Medlet

Privacy Policy

Last updated: September 27, 2026

The short version. Your medicine cabinet stays on your iPhone. Medlet has no account and no ads, and it does not sell your data or track you across other apps. If you choose to read a pack with AI, the photo of the pack goes through our server in the EU to Google Gemini and is not kept by us. We collect pseudonymous usage analytics only if you agree (where the law requires consent) and crash reports to fix bugs. You can switch AI reading, analytics and crash reports off at any time: Settings → Privacy.

Who we are

Medlet (“the app”, “we”, “us”) is developed and published by Matvey Pirogov, the controller of the personal data described in this policy. Contact: medlet@pirog.app.

Data that stays on your device

Everything you create in the app is stored only on your iPhone, in the app’s local storage:

We do not receive this data. It is included in your device backups according to your iCloud or computer backup settings. Deleting the app deletes it from your iPhone.

Data processed by services we use

ServiceWhat and whyYour choice
Apple (App Store, StoreKit) Payments for Medlet Pro are handled by Apple under Apple’s privacy policy. We never see your payment details. —
RevenueCat, Inc. (USA) Manages Pro subscriptions and purchases: a random app user ID, purchase and subscription records, app version and device type. Used to unlock Pro, restore purchases and count subscriptions. Needed to sell and restore Pro (contract).
Apple Ads attribution (Apple, via RevenueCat) If you install Medlet after tapping one of our ads on the App Store, the app gets an attribution token from Apple’s AdServices framework, and RevenueCat exchanges it with Apple for the campaign, ad group, keyword and country of that ad. No advertising identifier (IDFA) is used, and Apple does not treat this as tracking. Used only to see which of our ads pay off. Legitimate interest (measuring our own ads). You can object at any time: medlet@pirog.app.
AI reading of packs: Google Cloud Functions (EU) and Google Gemini API (Google LLC / Google Ireland) Only if you agree before your first AI scan. The photo of the pack (resized, without location or other photo metadata), the app language, the code read from the pack and a random installation ID go to our function in the EU (Belgium), which asks Google Gemini to read the name, strength, pack size, expiry date and what the medicine is used for. We don’t store the photo. Google processes it under its paid Gemini API terms: it does not use it to train models and may keep it for a limited time only to detect abuse. The random installation ID and a count of scans are stored in the EU (Firestore) for 62 days to limit the number of scans. Your explicit consent. Off at any time: Settings → Privacy. Without it, the code on the pack and manual entry still work.
Google Firebase Analytics (Google LLC / Google Ireland) Pseudonymous usage events: screens opened, paywall shown or purchase made, moving your data from the previous version, your answer about AI reading, the result and duration of an AI scan, adding a pack (how it was added and counts only — never medicine names, photos or dates) and marking a dose as taken (the remaining count only), plus device model, OS version, app version and approximate country. No advertising ID is collected and the data is not used for ads. In the EEA, the UK and Switzerland — only if you say yes during setup (consent). Elsewhere — on by default (legitimate interest). Off at any time: Settings → Privacy.
Google Firebase Crashlytics Crash reports: the error, the state of the app when it crashed, device model, OS and app version. Used only to find and fix bugs. On by default (legitimate interest). Off at any time: Settings → Privacy.

Reminders — expiry dates, course doses and “running out” — are local notifications that Medlet schedules on your iPhone. No push service is involved and nothing about them is sent to us. A reminder shows the medicine’s name; to hide it on the Lock Screen, turn off notification previews in iOS Settings.

Links to the App Store

Links to Medlet on our website and in our posts carry a campaign name, for example “launch-post”. Apple reports to us, in aggregate, how many people downloaded or subscribed after following each link.

What we don’t do

How long data is kept

On-device data stays until you delete it or the app. Photos sent for AI reading are not stored by us; the scan counter with the random installation ID is deleted after 62 days. Analytics data is kept for up to 14 months and crash reports for up to 90 days. Purchase records are kept by RevenueCat while needed to provide Pro and to meet legal accounting obligations.

International transfers

Our AI function and scan counter run in the EU. RevenueCat and Google (including Gemini) may process data in the United States. These transfers rely on the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.

Your rights

Depending on where you live (for example under the GDPR or US state laws), you may have the right to access, correct or delete your data, to object to or restrict processing, to data portability and to withdraw consent at any time. Most data never leaves your device, so you control it directly. For analytics, crash or purchase data, write to medlet@pirog.app — include the approximate date of purchase if your request is about a subscription. You can also complain to your local data protection authority.

Children

Medlet is not directed at children under 16, and we do not knowingly collect data from them.

Changes

If this policy changes, we will update this page and the date above. Significant changes will also be noted in the app’s release notes.