App Icon (Original)
It's a Match - Download
Download on the App Store

Privacy Policy

This Privacy Policy explains what personal data we process when you use the Preppy app and the Preppy website, why we process it, how it is stored, who receives it, and what rights you have. It applies worldwide, wherever you use Preppy, and contains additional sections for users in specific countries and regions.


Preppy is a deeply personal app. It holds information about your HIV status, your medication, your test results, your sex life and the people you have sex with. We take that seriously, and we have written this policy to be specific rather than vague. If anything here is unclear, write to hello@preppy.health and we will answer.


1. The Short Version

Before the detail, the essentials:

  • Preppy is not a medical device and does not replace a doctor. See Section 3.

  • We do not sell your personal data. We never have and we will not.

  • We do not run advertising, retargeting, ad profiles or cross-app tracking, and we are not part of any advertising network.

  • We do not use your personal data to train AI models, and we do not send your content to AI providers.

  • Your health and sex data is never used for marketing.

  • You can use Preppy with an anonymous account that is not connected to your name, email address or phone number.

  • Your data is stored in the European Union, under EU law, and stays there in normal operation. See Section 5.3.

  • Your entries are stored denormalized and pseudonymously: no single record combines your identity with your full health and sex history. See Section 6.

  • For product analytics we use TelemetryDeck, a privacy-focused service hosted in Germany that does not use cookies, IP addresses or persistent cross-app identifiers.

  • We may use aggregated, anonymized data for scientific research into PrEP, HIV prevention and sexual health. See Section 10.

  • The app has a built-in lock (Face ID / Touch ID / passcode), and a discreet notification style so reminders on your lock screen do not give you away.

  • We process as little data as possible, and only for as long as necessary.


2. Controller and Contact

2.1 Controller

The controller responsible for the processing described here under the EU General Data Protection Regulation (GDPR) and equivalent laws is:

Kevin Waltz
Wiltbergstraße 50
13125 Berlin
Germany
Email: hello@preppy.health


Further mandatory information is available in our Legal Notice at https://www.preppy.health.

2.2 Data Protection Officer

We are not legally required to appoint a Data Protection Officer under Art. 37 GDPR for the current scope of our processing. For all privacy matters, please contact hello@preppy.health directly.

2.3 EU / UK Representative

The controller is established in Germany, in the European Union, so no Art. 27 GDPR representative is required. For users in the United Kingdom, we can be reached at the address above.


3. Important Medical Notice

This section is central to understanding what Preppy is, and what it is not. Please read it carefully.

3.1 Preppy Is Not a Medical Device

Preppy is not a medical device, in-vitro diagnostic device, medical product or healthcare service within the meaning of Regulation (EU) 2017/745 (MDR), the German Medical Devices Implementation Act (MPDG), the UK Medical Devices Regulations 2002, the US Federal Food, Drug, and Cosmetic Act, or comparable legislation in other countries.


Preppy is not intended by its manufacturer for any medical purpose within the meaning of Art. 2(1) MDR. It is not intended for the diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of any disease, injury or disability. It is a personal self-tracking and organization tool: a place to record what you already know about yourself.

3.2 No Medical Advice, Diagnosis or Treatment Recommendation

Nothing in Preppy constitutes medical advice, a diagnosis, a prescription or a treatment recommendation. This includes, without limitation:

  • intake reminders and adherence streaks for PrEP, ART or DoxyPEP,

  • the calculation and display of protection windows, intake schemes and DoxyPEP time windows,

  • the labelling of a logged encounter as "risky" or "trusted",

  • check-up reminders and test result overviews,

  • statistics, calendars, charts and summaries of any kind.


These are conveniences for organizing information you have entered yourself. They are calculated from your own inputs and are only as accurate as those inputs. They are not a clinical assessment.

3.3 Preppy Does Not Protect You

Preppy does not protect against HIV, other sexually transmitted infections, or pregnancy. Only correct use of PrEP, condoms, treatment and regular testing does. Logging a pill in the app does not mean you have taken it, and marking an encounter as protected does not make it so.

3.4 Always Consult a Healthcare Professional

Always consult a qualified doctor, clinic, sexual health service or pharmacist regarding starting, changing, pausing or stopping PrEP, ART or DoxyPEP, regarding your HIV or STI status, regarding test results, side effects, kidney or liver values, and regarding any other health concern. Never delay seeking professional advice, and never disregard advice you have received, because of something displayed in Preppy.

3.5 Emergencies and PEP

Preppy is not suitable for emergencies and does not monitor you. In a medical emergency, contact emergency services immediately (112 in the European Union, 911 in the United States, 999 in the United Kingdom, or your local emergency number).


If you think you may have been exposed to HIV, post-exposure prophylaxis (PEP) is time-critical and must be started as soon as possible, ideally within a few hours and no later than 72 hours after exposure. Go directly to an emergency department, HIV clinic or sexual health service. Do not use Preppy to decide whether you need PEP.

3.6 No Liability for Health Decisions

Kevin Waltz accepts no liability for health decisions made on the basis of data tracked in, or information displayed by, Preppy. Use of the app is at your own risk. Statutory liability, in particular for injury to life, body or health and for intent and gross negligence, remains unaffected.

3.7 Why This Matters for Your Privacy

Because Preppy is not a healthcare service and we are not your healthcare providers, we cannot rely on the legal bases that hospitals, doctors and clinics rely on when they process health data. We are also not bound by medical confidentiality in the way a physician is. Instead, we process your health and sex data on the basis of your explicit consent, which you can withdraw at any time. Section 8.1 explains this in detail. In practical terms, it means the decision to put a piece of health information into Preppy is always yours, and always reversible.


4. What Data We Process

Depending on how you use Preppy, we process the following categories of personal data.

4.1 Account Data

  • A pseudonymous account identifier (a randomly generated Firebase user ID)

  • Your authentication method (anonymous, Sign in with Apple, or email and password)

  • Your email address, but only if Apple passes one on when you sign in. If you use Sign in with Apple with "Hide My Email", we only ever receive Apple's private relay address, not your real one. Where an email address exists it is held inside Firebase Authentication only; it is never written into your profile record or attached to any of your health, encounter, partner or location entries.

  • A salted password hash, if an email and password sign-in is used. We never see the password in plain text.

  • Your registration date

  • Optionally: a display name and a profile picture, both of which you choose and can leave empty

  • Your region and language code, used to format dates and select content

4.2 Health Data (Special Category Data)

  • Your HIV status (negative, positive, positive and undetectable, or unknown)

  • Whether you take PrEP, and under which scheme (daily or event-based / 2-1-1)

  • Whether you take antiretroviral therapy (ART)

  • Whether you use DoxyPEP

  • Every individual intake you log, with its exact date and time and the medication type

  • Your intake start and end dates, extensions and pauses

  • Your preferred daily intake time

  • Check-ups and appointments: date, free-text notes, the place, and the appointment type — which may itself be revealing, since the available types include STI screening, PrEP, ART and DoxyPEP follow-ups, vaccination, dermatology, urology, proctology and mental health

  • Test results: for HIV, syphilis, chlamydia, gonorrhea, trichomoniasis, hepatitis A, B, C and AB, herpes simplex 1 and 2, HPV, mpox, mycoplasma, ureaplasma, kidney values, and any custom test you add yourself, each recorded as positive, negative or pending

4.3 Sex Life Data (Special Category Data)

  • Logged encounters, with start and end time and duration

  • The number of partners involved, and which saved partners were linked

  • Whether protection was used

  • The type of penetration (for example anal, vaginal, oral) and sexual positions

  • The number of orgasms

  • A personal rating

  • Free-text notes

  • Solo activity entries and counters

  • Whether an encounter was classified as risky behaviour, derived from the above

4.4 Data About Other People (Partners)

For each partner you save, whatever subset of the following you choose to enter:

  • A name, or an anonymous placeholder if you use anonymous mode

  • Age, gender, trans status, pronouns, ethnicity, body type, sexual position

  • Anatomical details, including penis size and circumcision status

  • The partner's HIV status, as known or assumed by you

  • A rating and free-text notes

  • A profile photo and a photo gallery

  • Contact details and social media handles: phone number, Instagram, Snapchat, X/Twitter, Grindr, Romeo, OnlyFans, and a free-form handle

  • Whether the partner is archived, and whether the partner is marked as trusted


Section 9 deals specifically with this category, because it is data about people other than you.

4.5 Location Data

  • Places you save and attach to encounters or check-ups: a title, a city and country line, exact latitude and longitude coordinates, and, where Apple provides one, a stable Apple Maps point-of-interest identifier

  • The coarse position of your device while a map is open, if and only if you grant location permission


Location data attached to an encounter is, in combination, sensitive: it records where you had sex and when.

4.6 Images

  • Your profile picture

  • Partner profile pictures and gallery images

4.7 Technical and Usage Data

  • App version, operating system version, device type, device model class and language

  • Anonymized product analytics events, described in Section 7.13

  • Error and diagnostic information generated when something goes wrong

  • Server-side logs of the infrastructure providers we use, including IP addresses

4.8 Communication Data

  • The content of feedback and support messages you send us, together with app version, iOS version, device class and a debug flag

  • Our replies, and the read status of those replies

  • The content of any email you send us, and your email address

4.9 Device-Local Settings

Some preferences never leave your device, or are only shared between the app and its widgets on the same device. These include your chosen app icon, tab bar arrangement, biometric lock settings, notification schedules, and cached widget snapshots.


Only the data required to run an account is mandatory. Everything else — your name, your photo, every health field, every partner field, every location, every note — is optional. Preppy works if you leave all of it empty. Fields you do not fill in are not stored.



5. Where the Data Lives

5.1 On Your Device

A substantial part of Preppy runs locally. Your images are written to the app's private container and indexed in a local SwiftData database before any upload. Pending intakes and solo activities logged from a widget, a Shortcut or Siri are buffered locally and synced when the app next opens. Widget snapshots, your notification schedule, your app lock configuration and your interface preferences are stored in the app's local storage and in a shared App Group container that only Preppy and its own widgets can read. Other apps on your device cannot access any of this.

5.2 In the Cloud

Your account and your entries are synced to Google Firebase so that they survive a lost phone and follow you to a new device:

  • Cloud Firestore stores your account record and all your entries.

  • Firebase Storage stores your images.

  • Firebase Authentication stores your login credentials.


The Firebase project is operated by us. Google acts as our processor under a Data Processing Agreement.

5.3 Storage Region

Your data is stored in the European Union. Cloud Firestore runs in Google's Europe multi-region, which replicates the database across data centres inside the EU, and Firebase Storage is likewise located in the EU. Your health entries, encounters, partner records, places and images therefore live on European infrastructure, and are not stored in the United States. Analytics is processed separately by TelemetryDeck on servers in Germany.

5.4 What Never Leaves Your Device

The following are never uploaded to our servers:

  • Your device passcode, Face ID or Touch ID data. Biometric authentication is handled entirely by Apple's Secure Enclave; we only ever receive a yes-or-no result.

  • Health data you write into Apple Health.

  • Calendar events we create on your device.

  • Your precise live GPS position. We use it only to centre the map while you are looking at it. Only a place you deliberately save is stored.

  • Your photo library. We only receive the individual images you pick.



6. How Your Data Is Stored: Denormalized and Pseudonymous

This section explains our storage architecture, because it materially affects your privacy and it is unusual enough to be worth stating plainly.

6.1 Separate Records Instead of One Profile

We do not store one large document per user containing everything about you. Each records carries only a pseudonymous account identifier — a random string generated by Firebase — as the link back to you. None of them contains your name, your email address, your phone number or any other direct identifier. An individual record read in isolation says, for example, that some account logged a condomless encounter at a given time. It does not say who that account belongs to.


This is what we mean when we say the data is stored denormalized and pseudonymously. It is not marketing language: it is how the database is actually laid out, and it is the reason we can analyze usage patterns and produce research statistics without ever needing to touch your identity.

6.2 Access Control

Every record is bound to the account identifier that created it. Our server-side security rules are configured so that a signed-in account can only read and write its own records. No user of Preppy can see another user's data. There is no social layer, no discovery, no matching between users, no messaging and no public profile. Despite the tagline, Preppy never connects you to other Preppy users.

These rules are enforced on the server, not in the app, so they cannot be bypassed by a modified or reverse-engineered client. A request for a record belonging to a different account is rejected by the database itself.

6.3 What We Can See

We, as the operator, technically have administrative access to the database, as any operator does. We access individual records only when it is strictly necessary — to investigate a specific bug you have reported, to respond to a support request from you, or where we are legally compelled. We do not browse user data. Any statistical or research work is performed on aggregated data, as described in Section 10.



7. What We Do With Your Data, Feature by Feature

7.1 Account and Sign-In

Preppy requires an account so that your data can sync and survive device loss. Authentication runs through Firebase Authentication, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

You have two options:

  • Anonymous account. Preppy creates a random account identifier with no email address, no name and no link to your Apple ID. This is the most private option, and it is offered on equal footing with the other one rather than buried. Its limitation is real and you should understand it before choosing it: if you lose your device, uninstall the app or sign out, that account and everything in it cannot be recovered by us or by anyone else, because there is nothing to prove it was yours.

  • Sign in with Apple. Apple confirms your identity and passes us an identifier and, if you allow it, an email address. If you choose "Hide My Email", Apple generates a private relay address and we never learn your real one. An existing anonymous account can be upgraded to Sign in with Apple, keeping the same account identifier, so your data carries over and nothing is duplicated.


We do not offer social logins such as Google or Facebook, and we do not use phone number verification, so no third-party social network learns that you use Preppy.


Legal basis: performance of a contract, Art. 6(1)(b) GDPR, and our legitimate interest in securing the sign-in process, Art. 6(1)(f) GDPR.

7.2 Health Profile

Your HIV status, PrEP scheme, ART scheme and DoxyPEP usage are stored in your account record and drive what the app shows you. Every one of these fields is optional and every one can be hidden from the Health tab and from your Profile independently, or cleared entirely.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR, in conjunction with Art. 6(1)(a) and (b) GDPR.

7.3 Intake Tracking and Reminders

Each pill you log is stored as an individual record with a date, a time and a medication type.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR.

7.4 Encounters and Solo Activities

Encounters are stored as individual records with the details listed in Section 4.3. From them the app derives whether an encounter counts as risky behaviour, which in turn drives DoxyPEP windows and calendar warnings. Every field beyond the date is optional, and you can hide fields you never use from the entry form entirely, so they are never even offered.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR.

7.5 Partners

Partner profiles are stored as individual records linked to your account. Encounters reference partners by identifier rather than repeating their details. Marking a partner as trusted changes how risk is calculated for encounters involving only that partner. Archiving keeps a partner out of your active list without deleting the record. See Section 9 for the specific obligations that come with storing data about other people.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR, and, as regards the partner as a third party, Section 9.

7.6 Check-Ups and Test Results

Check-ups are stored with their date, type, notes and place. Test results are embedded within the check-up record, each with a test type and a result, including a pending state for results you are still waiting on.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR.

7.7 Places and Maps

When you attach a place to an encounter or a check-up, we store a title, a city and country line and exact coordinates as a separate place record, so that a place you use often is stored once. Map display, search and address lookup are provided by Apple's MapKit. Requests to Apple's mapping services carry your device's IP address and the search terms you type, and are subject to Apple's privacy policy; we do not send Apple your account identifier, your health data or the reason you are searching.


If you grant location permission, we use your position solely to centre the map while it is open. Preppy never tracks your location in the background, and your live position is never stored or transmitted to us. Only the place you deliberately pick is saved.


Legal basis: your consent for the device permission, Art. 6(1)(a) GDPR, and your explicit consent for the resulting record, Art. 9(2)(a) GDPR, since a place attached to an encounter reveals information about your sex life.

7.8 Images

Images you select are compressed and written to the app's private container, then uploaded to Firebase Storage under a path scoped to your account. The image itself is stored in Storage; only a reference — a storage path, an image ID and a timestamp — is written into the corresponding account or partner record. Deleting an image deletes the stored object and the reference.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR.

7.9 Apple Health

If you choose to, Preppy can write a logged encounter to Apple Health as a "Sexual Activity" sample, including whether protection was used. This is a one-way write to your own device. We never read anything from Apple Health, and Apple Health data never reaches our servers. You control this per encounter, or you can set it to always or never. Permission is managed by iOS and can be revoked at any time in the Health app or in Settings.


Legal basis: your explicit consent, Art. 9(2)(a) GDPR.

7.10 Device Calendar

If you choose to, Preppy can add a check-up to your device calendar and keep it in sync when you change the date. We store only the calendar event identifier so that we can find and update the same event later. The event is created on your device through Apple's EventKit and syncs wherever your calendar syncs, which may be iCloud or a third-party account you have configured — outside our control. Be aware that a calendar event may be visible to anyone with whom you share that calendar. Permission is managed by iOS and can be revoked at any time.


Legal basis: your consent, Art. 6(1)(a) GDPR.

7.11 Notifications

Preppy uses local notifications only. Reminders for intakes, DoxyPEP windows and check-ups are scheduled and delivered entirely on your device by iOS. We do not operate a push server, we do not use Firebase Cloud Messaging or the Apple Push Notification service, we do not store a device token, and no notification content ever passes through our systems. Notification permission is managed by iOS and can be revoked at any time.


Legal basis: your consent, Art. 6(1)(a) GDPR.

7.12 App Lock

You can lock the app behind Face ID, Touch ID or your device passcode, so that someone with physical access to an unlocked phone still cannot open Preppy. Authentication is performed by iOS; we receive only a success or failure result and never any biometric data. Biometric templates never leave Apple's Secure Enclave and are never accessible to us.


You can also choose a discreet notification style, so that reminders appearing on your lock screen do not reveal what the app is for or what medication you take.


Legal basis: our legitimate interest and yours in protecting highly sensitive data on a shared or lost device, Art. 6(1)(f) GDPR.

7.13 Product Analytics — TelemetryDeck

To understand which features are used and where the app is confusing or broken, we use TelemetryDeck, a service of TelemetryDeck GmbH, Hamburg, Germany. All processing and storage takes place on servers in Germany.


TelemetryDeck is built for privacy: it sets no cookies, builds no cross-app or cross-device profiles, uses no advertising identifiers, and passes nothing to advertising networks. IP addresses are not stored. Your account identifier is never transmitted in the clear: it is hashed with SHA-256 on your device before it leaves the app, and hashed again with a server-side salt by TelemetryDeck on receipt, so what is stored is a pseudonym that cannot be reversed into your account identifier. Timestamps are rounded.


What TelemetryDeck receives:

  • Event names describing actions, such as an intake being logged, an encounter being saved, a partner being saved, a check-up being created, a screen being viewed or a button being tapped

  • Coarse parameters attached to some events, such as the kind of medication (PrEP, ART or DoxyPEP), an intake scheme, whether reminders were switched on, the chosen accent colour, or whether a permission prompt was granted

  • App version, operating system version, device type and language

  • The hashed pseudonym and a rounded timestamp



What TelemetryDeck never receives:

  • Any free-text you write: notes, feedback text, partner names, place names

  • Any partner data, image, coordinate or address

  • Your email address, your real name or your raw account identifier

  • The date, time or duration of any specific encounter or intake

  • Any test result


Legal basis: our legitimate interest in understanding and improving the app, Art. 6(1)(f) GDPR, and, as regards the health-related parameters described above, your explicit consent, Art. 9(2)(a) GDPR.

7.14 Error Reporting

When an operation fails, the app records the technical error internally so that problems can be diagnosed. We do not use Firebase Crashlytics, Firebase Analytics, Firebase Performance Monitoring or any comparable third-party crash reporting service. Apple provides us with aggregated, anonymized crash and performance statistics through App Store Connect if you have enabled sharing of analytics with developers in your iOS settings; this is controlled by Apple and can be switched off under Settings → Privacy & Security → Analytics & Improvements.


Legal basis: our legitimate interest in a stable and secure app, Art. 6(1)(f) GDPR.

7.15 Feedback and Support

When you send feedback from within the app, we store your message, its type, the date, your account identifier, and technical context: app version, iOS version, device class and whether it was a debug build. This lets us reply to you in the app and reproduce the problem. Our replies are stored alongside your message.


Please do not include health details, partner names or other sensitive information in feedback unless it is genuinely necessary to describe the problem.


Legal basis: performance of a contract, Art. 6(1)(b) GDPR, and our legitimate interest in providing working support, Art. 6(1)(f) GDPR.

7.16 App Store Distribution and Review Prompts

Preppy is distributed through the Apple App Store. Apple operates the download and the store account, and is an independent controller for that processing under its own privacy policy. Preppy is free and contains no in-app purchases or subscriptions, so there is no payment processing at all.


The app may occasionally ask you to rate it using Apple's standard StoreKit review prompt. This prompt is displayed and handled by iOS. We do not learn whether you rated the app or what you wrote.


Legal basis: our legitimate interest in distributing and improving the app, Art. 6(1)(f) GDPR, and your consent for TestFlight participation, Art. 6(1)(a) GDPR.

7.17 Website

Our website at www.preppy.health provides information about the app and hosts this policy, our Terms of Use and our Legal Notice. When you visit it, the hosting provider processes technically necessary connection data, including your IP address, the time of access, the page requested, the volume of data transferred, and your browser and operating system, in order to deliver the page and protect against attacks. We do not use analytics, tracking or advertising cookies on the website.


Legal basis: our legitimate interest in a secure and functioning web presence, Art. 6(1)(f) GDPR.



8. Legal Bases in Detail

8.1 Health and Sex Life Data

Most of what Preppy stores is special category personal data under Art. 9(1) GDPR: data concerning health, and data concerning a natural person's sex life and sexual orientation. Processing this data is prohibited by default and requires a specific exception.

We rely on your explicit consent under Art. 9(2)(a) GDPR. This is a deliberate choice. We do not rely on Art. 9(2)(h), the exception for the provision of health care, because we are not healthcare providers and Preppy is not a healthcare service — Section 3 explains this. We do not rely on Art. 9(2)(i) or on any public interest ground.


Practically, this means:

  • Consent is granular in effect: every health and sex field is optional, and choosing not to enter something means it is never processed. Nothing is pre-filled and nothing is inferred.

  • Consent is given by a deliberate act on your part. Each piece of health or sex life information exists in Preppy because you chose to type it in, for a purpose that is visible to you at the moment you do it.

  • You can withdraw consent at any time, for everything or for a particular area, by deleting the relevant entries or by clearing the relevant fields. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

  • If you withdraw consent for the core health functions, we can no longer provide those functions. The app cannot track PrEP adherence without knowing that you take PrEP.


Under German law, § 22 BDSG additionally applies, and we implement the safeguards required by § 22(2) BDSG, which are described in Section 15.

8.2 Other Data

Where processing does not concern special category data, we rely on:

  • Art. 6(1)(b) GDPR, performance of the contract of use, for account management, sync and support

  • Art. 6(1)(f) GDPR, legitimate interests, for security, abuse prevention, stability, analytics and improvement of the app

  • Art. 6(1)(a) GDPR, consent, for device permissions and for optional features

  • Art. 6(1)(c) GDPR, legal obligation, where we are required to retain or disclose data



9. Data About Other People

Preppy lets you record information about other people: names, ages, photos, anatomical details, contact details, social media handles and their HIV status. This is other people's personal data, and much of it falls into more than one special category at once. A partner's HIV status is health data. Their sexual position, anatomical details and the encounters they appear in are data concerning sex life. Their gender and trans status may reveal gender identity or sexual orientation. Their ethnicity is data revealing racial or ethnic origin. Together with a name, a photo, a phone number and a Grindr handle, a single partner record can be one of the most sensitive documents a person could hold about someone else. This section sets out how we handle it and what we expect from you.

9.1 Your Role

If you use Preppy purely for your own personal purposes, your own processing of partner data is generally covered by the household exemption in Art. 2(2)(c) GDPR, so the GDPR does not impose controller obligations on you personally. That exemption is narrow: it does not apply if you use the data for professional or commercial purposes, publish it, or share it outside a purely personal context. If you fall outside the exemption, you are the controller for that data and responsible for complying with data protection law.


Regardless of the exemption, we are the controller for hosting and storing that data, and we apply everything in this policy to it.

9.2 What We Expect From You

  • Enter only what you actually need. Use anonymous mode, which stores a partner without a personal name, whenever a name is not necessary. Hide the partner fields you never use so the app stops asking for them.

  • Do not upload photos of other people without their agreement, and never upload intimate images without their explicit and current agreement. Sharing intimate images without consent is a criminal offence in many countries.

  • Treat another person's HIV status as the most sensitive thing you can write down. In several jurisdictions, disclosing someone's HIV status without their consent is unlawful and can be prosecuted.

  • Do not enter data about children.

  • Keep in mind that a note about someone else is still about them, and they may have rights over it.

9.3 Rights of the People You Record

If someone believes their data is stored in Preppy by another user and contacts us, we will handle the request under applicable law. There is a practical limit we should be honest about: partner records are pseudonymous and are not indexed by name, phone number or handle, so in most cases we have no reliable technical means of locating a specific individual's data across all users, and we cannot confirm whether they appear in anyone's app. Where we can identify the data, and where we are legally required to act, we will. Requests go to hello@preppy.health.

9.4 Deletion

Deleting a partner deletes the partner record and its images. Encounters that referenced that partner remain, but no longer point to an existing profile.



10. Scientific Research and Aggregated Use

We want Preppy to contribute something back to the field it belongs to. PrEP adherence, DoxyPEP uptake, testing frequency and sexual health behaviour are areas where real-world data is scarce, and the community that uses this app is the community that stands to benefit from better data about it.

10.1 What We Do

We may use data from Preppy in aggregated form for scientific research and statistical purposes, including:

  • research into PrEP and ART adherence patterns, and what helps or hinders them

  • research into DoxyPEP uptake and use

  • research into testing frequency, check-up intervals and gaps in care

  • research into sexual health behaviour and prevention at a population level

  • public health reporting, and collaborations with universities, research institutions and public health bodies

  • development, evaluation and improvement of the app itself

10.2 How We Do It, and the Limits We Set Ourselves

  • We aggregate. Research outputs describe groups, not individuals: for example, the share of users on a daily scheme who log an intake at least six days a week, or the median interval between check-ups.

  • We anonymize before analysis. Account identifiers, names, email addresses, images, free-text notes, contact details, social media handles and exact coordinates are removed or irreversibly replaced. Dates are generalized, for example to a week or a month. Coordinates, where used at all, are reduced to a coarse region such as a city or country.

  • We suppress small numbers. We do not publish or share any figure derived from a group small enough to allow an individual to be recognized.

  • We never share individual-level records. No researcher, institution, partner or third party receives per-user data. They receive aggregate figures.

  • We never use research data for advertising, marketing, commercial profiling, insurance, credit scoring, or any decision about an individual.

  • We never sell data, aggregated or otherwise.

  • We do not use your data to train AI models, and we do not send it to AI providers.

  • Partner data — information about other people — is excluded from research use entirely, other than in the form of counts that reveal nothing about any individual, such as the number of partners in a period.


Once data has been aggregated and anonymized in this way, it is no longer personal data, and data protection law no longer applies to it. The step of anonymizing your data is itself processing, and we set out its legal basis below.

10.3 Legal Basis

For the anonymization step and for statistical processing before anonymization is complete:

  • Art. 6(1)(f) GDPR, our legitimate interest in scientific research and public health knowledge, read together with Art. 5(1)(b) GDPR, which treats further processing for scientific or statistical purposes as compatible with the original purpose, and Art. 89(1) GDPR, which requires the safeguards described above

  • Art. 9(2)(j) GDPR, processing necessary for scientific research purposes in accordance with Art. 89(1), together with § 27 BDSG under German law

  • Where we go beyond aggregated and anonymized use — for example, if we ever wanted to run a study on individual-level data, or share pseudonymized data with a research partner — we will ask for your separate, explicit and specific consent under Art. 9(2)(a) GDPR first. We will not do it silently, and we will not treat continued use of the app as consent.

10.4 Your Right to Object

You can object to the use of your data for research purposes at any time, without giving a reason, by writing to hello@preppy.health. We will exclude your data from research processing going forward. We cannot retract statistics that have already been aggregated and published, because at that point your data is no longer identifiable within them and cannot be isolated.



11. Recipients of Your Data

We disclose personal data only where it is necessary to provide the service, where you have consented, or where we are legally required to.


Processors, acting on our documented instructions under Art. 28 GDPR:

  • Google Ireland Limited, Ireland, and Google LLC, United States — Firebase Authentication, Cloud Firestore and Firebase Storage

  • TelemetryDeck GmbH, Germany — product analytics

  • Our website hosting provider — delivery of www.preppy.health


Independent controllers, processing under their own privacy policies:

  • Apple Inc. and Apple Distribution International Ltd. — App Store distribution, Sign in with Apple, TestFlight, MapKit, Apple Health, iCloud calendar sync and App Store Connect analytics


We may also disclose data to courts, law enforcement or public authorities where we are legally obliged to do so, and to legal or tax advisors bound by professional confidentiality where necessary to establish, exercise or defend legal claims. We will resist overbroad requests and, where legally permitted, notify you.


We have no advertising partners, no data brokers, no marketing agencies and no analytics resellers.


An up-to-date list of processors is available on request at hello@preppy.health.



12. International Data Transfers

Your data is stored in the European Union and stays there in normal operation. Cloud Firestore and Firebase Storage are located in the EU, Firebase is contracted through Google Ireland Limited, and TelemetryDeck processes exclusively in Germany. There is no routine transfer of your health entries, encounters, partner records, places or images to any third country.

Some contact with providers outside the EEA is nevertheless possible, and we would rather name it than imply it never happens. Google's parent company in the United States may access data in limited circumstances, such as support and maintenance of the platform. Apple processes data in the United States for the services described in Section 7 — Sign in with Apple, App Store distribution, TestFlight and map search — which involve identifiers and technical data rather than the contents of your entries.

Where personal data does reach a country outside the European Economic Area that has not received an adequacy decision, in particular the United States, we rely on:

  • certification under the EU–US Data Privacy Framework, where the provider is certified — Google LLC and Apple Inc. are certified, and equivalent extensions apply for the UK and Switzerland; and

  • the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by additional technical and organizational measures including encryption in transit and at rest.


You may request a copy of the relevant safeguards at hello@preppy.health.



13. Retention

We keep personal data only as long as necessary:

  • Account data, health data, encounters, partners, check-ups, places and images: for as long as your account exists, or until you delete the individual entry.

  • Individual entries: deleted immediately when you delete them, subject to the propagation delay for embedded copies described in Section 6.2 and to short-lived provider backups.

  • Backups: in addition to the point-in-time backups Firebase maintains as part of its standard operation, we run a weekly export of the database to a private, access-restricted storage bucket in the European Union, so that data can be restored after a failure or a faulty release. Backups are not used for any other purpose. We do not currently apply a fixed expiry to these exports; they are kept until we remove them. Because a backup is a snapshot, data you have deleted can persist in an existing backup until that snapshot is removed, and a backup cannot be edited selectively to take out an individual record.

  • Analytics data at TelemetryDeck: retained in pseudonymized form for as long as needed for evaluation, in line with TelemetryDeck's retention policy.

  • Aggregated, anonymized research data: retained indefinitely, because it is no longer personal data.

  • Feedback and support messages: until the matter is resolved, and thereafter as required by statutory retention obligations for business correspondence.

  • Email correspondence: until the matter is resolved, subject to statutory retention periods.

  • Server and security logs: typically a few days, at most 30 days, unless required to investigate a specific security incident.

  • Device-local data: until you delete it, sign out, or uninstall the app.



14. Deleting Your Data

14.1 Deleting Individual Entries

You can delete any single intake, encounter, partner, check-up, place or image from within the app at any time, and you can clear any health field. This is the most granular control you have, and we encourage you to use it freely.

14.2 Deletion on Request

You can also ask us to delete your data by writing to hello@preppy.health. We will verify that the request comes from the account holder and act without undue delay, and in any case within one month.

14.3 Limits

We may retain data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. Aggregated, anonymized research data cannot be deleted because it can no longer be linked to you.



15. Security

We apply technical and organizational measures appropriate to the sensitivity of the data, including:

  • encryption of all data in transit using TLS, and encryption at rest by our infrastructure providers

  • per-account access rules enforced server-side, so that one account can never read another account's records

  • pseudonymous storage without direct identifiers on entry records, as described in Section 6

  • an optional device-level app lock using Face ID, Touch ID or your passcode, which can be applied to the whole app or to individual sections

  • storage of images in the app's private container, inaccessible to other apps

  • data minimization by design: every sensitive field is optional, and unused fields can be hidden from the interface so they are never collected

  • restricted administrative access, used only where strictly necessary

  • regular review of dependencies and security configuration


No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours under Art. 33 GDPR and, where the risk is high, notify you directly under Art. 34 GDPR.


We also recommend that you enable the app lock, use a device passcode, keep iOS up to date, and think carefully before sharing your screen or your device.



16. No Automated Decision-Making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

Preppy does compute things from your entries — protection windows, adherence streaks, DoxyPEP windows, and a risk classification for individual encounters. These calculations are displayed to you, and only to you. They are arithmetic on your own inputs, they produce no decision about you, they are never shared with anyone, and they are explicitly not a medical assessment. See Section 3.2.



17. Children

Preppy is not intended for children. The app carries an age rating in the App Store reflecting its content, and you must meet that age requirement and the age requirement of your App Store account to use it. We do not knowingly collect personal data from children.

If you believe a child has provided us with personal data, contact hello@preppy.health and we will delete it without delay.



18. Your Rights

18.1 Rights Under the GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:

  • access the personal data we hold about you and receive a copy (Art. 15 GDPR)

  • have inaccurate or incomplete data corrected (Art. 16 GDPR)

  • have your data erased (Art. 17 GDPR)

  • restrict processing (Art. 18 GDPR)

  • receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller (Art. 20 GDPR)

  • object to processing based on legitimate interests (Art. 21 GDPR)

  • withdraw consent at any time, with effect for the future (Art. 7(3) GDPR)

  • not be subject to automated decision-making (Art. 22 GDPR)

  • lodge a complaint with a supervisory authority (Art. 77 GDPR)


Access, correction and erasure you can exercise directly in the app: every entry is visible, editable and deletable by you at any time, which is the fastest route and requires no request to us.


Portability works differently. The app does not currently offer a self-service export, so if you want a machine-readable copy of your data under Art. 20 GDPR, email hello@preppy.health and we will produce one for you as a structured file.


For anything else, write to hello@preppy.health. Requests are free of charge and answered within one month, extendable by two months for complex requests, in which case we will tell you. We must verify your identity before acting. For an anonymous account there is by design nothing that proves the account is yours, so we may be unable to verify you and may have to decline the request under Art. 11(2) GDPR — this is the trade-off that comes with an account we cannot link to you.

18.2 Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise or defend legal claims. An informal email to hello@kaevin.io is enough. For research use, described in Section 10, you do not need to give a reason at all.

18.3 Supervisory Authority

Our lead supervisory authority is:


Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin, Germany
www.datenschutz-berlin.de


You may also complain to the supervisory authority in your country of residence or place of work. In the United Kingdom, that is the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch).



19. Additional Information for Users in the United States

This section applies to residents of US states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and others as they take effect. Where it conflicts with the rest of this policy, this section governs for those residents.

19.1 We Do Not Sell or Share Your Data

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the CPRA and under comparable state laws. We do not engage in targeted advertising. We have not sold or shared personal information in the preceding twelve months, and we do not sell the personal information of minors under 16.

19.2 Sensitive Personal Information

Preppy processes sensitive personal information as defined by California and other state laws, specifically personal information concerning health and personal information concerning sex life or sexual orientation. We use it solely to provide the service you requested, and for the aggregated research purposes described in Section 10. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you, and we do not use it for any purpose that would trigger the right to limit under Cal. Civ. Code § 1798.121. Nonetheless, you may direct us to limit its use at any time by contacting us.

19.3 Your Rights

Depending on your state, you have the right to know and access the personal information we hold, to correct inaccuracies, to delete it, to obtain a portable copy, to opt out of sale, sharing, targeted advertising and certain profiling — none of which we do — to limit the use of sensitive personal information, and not to be discriminated or retaliated against for exercising any of these rights. Some states require consent before processing sensitive data; where that applies, we rely on the explicit consent described in Section 8.1.


To exercise your rights, email hello@preppy.health. We will verify your identity and respond within 45 days, extendable once by a further 45 days where necessary. You may use an authorized agent, with proof of authorization. We honor Global Privacy Control signals where technically applicable.


If we deny a request, we will explain why. California residents may appeal by replying to our response; residents of states with a statutory appeal right may appeal within the period their law provides, and if the appeal is denied may contact their state Attorney General.

19.5 Health Data Laws

Preppy is not a HIPAA covered entity or business associate, so HIPAA does not apply to the data you enter. Where state consumer health data laws apply, in particular the Washington My Health My Data Act and the Nevada consumer health data law, we process consumer health data only with your consent as described in Section 8.1, we do not sell it, and you may withdraw consent and request deletion at hello@preppy.health.



20. Additional Information for Users in Brazil

This section applies under the Lei Geral de Proteção de Dados (LGPD) and prevails over conflicting provisions for users in Brazil.


Health data and data concerning sex life are sensitive personal data under Art. 5(II) LGPD. We process them on the basis of your specific and highlighted consent under Art. 11(I) LGPD. For research, we rely on Art. 11(II)(c) LGPD, studies by a research body with anonymization wherever possible, consistent with the safeguards in Section 10.


You have the right to confirmation of processing, access, correction of incomplete, inaccurate or outdated data, anonymization, blocking or deletion of unnecessary or excessive data, portability, deletion of data processed on consent, information about data sharing, information about the consequences of refusing consent, withdrawal of consent, and review of automated decisions. Requests go to hello@preppy.health and we respond within 15 days for full disclosure requests. You may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).


International transfers are made on the basis of your consent, standard contractual clauses, or the other grounds permitted by Art. 33 LGPD.



21. Additional Information for Other Regions

Canada. We process personal information under PIPEDA and applicable provincial laws, including Quebec's Law 25. Health and sexual information is sensitive information requiring express consent, which is the basis described in Section 8.1. You may access and correct your information and complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.


United Kingdom. The UK GDPR and the Data Protection Act 2018 apply in equivalent terms to the GDPR provisions described above. Your supervisory authority is the Information Commissioner's Office.


Switzerland. The revised Federal Act on Data Protection (revFADP) applies. Health and sexual data are sensitive personal data requiring explicit consent. Your supervisory authority is the Federal Data Protection and Information Commissioner.


Australia. We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. Health information and information about sexual orientation or practices are sensitive information collected only with your consent. You may complain to the Office of the Australian Information Commissioner.


Other countries. Where local law grants you rights beyond those described here, those rights apply and you may exercise them at hello@kaevin.io. Where local law imposes stricter requirements than those described here, we comply with them.



22. Cookies and Tracking Technologies

The Preppy app uses no cookies, no advertising identifiers, no IDFA, no fingerprinting and no cross-app or cross-device tracking. We do not participate in App Tracking Transparency because we do not track you across apps or websites owned by other companies, and we therefore never present that prompt.

The app stores technically necessary information on your device — your session, your preferences, your local database and your widget cache. Under § 25(2)(2) TDDDG in Germany and Art. 5(3) of the ePrivacy Directive, this does not require consent because it is strictly necessary to provide the service you requested.

The website uses no analytics, tracking or advertising cookies, and therefore displays no cookie banner.



23. Changes to This Policy

We update this policy when our features, our providers or the legal requirements change. The current version is always available at https://www.preppy.health/privacy-policy and in the app under Settings.

Continued use after a change constitutes acceptance of that change.



24. Definitions

  • Personal data — any information relating to an identified or identifiable natural person.

  • Special category data — data revealing health, sex life, sexual orientation, racial or ethnic origin, and the other categories listed in Art. 9(1) GDPR.

  • Pseudonymous — data that cannot be attributed to a specific person without additional information kept separately. Your entries are pseudonymous: they carry an account identifier, not your name.

  • Anonymized — data that can no longer be attributed to any person by any means reasonably likely to be used. Anonymized data is not personal data.

  • Denormalized — a database design in which records are stored separately and some values are deliberately duplicated across them rather than resolved by joining tables. See Section 6.

  • Controller — the party that determines the purposes and means of processing. For Preppy, that is Kevin Waltz.

  • Processor — a party that processes personal data on behalf of the controller, under contract.

  • Usage data — information collected automatically, such as app version, operating system version, device type, language and the events described in Section 7.13.



25. Contact

For any privacy question, request or complaint:


hello@preppy.health


We read every message and answer within one month, usually much sooner.



Preppy is not a medical device and does not replace contact with a healthcare professional. The app is a companion for personal use and does not protect against HIV infection. Use at your own risk.



Latest update: 14 August 2026

© Preppy 2026 • Stay healthy 🎗️

Disclaimer: Preppy is not a medical device and does not replace contact with a healthcare professional. The app serves as a companion for personal use and does not protect against HIV infection. Use at your own risk.