Pip App Privacy Policy

Effective date: August 7, 2026

Applies to: The Pip iPhone application (the "App")

Provider: Amity Holdings LLC, d/b/a Pip Diabetes Care ("Pip," "we," "us," or "our")

The short version

Pip keeps health records separate from optional shopping and store-account features.

  • Glucose readings, meter photos, notes, context tags, targets, reminders, and

reports stay on the iPhone. Pip does not receive them.

  • Photo reading runs on the iPhone. The user reviews every proposed value and

timestamp before saving.

  • The local health database and temporary meter images are excluded from

iCloud Backup and device-to-device migration.

  • Reports leave the App only when the user deliberately shares them through

Apple's share sheet.

  • Optional shopping, checkout, store-account, order, and AutoShip features use

Shopify and Recharge. They cannot access the local glucose log.

  • The App does not contain advertising, tracking, third-party analytics, or

session replay.

1. Health information stored on the iPhone

When a user saves a reading, the App can store the confirmed glucose value, date and time, optional context tag, optional note, targets, and reminder settings in a local database on that iPhone. Pip does not create or maintain a server-side copy of this health log.

Reminders are scheduled locally through Apple's notification system. Pip does not maintain a server-side reminder record.

2. Optional meter photo reading

Photo reading is optional. Manual entry remains available without camera access.

When a user chooses photo reading, the App processes the meter image on the iPhone and proposes text from the display. The image and proposed glucose value are not uploaded to Pip, Shopify, Recharge, or an artificial-intelligence service. The App shows the image, proposed value, and proposed meter timestamp for review. Nothing is saved until the user confirms it.

Temporary meter images are removed after save, cancellation, retake, failure, or next-launch recovery.

3. Storage, backup, and deletion

The local health database and temporary meter images are excluded from iCloud Backup and device-to-device migration. This privacy choice means Pip cannot restore the local health log after the App is deleted or when a user replaces the device.

Users can delete individual readings or erase all local Pip data within the App. Deleting the App also deletes its local database from that iPhone. Information previously exported or shared must be deleted separately from the destination the user selected.

4. User-directed reports and sharing

The App can create a PDF or CSV report on the iPhone. Sharing is entirely the user's choice. The report is passed to Apple's share sheet, and the user selects the destination, such as email, Messages, AirDrop, printing, or a storage provider. Pip does not receive a copy solely because the share sheet is used. Temporary export files are removed after the sharing flow.

5. Optional shopping and store account

The Shop tab uses Shopify to display current Pip products, maintain a cart, and complete checkout. A store account is not required to use the health log.

If a user signs in to a Pip store account, the App can retrieve account details such as name, email address, phone number, delivery address, and order history from Shopify. AutoShip management uses Recharge and Shopify customer authentication. Shopify, Recharge, and payment providers process commerce information under their applicable privacy terms.

Pip does not send glucose readings, meter photos, notes, context tags, targets, reminders, or reports to Shopify, Recharge, or payment providers.

Before a user first creates a cart, the App asks how Shopify may use shopping information. Necessary services support the cart, checkout, security, and orders. Optional analytics, preferences, marketing, and uses Shopify classifies as sale or sharing remain off unless the user allows them. These choices are stored on the iPhone, can be changed from Data and Privacy, and are sent to Shopify when a cart is created. Changing a choice creates a new checkout URL so the updated choice applies. The App does not request permission for cross-app tracking and does not contain advertising.

Payment details are entered and processed within Shopify Checkout and its payment providers. The App does not receive or store full payment-card details.

6. Information we do not collect or use

  • No server-side glucose log
  • No health-data account or cloud synchronization
  • No location or contacts
  • No advertising or cross-app tracking
  • No third-party analytics or session-replay SDK
  • No sale or rental of health information
  • No use of health information for marketing, insurance eligibility,

employment decisions, or unrelated profiling

7. Camera and notification permissions

The App requests camera permission only when a user chooses photo reading. Granting permission does not transmit an image. Notification permission is requested only when a user chooses a local reminder. Either permission can be revoked in iPhone Settings, and denying it does not prevent manual logging.

8. Security and retention

The App uses iOS data-protection and Keychain capabilities appropriate to local records and optional commerce sessions. Commerce connections use HTTPS and allowlisted Pip, Shopify, and Recharge destinations.

Local health information remains until the user deletes records, erases App data, or deletes the App. Commerce information is retained under Pip's website privacy policy and the applicable Shopify, Recharge, and payment-provider terms.

9. User choices and privacy rights

Users can enter readings manually, decline camera or notification access, review and correct a proposed photo reading, edit or delete individual readings, erase all local App data, export readings, sign out of a store account, change Shop privacy choices, request deletion of a store account, and delete the App.

Store-account deletion starts through the direct Delete Store Account action in the App and requires verification using the email address associated with the Shopify account. Pip confirms receipt immediately and generally completes a verified request within 30 days, subject to any legally permitted extension. An active AutoShip is not changed unless the user explicitly authorizes its cancellation. Limited order, payment, tax, fraud-prevention, and legal records may be retained where required. The local glucose log is separate and is not deleted unless the user separately chooses Erase Local Readings in the App.

Depending on location, a person may also have rights concerning commerce or other personal information held by Pip. Privacy requests can be sent using the contact information below.

10. Children's privacy

The App is not directed to children under 13, or the equivalent minimum age required by local law. A parent or legal guardian may use the App to help maintain a child's readings and is responsible for deciding whether to use its features.

11. Health information and intended use

Pip helps users record and organize glucose readings. It does not measure blood glucose, diagnose a condition, calculate medication doses, recommend treatment, provide clinical alarms, perform remote monitoring, or replace guidance from a qualified healthcare professional.

12. Changes to this policy

We may update this policy when the App or our information-handling practices change. We will update the effective date when changes are published. If a future version adds health-data cloud synchronization or otherwise changes how health information is handled, Pip will provide any notice or consent required before that feature is enabled.

13. Contact us

support@hellopip.com

Amity Holdings LLC, d/b/a Pip Diabetes Care

10 Burton Hills Blvd, Suite 400

Nashville, TN 37215

Any Questions?

We're happy to help!
Email us at community@hellopip.com