TirzeFlow
Privacy Policy
Updated on
TirzeFlow is a personal treatment journal. It holds health data you record yourself — weight, doses, measurements, side effects — which is the most sensitive information an app can hold. This policy states exactly what is collected, why, who it is shared with, and how to erase all of it. There is no advertising, no tracking, and nothing is sold.
1. Who is responsible for your data
TirzeFlow is developed and maintained by Guilherme Passarinho, an individual based in Brazil, who is the data controller for the personal data processed in the app under Brazil's General Data Protection Law (Law 13,709/2018) and equivalent legislation.
For anything related to privacy, including exercising your rights: suporte@gguip.dev.
2. What the app collects
The data below is provided by you or, for weight, read from the Health app or Health Connect when you turn that option on. TirzeFlow collects nothing in the background and does not access your calendar, contacts, or location. The camera is used only when you choose to take a progress photo.
Account data, needed for you to sign in:
- Name and email address.
- Password, stored only as an argon2id hash — the password itself is never written down and never travels in plain text on the server.
- The date and time you accepted the terms of use and this policy.
- If you sign in with Google or Apple: your account identifier at that provider and, for Apple, a refresh token used solely to revoke access when you delete your account.
Profile data, which feeds the app's calculations:
- Biological sex, date of birth, and height.
- Activity level, starting weight, goal weight, and treatment start date.
- Language, unit system, time zone, and treatment phase.
Health records, which are the content of the journal:
- Injections: date and time, dose in milligrams, injection site, lot number, and notes.
- Weigh-ins: date, weight, and where the record came from (typed by you or read from the Health app / Health Connect).
- Body measurements: waist, hip, chest, arm, thigh, and body fat percentage.
- Side effects: date, type, severity, and notes.
- Workouts: date, type, duration, perceived exertion, and notes.
- Nutrition: meals with calories and macronutrients, and water intake.
- Hunger and thoughts about food: two ratings from 1 to 5 per day.
- Pen purchases: date, dose, number of injections and, if you enter it, the price paid.
- Any reminders you set.
Technical data, generated by the session itself:
- IP address and app and operating system identification, stored alongside each active session. They let you end sessions and allow misuse of credentials to be detected.
- Server logs, which use only your internal identifier — never your name, your email, or any health data.
- Crash reports: when the app crashes or the server answers with an internal error, a technical report is sent to Sentry (section 6). It carries the error description, the app version, the device model and operating system, and your internal identifier.
Weight read from the Health app (iPhone) and Health Connect (Android):
- Reading is off by default. You turn it on in Profile > Health, and the system asks for your permission at that moment. You can turn it off at any time, in the same place or in the system settings.
- The app asks for a single data type, weight, and for reading only. It reads no other health data and never writes anything to the Health app or to Health Connect.
- Reading happens while the app is open. The first weigh-in of each day is used, and it is saved to your account alongside the weigh-ins you type. A weight typed by you is never replaced by one that was read.
- The weight that is read is used only to show your history and the calculations in section 4. It is not used for advertising, is not sold, and is not passed to any third party other than the hosting provider in section 6.
- The use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements. Data obtained through HealthKit follows Apple's rules for that service.
Data that stays only on your device and is not sent to the server:
- Progress photos: kept encrypted (AES-256) on the device, with the key held in the operating system's secure storage. They are not part of the server backup and do not follow you to a new device.
- Dietary restrictions, the day's menu swaps, and the request you write to build the menu. On iPhones with Apple Intelligence, that request is processed on the device itself.
3. Sensitive health data and your consent
Weight, measurements, medication dose, side effects, and hunger ratings are sensitive personal data concerning health. They are processed only because you gave specific, prominent consent when creating your account, and exclusively for the purposes set out in this policy.
You may withdraw that consent at any time by deleting your account inside the app, which erases all of these records. Withdrawal does not undo processing already carried out while consent was valid, but it ends any further processing.
4. What the data is used for
- Showing you your own history: weight progression, logged injections, measurements, side effects, workouts, nutrition, hunger, and pen purchases.
- Calculating the figures the app displays — body mass index, weekly average, calorie and protein targets, maintenance band, the next injection site in the rotation, pen stock, and spending.
- Authenticating you, keeping your session open, and protecting the account against unauthorised access.
- Sending strictly operational email: the sign-up verification code and the password reset code. TirzeFlow sends no newsletter, no promotion, and no marketing of any kind.
5. What TirzeFlow does not do
This section matters as much as the previous one, and it is verifiable: the app ships no usage analytics or advertising library. The only third-party tool that receives technical data is the crash reporting described in section 6.
- It does not sell, rent, or trade your data with anyone.
- It shows no advertising and does not use your data to target ads.
- It does not track you inside or outside the app, and uses no advertising identifiers.
- It uses no analytics or usage telemetry tools, and crash reporting is configured not to capture screen contents or what you type.
- It shares nothing with health plans, employers, pharmaceutical companies, insurers, or data brokers.
- It does not use your health data to train artificial intelligence models.
7. Where the data lives and for how long
Your account records are held on a server located in Brazil, in São Paulo. Crash reports are held on Sentry's servers in the European Union. The connection between the app and the server is always encrypted.
An encrypted backup is taken daily, kept for thirty days, and then discarded. It exists to restore the service in case of failure.
Your records are kept for as long as your account exists. When you delete the account they are erased from the database immediately; backups that still contain them expire within thirty days.
8. How the data is protected
- Passwords stored with argon2id, currently OWASP's recommended algorithm.
- All traffic between the app and the server protected by TLS.
- Session tokens kept in the operating system's secure storage — Keychain on iOS, Keystore on Android — never in a plain file.
- Every database query is scoped to your identifier, so the server cannot return someone else's record even if a record identifier is guessed.
- Encrypted backups, with the decryption key held off the server.
No system is immune to incidents. If a security incident occurs that may pose a material risk to your rights, you and Brazil's data protection authority (ANPD) will be notified as required by law.
9. Your rights
You have, among others, the rights of confirmation, access, correction, anonymisation, portability, erasure, and information about sharing. Two of them are implemented directly in the app:
- Correction: your profile data and the current week's injection can be corrected in the app. To correct or delete any other specific record, write to suporte@gguip.dev from the email address registered on the account.
- Erasure: deleting your account, done inside the app, erases everything.
Access and portability: to get a copy of all of your data, in an open, machine-readable format (JSON), write to suporte@gguip.dev from the email address registered on the account. For the remaining rights, write to the same address. You will get an answer within fifteen days.
10. How to delete your account
In the app, with no need to contact anyone: open the Profile tab, scroll to the bottom of the screen, and tap Delete my account. The app shows what will be erased and asks for confirmation. If you no longer have the app installed, the page tirzeflow.gguip.dev/en/delete-account/ explains how to request deletion by email.
Deletion is permanent and cascades: the account and every associated record — profile, injections, weigh-ins, measurements, side effects, workouts, meals, water intake, hunger ratings, pen purchases, reminders, and sessions. There is no soft delete and no grace period; the data cannot be recovered afterwards.
Progress photos and the key that protects them are erased from the device on which the deletion is done. Uninstalling the app also removes them.
If your account was created with Sign in with Apple, the authorisation granted to Apple is revoked at the same moment.
11. Children and adolescents
TirzeFlow is not intended for anyone under 18 and does not knowingly collect data from that age group. If we learn that an account was created by a minor, it will be deleted. If you are a parent or guardian and believe this has happened, write to suporte@gguip.dev.
12. Important health notice
13. Changes to this policy
This policy may be updated. The date of the latest update is always at the top of this page. Any change that materially affects how your data is handled will be announced inside the app before it takes effect.
14. Contact
Questions, requests, or complaints about privacy: suporte@gguip.dev. You may also complain directly to Brazil's National Data Protection Authority (ANPD).