Last updated: July 3, 2026 · Applies to the POIS Tracker iOS app ("the app").
POIS Tracker helps people living with post-orgasmic illness syndrome (POIS) log their symptoms, treatments and recovery, and explore what helps them. It is operated by Tiny Objects ("we", "us"). Questions about this policy: tinyobjectssoftware@gmail.com.
The short version: everything you log stays on your device — your raw entries are never transmitted to us. There are no analytics, no tracking, no ads, and we never sell data. The only optional sharing is a community contribution you have to explicitly turn on, and even that sends only anonymised summary statistics (never your entries), pooled so the results describe groups of people, not you.
The app keeps the following in its private database on your device. None of it is ever sent to us — not even if you opt in to community contribution, which sends only the anonymised summary statistics described further below:
Viewing the Community section requires no sharing at all. It shows pooled community results computed on our server from consented contributions (sections may be empty until enough people have contributed). Reading it only downloads those group-level aggregates — nothing about you is sent.
Contributing is separate, off by default, and only available after an explicit consent screen restricted to users who confirm they are 16 or older. If you consent, the app computes and sends only summary statistics — never your raw daily logs. A contribution contains, per factor you have enough data on:
Each item is labelled only by the name of the factor and outcome (for example "magnesium" and "wellbeing"). Never included: your daily logs, any exact dates or timestamps, notes or free text, your profile, or any account, device, or advertising identifier.
Rate-limiting without identifying you. So that no single device can flood the pool, each contribution carries a random token the app generates for itself. The server never receives that token directly — it receives only a one-way cryptographic hash of it, which it uses solely to enforce "at most one contribution per device per week". The hash cannot be reversed to the token, is never linked to the contents of your contribution, and is never shown to anyone.
k-anonymity. A factor's community result is only ever published once several independent people (currently at least three) have contributed to it — a pooled number that describes a group is shown, never anything traceable to one person. Because each contribution carries only summary statistics for a neutrally-named factor (no name, age, sex, location, dates, or free text), a pooled result over that group cannot be traced back to any individual.
Separately from the statistics above, you can choose to share an individual treatment trial with the community, via an explicit per-trial toggle when you set the trial up. This is a public post: other users of the app can see it and rate whether it was useful. A shared trial contains only structured data: the treatment(s) tried (by their library name), the schedule as day numbers (never calendar dates), your 0–10 daily wellbeing and symptom series over the trial, whether it was completed as planned, and — only if you tick them — coarse ranges of profile fields (for example an age band like "25–34", never an exact age). Your trial's name, your notes, calendar dates, and any identifier never leave the device; the server also rejects any value outside these structured formats. You can stop sharing at any time from the trial's own screen — the app holds a per-trial deletion token and uses it to remove the shared copy; deleting your account does the same for everything you shared. Usefulness votes are counted once per device using the same one-way hash described above, and are never linked to identity.
Withdrawal and deletion. At the moment you contribute, the server returns a one-time deletion token, stored on your device. Withdrawing consent in Settings stops future contributions, deletes anything still queued locally, and — if a contribution was already sent — uses that token to request its deletion from the server. A shared trial can be stopped at any time from its own screen, which removes it from the public feed; deleting your account requests removal of both your pooled contribution and every trial you shared. If you choose "delete anyway" while offline, the local data is erased immediately but any already-anonymised shared trial the server didn't confirm may remain in the public feed. Please note one inherent limit of any aggregate: a community result that was already computed and shown to others before your deletion cannot be "un-mixed" from that past result; your data is removed from all future aggregations.
NSPrivacyTracking = false).The app's database is protected with iOS file protection
(NSFileProtectionComplete), which keeps it encrypted while your device is locked.
You can additionally require Face ID / Touch ID or your passcode to open the app
(Settings → Privacy). Because the data lives only on your device, protecting the device itself
(passcode, Find My) is the most important safeguard.
Your logged data stays on your device until you remove it. You can delete a single day's entry from its day view, or use Delete account (Settings → Profile) to permanently erase everything — logs, trials, profile, settings, queued contributions and reminders — from the device. Since your logs live only on your device, this on-device deletion is complete for them. The one exception is community contributions you have already sent: those are held on our server, and deleting the app or your account requests their deletion using the one-time token on your device (subject to the aggregate limit noted in the community section). Deleting the app from your device also removes its local data (except any copies in your own backups, which you control).
POIS Tracker requires you to confirm you are 16 or older during onboarding, and does not allow use below that age. It is not directed at, and must not be used by, children under 16.
Your logged data never leaves your device, so it is never transferred anywhere. If you opt in to community contribution, the anonymised summary statistics described above are sent to our community server, which may be hosted outside your country; because those contributions carry no identifier and are only ever published as pooled, k-anonymous group results, they do not identify you. Apple's processing of your purchases is governed by Apple's own terms and safeguards.
If we change this policy — in particular, before any community service goes live or any sync feature is introduced — we will update the "Last updated" date and flag material changes in the app before they take effect.
Tiny Objects · tinyobjectssoftware@gmail.com