TideTracker
Privacy Policy
TideTracker keeps everything on your iPhone. There is no account, no server, no analytics and no tracking, and nothing is sent anywhere in the background. This page explains exactly what the app records, where it lives, and what that means for you.
Last updated: 28 July 2026
1. The short version
- Everything you record stays on your iPhone. Nothing is sent anywhere automatically or in the background. The only things that ever leave are ones you send yourself: a file you export, or a bug report or email you choose to write us — and a bug report shows you its entire contents before it sends, and never includes compound names, doses, measurements, photos or notes. See section 9.
- There is no account. No email address, no password, no sign-in.
- No analytics, no crash reporting, no advertising, no tracking. The app contains no third-party SDK of any kind.
- We have no server. There is nowhere for us to keep your data even if we wanted to.
- We cannot see your data — and we cannot recover it. That is the honest cost of the design: if you lose your phone and have no backup, the records are gone.
The rest of this page is the detail behind those five points. If anything here ever stops matching the app, the app is wrong and we will fix it.
2. Who is responsible
TideTracker is published by Viking Media & Software, an independent studio that builds and publishes its own software, and we are the data controller for the app. Contact us at [email protected]. If you need postal details for a formal request, ask and we will provide them.
We are the data controller in the sense that we publish the app. In practice, because the app sends us nothing, the only personal data we ever hold is what you choose to email us — see section 9.
3. This is health data
Peptide logs, injection sites, body measurements and progress photos are data concerning health. Under the UK and EU GDPR that is "special category" data under Article 9, and it deserves more care than an ordinary app record. We are saying so plainly rather than leaving you to work it out.
The protection we offer is structural rather than promissory: the data never leaves your device, so there is no copy of it on a server of ours to be breached, subpoenaed, sold or repurposed later.
4. What the app records
Everything below is entered by you, or imported at your request, and all of it stays on your device.
- Compounds — name, aliases, default mass, default beyond-use days, colour, notes.
- Vials — compound, lot number, vendor, mass, quantity, state, acquisition date, cost, storage location, notes, manufacturer expiry, an optional certificate-of-analysis file, and for blends the individual components and their masses.
- Reconstitutions — diluent volume, remaining volume, date performed, beyond-use date.
- Protocols — name, start date, cycle structure, active flag, notes, and per item the compound, schedule rule, titration ladder, times of day and site-rotation group.
- Logged doses — scheduled and taken times, dose in micrograms, draw volume in microlitres, injection site, status (taken, skipped or scheduled), a free-text note and any side effects you record.
- Measurements — body mass, body fat percentage, lean mass, waist, resting heart rate, HRV, sleep or a custom measure, with value, date, source and note.
- Progress photos — see section 6. Tracks carry a name, subject, linked compound or protocol, cadence, reminder time and notes; each photo carries its capture date and hour, a lighting note, an anchor flag and pixel dimensions.
- Supplies — syringes, swabs and similar: kind, spec, quantity and low-stock threshold.
- Settings — your preferences, such as whether Face ID lock is on, reorder lead days, whether Health import is enabled, the photo-key device-only option, and a cached flag noting a lifetime purchase.
5. Where it is stored
In a local database on your iPhone, inside the app group container shared with the TideTracker home-screen widget so the widget can display your schedule. If that shared container is unavailable, the app falls back to its own private container.
If you have iPhone backups switched on — iCloud or local — your TideTracker data is included in those backups, and Apple's terms and encryption apply to them. That backup is the only copy that exists outside the device itself, and it is yours, not ours.
We hold no copy and can perform no recovery. If your device is lost or wiped and you have no backup, the data cannot be retrieved by anyone, including us.
6. Progress photos
Progress photos are the most sensitive thing the app holds, so they get more protection than everything else.
- You take them with the camera inside the app, or import them from your photo library.
- They are stored as files encrypted with AES-GCM under a 256-bit key kept in the iOS Keychain. Thumbnails are encrypted too — an unencrypted thumbnail cache would defeat the point.
- By default the key is available after the device's first unlock, so your photos survive restoring an encrypted backup onto a new phone on the same Apple ID. Settings offers a stricter device-only option, with a written warning that photos protected that way will not survive a restore.
- They are never uploaded. They leave the device only when you explicitly export a track, which writes into a "TideTracker" album in your own Photos library using add-only permission.
- Importing from your library uses the system picker, which needs no photo library read permission at all — the app only ever receives the specific images you picked.
- No filters, enhancement or retouching are applied at any point. That is deliberate: a progress photo that has been quietly beautified is worthless.
7. Apple Health
Health import is off by default. If you switch it on in Settings, you grant permission per data type, and TideTracker reads body mass, body fat percentage, lean body mass, waist circumference, resting heart rate, heart rate variability and sleep analysis.
The app is read-only with respect to Health and never writes to it. The authorisation request passes an empty share set, and the app ships without the permission that writing would require, so writing is not merely disallowed but technically impossible.
Health data is used solely to populate your own measurement list on your own device. In line with Apple's HealthKit rules — and as a matter of fact, since nothing is transmitted — it is never used for advertising or marketing, never disclosed to third parties, and never sold. You can revoke access at any time in the Health app.
8. What we do not collect
Most privacy policies list what a company takes. Here is what this one does not:
- No account data — there is no account to hold.
- No analytics — the app contains no analytics SDK.
- No crash reporting — no crash SDK either.
- No advertising identifiers — no ad SDK, no IDFA, no tracking of any kind.
- No processors or sub-processors — there is nothing to process, because nothing is transmitted.
- No cookies or web tracking — the app has no web content.
The app makes no network requests at all. The only outbound links anywhere in it are three you can tap yourself: this page, the Terms of Use, and Apple's subscription management screen.
9. What can reach us, if you choose to send it
Two things, both entirely under your control:
Bug reports. Settings › Report a bug composes a message in your own mail app. You see the whole thing before you send it, and nothing is transmitted in the background. It contains the app version and build, your iOS version, your device model, whether shared storage is in use, and counts of vials, protocols, doses and measurements. It contains no compound names, no doses, no measurements, no photos and no notes.
Support email. Whatever you decide to write to us, and nothing more.
10. Subscriptions
Billing is entirely Apple's. We never see or store your card details, billing address or name.
Your entitlement is verified on your device against a signed App Store transaction. That is precisely why the app needs no account and no server of ours. The only thing stored locally is a flag noting a lifetime purchase, so you are not shown a paywall while offline.
11. Legal basis
Because your records never reach us, there is almost no processing by us to find a basis for. For completeness:
- Your entries, on your device — created by you, held by you, under your control. We are not a recipient of them.
- Health data you import — read only with your explicit, per-type permission, which is your explicit consent under Article 9(2)(a). Withdraw it any time in the Health app.
- Bug reports and support email — our legitimate interest in fixing the app and replying to you, on the basis of information you chose to send.
- Tax and accounting records for purchases — our legal obligation. These come from Apple and contain no health data.
12. Sharing and international transfers
We do not sell your data, and we could not if we wanted to — we do not have it. We share it with nobody for the same reason. There are no processors, no analytics providers, no advertisers and no data brokers involved in this app.
There are no international transfers of your records for the same reason: they do not travel. Email you send us is handled by our mail provider in the ordinary way.
13. Retention
- Your entries — kept on your device until you delete them or remove the app. We hold no copy, so there is nothing for us to retain or expire.
- Bug reports and support email — kept while they are useful for fixing the problem and supporting you, then deleted. We do not archive them indefinitely.
- Purchase and tax records — held by Apple, plus whatever we are required to keep for as long as tax law requires.
14. Deleting and exporting your data
Delete everything. Settings › Delete all data removes every vial, protocol, dose, measurement, supply, photo track and progress photo, including the encrypted photo files on disk. This is irreversible.
Delete individual items. Any single vial, protocol, dose, measurement, photo or track can be deleted on its own.
Delete the app. Removing TideTracker takes the database and all encrypted photo files with it. Note that a device backup made earlier may still contain them until that backup is deleted or overwritten.
Export. Settings › Export as JSON produces a plain, human-readable file with your vials, protocols, doses, measurements and photo timeline. Photo images export separately, per track, into a Photos album. Export is free, and stays free whether or not you have ever paid.
There is no account, so Apple's in-app account deletion requirement does not apply — there is nothing to close.
15. Your rights
You have the rights the GDPR and similar laws give you — access, correction, erasure, restriction, objection, portability and withdrawal of consent. In this app most of them you exercise directly and immediately: your data is on your device, you can read it, change it, export it and destroy it without asking us.
For the little we might hold — your emails to us — write to [email protected] and we will respond within one month.
You may also complain to your local data protection authority. In the EEA you can find yours through the European Data Protection Board; in the UK it is the Information Commissioner's Office.
16. Age
TideTracker is rated 17+ and is for adults. On first launch you confirm you are 17 or older before any data can be entered.
We deliberately do not ask for your date of birth. A birthdate is sensitive, the app has no other use for it, and the check is a self-declaration either way — so collecting one would make you less private without making anyone safer.
17. Security
- Progress photos are encrypted at rest with AES-GCM under a 256-bit key held in the iOS Keychain.
- An optional Face ID or Touch ID lock can be enabled for the whole app. It falls back to your device passcode, so a failed scan can never lock you out of your own records.
- The database relies on iOS file-level data protection.
- There is no data in transit to protect, because there is none.
- If the database cannot be opened, the app offers to export a raw copy and quarantines the old file into a dated folder rather than destroying it.
18. Permissions the app asks for
- Camera — when you take your first progress photo. Used for nothing else.
- Photos, add-only — when you first export, to write into a "TideTracker" album. The app never gains read access to your library.
- Health, read-only — only if you switch Health import on.
- Notifications — for dose and photo reminders. These are scheduled locally on your device; there is no push server and no device token.
- Face ID — only if you enable the app lock.
19. What we tell the App Store
TideTracker's App Privacy answer is "Data Not Collected", and its privacy manifest declares no collected data types, no tracking and no tracking domains. The only required-reason API the app uses is local preference storage, declared for the app's own settings and for the container it shares with the widget.
You can verify all of that on the App Store listing rather than taking our word for it.
20. Changes to this policy
If the app changes in a way that affects this page, this page changes first. The "last updated" date at the top always reflects the current version. Should we ever introduce anything that transmits your data — which is not the plan — we would ask for your explicit consent rather than quietly updating a policy.
21. Contact
Anything at all, including privacy questions and data requests: [email protected]. If you need postal details for a formal request, ask and we will provide them.
See also the TideTracker Terms of Use and our company Privacy Policy.