team is limited to what a person needs to do their job.
- Nothing is shared with a doctor, an insurer, an employer or a family member unless you choose to share it by generating an export yourself.
- Notifications never name a medicine. A reminder on your lock screen says nothing more explicit than “treatment”.
- You can export or delete everything, at any time.
The rest of this page is the detail. If you are in the United States, read our Consumer Health Data Privacy Notice as well: it carries the specific disclosures required by state health-privacy laws.
2. Who is responsible for your data
The data controller is Oolite OÜ (company being incorporated in Estonia; until registration, its founder acts as controller on its behalf), Estonia.
Privacy contact: fidele.richelieu@gmail.com. Representative under Article 27 GDPR: not required, the controller is established in the European Union.
3. What we collect
a. What you give us
- Waitlist: your e-mail address, and the answers you choose to give to the short pre-launch questions.
- Account: an e-mail address and authentication data. We do not require your legal name, your address or your date of birth.
- What you record in the app: the treatment you are following and its schedule, doses and times you log, weight, symptoms and side effects, mood and appetite, notes, photos or voice notes if you add them. This is health data, and section 4 applies to it.
- Support: what you write to us and the contact details you write from.
b. What is collected automatically
- Technical data: device type, operating system, app version, language, approximate region derived from your IP address, crash reports and error logs.
- Usage measurement: pages or screens opened, features used, and the source that brought you to the site. We use this in aggregate to understand what works, not to profile you.
- Cookies and similar technologies on the website. See section 12.
c. What you connect, only if you choose to
- Data from a health platform on your device (for example weight from Apple Health), read only with your explicit permission and only for the purpose you enabled. You can withdraw that permission in your device settings at any time.
We do not buy personal data from data brokers, and we do not collect precise location.
4. Health data deserves special treatment
Information about a treatment, a symptom or a body measurement is a special category of personal data under the GDPR and consumer health data under several US state laws. We process it only with your explicit consent, given when you create your account or enable the relevant feature, and only for the purposes described in section 5.
You can withdraw that consent at any time, from the app or by writing to us. Withdrawing it stops any further processing for that purpose and, if you ask, we delete the data. That also means the Service can no longer show you your history.
We are not a HIPAA covered entity or a business associate: HIPAA protects data held by healthcare providers and insurers, not data you record yourself in a consumer app. Your data is protected by this policy and by the laws referred to in sections 10 and 11.
5. Why we use it, and on what legal basis
- To provide the Service: store your entries, send the reminders you set, draw your charts, build an export you asked for. Basis: performance of our contract with you, and your explicit consent for health data.
- To keep it working and secure: diagnose crashes, prevent abuse and fraud, protect accounts. Basis: our legitimate interest in a safe, functioning service, and our legal obligations.
- To improve the product: aggregated, de-identified usage measurement. Basis: legitimate interest, or consent where the law requires it. We do not use the content of your health entries for this.
- To communicate with you: service messages, replies to your questions, and waitlist or marketing e-mails you asked for and can leave at any time. Basis: contract, legitimate interest, or consent.
- To comply with the law: accounting, and answering a lawful, binding request from an authority. Basis: legal obligation.
We do not make decisions about you by automated means that produce legal or similarly significant effects.
6. What we never do
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
- We do not use health data for advertising or to build advertising audiences, on our site or anywhere else.
- We do not use your health data to train artificial intelligence models, and we do not give it to a third party to do so.
- We do not send your data to an employer, an insurer, a pharmaceutical company or a data broker.
- We do not name a medicine in a notification, an e-mail subject line or anywhere else it could be read over your shoulder.
8. Where your data is stored
We are established in Estonia and use providers located in the European Economic Area and in the United States. Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision or on the European Commission’s standard contractual clauses, together with additional technical measures such as encryption. You can ask us for a copy of the safeguards we use.
9. How long we keep it
- Your entries: for as long as your account is open, because their whole point is your history. Delete an entry and it goes; delete your account and everything goes.
- After deletion: data is removed from our live systems promptly and disappears from encrypted backups within the backup rotation, which does not exceed 90 days.
- Waitlist e-mails: until you unsubscribe or ask us to delete them, and in any case no longer than three years after our last contact with you.
- Logs and security records: up to 12 months.
- Accounting records: for the period the law requires.
10. How we protect it
- Encryption in transit (TLS) and encryption at rest.
- Access limited to the few people who need it, with individual accounts and multi-factor authentication.
- Separation of production data from test data, and no use of real user data in development.
- Providers selected for their own security posture, under a data processing agreement.
- An internal procedure for security incidents, including notification to the competent authority and to you where the law requires it.
No service can promise perfect security, and we do not. What we can promise is that we design for the smallest possible amount of data, that we take protection seriously, and that we tell you honestly if something goes wrong.
11. Your rights
Wherever you live, you can ask us to: give you a copy of your data; correct it; delete it; export it in a portable format; restrict or object to a particular use; or withdraw a consent you have given. Exercising a right never costs you anything and never means worse treatment.
Write to fidele.richelieu@gmail.com. We reply within 30 days, or tell you why we need longer. We may need to check that the request really comes from you, using the e-mail address on the account. We will not ask you for extra identity documents unless we have no other way.
If you are in the EEA or the UK, you may also complain to your data protection authority; in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon). If you are in the United States, see the state-specific rights in our Consumer Health Data Privacy Notice, including the right to appeal a refusal.
13. Children
The Service is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, write to fidele.richelieu@gmail.com and we will delete it.
14. Changes to this policy
We update this policy when the Service or the law changes. The effective date at the top always tells you which version is in force. If a change materially affects how we use your data, we tell you before it takes effect and, where the law requires it, ask for your consent again.
15. Contact
Privacy questions and requests: fidele.richelieu@gmail.com.