Privacy Policy
Last updated: May 9, 2026
Solum is built around a simple principle: your data belongs to you. This policy explains what we collect (very little), what we don't collect (almost everything), and how your data is handled.
Data we do not collect
- No personal information — no name, email, or identity of any kind is required to use Solum.
- No dose data — all vial configurations, administrations, schedules, and observations are stored exclusively on your device.
- No usage analytics — we do not track how you use the app, which screens you visit, or how often you open it.
- No crash reporting that transmits personal data — if we implement crash reporting in future, it will be aggregated and stripped of any identifying information before transmission.
Data stored on your device
Solum stores all data in a local SQLite database on your device. This includes:
- Vial templates and instances
- Administration logs
- Schedules and reminders
- Observations
- App settings
This data never leaves your device unless you explicitly export it using the in-app export function.
Subscriptions
Subscription purchases are processed by Apple via the App Store or by Google via Google Play. Solum does not handle payment information directly — at no point do we see your card, address, or Apple/Google account details. Receipts are validated through RevenueCat, which processes anonymized subscription events on our behalf. RevenueCat's own privacy policy applies to the data they handle.
Referral attribution
During onboarding, new users may optionally enter a referral code. If a code is entered, Solum transmits a small amount of data to our server to credit the referrer. This section explains exactly what is sent, why, and what happens to it afterward.
What is sent:
- Referral code — the code you typed in, sent in plain text so the server can look up the referrer.
- Device identifier hash — a one-way SHA-256 hash of your device's vendor identifier (IDFV on iOS, Android ID on Android). This hash cannot be reversed to recover the original identifier. It is used solely to prevent the same device from being counted more than once.
- Pseudonymous user ID — a random UUID generated on your device at first launch. It contains no personal information and cannot be linked to your name, email, Apple ID, or Google account. It is used to verify that you later became a subscriber (via RevenueCat), so the referrer can be credited.
- Platform — whether you are on iOS or Android, so the server knows which deduplication method was used.
What is not sent:
- No name, email, phone number, or any other personal identifier.
- No dose data, vial configurations, schedules, observations, or any health-related information.
- No IP-based geolocation is stored. While our server necessarily receives your IP address during the request, it is not logged or retained.
- No device fingerprinting beyond the single hashed identifier described above.
How the data is used:
- The device identifier hash is compared against existing records to prevent duplicate attributions. Once the referral is processed and any applicable payout has been made, the hash is permanently deleted from our database.
- The pseudonymous user ID is used to query RevenueCat's API to confirm that the referred user holds an active subscription. This check happens server-side during a periodic batch process — no additional data is sent from your device.
- The referral code links the attribution to the referrer's account in our internal dashboard. This is a business-to-business relationship; end users do not receive monetary rewards.
Data retention:
- The device identifier hash is deleted once the referral conversion is marked as paid. It exists only for the duration of the refund window (typically 30 days) plus processing time.
- The pseudonymous user ID may be retained on the conversion record for recurring commission tracking. It remains pseudonymous — we have no way to associate it with your real-world identity.
- If you never enter a referral code, none of the above data is ever transmitted.
Your control:
- Entering a referral code is entirely optional. You can skip the screen with no effect on app functionality.
- If you enter a code, the privacy implications are disclosed on-screen before you proceed.
- If you have questions about a specific referral attribution, contact privacy@getsolum.app with your pseudonymous user ID (visible in Settings) and we will delete the associated conversion record on request.
Cloud Transfer
If you use the optional Cloud Transfer feature to move your data from one device to another, your data is end-to-end encrypted on your device before leaving it. Our server stores only an opaque encrypted blob it cannot read, and deletes it immediately after the new device downloads it (or after 24 hours if unclaimed). See our Cloud Transfer Privacy page for details.
Device backup
By default, your device may include the Solum database in a cloud or local backup (iCloud on iOS, Google backup on Android). This is covered by Apple's or Google's respective privacy practices. You can disable this in your device settings, or within Solum's Settings.
Your rights
Because we don't collect your data, there is nothing for us to delete, correct, or export on your behalf. All your data already lives locally on your device and is under your control.
To delete your Solum data entirely, uninstall the app from your device.
Children
Solum is not directed at children under 13 and we do not knowingly collect information from children.
Changes to this policy
If we make material changes to this policy, we will update the date at the top of this page and, where appropriate, notify you within the app.
Contact
Questions or concerns? Email us at privacy@getsolum.app.