Privacy

Your data stays yours.

Short version: we keep what’s necessary to make PillTrack work, we never sell it, and you can delete everything in two clicks.

Last updated · April 24, 2026

What we collect

  • Account basics — email, name (if provided), hashed password or OAuth identifier.
  • Medication data — names, schedules, doses you log. This is the whole point of the service.
  • Device metadata — browser, OS, timezone. Used so reminders fire at the right local time.
  • Push subscription — only if you enable reminders, and only the tokens needed to deliver them.

How we use it

To render your dashboard, fire dose reminders, compute adherence, generate PDF exports, and keep your sessions signed in. We do not run ad targeting, behavioral profiling, or third-party tracking SDKs.

Selling your data

We don’t. No pharmaceutical companies, no advertisers, no data brokers. Medication data is deeply personal and the whole point of PillTrack is that you can trust it.

Who we share with

Only these categories of subprocessors:

  • Hosting & database — Vercel (app) and Neon (Postgres).
  • Authentication — Google OAuth, if you choose to sign in that way.
  • Drug reference lookups — RxNorm and openFDA public APIs. We send drug names to resolve brand/strength/side effects; we do not send your name, email, or any identifying information.

We do not give these providers bulk data. They only see what’s required to render a page or deliver a reminder.

Deleting your account

Open Settings DataDelete account. Your medications, schedules, dose logs, profiles, and push subscriptions are cascade-deleted immediately. Backups roll off within 30 days.

Security

Data is encrypted in transit (TLS) and at rest (Neon’s managed storage). Passwords are stored only as bcrypt hashes — we can never see them. Push subscription endpoints are scoped per device and revoked on sign-out.

Children

PillTrack is intended for adults. Caregivers can track medications for minors by creating a named profile under their own account. We do not knowingly collect data directly from children under 13.

Questions or requests

For data export, correction, or deletion requests beyond the self-serve flow — or for anything you’re not sure about — email us. We’ll respond within 7 days.

This policy is a working draft while PillTrack is in open beta. It will be replaced with a legally reviewed version before any paid tier launches; material changes will be announced in-app.