Seen Together
ES Back to home

Privacy Policy

Last updated: July 8, 2026

Seen Together (“the app”, “we”) is made by Facundo Tenuta (“the maker”). This policy explains what information the app and this website handle, where it lives, and the few cases where data leaves your device. The short version: your health records stay on your phone, we don’t sell anything, there are no ads, and we don’t track you across other apps or websites.

1. Your health records stay on your device

Everything you log — pain intensity, location, bleeding, symptoms, medication, daily-life impact, notes, period days, cycle settings, and appointments — is stored only on your device, in a local database encrypted with SQLCipher (AES-256). A random 256-bit key is generated on your device and stored in the system Keychain (iOS) / Keystore (Android), marked device-only. That means the key is never sent to us, never synced to your other devices, and not carried into a backup that is restored onto a different device. We never receive your health records.

A health record leaves your device only when you explicitly choose to: when you export or share a doctor report (a PDF you send via your own apps). You control where that file goes.

2. Information that does leave your device

A few non-health features send limited data off your device. None of it ever includes your health records.

  • Anonymous usage analytics. We use Aptabase, a privacy-friendly analytics tool, to understand how the app is used. Each event records only that an action happened (for example, that the app was opened, or that a report was generated) — never the contents of a record. Events carry no personal information, are not tied to an identity you can be recognised by, and are never used to track you across other apps or to build an advertising profile.
  • Crash reports. We use Sentry, an error-monitoring tool, so we learn when the app breaks and can fix it. If a crash happens, a technical report — the error and its stack trace, the app version, and the device model — is sent to Sentry, hosted in its European region. The report never includes your health records or any information that identifies you, and carries no IP address. Sentry processes this data on our behalf and does not use it for its own purposes.
  • Push notifications. If you turn on notifications, a device push token is sent to our server so we can deliver reminders and occasional app updates. It is tagged only with a random per-device id and is never linked to your health data. If you leave notifications off, nothing is sent.
  • Feature voting and suggestions. If you vote on a feature or send a suggestion, that vote or suggestion text is sent to our server, tagged only with a random per-device id that is never linked to your health records. Votes are limited to one per device.
  • Feedback. When you send feedback, your message is sent to our server and stored so the maker can read it and improve the app. It is tagged with the same random per-device id, never with your health records. Your email address is included and stored only if you choose to add one so the maker can reply.
  • Our website (seentogether.app). The marketing website uses Google Analytics to understand aggregate visits (this is the website only, not the app). If you join the pre-launch waitlist, we store the email address you submit to notify you at launch. The app itself has no waitlist and never collects this.

3. Payments (optional tips)

Supporting the app is optional and never unlocks features. Tips are processed by Apple (App Store) or Google (Google Play) through their standard in-app purchase systems. We never see or store your payment details (card numbers and the like stay with Apple/Google).

After a tip completes we keep a small record of the transaction — the store’s transaction id, which tier, the amount, and an optional note you write — on your device and on our server, tagged with the same anonymous per-device id. This is never linked to your health records and contains no payment details. A copy of the receipt also stays on your device for your reference.

4. What we never do

  • We never sell your data.
  • We never serve ads, and we never embed advertising SDKs.
  • We never track you across other apps or websites, and we use no advertising identifiers.
  • We never require an account to use the app.

5. Data retention and deletion

On-device data. Your health records live on your device until you delete them — per item, or all at once via Settings → Delete everything, which permanently and immediately removes every local record. Uninstalling the app also destroys the encrypted database and its key. We never hold a copy, so there is nothing for us to delete on your behalf.

Off-device data — what we keep and for how long. The limited data that leaves your device (see Section 2) is tagged only with a random per-device id, never with your health records. We keep it until you ask us to delete it — we set no automatic expiry for it.

  • Push token (our server) — deleted on request; otherwise removed when you disable notifications or uninstall.
  • Feature votes and suggestions (our server) — deleted on request; otherwise kept until you ask.
  • Feedback message, and your email if you added one (our server) — deleted on request; otherwise kept until you ask.
  • Tip / transaction record (our server) — the per-device link is deleted on request; an anonymised record with no link to you may be kept where tax or accounting law requires it.
  • Waitlist email (website only) — deleted on request; otherwise kept until launch.
  • Anonymous usage analytics (Aptabase) — carries no identifier, so it cannot be tied to you or deleted individually; retained only in aggregate.
  • Crash reports (Sentry, EU region) — contain no personal or health data and no identifier; automatically deleted after up to 90 days.

How to request deletion of your off-device data:

  1. Email facundotenuta.dev@gmail.com with the subject “Delete my data — Seen Together”.
  2. Tell us what to remove (or say “all of it”). Because these records carry no name or account, include whatever helps us find them:
    • Everything tied to your device: your device id — open Settings, scroll to the bottom, and tap Copy ID, then paste it into your email. This lets us remove your push token, feature votes, and suggestions, which otherwise carry no handle you could give us.
    • Tips: the store transaction id — it’s on the receipt saved in the app, and in your App Store or Google Play order history.
    • Feedback: the email address you sent it with, if you added one.
  3. We complete the deletion and reply to confirm within 30 days.

6. Children

Seen Together is not directed at children and is intended for users 13 and older (or the minimum age in your region).

7. Changes

We may update this policy as the app evolves. Material changes will be reflected here with a new “Last updated” date.

8. Contact

Questions or requests: facundotenuta.dev@gmail.com.

Seen Together

Feel seen. Log with clarity. Speak with confidence to your doctor.

Product
How it worksPrivacyFrequently askedDownload
Project
SupportThe problemPrivacy policyHome

Medical disclaimer. Seen Together is not a medical device and does not provide diagnosis, treatment, or medical advice. It is a personal logging tool meant to help you prepare your conversations with health professionals. For any symptom, always consult your doctor.

Built and maintained by Facundo Tenuta © 2026 Seen Together