Plainlog privacy policy
Effective 13 September 2026. Applies to the Plainlog app for iOS and Android, to the version of Plainlog that runs in a web browser, and to this website.
The short version
Plainlog is a daily symptom log for people living with a chronic illness. Everything you enter is stored on your device and nowhere else. There is no account, no sign-in, no analytics, no advertising and no server of ours that ever sees what you record. You can export everything as a JSON file, and delete everything, from Settings inside the app.
Buying is the one thing that involves anyone else, and what happens depends on where you bought. The section below called "What leaves your device" says exactly what, for each way of buying. Nothing you type into Plainlog is part of it.
What the app stores, and where
Plainlog keeps the following in a private database on your device:
- the condition names, symptom names, colours and medication names you set up
- one entry per calendar day: symptom severities on a 0 to 10 scale, sleep hours, energy, pain, medications taken as yes or no, and your note
- your settings: reminder time if you set one, the date of first launch (for the 14-day free period), whether you have unlocked, and the demo-data switch
The database and any files are in the app's private storage on your phone or tablet, or in your browser's storage if you use the web version. They are covered by your device's own backup settings (for example an iCloud or Google device backup, if you have one turned on); we have no access to those backups.
What leaves your device
Nothing you record. The app itself makes no network request of ours at any point, and there is no server of ours that holds a copy of anything you typed. Specifically:
- No account. We do not ask for a name, email address, phone number or password.
- No analytics, no crash reporting, no advertising identifiers. No third-party analytics or advertising SDK is included in the app.
- Sharing is yours to start. When you export a monthly PDF report or a JSON backup, your phone's share sheet opens and you choose the destination. The app does not send the file anywhere by itself.
- Buying in the app on a phone or tablet. The one-time unlock is sold through Apple's App Store or Google Play. Apple or Google handles the payment and knows what you bought, under their own privacy policies; we see a sales figure, not a buyer. To check that the purchase went through, the app uses the RevenueCat purchases library, which is given an anonymous, randomly generated app user ID (we never pass it anything of yours to use as an identifier) together with the store receipt, and nothing about the content of your records. Like most purchase libraries it also sees the technical details of the request itself, such as your app version, device model, country and network address. RevenueCat's privacy policy is at revenuecat.com/privacy.
- Buying in the web version. A browser has no app store, so here we sell to you directly and the seller is Kehr & Co. LLC. Pressing the unlock button sends your browser to a small service we run at
pay.kehrandco.com, which opens a Stripe Checkout page. Stripe takes the payment and asks for your email address so it can send a receipt; Stripe holds your name, email, card details and country under its own privacy policy at stripe.com/privacy, and we can see in Stripe's dashboard that a purchase happened, for which app, and the email and country on it. Our own service then writes one small record: a one-way SHA-256 hash of your email address, the Stripe session reference, the unlock reference and the time. Not the address itself, not your name, not your card, and nothing whatsoever from inside the app — the app never contacts that service; your browser walks there, to Stripe, and back. The record exists for two reasons: so we can give you your unlock code again if you lose it, and so a refund can be traced to a sale. Ask us and we will delete it. - Support email. If you write to us, we receive what you send and use it only to help you. Please do not include health details in support email; we do not need them to help.
Permissions the app may ask for
- Notifications: only if you turn on the daily reminder in Settings. The reminder is scheduled on your phone; no server is involved. Off by default.
- Files and sharing: when you export a PDF report or your JSON backup, the phone's share sheet opens and you choose where it goes. Plainlog does not send it anywhere itself.
Each of these is optional and the app keeps working if you decline.
Health information and the FTC Health Breach Notification Rule
Plainlog holds health information you choose to enter. It is not offered to you by a healthcare provider or a health plan and we have no contract with either, so HIPAA does not apply to it — HIPAA covers providers, plans and clearinghouses and the people who handle records on their behalf, not an app you buy for yourself. The rule that does reach apps like this one is the Federal Trade Commission's Health Breach Notification Rule, 16 CFR Part 318, as amended in 2024.
We treat ourselves as covered by that Rule and design around it, rather than argue about whether it reaches an app that transmits nothing. Our design is the safeguard: your records live only on your device, are never sent to us, and we hold no copy, so there is no store of your health information at our end for anyone to breach.
If we ever did come to hold health information about you and it were acquired or disclosed without your authorisation, we would tell you, and the Federal Trade Commission, and where the Rule requires it the media — without unreasonable delay and within 60 calendar days at the outside. One practical consequence of having no accounts is worth saying out loud: we have no email or postal address for you, so we could not write to you individually. We would use the substitute notice the Rule provides for exactly that situation — a clear notice on the front page of this website, kept up for 90 days, and a free phone number staffed for at least as long — and we would put it in the app's release notes as well.
If this page ever stops saying "nothing is transmitted", the reason will be written here before the change ships, not after.
Consumer health data policy
Washington's My Health My Data Act and Nevada's SB 370 require a distinct, plainly labelled statement about consumer health data, and require it whether or not much data is involved. This is that statement, for Plainlog. It is short because the answer is mostly "none".
What we collect and why. Those laws define "collect" very widely — to buy, rent, access, retain, receive, acquire, infer, derive or otherwise process. Measured that way we collect none of what you enter in Plainlog. We never see it. It is written by you, held on your device, and read by nobody but you and whoever you hand it to yourself.
There is one thing we do hold, and only if you bought Plainlog in the web version rather than from an app store: the record described under "What leaves your device" — a one-way hash of the email address you paid with, the Stripe session reference, the unlock reference and the time. It is not a health record and it says nothing about your health. But because Plainlog is a daily symptom log for people living with a chronic illness, the bare fact that a particular person bought it can imply something, so we treat that record as consumer health data rather than split hairs about it. We collect it for two purposes and no others: so we can give you your unlock code again if you lose it, and so a refund can be matched to a sale.
Where it comes from. From you, at the checkout page, and from Stripe, which takes the payment. Nowhere else. We buy no data, and we receive none from any data broker, advertiser, analytics company or other app.
What we share. Nothing. We share no consumer health data with anyone and we have no affiliates to share it with; the developer is a one-person company. We have never sold consumer health data, we do not sell it, and we will not sell it, at any price, to anyone — selling it would need your signed authorisation under those laws and we will not be asking for one.
The categories of company that necessarily see something in the course of taking your money are these, and they are the whole list: payment and store processing (Stripe for a web purchase; Apple, Google and RevenueCat for an in-app purchase), and hosting (Cloudflare, which serves the checkout page and this website). Each handles that under its own privacy policy, none of them is given anything you recorded in the app, and none of them is given this data for their own advertising.
Your rights, and how to use them. Write to hello@kehrandco.com and you can: confirm whether we hold consumer health data about you, and get a copy of it; get the list of all third parties with whom we have shared it, and how to contact each — today that list is empty; withdraw your consent to our collecting or sharing it; and have it deleted, including by anyone we passed it to. We answer within two business days and complete within 30 days at the outside. There is no charge, no account needed, and asking changes nothing about your app or your purchase. If we ever refuse, we will say why in writing, and you can appeal by replying with "appeal" in the subject line for a written decision within 45 days. If we deny the appeal we will give you a link for complaining to the Washington Attorney General, and you can complain to your own state's Attorney General wherever you live.
Your choices and rights
- Export everything. Settings, Export everything, produces one JSON file with every record; it is yours to keep or move to another app.
- Delete everything. Settings, Delete everything, removes every record from the device in two steps, and on a phone or tablet removes the files the app stored too. Uninstalling the app does the same. Because we hold no copy, there is nothing for us to delete on our side; that is also why we cannot recover data you delete. One honest detail: the app clears the records out of its database, and the operating system reuses that space over time, but we cannot promise the bytes are unrecoverable by someone with the unlocked device and forensic tools. If that matters to you, erase the device rather than the app's data.
- Access, correction, portability. All of it is in the app, editable by you, exportable at any time. Nothing you entered is held by us, so there is nothing for us to give you a copy of. If you bought in the web version we hold the purchase record described above, and if you have written to us we hold that email; both are yours to see, correct or have deleted.
- Ask us. One address does everything: hello@kehrandco.com. Tell us what you want — to know what we hold, a copy of it, a correction, or deletion. Someone may ask on your behalf if you say so in writing. We do not charge for any of it and we do not treat anyone differently for asking, and asking never affects what the app does or what you paid.
- If we say no. We will say why, in writing. You can appeal by replying with the word "appeal" in the subject line, and you will get a written decision from us within 45 days. If you are still not satisfied you can complain to your state Attorney General, or, in the European Union or the United Kingdom, to your data protection authority.
Tracking, and Do Not Track
California's Online Privacy Protection Act asks every commercial site to answer two questions plainly, whatever its size, so here they are.
- How do we respond to a Do Not Track signal? We do not track you across websites or over time in the first place, so there is nothing for the signal to switch off. The app has no analytics and no advertising code, this website loads no script at all, and neither sets a cookie for tracking. We therefore do not act on Do Not Track signals, because there is nothing to stop. If that ever changes, this paragraph changes first.
- Do third parties collect personal information about you across sites through us? No. No third party is given a way to observe you here — there is no advertising network, no analytics provider, no social widget and no embedded tracker anywhere in the app or on this site.
How long things are kept
- What you record: for as long as you keep it. Nothing expires, nothing is deleted on a schedule, nothing is removed when a free period ends and nothing is removed if a purchase is refunded. Deleting is always your decision.
- Support email: kept while we are helping you and for up to twelve months after, so a follow-up makes sense, then deleted. Ask sooner and we will delete it sooner.
- A web purchase record (the email hash, the two references and the time): kept for up to seven years, because a business has to be able to evidence its own sales. Ask us to delete it and we will, and after that we can no longer hand your unlock code back to you.
- Stripe, Apple, Google and RevenueCat keep their own records under their own policies and their own legal duties. We cannot delete those for you; their policies say how to ask them.
Price, stated plainly
Plainlog is free to use for 14 days from first launch. After that, adding new entries needs a one-time purchase of $14.99. Viewing, editing, deleting, trends and PDF export of what you have already logged never lock, whether or not you buy.
Changes to this policy
If the app ever changes what it stores or where, this page will change first, the effective date at the top will move, and the in-app privacy screen will say what changed. We will not start collecting data quietly.
Contact
hello@kehrandco.com. Support answers within two business days.
Plainlog is made and sold by Kehr & Co. LLC, a Georgia limited liability company. More about us at https://kehrandco.com.