Sundry — Privacy Policy

Last updated 24 August 2026

Sundry is local by default. You can use it without an account, export your information whenever you like, and optionally turn on end-to-end encrypted Backup & Sync. This policy explains what stays on your iPhone, what leaves it only when you choose a cloud feature, and the controls available to you.

Local by default

Everything you enter about your medications is stored in the app's own storage on your iPhone:

If you do not create a Backup & Sync account, these details are not uploaded to Sundry or Supabase. Sundry contains no advertising or third-party analytics and does not use HealthKit. Deleting the app removes its local database. Your normal encrypted iPhone or iCloud device backup may include app data according to the backup settings you control with Apple.

Optional encrypted Backup & Sync

If you choose to create a Backup & Sync account, Sign in with Apple is the only sign-in method Sundry offers. Apple authenticates your Apple Account and gives Supabase a short-lived identity token to verify. Supabase keeps the encrypted copy available to your other devices in its U.S. East region.

You can share your email address or use Apple's private relay address. If Apple supplies the name you chose on the first authorization, Sundry saves the non-empty name in your Supabase account metadata; Apple does not supply it again on ordinary later sign-ins. No medication contents are sent to Apple as part of sign-in.

Medication contents are encrypted on your iPhone before upload. Sundry uses AES-GCM with a random vault key. Supabase receives ciphertext, not readable medication names, strengths, notes, schedules, counts, time zones, refill information, or reminder-response history. Row-level security separately limits every vault and record to the signed-in account. Optional authenticator-app verification adds a second sign-in factor.

Supabase can still see and process the information needed to provide the account and sync service:

The vault key is kept in Apple's Keychain and Sundry first marks it for end-to-end encrypted iCloud Keychain synchronization. When iCloud Passwords & Keychain is available, a new Apple device normally restores and verifies the key automatically after sign-in; Sundry retries before presenting recovery choices. If a synchronized write is unavailable, Sundry retains a device-only Keychain copy and clearly identifies that limitation in Settings.

Sundry offers a separate Recovery Kit as an optional independent backup, not a condition of everyday sync. Revealing it requires Face ID, Touch ID, Optic ID, or the device passcode. The Recovery Kit is not sent to Supabase in readable form and cannot be reset or looked up by Sundry. A copy from the app is marked local-only and expires from the clipboard after ten minutes.

You can instead approve a new iPhone from another signed-in Sundry device. The existing iPhone scans a one-time QR code that carries the new iPhone's request identifier and ephemeral public key directly between the screens; this prevents the relay from substituting a different public key. A displayed six-digit code helps you confirm the two screens match but is not an encryption key. After device-owner authentication on the existing iPhone, the devices use ephemeral key agreement to create a one-time encrypted vault-key package. Supabase relays that ciphertext but lacks the private keys needed to open it. A request stops working after 15 minutes. Sundry attempts to delete it after approval or cancellation; if the phone is offline or disappears, expired relay metadata is deleted during later device-approval activity or when the cloud account is deleted, so wall-clock deletion immediately after expiry is not guaranteed. Losing access to iCloud Keychain, every already-authorized device, and the optional Recovery Kit can make the encrypted cloud copy permanently unreadable.

Sync is local-first: signing out or deleting the cloud account does not delete the medications already on that iPhone. Deleting an individual synced medication leaves an encrypted deletion marker containing an opaque ID and timestamps so an old device cannot restore it, and removes its encrypted response-event rows. Deleting the cloud account removes the account, vault, encrypted medication and response-event records, and those markers from the live database. Sundry asks for a fresh Apple confirmation and revokes the associated Apple authorization before server deletion. Supabase's managed backups may retain an earlier encrypted database state for its documented backup window; because the medication fields and deletion markers are ciphertext, Supabase still does not have the key needed to read them.

Local reminders and alarms

Dose reminders, follow-ups, snoozes, and iOS 26 alarm-style reminders are scheduled locally with Apple's notification and alarm systems. Sundry does not send medication names or reminder responses to a push-notification server. Notification and alarm titles always use a partially masked medication name, response actions require the iPhone to be unlocked, and categories use a generic hidden-preview placeholder. Apple controls your lock-screen preview setting, final delivery, notification permissions, Focus, Silent Mode, and background execution; Sundry displays the current preview setting and links to the relevant iPhone Settings page.

Each medication can use Off, Gentle, or Persistent reminders. Gentle schedules one standard notification. Persistent schedules Time Sensitive follow-ups and, when available and authorized, an alarm-style alert until the dose is explicitly answered, snoozed, skipped, or stopped. A normal notification swipe does not count as a response.

Your export

Settings can create a portable JSON export containing your full, unmasked medication data and response history. The file is created on your device and goes only to the destination you choose in Apple's share/save sheet. It is not encrypted by Sundry after export, so store or share it only somewhere you trust.

Optional AI photo features

Sundry has two optional features that use a photo:

When you use either, that single image is sent over an encrypted connection to Sundry's service hosted by Netlify, which passes it to OpenAI's GPT‑5.6 Sol model using priority processing. The answer comes back to your phone. Sundry's function does not save the image or include medication records, your account email, or a persistent user/device identifier in the AI request. Netlify and OpenAI necessarily process ordinary network metadata such as an IP address and request time to operate and protect their services.

Each OpenAI Responses API request is marked store: false. OpenAI states that API inputs are not used to train its models by default. Under OpenAI's default API data controls, abuse-monitoring logs may contain customer content and be retained for up to 30 days, unless law requires longer retention.

Please note that a photo of a pharmacy label often shows your name, your pharmacy, and your prescriber. That information is part of the image you choose to send. You can cover anything you would rather not send, or skip these features entirely and type the details in yourself.

Asking first, and changing your mind

Sundry asks for your explicit permission before the first photo of each kind, and explains what will be sent. You can decline and still use every other part of the app.

You can withdraw that permission at any time in Settings → Photo features inside the app. Turning it off means no image will be sent again unless you choose to turn it back on.

Your controls

Service providers

Supabase provides optional account infrastructure and encrypted sync; Netlify hosts the optional photo-processing functions; OpenAI analyzes only the photos you choose to send; and Apple provides Sign in with Apple for optional cloud accounts as well as the device, Keychain, optional iCloud services, notifications, alarms, and export sheet. These providers process data under their own terms and privacy commitments. Sundry does not sell personal information or share it for advertising, marketing, or profiling.

Children

Sundry is not directed at children and does not knowingly collect information from them.

Changes

If this policy changes, the date at the top of the page changes with it. If Sundry ever begins sending something new off your device, it will say so in the app before it does.

Contact

Questions about privacy in Sundry can go to joshua.w.lyons@outlook.com.