Privacy Policy

Your health data is yours.

MySpoons is built on a simple principle: we don't need your data, so we don't take it.

Last updated: 2026-05-23
Short version: MySpoons has no server that holds your health data. No account is required. Everything you track stays on your iPhone and your personal iCloud Drive. We do not sell, share, or analyze your health information.

1. Overview

MySpoons ("the App") is developed and published by Zima Logistics LLC ("we," "us," "our"), a Colorado limited liability company. This Privacy Policy describes how the App handles information when you use it.

The core design of MySpoons is privacy-by-architecture: we do not operate servers that receive or store your health data. There is no user account system. Your data is stored locally on your device and optionally backed up to your personal iCloud Drive, which only you control.

2. Data We Do Not Collect

The following data is never collected, transmitted, or accessible to Zima Logistics:

  • Your medications, doses, adherence records, or schedules
  • Your symptoms, severity ratings, triggers, or body map entries
  • Your vitals: heart rate, blood pressure, glucose, weight, SpO₂
  • Your daily check-ins: sleep, energy, mood, pain, brain fog, stress
  • Your health events, doctor notes, or milestones
  • Your food log, nutrition data, or protein supplement entries
  • Your menstrual cycle data
  • Any profile information you create for yourself or family members
  • Your name, email address, or any other personal identifier
  • Analytics or usage telemetry of any kind

3. Local Storage

All health data you enter into MySpoons is stored locally on your iPhone using SwiftData, Apple's on-device persistence framework. This data is included in standard iPhone device backups (encrypted and managed by Apple) and optionally in your personal iCloud Drive backup managed by MySpoons (described in Section 4).

Deleting the App permanently deletes local data. Restore from an iCloud Drive backup or iPhone backup if you need to recover it.

4. iCloud Drive Backup

MySpoons includes an optional iCloud Drive backup feature. When enabled, the App exports a snapshot of your data to a file in your personal iCloud Drive storage under Files → iCloud Drive → MySpoons Backups/.

  • Backups are stored in your personal iCloud Drive, not on Zima Logistics servers.
  • Apple's iCloud encryption applies. Neither Apple nor Zima Logistics can read the contents of your personal iCloud Drive files.
  • A rolling 10 snapshots are retained. Older snapshots are deleted automatically when a new one is created.
  • Backups are hash-gated: a new snapshot is only written when your data has changed since the last backup.

5. HealthKit Integration

With your permission, MySpoons can read from and write to Apple's HealthKit framework. HealthKit data is governed by Apple's own privacy framework:

  • MySpoons requests only the HealthKit data types you explicitly authorize.
  • Health data read from HealthKit is displayed in the App and not transmitted to any server.
  • Health data written to HealthKit (e.g., vitals you log in MySpoons) is subject to Apple's HealthKit privacy rules and your own privacy settings in the Apple Health app.
  • HealthKit data cannot be used for advertising or sold to third parties — this is enforced by Apple's App Store policies, which MySpoons complies with fully.

You can revoke HealthKit permissions at any time in iPhone Settings → Health → Data Access & Devices → MySpoons.

6. Third-Party API Calls (Anonymous)

MySpoons makes limited, anonymous calls to third-party services for specific features. These calls never include your name, email, device ID, or any health records — only the minimum necessary query data.

  • NIH RxNorm API (rxnav.nlm.nih.gov): Used for the drug interaction checker and medication database lookups. Only drug names are sent. No personal data is transmitted. This service is operated by the U.S. National Library of Medicine.
  • OpenFDA (api.fda.gov): Used for FDA drug recall alerts. Only drug names are queried. No personal data is transmitted. This service is operated by the U.S. Food & Drug Administration.
  • Open-Meteo (open-meteo.com): Used for weather correlation in health events. Only geographic coordinates (latitude/longitude) are sent — no user identity, device ID, or health data. Open-Meteo is an open-source weather API that does not require registration or API keys.
Note: These three external API calls are the complete extent of MySpoons' network activity. There is no analytics SDK, no crash reporting service, no A/B testing framework, and no advertising network integrated into the App.

7. In-App Purchases

Premium features are available via in-app purchase, processed entirely by Apple's App Store. Zima Logistics does not receive or store your payment card information. Apple's privacy policy governs payment data: apple.com/legal/privacy.

Purchase records (e.g., confirmation that you have an active subscription) are verified locally via StoreKit using Apple's receipt validation. No purchase data is sent to Zima Logistics servers.

8. Children's Privacy

MySpoons is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the App, please contact us at support@zima-logistics.com and we will take appropriate action.

9. Changes to This Policy

We may update this Privacy Policy when the App's functionality changes. The "Last updated" date at the top reflects the most recent revision. Continued use of the App after a policy update constitutes acceptance of the revised policy. For material changes, we will display an in-app notice.

10. Contact

Questions, concerns, or requests related to this Privacy Policy:

💌
Zima Logistics LLC — Privacy Contact support@zima-logistics.com