Protocol Her is made by DZ LABS LLC, a Florida (USA) limited liability company. We are the data controller for the limited data described in this policy. You can reach us at contact@dzlabsllc.com.
This policy covers the Protocol Her iOS app (bundle com.dzlabs.protocolher) and this website.
Protocol Her has no sign-up and no user accounts. Everything you log in the app is written to a private database on your iPhone, protected with iOS Data Protection (encrypted at rest) — we never receive a copy. That includes:
Photos and lab files are additionally stored with iOS file protection and excluded from device backups, so they don't leave the phone through iCloud backup either.
If you subscribe to Protocol Her Pro, Apple processes the payment — we never see your name, card number, or Apple ID. To know whether your subscription is active, the app uses RevenueCat, which receives the App Store receipt, a randomly generated anonymous app-user ID, device identifiers used by its SDK (such as the identifier-for-vendor, and the advertising identifier only if you allow tracking when iOS asks), and, when Apple provides one, an Apple Search Ads attribution token. This is purchase information tied to a random ID, not to your identity. If you enter an optional creator code during setup, it is stored as an attribute on that same anonymous ID so we can credit the creator; it is not linked to your identity.
Protocol Her uses AppsFlyer, an ad-attribution service, to measure whether our advertising works — for example, whether an ad on another platform led to an app install or subscription. For this purpose the app sends AppsFlyer anonymous install and attribution data, and your device's advertising identifier only if you allow tracking when iOS asks. RevenueCat also forwards anonymous subscription events to AppsFlyer under the same anonymous app-user ID. AppsFlyer may then report attribution results to the advertising network that showed the ad, such as Meta. If you decline the tracking prompt, the advertising identifier is not shared; limited, anonymized attribution signals may still be sent, and Apple's privacy-preserving SKAdNetwork framework may report aggregate ad results that are never tied to you. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking.
What never leaves your phone. Your protocol data — doses, logs, measurements, side-effect notes, cycle entries, and photos — is stored on your device and is never uploaded to us, shared, or sold. Attribution measurement involves none of it.
Protocol Her can connect to Apple Health in two limited ways, each opt-in and off by default. Body weight: you switch it on with a toggle in Profile, which asks your explicit permission; once on, the app reads existing body-weight entries from Apple Health and writes the weights you log back to it. Steps and sleep: you connect them from the Analytics tab, which asks your explicit permission; once connected, the app reads your daily step counts and recorded sleep sessions to display them alongside your protocol — read-only, and nothing is written. No other Health data is read or written. Health data stays on your device under Apple's HealthKit rules; it is never sent to our servers, never used for advertising, marketing, or any other use-based data mining, and never sold or shared with third parties.
If you email support, we receive your email address and whatever you include in the message. We use it solely to respond and keep it only as long as needed to resolve the issue.
| Provider | What they handle | Why |
|---|---|---|
| Apple | Payment processing, App Store delivery, optional Apple Health integration | Distributing the app and processing subscriptions |
| RevenueCat | App Store receipt, anonymous app-user ID, subscription status, device identifiers used by its SDK, Apple Search Ads attribution token, optional creator code | Knowing whether Pro is active; crediting ad campaigns |
| AppsFlyer | Anonymous install and subscription events; your device's advertising identifier only if you allow tracking when iOS asks | Measuring whether our advertising works |
| Meta (ad network) | Attribution results for ads it showed, reported by AppsFlyer — anonymous identifiers and events, never your logs | Confirming which ads led to installs and subscriptions |
Each processor only receives what's listed above, only for the listed purpose, and is required to protect your data to at least the standard described in this policy. None of them receives your health or protocol data, and none of them may sell your data. AppsFlyer and Meta receive only the ad-attribution signals described in section 3.
The camera and photo-library permissions exist so you can take progress photos and capture bloodwork pages. These photos stay on your device (see section 2). The app never scans your photo library in the background.
Because your health data lives on your device and not on our servers, you already hold direct control over most of it: you can read, export, correct, and delete it in the app without asking us.
For the limited data we do process off-device (support emails, subscription records and related identifiers in RevenueCat, and ad-attribution data in AppsFlyer), you can ask us to access, correct, delete, or export it, or to restrict or object to processing, by emailing contact@dzlabsllc.com. We respond within the timelines required by law.
Our legal bases are performance of a contract (providing the app and subscription), legitimate interests (security, abuse prevention, and privacy-preserving ad-attribution measurement that does not use the advertising identifier), and consent for identifier-based ad attribution — the iOS tracking prompt, which you can decline or withdraw at any time in iOS Settings → Privacy & Security → Tracking. You also have the right to lodge a complaint with your supervisory authority.
We do not sell personal information, and we do not use sensitive personal information beyond what's necessary to provide the service. We use AppsFlyer to measure our own app-install advertising, which may constitute "sharing" under California law. Declining the iOS tracking prompt (or turning tracking off later in iOS Settings → Privacy & Security → Tracking) stops the advertising-identifier portion of that flow; some non-identifier attribution signals may still be sent as described in section 3, and you can object to those by emailing us. You have the rights to know, delete, correct, opt out of sharing, and to non-discrimination for exercising them. Submit requests to contact@dzlabsllc.com.
Protocol Her is intended for adults and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a minor has used the app, contact us and we will help remove any associated data.
On-device data is protected with iOS Data Protection (encryption at rest) and, for sensitive values, the iOS Keychain. Data in transit (subscriptions) uses TLS encryption. No system is perfectly secure, but our architecture is built so that the most sensitive data never leaves your phone in the first place.
If we change this policy in a meaningful way — for example, if a future feature moves data off-device — we'll update this page, change the date above, and call it out in the app before the feature applies to you. (July 18, 2026: added the "Ad attribution" section for version 1.0.3 — AppsFlyer ad-measurement signals, with the advertising identifier used only if you allow the iOS tracking prompt.)
DZ LABS LLC · Florida, USA
contact@dzlabsllc.com