Shotly Privacy Policy
Effective Date: July 29, 2026 Last Updated: July 29, 2026
Operator / data controller: Bilal Labs (“Shotly,” “we,” “us”) Contact: bilaldemirerlabs@gmail.com
Introduction
We built Shotly to help people taking GLP-1 medications stay organized — tracking shots, doses, weight, and side effects in one place.
Shotly is designed to keep your health entries on your device. We take that seriously.
This Privacy Policy explains:
- What we collect
- How we use it
- Who we share it with
- Your rights and choices
- How to contact us
We’ve also created a separate Health Data Privacy Policy with extra details about sensitive health information.
Where This Policy Applies
| Platform | How it works |
|---|---|
| iOS App | No user account. Your health entries (shots, weight, side effects, treatment profile) are stored locally on your device. |
| Android App | No user account. Same local on-device storage as iOS. |
| Website (if any) | If we maintain a marketing site, it may use limited analytics to understand traffic. We do not design any website to collect health data. Please do not submit health information through website forms or support requests unless it is necessary. |
Key Terms (Plain English)
- Health data: Information about your health that you enter into the app (for example, injections, side effects, weight, medication profile).
- On-device storage: Data kept in the app’s local storage on your phone or tablet, not uploaded to Shotly servers as part of normal tracking.
What We Collect (and Why)
Account Information
Shotly does not require an account. We do not collect a login email, password, or social sign-in for the core app experience.
Health Data (Optional — you choose what to enter)
If you use Shotly’s tracking features, the app stores on your device information you enter, such as:
- GLP-1 medication profile (type, brand, dose, schedule)
- Injection / shot records (date/time, dose, site, status, notes)
- Side effects and wellness notes (type, severity, optional notes, optional linked shot / site)
- Weight entries (date, value, unit, optional notes)
- Optional height (for BMI-related display)
- Reminder preferences (shot, weight, side-effect check-ins)
Why? To provide Shotly’s core features and help you stay organized.
We do not send these health entries to analytics, advertising, or attribution tools.
Apple Health / Health Connect
Shotly does not currently import from or write to Apple Health (iOS) or Health Connect (Android). If we add those integrations later, we will update this policy and ask for your permission first.
Device & Technical Information
To keep the app reliable and up to date, we (and limited service providers) may process:
- App version and basic device/OS context needed to check whether an update is required
- Remote configuration values (for example, a minimum supported app version and App Store link)
Why? So we can nudge you to update when an older build is no longer supported, and keep the Service working.
This remote-configuration traffic does not include your health entries (injection logs, dosage, side effects, weight entries, or notes).
We do not use advertising identifiers for tracking. Apple’s privacy nutrition labels for Shotly reflect that we do not collect data types for tracking purposes as configured in our iOS privacy manifest.
Notifications (Optional)
If you enable reminders, the app schedules local notifications on your device (for example, shot day, weight check-in, side-effect check-in). Notification content is generated on-device from your settings; we do not operate a separate push-notification account tied to your identity for these reminders.
Payment and Subscription Information
Shotly is currently free to download and use. We do not process payment card details. If we introduce paid subscriptions later, purchases would be handled by the Apple App Store or Google Play Store, and this policy would be updated.
Non-Health Usage Analytics & Attribution
Shotly does not currently use third-party product analytics or attribution SDKs (for example, Mixpanel or AppsFlyer) inside the app.
If we add analytics later, we will update this policy, and we commit not to send your health entries through those tools.
Legal Bases (EEA/UK and similar regions)
If you are in the European Economic Area (EEA), the United Kingdom, or another region that requires a legal basis for processing, we process information under:
- Contract: To provide Shotly’s core features on your device (saving, displaying, and exporting your data when you ask).
- Legitimate interests: To keep Shotly reliable and secure, deliver mandatory update checks via remote configuration, and prevent abuse of the Service.
- Consent (where required): For optional features that require consent under applicable law (for example, notification permissions). You can withdraw consent in system or app settings.
- Legal obligations: To comply with applicable laws and respond to lawful requests.
Questions or objections: bilaldemirerlabs@gmail.com
Where & How We Store Your Data
| Data | Storage | Notes |
|---|---|---|
| Health entries & profile | On your device (local app storage) | Not uploaded to Shotly cloud storage as part of normal use. Remains until you delete it or uninstall / clear the app. |
| Remote Config (min version / store URL) | Google Firebase Remote Config | Fetches configuration only; does not store your health entries. |
| Support email | Your email provider ↔ ours | Only what you choose to include when you contact us. |
Backups: Depending on your device settings, your phone’s OS may include app data in device backups (for example, iCloud or Google backup). Those backups are controlled by you and the platform provider, not by Shotly servers.
How Long We Keep Your Data
| Data Type | Retention |
|---|---|
| On-device health entries | Until you delete them in the app (where available), clear app data, or uninstall the app. |
| Remote Config fetch metadata | Handled by Firebase under Google’s practices; used only to deliver configuration. |
| Support emails | As long as reasonably necessary to respond, keep a record of the request, and meet legal obligations. |
Your Privacy Rights
Depending on where you live, you may have rights to:
- Access your data
- Export your data
- Correct inaccurate data
- Delete your data
- Restrict or object to certain uses
- Withdraw consent at any time
In Shotly you can:
- Export your data as CSV from Settings (“Export CSV for doctor”)
- Correct entries by editing them in the app
- Delete data by clearing app data / uninstalling the app, or by contacting us for help
Email: bilaldemirerlabs@gmail.com
Requests, verification, and appeals
Because Shotly stores health entries on-device, we often cannot access your logs from our servers. For many requests, the practical path is export or delete on your device. If we deny a request we can fulfill, you can appeal by replying to our email. We will review and respond as required by applicable law.
Who We Share Data With (and Why)
We share data with service providers only as needed to run Shotly. They may use data only to provide services to us, subject to applicable contracts and safeguards.
| Vendor | Purpose |
|---|---|
| Google Firebase Remote Config | Minimum app version / update messaging (no health entries) |
| Apple / Google (app platforms) | App distribution; optional OS-level backups you control |
We do not sell your data. We do not share your data for targeted advertising. We do not send health entries to analytics or attribution tools.
Support communications
If you contact us by email, we use the information you provide to respond. If your message includes health details, we treat that as sensitive and use it only to help you.
Legal requirements
We may disclose information if required by law or legal process, or if we believe disclosure is necessary to protect rights, safety, and security — noting that on-device health entries are typically not in our possession.
Corporate transactions
If Shotly is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information we hold (for example, support correspondence or configuration systems) may transfer as part of that transaction. We will provide notice when required by law.
Security
We rely on the security of your device and the OS sandbox for on-device storage, plus reasonable safeguards for any limited server-side configuration we operate (for example, encrypted transit to Firebase).
No method of storage is 100% secure. Protect your device with a passcode / biometrics and keep your OS updated. Jailbreaking or rooting increases risk and may break the app.
Data Controller
Bilal Labs is the data controller responsible for personal information processed under this Privacy Policy in connection with Shotly.
Privacy requests: bilaldemirerlabs@gmail.com
International Data Transfers
Remote configuration may be processed on infrastructure in the United States or other locations where Google operates Firebase. Where required (such as under GDPR), we rely on appropriate safeguards such as Standard Contractual Clauses.
Your health entries stay on your device unless you export or share them yourself.
Children’s Privacy
Shotly is not intended for anyone under 18. We do not knowingly collect personally identifiable information from children under 18. If you believe a child has provided us information, contact bilaldemirerlabs@gmail.com so we can take appropriate action.
Cookies
If we operate a website, it may use cookies or similar technologies for basic traffic measurement. You can control cookies in your browser. The mobile app does not use website cookies for health tracking.
Exporting or Deleting Your Data
| Action | How |
|---|---|
| Export | Settings → Export CSV for doctor (share sheet on your device) |
| Delete | Clear the app’s data in system settings, uninstall the app, or contact bilaldemirerlabs@gmail.com for guidance |
Need help? bilaldemirerlabs@gmail.com
Changes to This Policy
We may update this policy from time to time. We’ll post the latest version at the public privacy URL used for Shotly’s App Store / Play listings. If changes are material, we will provide additional notice where required (for example, in-app notice).
Contact Us
Email: bilaldemirerlabs@gmail.com
Shotly Health Data Privacy Policy
Last Updated: July 29, 2026
This Health Data Privacy Policy supplements our main Privacy Policy and explains how we handle sensitive health information.
What Counts as Health Data in Shotly
Health data includes information you enter about:
- GLP-1 medication profile and dosing schedule
- Injections / shots (date/time, dose, site, status, notes)
- Side effects and well-being notes
- Weight entries and optional height
- Related tracking information you choose to store in the app
Health Data Storage
Health data is stored on your device in Shotly’s local app storage. It is not uploaded to Shotly cloud databases as part of normal use.
Sources of Health Data
We collect health data from:
- You (when you enter information in the app)
We do not currently import from Apple Health or Health Connect.
Why We Use Health Data
We use health data to:
- Provide Shotly’s core tracking, reminders, history, and export features
- Help you review your progress on-device
- Improve app reliability where that does not require sending health entries off-device
- Comply with legal obligations
We do not use health data for targeted advertising. We do not sell health data.
How We Share Health Data
We share health data only in limited circumstances:
- You — when you export or share a CSV (or screenshots) yourself.
- Support — only if you email us health details needed to resolve an issue.
- Legal requirements — if required by law (noting on-device data is usually not held by us).
- Corporate transactions — for information we actually hold, with notice where required.
We do not share health data for targeted advertising and do not sell it. We do not send health entries to analytics or attribution tools.
Your Rights
You have the right to:
- Access your health data (in-app)
- Export your health data (CSV)
- Delete your health data (clear app data / uninstall / contact us)
- Withdraw consent for optional permissions (for example, notifications) at any time
If we deny a request we can fulfill, you can appeal by emailing us. You may also contact your regulator depending on where you live.