Legal

Privacy Policy

Last updated: July 18, 2026

NeckPill ("we", "us", or "our") is developed by Przemyslaw Raciborski. This Privacy Policy explains what information we collect, how we use it, and your rights when you use the NeckPill iOS and Android applications and the website at neckpill.app. Some behavior differs by region — see Section 4.

NeckPill does not require account registration. No email address or personal credentials are collected.

1. Information We Collect

We collect the minimum data necessary to operate and improve the app:

2. Information We Do Not Collect

3. Biometric Data (Face & Neck Scan)

The optional face & neck scan runs only after your explicit in-app consent. The photo and the measurements derived from it are processed and stored entirely on your device — they are never uploaded, and we never possess them. The full rules — what is collected, what it is used for, consent, the retention schedule, and how deletion works — are documented in our dedicated Biometric Data Policy, which supplements this Privacy Policy and serves as the written policy required by biometric privacy laws such as Illinois BIPA.

4. Analytics, Attribution & Your Consent

How analytics and attribution are switched on depends on your region:

In both cases you can opt out at any time via App Settings → Opt Out of Analytics — this immediately stops all Firebase analytics collection and opts your device out of Tenjin attribution.

On iOS 14.5+, use of your device's advertising identifier (IDFA) additionally requires your explicit permission via Apple's App Tracking Transparency (ATT) framework, in every region. If you grant permission, the IDFA may be used to:

If you deny ATT permission, no IDFA is collected; campaign measurement then relies solely on Apple's privacy-preserving, aggregate SKAdNetwork reports, which contain no device-level identifiers. You can change the ATT permission at any time in iOS Settings → Privacy & Security → Tracking. On Android, you can reset or delete your advertising ID in Settings → Privacy → Ads.

5. Third-Party Services

The following third-party SDKs process limited data on our behalf:

6. Data Retention

Anonymous analytics data is retained by Firebase for up to 14 months. Attribution records are retained by Tenjin for as long as needed for campaign measurement. Crash reports in Sentry are retained for 90 days. RevenueCat retains subscription records as required for billing integrity. Your local workout data is deleted when you uninstall the app.

7. Children's Privacy

NeckPill is not directed at users under 16. The app does not collect personal data, so parental supervision and iOS Screen Time controls are the recommended tools for managing access for younger users.

8. Your Rights (GDPR, CCPA & Other Laws)

Depending on where you live — the GDPR in the EEA/UK/Switzerland, the CCPA/CPRA and similar US state laws, Brazil's LGPD, and others — you may have rights to access, delete, or opt out of the sharing of personal information. Since we collect no personal data tied to your identity, most standard data rights are satisfied by design. You can exercise your choices directly:

9. Security

All data transmitted to third-party services uses TLS encryption. Workout data never leaves your device. We do not operate servers that store personal data.

10. Changes to This Policy

We may update this Privacy Policy. The updated version will be posted here with a revised date. Continued use of the app after changes constitutes acceptance.

11. Contact

Questions or requests regarding this policy:
📧 support@neckpill.app
🌐 neckpill.app