Privacy Policy for Perilog

Effective date: July 16, 2026

Perilog ("the app", "we", "our") is developed by an individual developer (note: update to a registered company name here if/when an LLC or other entity is formed). This policy explains what data Perilog collects, why, and how it's handled.

The short version: Your health and journal data never leaves your device — or, if you enable iCloud, your own private iCloud account. Perilog has no server, no backend, and no account system. There is nothing for us to see, store, sell, or lose — because we never receive it in the first place.

What we collect

Symptom, cycle, and journal data — NOT collected by us

Everything you log in Perilog — symptoms, cycle entries, notes, moods, and any other journal content — is stored only on your device, in a local Core Data database. It is never transmitted to us or to any server. We have no access to it, no copy of it, and no way to retrieve it if you lose your device.

iCloud backup — your data, your account, never ours

If you're signed into iCloud on your device, Perilog automatically backs up and syncs your journal data using Apple's CloudKit, storing it in your own private CloudKit database — the same private storage tier Apple uses for Notes, Reminders, and Health data. This is not our server: it is a container inside your personal iCloud account, encrypted and access-controlled by Apple, that only you (and your other signed-in devices) can read. We, the developer, have no access to this data, no way to query it, and no copy of it — Apple's private CloudKit database is architecturally inaccessible to app developers by design. If you're signed out of iCloud, or it's unavailable for any reason, Perilog works exactly as before, storing data locally only, with no loss of functionality.

Purchase data — collected, but not linked to your identity

Perilog offers subscriptions and a lifetime unlock via in-app purchase, processed through RevenueCat, our payment/entitlement infrastructure provider. RevenueCat receives:

This ID is not your name, email, or Apple ID — it cannot be used to identify you personally. RevenueCat uses this data solely to validate your purchase and unlock the correct features. It is never used for advertising or analytics.

What we do NOT collect

Local notifications

Reminders you enable are scheduled entirely on your device using Apple's local notification system. No push notification server is involved, and no data about your reminders is sent anywhere.

Exporting your data

Perilog lets you export your own journal data as a PDF or CSV to share with a healthcare provider, using the standard iOS share sheet. This export happens entirely on your device and at your discretion — it is you sharing your own data with whomever you choose. We (the developer) never receive a copy of this export.

Storage and retention

All journal data lives in your device's local storage for as long as the app is installed. Because there is no server copy:

If you're signed into iCloud, your journal data is also mirrored into your own private iCloud (see "iCloud backup" above), which survives losing or replacing your device. If you're not signed into iCloud, please back up your device (e.g., via encrypted iTunes/Finder backup) if you want a copy preserved.

Please back up your device (e.g., via encrypted iCloud/iTunes backup, which is entirely under Apple's and your control) if you want a copy preserved.

Third parties

RevenueCat — purchase and subscription infrastructure. Receives anonymous App User ID and purchase history only, for app functionality (entitlement validation) purposes. See RevenueCat's own privacy policy: https://www.revenuecat.com/privacy/

We do not use any other third-party SDK.

Your rights (GDPR)

Because Perilog stores your journal data only on your device, most of these rights are already in your hands directly, without needing to contact us:

For purchase data held by RevenueCat, you may contact us at the address below and we will forward a deletion/access request to RevenueCat on your behalf.

Your rights (CCPA)

We do not sell your personal information, and never have.

Children's privacy

Perilog is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has provided data through the RevenueCat purchase flow, contact us and we will investigate.

Changes to this policy

If our data practices change (for example, if we ever add an analytics or crash-reporting SDK), we will update this page and revise the effective date above.

Contact

Questions about this policy? Email 1anfibi@gmail.com.