Privacy policy
What is collected, which is almost nothing.
A wall of clauses nobody reads is not consent. This is short enough to actually read, and it is the same policy the app shows you on its own screen.
On this page
- The short version
- Who is responsible
- Your health data stays on your device
- Your phone's own backup may include it
- There is no account
- Anonymous usage data, and how to switch it off
- Your data is never sold or shared
- What the app asks your phone for
- Subscriptions and purchases
- Keeping, exporting and deleting
- Your rights
- Children
- Security
- Changes to this policy
- Contact
1. The short version
Everything you record in PotsLog — entries, symptoms, standing tests, heart rate, medications, fluid, sodium, notes and reports — is stored on your phone and nowhere else. We have no server that holds it, no account that identifies you, and no copy of it. We do not sell it, share it, or hand it to anyone.
The one thing that can leave your phone is an anonymous count of which features get used, so the app can be improved. It never includes anything you recorded. You can switch it off in the app, in Settings → Your Data, and section 6 lists exactly what it contains.
2. Who is responsible
PotsLog is made and published by Nelu, the developer of the Android
application com.nelu.pots. For the purposes of the UK and EU General Data
Protection Regulation, Nelu is the controller for the limited usage data described in
section 6. Nelu is not a controller or processor of your health record,
because that record is never received — it stays on your device, under your control.
You can reach a person at nelucode@gmail.com.
3. Your health data stays on your device
Entries, symptoms, standing tests, medications and reports are stored on the phone you typed them into. They are not uploaded to us, not readable by us, and there is no server of ours for them to sit on.
Concretely, this means:
- The app stores your record in a database in its own private storage on the device, which other apps cannot read.
- Reports and exports are generated on the device. A PDF or spreadsheet goes wherever you send it — a file, a message, a print — and never to us.
- Uninstalling the app removes that storage, along with everything in it.
4. Your phone's own backup may include it
If you use Google Drive backup, your phone may include PotsLog the way it includes your other apps — to your account, under your password, where we cannot reach it. We are not part of that arrangement and never receive a copy.
This is deliberate rather than accidental. The app has no server by design, so your phone's own backup is the only thing standing between a dropped handset and a symptom record built over years. If you would rather it were excluded, you can turn app backup off for PotsLog in your phone's own backup settings, and the app's Your Data screen shows you the current state either way.
5. There is no account
You do not sign up, so there is no name, email address, username, password or profile for anyone to leak, subpoena or buy. The app does not ask who you are and has nowhere to put the answer.
We do not collect or use any advertising identifier, device identifier, installation identifier or hashed equivalent, and the app contains no advertising and no advertising SDK.
6. Anonymous usage data, and how to switch it off
The app can send anonymous counts about how it is used, through Google Firebase Analytics and Crashlytics, so that the parts people rely on can be improved and crashes can be fixed. This is on by default and you can turn it off at any time in Settings → Your Data → Anonymous usage data. Turning it off stops collection at the source rather than merely discarding it afterwards, and the choice survives a full data wipe.
What it can contain. The set of events the app is able to send is a fixed, closed list in its source code, and every value in it is a number — there is no way for text to be sent at all. The complete list:
| What is reported | The values attached |
|---|---|
| The app was opened | Whole days since install |
| A check-in was saved | None |
| A day was rated overall | Which of the three ratings, as a number |
| A standing test was completed | Whether it was a short check |
| A report was created | Window length; days since install |
| The plans screen was shown, scrolled or dismissed | Where it was opened from; scroll depth as a percentage |
| A paid feature was reached without a subscription | Which feature and which tier, as numbers; how many findings were waiting |
| A plan was chosen, bought, cancelled or failed | Which plan, as an index |
| A trial started or ended; a hardship grant was taken; purchases were restored | None, or a yes/no flag |
| Crash reports | The crash itself, plus the name of the screen it happened on |
What it can never contain. No symptom, no heart rate or blood pressure, no medication name, no note, no trigger, no severity, no fluid or sodium figure, no report contents, and no date of any entry. No user id, device id, installation id, advertising id or hashed identifier is attached to any of it, and no crash report carries a user key. These are not promises about our intentions; the app's event definitions accept numbers only, so a name or a note cannot be placed in one even by mistake.
Where this data does go, Google processes it as our processor under Firebase's terms, and it may be handled on servers outside your country. If a build of the app ships without Firebase configured, nothing is sent at all and the app makes no network request of any kind.
7. Your data is never sold or shared
Not with advertisers, not with insurers, not with employers, not with data brokers, not with researchers, not in aggregate, and not de-identified. There is no arrangement under which this changes, and there is no business model here that would want one.
We will disclose information only if we are legally compelled to — and the only thing we hold that could be disclosed is the anonymous usage data in section 6. Your health record is not ours to hand over.
If PotsLog were ever sold or transferred to someone else, this policy would go with it, and the change would be announced in the app before it took effect. There is still no health data to transfer.
8. What the app asks your phone for
Very little, and nothing that reads your body.
| Permission | Why |
|---|---|
| Notifications | Dose reminders and check-in reminders, at the times you set. Decline it and the app works; you just get no reminders. |
| Exact alarms | So a dose reminder arrives at the time it is due rather than whenever the system next feels like it. Used for dose reminders only. |
| Run at start-up | So reminders you already set survive a restart. |
That is the whole list. The app requests no location, no contacts, no camera, no microphone and no files, and it contains no advertising permission of any kind.
It does not read your phone’s health store. Earlier builds could read heart rate, sleep and steps from Android Health Connect, and this policy described that. They no longer can: the permissions are not declared, so there is nothing to grant and nothing to revoke. Your heart rate is the figure you or your watch put in front of you during a standing test and you enter; your sleep is what you type on the check-in screen. Everything in your record is something you put there.
9. Subscriptions and purchases
PotsLog Plus is billed by Google Play, not by us. Google handles the payment, holds the payment details and issues the receipt; we never see a card number, a billing address or your name. What the app receives back is whether an entitlement is active.
Google's own handling of that transaction is covered by Google's privacy policy.
10. Keeping, exporting and deleting
- How long your record is kept: for as long as you keep it. It is on your device and nothing expires it.
- Export: Settings → Your Data → Export all data gives you the whole record as a PDF, a spreadsheet or a complete backup file. Free on every plan, always.
- Delete: Settings → Your Data → Delete all data removes it from the device permanently and immediately. We have no copy to restore, so please export first if you want to keep one. Uninstalling the app has the same effect.
- Usage data: retained by Google Firebase under its standard retention settings and deleted on that schedule. Because it carries no identifier, it cannot be traced back to you or picked out for individual deletion — switching the setting off stops any further collection.
Full instructions, including what to do after uninstalling, are on the delete your data page.
11. Your rights
Under the UK/EU GDPR, the California Consumer Privacy Act and comparable laws elsewhere, you have rights to access, correct, delete, restrict, object to and port your personal data.
For your health record, the app satisfies all of them directly and immediately: you hold the only copy, you can read and edit every entry, export it in a portable format, and delete it outright. You do not need to ask us, and there is no request for us to fulfil, because there is nothing of yours in our possession.
For the anonymous usage data in section 6, our lawful basis is legitimate interest in maintaining and improving the app; it holds no identifier, so it cannot be linked to you. You can withdraw from it at any time with the in-app switch. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use it for cross-context behavioural advertising.
If you believe your rights have not been respected, write to us first at nelucode@gmail.com; you also have the right to complain to your national data protection authority.
12. Children
PotsLog is intended for people aged 18 and over and is not directed at children. We do not knowingly collect personal data from children. Since the app has no account and collects no identifying information, we have no way to detect a child's use of it — a parent or guardian who is concerned should uninstall the app, which removes everything it holds.
13. Security
Your record is held in the app's private storage, protected by the operating system's own sandbox and by your device's encryption and screen lock. The strongest security measure here is architectural rather than technical: data that never leaves a device cannot be intercepted in transit, exposed by a server breach, or taken in a credential leak, because none of those things exist in this product.
What that leaves you responsible for: a device lock, and care with any export file you create, which is an ordinary readable document once it is out of the app.
14. Changes to this policy
If this policy changes, the date at the top of this page changes with it and the updated version appears both here and on the app's own privacy screen — the two are generated from the same text and are not allowed to drift. A change that materially affects what is collected will be announced in the app before it takes effect, and never applied retroactively to data already recorded.
15. Contact
Email nelucode@gmail.com. It goes to someone who works on the app, not to a queue.
What this app is not — the medical disclaimer, which is the one that actually changes how you should use it · Terms of use · How to delete your data