GILA

Privacy Policy

Effective 27 July 2026. Last updated 9 August 2026. Türkçe okuyun

The short version

Gila keeps your health records in Apple Health and in your own private iCloud account. We cannot see them. There is no Gila account, no login, and no server of ours holding your weight, medications, measurements, nutrition or symptoms.

The only information that ever reaches a server we control is a feedback report, and only when you choose to send one. The app contains no analytics, no advertising, no tracking, and no third-party code of any kind.

Who this policy covers

This policy applies to the Gila app for iPhone, iPad and Apple Watch, including its widgets and Watch complications. Gila is made by not bad engineering, a solo software studio run by Sinan Yasar.

This app-specific policy governs the Gila app. The not bad engineering company privacy policy covers this website. The website and the app are different things: the website is served through Cloudflare, and the app is not. Where the two policies differ about the app, this page is the one that applies.

What Gila stores, and where it lives

Gila records the things you enter yourself:

  • Body weight
  • Medication and injection logs, including dosage, injection site, pain level and your notes
  • Symptoms and their resolution dates
  • Body measurements such as waist, hips, chest, neck, arms and thighs
  • Nutrition entries for protein, fiber and water

All of it is stored on your device, in Apple Health where relevant, and in your own private iCloud database so it can sync between your iPhone, iPad and Apple Watch. That iCloud database belongs to your Apple Account. We have no access to it. This is not a promise to handle your records carefully, it is that we cannot reach them at all.

Your profile and preferences, which can include a name if you enter one, your starting weight, goal weight, height, unit choices and appearance settings, sync through your own iCloud key-value storage. Those are not accessible to us either.

Because there is no account system, we do not know who you are. Gila never asks for an email address, a phone number or a password in order to work.

Apple Health and HealthKit

Gila asks for permission to read from and write to Apple Health. Permission is yours to grant, refuse or revoke at any time in the Health app, and Gila works with the permissions you choose.

What Gila reads from Apple Health

  • Body weight, so that readings from your scale, your Apple Watch or another app appear in Gila without you retyping them, and so the chart reflects your real history.
  • Height, used together with weight to calculate BMI and related stats.

What Gila writes to Apple Health

  • Body weight you log in Gila, so the rest of your health apps stay in step with it.
  • Water you log in Gila, for the same reason. Gila writes hydration to Apple Health but never reads it back.

Health data is used only to provide the features you see in the app: your chart, your stats, your milestones and your history. It stays on your device, in Apple Health, and in your own iCloud.

What never happens to your Health data

  • It is never used for advertising or marketing of any kind, by us or by anyone else.
  • It is never used for data mining, profiling, or building models.
  • It is never sold, rented or traded.
  • It is never shared with third parties, including advertisers, data brokers and analytics providers.

Feedback reports, the one thing you send us

Gila has a feedback form. If you fill it in and submit it, that report is posted to our own intake service at api.notbad.engineering. Nothing is sent unless you actively submit a report. A report contains:

  • The message you typed
  • An email address for a reply, if you choose to give one, used only to answer you
  • The app version and build number
  • Your device model, operating system version, locale and preferred language, so a bug can be reproduced on the right hardware
  • A recent diagnostic log bundle, only if you opt in when sending

The diagnostic logs are written deliberately to avoid your health values. They record counts, states and error descriptions, for example how many records failed to sync and why, not what those records say. Your weights, doses, measurements and symptom notes are not in them.

Reports are stored on our infrastructure at Cloudflare and are delivered into a private issue tracker so that they can be read and acted on. Only the developer has access. The intake service records a salted, irreversible hash of your IP address purely to rate limit abuse, and does not keep the address itself.

How long reports are kept

  • Attached diagnostic logs are deleted automatically after 30 days.
  • The report itself, meaning your message, the app and device details and your reply address, is deleted automatically after 365 days.

You can ask for a report to be deleted sooner. Email legal@notbad.engineering from the address you used, or tell us roughly when you sent it and what it said, and it will be removed.

Third-party code and tracking

There is none. Gila has no third-party dependencies at all: no Swift Package Manager, CocoaPods or Carthage packages, no analytics SDK, no advertising SDK, no crash reporting SDK, no social login. The app is built entirely on Apple's own frameworks.

Gila does not track you across apps or websites, does not use the advertising identifier, and does not use Apple's App Tracking Transparency framework because it has nothing to ask you for. Its privacy manifest declares no tracking and no tracking domains, and the App Store privacy label matches what this page says.

We do not use your information to build a profile of you, we do not enrich it from other sources, and we do not sell it. There is no advertising in Gila.

Payments

Gila+ is a one-time purchase that unlocks the paid features. It is handled entirely by Apple's In-App Purchase system. Your payment details go to Apple, never to us, and we never see your card number, billing address or Apple Account credentials. The app only learns whether the purchase is active, so it knows what to unlock. There are no subscriptions and no recurring charges.

Deleting your data

Because your records live in your own storage, deleting them is something you can do without asking us.

  • Individual entries can be deleted inside the app, and that removes them from your iCloud sync as well.
  • Deleting the app removes its local data from that device.
  • To remove the synced copy, clear Gila's iCloud data from your Apple Account storage settings on any of your devices. This removes the records from every device signed in to that account.
  • Anything Gila wrote to Apple Health is managed by you in the Health app, under Gila's data sources, and stays there until you delete it. Deleting Gila does not delete what is already in Apple Health.
  • Feedback reports expire on the schedule above, or sooner if you ask.

You have the right to ask what we hold about you and to have it deleted. In practice, the only thing we can hold is a feedback report you sent us, so ask at legal@notbad.engineering and we will tell you what is there and remove it.

Age

Gila is intended for adults managing their own treatment and is not directed at anyone under 16. We do not knowingly collect information from children under 16. If you believe a child has sent us a feedback report, contact us and it will be deleted.

Gila is not a medical device and does not give medical advice. It records what you tell it. Decisions about your medication belong with you and your clinician.

Changes to this policy

If this policy changes, the new version will be posted at this same address, gila.fyi/privacy, with an updated effective date at the top. Material changes will also be noted in the app's release notes.

Contact

Questions about this policy, or about anything Gila does with your data, go to legal@notbad.engineering. A real person reads it.