Privacy Policy
1. Who we are
Remindr (“we”, “us”, or “our”) operates the Remindr mobile application. For the purposes of applicable data protection law, we act as the data controller for personal data described in this Privacy Policy.
Contact: [email protected]
Address: Turkey
2. Scope
This Privacy Policy explains how we collect, use, store, and share personal data when you use the Remindr mobile app and related backend services. It applies to account holders and to information you enter about people you care for within the app.
This policy does not cover third-party websites or services linked from the app (for example, app store listings or OAuth provider policies. Those services are governed by their own policies.
3. Information we collect
3.1 Account and identity data
When you register or sign in, we may collect:
- First and last name
- Email address
- Password (stored hashed on our servers not plain text)
- Phone number (optional)
- Date of birth (optional)
- Profile avatar image (optional)
- Authentication provider and provider identifier (for Google or Apple sign-in)
- Internal user identifier (
ulid) and session token metadata
3.2 Reminder data
- Title, notes, dates and times, categories, repeat settings
- Frequency and schedule times (for example once daily, twice daily)
- Completion state and completed-date history
3.3 Patient data
- Patient name, relationship to you, date of birth, avatar emoji
3.4 Medication and health-related schedule data
- Medication name, dosage, form/frequency, scheduled dates and times
- Stock quantities, dose logs, refill logs
This data may relate to health and care routines. It is stored because you choose to enter it.
3.5 Task data
- Task description, state, and optional task date
3.6 Feedback and bug reports
- Name, email, description (required in current product direction)
- Optional screenshot/image attached to a report
3.7 Device and push notification data
- Expo push token
- Platform (iOS/Android) and device model identifiers where available
3.8 Technical and security data
- IP address captured on server-side saves (via environment/client IP helper)
- API request metadata logged on the server (method, host, source)
- Session records may include IP address and user agent (Laravel sessions table)
- Login requests may include a static device label (for example, “mobile”)
3.9 Data stored locally on your device
The app stores data on your device using Expo Secure Store (authentication token, session identifiers) and AsyncStorage (cached reminders, patients, animals, medications, tasks, settings, feedback list, and offline sync queue. Local storage allows offline use and faster loading.
3.10 What we do not collect (based on current code)
- No GPS/location tracking SDK identified in the mobile codebase
- No third-party product analytics SDK (for example, Firebase Analytics, Sentry) identified in app source
- No in-app advertising identifiers identified
The app requests photo-library permission for avatar and feedback images, and notification/alarm
permissions for reminders.
A RECORD_AUDIO permission appears in app configuration in connection with alarm
audio playback not for recording user audio content.
4. How we collect information
- Directly from you when you register, create content, upload images, or send feedback.
- Automatically when the app communicates with our API (for example, IP address and request logs).
- From third-party sign-in providers when you choose Google or Apple authentication (tokens/identifiers validated server-side).
- On your device when the app caches data locally or registers for push notifications.
5. Why we use information
We use personal data to:
- Provide and operate the Service (store and sync your reminders, patients, animals, medications, and tasks)
- Authenticate you and maintain your session
- Schedule and deliver notifications and alarms on your device
- Send password-reset codes by email
- Register and use push tokens for cross-device alarm sync where enabled
- Review bug reports and optional screenshots you submit
- Secure the Service, troubleshoot errors, and prevent abuse
- Comply with legal obligations
- Improve the Service based on support feedback and usage patterns visible in server logs
We do not use your data for third-party advertising.
6. Legal bases (EEA/UK users)
If you are in the European Economic Area or the United Kingdom, we process personal data on the following bases:
- Contract to provide the Service you request (account, sync, notifications.
- Legitimate interests to secure the Service, prevent fraud/abuse, and improve reliability, balanced against your rights.
- Consent where required for optional processing (for example, certain permissions on your device. You may withdraw consent via device settings, though some features may not work.
- Legal obligation where we must retain or disclose data under applicable law.
7. Sharing and processors
We share personal data only as described below:
7.1 Service providers and infrastructure
We use hosting and email infrastructure to run the backend API and send password-reset messages. Our API is hosted at https://api.remindr.org.uk/. Password-reset emails are sent via Gmail / Google Workspace.
7.2 Authentication providers
If you use Google or Apple sign-in, those companies process authentication data under their own policies. We receive validated identity information needed to create or access your account.
7.3 Expo push notification service
Push tokens and notification payloads may be processed by Expo’s push service to deliver notifications to your device.
7.4 Legal and safety
We may disclose information if required by law, court order, or governmental request, or if we believe disclosure is necessary to protect rights, safety, or security.
7.5 No sale of personal data
We do not sell your personal data. We do not share it for cross-context behavioral advertising based on the current application code.
7.6 Administrative access
Authorized personnel may access feedback/bug reports and related metadata for support and quality purposes.
8. International transfers
Application data is hosted on servers in Türkiye. Network connectivity may be routed via Cloudflare. Password-reset email is processed via Google. Depending on where you live, your use of the Service may involve international transfers of personal data. Where required, we implement appropriate safeguards (for example, Standard Contractual Clauses).
9. Retention
We retain personal data for as long as your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and comply with legal obligations.
- Account data: deleted when you delete your account.
- Content you create: until deleted by you or your account is deleted.
- Server logs: 30 days.
- Push tokens: until unregistered on logout or account deletion where implemented.
When you delete your account, we permanently delete all user-related data from our systems.
Data stored locally on your device may remain until you uninstall the app or clear app storage, even after logout or account deletion.
10. Security
We use administrative, technical, and organizational measures designed to protect personal data, including HTTPS transport, authenticated API access, hashed passwords, and access controls on server infrastructure.
No method of transmission or storage is 100% secure. You are responsible for securing your device and credentials. Authentication tokens are stored in Expo Secure Store on device.
If you have security concerns, contact us at [email protected].
11. Your choices and rights
11.1 In-app controls
- Access/update profile: edit account details in the app.
- Delete account: available from Profile → Details; calls authenticated delete endpoint.
- Logout: revokes session token and unregisters push token where applicable.
- Permissions: manage notifications, photos, and alarms in device settings.
11.2 Data export
The current application does not provide a self-service data export or download feature. You may request a copy of your data by contacting us at [email protected], subject to applicable law and identity verification.
11.3 Rights under applicable law
Depending on your location, you may have rights to access, rectify, erase, restrict, object to, or port your personal data, and to withdraw consent where processing is consent-based. You may also lodge a complaint with your local supervisory authority.
To exercise rights, email [email protected]. We may need to verify your identity before responding.
12. Children
The Service is not directed to individuals under 12 years of age. We do not knowingly collect personal data from anyone under 12. Individuals under 12 may not use the Service. Because the app allows caregiver-entered patient profiles (including minors' names and dates of birth), the adult account holder is responsible for having a lawful basis to enter that information.
If you believe we collected a child's personal data improperly, contact [email protected].
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date and, where required, provide additional notice. Continued use after changes become effective means you accept the updated policy.
14. Contact
Privacy questions or requests:
- Email: [email protected]
- Address: Turkey