Last updated 25 August 2026
Sundry is local by default. You can use it without an account, export your information whenever you like, and optionally turn on end-to-end encrypted Backup & Sync. This policy explains what stays on your iPhone, iPad, or Android device; what leaves it only when you choose a connected feature; and the controls available to you.
Everything you enter about your medications is stored in the app's private storage on your device:
If you do not create a Backup & Sync account, these details are not uploaded to Sundry or Supabase. Sundry contains no advertising, does not sell data, and does not read or write Apple Health or Android Health Connect. Sundry does not include its own general-purpose analytics tracker. The Android trusted-device QR scanner does send limited diagnostic and usage telemetry to Google, as explained below.
Deleting the app removes its local database. A normal encrypted Apple device or iCloud backup may include the iOS app data according to the backup settings you control with Apple. On Android, the operating system may include the local database and ordinary preferences in an encrypted cloud backup or device-to-device transfer; authentication sessions, Android Keystore material, and Sundry's device-bound secure preferences are excluded.
If you choose to create a Backup & Sync account, Sundry uses Sign in with Apple on iOS and Continue with Google on Android. Apple or Google authenticates your account and gives Supabase a short-lived identity token to verify. Supabase keeps the encrypted copy available to your other authorized devices in its U.S. East region.
The identity provider may share your email address, provider account identifier, and the profile name you approve. Apple may instead provide a private relay address and normally supplies a chosen name only on first authorization. Sundry stores any non-empty name in Supabase account metadata. No medication contents are sent to Apple or Google as part of sign-in.
Medication contents are encrypted on your device before upload. Sundry uses AES-GCM with a random vault key. Supabase receives ciphertext, not readable medication names, strengths, notes, schedules, counts, time zones, refill information, or reminder-response history. Row-level security separately limits every vault and record to the signed-in account. Optional authenticator-app verification adds a second sign-in factor.
Supabase can still see and process the information needed to provide the account and sync service:
On iOS, the vault key is kept in Apple's Keychain and Sundry first marks it for end-to-end encrypted iCloud Keychain synchronization. When iCloud Passwords & Keychain is available, a new Apple device normally restores and verifies the key automatically after sign-in; Sundry retries before presenting recovery choices. If a synchronized write is unavailable, Sundry retains a device-only Keychain copy and clearly identifies that limitation in Settings. On Android, the local vault key and session are wrapped with a device-bound Android Keystore key and excluded from operating-system backup, so a restored app may require the Recovery Kit or approval from an already authorized device.
Sundry offers a separate Recovery Kit as an optional independent backup, not a condition of everyday sync. Revealing it requires device-owner authentication such as Face ID, Touch ID, Optic ID, an Android biometric, or the device credential. The Recovery Kit is not sent to Supabase in readable form and cannot be reset or looked up by Sundry. A copy from the app is marked local-only and expires from the clipboard after ten minutes.
You can instead approve a new supported device from another signed-in Sundry device. The existing device scans a one-time QR code that carries the new device's request identifier and ephemeral public key directly between the screens; this prevents the relay from substituting a different public key. A displayed six-digit code helps you confirm the two screens match but is not an encryption key. After device-owner authentication on the existing device, the devices use ephemeral key agreement to create a one-time encrypted vault-key package. Supabase relays that ciphertext but lacks the private keys needed to open it. A request stops working after 15 minutes. Sundry attempts to delete it after approval or cancellation; expired relay metadata is also deleted during later approval activity or when the cloud account is deleted. Losing access to every already-authorized device and the optional Recovery Kit can make the encrypted cloud copy permanently unreadable.
An Apple identity and a Google identity can share one encrypted account only when Supabase recognizes them as identities of the same account. Apple's Hide My Email may prevent automatic email matching. Do not assume that two sign-ins with different addresses will combine; keep your Recovery Kit and use an already authorized device when linking or recovering access.
Sync is local-first: signing out or deleting the cloud account does not delete medications already stored on that device. Deleting an individual synced medication leaves an encrypted deletion marker containing an opaque ID and timestamps so an old device cannot restore it, and removes its encrypted response-event rows. Deleting the cloud account removes the account, vault, encrypted medication and response-event records, and those markers from the live database. A Google-only account can be deleted from Android after fresh Google confirmation. An Apple-linked account requires fresh Apple confirmation and revocation; use the iOS app or the account-deletion request page when Android cannot safely complete that provider revocation. Supabase's managed backups may retain an earlier encrypted database state for its documented backup window; because medication fields and deletion markers are ciphertext, Supabase still does not have the key needed to read them.
On Android, Sundry uses Google Code Scanner only when you choose to scan the one-time QR code for trusted-device approval. Google states that code image processing occurs on the device and that it does not store the image or scan result. The underlying ML Kit library collects limited device and app information, device or per-installation identifiers, performance metrics, API configuration and size information, feature versions, event types, and error codes for diagnostics and usage analytics. Because Sundry enables auto-zoom, Google may also receive a randomly generated scan-session identifier, zoom changes, and predicted barcode bounding-box coordinates. Google states that this telemetry is encrypted in transit and is not transferred to third parties. It does not include your medication records or the readable vault key.
Dose reminders, follow-ups, and snoozes are scheduled locally with the notification and alarm systems on your device. Sundry does not send medication names or reminder responses to a push-notification server. Reminder titles use a partially masked medication name, and response actions require device unlock. Apple and Google control final delivery, lock-screen display, notification permissions, Focus or Do Not Disturb modes, battery restrictions, and background execution.
Each medication can use Off, Gentle, or Persistent reminders. Gentle schedules one standard local notification. Persistent schedules follow-ups until the dose is explicitly answered, snoozed, skipped, or stopped. On iOS 26 and later it can also use an authorized alarm-style alert. On Android it uses AlarmManager, requesting exact-alarm and full-screen capabilities where Android makes them available and falling back to high-priority notifications and inexact delivery when those capabilities are unavailable. A normal notification swipe does not count as a response. No mobile operating system can guarantee delivery in every condition.
Settings can create a portable JSON export containing your full, unmasked medication data and response history. The file is created on your device and goes only to the destination you choose in the system share or save chooser. It is not encrypted by Sundry after export, so store or share it only somewhere you trust.
Sundry has two optional features that use a photo:
When you use either, that single image is sent over an encrypted connection to Sundry's service hosted by Netlify, which passes it to OpenAI's GPT‑5.6 Sol model using priority processing. The answer comes back to your phone. Sundry's function does not save the image or include medication records, your account email, or a persistent user/device identifier in the AI request. Netlify and OpenAI necessarily process ordinary network metadata such as an IP address and request time to operate and protect their services.
Each OpenAI Responses API request is marked store: false. OpenAI states that API inputs are not used to train its models by default. Under OpenAI's default API data controls, abuse-monitoring logs may contain customer content and be retained for up to 30 days, unless law requires longer retention.
Please note that a photo of a pharmacy label often shows your name, your pharmacy, and your prescriber. That information is part of the image you choose to send. You can cover anything you would rather not send, or skip these features entirely and type the details in yourself.
Sundry asks for your explicit permission before the first photo of each kind, and explains what will be sent. You can decline and still use every other part of the app.
You can withdraw that permission at any time in Settings → Photo features inside the app. Turning it off means no image will be sent again unless you choose to turn it back on.
Supabase provides optional account infrastructure and encrypted sync; Netlify hosts the optional photo-processing functions; OpenAI analyzes only the photos you choose to send; Apple provides Sign in with Apple, Keychain, optional iCloud services, notifications, alarms, and system sharing; and Google provides Continue with Google, Android platform services, and the optional trusted-device QR scanner. These providers process data under their own terms and privacy commitments. Sundry does not sell personal information or share it for advertising, marketing, or profiling.
Sundry is an organization, supply-projection, and reminder tool. It is not a medical device, does not diagnose or treat any condition, and does not provide medical advice. Counts, projections, AI photo results, sync, and reminders can be wrong, delayed, or unavailable. Always check medication details and photo suggestions yourself, follow the label and the directions from your licensed healthcare professional, and speak with your doctor or pharmacist before changing how you take, refill, or stop a medication. If you think you may be experiencing a medical emergency, contact local emergency services.
Sundry is not directed at children and does not knowingly collect information from them.
If this policy changes, the date at the top of the page changes with it. If Sundry ever begins sending something new off your device, it will say so in the app before it does.
Questions about privacy in Sundry can go to joshua.w.lyons@outlook.com.