Privacy Policy
Last updated: July 18, 2026
NeckPill ("we", "us", or "our") is developed by Przemyslaw Raciborski. This Privacy Policy explains what information we collect, how we use it, and your rights when you use the NeckPill iOS and Android applications and the website at neckpill.app. Some behavior differs by region — see Section 4.
NeckPill does not require account registration. No email address or personal credentials are collected.
1. Information We Collect
We collect the minimum data necessary to operate and improve the app:
- Anonymous usage data — app screens visited, features used, session duration. Collected via Firebase Analytics. No personally identifiable information (PII) is included.
- Install attribution data — device advertising identifiers (IDFA on iOS, only with your App Tracking Transparency permission; Google Advertising ID on Android), device model, OS version, and coarse region. Collected via Tenjin to measure which advertising campaigns bring users to NeckPill.
- Crash and error reports — device model, OS version, app version, and stack traces when the app crashes. Collected via Sentry. No PII is included.
- Subscription status — whether you have an active subscription and its type (monthly/annual). Managed via RevenueCat using an anonymous store identifier. We never receive your payment card details.
2. Information We Do Not Collect
- We do not collect your name, email address, or any credentials — there are no accounts.
- NeckPill was intentionally designed to keep all workout and exercise data on your device only — no training data is ever uploaded to the cloud. This is a deliberate privacy-first design decision to protect your personal fitness data.
- We do not access your microphone, contacts, or location. The camera is used only if you choose to take the optional face & neck scan — photos and derived measurements are processed and stored on your device and are never uploaded (see Section 3).
- We do not use HealthKit, Google Fit / Health Connect, or read any health data.
- We do not sell or rent your data to any third party.
3. Biometric Data (Face & Neck Scan)
The optional face & neck scan runs only after your explicit in-app consent. The photo and the measurements derived from it are processed and stored entirely on your device — they are never uploaded, and we never possess them. The full rules — what is collected, what it is used for, consent, the retention schedule, and how deletion works — are documented in our dedicated Biometric Data Policy, which supplements this Privacy Policy and serves as the written policy required by biometric privacy laws such as Illinois BIPA.
4. Analytics, Attribution & Your Consent
How analytics and attribution are switched on depends on your region:
- European Economic Area, United Kingdom, Switzerland, and South Korea — analytics and attribution are off by default and only start after you explicitly opt in during onboarding (GDPR / UK GDPR / Swiss FADP / Korean PIPA). If you decline, no data is sent to Firebase or Tenjin.
- All other regions — anonymous analytics and install attribution are enabled by default on an opt-out basis.
In both cases you can opt out at any time via App Settings → Opt Out of Analytics — this immediately stops all Firebase analytics collection and opts your device out of Tenjin attribution.
On iOS 14.5+, use of your device's advertising identifier (IDFA) additionally requires your explicit permission via Apple's App Tracking Transparency (ATT) framework, in every region. If you grant permission, the IDFA may be used to:
- Measure the effectiveness of our advertising campaigns
- Deliver more relevant ads to you on third-party platforms (e.g. Meta, TikTok)
- Build aggregated audience profiles to reach similar users
If you deny ATT permission, no IDFA is collected; campaign measurement then relies solely on Apple's privacy-preserving, aggregate SKAdNetwork reports, which contain no device-level identifiers. You can change the ATT permission at any time in iOS Settings → Privacy & Security → Tracking. On Android, you can reset or delete your advertising ID in Settings → Privacy → Ads.
5. Third-Party Services
The following third-party SDKs process limited data on our behalf:
- Firebase Analytics (Google) — anonymous usage analytics. Firebase Privacy · Google GDPR.
- Tenjin — install and ad-campaign attribution. Tenjin Privacy Policy.
- RevenueCat — subscription management using anonymous store IDs. RevenueCat Privacy Policy · RevenueCat DPA.
- Sentry — crash and error reporting. Sentry Privacy Policy · Sentry DPA (GDPR).
- Apple App Store / Google Play — all payments are handled entirely by Apple or Google. Apple Privacy Policy · Google Privacy Policy.
6. Data Retention
Anonymous analytics data is retained by Firebase for up to 14 months. Attribution records are retained by Tenjin for as long as needed for campaign measurement. Crash reports in Sentry are retained for 90 days. RevenueCat retains subscription records as required for billing integrity. Your local workout data is deleted when you uninstall the app.
7. Children's Privacy
NeckPill is not directed at users under 16. The app does not collect personal data, so parental supervision and iOS Screen Time controls are the recommended tools for managing access for younger users.
8. Your Rights (GDPR, CCPA & Other Laws)
Depending on where you live — the GDPR in the EEA/UK/Switzerland, the CCPA/CPRA and similar US state laws, Brazil's LGPD, and others — you may have rights to access, delete, or opt out of the sharing of personal information. Since we collect no personal data tied to your identity, most standard data rights are satisfied by design. You can exercise your choices directly:
- Opt out of analytics and attribution (this also serves as "Do Not Sell or Share My Personal Information" under US state laws) at any time via App Settings → Opt Out of Analytics. This immediately stops all Firebase analytics collection and Tenjin attribution.
- Withdraw ATT tracking permission via iOS Settings → Privacy & Security → Tracking → NeckPill, or reset/delete your advertising ID via Android Settings → Privacy → Ads.
- Request information about what anonymized data may be associated with your device via support@neckpill.app
9. Security
All data transmitted to third-party services uses TLS encryption. Workout data never leaves your device. We do not operate servers that store personal data.
10. Changes to This Policy
We may update this Privacy Policy. The updated version will be posted here with a revised date. Continued use of the app after changes constitutes acceptance.
11. Contact
Questions or requests regarding this policy:
📧 support@neckpill.app
🌐 neckpill.app