Tomely — Privacy Policy
Last updated: 2026-08-29
1. Who we are
Tomely (listed on the App Store as "Tomely: Med Reminders") is a personal medication reminder and tracking app developed and sold by Gabriel Barca, an individual developer based in Brazil.
If you have any question about this policy or about your data, write to medcontrolsupport@gmail.com. We answer every message.
2. The short version
- We collect the e-mail address you sign up with and the medication information you type into the app.
- We use that information for one purpose only: to run the reminder and tracking service you asked for.
- We do not sell your data. We do not show ads. We do not track you across other apps or websites.
- You can delete your account and all of your data from inside the app at any time.
3. What we collect
Account data
- Your e-mail address.
- Your password, stored only as a cryptographic hash. We never store or see your password in readable form.
Medication data (entered by you)
- Medication name, price, dosage, quantity, start date and end date.
- Schedule information: recurrence type, days of the week and reminder times.
- Dose history: the records created when you mark a dose as taken.
Usage data (anonymous)
- Anonymous analytics events such as screen views and which features are used, collected through Firebase Analytics (Google).
Subscription status
- Whether your account is on the free or premium plan, and which product granted it, received from RevenueCat.
4. What we do NOT collect
- We do not collect your payment card data. Purchases are processed entirely by the Apple App Store or Google Play — card details never reach the app or our servers.
- We do not collect an advertising identifier. Firebase Analytics is configured without advertising ID support, so no advertising ID is read or transmitted.
- We do not run ads and we do not ask for App Tracking Transparency permission, because we do not track you across other companies' apps or websites.
- We do not collect push notification tokens. Reminders are local notifications, scheduled and fired by your own device.
- We do not collect your precise location, contacts, photos, or health data from Apple Health / Google Fit.
5. Medication data is treated as sensitive
The medication information you enter can reveal something about your health. We treat it accordingly:
- It is used only to provide the reminder and tracking service — to schedule your notifications, show your medications and keep your dose history.
- It is never shared with third parties other than the service providers listed in section 7, who process it strictly on our instructions.
- It is never sold, rented or made available to data brokers.
- It is never used for advertising, profiling or any decision about you.
6. Why we use your data, and on what legal basis
| What we do | Why | Legal basis (LGPD / GDPR) |
|---|---|---|
| Create and maintain your account | So you can sign in and reach your data from any device | Performance of a contract |
| Store your medications and schedules | So the app can remind you and keep your history | Performance of a contract; your consent for health-adjacent data |
| Send local reminders | The core function of the app | Performance of a contract |
| Anonymous analytics | To understand which features are used and fix problems | Legitimate interest |
| Verify your plan through RevenueCat | To unlock premium features you paid for | Performance of a contract |
| Answer support e-mails | To help you | Legitimate interest |
Where local law requires consent for health-adjacent data, you give that consent by choosing to enter your medication information into the app, and you can withdraw it at any time by deleting the data or your account (section 10).
7. Who else processes your data
We use a small number of service providers ("processors"). They may only process your data to provide their service to us:
| Provider | What it does | What it can see |
|---|---|---|
| Amazon Web Services (AWS) | Hosts our backend servers and database | Account and medication data, at rest and in transit |
| Google (Firebase Analytics) | Anonymous product analytics | Anonymous usage events; no advertising ID |
| RevenueCat | Manages purchase receipts and subscription status | An app-specific user identifier and your purchase/entitlement status |
| Apple (App Store) / Google (Google Play) | Process purchases and refunds | Their own billing data, under their own privacy policies |
We do not have any other recipients. We do not transfer your data to advertisers, insurers, employers, pharmaceutical companies or data brokers.
8. Where your data is stored, and international transfers
Our backend runs on AWS infrastructure, in a region located in the United States or Brazil. Our processors (Google, RevenueCat, Apple) may process data in the United States and in other countries where they operate.
This means your personal data may be transferred outside your country of residence, including to countries whose data protection laws differ from your own. When that happens, the transfer is covered by contractual safeguards with the provider — standard contractual clauses or equivalent mechanisms — and the data remains subject to this policy.
9. How long we keep your data
- Account and medication data: for as long as your account exists.
- After you delete your account: deleted from our production systems. Encrypted backups may still contain the data for a short retention window before rotating out.
- Anonymous analytics: retained according to Firebase's default retention settings; these events are not linked to your identity.
10. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you;
- Correct data that is wrong or incomplete;
- Delete your data;
- Export (portability) your data in a machine-readable format;
- Withdraw consent for the processing of your medication data;
- Object to or restrict processing based on legitimate interest;
- Know with whom your data has been shared.
These rights are given by the Brazilian LGPD (Lei 13.709/2018) and, for users in the European Economic Area and the United Kingdom, by the GDPR. Users elsewhere get the same treatment as a matter of policy.
How to exercise them: the fastest route for deletion is in the app — open Settings → Delete account. Your account, your medications and your dose history are permanently deleted; this cannot be undone. For anything else, write to medcontrolsupport@gmail.com and we will reply within 30 days.
You also have the right to complain to your data protection authority — in Brazil, the ANPD; in the EEA/UK, your national supervisory authority.
11. Security
Passwords are stored only as hashes. Traffic between the app and our servers is encrypted in transit (HTTPS/TLS). Access to production systems is restricted to the developer. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the competent authority as required by law.
12. Children
Tomely is not directed at children. You must be at least 16 years old to create an account. If you believe a child has created an account, write to medcontrolsupport@gmail.com and we will delete it.
13. Notifications
Medication reminders are local notifications: your device schedules and displays them. The reminder content stays on your device, and no push token or reminder delivery data is sent to us.
14. Purchases
Tomely offers a monthly subscription, an annual subscription (both with a 7-day free trial) and a one-time premium purchase. All payments are handled by the Apple App Store or Google Play. We receive only your subscription/entitlement status through RevenueCat — never your card number, billing address or store account credentials.
15. Changes to this policy
If we change this policy we will update the date at the top and, for material changes, notify you in the app or by e-mail before the change takes effect.
16. Contact
Data controller: Gabriel Barca, individual developer, Brazil. E-mail: medcontrolsupport@gmail.com