Privacy policy
Version of 2026-08-23
What reaches our servers about you, what never does, and what you can do about it.
Who processes the data
The controller is Aliaksei Herasimenok, sole proprietor, registration number 192612658, registered on 29 February 2016 by the Minsk City Executive Committee. Address: 5 Nemanskaya St., apt. 58, 220063 Minsk, Republic of Belarus.
For anything about this policy or your data, write to privacy@mypills.life. We answer within 30 days.
What we process
To sign you in and reach you: your email address, the name you gave at registration, your time zone and interface language. A phone number is asked for only if you switch on SMS alerts yourself.
Technical details at registration and address confirmation: IP address and browser information. They exist to limit guessing and abuse, and are kept for a limited time.
The schedule as a structure: dose times, the cell number in the device, the number of units, the time zone.
Dose reports: that a dose was due at a given time and what came of it — confirmed, missed or deferred — with a timestamp. This includes the state of an escalation and the record that a notification was sent: a message code and a time, with no text.
Device details, if you connected one: serial number, cell states, battery level, technical events.
Encrypted values we cannot read: medication name, strength, package barcode, directions, notes, the name of the person cared for, the caption shown on the device screen. These are encrypted in your browser with a key derived from your password, which never reaches our servers. What we hold is ciphertext.
Health data
Information about taking medication is a special category of personal data. The service is built so that as little of it as possible reaches the server.
We do not hold what you take in readable form. We hold that a dose was due at a time and whether it was confirmed. That is still health-related data, and we process it only with your explicit consent.
Alerts to your family carry no medication names: the message says the time of the missed dose and links to the app. The details are visible only to someone holding the key.
If you use the dispenser in local mode, with no account, no health data reaches us at all: the schedule lives in the device and in your browser.
One thing does leave in local mode: a barcode, when you look a packet up in the shared directory. The request carries no account and no cookie, and we store neither who asked nor what they asked — only how many times a barcode has been asked about at all, so we know which entries are worth filling in. The directory itself is a product catalogue: a name and a barcode, with no link to any person. If you add a medication to it, only the name and the barcode are sent, and only if you explicitly choose to.
On what basis
Health data — on your explicit consent, given as a separate action at registration. You may withdraw it at any time; we then stop processing and delete the data, except what the law requires us to keep.
Your email address and account details — to perform our agreement with you, which is to say, to make the service work at all.
Technical records of sign-in attempts and code sending — our legitimate interest in protecting accounts from guessing.
Where the data lives
The service runs in two independent regions: the European Union and Russia. The region is chosen at registration, and personal data does not pass between regions — they are separate servers with separate databases.
Data of users who chose the Russian region is held on servers in the Russian Federation. Data of the European region is held on servers in the European Union.
An existing account cannot change region. If you need another one, export your data, delete the account and register again.
Cloud services are not offered in the Republic of Belarus. The dispenser remains fully usable there in local mode, where no personal data reaches us.
Who else sees it
The hosting provider whose servers run the service in your region, to the extent hosting requires.
The mail provider — only the recipient address and the text of the letter: a confirmation code, a recovery link, a notice that a password changed.
Telegram — only if you connected that channel yourself and consented to it. Medication names never appear in those messages.
The payment provider, once paid plans exist: what a payment requires, and nothing about your treatment.
We do not sell personal data and do not pass it on for advertising.
How long we keep it
For as long as your account exists. When you delete it, the schedule, the intake history and the encrypted values go with it.
Technical records of sign-ins and code sending — no longer than 12 months.
Deleting your account deletes the consent records too. One line stays in our log: that an account with a given identifier was erased on request — with no name, no address and nothing else about you. It exists so that we can confirm the deletion happened.
Your rights
To obtain a copy of your data, correct it, delete it, restrict processing, withdraw consent, and receive your data in a machine-readable form.
You can export your data and delete your account yourself, in the app: “Account and data”. Deleting also withdraws consent to processing health data.
Write to privacy@mypills.life. We answer within 30 days.
You may complain to the data protection authority in your country if you believe we have breached your rights.
When somebody else created the profile
The service is built for families: a daughter may create a profile for her father and watch his doses. In that case we receive information about a person from somebody other than them.
Whoever creates the profile must tell the person whose data they are entering and make sure they do not object. The app says so at the moment a profile is created.
The person whose profile was created may write to privacy@mypills.life and ask for access to their data or its deletion, even though the account belongs to somebody else.
Children
Only an adult may open an account. A child's profile may be created by their legal guardian, who is also responsible for consent to processing the child's data.
Changes
We may change this document. Every version carries a date, and we announce material changes by email before they take effect.
If a change affects the basis for processing health data, we ask for consent again.