Privacy Policy
Last updated: August 29, 2026
Plain-language summary
- There is no Keystone Apps server behind Pillar. Your medications, schedules, and dose history sync only through your own private iCloud account (Apple's CloudKit), the same way Apple's own apps sync — we never see, receive, or store a copy of that data ourselves.
- If you import from the Health app, that import is read-only and kept in a completely separate, iCloud-never-synced store on your device. Pillar never writes anything back to Health.
- The AI features (turning typed text into a schedule, and writing a plain-language adherence summary) run entirely on-device using Apple's on-device Foundation Models framework. Nothing you type is sent to a server — Apple Intelligence's cloud option is never enabled for these features.
- Proof-of-dose photos and profile pictures are stored only in the app's local storage on your device, encrypted while the device is locked, and deliberately excluded from iCloud backup and sync.
- To help auto-complete a medication's details, Pillar can look up the name you typed against RxNav, a free public drug-database API run by the U.S. National Library of Medicine — only the medication name is sent, never anything that identifies you.
- We don't use any analytics, advertising, or tracking SDKs of any kind, we don't sell your information, and there's no account or sign-in beyond your own Apple ID / iCloud.
Overview
This Privacy Policy explains how Keystone Apps ("we," "us," or "our") handles information in connection with Pillar (the "App"), an iOS and watchOS app that helps you track medications and stay on schedule using AlarmKit-based alarms, dose logging, adherence insights, and optional AI-assisted scheduling.
We wrote this policy to describe exactly what the App does — not a generic template. If anything here seems inconsistent with the App's real behavior, please contact us so we can fix it.
Pillar is not a medical device and does not provide medical advice. It is a reminder and record-keeping tool: it never diagnoses a condition, and it never calculates, suggests, or adjusts a dose. Pillar does show a warning when two medications you have added both appear in a small, hand-curated list of widely documented, high-severity interactions — see Interaction Warnings below for exactly what that does and does not cover. Always follow guidance from a licensed healthcare professional for decisions about your medications.
Information We Collect
Medication, schedule, and health-related data you enter
Profiles, medications, dosing schedules ("regimens"), logged doses, supply counts, and optional entries like doctors, pharmacies, and appointments are stored in the App's local database on your device and, where iCloud is signed in, synced through your own private CloudKit database — the same private-to-you storage Apple provides to any app. We do not operate a server that receives or stores this data, and we cannot see it.
Data imported from the Health app
If you choose to import medications or dose history from Apple Health during onboarding or later, that data is read read-only and kept in a separate, local-only part of the App's storage that is never synced to iCloud and never merged into the synced data described above. Importing a medication creates a new, independent record in Pillar seeded from the Health entry — the original Health object itself is never uploaded anywhere. Pillar never writes data back into the Health app.
Photos
If you attach a photo as proof of a logged dose, or set a profile picture, that image is saved only to the App's local storage on your device (encrypted while the device is locked) and is deliberately excluded from iCloud backup and from the sync described above. We never receive a copy of these photos.
Text you type for AI-assisted features
When you describe a dosing schedule in your own words for the App to turn into a structured schedule, or ask the App to summarize your adherence history, that text and the relevant numbers are processed entirely on-device — see On-Device AI Features below. None of it is sent to us or to any server.
Medication name lookups
When you add or edit a medication, the App may send the name you typed to RxNav, a free public API operated by the U.S. National Library of Medicine, to resolve it to a standard drug code. Only the medication name text is sent — never your identity, your other medications, or any other data. This lookup is best-effort: if it fails or times out, nothing else about the App is affected.
Diagnostic data
We do not use any analytics or crash-reporting SDKs in Pillar. Aside from the specific items above, we do not collect usage statistics, device identifiers, or any other diagnostic data, and there is no account, sign-in, or profile with us — only your own Apple ID / iCloud account, which we never see.
Permissions We Request
Pillar requests the following device permissions. Each is optional, requested only when relevant, and can be changed at any time in iOS Settings → Pillar.
| Permission | Why we ask |
|---|---|
| Alarms (AlarmKit) | So medication reminders can reach you through Silent mode and Focus, with Lock Screen and Dynamic Island presence — the reason the App exists. |
| Notifications | For refill and expiration reminders, and to let you know if Pillar loses its alarm permission. This is the standard notification permission, separate from the Alarms permission above. |
| Camera | To let you take a photo as proof of a logged dose. The photo stays on your device. |
| Photo Library | To let you attach an existing photo as proof of a dose, or as a profile picture. Stays on your device. |
| Health | Read-only access to import your existing medications and dose history, so you don't have to re-enter them. Pillar never writes anything back to Health. |
The App does not request microphone, speech recognition, contacts, or location access, and does not use any of those capabilities.
On-Device AI Features
Pillar includes two AI-assisted features, both built on Apple's on-device Foundation Models framework (part of Apple Intelligence):
- Schedule parsing: when you type a plain-language description of a dosing schedule, the App extracts a structured pattern (times of day, days of week) from it.
- Adherence summaries: in Insights, you can generate a short, plain-language summary of your adherence numbers (percentages, average timing) for a medication.
Both features run entirely on your device. The cloud-based option Apple Intelligence otherwise offers is never enabled for these features, so the text you type and the numbers behind a summary are never transmitted to Apple, to us, or to any other server. Both features are also built to stay narrowly factual — they're instructed never to suggest, calculate, or comment on a dose amount, explain what a medication is for, or mention interactions, contraindications, or symptoms, and their output is checked before it's shown to you. These features require a device that supports Apple Intelligence; on devices that don't, they're simply unavailable.
Interaction Warnings
When two medications on the same profile both appear in a small, hand-curated list of widely documented, high-severity drug interactions — the kind carrying an FDA boxed warning, such as warfarin with NSAIDs or benzodiazepines with opioids — Pillar shows a warning on the Medications screen naming the pair. This check runs entirely on your device against a list bundled inside the App. No information about your medications is sent anywhere in order to perform it.
This is not a comprehensive interaction check, and must not be relied on as one. The list is deliberately small and covers only well-established, uncontroversial pairs. It does not account for your dosage, your medical history, other substances you take, or any interaction outside that list. The absence of a warning does not mean two medications are safe to take together. Pillar is not a substitute for review by a pharmacist or physician, and you should always confirm your full medication list with a qualified healthcare professional.
How We Use Information
The information described above is used to:
- schedule and deliver your medication alarms and show what's due, taken, or overdue;
- maintain your dose history, supply counts, and adherence statistics;
- check the medications on a profile against the bundled interaction list described above;
- sync your data across your own devices via your private iCloud account;
- generate the on-device AI results you specifically request;
- manage your free-tier limits and Pro subscription entitlement.
We do not use any information from the App to build advertising profiles, we do not sell your personal or health information, and we have no mechanism to access your synced iCloud data, since it lives in your own private CloudKit database, not on a server we operate.
Third-Party Services
Pillar relies on the following third parties, all of which are Apple's own platform services except for one drug-lookup API:
| Service | Provider | Purpose |
|---|---|---|
| iCloud / CloudKit (private database) | Apple | Syncs your medications, schedules, and dose history across your own devices, signed in with your own Apple ID |
| HealthKit | Apple | Read-only import of medications and dose history from the Health app, if you choose to use it |
| Foundation Models (Apple Intelligence, on-device) | Apple | Powers schedule parsing and adherence summaries, entirely on-device — see On-Device AI Features |
| App Store / StoreKit | Apple | Processes all subscription purchases and payment |
| RxNav | U.S. National Library of Medicine (NLM/NIH) | Resolves a medication name you type to a standard drug code — receives only that name text |
These providers operate under their own privacy practices — see Apple's Privacy Policy and the National Library of Medicine's web policies. We do not use any advertising, attribution, or analytics SDKs, and Pillar does not request App Tracking Transparency permission because it does not track you across other companies' apps or websites.
Data Storage, Sync & Security
Pillar keeps two separate stores on your device. Your own medications, regimens, dose events, supply, and related records ("app-owned data") sync through your private CloudKit database when you're signed into iCloud — encrypted in transit and at rest by Apple's infrastructure, and accessible only to you, the same as any other app's iCloud data. Data imported from Health lives in a second, local-only store that is never synced or merged into the first. Proof-of-dose photos and profile pictures are saved as encrypted files in the App's local storage, marked to be excluded from both iCloud backup and sync, so they never leave your device.
You can create a local backup file of your app-owned data (profiles, medications, regimens, dose history, and supply) from Settings, and restore from one later — this is a self-contained file you choose where to save and share, not something we upload for you. A backup does not include the proof-of-dose photo files themselves, only a reference to them, since those are explicitly on-device-only.
Family Profiles & Caregiver Sharing
Pro plans let you manage more than one profile (for example, tracking your own medications alongside a family member's) within your own account — this still lives in your own private CloudKit database, not a shared or cross-account store. A future "caregiver circle" feature, which would let someone else view a profile's adherence using Apple's CloudKit sharing, is planned but not yet available in the App. If and when it ships, we'll update this policy to describe exactly what it shares and how consent works before it's usable.
Your Choices & Rights
- Permission controls: grant, deny, or revoke Alarms, Camera, Photo Library, or Health access at any time in iOS Settings → Privacy & Security, or Settings → Pillar.
- iCloud sync: you can turn off iCloud for Pillar at any time in iOS Settings → [your name] → iCloud; the App continues to work locally on that device.
- Deletion: deleting a record in the App removes it from your device and, if iCloud sync is on, from your private CloudKit database on your next sync. Deleting the App removes its local data from that device. Because we never hold a copy of your synced data ourselves, there is nothing further for us to delete on our end.
- AI features are optional: you can always enter a schedule manually and skip Insights' AI summary — core alarm and logging functionality never depends on them.
- If you are in the EEA, UK, or California, you may have additional rights (access, deletion, correction, or portability of any personal information we process). Contact us using the details below to exercise these rights.
Children's Privacy
Pillar is designed for adults managing their own medications or a family member's, and is not directed at children under 13 (or the equivalent minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to remove it.
International Users
Pillar is available globally. Your app-owned data syncs through Apple's iCloud infrastructure, which may store data on servers outside your country under Apple's own data-protection commitments. A medication-name lookup, when it occurs, is sent to a server operated by the U.S. National Library of Medicine.
Changes to This Policy
We may update this Privacy Policy from time to time, for example as we add features or for legal reasons. We'll update the "Last updated" date above, and if a change is material, we'll provide additional notice (such as an in-app notice) where appropriate.
Contact Us
Questions about this policy or how Pillar handles your information? We're happy to help.
info.keystoneapps@gmail.com