This Privacy Policy explains what the PillOrg app (the “App”) does with your information. PillOrg is operated by an individual developer (contact details at the end of this policy), who is the data controller for the purposes of the GDPR and UK GDPR.
Your health data never leaves your device. What medications you take, when you take them and whether you took them is data concerning health — a special category of personal data under Article 9 of the GDPR, and “consumer health data” under several US state laws. PillOrg has no account, no server and no sync: it is stored on your own device and nowhere else. We never receive it, we cannot see it, and there is nothing of yours for us to hand over to anyone.
The App keeps the following as files in its own private storage:
PillOrg contains no analytics SDK, no advertising SDK, no crash reporter and no tracking of any kind. There is no sign-up, so we never learn your name or your email address. We do not know what you take, we do not know whether you took it, and we do not build a profile of you. This is not a policy position but a fact about how the App is built: there is nowhere for that information to go.
One request, and it carries nothing about your health.
If you buy PillOrg Pro, purchase handling goes through RevenueCat. It receives an anonymous identifier generated for that installation, your purchase receipt and basic device and country information — enough to tell the App whether Pro is active and to restore it on a new device. It never receives a medication name, a dose, a schedule or an intake record. Payment itself is handled entirely by Apple or Google; we never see your payment card details.
RevenueCat's Customer Center, which the App can open so you can cancel, request a refund or answer an exit survey, is part of the same service and receives the same purchase data and nothing more.
If you never buy anything, PillOrg makes no network requests at all.
Dose reminders are local notifications, scheduled by your device from data that never leaves it. No server is involved, so they arrive in airplane mode. A notification shows the medication and the dose on your lock screen, and its Take, Skip and Snooze buttons are handled entirely on the device. If a lock-screen preview is more than you want a passer-by to see, hide notification content for PillOrg in your system settings.
| Provider | What it receives | Where |
|---|---|---|
| RevenueCat, Inc. | Purchase receipts and an anonymous installation identifier — only if you buy Pro. Never health data | United States |
| Apple Inc. / Google LLC | Payment processing for a purchase | Global |
Each of these receives data under its own privacy policy. We will update this table whenever a provider is added or removed.
Because nothing of yours is stored on a server, there is no database of yours to transfer anywhere. The limited purchase data above is processed in the United States; where personal data is transferred out of the European Economic Area or the United Kingdom, those transfers rely on the European Commission's Standard Contractual Clauses, which our providers incorporate into their agreements with us.
Your medications and your intake history stay on your device for as long as you keep the App installed. Deleting the App deletes all of it — there is no copy anywhere else, and nothing to restore. Purchase records held by RevenueCat, Apple or Google are kept under their own retention rules, because they are part of a billing relationship rather than something we hold.
Delete a medication, a course, a logged dose or a whole profile in the App, or remove the App to delete everything at once. There is no account to close and no request to send us. See Your data and how to delete it for the details.
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to receive a copy in a portable format, to have it deleted, and to object to or restrict processing. In PillOrg's case those rights are largely satisfied by the design: your health data is already in your hands, and we hold none of it. For the purchase data described above, email us and we will help. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decision-making. If you are in the EEA or the UK you also have the right to lodge a complaint with your local data protection authority.
PillOrg lets you keep a profile for someone else — a partner, a parent, or your child. Because none of it leaves your device, there is no request for them to make of us; the records are in your hands and it is for you to manage them responsibly. If you keep records for another adult, please make sure they know and agree. The App is intended for adults and is not directed to children.
Your data sits in the App's private storage, protected by your device's own sandbox and, where you have enabled it, its encryption. PillOrg does not lock itself behind a passcode or biometrics, so anyone holding your unlocked device can see what you take — keep a device passcode.
We may update this policy as the App changes. The date and version at the top reflect the latest revision. If a change materially affects what leaves your device or who receives it, we will say so in the App.
Questions, requests or complaints about your privacy? Email mail@timeofjohnny.com. We aim to reply within a few business days.