Legal

Privacy policy

How Pensday handles your data: on-device body-scan photos, exactly what we transmit and why, the data types we collect, retention, deletion, and your GDPR/CCPA rights.

Last updated

Your health data is yours. This policy explains, in plain language, exactly what Pensday collects, what stays on your device, and how to get your data out or delete it entirely.

Pensday was formerly called Tiro. It is the same app, and the App Store listing may still show the Tiro name while the change rolls out.

Introduction and scope

This policy explains how Pensday (“we”, “us”, “our”) collects, uses, and protects your information when you use the Pensday mobile app and this website. Pensday is operated by Lightzone Solutions LTD, a company registered in England & Wales. Pensday is a GLP‑1 tracking companion: it is not a medical device and does not provide medical advice. By using Pensday you agree to this policy.

The data we collect, and why

Pensday is anonymous-first: you can use every core feature without creating an account. We collect only what the app needs to work for you:

  • Health & Fitness data you enter: doses (medication, mg, date, time, injection site, how it felt), the inputs behind your estimated medication-level curve, your titration schedule, symptoms, weight, water, food and nutrition logs and macros, and the numeric body measurements derived from a body scan. By default this is stored only on your device. It is transmitted to and stored in your private account (on our backend) only if you turn on sign-in / sync.

  • Contact info (optional): if you choose to sign in with Apple, Google, or email, we receive an email address, and (with Sign in with Apple, on first consent) a display name. Anonymous users provide neither. We use this only for your account, backup, and cross-device restore, never for marketing.

  • An anonymous user ID: created on first launch so the food-recognition service can be rate-limited fairly and so your data can sync if you opt in. It is not an advertising identifier and is never shared for advertising or with data brokers.

  • Food photos, voice notes, and typed meal entries: when you log a meal by photo or by voice, that image or recording is sent securely to our food-recognition service purely to produce the calorie/macro estimate, and is not stored afterwards (see “Food photo & voice recognition” below).

  • Anonymous usage events: which screens and features are used (for example, that a dose was logged or a paywall was shown), tied to a random install ID. These events never contain your name, email, or any health value such as a dose, weight, or measurement. They are sent to our own server, which forwards them to our analytics providers (see “Third parties and sub-processors”).

  • Crash reports: if the app crashes, a technical report (device model, OS version, app version, and what the app was doing) is sent so we can fix the bug. Crash reports are configured not to include personal data.

  • Notification token: if you allow notifications, your device’s push token and anonymous ID are used to deliver dose and pen-day reminders.

  • Purchase status: if you subscribe to Pensday Plus, your anonymous ID and Apple’s purchase receipt are used to confirm and restore your subscription. Payment itself is handled entirely by Apple; we never see your card details.

  • Ad attribution: if you installed Pensday from an Apple Search Ads ad, the app reads Apple’s privacy-preserving attribution token to learn which campaign led to the install. This does not use the advertising identifier (IDFA).

What we do NOT collect: no advertising identifier (IDFA), no location, no contacts, and no browsing or search history. Pensday contains no ads and no cross-app or cross-site tracking, and we never sell or rent your data.

Your body-scan photos are never collected. See the next sections.

Apple Health

Pensday can connect to Apple Health (HealthKit) so your data stays consistent across the apps and devices you already use. This connection is optional, is off until you turn it on, and can be turned off at any time, either inside the app (Profile → Apple Health) or in the iOS Settings → Health → Data Access & Devices screen, where you control each data type individually. The app appears there as Pensday, or as Tiro if your installed version still shows the old name.

Data Pensday writes to Apple Health (only the entries you log in Pensday): your weight, body fat percentage and BMI from body scans, the calories and macronutrients (protein, carbohydrates, fat, fiber) of meals you log, and your water intake.

Data Pensday reads from Apple Health (only if you allow it): your step count and active energy for your daily dashboard, and, so your history stays complete, weight and dietary-energy entries recorded by your other apps or devices.

How your Health data is handled:

  • Health data is processed on your device. Pensday does not transmit your Apple Health data to our servers, and it is never stored in iCloud by Pensday.
  • We never use Apple Health data for advertising or marketing, and we never sell it or share it with data brokers or other third parties.
  • Apple Health data is used solely to provide the app’s health- and fitness-tracking features to you.
  • When you delete your account or your data in Pensday, Pensday also removes the samples it wrote to Apple Health (on a best-effort basis). Entries that other apps or devices wrote to Apple Health are not affected; you can manage those in the Apple Health app.

Your use of Apple Health is also governed by Apple’s own privacy policy.

Body-scan photos never leave your device

If you use the camera body scan, the photos and the analysis that estimates your measurements run entirely on your device. The images are processed on your phone and then discarded: they are never uploaded to our servers and are never shared with any third party. Only the numeric measurements you choose to save are kept, and they leave your device only if you have enabled sync. This is why body-scan photos are not listed as “data collected” on our App Store privacy label.

Sharing with a clinic you choose

Pensday can show a clinic you are already seeing the record you keep in the app. This is off unless you start it, and nothing about you exists on their side until you do. The clinic gives you a code (read out to you, scanned, or emailed) and nothing is shared until you enter it on your own phone and tick the categories you want them to have.

You tick each category separately, and none of them starts ticked:

  • Doses and schedule: your shot history and the plan you are following: each dose with its date, time and amount, ones you skipped or took late, your titration steps, the injection site you used, and any note you attached.
  • Side effects: the symptoms you logged, how strong each one was, the day it happened, and any note on it.
  • Weight: each weight you recorded, with the date.
  • Daily nutrition totals: your calories, protein, fibre, carbohydrate and fat for each day, and how they compare with your targets. Daily totals only: never the individual meals, and never a food photo.
  • Water: how much you drank each day.
  • Body scans: the measurements a scan produced, your estimated body fat and BMI, and the ten numbers a 3D body figure is rebuilt from. Never the photographs, which never leave your phone at all.
  • About you: your sex, height and year of birth, your starting weight, your goal weight and when you started, the medication you told the app you are on, and how active you said you are.

What a clinic never receives, whatever you tick: your food photos, your voice notes and the individual meals behind those daily totals; your body-scan photographs; and anything the app holds that is not in the list above. The notes you attach to a dose or a symptom travel with those two categories and are the only free text that does. There is no photograph anywhere in what a clinic receives: the tables that hold this data have no column a picture could be stored in.

Every time someone at the clinic reads your data, you see it. Opening your record, taking a copy of it, and reading the clinic’s own notes about you are each written to a log before the data is returned to them. The same log is in your app under “Who has seen my data”, with the clinician’s name, the time, and which categories they saw.

You can stop at any time, from your phone. Turning a category off, or ending the link altogether, deletes from our servers everything that category covered, unless you are still sharing that same category with another clinic, in which case it stays for them. It also deletes, unconditionally, any notes that clinic wrote about you on that link. What survives is the access log: it is the record of what was looked at while the link was open, so ending the link does not erase it. We delete each entry two years after it was written.

Lawful basis. Health data is special-category data under Article 9 of the UK and EU GDPR. Sharing with a clinic runs on your explicit consent under Article 9(2)(a), given category by category and withdrawable at any time by the route above. Nothing is pre-selected, because a pre-ticked box is not explicit consent.

Once your clinician has seen your record, what they do with it is governed by their own professional and data-protection obligations, the same ones that cover anything else you tell them in an appointment. Pensday is not your clinician and does not make clinical decisions; see the medical disclaimer.

Food photo & voice recognition

To recognize a meal, a food photo, voice recording, or typed description is sent over an encrypted (TLS) connection to our recognition service, hosted on Supabase, which passes it to our AI provider Google (Gemini) for inference. The image or audio is used only to generate the estimate and is not stored after processing; we keep only an anonymized counter to prevent abuse. These items are processed transiently and are not linked to your identity.

Your permission before anything is sent to the AI

Pensday asks you inside the app, before the first meal you scan, and will not send anything to the AI provider until you agree. The request tells you exactly what is sent, and who receives it:

  • What is sent: only the single item you submit for that scan: the meal photo you take, the voice clip you record, or the description you type. Nothing else is attached to it: not your name, email, weight, body scans, doses or symptoms.
  • Who receives it: our own server, which forwards it to Google (Gemini, on Google Cloud Vertex AI) to identify the food and estimate its nutrition. The estimate is returned to your phone.
  • What they may do with it: Google states that data sent to Vertex AI is not used to train its foundation models. Google processes it under the Google Cloud data processing terms, which require confidentiality and security protections equivalent to those described in this policy, and it is not shared with anyone else.

You can decline, and every other part of Pensday keeps working: you can still log meals by entering them yourself. If you agree and later change your mind, turn it off under Profile → AI food scanning; nothing further will be sent.

Third parties and sub-processors

We use a small, fixed set of infrastructure providers to run the app. They process data only on our instructions and only to provide the service:

  • Supabase: our backend: authentication, database, private storage, and the edge functions that power sync and food recognition.
  • Google (Gemini): the AI model that recognizes food from photos, voice, and text. It receives the meal input only to return an estimate, only after you have agreed in the app, and Google states it is not used to train its foundation models.
  • Open Food Facts: the volunteer-run public food database. When you scan a barcode, only that barcode is looked up. No personal data is sent, and it is not an AI service.
  • Apple: the App Store, which distributes the app, handles Sign in with Apple and in-app purchases, and provides Apple Search Ads attribution.
  • RevenueCat: manages Pensday Plus subscription status from Apple’s purchase receipts, linked to your anonymous ID.
  • OneSignal: delivers push notifications, such as dose and pen-day reminders, if you allow them.
  • Sentry: receives crash reports so we can find and fix bugs, configured not to include personal data.
  • Google Analytics and PostHog (EU): receive the anonymous usage events described above, forwarded by our own server. They never receive health values, your name, or your email.

We do not use any advertising network or data broker, and no provider receives your body-scan photos.

Where GDPR applies, we process your data on the basis of your consent (which you can withdraw at any time by turning off sync, signing out, or deleting your account), to perform our contract with you (providing the app), and our legitimate interest in keeping the app secure and functional. Health data is processed only with your explicit consent.

Sharing with a clinic runs on your explicit consent under Article 9(2)(a), given separately for each category and withdrawn by turning that category off or ending the link. We also keep a record of every read a clinic makes of your data; we do that to be able to show you that record and to meet our own accountability obligations under Article 5(2), so its basis is our legitimate interest in an auditable system rather than your consent, which is why it survives you withdrawing the rest.

Data retention

Data you keep on your device stays until you delete it in the app or remove the app. If you enable sync, we keep your synced data for as long as your account is active. Food photos, voice recordings, and typed meal entries are processed transiently and are not retained after the estimate is produced. When you delete your account, your personal data is deleted from our systems within 30 days, except where we are legally required to retain limited records.

Data shared with a clinic is kept while the link is active. Turning a category off, or ending the link, deletes what that category covered unless another clinic you still share it with covers it too, and deletes that clinic’s notes about you on that link outright. The access log (who read what, and when) is kept so that you can see it, and each entry is deleted two years after it was written. Deleting your account removes everything shared with every clinic along with the rest of your data.

Your rights and how to exercise them

You can access, export, correct, or delete your data at any time. Most of this is available directly in the app under Settings: use Export my data to download everything as a JSON file, and Delete account & all data to erase everything on your device and on our servers. You can also delete your account from the account deletion page or by emailing us.

To revoke consent, turn off sync or sign out (which stops data leaving your device), turn off AI food scanning under Profile → AI food scanning (which stops anything being sent to our AI provider), or delete your account (which erases it).

GDPR (EEA/UK): you have the right to access, rectification, erasure, portability, restriction, and objection, and to lodge a complaint with your local data protection authority. CCPA/CPRA (California): you have the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information, and we do not sell or share your personal information. We will not discriminate against you for exercising any of these rights.

Children’s privacy

Pensday is rated 13+ and is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has used the app, contact us and we will delete the data.

International data transfers

If data is transferred outside your region, we use appropriate safeguards (such as the standard contractual clauses) to protect it in line with applicable law.

Security

We use encryption in transit (TLS), access controls, and reputable infrastructure providers to protect your data. No system is perfectly secure, but we work to protect your information and will notify you of a breach where required by law.

Changes to this policy

We may update this policy as the app evolves. Material changes will be highlighted in the app or on this page, and the “last updated” date above will change.

Contact us

Questions about privacy, or want to exercise a data right? Email support@pensday.com and we’ll help. Pensday is operated by Lightzone Solutions LTD (England & Wales).