Privacy Policy
Last updated: 15 September 2026
Medly Care is an app for recording medication doses, temperatures and notes for a sick child. Doing so creates health data, a child's health data. This policy explains what happens to it.
The short version: no advertising, no tracking, no analytics, no sale or sharing of your data with third parties for their own purposes. The app loads no external fonts or scripts. Only what is needed to run the service is processed.
1. Controller
Arina Coviello
c/o Las Burg 29173
Hauptstrasse 396
79576 Weil am Rhein
Germany
Phone: +41 32 511 78 44
Privacy enquiries: privacy@medlykids.com
General contact: support@medlykids.com
No data protection officer has been appointed; the legal thresholds for doing so are not met.
2. What data is processed
Account
- Email address, which is your login
- Password, stored only as a cryptographic hash
- Display name, optional; it appears on every entry so that within a household it stays clear who recorded what
- Language and time format preference
- The time you gave consent to this policy
Details about the child
- Name or nickname
- Date of birth, optional
- Weight, optional
- Allergies, optional
Entries: this is health data
- Medication doses: product, amount, unit, time, and the minimum interval and daily maximum you configured
- Temperature readings with the time taken
- Free-text notes
- For each entry, who created it and who last changed it
Household
- Household membership and role
- For an invitation: the invited person's email address, plus an invitation token stored only as a hash
Purchasing the full version
- Apple's transaction identifier and Apple's response confirming the purchase
Payment details never reach us. The purchase is handled entirely by Apple; we only learn that it happened.
When you visit this website
The web server records standard access data: IP address, time, page requested, amount of data transferred, browser identification. This serves the operation and security of the site, on the basis of Art. 6(1)(f) GDPR. The site sets no cookies and loads nothing from third-party servers.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Running your account and signing you in | Email, password hash, name | Art. 6(1)(b) GDPR, performance of the contract |
| Storing and displaying entries | Child details, health data | Art. 6(1)(b) together with Art. 9(2)(a) GDPR, your explicit consent |
| Shared access within a household | Memberships, invitations | Art. 6(1)(b) GDPR |
| Verifying a purchase and unlocking the full version | Transaction identifier | Art. 6(1)(b) GDPR |
| Operating and securing the systems | Access data | Art. 6(1)(f) GDPR, legitimate interest |
About consent for health data
Medication doses, temperatures and notes about a child are health data under Art. 9 GDPR. They are processed solely on the basis of your explicit consent, which the app obtains before first use. You give that consent as the person with parental responsibility, on the child's behalf as well.
You may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it. In practice you withdraw it by deleting your account in the app under Profile → Privacy & Data, or by writing to privacy@medlykids.com.
4. Who else processes the data
We use service providers who act solely on our instructions. Data processing agreements under Art. 28 GDPR are in place with each of them.
| Service | Purpose | Place of processing |
|---|---|---|
| Supabase | Database, authentication, server-side functions | European Union |
| GitLab Inc. | Serving this website | United States |
| Hostpoint AG | Domain and DNS administration | Switzerland, covered by an EU adequacy decision |
| Apple | App distribution, purchase handling and verification | Ireland and the United States |
Transfers to the United States occur in connection with Apple and GitLab. They rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, or on standard contractual clauses under Art. 46(2)(c) GDPR. For the purchase itself Apple acts as its own controller, and Apple's own privacy policy applies.
In GitLab's case this concerns only visits to this website. It does not affect the data held by the app. That stays with Supabase in the European Union.
Beyond this we disclose data only where we are legally required to. It is never sold or used for advertising.
5. Who sees what within a household
If you invite another person into your household, they can see every child and every entry in it, including entries made before the invitation. Each entry carries the name of the person who made it. An invitation takes effect only once the invited person explicitly accepts it, and it expires after 14 days.
6. Retention
- Account and health data: for as long as the account exists. Delete the account and they are deleted.
- Entries: a deleted entry is first only marked as deleted, so that a household can still follow what changed, and is removed for good with the account at the latest.
- Purchase records: as long as needed for the unlock and for statutory retention periods.
- Web server access data: a few days.
7. Your rights
Under the GDPR you have the right to
- access the data held about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent you have given (Art. 7(3))
Two of these you can exercise directly in the app, without writing to us. Under Profile → Privacy & Data you can export your data in machine-readable form and delete your account along with every entry belonging to it.
For anything else, a message to privacy@medlykids.com is enough.
8. Complaint to a supervisory authority
You may lodge a complaint with a data protection supervisory authority at any time, in particular in the Member State where you live. The authority responsible for us is
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg
Lautenschlagerstrasse 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
9. Security
- All transfers use TLS; stored data is encrypted at rest.
- Access is enforced in the database itself: every query checks, row by row, whether the requesting account belongs to the household. A bug in the app cannot bypass that check.
- Passwords exist only as hashes and are not readable by us.
10. No automated decision-making
There is no automated decision-making in individual cases and no profiling within the meaning of Art. 22 GDPR. The app calculates using the values you configured yourself and points out when a dose contradicts them. It decides nothing. Medly Care records information and is not a substitute for professional medical advice, diagnosis or treatment.
11. Changes to this policy
If the processing changes, we will update this policy. The version published here, bearing the date above, is the one that applies.