Privacy Policy
This Privacy Policy describes how the independent software developer who publishes the Pinny application on the Apple App Store, as identified in the App Store listing (the "Developer", "we", "us" or "our"), collects, uses, discloses and otherwise processes personal information in connection with the Pinny mobile application (the "Application"). It also describes your rights in respect of that information.
This Privacy Policy is issued in compliance with the Protection of Personal Information Act 4 of 2013 (South Africa) ("POPIA"), Regulation (EU) 2016/679 (the "GDPR"), the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended ("CCPA"), the Privacy Act 1988 (Australia) and comparable legislation. Capitalised terms not defined herein have the meanings given in the Terms of Use.
1. Responsible Party and Controller
1.1 For the purposes of POPIA the Developer is the "responsible party", and for the purposes of the GDPR and UK GDPR the Developer is the "controller", in respect of the limited categories of personal information described in clause 3 that are transmitted from your device. The Developer is not a responsible party or controller in respect of Health Information, which is processed exclusively on your device and is not transmitted to or accessible by the Developer.
2. Architecture of the Application
2.1 The Application is designed as a local-first application. It does not require or offer user accounts, does not authenticate users, and does not transmit User Data to any server operated by or on behalf of the Developer. All Health Information and other User Data are stored in the Application’s private container on your device and are protected by the security mechanisms of the iOS operating system, including device encryption and passcode protection where enabled by you.
2.2 User Data may be included in device backups made by you through Apple’s iCloud Backup or a computer backup. Such backups are governed by Apple’s privacy policy and are not accessible to the Developer.
3. Categories of Personal Information Processed
3.1 Health Information (device only). Medication and dose, injection schedule, injection records (date, time, dose, injection site, notes), body weight, body measurements, symptom records, progress photographs, cost settings, reminder preferences and, if entered, your first name. This category constitutes special personal information under section 26 of POPIA and data concerning health under Article 9 of the GDPR. It is processed solely on your device, by you, and is never transmitted to the Developer or to any third party except where you elect to share a file as described in clause 3.6.
3.2 Purchase Information. Where you purchase Pinny Plus, Apple processes your payment and billing information as an independent controller under Apple’s privacy policy. To validate entitlement and restore purchases across devices, the Application transmits to the Developer’s subscription management provider (RevenueCat, Inc.) a pseudonymous identifier generated by the Application, the App Store transaction receipt, the product purchased, and the device platform and application version. No Health Information is included.
3.3 Usage Information. Subject to your consent (see clause 4.1(c)), the Application transmits pseudonymous event data describing interaction with the Application, for example that a screen was opened or a feature was used, together with the application version, device model, operating system version, language and country. Event data are designed so as never to include the values you enter: no weight, dose, symptom, note, photograph or other Health Information is transmitted. Usage Information is processed by PostHog, Inc. on infrastructure located in the European Union.
3.4 Diagnostic Information. In the event of an application crash or error, a technical report comprising the device model, operating system version, application version, and a stack trace identifying the point of failure in the software is transmitted to the Developer’s crash-reporting provider (Functional Software, Inc., trading as Sentry). Diagnostic reports are configured so as to exclude User Data.
3.5 Correspondence. If you contact the Developer, the Developer will process the information you provide, including your contact details and the content of your communication, for the purpose of responding to you.
3.6 Information You Elect to Share. The Application enables you to export a backup file, a spreadsheet or a report and to transmit it to an application or recipient of your choosing using the sharing functionality of your device. Information so shared leaves the Application at your direction and is thereafter subject to the privacy practices of the recipient. The Developer does not receive a copy.
4. Purposes and Legal Bases of Processing
4.1 The Developer processes the categories of personal information described in clauses 3.2 to 3.5 for the following purposes and on the following legal bases:
(a) Purchase Information: to provide, validate and restore your Pinny Plus entitlement and to detect fraudulent transactions. Legal basis: performance of a contract (GDPR Article 6(1)(b); POPIA section 11(1)(b)).
(b) Diagnostic Information: to identify, diagnose and remedy defects in the Application and to maintain its security and stability. Legal basis: the Developer’s legitimate interests in maintaining a functioning and secure product (GDPR Article 6(1)(f); POPIA section 11(1)(f)).
(c) Usage Information: to understand how the Application is used, to identify usability problems and to improve the Application. Legal basis: your consent (GDPR Article 6(1)(a); POPIA section 11(1)(a)), which you may withdraw at any time by disabling "Anonymous usage statistics" under More → Privacy and about. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
(d) Correspondence: to respond to your enquiries and to comply with legal obligations. Legal basis: legitimate interests and compliance with legal obligations.
4.2 The Developer does not process personal information for the purposes of direct marketing, does not serve advertising within the Application, does not sell or share personal information within the meaning of the CCPA, and does not engage in "tracking" as defined by Apple’s App Tracking Transparency framework.
4.3 The Developer does not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
5. Apple Health (HealthKit)
5.1 If, and only if, you enable the Apple Health integration, the Application will request permission to read and write the body mass data type within HealthKit. The Application uses HealthKit data solely to display your weight history within the Application and to record weigh-ins you enter into Apple Health at your request.
5.2 In accordance with Apple’s requirements, HealthKit data are not stored in iCloud by the Application, are not used for advertising, marketing or any use-based data mining, are not sold, and are not disclosed to any third party except as directed by you through the sharing functionality described in clause 3.6.
5.3 You may revoke the Application’s HealthKit permissions at any time in the Health application or the Settings application on your device.
6. Recipients and Processors
6.1 The Developer engages the following third parties as processors (operators, in POPIA terms) acting on documented instructions and bound by written data processing terms: RevenueCat, Inc. (subscription management, United States); PostHog, Inc. (usage analytics, European Union hosting); and Functional Software, Inc. (Sentry) (crash reporting, United States).
6.2 Apple Inc. processes payment, billing and App Store account information as an independent controller under the Apple Privacy Policy.
6.3 The Developer may disclose personal information where required to do so by law, regulation, court order or lawful request of a public authority, or where necessary to establish, exercise or defend legal claims.
6.4 In the event of a sale, merger or transfer of the Application to a successor, the limited personal information described in clause 3 may be transferred to the successor, who will be bound by this Privacy Policy or a policy no less protective.
7. International Transfers
7.1 Usage Information is processed within the European Union. Purchase Information and Diagnostic Information are processed in the United States. Transfers of personal information from South Africa are made in accordance with section 72 of POPIA, and transfers from the European Economic Area and the United Kingdom are made under the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, or to recipients participating in the EU-U.S. Data Privacy Framework, as applicable.
8. Retention
8.1 Health Information and other User Data remain on your device until deleted by you through the Application’s erase function, by deletion of individual records, or by removal of the Application from your device.
8.2 Purchase Information is retained for the duration of your entitlement and thereafter for the period required to comply with tax, accounting and consumer law obligations.
8.3 Usage Information and Diagnostic Information are retained for no longer than is necessary for the purposes set out in clause 4 and in any event for no more than twenty-four (24) months from collection, after which they are deleted or irreversibly aggregated.
8.4 Correspondence is retained for as long as necessary to respond to and resolve your enquiry and thereafter for the period required by applicable law.
9. Security
9.1 The Developer implements appropriate technical and organisational measures to protect the personal information it processes, including encryption of all information in transit using Transport Layer Security, pseudonymisation of Usage and Purchase Information, and restriction of access to processor dashboards. Security of information stored on your device depends on the security measures you apply to the device, including passcode, biometric protection and operating system updates.
9.2 In the event of a security compromise affecting personal information under the Developer’s control, the Developer will notify the Information Regulator (South Africa), any other competent supervisory authority, and affected data subjects as required by section 22 of POPIA, Articles 33 and 34 of the GDPR and comparable legislation.
10. Your Rights
10.1 Subject to applicable law, you have the right to request access to, rectification of, erasure of, and restriction of the processing of your personal information; to object to processing based on legitimate interests; to receive personal information you have provided in a structured, commonly used and machine-readable format; and to withdraw consent at any time where processing is based on consent.
10.2 Because Health Information and other User Data are held exclusively on your device, these rights are exercised directly within the Application: you may view and correct any record; export all User Data under More → Your data; and permanently erase all User Data under More → Your data → Erase everything. Erasure is immediate and irreversible and cannot be performed or reversed by the Developer.
10.3 Requests relating to Purchase Information, Diagnostic Information or Correspondence may be made to the Developer using the contact details in clause 13. The Developer will respond within the period prescribed by applicable law, and in any event within thirty (30) days, subject to verification of your identity.
10.4 Residents of California have the right to know the categories and specific pieces of personal information collected, the right to delete, the right to correct, and the right not to be discriminated against for exercising those rights. The Developer does not sell or share personal information and does not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
10.5 You have the right to lodge a complaint with a supervisory authority, in particular the Information Regulator of South Africa, the Information Commissioner’s Office (United Kingdom), the data protection authority of the EU Member State of your habitual residence, or the Office of the Australian Information Commissioner, as applicable.
11. Children
11.1 The Application is not directed at persons under the age of eighteen (18) and the Developer does not knowingly collect personal information from children. If the Developer becomes aware that personal information has been collected from a child, it will take steps to delete such information promptly.
12. Changes to this Privacy Policy
12.1 The Developer may amend this Privacy Policy from time to time. The amended Policy will be made available within the Application and the "Last updated" date will be revised. Where a change materially affects the processing of your personal information, the Developer will provide notice within the Application and, where required by law, obtain your consent.
13. Contact
13.1 Requests, questions and complaints concerning this Privacy Policy or the processing of personal information should be directed to the Developer using the contact details set out below and in the App Store listing.