Privacy
Last updated 5 September 2026
Tilly keeps a health journal for you. Health data is the most protected kind there is, and this page treats it that way: what we keep, why we are allowed to, where it goes, how long it stays, and how you take it back. It is written to be read.
Who is responsible
The controller of your data is [Legal entity name], [registration number], [registered address], Romania (“we”, “us”, “Tilly”). Write to hello@tilly.day for anything on this page. We are small enough that a person reads every message.
What Tilly keeps, and why
Everything below is kept for one reason: to run the journal you asked for. We do not build profiles for advertising, we do not sell data, and we show no ads.
- Your account. The email address, and the Apple ID or Google account if you sign in with one, plus a sign-in identifier. Sign-in is handled by Clerk; we never see a password. Why: to run your account and keep your journal across phones (contract, GDPR art. 6(1)(b)).
- Your journal. Your medication, dose schedule and shots; weigh-ins and measurements; meals, their photos and the figures estimated for them; feelings, symptoms and side effects; water; progress photos; notes for your doctor; your targets and reminders. Why: this is the service itself, and because it is health data we ask for your explicit consent to it in the app before anything is stored (GDPR art. 9(2)(a) together with art. 6(1)(a)). You can withdraw that consent at any time by deleting your account.
- From Apple Health, only when you switch it on. Weigh-ins and waist measurements, and daily totals of steps, active calories and sleep. Each stream has its own switch under You → Connected apps; Tilly reads only what you switched on, and every read shows in the app as a line you can open. With a separate permission it can write weigh-ins, meals and water back to Health. Why: your explicit consent, given stream by stream (art. 9(2)(a)). Apple Health data is used only to show you your own days and answer your own questions, never for advertising, never sold, never shared with anyone for their own purposes.
- Conversations with Tilly. Your questions, the parts of your journal Tilly read to answer, and the answers, so you can come back to them. Why: part of the service, under the same consent as the journal.
- Subscription state. Whether Premium is active, since when, until when, and an anonymous purchase identifier from RevenueCat. We never see your card or your Apple ID balance. Why: contract (art. 6(1)(b)).
- Usage counts. How many photos and questions you used this day or week, to apply the free limits. Why: contract. Kept a month.
- Usage analytics. A small set of events, such as “a meal was logged” or “the paywall was shown”, tied to a random identifier, with which form of medication you use (weekly or daily), your plan and your language. No meal text, photos, weights or figures are attached. Session recording is off. Why: our legitimate interest in seeing which parts of the app work and which do not (art. 6(1)(f)); we judged this the least intrusive way to do it, and you can object below.
- Support email. What you write to us and our answers, kept so we can follow up. Why: legitimate interest in answering you (art. 6(1)(f)).
Tilly asks for no data it does not need. There is no advertising identifier, no contact list, no location.
Where it goes
We use a handful of providers to run Tilly. Each processes data only on our instructions, under a data processing agreement, and only for the purpose named here.
- Convex (hosting and database, United States) holds your journal, photos and conversations on our behalf.
- Clerk (sign-in, United States) holds your account and sign-in identifiers.
- Language models through OpenRouter (United States). When Tilly reads a meal line, reads a photo of a plate, or answers a question, the text or photo and only the parts of your journal needed for that answer are sent to a language model. Requests are made under terms that do not allow the provider to keep them or train on them. Tilly always shows you what it read. Your name and email are never sent.
- Food databases (USDA FoodData Central, and a web search through Exa, United States). To put figures on a food, Tilly may look the item up. Only the food name goes, never anything about you.
- Apple and RevenueCat (subscriptions). Apple handles the purchase under its own terms; RevenueCat tells us whether it is active.
- PostHog (analytics, hosted in the European Union) receives the usage events described above.
- Apple (notifications). Reminders are scheduled on your phone; nothing is sent to us or to Apple to ring one.
Transfers outside the EU. Some of these providers process data in the United States. Where a provider is certified under the EU–US Data Privacy Framework we rely on that; otherwise we rely on the European Commission's standard contractual clauses, with the additional measures they require. You can ask us for a copy of the safeguards in place for any provider.
We disclose personal data to no one else, unless the law obliges us to, or it is needed to establish or defend a legal claim, or to protect someone's life. If Tilly is ever sold or merged, your data goes with it under this same policy, and you are told before it happens.
How long it stays
- Your journal, photos and conversations: for as long as you have an account. Delete a line, a photo or a conversation and it is gone from our servers at once. Photos uploaded but never attached to a meal are swept nightly.
- Your account: until you delete it. Deleting it from You → Account wipes your journal, photos, conversations, permissions and usage rows from our servers within seconds; we then delete your sign-in record at Clerk and your purchase identifier at RevenueCat within 30 days. Backups taken by our hosting provider are overwritten within 30 days. There is no undo, which is why the app asks twice.
- Usage counts: a month.
- Analytics events: 12 months, then deleted.
- Support email: two years after the last message, then deleted.
- Purchase records that tax law makes us keep: the period Romanian law requires, without your journal attached.
We may delete an account nobody has opened for two years, after warning you by email a month ahead.
Your rights
Under the GDPR you can, at any time and for free:
- See and take your data. You → Account → Export gives you your whole journal as a file, immediately, in a form you can carry elsewhere (access and portability, art. 15 and 20).
- Correct it. Every line in the journal can be edited. Tell us if something you cannot reach is wrong (art. 16).
- Delete it. You → Account → Delete account, immediately, no questions (art. 17). Or write to us.
- Withdraw consent. Switch off any Apple Health stream under Connected apps; delete the account to withdraw consent to the journal altogether. Withdrawal does not affect what was lawfully done before.
- Object to analytics, or ask us to restrict processing while a question is settled (art. 18 and 21). Write to us; analytics stop for your account.
- Not be subject to automated decisions. Tilly makes none. Its estimates and answers are information shown to you; nothing is decided about you by a machine.
- Complain. We would rather hear from you first, but you can always go to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Bucharest, dataprotection.ro, or to the authority of the EU country you live in.
For a request by email we may ask you to confirm it from the address on the account, so nobody else can get your journal. We answer within a month.
How it is protected
Data travels encrypted (TLS) and is stored encrypted at rest by our providers. Only you can reach your journal; every read and write on the server checks that the signed-in account owns the row. We keep no copy of your data on laptops. Access to production is limited to the people who run Tilly, and there is one of them. If a breach ever affects your data, we tell the authority within 72 hours and tell you without undue delay, as the law requires.
Children
Tilly is for adults on a GLP-1 medication under a prescriber's care. It is not for anyone under 18, and we do not knowingly keep a child's data. If you believe a child has an account, write to us and it is deleted.
This website
tilly.day sets no cookies and runs no analytics. The typeface is loaded from Google Fonts, so Google sees the request for the font file, including your IP address; nothing else about your visit leaves your browser.
Changes
When this page changes in a way that matters, the app tells you, once, before the change applies, and asks again for consent where the law requires it. Small edits for clarity are just made, and the date at the top moves.
Contact
Write to hello@tilly.day, or by post to the address above. A person reads it.