1. Who is responsible
ZinXan AI Ltd provides JabKeeper and jabkeeper.com. We are registered in England and Wales, company number 12451101.
We are responsible as controller for personal information whose purposes and means of processing we determine in connection with JabKeeper, our website and support. Most diary processing happens on your device; that does not mean that health information is unprotected or that this policy applies only to information uploaded to us.
Our privacy contact is matilde.enevoldsen19@gmail.com. You may also write to our registered office, marked “JabKeeper Privacy”. The same contact handles access requests, deletion requests, consent questions and complaints. The person accountable for privacy, and our privacy officer, is the Director of ZinXan AI Ltd, who can be reached at the same email and postal address.
This policy covers the iPhone app, website and support. It does not replace the privacy notices of Apple, an email or calendar provider you choose, or a recipient to whom you independently send information. Our Consumer Health Data Privacy Policy (Washington) and Nevada Consumer Health Data Privacy Policy set out the additional information and rights those states' health-data laws require.
2. The important distinction: local data and data we receive
Your JabKeeper diary is stored locally on your device. We do not receive a copy of it through the app. There is no JabKeeper account, developer-operated diary cloud sync, advertising SDK or third-party analytics SDK in the app.
Some information can nevertheless leave your device when you choose an integration, buy through Apple, visit our website or contact support. In particular, Apple Health and Calendar can contain separate copies under your control, and an email to support reaches us and the email providers involved. The following sections explain those different flows rather than treating all of them as “no data collection”.
We do not sell personal information, share it for cross-context behavioural advertising, or use health information for advertising, data brokerage, credit decisions or insurance decisions. We do not use your diary or identifiable support health information to train artificial-intelligence models. We do not operate an advertising profile or infer a diagnosis from a visit to our website. We do not make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects on you.
3. Information processed on your device
Depending on the features you use, JabKeeper stores and processes:
- Medicine and injection records: medicine names, prescribed dose values and units, dates, injection sites, schedules, notes and reminder preferences.
- Weight, goals and nutrition: weight, height, selected goals and pace, food entries and their calorie or protein values, and outputs such as totals, BMI, charts and estimated goal dates.
- Symptoms and settings: symptom or side-effect descriptions, severity, associated dates, app preferences, and the date you gave health-data consent and confirmed you are 18 or over.
- Purchase status: the product and entitlement information needed to recognise an eligible paid unlock.
The purpose is to provide the diary, displays, organisational reminders and other features you choose. Records you type are supplied by you. Body-weight readings may also come from Apple Health when you authorise reading that category. Calculations are generated from the available inputs on your device.
Much of this information is health information and may be special-category or sensitive personal information under applicable law. A calculation derived from health records can itself be health information. We do not treat it as anonymous merely because you have not created an account.
These local records are not available to our support staff unless you independently send information to us. JabKeeper does not give us remote access to your diary.
4. Apple Health
Apple Health integration is optional and requires your permission. The integration is limited to reading and writing body mass (body weight) and writing dietary energy consumed for the corresponding features. JabKeeper does not write your medication names, doses or injection history to Apple Health. During setup, you can also choose to read your latest body weight from Apple Health once; ongoing Health sync is part of the paid unlock and stays off until you turn it on.
Imported body-weight data is used for your local weight history and related displays. Weight and dietary-energy entries you choose to write become records in Apple Health. The integration does not upload your diary to a JabKeeper server.
Apple Health can have its own storage, synchronisation, backup and sharing arrangements, depending on your Apple settings and permissions you give to other apps or people. Apple's handling is explained in Apple's privacy information. Review the Health permission screen and your Health and device settings.
You can refuse or revoke the relevant Health permissions. An affected Health feature may then stop working; unrelated diary functions do not depend on granting those permissions.
How deletions work while Health sync is on:
- If you delete a weight or food entry that JabKeeper wrote to Apple Health, JabKeeper also asks Apple Health to delete that entry. If it can't do so straight away, it tries again the next time you open the app while sync and write permission are on.
- If you delete a weight that JabKeeper imported from Apple Health, JabKeeper hides it from your diary. The original stays in Apple Health.
- If you delete an imported weight in Apple Health or its source app, JabKeeper removes its copy the next time it syncs.
Revoking access, turning sync off, withdrawing consent or deleting JabKeeper does not remove entries already written to Apple Health. Review and delete those entries in Health as needed.
5. Calendar and notifications
Calendar integration is optional and part of the paid unlock. If you turn it on and allow calendar access, JabKeeper adds one event for your next injection to your device's default calendar, with an alert one hour before. The event title shows your medicine and dose, and its notes say that the schedule is your own record and not dosing advice. JabKeeper updates the event when your schedule changes.
The event is handled by the service behind your default calendar. It may synchronise through iCloud, Google, Microsoft or another provider, and a shared or workplace calendar may expose it to other people or an administrator. We do not receive your calendar through this feature or use it to build a profile of your activities.
To stop Calendar sharing, turn off Calendar in JabKeeper's settings. JabKeeper then removes its event, as long as calendar access still allows it. If you revoke calendar access first, JabKeeper cannot remove the event, so delete it in your calendar.
Notifications are scheduled on your device for the reminder features you enable. Injection reminders name your medicine and dose. Their contents may be visible in notification previews, on a lock screen or through your device's notification-sharing arrangements. You can change previews and notification permissions in device settings. Turn off reminders or notification permissions to stop those alerts. Previously delivered notifications may require separate deletion.
6. Purchases and information supplied by Apple
Apple handles payment, billing details and its customer relationship under its own terms and privacy information. We do not receive your payment-card number or Apple Account password.
JabKeeper uses Apple's product and transaction-entitlement information to determine whether a paid feature is available and to restore eligible purchases. This does not require sending your health diary to us or Apple for payment verification.
As an App Store developer, we may receive the sales, financial, refund or transaction information that Apple makes available to us for distribution, accounting and support. Those reports are separate from your diary. Do not assume that a transaction reference is anonymous simply because it is not your name.
Apple may also make app-related crash, performance or other technical reports available through its developer services, depending on the service and relevant device-sharing settings. This is distinct from adding an analytics SDK to JabKeeper. We use any such information we receive to investigate faults, reliability and security, not to identify treatment patterns or advertise to you. We do not intentionally place diary contents in diagnostic reports.
7. Support and other correspondence
When you email us, we receive your email address, any name or signature included, the message and attachments, and ordinary email-delivery information. For a software problem, useful information may include your device model, iOS version, app version and steps needed to reproduce the issue.
The published support address uses Gmail, provided by Google. Your own email provider also handles messages you send. Sending an email is therefore not the same as keeping an entry only in JabKeeper. Google's services have their own applicable terms and privacy information.
Please do not send your full diary, prescription, patient identifiers, payment-card details or other unnecessary sensitive information. Use a test entry and redact screenshots wherever possible. We do not need your medical history to explain how a button or purchase works.
We use correspondence to respond to the request, investigate a problem, handle a rights request or complaint, and maintain necessary security or legal records. We do not add support correspondents to a marketing list.
If a support issue genuinely requires us to handle identifiable health information, we will explain what is needed and why and obtain separate explicit consent where required before using it for that purpose. Unsolicited health information is not treated as permission for unrestricted use: we minimise it and remove unnecessary material rather than putting it into general development, analytics or AI tools. If law requires limited retention for a legal claim, we apply that exception narrowly.
8. Website, cookies and technical records
You can read our website without a JabKeeper account. The website does not use advertising pixels, behavioural analytics or tracking cookies.
It stores two small items in your browser, neither of which is a health record or an advertising identifier:
- Theme preference. If you use the light or dark switch, your choice is saved in your browser's local storage so it is remembered. If you would rather it isn't stored, don't use the switch, or clear the site's stored data: the site then follows your device's light or dark setting.
__cf_bmsecurity cookie. Our website is hosted on Laravel Cloud, and requests pass through Cloudflare's network for delivery and protection. Cloudflare may set this strictly necessary cookie to tell people apart from automated bots. It expires after 30 minutes of inactivity and is not used for tracking or advertising.
Serving and protecting a website involves processing connection information. Laravel Cloud and Cloudflare, as our hosting and infrastructure providers, may process an IP address, request time and requested page, together with technical connection or browser information, to deliver the page, diagnose errors and protect the service. We do not use these records to determine which medicine a visitor takes.
The website has no form for uploading a health diary. A link to Apple or another website takes you to a separately operated service. Its processing is covered by its own notice.
Before adding a non-essential cookie, SDK, advertising service or materially different tracking purpose, we will update the information provided to you and obtain any consent the law requires. This policy does not pre-authorise such a change.
9. Purposes, legal bases and your choices
For processing to which the UK GDPR or EU GDPR applies, we use the following bases, according to the particular activity:
Health processing in the app. For health-data processing for which we are responsible, our basis is your consent under Article 6(1)(a) and your explicit consent under Article 9(2)(a). JabKeeper asks for this consent on a dedicated screen before you enter any health information, as a separate choice from confirming your age and accepting the Terms. An operating-system permission controls technical access; it is not treated as automatically satisfying every legal consent requirement. Apple Health and Calendar are separate, optional choices that stay off until you turn them on.
Supplying purchases and requested non-medical support. We process the information objectively necessary to supply the paid entitlement, deal with a purchase issue or answer a service request under Article 6(1)(b), where needed for our contract or steps you request before it. This basis does not authorise unrelated health-data use.
Security, reliability and ordinary administration. We rely on Article 6(1)(f) where necessary for legitimate interests in maintaining a secure website, preventing abuse, resolving technical faults and administering ordinary business correspondence, after considering your rights and the sensitivity of the information. These interests are not a basis for advertising with health data.
Legal duties and claims. Article 6(1)(c) applies where a legal duty requires a record or response. Article 6(1)(f) may apply to necessary handling of a legal claim. If special-category information is genuinely necessary to establish, exercise or defend a legal claim, Article 9(2)(f) may apply. We do not treat a general desire to keep records as a health-data exception.
Elsewhere, we obtain meaningful or express consent where local law requires it and use any requested-service or other legal exception only within its conditions. The Consumer Health Data Privacy Policy explains the additional US rules.
Reading this policy, accepting the Terms, buying the app, or remaining silent is not explicit health-data consent. You can withdraw your consent at any time in JabKeeper under Settings, Privacy & support, “Withdraw consent and delete diary”, or by contacting our privacy address. Withdrawing takes one confirmation and is at least as easy as giving consent. You may separately revoke Health, Calendar and notification permissions through their controls.
When you withdraw consent in the app, JabKeeper stops processing your health information, deletes your diary from the device, cancels its reminders and removes its Calendar event where calendar access allows. Your paid unlock is not affected. Entries already written to Apple Health stay there until you delete them in Health. To use JabKeeper again, you would need to give consent again and start a new diary.
Withdrawal does not make earlier lawful processing unlawful. We stop the affected consent-based processing and address deletion unless another lawful requirement permits limited retention. We do not impose a penalty or remove unrelated purchased functionality.
You are not required to provide us with health records for general support. Without an email address or other reply route, we may be unable to answer a message. Without the data needed for a particular local calculation, the app cannot produce that calculation.
10. Who receives information
We limit recipients according to the activity:
Services you choose. Apple Health receives the weight and dietary-energy information you authorise. The service behind your default calendar receives the injection event when you turn Calendar on. An email provider or other recipient you independently choose receives what you send through it. These choices do not give us a general permission to distribute the rest of your diary.
Providers supporting our operations. Laravel Cloud and Cloudflare handle website connection information. Google handles correspondence sent to the published Gmail address. Relevant professional advisers may receive the minimum administrative information needed for a particular legal, accounting or security task. A provider acting on our behalf must be bound by the protections and instructions required by applicable law; an independent service provider remains responsible for its own processing.
Legal recipients. We may disclose information we actually hold to an authority, court or other recipient where disclosure is legally required, or where another specific legal basis permits a necessary disclosure. We assess health information under the additional rules that protect it. This is not a general permission to release health data whenever it might be useful to someone. We cannot supply a local diary we do not possess or access.
We do not share health information with advertisers, data brokers, employers, insurers or pharmaceutical companies for their commercial purposes. We do not disclose consumer health data to an affiliated business for its independent use.
A merger or business transfer is not permission to sell health information or change its permitted uses. Any handling of personal information we actually hold in a business transition must remain within applicable law, these notices and any required separate consent. There is no server-held JabKeeper diary database to include in a business transfer.
11. Retention and deletion
Local app records. Records remain on the device until you delete them, withdraw consent in the app, or delete the app and its data, subject to device operation and storage. The local diary database is excluded from device backups. We cannot recover it for you. “Offload App” normally preserves documents and data and is not a deletion method.
Health and Calendar copies. These remain under the controls and retention arrangements of the relevant service. JabKeeper removes its Calendar event when you turn Calendar off or withdraw consent, where calendar access allows, and deletes individual Health entries it wrote when you delete them in the app while Health sync is on (section 4). Otherwise, including after you delete the app, remove those copies in Health or Calendar.
Correspondence. We keep support messages only as long as needed to handle the issue and necessary follow-up. The criteria are whether the matter is still open, a related issue or dispute is reasonably outstanding, and whether a specific legal or security obligation requires a limited record. Unnecessary health attachments are removed rather than retained as a standard support archive. We periodically review closed correspondence and delete or minimise it when the remaining purpose ends.
Technical and financial records. Connection and diagnostic information is retained for the shortest period reasonably needed for the relevant operational or security purpose, taking account of incident investigation and provider settings. Financial and necessary legal records are kept for the period required by the applicable accounting, tax or other legal obligation. Those records do not need to include your diary.
A deletion request concerning information held by us is handled under the deadlines and exceptions of applicable law. We tell you when a lawful exception prevents complete deletion and limit the retained information to that exception. Where we must pass a request to a provider or other recipient, we do so. Copies in backups are dealt with within applicable statutory deadlines and are not restored to ordinary use to avoid a deletion request.
12. International processing
We operate from the United Kingdom. Information you send to support is handled in connection with our UK business. External providers, including Google for email, Laravel Cloud and Cloudflare for the website, and the Apple or calendar services you use, can process information in other countries, including the United States. A provider's location does not mean your local diary has been uploaded there.
Where a transfer we make is restricted by applicable data-protection law, we use a lawful transfer mechanism before it occurs. Depending on the recipient and law, this may be UK adequacy regulations, an EU adequacy decision, or approved contractual safeguards, together with the required assessment and supplementary protection. For UK or EEA transfers, those safeguards can include the appropriate Standard Contractual Clauses and, for UK transfers, the applicable UK transfer agreement or addendum. We do not assume that a provider qualifies for an adequacy scheme merely because it operates in a country covered by one.
You can ask our privacy contact for the countries and safeguards relevant to information we hold about you and for a copy or explanation of applicable safeguards, with necessary confidential or third-party information redacted. Your acceptance of this policy is not consent to an otherwise unlawful international transfer or a waiver of our accountability.
13. Security
Local storage avoids maintaining a developer-held cloud diary, but no device or service is risk-free. We use safeguards proportionate to the information and processing for which we are responsible, limit access to correspondence to those who need it, and do not intentionally record health entries in diagnostic logs.
Protect your device and email account, install relevant updates, and review lock-screen and shared-calendar settings. We do not promise that the app has a separately encrypted database, an independent app passcode or a particular security certification unless that protection is expressly described and actually provided in your version.
Where a security incident creates a legal notification obligation, we will notify the relevant regulator, affected people or other recipients as the applicable law requires. Different laws have different deadlines and tests; there is no single worldwide notification period.
14. Access, correction, deletion and other rights
Depending on the law that applies, you may request confirmation of processing, access to information, correction, deletion, restriction, a portable copy, withdrawal of consent, or an objection to particular processing. You may also have rights concerning recipients, sensitive information, automated decisions and appeals. These rights have legal conditions and exceptions; we will explain a refusal rather than treating a right as unavailable merely because the app has no account.
You can view, edit and delete your local entries in JabKeeper, or delete the whole diary by withdrawing consent. We cannot look up or remotely alter a diary we do not receive, but we will explain the available local controls and provide assistance required by law. You do not have to upload your whole diary or create an account to make a request. Where a portable copy is legally required, we will explain how it can be provided for the information within our responsibility; this is not a claim that every app version has a built-in export button.
To make a request about information we hold, email matilde.enevoldsen19@gmail.com or write to our registered office. Explain what you need and the service or correspondence concerned. We may request proportionate information needed to verify your identity or an agent's authority; we do not request unrelated health records as identity evidence.
For UK and EEA rights requests, we normally respond within one month, subject to the particular statutory rules. Where an extension is legally permitted, we explain it within the required period. For applicable US requests, the relevant state deadline applies; Washington and Nevada health-data deadlines and appeals are set out in our separate policies for those states. A shorter applicable deadline takes priority.
Requests are normally free. We charge a fee or decline a request only where the applicable law permits it and explain the basis. We do not unlawfully discriminate against someone for exercising a privacy right.
15. Additional regional information
United States. We do not sell personal information or share it for cross-context behavioural advertising, including sensitive information. We do not use precise location to track visits to healthcare locations or operate healthcare geofences. We do not offer financial incentives in exchange for personal information. Depending on your state's law and its applicability, you may have rights to know, access, correct, delete, obtain a copy, opt out of particular uses, limit sensitive-data use, use an authorised agent and appeal a refusal. The data categories and purposes described above also describe the information handled by this service; we do not keep an undisclosed advertising or commercial health-profile category.
Because there is no sale or targeted-advertising sharing to opt out of, that remains our practice whether or not your browser sends Global Privacy Control or “Do Not Track”. We do not claim that this statement replaces a technical signal-handling duty if our practices change. If we decline a request you make under a US state privacy law, you can appeal by replying to our decision; we respond in writing, with reasons, within the period that law sets, and tell you how to contact your state Attorney General if we deny the appeal. Our Washington and Nevada consumer health data privacy policies supplement these provisions. Protection under HIPAA is not assumed merely because information concerns health; applicable consumer-health and medical-confidentiality laws, including California's Confidentiality of Medical Information Act, are not excluded by this policy, and we keep any medical information we receive confidential to the standard those laws require.
Canada. We obtain the form of consent required for the information and purpose, including express consent where required for sensitive information. You may request access and correction and raise a privacy concern with us or the appropriate federal or provincial privacy authority. Applicable provincial protections and language requirements are not waived.
Australia and New Zealand. Where their privacy laws apply, you may seek access and correction and complain through the contact route below. We remain responsible for applicable overseas-disclosure obligations; this policy does not ask you to waive them.
Other locations. We honour rights and obligations that apply to us under your local law. This policy is not a representation that every feature is authorised for distribution in every country, or that local requirements are identical.
16. Age and children
JabKeeper is intended for adults aged 18 or over. The app asks you to confirm that you are 18 or over before you start, and we do not direct it to children or knowingly solicit children's personal information through support. We do not collect a date of birth merely because this policy sets an age limit.
If you believe a child has sent personal information to us or that an issue concerning children's privacy needs attention, contact us without sending unnecessary health information. We will investigate and take the action required by applicable law, including deletion where appropriate. An age statement does not remove an obligation that arises from our actual knowledge or the way a service is used or marketed.
17. Complaints and regulators
You can make a privacy complaint through the same email or postal contact as a request. A particular form or email subject is not required. We acknowledge data-protection complaints within 30 days of receipt, investigate and keep you informed, and communicate an outcome without undue delay. A more protective applicable deadline takes priority. This complaints process is separate from the one-month UK and EEA rights-request response period.
You may complain to a competent regulator without losing any right to go to court. Relevant routes include the UK Information Commissioner's Office (which becomes the Information Commission on 30 September 2026), your EEA supervisory authority, the Office of the Privacy Commissioner of Canada or a competent provincial authority, the Office of the Australian Information Commissioner, and the New Zealand Privacy Commissioner. US health-data complaint routes appear in our Washington and Nevada consumer health data privacy policies.
18. Changes to this policy
We update the version and effective date when this policy changes. For a material change, we give a prominent notice through an appropriate app or website channel before it takes effect where required. We do not retrospectively apply a materially different health-data purpose based only on a changed webpage or continued use.
Where a new activity requires consent, including separate consent to health-data sharing, we obtain it before beginning that activity. Existing choices and legally binding privacy commitments are respected unless changed through a lawful process.
For a copy of this policy, an accessible version, or a privacy question, contact matilde.enevoldsen19@gmail.com.