Privacy Policy
1. Data Storage
All health data you enter into PrEPPED+ — including but not limited to PrEP dose logs, encounter records, STI test results, partner information, Doxy PEP logs, vaccines, and related notes are stored locally on your device using Apple's Core Data framework. It is not uploaded to any cloud service and we have no ability to access it.
2. Data We Do Not Collect
We do not collect:
- Names, email addresses, or account credentials — PrEPPED+ has no accounts
- Health data — PrEP logs, encounters, test results, partner information, or symptom records
- Partner phone numbers — numbers entered for anonymous partner notifications are sent directly to a third-party SMS service and are not stored on our servers or retained after delivery (see Section 3)
- Persistent location data — your location is used only to determine your zip code to find nearby clinics and is not stored (see Section 3)
Anonymous crash diagnostics and analytics are collected as described in Section 3. These contain no health data or personal information.
3. Third-Party Services
PrEPPED+ uses the following third-party services:
RevenueCat — acts as a data processor to manage in-app subscriptions on our behalf. RevenueCat processes an anonymous app user ID and purchase transaction data from Apple solely to manage your subscription state. It does not receive any health data and does not use this data for its own purposes. See RevenueCat's Privacy Policy.
CDC NPIN API — powers the clinic finder feature. When you use the clinic finder, your zip code determined by your current location is sent to the US Centers for Disease Control and Prevention's National Prevention Information Network to retrieve nearby PrEP providers. No personal information, health data, or identifiers are included in this request. See CDC's Privacy Policy.
Sentry — used for anonymous crash reporting to identify and fix technical issues. Sentry receives device model, iOS version, app version, and crash stack traces when the app crashes. No health data, personal information, partner names, or any user-generated content is included in crash reports. See Sentry's Privacy Policy.
TelemetryDeck — used for anonymous usage analytics to improve the user experience. TelemetryDeck uses a privacy-first architecture that hashes all user identifiers on-device before transmission using a daily rotating salt. This means neither TelemetryDeck nor PrEPPED+ can identify individual users from analytics data. TelemetryDeck does not collect personally identifiable information and their data collection does not fall under GDPR or similar privacy laws by design. See TelemetryDeck's Privacy Policy.
Textbelt — powers the anonymous partner notification feature. When you choose to notify a partner, the phone number you enter is sent to Textbelt solely to deliver a single anonymous SMS. PrEPPED+ does not store the phone number on any server, does not include your name or identity in the message, and does not transmit any health data. The phone number is sent directly from your device to Textbelt for delivery and is not retained by us. See Textbelt's website.
Apple App Store — handles payment processing for subscriptions. Apple's standard terms and privacy policy apply.
4. Location Data
PrEPPED+ requests access your location only to determine your city and/or zip code when you use the clinic finder or local outbreak alert feature. Your zip code is used solely to find PrEP providers and health alerts near you and is sent to the CDC NPIN API and our backend API for this purpose. It is not stored on our servers, not linked to your identity, and not used for any other purpose. You can use all other features of PrEPPED+ without granting location access.
5. Notifications
If you enable reminders — PrEP dose reminders, Doxy PEP reminders, or testing reminders — these are scheduled locally on your device using Apple's notification system. Notification content is generated on-device and is not sent through our servers. If you enable Discreet Notifications in settings, reminder text is replaced with generic language that does not reference health content.
6. Anonymous Partner Notifications
PrEPPED+ includes a feature that allows you to send an anonymous SMS notification to a partner — for example, to suggest they get tested. When you use this feature:
- The phone number you enter is sent directly from your device to Textbelt, a third-party SMS delivery service, to send a single anonymous message
- The message does not include your name, identity, or any information that could identify you
- No health data about you or your partner is included in the message
- The phone number is not stored on our servers and is not retained by PrEPPED+ after delivery
- We have no record of who you notified or when
This feature is entirely optional and initiated only by your explicit action.
7. Apple Watch and Widgets
If you use the PrEPPED+ Apple Watch app or home screen widgets, data is transferred between your iPhone and Apple Watch using Apple's WatchConnectivity framework. This communication happens directly between your paired devices and does not pass through any external server.
8. Data Deletion
You can delete all data at any time from Settings → Delete All Data within the app. This permanently removes all encounters, test results, medication logs, partner information, and preferences from your device. Because we do not store your data remotely, deletion is immediate and irreversible.
Uninstalling the app permanently removes all stored data from your device. Because we do not store your data remotely, this cannot be recovered. We recommend using the Delete All Data option in settings before uninstalling if you want to confirm all data is removed.
9. Biometric Security
PrEPPED+ supports biometric (Face ID, Touch ID) to lock the app. Biometric data is handled entirely by Apple's LocalAuthentication framework. We never access, store, or transmit biometric data.
10. Children
PrEPPED+ is a sexual health app rated 18+ on the App Store. It is designed for adults on PrEP or considering PrEP.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the app after changes constitutes acceptance of the updated policy. We will not make changes that materially reduce your privacy protections without prominent notice.
12. Contact
If you have questions about this privacy policy or how PrEPPED+ handles your data, contact us at privacy@getpreppedapp.com.