We answer within 1 month. If a request is complex, this can grow by 2 more months; we will tell you why.
2. What stays only on your phone
The journal
Your answers to the daily questions: sleep, mood, stress, body, the day's events.
When you wake up, so the morning question arrives in the morning.
Your own guess about what your state depends on, if you name one.
What you take and from which day, if you write it down.
Your goals and question set.
Health details from your profile, if you add them on «Me» → «Age, sex, height, weight»: long-term conditions, blood pressure, main concern, smoking, alcohol, stress, dietary restrictions, known triggers.
Your city's weather, next to your records.
The consents you give in the app, with their dates.
This is health data. The coincidences, the "Instrument" and the "Going to an expert" document are all calculated by the phone itself.
Where exactly it is
In the app's database on this iPhone. Other apps cannot reach it. The iPhone protects its own storage, and that protection rests on your phone's passcode.
We have no copy of the journal on our servers. We cannot read it.
Your iPhone backup (iCloud or a computer) includes the journal. That is between you and Apple, or your computer. We have no access to it.
Signing out does not erase the journal: sign in again and it is there. To erase it: "Me" → "Delete everything".
If you delete ProTilo from your iPhone, the journal leaves that phone. It does not leave your iPhone backups or copies you have already saved.
Copies you make
"Take a copy of the data" — a file in an open format (JSON). The phone builds it. You decide where it goes.
"A copy to restore from" — a file locked with a 28-character key (XChaCha20-Poly1305 encryption). The key is created on your phone and shown only to you. We do not have it. If both the phone and the key are lost, nobody can open the copy. Neither can we.
"Going to an expert" — the phone builds the PDF. You decide who gets it.
"Ask AI" — the phone builds a text from your records. You copy it and paste it into an AI service of your choice. We send nothing to any AI company. Before the first time, the app asks for your consent.
Whatever you paste is then handled under that company's rules. Google Gemini: policies.google.com/privacy · Anthropic Claude: anthropic.com/legal/privacy · OpenAI ChatGPT: openai.com/policies/privacy-policy
The cloud copy — only if you turn it on
Off by default. You turn it on with a separate consent: "Me" → "A copy to restore from".
The phone locks the copy with your key before it leaves. We keep the locked copy in Google Cloud Storage in the EU. We cannot open it.
What we can see: whose copy it is (the account), its size, when it was saved, and the times of the last few attempts to save it (to limit how many there can be). Nothing else.
We keep 1 copy — the latest. Each new copy replaces the previous one.
The copy updates itself at most once a day when there are new records, or when you tap "Save now".
To turn it off: "Me" → "A copy to restore from" → "Turn off the copy in the cloud". We erase it at once. For 7 more days it sits, locked, in the storage bin; then it is gone for good.
Deleting your account erases it too.
On a new phone: sign in → "copy found" → type your key.
3. What our server keeps
Account: email, how you sign in (Apple, Google, or email and password), the name Apple or Google passed on (if any), an automatic nickname (you can change it), your account number, language, and when the account was created and changed. Why: so your account and sign-in work.
Your password is kept by Google Firebase Authentication, only in hashed form. We never see it.
Age check: your "I am 18 or older" confirmation, your date of birth if you give it, and your age on the day you signed up. Why: ProTilo is for adults only. You also see your age, from your date of birth, on «Me» and in the text for AI.
Consent records: what you accepted (Privacy Policy and Terms, the medical notice, consent to "Ask AI", the cloud copy, your choice about crash reports), its version and the time. Why: to prove consent (GDPR article 7).
City: its name, country and the coordinates of the city centre. Why: weather and air.
Profile, if you fill it in ("Me" → "Age, sex, height, weight"): sex, height, weight, an avatar from the list, country, goal, chronotype, type of work, usual bedtime and wake-up time, sleep goal, caffeine sensitivity, activity goal and fitness level, water, meals per day, screen time before sleep. All optional. Height and weight are health data. Why: to show them on "Me" and in the text for AI. From version 2.0, long-term conditions, blood pressure, main concern, smoking, alcohol, stress, dietary restrictions and known triggers stay only on the phone (section 2).
Reminder settings: the time and the switches. Why: so your choice also applies on another phone.
Your choice about crash reports. Why: so your choice applies.
Records from versions before 2.0, if you used ProTilo earlier: your old check-ins, notes, hints, the Apple Health figures that version copied, and profile details entered there (including conditions and blood pressure, if they were entered). Why: so your earlier journal stays available.
Export requests and their status.
The record of a deletion request: the account number, when it was asked for, when it was carried out and how much of what was erased. Why: to prove the deletion happened, and never to bring the erased account back from a backup.
A service security log: exports, deletions, service actions.
The answers in the new journal (version 2.0 onwards) are not on the server.
4. Weather and location
The app refreshes the weather and air for your city every time you open it — at most once every 2 minutes. The iPhone may also fetch the daily weather summary in the background, when it decides to.
You choose the city: "Me" → "Weather and air". Or, if you allow location, the phone finds the nearest city from a list built into the app.
Your exact position never leaves the phone. Location permission is optional.
Daily weather summaries used for comparisons come only from the city you chose.
Open-Meteo (OpenMeteo GmbH, Switzerland) receives the coordinates of the city centre: weather, air, climate normals. Open-Meteo keeps technical logs with the IP address for up to 90 days.
NOAA (USA) provides a general geomagnetic forecast. The request carries nothing about you.
Apple's map service in iOS receives the city coordinates to show the city's name.
Weather records stay in your journal on the phone. No weather or location records reach our server.
The city you choose is kept with your account (section 3).
Your consent to records also lets the app compare the weather with your records. The comparison happens on the phone. Withdraw the consent and the comparison stops, and no new weather records are written to the journal.
5. Crash reports
When the app crashes or hits an error, it sends a technical report to Sentry. Reports are stored in the EU (Frankfurt).
A report holds: what went wrong, the app version, the iPhone model, the iOS version, a random installation number and the last technical steps before the error.
No name, no email, no account number. Reports are built so that journal records do not get into them.
Basis: our legitimate interest in a stable, safe app.
On by default. To switch off: "Me" → "Analytics and data rights" → "Diagnostic Reports". It takes effect from the next launch. You can object at any time.
Sentry erases reports after 90 days at the latest. Reports carry no account number, so they cannot be linked to you; reports from versions before 2.0 we ask Sentry to erase.
6. Usage statistics
This version collects no usage statistics.
7. Emails
Service emails only: a password-reset link, a welcome after sign-up, "account not created" (if you are under 18), "export request received" and "export ready", account deletion (queued and done).
We send them through Google Workspace (Gmail).
No marketing emails.
If you write to us, we keep the conversation while we help you and for 24 months after.
8. Who else handles data
Working for us (processors, GDPR article 28)
Google Cloud and Firebase (Google Ireland Ltd, Google LLC): database, server functions, file storage, sign-in. The database is in the EU (multiple European regions). Functions run in the EU (Belgium). Sign-in (Firebase Authentication) runs in Google's data centres in the USA.
Google Workspace (Google Ireland Ltd): service emails — the address and the email itself.
Sentry (Functional Software, Inc.): crash reports. Stored in the EU; the company is in the USA.
Expo (650 Industries, Inc., USA): app updates. Each time the app starts, the phone asks Expo whether a newer version of the app's code exists. Expo sees the IP address, the app version, the update channel, the platform, the number of the current update and a random installation number. If the app crashes while starting an update, Expo receives a report of that error — so it can go back to the previous version. No journal records are involved.
Acting on their own account
Apple: App Store, Sign in with Apple, iOS services (backups, location, city names).
Google: Sign in with Google, if you choose it.
Open-Meteo (Switzerland): weather — city coordinates; the IP address in its logs.
NOAA (USA): a general geomagnetic forecast. Nothing about you; like any website, it sees your phone's network address.
AI companies you paste text into: whatever you paste.
Transfers outside the EU
Google (USA): EU-US Data Privacy Framework and EU Standard Contractual Clauses.
Sentry and Expo (USA): EU Standard Contractual Clauses.
Open-Meteo (Switzerland): the EU adequacy decision for Switzerland.
9. Legal basis
Account, sign-in, service emails, settings — contract (GDPR article 6(1)(b)).
App updates (Expo) — contract and our legitimate interest in a working, secure version of the app (article 6(1)(b), (f)).
Age check — contract and our legitimate interest in keeping ProTilo adult-only (article 6(1)(b), (f)).
The journal on your phone (health data) — your explicit consent (article 9(2)(a)).
Health details from your profile on the phone — your explicit consent: you enter them yourself on a screen that says they stay on the phone (article 9(2)(a)).
Comparing weather with your records — the same explicit consent to records (article 9(2)(a)).
Height and weight in your profile (optional) — your explicit consent: you enter them yourself on a screen that says where they are kept (article 9(2)(a)). The rest of the profile — contract (article 6(1)(b)).
Records from versions before 2.0 — the consent given in that version (article 9(2)(a)).
The cloud copy — your explicit consent (article 9(2)(a)).
Consent records — to prove consent (article 6(1)(c) with article 7(1)).
City and weather — contract (article 6(1)(b)). The phone's location — only with your permission in iOS.
Crash reports — our legitimate interest (article 6(1)(f)). You can object at any time.
Answering your messages — contract and legitimate interest (article 6(1)(b), (f)).
ProTilo needs an account: the journal is bound to it. Everything else is optional. Without consent to records the app opens, but the journal stays empty.
10. How long we keep things
The journal and the health details from your profile on the phone — until you erase them ("Delete everything"), delete your account (then that phone erases them too) or delete the app.
The cloud copy — only the latest. Erased when you turn the copy off or delete the account; locked in the bin for 7 more days.
Account, profile, city, settings, consents, records from versions before 2.0 — until the account is deleted (7 days after you ask).
Account export file — the link works for 7 days; the file is erased within 21 days.
Unfinished sign-up (age not confirmed) — not erased automatically: write to privacy@protilo.com and we erase it within 1 month.
Service security log — 90 days. After an account is deleted, its account number in the log is replaced with a pseudonym.
The record that a deletion was carried out — for as long as we may need to prove the deletion happened. It contains no journal records.
Crash reports — up to 90 days.
Your messages to us — while we help you, and 24 months after.
Server backups: the database can be rolled back to any moment in the last 7 days; daily database backups — 30 days; the sign-in accounts backup — 30 days.
Deleted data leaves the backups when they expire. We never bring a deleted account back from a backup. If we ever have to restore the database from a backup, we delete again the accounts deleted after that backup was made.
Google erases deleted data from its internal systems within up to 180 days.
11. Erase, switch off, withdraw consent
Delete your account
"Me" → "Delete the account for good". You sign in once more and type the word DELETE.
The account closes at once and is erased after 7 days. During those 7 days you can sign in and cancel.
What is erased: everything in section 3, the cloud copy, export files and your sign-in account. Crash reports carry no account number, so they cannot be linked to you; reports from versions before 2.0 we ask Sentry to erase. At the end we send a confirmation email.
If you signed in with Apple, the confirmation email tells you how to remove ProTilo from the apps that use your Apple ID.
On the phone where you asked for deletion, the journal is erased the first time the app opens at least one day after the deletion takes effect. On any other phone, tap "Delete everything" first, or delete the app.
What remains: the record that the deletion was carried out, the service security log with the account number replaced with a pseudonym (section 10), backups until they expire (section 10), and copies outside our reach — files, iPhone backups and anything pasted into an AI.
Erase only this phone
"Me" → "Delete everything". Erases the journal, keys and reminders on this phone at once and signs you out. The account itself stays.
Withdraw consent
Consent to records: "Me" → "Privacy and consents". The app stops recording and reminding at once. What is already recorded stays on the phone until you erase it.
The cloud copy: "Turn off the copy in the cloud" — the copy is erased at once.
Crash reports: "Me" → "Analytics and data rights" → "Diagnostic Reports".
You can withdraw at any time. What happened before stays lawful.
12. Your rights
Access and a copy. Journal: "Me" → "Take a copy of the data" — a file with every record. Account: "Me" → "Account security" → "Request Data Export" — a file by email, usually within minutes; the link works 7 days; the next request after 30 days. The file also holds your consent history. Consent history: "Me" → "Analytics and data rights" → "View consent history".
Correction. Profile: "Me" → "Age, sex, height, weight". Today's journal record: "Correct this record" — the correction is added beside it; the original stays.
Erasure: section 11.
Portability: both files are in an open format (JSON).
The journal on your phone is fully in your hands: we cannot see it, so we cannot change it either.
All of this is free. To protect the account, we may ask you to write from the account email.
Complaints. Portugal (our supervisory authority): CNPD — Comissão Nacional de Proteção de Dados, Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt, geral@cnpd.pt. If you live in another EU country, also your country's authority (list: edpb.europa.eu). If you live in Ukraine, also the Ukrainian Parliament Commissioner for Human Rights, www.ombudsman.gov.ua.
13. Adults only
ProTilo is only for people aged 18 or older. The app asks your age when you sign up.
If we learn that an account belongs to someone under 18, we close it and erase its data.
Server rules let each account reach only its own data.
Google encrypts data on its disks.
The phone locks the copy with a key we do not have.
The copy key sits in the iPhone keychain. To show it again, the phone asks for Face ID or the passcode; on an iPhone without a passcode it shows it at once.
Only the people who run ProTilo can access our servers.
If a breach happens, we tell the CNPD within 72 hours, and we tell you without delay if it could seriously harm you.