Privacy Policy

Last updated: 2026-10-08

This Privacy Policy explains how We Are So Back Ltd ("we", "us"), a company registered in the Republic of Cyprus, handles information when you use Thyroid Coach (the "App").

Thyroid Coach records health-related information you choose to enter — your medication and supplement schedule, daily check-ins, and lab values. We designed it so that this information stays on your device. This Policy explains exactly what that means.

TL;DR

  • No accounts, no sign-up.
  • No network calls for any core feature. Your timeline, check-ins, labs, trends, and doctor report all run on your device.
  • Your health log (dose times and strengths, check-ins, symptoms, lab values, notes) never leaves your device unless you export or share it yourself.
  • We use PostHog (EU-hosted) for usage statistics and crash reports, under a random identifier. They never include your health log. You can turn this off in Settings.
  • If you installed the App from an Apple Ads ad, we record which campaign and search keyword it was, so we know which ads work. No tracking prompt, no advertising identifier, no cross-app tracking.
  • We never use your health information for advertising or marketing, and we never sell or share it.
  • Subscription billing is handled by Apple. RevenueCat helps us verify it. Neither receives your name or email from us.
  • The App never sends notifications about your free trial or subscription.

Who we are

We Are So Back Ltd, Cyprus. Contact: wearesobackltd@gmail.com.

We are the data controller for any personal data processed via the App. We have not appointed a Data Protection Officer because we do not meet the thresholds in GDPR Article 37.

Information we collect today

Stored only on your device (we never see it):

  • Your onboarding answers and preferences — including your wake anchor, reminder settings, and the symptoms you choose to track (in iOS UserDefaults).
  • Your health log (via SwiftData and the iOS file system), which may include: your medication and supplement regimen and timing, "taken / with food / missed" dose logs, an optional "iron bothered my stomach" flag, daily and weekly check-in entries (energy, mood, cognitive and iron-related symptoms), an optional menstrual-heaviness flag and pregnancy flag, lab values you enter (such as TSH, free T4, and ferritin) with their units and printed reference range, appointment dates, and any notes you add.
  • Doctor-visit report PDFs you generate. These are produced on your device from the data above. They are not uploaded anywhere. If you choose to share one — by email, Messages, AirDrop, or printing — that action, and where it goes, is entirely under your control through the standard iOS share sheet.

Sent off-device when you use the App:

  • Usage analytics (PostHog). The App sends usage events to PostHog, a product analytics service we use as a processor, hosted in the European Union (PostHog EU Cloud). Each event carries:

    • a random identifier generated on your device when the App is first installed. It is not derived from your Apple ID, your device hardware, or anything else that identifies you;
    • a random identifier for the current session;
    • the event and its details: the screens you open; the onboarding steps you view and the options you tap there, recorded as fixed choices (how long you have been managing hypothyroidism, which parts you find hardest, how consistent your timing is, whether you take iron, and your goal; never anything you type); the hour of day you chose for reminders and your wait time before breakfast; which features you use, for example logging a dose, completing a check-in, adding a lab result or sharing your report, with coarse details such as the type of entry, which lab test it was, or how many fields you filled in; the paywall screens you see and the plan you pick; and whether a purchase or restore was started, completed, cancelled or failed (never payment details);
    • the App version, iOS version, device model, language and region setting, whether a subscription or free trial is active, and the date of first launch;
    • your IP address, which PostHog receives as part of any network request and may use to derive an approximate (city-level) location. We do not use this for advertising or to identify you.
    • Crash reports. If the App crashes, the PostHog SDK records the crash (the error type, App and OS version, and the call stack) and sends it on the next launch under the same random identifier.

    Analytics never include your health log: no dose times or strengths you logged, check-in ratings, symptoms, lab values, notes, report contents, or your name. You can switch analytics off at any time in Settings → Share anonymous usage data.

  • Subscription data. When you subscribe, restore, or open the App with an active subscription, Apple receives your Apple ID and payment information (we do not), and RevenueCat receives a randomly generated anonymous App User ID, your subscription status, and basic device identifiers provided by Apple's servers. RevenueCat also forwards subscription events (trial started, renewal, cancellation, expiration, refund, product, price and store country) to PostHog under the same random identifier the App uses. None of this contains your name, email, Apple ID, or health information.

  • Apple Ads attribution. If you installed the App after tapping an ad in Apple Ads, Apple's AdServices framework gives the App a one-time token, which the App sends to Apple to learn which campaign, ad group, keyword and ad led to the install, and when the ad was tapped or seen. The App stores those IDs, and Apple's identifier for this App's purchase record, with RevenueCat alongside your anonymous App User ID, so we can see which ads lead to subscriptions. If you did not come from an ad, Apple only reports that. This uses no tracking prompt, never reads the advertising identifier (IDFA), and is not combined with data from other companies' apps or websites.

That is the full list. The App contains no sign-in, no profiles, no backend servers operated by us, no ad networks, and no cross-app or cross-site tracking. The App's timeline, reminders, charts, and doctor report are all composed locally on your device.

Your health information

Some of what you record in Thyroid Coach is health-related. We treat it with particular care:

  • It is stored only on your device. We do not operate any server that receives it, and we cannot see it.
  • We never use health information for advertising, marketing, or any form of data mining, and we never sell or share it. This is a firm commitment, not merely current practice.
  • It leaves your device only when you decide to export or share it — for example, sending your doctor report PDF to your clinician, or creating an encrypted backup file. Those actions are initiated by you and go where you send them.
  • If your iPhone is set to back up to iCloud or to your computer, the App's on-device data may be included in your own device backup, encrypted and controlled by your Apple ID or your computer. That backup is between you and Apple; we have no access to it.

Notifications

With your permission, the App schedules local notifications on your device to remind you about medication and supplement timing, wait-window completions ("you can have your coffee now"), blood-draw days, and a weekly check. These are generated and delivered entirely on your device — there is no push server, and no information about you is sent anywhere to deliver them. The App never sends notifications about your free trial or subscription. You can disable notifications at any time in the iOS Settings app; the App still works through its on-screen timeline and app badge.

Not medical advice

Thyroid Coach is a general-wellness and self-tracking tool to help you follow the plan your own doctor has given you. It does not diagnose any condition, does not interpret your lab values, and never recommends or changes a dose. It is not a medical device. See the Terms of Service for more. This does not affect how we handle your data, but it is important context for what the App is.

If we change what we collect

If we ever add a new kind of data collection or a new provider, we will update this Policy first, with the provider's name, the data they receive and the legal basis, and ask for your consent in the App wherever the law requires it. We will never include your health log in analytics.

How we use information

  • To provide the App: verify your subscription, restore purchases.
  • To improve the App: understand which features are used, where people drop off during onboarding, subscription behaviour, and crashes.
  • To measure our advertising: see which of our own Apple Ads campaigns and keywords lead to installs and subscriptions.
  • To protect the App: prevent fraud and abuse of the subscription system.
  • To comply with our legal obligations (tax records for subscription transactions).

We do not use the health information you enter for any purpose of our own — it exists solely to power the features you see, on your device.

Legal bases under the GDPR

Where the GDPR applies, we rely on:

  • Contractual necessity (Art. 6(1)(b)) for subscription management and restore purchases.
  • Legitimate interests (Art. 6(1)(f)) for usage analytics, crash reporting, measuring our own ads, fraud prevention and security. You may object at any time, including by turning analytics off in Settings.
  • Consent (Art. 6(1)(a)) for any future collection where the law requires it.

Because the health-related information you enter never reaches us, we do not process special-category data (GDPR Art. 9) on our own servers. It is processed locally on your device, under your control.

Third-party services and subprocessors

Service Why we use it What they receive
Apple App Store / StoreKit Process subscription purchases Apple ID, payment info, transaction details
RevenueCat Verify subscription receipts and entitlements; keep Apple Ads attribution Anonymous App User ID, subscription status, device identifiers from Apple, Apple Ads campaign, ad group and keyword IDs
PostHog (EU Cloud) Usage analytics and crash reports Random install identifier, usage events described above, device and app version, IP address
Apple Ads / AdServices Tell us which ad led to an install A one-time attribution token

None of these services receives the health log you record in the App.

International transfers

PostHog processes analytics in the European Union. Some other providers are located outside the EEA, including in the United States (Apple, RevenueCat). Transfers of personal data outside the EEA are made under the European Commission's Standard Contractual Clauses and/or the EU-US Data Privacy Framework where the provider is certified.

Data retention

We do not maintain user accounts or store personal information about you on our own servers. Where third parties retain data on our behalf:

  • Apple and RevenueCat keep subscription and transaction records, and the Apple Ads attribution stored with them, for the lifetime of your subscription plus the period required by accounting and tax law (typically seven years under Cypriot / EU law).
  • Analytics events and crash reports are kept in PostHog for up to 7 years, and can be deleted on request.

You can delete all device-side data — including your entire health log, every check-in, lab entry, and note — by uninstalling the App. You can also delete individual entries within the App.

Your rights — GDPR (EU / EEA / UK / Switzerland)

You have the right to:

  • access the personal data we hold about you;
  • have it rectified or erased;
  • restrict or object to processing;
  • portability;
  • withdraw consent at any time, where consent was the legal basis;
  • lodge a complaint with your supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection.

Because your health log lives only on your device, you already have direct access to it — you can view, edit, export, and delete it yourself at any time, without asking us. To exercise any right regarding the limited subscription data described above, email wearesobackltd@gmail.com. We respond within 30 days.

Your rights — California (CCPA / CPRA)

If you are a California resident:

  • Categories of personal information collected in the last 12 months: identifiers (a random install identifier and the anonymous App User ID used to verify your subscription), internet or other electronic network activity (the usage events described above, and which Apple Ads campaign led to your install) and commercial information (your subscription status). Your health log is stored on your device and is not collected by us.
  • Categories sold or shared: None. We do not sell or share personal information as defined under the CCPA, and we have not done so in the preceding 12 months. We do not engage in cross-context behavioural advertising.
  • Your rights: to know, delete, correct, and non-discrimination. To exercise, email wearesobackltd@gmail.com.

Children's privacy

The App is intended for adults managing their own care. It is not directed at children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Security

All network requests (subscription verification, analytics and ad attribution) use HTTPS. Because we hold no personal data on our own servers, and because the App's core features do not transmit data, there is no centralised user dataset on our side. The health information you enter is protected by your device's own security — passcode, Face ID / Touch ID, and iOS data protection. Our service providers maintain their own security programmes and certifications.

Changes to this Policy

We may update this Policy. For material changes, we will give you at least 30 days' notice in the App and update the "Last updated" date at the top. Material changes include new categories of data, new service providers, or new purposes of use. Non-material changes (clarifications, typo fixes) take effect when posted.

Earlier versions of this Policy are available on request from the contact address below.

Contact

We Are So Back Ltd Cyprus wearesobackltd@gmail.com