Effective as shipped with the current app version.
This is the same text shipped inside the Shoteo app, where it is shown before first use. The app-bundled copy is the one consent is recorded against. The English version of these documents is the authoritative one.
Shoteo keeps everything you log on your own phone. There is no account, no server run by us, and no copy of your health data anywhere but this device. You can take all of it out at any time, and you can erase all of it at any time.
This policy covers the Shoteo app on iOS and Android, and the website at shoteo.codexo.at where it is published. Nothing you do in the app is connected to the website, because the app makes no connection to it. The policy reads the same on both platforms — unlike most apps, there is no platform-specific storage or analytics to describe, because there is no storage or analytics outside your device on either platform.
There are none, in either place. The app embeds no analytics, advertising, tracking or crash-reporting services of any kind, and it has no use for cookies because it talks to no server. The website is a set of static pages that sets no cookies, runs no scripts that watch you, and loads everything it needs — including its fonts — from its own address, so opening it sends nothing about you to any third party. Its hosting provider necessarily sees what any web server sees to deliver a page, such as your IP address in its technical logs; we add nothing to that and receive nothing from it.
Three sources, all initiated by you: what you type into the journal; CSV files you choose to import (from a spreadsheet or another tracker's export — read locally, never uploaded); and a JSON backup you restore. The app pulls data from nowhere on its own.
Your profile (height, start weight, goal weight, start date, unit preferences); the medications you add (name, ingredient, delivery route, concentration, current dose, schedule, colour, dose presets, active state); and every journal entry you make — weigh-ins and waist values, dose events (date, time, dose, site, pain, status, notes), body measurements, nutrition, symptoms, wellness, and lab values. Alongside that it stores your reminder settings, your theme choice, and the record that you accepted these documents (the version and the date).
In a database inside the app's own private storage on this device, under keys prefixed "shoteo:". Next to it the app keeps one plain JSON snapshot of the same journal, as a file in that same private storage, rewritten as you log. It is there so your journal survives a database the app can no longer open, and so it can be restored when you set up a new phone. A small duplicate of two values — your profile and your consent record — is kept in the device's key-value store so the app can recover if the main database comes back empty after a restart. Nothing is stored outside the app's sandbox. Because all of it sits in that sandbox, your phone's own backup — iCloud Backup on iPhone, Auto Backup on Android — includes it, which is what carries your journal to a new phone. That copy is made by your phone, not by the app, and it is held under the terms of whoever provides it; you can stop it by turning that backup off in your system settings.
Your health data is never sent anywhere by the app. It makes no network requests with your journal in them: there is no sync, no analytics, no advertising, and no crash reporting that could carry it. It leaves by two routes, both yours to control. One is when you explicitly export or share it — a JSON backup, a CSV file, or a PDF summary — and then it goes wherever you send it; from that moment the receiving app or service, not Shoteo, decides what happens to it. The other is your phone's own backup, if you have it switched on: the operating system copies the app's storage along with every other app's, to iCloud or to Google, under your agreement with them.
Reminders are scheduled and delivered by your device, locally, and only if you turn them on and grant permission. They contain the medication name and the date and time of a scheduled dose, so treat them as you would any notification visible on a lock screen. You can turn them off in Settings or revoke the permission in your system settings.
Settings offers a full JSON backup (everything, restorable into the app), a CSV file per data type, and a PDF summary intended for a clinician. All three are produced on the device and handed to your system share sheet.
"Delete all data" in Settings erases the database, the JSON snapshot file, the duplicate copies, and your consent record, and returns the app to its first-launch state. It cannot be undone from inside the app. A copy already taken by your phone's own backup is outside the app's reach — clear that through your system settings if you want it gone too. Deleting the app itself removes its storage as well. Files you had already exported or shared are outside the app's reach — delete those wherever you sent them.
The main protection is architectural: data that never leaves your device cannot be intercepted in transit, breached on a server, or mishandled by a vendor, because none of those places exist for it. On the device it sits in the app's sandboxed private storage, which the operating system isolates from other apps, and it is covered by whatever device-level encryption and screen lock you use. The one copy that does travel is your phone's own backup, if you use it — that one is secured by Apple or Google, to the standard described in their terms, not by us. That makes your device's own security — a lock screen, OS updates — the part that matters most, and it is in your hands.
There are none. Sections about standard contractual clauses or overseas processors exist in privacy policies because data moves between countries; yours does not move at all. The one nuance: if your phone's own backup is enabled, where that backup lives is governed by your agreement with Apple or Google, not by us.
Shoteo is not intended for children. It is meant for adults tracking their own prescribed treatment, and no part of it is designed, marketed or directed at minors — including children under 13 in the sense of the U.S. COPPA rule, from whom we knowingly collect nothing, as we collect nothing from anyone. The app performs no age verification, because it collects nothing that would allow it: there is no account and no identifying information. If a child has used the app on a shared device, the journal can be erased completely with "Delete all data" in Settings.
The controller responsible for the processing of your personal data is:
Codexo e.U.
Grillgasse 19/46, 1110 Vienna
Austria
Companies register: FN 671926b, Handelsgericht Wien
Email: contact@codexo.at
Note what this means in practice: because your journal never leaves your device, the controller does not hold it. We cannot look up your data, restore it, or delete it for you — and equally, we cannot lose it or hand it to anyone else.
Under the GDPR you have the right to access your personal data, to correct it, to erase it, to restrict or object to its processing, and to receive it in a portable form. Because your health data stays on your device and we hold no copy of it, these rights are ones you exercise directly in the app rather than by asking us: the journal itself is your access, editing any entry is your correction, the JSON and CSV exports are your portability, and "Delete all data" is your erasure. A request to us for a copy or a deletion of your journal would find nothing to act on. If you believe your data-protection rights have been infringed, you may complain to the Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40-42, 1030 Vienna, dsb.gv.at, or to the authority where you live.
If you live in the United States, state privacy laws — California's CCPA/CPRA, Washington's My Health My Data Act, and the growing number of laws like them — give you rights over consumer health data that a business collects, sells or shares. Shoteo's position under all of them is the same: we do not collect your health data, we do not sell it, we do not share it, and we do not use it for advertising of any kind, targeted or otherwise — we never have it in the first place. There is nothing to opt out of and no request to send, because everything those laws let you demand is already in your hands: your access is the journal itself, your deletion is "Delete all data", and your portability is the export. Shoteo is not a HIPAA covered entity and your journal is not part of any medical record — it is a private note on your own phone, protected by staying there.
Health data is "special category" data under Article 9 of the GDPR — the class the law protects most strictly. Shoteo meets that obligation architecturally rather than contractually: your journal is stored on your device under your own control, and we neither receive nor process it, so there is no processing by us for which a legal basis would be needed. The record that you accepted this policy and the disclaimer is stored on your device as well, so that the app can tell whether the terms you agreed to have since changed. Data is kept for as long as you keep it: nothing expires on its own, and everything is removed when you delete it in the app or uninstall the app.
This policy is shipped inside the app, so it changes only when the app is updated. When a change affects what you agreed to, the app records a new version of these documents and asks you to read and accept them again before you continue. The current version is always the one shown here, and the same text is published at the address below.
Questions about this policy or your data: contact@codexo.at.