§ 01The short version
Nothing leaves your phone. dialysisPal is a fully offline app. It has no server, no account, no analytics, no tracking, no advertising, no third-party SDKs that phone home. Your data can optionally sync via Apple's iCloud (end-to-end, between you and Apple) or connect to Apple HealthKit (on-device only), but neither passes through us. We have no servers to send it to.
If that is enough for you, you can stop reading. The rest of this page is the long, careful version, written so a regulator (or a curious user) can verify the claim above against the actual app behaviour.
§ 02Who is responsible
The "data controller" (the legal term for whoever decides what happens with your data) is:
- Operator
- Alexander Kucera
- Address
- See Impressum for the full registered address required by §5 TMG.
- Contact
- a.kucera@babylondreams.de
I am a single person operating dialysisPal as an independent developer. There is no company, no team, no investors, no parent organisation.
§ 03What dialysisPal collects
The honest answer: nothing on our side. The app stores your entries (UF volumes, dwell times, weight, blood pressure, notes) locally in an on-device database. None of it is transmitted to me, my server (which doesn't exist), or any third party.
The data the app processes on your device, locally, includes:
- Peritoneal dialysis bag entries (volume, dextrose concentration, dwell time, drain volume)
- Vital signs you choose to log (weight, blood pressure, heart rate, temperature)
- Free-text notes you write
- Your reminder schedule and app preferences
This data never leaves the iPhone or iPad it was entered on, except via mechanisms you control: see iCloud sync below.
§ 04iCloud sync (optional)
If you have iCloud enabled at the iOS level, your dialysisPal database may be backed up to your private iCloud space, the same way Notes and Reminders are backed up. This is handled entirely by Apple's CloudKit infrastructure. The backup is encrypted in transit and at rest. I have no access to it. Apple's terms govern that data: apple.com/legal/privacy.
You can disable iCloud sync for dialysisPal at any time in iOS Settings → Apple ID → iCloud → Apps using iCloud.
§ 05Analytics, ads, tracking
None.
That is not a marketing line; it is a technical fact. The app contains no analytics SDK (no Firebase, no Amplitude, no Mixpanel, no Sentry), no advertising network (no AdMob, no Meta SDK, no AppLovin), no attribution tracker, no IDFA access, no third-party crash reporter. App Store Connect provides aggregate, anonymised crash and download statistics to me as the developer; that is Apple's standard and is not customisable.
§ 06Health data and HealthKit
dialysisPal can optionally read or write to Apple HealthKit if you enable it. Examples: pulling weight from your scale, writing logged blood pressure to Health. This integration is sandboxed by iOS: the OS, not the app, controls which data types you grant. You can review and revoke permissions in iOS Settings → Privacy & Security → Health → dialysisPal.
Data exchanged with HealthKit stays on-device. It is never sent to me.
§ 07Your rights under GDPR
Because dialysisPal does not collect personal data on a server, most GDPR rights (access, deletion, portability) are exercised by interacting with your own device:
- Access. Open the app. Everything is there.
- Deletion. Delete an entry, or delete the app, or both. Local-only data is gone.
- Portability. Use the in-app CSV/JSON export to take your data with you.
For questions about GDPR specifically (including the legal bases I rely on for the limited processing that does occur, such as App Store delivery and support email): see the dedicated GDPR notice.
§ 08Children
dialysisPal is not directed to children under 13 (or under 16 in the EU). It is a clinical tracking tool intended for adult patients or caregivers managing peritoneal dialysis. The app is rated 17+ on the App Store as a precaution.
§ 09Changes to this policy
If this policy changes (for instance, if I one day add an opt-in cloud feature), I will update the "Last updated" date and describe the change in the changelog. You will see the change before any new processing begins, and any genuinely new processing will be opt-in.
§ 10Contact
Privacy questions: a.kucera@babylondreams.de. I read every email myself.