Overview
Stack My Med collects information needed to provide the app: account access, label scanning, product cabinet storage, private product notes, scheduling, adherence tracking, optional HealthKit context, subscription status, support, and diagnostics.
We do not sell personal information. Data is used to operate, secure, improve, support, and measure Stack My Med.
Our public website uses Google Analytics 4 to understand visits, traffic sources, page views, and App Store download clicks. Google may process browser and device information, approximate location, referrer, IP address, and interaction events for website analytics. Native app measurement has separate choices, described below; website consent does not enable measurement in the app.
Optional Google measurement in the app
In app versions that offer Measurement choices, Google Firebase Analytics is optional. If you enable Google install and subscription analytics, Google processes installation, app-session, technical app/device and subscription data, including actual purchase amounts, currency, the subscription product and technical transaction identifiers. Firebase can also collect automatic technical, lifecycle and subscription events. Google also derives approximate geographic information from IP addresses for analytics and, when separately permitted, advertising measurement; this does not use Apple Location Services. If you separately enable Google advertising measurement and currently allow iOS tracking, these data may be used to measure Google ads. Personalized advertising remains disabled. These native choices are separate from website consent, account creation and Advisor acknowledgement, and may be changed in Profile. You can continue using Stack My Med without enabling either choice.
We do not send medication or supplement names, label scans or photos, health/HealthKit data, reminder or Cabinet contents, questionnaire answers, Advisor conversations, email, phone or backend account IDs to Google. We do not set Google's user ID or user-provided data for enhanced conversions. Automatic screen reporting, IDFV collection and Google advertising-ID support are disabled in this integration. Technical analytics identifiers are not anonymous data.
Other measurement providers
Our public web funnel uses Meta Pixel and Meta Conversions API only after you choose to allow optional web analytics and advertising measurement. We use them to measure generic page and funnel-step views, successful lead capture, checkout start, trial start, and the first paid conversion. Website measurement data sent to Meta may include _fbc and _fbp, the real IP address and browser user agent for the website event, your consent state, generic plan, value, and currency fields, and a hashed pseudonymous external ID.
We use the email address you submit to maintain your lead and provide access. If you agree to the updated web analytics and advertising measurement notice, we also send Meta a normalized SHA-256 hash of that email, together with eligible lead, checkout, trial, and first-payment events, to help match those events to your Meta account and measure advertising. Hashing does not make the email anonymous. We do not send your plain-text email to Meta or any email representation to PostHog. Previous consent given under our no-email-sharing notice does not authorize email matching; a new choice is required before this additional sharing begins.
For web measurement, we do not send phone numbers, supplement or medication names, quiz answers, health data, free text, scan contents, or label data to Meta.
We do not send any quiz-derived scores, result buckets, goals, or other quiz-derived metadata to Meta.
Our public web funnel uses PostHog only after you allow optional analytics. We send only explicitly instrumented, privacy-filtered funnel events. PostHog automatic capture, automatic page views, and session recording are disabled. Those events may include a random funnel session ID and generic event, step, plan, design, and consent metrics. We do not send PostHog email addresses or email hashes, Stripe Checkout session identifiers, supplement or medication details, raw quiz answers, health data, or free text.
We use aggregate backend usage reports to understand privacy-safe product usage such as active users, scan volume, schedule refreshes, dose logging, and subscription status. These reports do not include product names, label photos, health answers, free-text notes, or dosage text.
We may use Amplitude in the app to understand privacy-filtered product behavior such as app opens, sign-in completion, screen usage, scan funnel steps, dose actions, cabinet actions, and paywall views. We do not send supplement or medication names, label photos, dosage text, health answers, HealthKit values, free-text notes, email addresses, phone numbers, or raw per-product identifiers to Amplitude.
Product note analytics use limited metadata only and exclude private note text and note previews. We do not send private product note text to Amplitude or Meta. Note analytics may include the feature action, source, active/paused status, and note-count bucket.
After App Tracking Transparency (ATT) authorization, supported app versions use the Meta SDK to measure iOS installation, app activation and a verified first paid annual subscription. Subscription measurement includes the actual amount, currency, annual subscription product and a technical transaction identifier, alongside the SDK's technical app/device identifiers. It is separate from consent in the public web funnel. The native app does not offer a trial; a website trial is a separate purchase flow.
Separately, we register app installations using Apple’s SKAdNetwork, which can provide aggregate advertising-attribution reports without ATT authorization. These reports do not include user or device identifiers. Access to the iOS advertising identifier (IDFA) remains restricted to users who authorize tracking.
On September 8, 2026, we disabled Adapty's monetary-event forwarding to this native Meta destination for the switch to SDK-based initial-subscription measurement in the new app version. Previously submitted subscription and renewal events can remain in Meta; older app versions do not gain the new SDK reporting automatically. Adapty continues subscription validation and accounting and may forward enabled nonmonetary subscription-lifecycle events after ATT authorization. RevenueCat continues services for legacy app versions with its separately configured integration. We do not send supplement or medication names, label photos, dosage text, health answers, HealthKit values, free-text notes, email addresses, or phone numbers to Meta for native advertising measurement. Technical identifiers are not anonymous data.
Advisor message content is not used for product analytics, ads, or commerce personalization. Advisor analytics are limited to typed, content-free feature events and do not contain messages, results, product or medicine data, health data, or raw identifiers.
Medical and supplement information in Stack My Med is informational only. It is not a diagnosis, treatment plan, or substitute for professional medical advice.
Data we collect
Account and identifiers
When you sign in, we may process your Apple Sign in name or email when Apple provides it, a Convex user ID, anonymous user ID, auth identifiers, device-related identifiers, push notification metadata, and live activity token hashes.
Health and profile information
If you provide it, Stack My Med stores self-reported profile answers such as age range, goals, lifestyle information, conditions or concerns, pregnancy status, and similar health-related context. If you connect Apple Health, the app may read summaries such as steps, heart rate, sleep, and active calories to show context around your routine.
Label photos and product records
When you scan a product or add notes, label photos, extracted product facts, supplement or medication names, dosage, ingredients, private product notes that you write, schedule entries, cabinet assignments, adherence events, and related scan metadata may be stored off-device so the app can work across sessions.
Purchases and usage
We store subscription entitlement state, App Store transaction identifiers, scan counts, privacy-safe feature usage metrics, AI audit events, backend failures, diagnostics, and limited device attribution identifiers needed to operate, debug, and measure the service.
Advisor processing and history
Advisor is an optional educational conversation, not medical advice. Before sending, you must acknowledge the current processing disclosure in the app. Your messages and relevant conversation history are sent to OpenAI to generate replies. This consent is saved for your account and disclosure version; it does not replace your separate Cabinet-sharing choice.
Cabinet sharing is off by default and fixed for that conversation. If you enable it, the shared context includes a bounded selection of product and brand names, ingredients, label amounts and units, including medicine labels, plus inventory and intake-plan status. Status can be regular, paused, as-needed, unscheduled, or unknown; it is not proof of actual intake, adherence, safety, or a complete interaction check. Empty, incomplete, or truncated context may limit the response. Start a new chat to change the sharing choice.
Schedule times, reminders, adherence records, Apple Health or HealthKit data, profile answers, email, private notes, and label images or OCR are not automatically attached to this chat. Raw database IDs and other conversations are not included in the provider context. Information you type into a message is still sent, including any health or personal details you choose to enter. Share only information you are comfortable sending.
Public evidence search uses predefined public topics, not your messages or Cabinet details. The private reply-generation step may use your conversation and enabled Cabinet context with the retrieved evidence. Advisor cannot change your products or treatment; it does not diagnose, prescribe, or guarantee safety.
Saving future chats is off by default. Temporary chats become inaccessible 24 hours after creation. Physical cleanup follows scheduled expiry and a bounded hourly cleanup job; completion can occur later than the access cutoff. With an eligible Premium subscription and separate opt-in, new chats can be saved until you delete them. Turning saving off or losing Premium does not delete already saved chats; read, export, and delete remain available. To continue without saving, start a new temporary chat.
From Advisor or Profile, open Processing and privacy to export retained chats, delete an individual chat from History, delete all chats, or withdraw processing consent. Export includes visible user and assistant text, details, citations, conversation/request identifiers, timestamps, retention and sharing choices, and consent/history settings. Hidden prompts, provider response identifiers, Cabinet snapshots, and technical usage counters are not exported. Export can be cancelled and restarted; a failed or partial export is not a completed file. Delete-all may take several bounded steps; wait for confirmation or resume it if interrupted.
Withdrawal stops future AI processing and turns off saving future chats. It does not delete existing chats or recall data already sent to OpenAI; use deletion separately. These privacy controls remain available when generation is disabled or Premium lapses. Account deletion removes account-owned chat, consent, and usage records; aggregate content-free operational counters may remain until expiry.
OpenAI requests use store:false; this is not zero provider retention. Provider retention follows the applicable account data controls and policy, and we do not claim zero-data-retention, EU-only processing, a healthcare agreement, or clinical review. See OpenAI's API data policy. Chat content is stored in our authenticated, user-scoped backend, not end-to-end encrypted. Content-free account and aggregate daily usage reservations enforce technical limits; they are not purchased message credits and expire separately from chats.
Service providers and processors
Stack My Med uses third-party processors to operate the app and public website:
- Convex for app database, authentication, backend functions, and file storage metadata.
- Apple for Sign in with Apple, StoreKit purchases, HealthKit, Push Notifications, and platform services.
- Adapty for current iOS subscription status, purchase validation, entitlement management, paywall delivery, and subscription attribution events.
- RevenueCat for those services in legacy app versions that remain installed.
- Meta for consent-gated public web advertising measurement and, after ATT authorization, iOS app-install, limited app activation, and subscription attribution measurement when Meta advertising is enabled.
- PostHog for consent-gated public web product analytics.
- Amplitude for privacy-filtered app product analytics, funnels, cohorts, and feature-usage reporting.
- OpenAI for acknowledged Advisor messages and relevant conversation history, and optional Cabinet product labels (including medicine labels) and derived inventory/intake-plan status. Cabinet sharing is off by default. Public evidence retrieval uses predefined topics without private messages or Cabinet details. Requests use
store:false, which does not promise zero provider retention. Gemini label extraction and Perplexity product enrichment below are separate scanner services. - Gemini for AI extraction of product label images and text.
- Perplexity for product, safety, warning, interaction, and source-context enrichment.
- Google Analytics 4 for public website analytics, traffic-source reporting, page view measurement, and App Store click measurement; Google Firebase Analytics for separately enabled native install and subscription analytics and, with an additional native choice and current iOS tracking permission, Google advertising measurement. Personalized advertising remains disabled.
These providers receive only the information needed for the services they support.
Your choices
- You can choose whether to grant camera, photo library, notification, and HealthKit permissions.
- You can disconnect HealthKit permissions in iOS Settings.
- You can delete your Stack My Med account in the app or follow the instructions on the account deletion page.
- You can cancel an active Apple subscription in your Apple ID subscription settings.
- You can manage Apple tracking and advertising settings in iOS Settings.
- In app versions that offer Measurement choices, you can separately enable or disable Google install and subscription analytics and Google advertising measurement in Profile. Advertising measurement also requires current iOS tracking permission; neither choice is required to use the app.
- You can decline Advisor processing, withdraw a previous acknowledgement, or re-acknowledge later. Withdrawal is separate from deleting retained Advisor content.
- You can keep saved Advisor history off, explicitly opt in while Premium is active, export or delete retained history, and retain read/export/delete access if Premium later lapses.
- In the public web funnel, select “Allow all” to allow the disclosed analytics and advertising measurement, including hashed-email matching, or select “Choose” to review the optional setting and save your selection. Reopen the settings using the “Cookies” link at the bottom of the page. Turn off “Analytics and ad measurement” and select “Save selection” to withdraw consent for subsequent optional measurement and email matching. Withdrawing consent does not undo processing that already occurred.
Turning off native Google measurement stops future submissions by the app, disables Google analytics collection and resets local Google analytics data. It cannot recall requests or data already sent. Signing out or deleting your Stack My Med account resets local Google measurement, but does not automatically erase Google's previously collected records. Contact support@stackmymed.com about data already sent. We do not promise that a local reset is a completed remote erasure request. If the app cannot save a choice because local storage is unavailable, it disables measurement for that session and reports the failure; retry and check your saved choices after restarting.
Contact
For privacy questions, support requests, or account deletion help, email support@stackmymed.com.