Privacy & Legal
Everything you need to know about how PeePal handles your data.
Last updated: 9 August 2026
Data Retention Overview
PeePal stores health data locally first using Apple Core Data. The iOS Tracking store can sync selected tracking records through the user's Apple-managed private CloudKit database when iCloud is available. The app accesses that database through your iCloud entitlement. The PeePal operator does not operate servers that hold your health data, has no independent backend access, and does not run a PeePal-managed health-data synchronisation service.
What stays on your device
- Profile details, health conditions, medications, symptoms, and settings
- Local caches and derived insights that can be regenerated
What can sync through private CloudKit
- Fluid intake records, including timestamps, amounts, beverage types, and notes you add
- Bathroom visit records, including timestamps, urgency, colour, volume fields, and notes you add
- Historical tracking data and selected tracking-derived cache rows
What stays on your device only
- App preferences and settings
- Derived insights and pattern data
iCloud backup
iCloud device backup is separate from CloudKit private database sync. If you have iCloud backup enabled on your device, local app data may also be included in your encrypted device backup where iOS allows it. The PeePal app accesses its private CloudKit database only through your iCloud entitlement; the PeePal operator has no independent backend access. PeePal does not access iCloud backup data. Apple's iCloud Privacy Policy governs this storage.
Deleting your data
PeePal → Profile → Data Management → Delete All Data attempts to remove its implemented set of local and private CloudKit records. It requires an existing profile to begin, reports a partial result when a deletion component fails, and may leave some local settings, derived or audit artefacts until a future update completes this capability. Avoid adding new records while deletion is running. iCloud device backups are separate; remove them through iOS Settings → Apple ID → iCloud → Manage Account Storage if required.
Analytics
PeePal may use first-party anonymous product analytics to understand whether core logging features are being used. These aggregate analytics are not linked to users, not used for tracking, and never include health, identity, profile, or free-text content. Anonymous crash reports are sent via Sentry (see below) to help us fix bugs; they contain no health data.
Privacy Policy
This Privacy Policy describes how PeePal ("we", "us", "our") handles information in connection with the PeePal mobile application and this website.
The short version
Your health data is local-first. Selected tracking data can sync through your Apple-managed private CloudKit database when iCloud is available, but we do not collect, store, or process your personal health information on any server we operate. We do not sell your data. We do not share your data with third parties for advertising or commercial purposes.
Information we do not collect
- Your name, email address, or any account credentials (there is no account)
- Your bathroom visit logs, fluid intake records, or health data on any server we operate
- Your location
- Your Apple Health or HealthKit data beyond on-device processing
Profile may store optional biological sex on the device so the visit form can show relevant fields. That value stays in the local record, and in optional private iCloud sync if you use it. It is not an account, and it is not sent in anonymous product analytics.
Information we may collect
PeePal may collect first-party anonymous product analytics to understand whether core intake and output logging features are being used. These analytics are aggregate, not linked to users, and not used for tracking, advertising, data brokerage, or cross-app or cross-site profiling. They are stored with no configured retention time limit for long-term analysis.
Product analytics include no raw log values, no notes, no symptoms, no profile details, no visit history, no HealthKit values, and no free text. They also never include names, email addresses, accounts, user identifiers, device identifiers, install identifiers, advertising identifiers, IDFA, location data, raw intake volumes, bathroom visit volumes, urine colour, timings, menstrual data, leakage data, medication, conditions, or biological sex.
Crash reporting
PeePal uses Sentry for crash and error reporting. Crash reports contain technical diagnostic information (device type, OS version, stack trace). Personal health data is scrubbed before transmission. Those diagnostic reports are retained for 30 days.
This website
This website does not run analytics scripts or marketing tags. Cloudflare may retain ordinary edge access logs to operate the site.
The Diary stores entries in IndexedDB in this browser only. It does not send diary entries to PeePal, the iOS anonymous core-use service, or any third party. If you contact us by email, we receive and store your email address solely to reply to you.
Children
PeePal is not intended for children under 13. We do not knowingly collect information from children.
Changes to this policy
We will update the "Last updated" date at the top of this page if this policy changes. Continued use of PeePal after a change constitutes acceptance.
Contact
For privacy enquiries, email admin@peepal.info.
Terms of Use
By downloading or using PeePal, you agree to these terms. If you do not agree, do not use the app.
Use of the app
PeePal is provided for personal, non-commercial use. You may not reverse engineer, decompile, or attempt to extract source code from the app. You may not use the app for any unlawful purpose.
No warranty
PeePal is provided "as is" without warranty of any kind. We make no guarantees about accuracy, completeness, or fitness for any particular purpose — including medical or clinical use.
Limitation of liability
To the fullest extent permitted by law, PeePal and its developers shall not be liable for any loss or damage arising from your use of, or inability to use, the app.
Intellectual property
All content, design, and code in PeePal are the property of PeePal and its developers. You may not reproduce or redistribute any part without written permission.
Governing law
These terms are governed by the laws of England and Wales.
Changes to terms
We may update these terms. Continued use of PeePal after changes constitutes acceptance.
Medical Disclaimer
PeePal is a wellness tool, not a medical device.
The information and insights provided by PeePal are for general informational and wellness purposes only. They do not constitute medical advice, diagnosis, or treatment.
PeePal is not a substitute for professional medical advice. Always seek the advice of your GP, consultant, or other qualified healthcare professional with any questions you may have regarding a medical condition. Never disregard professional medical advice or delay in seeking it because of something you have read in or exported from this app.
If you think you may have a medical emergency, call 999 (UK) or your local emergency number immediately.
The health guides available in PeePal are educational resources only and have not been reviewed or approved by a regulatory body. They are not a substitute for advice from a qualified healthcare professional.