Pilloved
Back to home

Privacy Policy

Last updated 1 September 2026

Pilloved is built around health information, so privacy isn't a feature — it's the foundation. Medication names, doses, and notes are encrypted on your device, so our servers only ever store scrambled data. This policy explains what we collect, why we collect it, how we protect it, and the choices you have.

1. Who we are

This Privacy Policy describes how Pilloved ("Pilloved", "we", "us", or "our") handles personal information in connection with the Pilloved mobile application and https://pilloved.com (together, the "Service").

Pilloved is the data controller for the personal information described in this policy. If you have any questions, you can reach us at hello@dobro.dev.

2. Information we collect

We collect only what we need to make shared medication tracking work. This falls into a few categories:

  • Account information — your name, email address, and authentication details used to create and secure your account.
  • Health information — the medications, doses, schedules, and notes you add. The sensitive parts (medication names, doses, and notes) are encrypted on your device before they reach us, so we store only scrambled data we cannot read.
  • Short names for alerts — an optional short name for you or for a managed profile, so an alert can name who it is about on a lock screen, and an optional nickname and emoji for a medication, so an alert can name which medication it is about. Unlike your display name and your medication names, these are stored unencrypted; section 4 explains why, and how to change or remove them.
  • Group and coordination data — group membership, roles (patient, monitor, admin), dose timing, and dose status (taken, skipped, snoozed). This timing data is not encrypted, which is what lets reminders and missed-dose escalation work reliably even when a phone is asleep.
  • Device and technical data — device type, operating system, app version, push-notification tokens, IP address, and time zone, used to deliver notifications and keep the Service secure and functioning.
  • Diagnostic and usage data — crash reports and basic, aggregated usage information that helps us find bugs and improve the app.

3. Encryption, and your recovery code

Medication names, doses, and notes are encrypted on your device using keys we never see. So are your health log entries, your patient notes, and the names and dates of birth of any managed profiles you create. Our servers store only the encrypted, scrambled version, which means we cannot read your medication details — and neither can anyone who might gain access to our infrastructure.

Timing, schedules, dose status, and group membership are intentionally not encrypted. That trade-off is deliberate: it's what allows server-side jobs to generate doses, send reminders, and escalate missed doses on time, without ever needing to read your private health details.

The key that unlocks the encrypted fields lives on your devices and, in wrapped form, on the recovery code the app asks you to save when you first create a group. We do not hold that key and cannot recreate it.

This has a consequence worth stating plainly: if you lose access to all your devices and do not have your recovery code, your encrypted data is permanently unreadable. We cannot recover it — not for any reason, including a support request. There is no back door and no support override. Please keep your recovery code somewhere safe, like a password manager. You can view it again at any time in the app under Settings → Security → Recovery code, and Settings → Export my data writes your full history to a CSV whenever you like, free on every plan.

4. The short names you allow in alerts

Because your display name and your medication names are encrypted, a notification we send can only say "Dose overdue" — it has nothing readable to name. The short names listed in section 2 are the deliberate exception: when you allow your name in alerts, we store a short version of it unencrypted, so an alert to someone who monitors your doses can read "Michael: dose overdue" instead. The same applies to a managed profile you set up, and, separately, to a nickname and emoji you can give an individual medication.

These are the only fields we store unencrypted for the sake of a notification. You choose whether to have them at all and what they say, they are never generated from your encrypted data without your having turned them on, and you can change or remove any of them at any time — yours in Settings, a managed profile's on the Group screen, a medication's on that medication. Removing one returns the affected alerts to their unnamed wording. The encrypted names themselves are never altered by any of this.

Two consequences worth stating outright. First, anything you put in one of these fields can appear on a lock screen, including one someone else can see — pick wording you are comfortable with there. Second, because they are unencrypted, we and our hosting provider can read them, and they would be readable in a data breach.

5. How we use your information

We use the information we collect to:

  • Provide the Service — create your account, sync data across devices, and show each person the doses and groups they're part of.
  • Send reminders and nudges — deliver timezone-aware reminders, monitor nudges, and missed-dose escalations.
  • Keep the Service secure — detect, prevent, and respond to fraud, abuse, and security incidents.
  • Support you — respond to your questions and requests.
  • Improve Pilloved — fix bugs and understand, in aggregate, how features are used.
  • Meet legal obligations — comply with applicable laws and enforce our Terms of Service.

6. We do not sell your data

We do not sell your personal information, and we never use your health information for advertising. Because medication names, doses, and notes are encrypted on your device, we have no access to those details in the first place.

7. How information is shared

We share information only in the limited circumstances below:

  • Within your groups — data is shared with the people you invite, in the roles you assign. Every record is protected by row-level security: patients see their own data, monitors see only the medications assigned to them, and group admins manage their own group.
  • Service providers — Supabase (database, authentication, and server-side jobs, where the encrypted fields remain scrambled to them), Google Firebase (push-notification delivery, and product analytics if you leave them enabled), and Sentry (crash diagnostics, scrubbed before they are sent so that message bodies, request payloads, and headers are removed and only your account ID remains). If you buy a subscription, Apple or Google process the payment and tell us only that a purchase happened — we never receive your card details. These providers are based in the United States and process data on our behalf under contractual confidentiality and security obligations.
  • Legal reasons — we may disclose information if required by law, regulation, legal process, or to protect the rights, safety, and security of our users, the public, or Pilloved.
  • Business transfers — if Pilloved is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

8. Data retention

We keep your information for as long as your account is active or as needed to provide the Service, and for as long as we're required to keep it for legal, accounting, or security purposes.

When you delete your account, we delete the account and the personal data attached to it, including the records of any subscription you bought. Deletion lives in the app under Settings → Delete account and takes effect immediately; copies linger in our backups, which age out within 30 days. If you no longer have the app installed, you can request deletion at pilloved.com/delete-account.

Two things sit outside what our deletion can reach. If you subscribed, Apple or Google keeps its own record of that transaction under its own policies — we don't control it, so you'd need to ask them. And if you're the only organizer of a group that still has other members, we ask you to hand that role to someone else first, so the group isn't left with nobody who can manage it; deleting as a group's only member removes the group along with you.

9. Your rights and choices

Depending on where you live, you may have some or all of the following rights over your personal information:

  • Access — most of your data is visible in the app, and Settings → Export my data writes your full history to a CSV file you can keep or take elsewhere. It's free on every plan, it covers everything on your account rather than a recent window, and it's built on your device, because that's the only place your data can be read. The formatted, doctor-ready report under Insights is a paid convenience — a nicer rendering of what the export already gives you in full.
  • Correction — edit or update the medications, profiles, and groups you manage at any time, directly in the app.
  • Deletion — delete your account and its data yourself, in the app, under Settings → Delete account. If you no longer have the app installed, use pilloved.com/delete-account.
  • Portability — the CSV export above is yours to take anywhere, or you can ask us for your data in another portable format.
  • Objection and restriction — turn usage analytics off in Settings, turn notifications off on your device, or ask us to restrict certain processing.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

10. Security

Beyond on-device encryption of medication names, doses, and notes, we protect your data with encryption in transit, access controls, and row-level security so that each request can only reach the data it's authorized to see. Server-side jobs that generate doses and reminders operate on timing alone, under the same access rules as the app.

No method of transmission or storage is ever completely secure, but we work to protect your information using safeguards appropriate to its sensitivity.

11. Children's privacy

Pilloved is not directed to children, and we do not knowingly collect personal information directly from children for their own accounts. Caregivers may, however, create managed profiles to track medication on behalf of a child. The caregiver is responsible for that profile and confirms they have the right to manage it.

12. International data transfers

We may process and store information in countries other than the one you live in. Where we transfer personal information across borders, we take steps to ensure it remains protected in line with this policy and applicable law.

13. Changes to this policy

As Pilloved grows, we may update this policy. When we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you in the app or by email.

14. Contact us

Questions, requests, or concerns about your privacy? Email us at hello@dobro.dev and we'll be glad to help.