Tilly

Privacy

Last updated 5 September 2026

Tilly keeps a health journal for you. Health data is the most protected kind there is, and this page treats it that way: what we keep, why we are allowed to, where it goes, how long it stays, and how you take it back. It is written to be read.

Who is responsible

The controller of your data is [Legal entity name], [registration number], [registered address], Romania (“we”, “us”, “Tilly”). Write to hello@tilly.day for anything on this page. We are small enough that a person reads every message.

What Tilly keeps, and why

Everything below is kept for one reason: to run the journal you asked for. We do not build profiles for advertising, we do not sell data, and we show no ads.

Tilly asks for no data it does not need. There is no advertising identifier, no contact list, no location.

Where it goes

We use a handful of providers to run Tilly. Each processes data only on our instructions, under a data processing agreement, and only for the purpose named here.

Transfers outside the EU. Some of these providers process data in the United States. Where a provider is certified under the EU–US Data Privacy Framework we rely on that; otherwise we rely on the European Commission's standard contractual clauses, with the additional measures they require. You can ask us for a copy of the safeguards in place for any provider.

We disclose personal data to no one else, unless the law obliges us to, or it is needed to establish or defend a legal claim, or to protect someone's life. If Tilly is ever sold or merged, your data goes with it under this same policy, and you are told before it happens.

How long it stays

We may delete an account nobody has opened for two years, after warning you by email a month ahead.

Your rights

Under the GDPR you can, at any time and for free:

For a request by email we may ask you to confirm it from the address on the account, so nobody else can get your journal. We answer within a month.

How it is protected

Data travels encrypted (TLS) and is stored encrypted at rest by our providers. Only you can reach your journal; every read and write on the server checks that the signed-in account owns the row. We keep no copy of your data on laptops. Access to production is limited to the people who run Tilly, and there is one of them. If a breach ever affects your data, we tell the authority within 72 hours and tell you without undue delay, as the law requires.

Children

Tilly is for adults on a GLP-1 medication under a prescriber's care. It is not for anyone under 18, and we do not knowingly keep a child's data. If you believe a child has an account, write to us and it is deleted.

This website

tilly.day sets no cookies and runs no analytics. The typeface is loaded from Google Fonts, so Google sees the request for the font file, including your IP address; nothing else about your visit leaves your browser.

Changes

When this page changes in a way that matters, the app tells you, once, before the change applies, and asks again for consent where the law requires it. Small edits for clarity are just made, and the date at the top moves.

Contact

Write to hello@tilly.day, or by post to the address above. A person reads it.