YOUR PRIVATE JOURNAL

Privacy Policy

This policy covers PainTrack. Encrypted backups, appointment-summary exports, saved drafts, and entry corrections are available from version 1.1. PainTrack is a personal journal without a PainTrack account, journal-sync cloud, analytics, advertising, or subscription service.

What the app stores

PainTrack stores information you choose to record in the app’s local database. This can include No Pain or pain outcomes, categorical pain states, precise raw body-map selections and radii, timestamps and local time context, notes, your chosen body illustration, and reminder settings.
Unfinished check-ins are saved automatically in the same protected local storage so you can continue later. You can discard a draft from its check-in screen. When you correct a saved entry, PainTrack keeps earlier versions with that entry, including their original notes and body locations. History, patterns, and summaries use the latest version.
Raw spatial selections are preserved separately from any anatomical label that may later be derived from them. The app does not ask for your name, email address, date of birth, gender, diagnosis, medications, food, activity, sleep, or account credentials. The separate, optional public support form is described below.
Calendar views, pain-frequency views, and appointment summaries are calculated on your device from your saved records. Optional discussion text you enter for an appointment summary is used for that summary and is not added to your saved check-ins.

Where the information goes

There is no PainTrack account, journal-sync server, or developer-operated backup service in this version.
The app does not sell or share your journal with advertisers or data brokers.
The app does not include analytics, advertising, or third-party sign-in SDKs.
On iOS, PainTrack applies Apple’s backup-exclusion setting to its database directory and files. Apple describes that setting as guidance to the system, not a guarantee. On Android, PainTrack disables app backup and device-transfer extraction.
Operating-system backup, restore, migration, security, and storage behavior is controlled by the device platform and may change outside PainTrack. PainTrack does not operate its own backup or restore server. The optional backup file described below is created only when you request it.
If you use the web version, records stay in that browser’s local website storage. Browser or operating-system tools can clear or otherwise manage that storage.

Backups you choose to save

When you choose Save encrypted backup, PainTrack encrypts a copy of your journal on your device using the password or passphrase you enter. The backup includes saved check-ins, notes, exact body-map locations, recorded dates and times, unfinished drafts, earlier versions of corrected entries, and your illustration choice. Reminder settings and notification permissions remain on each device.
You choose where to save the encrypted file using your device’s save or share sheet, or your browser’s download controls. PainTrack does not upload it to a PainTrack server or keep a copy for the developer. A file-storage or sharing service you select may store or transfer the file under its own policies. Keep the file and its password safe; PainTrack cannot recover a lost file or forgotten password.
To restore, you choose a backup file and enter its password. PainTrack opens and checks it locally, then shows a summary for you to review before you choose Restore this journal. Restoration is allowed only in an empty journal, so it does not merge with or overwrite existing check-ins or unfinished drafts. Your backup password is not saved in the journal or sent to the developer.

Appointment summaries you choose to share

You choose the reporting dates and review the summary before selecting Export PDF. Check-in notes are excluded by default and are included only when you turn on Include check-in notes. Optional discussion text you enter is included in the summary. Export opens your device’s share sheet or your browser’s print dialog so you can decide whether to save a copy or send it somewhere.
Appointment PDFs are not encrypted or password-protected by PainTrack. Anyone who can access a copy can read the information it contains. Review its contents and your chosen destination before sharing. A person, app, email service, printer, or storage provider you choose may receive or retain the report under their own practices. PainTrack does not automatically send reports to the developer, a clinician, or any other recipient.

Temporary export files

Creating an export can place a temporary file in PainTrack’s private app cache. Backup files in that cache are encrypted; appointment PDFs are not. iOS removes completed export copies after the share sheet closes. Android may retain a copy so the app you selected can finish reading it; it is cleared when you next export that type of file or use the Settings erase control. Interrupted exports can also leave temporary copies until a later cleanup.
In the web version, PainTrack offers encrypted backup files for download and opens temporary appointment-report previews for printing. The Settings erase control closes any report previews still managed by PainTrack. It cannot remove files already downloaded or saved elsewhere.

Optional support requests

PainTrack does not automatically transmit your pain journal, body-map selections, severity, notes, settings, reminders, app usage, or diagnostics. If you choose Open support form, the app opens the public Support page in your system browser without sending or prefilling app or device data.
If you affirmatively submit that form, you provide your name, reply email address, selected topic, and a technical description. Submission is optional and does not affect access to PainTrack. The form accepts no attachments or screenshots. Do not include pain locations, symptoms, diagnoses, medications, journal notes, or other health or sensitive information.
The Support page is hosted through Expo Application Services on Cloudflare infrastructure. The host necessarily processes ordinary web-request information, such as IP address, browser type, referring page, and access time, to serve and protect the page. The form sends the fields you enter through a minimal PainTrack relay and Amazon Simple Email Service to the developer’s private support inbox. The relay does not keep a ticket database, attach app data, or forward your IP address in the support message. Amazon and the private mailbox provider may process limited delivery, security, and backup records under their own policies and legal obligations.
Support information is used only to respond to and troubleshoot the request, protect the form from abuse, or complete a privacy request. It is not used for analytics, advertising, marketing, profiling, sale, or tracking. The form has no advertising or analytics scripts, tracking pixels, third-party form SDK, CAPTCHA, account creation, or file upload.
Support correspondence is kept only as long as needed to handle the request. An inactive request is ordinarily closed after 30 days without a reply, and its active support-mailbox copy is typically deleted within 30 days after closure, except when security or law requires longer retention. Service providers may keep limited delivery, security, and backup records under their own retention policies. To request access, correction, or deletion, choose Erasing local data or privacy on the same form and use the same reply address; we may verify control of that address. The support service cannot access, restore, or erase your local PainTrack journal.
You consent separately each time you select Send. You may withhold consent by not submitting the optional form, or withdraw it later by making a privacy request through the same page. If you are under 13, ask a parent or guardian to submit a request.

Notifications

If you enable reminders, PainTrack schedules them locally on your device. Notification previews use neutral wording and do not display pain locations or states. The current app does not register for remote push notifications.

Retention and your control

Records remain until you erase them in Settings, clear the browser’s website data, or remove the app and its local data. The Settings erase control removes check-ins, unfinished drafts, earlier versions of corrected entries, raw and derived locations, notes, body illustration choice, reminder settings, and scheduled PainTrack notifications from PainTrack on that device. It also attempts to remove temporary export files managed by PainTrack and reports a warning if that cleanup could not be completed.
Erasing data in PainTrack cannot delete encrypted backups, PDFs, printed reports, or other copies you saved outside the app or sent to someone else. Manage those copies with the destination or recipient you chose. The developer and support service cannot retrieve a lost journal or recover your backup password. If you want to keep your journal when changing devices or removing the app, save an encrypted backup and confirm you have both the file and its password first.

Questions and future changes

Use the public Support page for technical questions or privacy requests. If you are testing through TestFlight, you can also use TestFlight’s Send Beta Feedback control. In either case, avoid private health details and screenshots. We will update this policy and the App Store privacy disclosure before releasing features that change how your information is handled, such as accounts, cloud sync, analytics, or another data flow.