1. Scope and What Counts as Consumer Health Data
This Consumer Health Data Privacy Policy explains how the PillsCheck mobile application handles Consumer Health Data. "Consumer Health Data" means personal information that is linked or reasonably linkable to you and that identifies, or could reasonably be used to identify, your past, present, or future physical or mental health status, depending on applicable law.
This policy applies only to Consumer Health Data processed by the PillsCheck app. It supplements, and should be read together with, our general Privacy Policy.
"PillsCheck," "we," "us," and "our" refer to Ivan Sokalskyi, an independent developer operating as a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland, NIP 8982299245, with registered business address at ul. Edwarda Abramowskiego 45, 51-663 Wrocław, Poland. You can contact us using the details listed below.
This policy is intended in particular for residents of U.S. states with consumer-health-data laws, including Washington (My Health My Data Act, RCW 19.373), Nevada (Senate Bill 370, NRS 603A.400 to 603A.470), and Connecticut (the Connecticut Data Privacy Act health-data provisions). It also describes how the same medication information is treated as "data concerning health" under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR.
2. Categories of Consumer Health Data
We do not collect Consumer Health Data on our servers, because we operate none. PillsCheck lets you enter and manage health-related information that stays within your own device and Apple Account. The categories below are the complete inventory of Consumer Health Data that the app stores, and they are identical to the categories described in our general Privacy Policy:
- Medication name or label that you enter.
- Free-text dosage label that you enter (for example, "50 mg, 1 tablet").
- Free-text note that you enter, which may contain any health detail you choose to record.
- Dosage importance that you select (low or high), which controls whether a reminder is audible or breaks through silent mode and Focus.
- Medication schedule and recurrence rule (for example, daily, every N days, specific weekdays, or an on-and-off cycle).
- Reminder times and start date for each medication.
- Optional medication photo that you add from the camera or your photo library, normalized to a smaller image (about 900 pixels, JPEG) and stored inline (base64-encoded) inside the single local app data file, not as a separate image file.
- Dose-outcome and adherence records (for example, taken, missed, cancelled, or pending, together with scheduled times, deadlines, snooze times, and update timestamps).
- Reminder lifecycle metadata (for example, identifiers, enabled or disabled state, inactive-since timestamp, deleted-at timestamp, and created-at timestamp).
All of the categories above are health-related. This information may be considered Consumer Health Data under laws such as the Washington My Health My Data Act and Nevada SB370, and a "special category of personal data" - specifically, "data concerning health" - within the meaning of Article 9(1) of the GDPR and the UK GDPR.
This information is processed on your device. If your device is signed into iCloud, the medications and dose records above (including any attached medication photo) are also stored in the private database of your own iCloud account, so they can be restored after a reinstall and appear on your other devices; app settings are not included. PillsCheck has no backend server, no user accounts, and no cloud storage operated by us: that copy is held by Apple within your Apple Account, under Apple's iCloud terms. We do not receive, view, host, or store this Consumer Health Data, and we have no technical means to access it, including in your iCloud.
3. Purposes for Local Processing
The app processes Consumer Health Data locally only to provide the features you request, including creating medication schedules, saving the optional medication photos you choose to attach, sending device-based reminders and alarms, recording dose outcomes, and showing your medication history inside the app.
We practice data minimization. PillsCheck is designed to use only the information you choose to enter, and only for the local app functions you choose to use. There is no secondary use of your Consumer Health Data - no analytics, no advertising, no profiling, and no aggregation.
4. Sources of Consumer Health Data
The source of Consumer Health Data in PillsCheck is you. You provide the information directly when you enter, edit, or manage medication details, photos, and reminder settings on your device.
We do not obtain Consumer Health Data from data brokers, advertising networks, analytics providers, healthcare providers, pharmacies, insurers, or any other third parties.
5. Sharing of Consumer Health Data
We do not share, sell, or disclose Consumer Health Data.
Because Consumer Health Data is never sent to us, we do not share, sell, rent, trade, disclose, or otherwise make it available to any third parties, affiliates, advertising networks, analytics providers, data brokers, or marketing partners. We do not process Consumer Health Data for targeted advertising, profiling, cross-app tracking, or sale.
The one entity that stores Consumer Health Data other than your own device is Apple, and only because you are signed into iCloud: the copy described in Section 2 is kept in your own iCloud account, where Apple provides the storage and encryption as the operator of that account. Apple is not given the data for its own purposes by us, it is not sold or disclosed to anyone else, and the data is not accessible to us. Turning it off is a switch in the app, under Settings, then iCloud Sync, and deleting the copy is described in Section 8.
PillsCheck is offered as a paid auto-renewing subscription (a monthly or yearly plan), sold and processed entirely by Apple through the App Store. We receive only Apple's aggregate sales reporting, and we receive no payment or card data and no Consumer Health Data through the purchase. The subscription is a payment for access to the app; it is not a sale of Consumer Health Data, and the subscription gives us no additional access to your health data, which remains stored only on your device and in your own iCloud account.
6. U.S. Consumer Health Data: Consent and No Sale
This section addresses U.S. consumer-health-data laws, including the Washington My Health My Data Act, Nevada SB370, and the Connecticut Data Privacy Act. It is separate from, and does not replace, the GDPR and UK GDPR consent discussion in Section 12 and in our general Privacy Policy.
- Collection limited to what is necessary. The app collects and stores Consumer Health Data only as necessary to provide the medication-reminder and tracking service you request, and it stores that data on your device and, where iCloud is signed in, in your own iCloud account so the service survives a lost or replaced phone. Because the app does not collect Consumer Health Data beyond what is necessary to deliver the features you ask for, the additional opt-in consent that the My Health My Data Act requires for non-necessary collection is not triggered.
- No sale, so no authorization is sought. We do not sell Consumer Health Data, and we will not sell it. Because no sale occurs, no "valid authorization" to sell Consumer Health Data under the My Health My Data Act, Nevada SB370, or any similar law is sought or required.
- Consent and withdrawal. Your consent to this processing is given by your own choice to enter information into the app. You may withdraw that consent at any time by editing or deleting the information, by turning the iCloud Sync switch off, or by uninstalling the app, as described in Section 8.
7. No Geofencing
PillsCheck does not use location services. The app contains no location tracking, no GPS use, and no geofences of any kind, including any geofence around health-care facilities or other locations. We do not use location to identify or track you, to collect Consumer Health Data, or to send you notifications.
8. How to Exercise Your Rights
Depending on where you live, you may have privacy rights relating to Consumer Health Data, including the rights to confirm whether it is collected, shared, or sold, to access it, to withdraw consent, and to delete it. Because PillsCheck stores Consumer Health Data on your device and in your own iCloud account, and we hold no copy of either, you exercise these rights directly on your device and in your Apple Account settings; we have no copy to access or delete on your behalf.
- Confirm and access. To confirm what Consumer Health Data exists and to access it, open the PillsCheck app and review the medication, schedule, reminder, photo, and history information stored in the app. We do not collect, share, or sell this data; everything the app holds about you is visible to you inside the app.
- Correct or delete specific items. To correct or delete specific Consumer Health Data, edit or delete the relevant medication, schedule, reminder, photo, note, or history item in the app's management screens. Deleting an individual reminder removes it from view and marks it as deleted, but the underlying record (including its note and photo) is retained in the app's local data file, and in the iCloud copy, until both are removed as described below. In other words, in-app deletion of a single reminder is not, by itself, an immediate and permanent erasure of the underlying record.
- Delete all Consumer Health Data. To erase the data held on your device, delete the PillsCheck app; this removes the single local data file in which all of it is stored. Deleting the app does not delete the copy in your iCloud account, which exists so that a reinstall can restore your history. To erase that copy as well, either turn the iCloud Sync switch off in the app's Settings and choose to delete the iCloud copy, or open iOS Settings, tap your name, then iCloud, then the storage-management screen listing the apps that store data in iCloud, select PillsCheck, and delete its data. No copy exists on our side for us to delete. If your device backup settings include app data, you may also need to delete any device backups that you control.
- Withdraw consent. You may withdraw your consent to local processing at any time by deleting the relevant data or by uninstalling the app.
If you contact us about a privacy request, please do not send medication names, dosage details, schedules, photos, notes, or other health information unless you choose to include that information in your message.
9. PillsCheck Website and Third-Party Technologies
This Consumer Health Data Privacy Policy concerns the PillsCheck mobile application, whose only network destination is your own iCloud account, as Section 2 describes; it transmits no Consumer Health Data to us or to any third-party service. Separately, the PillsCheck marketing website (https://pillscheck.com) loads the Tailwind CSS styling framework from a public content delivery network (cdn.tailwindcss.com). When your browser fetches that file, the CDN provider receives standard request information such as your IP address, User-Agent, and referring page. We do not control or have access to that provider's logs.
This affects only visitors to the website. No Consumer Health Data is transmitted to the CDN; the medication information, schedules, reminders, photos, and history described in this policy are never sent to the website or the CDN. If you prefer to avoid this third-party request, a browser extension that blocks external CDNs can be used; the page will still render, only with reduced styling.
10. Data Security and Storage
PillsCheck is designed to reduce privacy risk by keeping Consumer Health Data within your own device and your own Apple Account. You are responsible for protecting access to both, including through your device passcode, biometric unlock settings, operating-system updates, Apple Account two-factor authentication, and backup settings.
On your device, all Consumer Health Data, including any medication photos you attach, is stored in a single local JSON file inside the app's private Application Support directory within the iOS app sandbox. The app relies on the iOS app sandbox and operating-system file protection tied to your device passcode and biometric unlock, together with the device-level encryption provided by iOS. We do not add a separate application-layer encryption layer, and we operate no server-side storage or remote backup of our own for this data.
The iCloud copy described in Section 2 is transmitted and stored by Apple, encrypted in transit and at rest in Apple's infrastructure and reachable only through your Apple Account. Two further Apple-side cases are worth naming: if you choose a photo stored in your iCloud Photos, iOS and Apple (not PillsCheck) may retrieve that photo from your own iCloud; and if you have iCloud Backup or device backups enabled, app data may be included in those backups. All of these are governed by Apple and your device settings, not by us.
11. HIPAA Does Not Apply
The U.S. Health Insurance Portability and Accountability Act (HIPAA) does not apply to PillsCheck. We are not a "covered entity" (such as a health plan, health-care clearinghouse, or health-care provider conducting standard electronic transactions) and we are not a "business associate" of any covered entity. PillsCheck is a personal medication-reminder tool that you use to track your own medication; the information you record is consumer-generated health information that falls outside HIPAA. We therefore do not, and cannot, claim to be "HIPAA compliant," and HIPAA imposes no obligations on us here.
12. Relationship to GDPR and UK GDPR
For users in the European Economic Area and the United Kingdom, the medication information described above is "data concerning health" and a special category of personal data under Article 9(1) of the GDPR and the UK GDPR. Where the GDPR or UK GDPR applies, the processing of this data - on your device and in your own iCloud account - is based on your explicit consent under Article 9(2)(a), which you give by your free choice to enter the information into the app and which you may withdraw at any time by editing or deleting that information or by uninstalling the app.
You also have the rights set out in Articles 15 to 22 and Article 7(3) of the GDPR and UK GDPR, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Because we hold no copy of the data, these rights are exercised in the app and in your Apple Account settings as described in Section 8. You have the right to lodge a complaint with a supervisory authority. In the EU and EEA, the authority competent for processing carried out by us is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl; you may also complain to the supervisory authority of your habitual residence or place of work in the EEA. In the United Kingdom, you may lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, https://ico.org.uk. These rights are described in more detail in our general Privacy Policy.
13. Changes to this Policy
We may update this Consumer Health Data Privacy Policy from time to time. If we make changes, we will post the updated policy and update the "Last Updated" date above. If required by law, we will provide additional notice or request your consent.
14. Contact Information
If you have questions about this Consumer Health Data Privacy Policy, or to make a privacy request, contact us at:
privacy_pills@rongan.me
Ivan Sokalskyi
Sole proprietor (jednoosobowa działalność gospodarcza)
NIP: 8982299245
ul. Edwarda Abramowskiego 45
51-663 Wrocław, Poland
© 2026 Ivan Sokalskyi