Privacy · Terms · Delete account or data
CLiR.health App — Privacy Policy
Effective date: September 10, 2026 (previous version: July 22, 2026) · Applies to the CLiR.health Android and iOS apps (co.clir.health)
The short version: using CLiR.health without signing in keeps your records on your device. Everything you enter stays on your device — and, if you use your phone's backup service, in your own encrypted Google or iCloud backup that only you control. We have no behavioral analytics on your records or ads. Signing in processes account information as described below.
If you activate CLiR Cloud, through a subscription or complimentary access, the app keeps an encrypted copy of your records in your CLiR Cloud account so they can be restored on another phone. That copy is encrypted in transit and at rest, is used for backup, sync, and optional AI access you authorize, and is deleted when you ask or 90 days after your subscription ends.
What the app stores — on your device
The app keeps the records you create so it can work:
- Dosing protocols you set up (compound, dose, schedule, duration)
- Your dose log (what you logged, when, and at which injection site)
- Supply and inventory counts
- Custom injection sites and app settings
All of this is stored in the app's private local storage on your phone. Unless you turn on CLiR Cloud, it is never transmitted to CLiR.health or anyone else, and we could not access, recover, or delete it for you even if asked — we never have it.
What we don't do
- No behavioral analytics, telemetry, or crash reporting on your dosing records
- No advertising and no ad SDKs
- No selling personal data or using it for advertising. Service providers and optional AI connections process data as described below.
- No account is required to use the app. Signing in is needed only for CLiR Cloud (below)
CLiR Cloud (optional paid subscription)
CLiR Cloud is an optional subscription that backs up your app data to your account and restores it on any phone you sign into. Account data is processed when you sign in, even before subscribing. Uploading your records requires an active CLiR Cloud entitlement.
Signing in. You sign in with Google or with Apple. We receive the identifier your provider issues for our app, and — if you allow it — the email address and display name on that account. We never see your password. Apple's "Hide My Email" works normally.
What is stored. When CLiR Cloud is on, the app uploads the same records listed above (protocols, dose log, supply, sites, settings) as a single backup file tied to your account, together with the time of the last change and the app version that wrote it. Nothing else is collected — no location, no contacts, no device identifiers beyond a random per-install sync marker.
Where and how it is stored. The backup is stored in Google Cloud (Firestore) in the United States, in a project controlled by CLiR Health LLC. It is encrypted in transit (TLS) and at rest (Google-managed encryption). Access is restricted by server-side rules so that only the signed-in account that owns a backup can read, replace, or delete it. CLiR Health staff do not read backups except where strictly necessary to investigate a problem you have reported to us, and never for any other purpose.
Subscription and billing. Purchases are made through Google Play or the App Store; CLiR.health never sees your card details. To know whether your subscription is active, we use RevenueCat, a subscription-management service, which receives your app user ID (the sign-in identifier above) and purchase receipts from the store. RevenueCat provides subscription and revenue analytics from these purchase records; it does not receive your dosing records. RevenueCat's own privacy policy governs its handling of that data.
Service providers. Google (Firebase Authentication, Firestore), Apple (Sign in with Apple, App Store billing), and RevenueCat act as processors on our behalf for the purposes described here. If you choose to connect an AI assistant, its provider also receives the data you request as described below.
Retention and deletion. Your backup is kept while your subscription is active. You can delete it at any time in Settings → CLiR Cloud → Delete cloud copy, which removes it immediately; the data on your phone is untouched. If your subscription ends, the backup remains available to you (read-only) and is permanently deleted 90 days after the end of the last paid period. Signing out does not delete the backup. To delete your sign-in account and cloud copy, use Settings → CLiR Cloud → Delete account. If requested, sign out and sign back in first to confirm your identity. You can also email app@clir.health from the address on the account; we remove the account and any backup within 30 days. Account deletion does not erase records on your phone or cancel your store subscription. Manage the subscription separately in Google Play or the App Store. Store and RevenueCat purchase records are separate from your cloud backup and follow their respective retention policies.
Connecting an AI assistant (optional). Subscribers can connect Claude or ChatGPT to their CLiR Cloud data through a connector we host (https://clir-health.web.app). This only happens if you set it up yourself, inside the assistant, and sign in with your CLiR Cloud account. Once connected, the assistant can read your protocols, dose log, adherence summaries and supply when you ask it questions; it cannot add, change, or delete anything. Whatever the assistant reads is then handled by Anthropic or OpenAI under their own privacy terms, not ours. Disconnect at any time from the assistant's connector settings, or by deleting your CLiR Cloud account in the app, and access stops immediately.
Backups and exports
You can export your data as a JSON backup or an Excel spreadsheet. Exports happen only when you tap them, and your phone's share sheet lets you choose where the file goes (your files, your cloud drive, an email — your choice). Exported files contain your records, so store them as carefully as you would the app itself. CLiR.health never receives a copy.
Your phone's own backup system
Separately from the exports above, your phone's operating system may include the app's data in your personal device backup — Google's device backup on Android, iCloud Backup on iOS. This is a feature of your phone, not of the app: the backup belongs to your Google or Apple account, is encrypted by Google/Apple, and may be restored automatically if you reinstall the app or move to a new phone. CLiR.health has no access to these backups and receives nothing from them.
You control this in your phone's settings (Android: Settings → Google → Backup; iOS: Settings → your name → iCloud → Backups). If you exclude the app or disable device backup, your data exists only on the device and in exports you make yourself.
Network use
Without signing in, the app works offline and makes no network requests of its own; the only time it touches the network is when you tap a citation (for example, an FDA label or a published study) — that link opens in your browser, and the website you visit is governed by its own privacy policy, not this one. When you sign in, the app additionally talks to Google (sign-in and backup storage) and RevenueCat (subscription status) as described above, and to nothing else. If you connect an AI assistant, that assistant's provider talks to our connector on your behalf; the app itself does not.
Notifications and permissions
Dose reminders are created and scheduled locally on your device. The app asks for:
- Notifications — to show dose reminders.
- Alarms & reminders (exact alarms) — so reminders fire at the precise scheduled time even when the app is closed. This is the app's core function.
- Network access — used to open cited sources and, if you subscribe, for CLiR Cloud.
Retention and deletion (on the device)
Your data stays on your device until you delete it in the app or uninstall the app. Uninstalling removes the app's data from the device itself; a copy may remain in your personal device backup (see "Your phone's own backup system" above) and can be restored if you reinstall. Export files you previously saved elsewhere are likewise unaffected by uninstalling. To remove every copy: delete your data in the app (or uninstall), remove the app from your device backup in system settings, delete any exports you created, and — if you used CLiR Cloud — delete the cloud copy in Settings or email us.
Children
The app is intended for adults (18+) and is not directed to children.
Changes to this policy
If the app changes how it handles data, this policy will be updated first and the effective date revised. Material changes will be called out in the app's release notes.
Contact
Questions about this policy or your data: app@clir.health