Privacy Policy

Effective date: September 22, 2026

This page explains, in plain language, what information may be entered into Protocolit, when it stays on your device, when account services may process it, and how to get in touch with questions or requests.

TL;DR

Protocolit stores app data on your device. If you create an account, your email address, sign-in session, and password-reset requests are processed by our account and email providers. Depending on the version and configuration you are using, account-linked records may stay local to the device or may sync or back up to your account. We do not sell personal information, run ads, or use third-party tracking analytics. Privacy requests can be sent to contact@protocolit.app.

Who this policy covers

This policy covers the Protocolit app and the Protocolit website. Protocolit is operated by 36th Floor LLC.

Information you may enter

Users may choose to enter protocol details, schedules, dose logs, notes, weight entries, supply information, onboarding answers, and other related records needed to use the app.

What stays on your device

Protocolit uses local device storage for app state. Your records stay on your device, and Protocolit also keeps a backup copy on your own device. If the app ever has trouble opening your saved data, it will restore from that backup instead of losing your data and asking you to start over. If you delete the app, clear app storage, or lose the device without a backup, those local records may still be lost.

Accounts, sign-in, and sync

If you create or sign in to a Protocolit account, your email address and authentication state are processed to sign you in, keep your session active, secure access, and support password recovery. In the current device-local version of Protocolit, signing in does not back up or transfer your records, and phone and web keep separate records even with the same login. The app indicates when data is saved locally on the current device.

Password reset and account emails

When you request a password reset, a recovery code may be sent to the email address tied to your account. Protocolit uses Supabase for authentication and Resend to deliver account emails.

How information may be used

Information may be used to provide core app functionality such as schedules, logging, reminders, supply views, history, exports, password recovery, support responses, and reliability improvements.

Notifications

The app may request permission for reminders or notifications. Users can control these permissions from device settings.

Support emails

If you email Protocolit support, we receive the information you send in that message and any attachments you include. Support email helps us answer questions, troubleshoot issues, and handle privacy requests.

What we do not use the app for

Protocolit is intended for personal organization and reference. It is not medical advice and does not replace a licensed clinician. Questions about your health, treatment, or personal medical decisions belong with a qualified professional.

Your privacy requests

You can write to contact@protocolit.app to ask what account or support information we hold, request deletion of information we control, or ask privacy questions. We aim to respond to privacy requests within 45 days.

Security

Access to Protocolit accounts depends on your email and password, and password recovery uses emailed recovery codes. No system is perfect, and no method of transmission or storage is completely secure.

Children

Protocolit is not directed to children under 13, and we do not knowingly build the service around collecting personal information from children.

Changes to this policy

If this policy changes in a way that affects how data is handled, we will update this page with a new effective date.

Contact

Questions about this Privacy Policy can be sent to contact@protocolit.app.