Important Notice
Penzy is a personal local record tool for GLP-1 routines and body changes. It helps you record medication execution, inventory, expiry dates, weight, appetite, discomfort, reminders, and trends. Penzy is not a medical institution and does not provide diagnosis, treatment, prescriptions, drug purchasing, dosage adjustment, efficacy assessment, or medical advice.
Weight, medication records, inventory, discomfort notes, appetite changes, and related health logs may be sensitive personal information. Please use Penzy only after you understand and agree to this policy. If you do not agree, stop using the App and delete it.
No privacy policy can remove every risk. Penzy reduces risk through local storage, data minimization, clear notices, and no advertising or analytics SDKs. Device loss, system backups, user-initiated exports or sharing, third-party apps, Apple system services, and future platform changes may still create additional risk.
1. Scope and Service Provider
This policy applies to the Penzy iOS App and related static information pages. The service provider is the Penzy developer. You can contact us at hazen_sun@foxmail.com. If the App Store listing shows a different legal seller or developer entity, the App Store listing controls for that store context.
The current version is a local-first single-user app. It does not require registration or sign-in, does not upload health records by default, does not include advertising SDKs, does not include analytics SDKs, and does not provide community features or telemedicine. The App may, with your explicit permission, read your last 30 days of body weight, body fat percentage, and waist circumference from Apple Health to prefill onboarding fields and create local trend records. It does not write to Apple Health and does not use CloudKit or iCloud Drive sync.
This policy does not govern Apple, email providers, share-sheet destinations, doctors, pharmacists, or any third-party app or service that you choose to use. Once you leave Penzy or share data through system features, the third party's own terms and privacy rules may apply.
2. Information We Process and Why
During normal use, Penzy stores record data on your device. The table below explains what the current version processes, why it is processed, and where it is stored or transmitted.
| Scenario | Information involved | Purpose | Storage or transfer |
|---|---|---|---|
| First-use confirmation | Whether you acknowledged the non-medical notice and sensitive health-record processing notice | To confirm that you understand the product boundary and data sensitivity | Stored locally in UserDefaults; not uploaded |
| Body baseline | Initial weight, height, reference target weight, and derived BMI | To create a local baseline, trend display, and local report | Stored in the App's local data file on your device |
| Optional Apple Health import | Last 30 days of body weight, body fat percentage, and waist circumference | To prefill body baseline fields and create local trend records | Read only after iOS authorization; imported to local records; not written back to Apple Health; not uploaded |
| Diary records | Medication dates, weight, appetite, discomfort, notes, record titles, and details | Personal logs, calendar review, trend display, and local CSV export | Stored locally on your device; not uploaded by default |
| Inventory and plans | Drug name, specification, source, batch number, expiry date, remaining doses, low-stock threshold, cycle, and reminder time | To record inventory status and medication execution based on your external plan | Stored locally on your device; not uploaded by default |
| Local notifications | Weight reminder settings, medication-day reminder settings, dates, and times | To deliver iOS local reminders | Submitted to iOS local notification services; reminder text can avoid showing drug names or specs |
| CSV export and system sharing | The records, titles, details, and dates that you choose to export | To create a local file for your own archive or for sharing with a professional | Generated locally and then handed to the iOS share sheet; you choose the destination |
| Feedback | Feedback type, content, optional contact details, record count, and inventory-batch count | To receive and respond to feedback that you actively submit | Leaves your device only if you send it through email or a share target |
| Purchase or unlock status | Whether the App is unlocked, free recording limits, StoreKit purchase result, and restore-purchase status | To distinguish free and unlocked local-record capabilities | Unlock state is stored locally; payments, refunds, taxes, and billing credentials are handled by Apple |
3. Sensitive Personal Information
Health-related data that you enter or import, including weight, body fat percentage, waist circumference, medication execution, inventory, discomfort, appetite changes, and health notes, may reveal your health condition, medication status, or lifestyle. Misuse or disclosure of this data may affect your dignity, safety, property interests, insurance, employment, or social evaluation. We therefore treat this information as sensitive personal information.
The reason this information is processed is that Penzy's core function is to help you keep local personal health-related logs, inventory, reminders, and reviewable trends. If you do not provide it, the related recording, trend, reminder, and export features may not work or may be incomplete.
Current protections include local-first storage, no required account, no default health-record upload, no advertising tracking, no use of health records for marketing or data brokerage, local file protection provided by iOS, reminder text that can avoid drug names or specifications, first-use compliance acknowledgement, and explicit Apple Health permission prompts.
4. Legal Basis, Consent, and Withdrawal
Where applicable, Penzy processes information because it is necessary to provide the local record, reminder, trend, export, feedback, and unlock features that you request, and because you actively choose to enter sensitive information, authorize Apple Health access, enable notifications, send feedback, or export and share files.
You may refuse to enter information, decline or revoke Apple Health permission, turn off notification permission, stop exporting records, stop sending feedback, or stop using the App. Revoking permission does not affect processing that was already completed before withdrawal. Turning off Apple Health access does not automatically delete records that were previously imported to your local data; delete those records in the App or remove the App and its data if needed.
5. Device Permissions
- Notifications: Used only for weight reminders and medication-day reminders. You can disable Penzy notifications in iOS settings.
- Apple Health: Requested only when you choose to authorize it. The current version reads only the last 30 days of body weight, body fat percentage, and waist circumference. It does not read height, BMI, medication, symptoms, or other Health data, and it does not write to Apple Health.
- Email and sharing: Feedback, CSV export, and recommendation sharing use the system mail composer or share sheet. Content leaves your device only after you confirm sending or choose a destination.
- Unused permissions: The current version does not request camera, photos, location, contacts, microphone, Bluetooth, CloudKit, calendar, or address-book permissions.
7. Third-Party Services and SDK List
The current version does not integrate advertising SDKs, analytics SDKs, third-party login SDKs, map or location SDKs, cloud-sync SDKs, or health-data servers. It may use the following Apple, system, or static website capabilities:
- HealthKit / Apple Health: Reads the last 30 days of body weight, body fat percentage, and waist circumference after your authorization.
- StoreKit / App Store: Supports non-consumable unlocks, restore purchases, refunds, and revocation handling. Payment information is handled by Apple.
- Penzy static website configuration: May be used for paywall display copy, such as unlock scope or explanatory text. The request does not include health records, local records, or an account identifier.
- UserNotifications: Used for local weight reminders and medication-day reminders.
- System mail and share sheet: Used when you actively send feedback, export CSV, or share recommendation text.
- TestFlight: If you participate in testing, installation, crash reporting, and feedback features are handled under Apple's TestFlight rules.
8. Retention, Deletion, and Backups
Your diary, inventory, plans, reminder settings, and local records imported from Apple Health stay on your device until you delete the relevant content, uninstall the App and its data, erase device data, or iOS handles the data because of storage, restore, or system conditions. The current version supports correcting or deleting individual records, deleting inventory batches, and clearing local health and inventory data.
Penzy does not use CloudKit or iCloud Drive sync and does not actively sync records to the cloud. If you enable iCloud backup or other device backup features in iOS, whether local App data is included is controlled by Apple system rules and your settings. You can manage iCloud backup in iOS settings or delete the App and its data if you do not want it retained.
CSV files and feedback drafts are generated locally first. Once you save them to Files, send them by email, or share them with a third party, later storage and deletion are controlled by you and the recipient.
9. Your Rights
Subject to applicable law, you may access, correct, copy, export, and delete your local records, revoke notification permission, withdraw Apple Health permission, or stop using the App. Because the current version does not use an account or server for your health records, we cannot remotely view, modify, or delete records stored only on your device.
If you previously submitted feedback by email, you may contact us at hazen_sun@foxmail.com to request access, deletion, or cessation of use of that feedback. To protect privacy, please do not send identity documents, prescription photos, complete medical records, insurance information, payment credentials, or other unnecessary sensitive materials in feedback.
If you believe our processing affects your personal-information rights, contact us first. We will verify and handle the request within a reasonable period. This policy does not limit any mandatory rights you may have under applicable law.
10. International Transfers
The current version has no Penzy account, proprietary server, or cloud sync, and we do not actively transfer your local health records across borders. When you use App Store, TestFlight, Apple Health, iCloud backup, email services, or share-sheet destinations, data may be processed by Apple or the third party you choose in different regions under their own rules.
If we later add proprietary servers, cloud sync, overseas vendors, cross-platform accounts, or third-party SDKs that involve cross-border personal-information transfer, we will update this policy before launch, describe the recipient, purpose, method, data categories, and rights process, and obtain any legally required consent or complete required procedures.
11. Children and Minors
Penzy is not directed to children under 14 and does not recommend independent use by minors. If a minor needs to record information, use should occur with guardian consent and supervision, and any medication-related matter should follow a doctor, pharmacist, and official drug instructions.
If we learn that a child under 14 submitted feedback without guardian consent, we will delete or stop processing the relevant feedback after reasonable verification.
12. Security Incidents
Because current health records are stored locally by default, your device password, system account, backups, exported files, and share destinations are important security factors. We recommend enabling a device lock, avoiding access by untrusted people, sharing CSV and feedback materials carefully, and periodically reviewing iOS Health, notification, and iCloud backup settings.
If personal information in feedback emails or any future Penzy server is leaked, tampered with, or lost, we will take remedial measures as required by applicable law and notify affected users and regulators through email, page notice, or other reasonable means when required. Because the current version has no account system, we may not be able to identify every affected device.
13. Updates to This Policy
If future versions add accounts, server sync, cloud backup, third-party SDKs, advertising, analytics, CloudKit, subscriptions, Apple Health writing, Android versions, or other data processing, we will update this policy and provide appropriate notice in the App, on the website, or in App Store metadata. Material changes may require a new confirmation before continued use.