Shotly Privacy Policy

Effective Date: July 29, 2026 Last Updated: July 29, 2026

Operator / data controller: Bilal Labs (“Shotly,” “we,” “us”) Contact: bilaldemirerlabs@gmail.com


Introduction

We built Shotly to help people taking GLP-1 medications stay organized — tracking shots, doses, weight, and side effects in one place.

Shotly is designed to keep your health entries on your device. We take that seriously.

This Privacy Policy explains:

We’ve also created a separate Health Data Privacy Policy with extra details about sensitive health information.


Where This Policy Applies

Platform How it works
iOS App No user account. Your health entries (shots, weight, side effects, treatment profile) are stored locally on your device.
Android App No user account. Same local on-device storage as iOS.
Website (if any) If we maintain a marketing site, it may use limited analytics to understand traffic. We do not design any website to collect health data. Please do not submit health information through website forms or support requests unless it is necessary.

Key Terms (Plain English)


What We Collect (and Why)

Account Information

Shotly does not require an account. We do not collect a login email, password, or social sign-in for the core app experience.


Health Data (Optional — you choose what to enter)

If you use Shotly’s tracking features, the app stores on your device information you enter, such as:

Why? To provide Shotly’s core features and help you stay organized.

We do not send these health entries to analytics, advertising, or attribution tools.


Apple Health / Health Connect

Shotly does not currently import from or write to Apple Health (iOS) or Health Connect (Android). If we add those integrations later, we will update this policy and ask for your permission first.


Device & Technical Information

To keep the app reliable and up to date, we (and limited service providers) may process:

Why? So we can nudge you to update when an older build is no longer supported, and keep the Service working.

This remote-configuration traffic does not include your health entries (injection logs, dosage, side effects, weight entries, or notes).

We do not use advertising identifiers for tracking. Apple’s privacy nutrition labels for Shotly reflect that we do not collect data types for tracking purposes as configured in our iOS privacy manifest.


Notifications (Optional)

If you enable reminders, the app schedules local notifications on your device (for example, shot day, weight check-in, side-effect check-in). Notification content is generated on-device from your settings; we do not operate a separate push-notification account tied to your identity for these reminders.


Payment and Subscription Information

Shotly is currently free to download and use. We do not process payment card details. If we introduce paid subscriptions later, purchases would be handled by the Apple App Store or Google Play Store, and this policy would be updated.


Non-Health Usage Analytics & Attribution

Shotly does not currently use third-party product analytics or attribution SDKs (for example, Mixpanel or AppsFlyer) inside the app.

If we add analytics later, we will update this policy, and we commit not to send your health entries through those tools.


Legal Bases (EEA/UK and similar regions)

If you are in the European Economic Area (EEA), the United Kingdom, or another region that requires a legal basis for processing, we process information under:

Questions or objections: bilaldemirerlabs@gmail.com


Where & How We Store Your Data

Data Storage Notes
Health entries & profile On your device (local app storage) Not uploaded to Shotly cloud storage as part of normal use. Remains until you delete it or uninstall / clear the app.
Remote Config (min version / store URL) Google Firebase Remote Config Fetches configuration only; does not store your health entries.
Support email Your email provider ↔ ours Only what you choose to include when you contact us.

Backups: Depending on your device settings, your phone’s OS may include app data in device backups (for example, iCloud or Google backup). Those backups are controlled by you and the platform provider, not by Shotly servers.


How Long We Keep Your Data

Data Type Retention
On-device health entries Until you delete them in the app (where available), clear app data, or uninstall the app.
Remote Config fetch metadata Handled by Firebase under Google’s practices; used only to deliver configuration.
Support emails As long as reasonably necessary to respond, keep a record of the request, and meet legal obligations.

Your Privacy Rights

Depending on where you live, you may have rights to:

In Shotly you can:

Email: bilaldemirerlabs@gmail.com

Requests, verification, and appeals

Because Shotly stores health entries on-device, we often cannot access your logs from our servers. For many requests, the practical path is export or delete on your device. If we deny a request we can fulfill, you can appeal by replying to our email. We will review and respond as required by applicable law.


Who We Share Data With (and Why)

We share data with service providers only as needed to run Shotly. They may use data only to provide services to us, subject to applicable contracts and safeguards.

Vendor Purpose
Google Firebase Remote Config Minimum app version / update messaging (no health entries)
Apple / Google (app platforms) App distribution; optional OS-level backups you control

We do not sell your data. We do not share your data for targeted advertising. We do not send health entries to analytics or attribution tools.

Support communications

If you contact us by email, we use the information you provide to respond. If your message includes health details, we treat that as sensitive and use it only to help you.

Legal requirements

We may disclose information if required by law or legal process, or if we believe disclosure is necessary to protect rights, safety, and security — noting that on-device health entries are typically not in our possession.

Corporate transactions

If Shotly is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information we hold (for example, support correspondence or configuration systems) may transfer as part of that transaction. We will provide notice when required by law.


Security

We rely on the security of your device and the OS sandbox for on-device storage, plus reasonable safeguards for any limited server-side configuration we operate (for example, encrypted transit to Firebase).

No method of storage is 100% secure. Protect your device with a passcode / biometrics and keep your OS updated. Jailbreaking or rooting increases risk and may break the app.


Data Controller

Bilal Labs is the data controller responsible for personal information processed under this Privacy Policy in connection with Shotly.

Privacy requests: bilaldemirerlabs@gmail.com


International Data Transfers

Remote configuration may be processed on infrastructure in the United States or other locations where Google operates Firebase. Where required (such as under GDPR), we rely on appropriate safeguards such as Standard Contractual Clauses.

Your health entries stay on your device unless you export or share them yourself.


Children’s Privacy

Shotly is not intended for anyone under 18. We do not knowingly collect personally identifiable information from children under 18. If you believe a child has provided us information, contact bilaldemirerlabs@gmail.com so we can take appropriate action.


Cookies

If we operate a website, it may use cookies or similar technologies for basic traffic measurement. You can control cookies in your browser. The mobile app does not use website cookies for health tracking.


Exporting or Deleting Your Data

Action How
Export Settings → Export CSV for doctor (share sheet on your device)
Delete Clear the app’s data in system settings, uninstall the app, or contact bilaldemirerlabs@gmail.com for guidance

Need help? bilaldemirerlabs@gmail.com


Changes to This Policy

We may update this policy from time to time. We’ll post the latest version at the public privacy URL used for Shotly’s App Store / Play listings. If changes are material, we will provide additional notice where required (for example, in-app notice).


Contact Us

Email: bilaldemirerlabs@gmail.com


Shotly Health Data Privacy Policy

Last Updated: July 29, 2026

This Health Data Privacy Policy supplements our main Privacy Policy and explains how we handle sensitive health information.


What Counts as Health Data in Shotly

Health data includes information you enter about:


Health Data Storage

Health data is stored on your device in Shotly’s local app storage. It is not uploaded to Shotly cloud databases as part of normal use.


Sources of Health Data

We collect health data from:

We do not currently import from Apple Health or Health Connect.


Why We Use Health Data

We use health data to:

We do not use health data for targeted advertising. We do not sell health data.


How We Share Health Data

We share health data only in limited circumstances:

  1. You — when you export or share a CSV (or screenshots) yourself.
  2. Support — only if you email us health details needed to resolve an issue.
  3. Legal requirements — if required by law (noting on-device data is usually not held by us).
  4. Corporate transactions — for information we actually hold, with notice where required.

We do not share health data for targeted advertising and do not sell it. We do not send health entries to analytics or attribution tools.


Your Rights

You have the right to:

If we deny a request we can fulfill, you can appeal by emailing us. You may also contact your regulator depending on where you live.