Privacy Policy

Last updated: 11 August 2026

Plainlog is a medication and weight log that runs entirely on your phone. This page explains, in full, what that means for your data. Every sentence here is meant to be checkable, not just reassuring.

The short version

There is no account. There is no server. Plainlog does not run analytics, does not use a crash reporter that sends your health data anywhere, and does not show advertising. Everything you log — doses, weights, notes — is stored in a single database file on this device. That file does not leave the device unless you export it or back it up yourself, and send it somewhere yourself.

We are not being careful with your data. We simply do not have it.

What Plainlog stores, and where

Doses, medications, weights, notes, and the timestamps attached to them are stored in a local database inside the app’s own storage on your device. Nothing is transmitted anywhere as part of normal use — opening the app, logging a dose, viewing your history or your estimated-level chart, and setting a reminder all happen entirely on-device.

Apple Health

If you choose to connect Apple Health, Plainlog reads and writes weight data through Apple’s HealthKit framework, on your device, under permissions you grant and can revoke at any time in iOS Settings. Plainlog does not use Health data for advertising, marketing, or any purpose other than showing it back to you inside the app, and does not sell or share Health data with any third party. Weight entries imported from Apple Health are excluded from Plainlog’s own backup files — see “Backups,” below, for why that distinction exists and what it means for restoring your data.

Export

You can export your log as a CSV file or a PDF, for your own use or to bring to an appointment. An export leaves the app only when you choose to share, save, or send it through your device’s own share sheet — the same mechanism any app uses to save a file to Files, AirDrop it, or attach it to an email. Plainlog has no part in where that file goes after you choose a destination.

Backups

Plainlog can write an encrypted or plaintext backup file of your log, which you save wherever you choose — iCloud Drive, Google Drive, Dropbox, a USB drive, or anywhere else your device can save a file to. Plainlog has no cloud service of its own and does not upload this file anywhere.

When you protect a backup with a passphrase, we could not read that file even if you handed it to us: the passphrase never leaves your device, and we have no server to send it to. There is no account recovery and no way for anyone to reset a lost passphrase, because we never hold it. You can also save a backup without a passphrase — the file is then readable by anything that opens it, and its name says UNENCRYPTED so you always know which kind you have. That option exists because a forgotten passphrase makes the only copy of your history permanently unreadable, and it’s your call which risk you’d rather carry. Weight entries imported from Apple Health are excluded from backup files, either way. Restore reverses this process, reading a backup file you select back into the app.

Your device’s own backup

This is the one nuance in “nothing leaves the device,” and we want it stated plainly rather than left for you to discover. Plainlog’s own database file lives in the app’s normal storage area, which means it is included automatically in iCloud Backup on iOS or Android Auto Backup on Android — the same system backup that preserves your other apps’ data — if you have that feature turned on in your device settings. This is your operating system backing up your device, not Plainlog uploading anything; Plainlog makes no network connection to do this and has no way to turn it off from inside the app. If you do not want your log included in your device’s own backup, your device’s settings — not Plainlog’s — control that.

Subscription

Plainlog is a paid app with a free trial. Payment is handled entirely by Apple or Google, through their standard subscription systems — Plainlog never sees your card details. To check whether your subscription is active, Plainlog uses RevenueCat, a subscription-management service. RevenueCat sees that a subscription exists and its status; it does not see your doses, weights, notes, or any other health information — that data stays on your device and is never sent to RevenueCat or to us. This is the only network connection Plainlog’s normal operation makes.

What we don’t do

Deleting your data

Deleting an entry inside the app is permanent — there is no undo and no recovery, by design. Deleting the app deletes the database with it, unless a device backup (see above) or a Plainlog backup file you made still exists somewhere. If you want a copy before deleting the app, export or back up first.

Children

Plainlog is not directed at children and is not intended for use by anyone under 17. We don’t knowingly collect information from children, and since the app collects nothing from anyone regardless of age, there is no children’s data on our end to be concerned about.

Changes to this policy

If this policy changes, the “last updated” date above will change with it. Because Plainlog has no way to contact you directly, check this page periodically if you want to stay current.

Contact

Questions about this policy or your data: support@plainlog.app