Pillfolk

Pillfolk privacy policy

Effective 13 September 2026. Applies to the Pillfolk app for iOS and Android, to the version of Pillfolk that runs in a web browser, and to this website.

The short version

Pillfolk is a household medication list, schedule and dose log (the web version sends no reminders). Everything you enter is stored on your device and nowhere else. There is no account, no sign-in, no analytics, no advertising and no server of ours that ever sees what you record. You can export everything as a JSON file, and delete everything, from Settings inside the app.

Buying is the one thing that involves anyone else, and what happens depends on where you bought. The section below called "What leaves your device" says exactly what, for each way of buying. Nothing you type into Pillfolk is part of it.

What the app stores, and where

Pillfolk keeps the following in a private database on your device:

The database and any files are in the app's private storage on your phone or tablet, or in your browser's storage if you use the web version. They are covered by your device's own backup settings (for example an iCloud or Google device backup, if you have one turned on); we have no access to those backups.

What leaves your device

Nothing you record. The app itself makes no network request of ours at any point, and there is no server of ours that holds a copy of anything you typed. Specifically:

Permissions the app may ask for

Each of these is optional and the app keeps working if you decline.

Health information and the FTC Health Breach Notification Rule

Pillfolk holds health information you choose to enter. It is not offered to you by a healthcare provider or a health plan and we have no contract with either, so HIPAA does not apply to it — HIPAA covers providers, plans and clearinghouses and the people who handle records on their behalf, not an app you buy for yourself. The rule that does reach apps like this one is the Federal Trade Commission's Health Breach Notification Rule, 16 CFR Part 318, as amended in 2024.

We treat ourselves as covered by that Rule and design around it, rather than argue about whether it reaches an app that transmits nothing. Our design is the safeguard: your records live only on your device, are never sent to us, and we hold no copy, so there is no store of your health information at our end for anyone to breach.

If we ever did come to hold health information about you and it were acquired or disclosed without your authorisation, we would tell you, and the Federal Trade Commission, and where the Rule requires it the media — without unreasonable delay and within 60 calendar days at the outside. One practical consequence of having no accounts is worth saying out loud: we have no email or postal address for you, so we could not write to you individually. We would use the substitute notice the Rule provides for exactly that situation — a clear notice on the front page of this website, kept up for 90 days, and a free phone number staffed for at least as long — and we would put it in the app's release notes as well.

If this page ever stops saying "nothing is transmitted", the reason will be written here before the change ships, not after.

Consumer health data policy

Washington's My Health My Data Act and Nevada's SB 370 require a distinct, plainly labelled statement about consumer health data, and require it whether or not much data is involved. This is that statement, for Pillfolk. It is short because the answer is mostly "none".

What we collect and why. Those laws define "collect" very widely — to buy, rent, access, retain, receive, acquire, infer, derive or otherwise process. Measured that way we collect none of what you enter in Pillfolk. We never see it. It is written by you, held on your device, and read by nobody but you and whoever you hand it to yourself.

There is one thing we do hold, and only if you bought Pillfolk in the web version rather than from an app store: the record described under "What leaves your device" — a one-way hash of the email address you paid with, the Stripe session reference, the unlock reference and the time. It is not a health record and it says nothing about your health. But because Pillfolk is a household medication list, schedule and dose log (the web version sends no reminders), the bare fact that a particular person bought it can imply something, so we treat that record as consumer health data rather than split hairs about it. We collect it for two purposes and no others: so we can give you your unlock code again if you lose it, and so a refund can be matched to a sale.

Where it comes from. From you, at the checkout page, and from Stripe, which takes the payment. Nowhere else. We buy no data, and we receive none from any data broker, advertiser, analytics company or other app.

What we share. Nothing. We share no consumer health data with anyone and we have no affiliates to share it with; the developer is a one-person company. We have never sold consumer health data, we do not sell it, and we will not sell it, at any price, to anyone — selling it would need your signed authorisation under those laws and we will not be asking for one.

The categories of company that necessarily see something in the course of taking your money are these, and they are the whole list: payment and store processing (Stripe for a web purchase; Apple, Google and RevenueCat for an in-app purchase), and hosting (Cloudflare, which serves the checkout page and this website). Each handles that under its own privacy policy, none of them is given anything you recorded in the app, and none of them is given this data for their own advertising.

Your rights, and how to use them. Write to hello@kehrandco.com and you can: confirm whether we hold consumer health data about you, and get a copy of it; get the list of all third parties with whom we have shared it, and how to contact each — today that list is empty; withdraw your consent to our collecting or sharing it; and have it deleted, including by anyone we passed it to. We answer within two business days and complete within 30 days at the outside. There is no charge, no account needed, and asking changes nothing about your app or your purchase. If we ever refuse, we will say why in writing, and you can appeal by replying with "appeal" in the subject line for a written decision within 45 days. If we deny the appeal we will give you a link for complaining to the Washington Attorney General, and you can complain to your own state's Attorney General wherever you live.

Children

Pillfolk is for adults. A parent may enter a child's medication as data the parent manages; the child is never a user, the app never asks for a child's birthdate (only an optional age band), and nothing is collected online from anyone. We do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information, write to hello@kehrandco.com and we will delete it.

Your choices and rights

Tracking, and Do Not Track

California's Online Privacy Protection Act asks every commercial site to answer two questions plainly, whatever its size, so here they are.

How long things are kept

Price, stated plainly

Pillfolk is free for one person with unlimited medications, every schedule type, the dose log, history and the printable medication list. Adding a second person needs a one-time purchase of $14.99, which unlocks unlimited people. Nothing already entered is ever hidden, locked or deleted, including if a purchase is refunded.

Changes to this policy

If the app ever changes what it stores or where, this page will change first, the effective date at the top will move, and the in-app privacy screen will say what changed. We will not start collecting data quietly.

Contact

hello@kehrandco.com. Support answers within two business days.

Pillfolk is made and sold by Kehr & Co. LLC, a Georgia limited liability company. More about us at https://kehrandco.com.