Tessly Privacy Policy
The short version. Your medications, supplements, routines, steps, measurements, wellbeing check-ins and their logs stay on your iPhone. An optional Tessly account, created with Sign in with Apple, syncs only your food diary and assistant chat. The AI assistant and share links are used only when you choose them. There is no advertising or third-party analytics code; the app sends only anonymous daily usage counts and crash reports, both of which you can turn off.
Who this policy covers
This policy describes how the Tessly iOS app and its Home Screen widget handle your information. It applies to the app as distributed on the App Store.
What Tessly stores on your device
Everything you enter stays in Tessly's local database on your iPhone, inside a storage area shared between the app and its widget:
- Names of medications, supplements, steps trackers and health routines that you create
- Wellbeing check-ins you record: 1–5 scales such as mood or appetite, symptoms with how strong they were, notes, dose steps and injection sites
- Dosage or amount text, schedules, and reminder preferences that you configure
- Notes you attach to an item
- Stock and refill values you enter
- Your logs: taken, skipped, snoozed, and not-logged occurrences, with their dates and times
- App settings, including privacy mode and appearance preferences
This health adherence data is not readable by us, shared with third parties, or used to build a profile of you. It leaves your iPhone only as an end-to-end encrypted copy when you turn on health data sync with Tessly Plus, or as a report you explicitly publish with a share link, both described below.
Device backups and iCloud
If you have iPhone backups enabled, Tessly's local database may be included in your own encrypted device backup, the same way other apps' data is. That backup belongs to you and is governed by Apple's terms, not ours. Tessly does not store health data in iCloud.
Health data sync (Tessly Plus, optional)
If you have Tessly Plus, are signed in with Apple and turn on health data sync, your medications, supplements, routines, their logs, wellbeing check-ins, and the measurements and readings you enter are copied to your other devices signed in to the same account. Before leaving your iPhone, each item is encrypted with AES-GCM under a key created on your device and kept in your iCloud Keychain. Our server stores only this encrypted data, a random-looking identifier per item and the time it last changed, so it can order changes; it has no key and cannot read what you entered. Data read from Apple Health (steps, imported weight and readings) is not included. You can turn sync off or delete the encrypted copy at any time in Settings → Account & Sync; deleting your account deletes it too. If your iCloud Keychain is lost, the encrypted copy cannot be recovered by anyone, including us, but the data on your devices stays.
Food diary and Tessly account
The food diary works on your iPhone without an account. If you sign in with Apple and turn on sync, Tessly stores your food entries, optional daily goal and assistant chat on the Tessly server so they appear on your other devices. Sign in with Apple gives us an anonymous account identifier; we do not request your name or email.
Food photos are stored on the server only with Tessly Plus. Without it, entries sync without their photos and the photos stay on your device. Medications, supplements, routines and measurements sync only as the end-to-end encrypted copy described above, and Apple Health data is never synced.
Food search and barcodes
Searching for a packaged food and scanning a barcode are free and work without an account. Barcodes are read on your iPhone. The search text you type, or only the barcode number, is sent to the Tessly server to find matching products in our copy of the public Open Food Facts database. It is used only to answer that request: it is not stored with your account and is not written to our logs. If a barcode is not in our copy, our server may look up that number in Open Food Facts directly; only the number leaves our server, never anything about you. Product information comes from Open Food Facts under the Open Database License.
AI food assistant (Tessly Plus)
Before the first request you are asked for explicit consent. When you send a message, its text, any attached photos and a compact summary of your last 14 days of food entries are sent through OpenRouter to the configured AI model to prepare a reply, an editable draft or a weekly summary. We request providers that do not retain or train on this data. Nothing the assistant suggests — food, a measurement or a medication schedule — is saved until you review and confirm it.
Your medications and supplements with their logs, body measurements and blood pressure or pulse readings you logged in Tessly, health routines, and wellbeing check-ins are sent to the assistant only when you tap Allow or Always allow for that category, or turn the category on for a weekly review; you can turn "Always" off in Account & Sync at any time. This shared data is used only to answer that request and is not stored on our server; the assistant's reply or weekly review, which may describe it, is stored with your chat or review. Data read from Apple Health (steps, imported weight and readings) is never sent to the assistant. If you send a photo of a prescription or package, the assistant transcribes it into a schedule you review; it does not recommend doses. When the optional reference lookup is on, medication names are sent to a web-search provider to find official information pages. The assistant's answers are not medical advice.
When you dictate a message, the microphone records only while you hold or tap the mic. The recording is sent once through our server and OpenRouter to a speech-to-text model on providers that do not retain or train on it; only the resulting text comes back into the message field for you to review before sending. Neither the audio nor the transcript is stored on our server, and the recording is deleted from your iPhone right after.
For each assistant, weekly review and dictation request we keep only its type, the AI model, token counts and cost, linked to your account, to enforce daily limits and understand what the service costs. It holds nothing you wrote, said or photographed. Deleting your account unlinks these records.
When the app crashes or freezes, iOS gives it a technical report (where in the code it happened, the app version and the iPhone model). Tessly sends these reports to our server so we can fix problems. They contain nothing you entered, are not linked to your account, are kept for 90 days, and can be turned off in Settings → Privacy & Security.
Once a day the app also sends anonymous usage counts for the previous day: how many times a few features were used (for example app opens, logged doses or assistant messages) and the week the app was installed. If you answer the optional question during setup about how you heard of Tessly, your answer (for example “a friend” or “YouTube”) is added to these counts once. They carry no names, doses, notes, device or account identifiers; the server only adds them to totals shared by all devices. You can turn this off in Settings → Privacy & Security.
Share links (Tessly Plus)
When you create a share link, the PDF report you chose is uploaded to the Tessly server and can be opened by anyone who has the link until it expires (1, 7 or 30 days) or you revoke it. We store only a fingerprint of the link, not the link itself. Expired and revoked reports are deleted.
Body measurements
Weight and body measurements you enter are stored locally, with their dates and units. You can edit or delete manual entries. Hiding a measurement from Today keeps its history.
Health data (HealthKit)
If — and only if — you enable the steps tracker and grant permission, Tessly reads your daily step count from Apple Health. Step access is read-only.
If you connect weight in Tessly, the app also requests read-only access to your weight history. Imported measurements, source identifiers and import progress are stored on your device. Manual entries take priority for the same day. Disconnecting weight import keeps saved history; Remove Imported History removes the imported copy from Tessly while keeping manual entries and Apple Health data. Tessly never writes weight or body measurements to Apple Health.
If you connect blood pressure and heart rate, Tessly reads these readings from Apple Health (heart rate as a daily summary) and stores imported blood pressure readings on your device. With your permission, readings you log in Tessly are also saved to Apple Health; this is the only data Tessly writes there, and you can turn it off in Settings → Health Data or in the Health app. Deleting a reading you logged in Tessly also deletes the copy Tessly saved in Apple Health; readings from other apps are never changed. Tessly only records and shows these values and does not interpret them.
Data read from Apple Health is used solely to display and log your progress inside the app and its widgets. They are never transmitted off your device, never used for advertising or marketing, and never shared with third parties or data brokers. You can revoke this permission at any time in the Health app, and Tessly falls back to manual entry.
Notifications
Tessly schedules local notifications on your device to remind you to log an occurrence. They are generated on your iPhone and are not delivered through any Tessly server.
Depending on your settings, a notification may display an item name and dosage or amount on your Lock Screen. If you turn on privacy mode, Tessly hides those details and shows generic wording instead. Consider privacy mode if other people can see your Lock Screen.
Widgets
Home Screen widgets read the same local data to show today's items. As with notifications, item names and amounts may be visible on your Home Screen unless privacy mode or an item-level privacy setting hides them.
Reports and exports
With Tessly Plus you can generate PDF reports and CSV logs from your data. These files are created entirely on your device and saved wherever you choose through the system file picker.
Once you export a file and share it — by email, messaging, cloud storage, or with a clinician — it leaves Tessly's control and is governed by whatever service you sent it to. Exported files can contain sensitive health information, so share them deliberately.
Purchases
Tessly Plus is an auto-renewable subscription processed by Apple. Tessly never sees or handles your payment details. To unlock server features, the app sends Apple's signed transaction to our server, which verifies it and links it to your Tessly account; Apple also notifies our server about renewals, refunds and cancellations for that subscription. Apple's own privacy policy governs the transaction itself.
What Tessly does not do
- No account required for tracking, reminders or the local food diary
- No sync of medications, supplements, routines or measurements except the optional end-to-end encrypted copy, and no sync of Apple Health data
- No third-party analytics, crash reporting, attribution, or advertising SDKs
- No tracking across apps or websites, and no App Tracking Transparency prompt, because no tracking takes place
- No sale or sharing of personal information
- No caregiver, clinician, employer, or insurer sharing
Retention and deletion
Your data stays on your device until you remove it. You can delete individual items and their history inside the app, or everything at once in Settings → Delete Data: this removes your medications, supplements, routines, steps, measurements, wellbeing check-ins, food diary with photos, assistant chat and scheduled reminders from the iPhone and signs you out. Deleting Tessly from your iPhone removes its local database and the shared storage used by the widget.
If you use a Tessly account, you can delete it in the app under Account & Sync. This deletes your synced food entries, photos, chat, weekly reviews and share links from our server. Your local data and your App Store subscription are not affected; manage the subscription in your Apple Account settings.
Children
Tessly is not directed to children and does not knowingly collect information from children.
Not medical advice
Tessly is a reminder and logging tool. It does not diagnose, treat, prevent or cure any condition; it does not recommend dosages or dose changes; and it does not check drug interactions, contraindications, or prescription validity. Everything Tessly shows is a description of what you told it. Talk to a qualified healthcare professional about your treatment.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new "last updated" date. Material changes will also be noted in the app's release notes.
Contact
Questions about this policy or about privacy in Tessly: info@links.academy