Operator: sora Jung, the individual developer operating PillNotify
Effective date: 2026-09-11
PillNotify stores supplement and reminder information on the device and provides general nutrition reference information. This is wellness/nutrition information and does not diagnose, treat, prevent, or determine individual safety or suitability. PillNotify currently has no account creation or account-based synchronization.
The app may store supplement names, notes, dosage and reminder times, reviewed ingredient candidates, intake checks and records, an adult Nutrition reference profile, app/consent state, and secure-storage values for AI cache and request recovery. There is currently no single control to delete all local data.
After the external-processing disclosure, an AI lookup sends requestId, the entered supplementName, and locale to the server. An App Check token and installation identifier may be technical headers. Dosage, intake times, the Nutrition profile, other supplements, and health records are not in the AI request body.
The server sends the supplement name and resolver instructions/schema/model metadata to OpenAI. store:false is not a promise of zero-day retention or the absence of all operational or legal retention by the provider.
Firebase Analytics may collect screen and limited feature events; Crashlytics may collect release crash and fatal-error diagnostics. AdMob and UMP provide ads, consent, and privacy options, and iOS may request ATT authorization. App Check/platform attestation and an installation identifier protect resolver requests and quota.
Advertising and analytics SDKs may process approximate location derived from network information such as an IP address, along with advertising, usage, performance, and diagnostic data. PillNotify does not directly collect precise GPS location for this purpose.
The server may use HMAC/digests of installation identity and request input, request state and limited result DTOs/failure categories, quota state, budget reservations, processing times, and allowlisted operational logs. This is pseudonymous operational metadata. Cloud Run/Firebase managed-access or audit metadata may also exist.
Users can delete individual supplements, intake records, and the Nutrition profile using the available screens. There is currently no server-metadata deletion API/UI or control for deleting all user data. How every platform secure-storage item behaves on uninstall requires separate verification.
Requests can be sent to aros.care@gmail.com through a manual review process; Requestors should provide a reply address and minimum time/feature details only. Do not send App Check tokens, installation identifiers, API keys, secrets, or raw health information. The operator would determine which User quota, Request, or Budget metadata can be located using pseudonymous HMAC/digests and reply with the scope and outcome. Immediate deletion cannot be promised for TTL-processed records, provider/Firebase/Cloud Run managed logs, backups, or legally retained records. This process is not active until its tools, authorization, and response period are finalized.
Users may enter ingredients manually without AI and may use UMP privacy options where available. Nutrition Guide references are for nonpregnant, nonlactating adults aged 19 or older. Firebase, AdMob, OpenAI, and other third-party services may process data outside the user’s country; current provider terms and store disclosures must be checked.
Support: aros.care@gmail.com
When data flows, SDKs, or retention change, this policy and store disclosures will be reviewed together with an effective date and change summary.
This page is not legal advice.