Privacy Policy
Last updated September 17, 2026
Pinned is built local-first: your protocol, dose, inventory, and health records are stored on your device. We do not run accounts, and we do not operate a server that stores your health data. Your health entries — protocols, doses, inventory, injection sites and notes — never leave your device and are never shared with anyone. Separately, ad measurement happens only with your permission, as described below.
Who is responsible
Pinned and this website are provided by NETKREATIVES BV, Volaardestraat 88, 9200 Dendermonde, Belgium, enterprise number 0638.905.445. We are the controller of the personal data described here. Privacy questions and requests: [email protected].
What stays on your device
- Protocols, dose logs, schedules, and injection-site history
- Inventory (vials, diluents, supplies) and reconstitution records
- Measurements, check-ins, symptoms, notes, and progress photos
- Data imported read-only from Apple Health (only the types you approve). Health data is never transmitted off your device by Pinned.
Deleting the app deletes this data. You can also erase it in-app (Settings → Reset). Optional backups are encrypted and created only when you export them.
Notifications
Dose and check-in reminders are scheduled locally on your device. Reminder content can be redacted from the lock screen in Settings.
What leaves your device
Purchases in the app. Subscriptions bought in the app are processed by Apple. We use RevenueCat to validate purchases; it receives your purchase history and a random anonymous identifier — never your name, email, or health data. See the RevenueCat privacy policy.
Anonymous usage counts. To learn which parts of Pinned are actually used, the app sends a small number of anonymous events to TelemetryDeck, a privacy-focused analytics service based in Germany — for example "a dose was logged" or "the paywall was shown". Each event carries a random identifier that Pinned generates itself; it is not your Apple ID, not your device's advertising ID, and is not linked to your purchases, and it is hashed on your device before it is sent, so TelemetryDeck never receives the identifier itself. Events never include your protocols, compounds, doses, measurements, notes, photos, or any health data — the app is built so those values cannot be attached to an event. TelemetryDeck does not store your IP address. You can turn this off at any time in Settings → Privacy → Share anonymous usage; switching it off deletes the random identifier, so turning it back on creates a new one that cannot be linked to the old.
Nothing else. Apart from the purchase records and anonymous usage events above — and the ad measurement described in the next section, if you allow it — nothing leaves your device. Pinned shows no ads. Your protocols, doses, inventory, injection sites and notes are never part of any of this, and are never shared with anyone.
Ad measurement in the app — only with your permission
We advertise Pinned with Meta and want to know which ads lead to installs and subscriptions. The app asks you once, after onboarding. In the European Union, the EEA, the United Kingdom and Switzerland nothing is sent to Meta unless you choose Allow. Elsewhere measurement is on by default and you can switch it off.
If it is on, Meta's software in the app tells Meta that the app was opened, that onboarding was finished, that the purchase screen was seen, that the purchase button was tapped, and that a trial was started or a subscription was bought, with its price and currency — together with device and network information such as device model, system version, language, time zone and IP address. Your device's advertising identifier is included only if you also allow Apple's tracking prompt.
No health entry is ever part of this. Your protocols, substances, doses, inventory, injection sites, measurements, photos and notes are never sent to Meta or to anyone else.
Change your choice at any time in the app under Settings → Ad measurement, and Apple's tracking permission in the iOS Settings app. Where no ad software runs, the app only tells Apple that it was installed (SKAdNetwork), which identifies no one.
This website and cookies
This website is hosted on Cloudflare, which processes technical request data such as your IP address and browser headers to deliver and protect the site; Cloudflare may set a strictly necessary security cookie. The site has no analytics, and the pages you read here load no tracker.
The one exception is the pages under pinnedtracker.com/start, where you can answer a few questions and buy a subscription on the web. There, and only after you choose Allow in the banner, the page loads Meta's pixel and tells Meta that you viewed the page, saw your result, opened the price screen and went to the checkout, and whether a trial or purchase followed. The same events, carrying the same ID so that they are counted once, also go to Meta through our own relay (a Cloudflare Worker we run), with your IP address, your browser type and the values of Meta's cookies. Your answers to the questions are never stored and never sent to anyone.
Choose “No thanks”, or never answer, and nothing from Meta is loaded, no marketing cookie is set and nothing reaches the relay. You can change your choice at any time through “Cookie settings” at the bottom of the page; a later no also deletes Meta's cookies. What is stored in your browser:
- _fbp — set by Meta's pixel after Allow; 90 days
- _fbc — set by Meta's pixel after Allow, when you arrive from a Meta ad; 90 days
- w2a.consent — your choice (“yes” or “no”), kept in your browser's local storage until you change it; it is not sent to us
Buying on the web
If you buy a subscription on this website instead of in the app, the checkout is run by RevenueCat (United States) and its payment provider. You enter your e-mail address and payment details there; we never see your full card details. Your e-mail address is used to send your receipt and the link that unlocks the app, and to let you manage or cancel the subscription.
RevenueCat keeps the purchase record and an anonymous app user identifier, so that the app can recognise the purchase. If you allowed measurement on those pages, our relay first confirms the purchase with RevenueCat and then reports to Meta that a trial or purchase happened, with its value and currency, and with a hashed (SHA-256) form of your e-mail address and of the anonymous identifier, which Meta uses to match the purchase to an ad. Your e-mail address is never sent in readable form, and nothing you enter in the app is ever included. The purchase terms apply to web purchases.
When you contact us
If you email us we receive your address and what you write, and we use it to answer you. Please leave out health details that are not needed for your question.
Why we may process this
Performing our contract with you: providing the app, confirming purchases and handling a purchase made on the web. Our legitimate interest in a working, improving product: privacy-preserving usage statistics (which you can switch off), site security and answering support requests. Your consent: ad measurement in the app where consent is required, the advertising identifier, and Meta's pixel and our relay on the /start pages. You can withdraw consent at any time; that does not affect earlier processing. A legal obligation: keeping the accounting records of web purchases.
Who receives data, and where
The recipients are the providers named above, acting for us or, in the case of Meta, also for their own purposes. TelemetryDeck processes data in Germany. Meta, RevenueCat and its payment provider, Cloudflare and Apple may process data in the United States or other countries outside the EEA; they rely on the EU–US Data Privacy Framework or on the European Commission's standard contractual clauses. We do not sell personal data, and no health entry is ever among the data these providers receive.
How long
Data on your device stays until you delete it or remove the app. Your consent choice is kept in the app or in your browser until you change it. We keep support emails for up to two years after the last contact, and the accounting records of a web purchase for as long as Belgian tax and accounting law requires. The providers keep data as described in their own policies; Meta's cookies last 90 days.
Your rights
Because your health data lives on your device, you control it directly: export it in the app, or delete it at any time. For the limited data described above you may ask us for access, correction, deletion, restriction or a copy in a portable format, and you may object to processing based on our legitimate interests. Write to [email protected]; we answer within one month. The data deletion page explains how to remove what is on your device. You may also complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be, or to the authority where you live. CCPA requests go to the same address.
Changes
If we change this policy, we will update this page and the date above. If a change affects a consent you gave, we ask again.