Privacy Policy
Last updated: September 27, 2026
Who we are
Medlet (“the app”, “we”, “us”) is developed and published by Matvey Pirogov, the controller of the personal data described in this policy. Contact: medlet@pirog.app.
Data that stays on your device
Everything you create in the app is stored only on your iPhone, in the app’s local storage:
- your medicines and packs: names, strength, quantity, expiry dates, lot numbers, what they are used for and where they are kept;
- photos of packs you take or pick, and the cut-out images made from them on your iPhone;
- app settings such as the theme, your privacy choices and your answer about AI reading.
We do not receive this data. It is included in your device backups according to your iCloud or computer backup settings. Deleting the app deletes it from your iPhone.
Data processed by services we use
| Service | What and why | Your choice |
|---|---|---|
| Apple (App Store, StoreKit) | Payments for Medlet Pro are handled by Apple under Apple’s privacy policy. We never see your payment details. | — |
| RevenueCat, Inc. (USA) | Manages Pro subscriptions and purchases: a random app user ID, purchase and subscription records, app version and device type. Used to unlock Pro, restore purchases and count subscriptions. | Needed to sell and restore Pro (contract). |
| Apple Ads attribution (Apple, via RevenueCat) | If you install Medlet after tapping one of our ads on the App Store, the app gets an attribution token from Apple’s AdServices framework, and RevenueCat exchanges it with Apple for the campaign, ad group, keyword and country of that ad. No advertising identifier (IDFA) is used, and Apple does not treat this as tracking. Used only to see which of our ads pay off. | Legitimate interest (measuring our own ads). You can object at any time: medlet@pirog.app. |
| AI reading of packs: Google Cloud Functions (EU) and Google Gemini API (Google LLC / Google Ireland) | Only if you agree before your first AI scan. The photo of the pack (resized, without location or other photo metadata), the app language, the code read from the pack and a random installation ID go to our function in the EU (Belgium), which asks Google Gemini to read the name, strength, pack size, expiry date and what the medicine is used for. We don’t store the photo. Google processes it under its paid Gemini API terms: it does not use it to train models and may keep it for a limited time only to detect abuse. The random installation ID and a count of scans are stored in the EU (Firestore) for 62 days to limit the number of scans. | Your explicit consent. Off at any time: Settings → Privacy. Without it, the code on the pack and manual entry still work. |
| Google Firebase Analytics (Google LLC / Google Ireland) | Pseudonymous usage events: screens opened, paywall shown or purchase made, moving your data from the previous version, your answer about AI reading, the result and duration of an AI scan, adding a pack (how it was added and counts only — never medicine names, photos or dates) and marking a dose as taken (the remaining count only), plus device model, OS version, app version and approximate country. No advertising ID is collected and the data is not used for ads. | In the EEA, the UK and Switzerland — only if you say yes during setup (consent). Elsewhere — on by default (legitimate interest). Off at any time: Settings → Privacy. |
| Google Firebase Crashlytics | Crash reports: the error, the state of the app when it crashed, device model, OS and app version. Used only to find and fix bugs. | On by default (legitimate interest). Off at any time: Settings → Privacy. |
Reminders — expiry dates, course doses and “running out” — are local notifications that Medlet schedules on your iPhone. No push service is involved and nothing about them is sent to us. A reminder shows the medicine’s name; to hide it on the Lock Screen, turn off notification previews in iOS Settings.
Links to the App Store
Links to Medlet on our website and in our posts carry a campaign name, for example “launch-post”. Apple reports to us, in aggregate, how many people downloaded or subscribed after following each link.
What we don’t do
- No account and no sign-in. No ads in the app and no advertising SDKs.
- No tracking across apps and websites owned by other companies, and no advertising identifier (IDFA).
- We don’t sell or share your personal data for advertising.
- No access to Apple Health, your contacts or your location.
How long data is kept
On-device data stays until you delete it or the app. Photos sent for AI reading are not stored by us; the scan counter with the random installation ID is deleted after 62 days. Analytics data is kept for up to 14 months and crash reports for up to 90 days. Purchase records are kept by RevenueCat while needed to provide Pro and to meet legal accounting obligations.
International transfers
Our AI function and scan counter run in the EU. RevenueCat and Google (including Gemini) may process data in the United States. These transfers rely on the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
Your rights
Depending on where you live (for example under the GDPR or US state laws), you may have the right to access, correct or delete your data, to object to or restrict processing, to data portability and to withdraw consent at any time. Most data never leaves your device, so you control it directly. For analytics, crash or purchase data, write to medlet@pirog.app — include the approximate date of purchase if your request is about a subscription. You can also complain to your local data protection authority.
Children
Medlet is not directed at children under 16, and we do not knowingly collect data from them.
Changes
If this policy changes, we will update this page and the date above. Significant changes will also be noted in the app’s release notes.