Last updated: 25 August 2026
The controller for the processing described in this policy is:
In this policy we use "Pautia", "we" or "the controller" interchangeably to refer to the provider where it reads more easily.
Pautia has been designed around a principle of minimisation: information about treatments, medicines, doses and dose history is stored, as a general rule, in the browser storage of the device itself.
There is no central Pautia database from which we could look up its users' health history.
When you turn on certain optional features, some data may leave the device. This policy explains each case separately.
In particular, the Family sharing feature temporarily stores an end-to-end encrypted package on Pautia's infrastructure. Pautia does not hold the key needed to decrypt it and does not use that content for any purpose of its own. However, we do not base our legal protection solely on that technical impossibility: the metadata and other personal data associated with running the service are processed in accordance with the GDPR, and the encrypted content receives protection measures appropriate to its particular sensitivity.
This information is stored on the user's device using browser storage technologies. Pautia does not keep a central database of those treatments and cannot remotely look up which medicines you have recorded or which doses you have marked. You are the one who enters, changes and deletes that information.
When you use Pautia in a strictly personal or household context, the processing you yourself carry out of that data may fall within the exception for purely personal or household activities in article 2(2)(c) GDPR.
Pautia is currently designed for personal and family use. Use of the application by a care home, clinic, professional home-help service, company or other organisation to manage the health data of patients, residents, clients or workers requires a specific analysis and agreement. Handing out free licences to a pharmacy, association or entity for distribution among its users does not by itself authorise that entity to use Pautia as a professional tool for managing third parties' health data.
Optional backup to Google Drive. If you turn on backup, Pautia creates an end-to-end encrypted file in your own Google Drive account. The application uses the drive.file scope, limited to files created by the application itself: Pautia does not obtain general access to your Google Drive content with that permission. The backup content is encrypted on the device before being uploaded and, under the current technical design, neither Pautia nor Google holds the key needed to read it. Recovery depends on the credentials and mechanisms shown inside Pautia: if you lose the device and the items needed to recover the backup, we may not be able to restore it for you.
Synchronisation between your devices. If you turn this on, your devices use the encrypted copy in your own cloud to stay in sync. The file is downloaded, decrypted and processed locally, then uploaded again encrypted. Pautia does not keep an additional copy on a server of its own for this synchronisation.
Photographs of packaging. These are stored locally in IndexedDB and may be included in the encrypted Google Drive backup if you have that option enabled. You can exclude them from the backup in the relevant settings. Photographs are not included in Family sharing, in the link used to show a treatment to another person, or in the printed or PDF schedule, in line with the current implementation.
People's names and minors. You can use names or labels such as "Mum" or "Jesús" to keep treatments apart. If you manage the medication of a minor child or another person in your care, that data is entered from your device: Pautia does not create accounts for minors and does not ask a minor directly for their health data. If you use the data of another adult who can decide for themselves, you must respect their rights and have sufficient authorisation to record or share that information.
Pautia does not use user accounts with a username and password.
When you make a purchase, Stripe processes the payment and passes us the data needed to confirm the transaction, including the email address associated with the purchase, the plan bought and the necessary information about the transaction.
With that data we generate a signed licence containing the email address, the plan and, where applicable, its expiry date. The licence is sent to the email address given and is then stored on your device.
Pautia does not keep its own database of customer profiles, but certain data about the transaction necessarily remains at Stripe, in the email system used to send you the licence, and temporarily in the technical logs described in section 3.5.
Purpose: managing the purchase, issuing and sending the licence, handling resends, managing renewal or cancellation and evidencing the contractual relationship.
Legal basis: performance of the contract or pre-contractual measures requested by the data subject, article 6(1)(b) GDPR; and, for any applicable legal obligations, article 6(1)(c) GDPR.
Pautia does not receive or store your full card number. Payment takes place on Stripe's infrastructure.
Stripe may act as a processor when it processes certain data following our instructions, and also as an independent controller for certain purposes of its own, such as security, fraud prevention, regulatory compliance and others described by Stripe in its privacy documentation.
Pautia currently uses Stripe Payments, Payment Links and the billing functionality needed for subscriptions.
You can generate a link containing one treatment in order to show it to a person of your choosing.
The treatment content is placed in the part of the address after the # symbol, known as the fragment. That part is processed locally by the browser and is not included in the HTTP request made to the server.
The Pautia implementation verified on 25 August 2026 makes no requests to third-party services from that page and does not send the fragment content to Pautia, SiteGround, Cloudflare Web Analytics or any other provider.
The server does receive, as with any page visit, the request needed to serve the viewer and the technical connection data described in section 3.5, but it does not receive the treatment that appears after the #.
The link:
Whoever receives the link may keep it, copy it or forward it. The link may also be stored by the browser, the operating system or the messaging service you use to share it.
You should therefore treat it as you would a document containing health information and send it only to people you want to give access to.
When you visit a website, or the application communicates with a server, the IP address and other technical data are needed to establish the connection. Pautia uses that data only for operation, security, abuse prevention and troubleshooting.
Temporary use of the IP by our code. In certain operations our program may temporarily use the IP address to limit abusive requests, for example to prevent an abnormal number of resend requests. That data is kept in memory for a maximum of about ten minutes for that purpose and is not written to a permanent database by this mechanism.
Logs of the web and application hosting. The provider hosting the website and the application files keeps technical access logs for 14 days. These logs may include the IP address, date and time, resource requested, user agent and technical fingerprints of the connection used by the infrastructure. They are consulted only where necessary for security or troubleshooting and are deleted within the stated period.
Cloudflare Worker logs. The Pautia program that manages licences and certain functions is hosted on Cloudflare Workers.
The detailed automatic capture of every invocation, which could include additional connection data, was switched off on 25 August 2026.
The messages our own code explicitly generates may be kept at Cloudflare for approximately three days. Depending on the operation, they may record the time and outcome of an operation and, in certain transactional operations, the email address to which a licence or notice was sent.
The IP addresses our code explicitly writes into those logs relate to access to the administration panel, not to ordinary user routes, according to the implementation audited on the date of this policy.
Legal basis for logs and security measures: the controller's legitimate interest in maintaining security, preventing abuse and diagnosing errors, article 6(1)(f) GDPR. That interest is exercised by applying short retention periods and minimisation.
On the public website we use Cloudflare Web Analytics for general audience statistics. We do not use this tool inside the Pautia application.
Under the current configuration:
Where the technical data processed to provide this measurement is personal data, our legal basis is the legitimate interest in understanding the general operation and use of our own website, article 6(1)(f) GDPR. The Cookies Policy also explains the application of article 22.2 LSSI-CE.
You may voluntarily give us your email address to receive Pautia news. Subscription uses double opt-in: giving the address is not enough; you must then confirm through the message you receive.
Data: email address and the technical data needed to manage sign-up and unsubscribe.
Purpose: sending you Pautia news.
Legal basis: consent, article 6(1)(a) GDPR.
You may withdraw consent at any time using the unsubscribe mechanism included in the messages. Resend is currently configured without open tracking and without click tracking, so we do not know whether you open our emails or click their links.
When you unsubscribe, we stop using the address for that purpose. We may keep the minimum data needed in a suppression list in order to honour the unsubscribe and avoid accidentally adding that address again.
If you contact us, we will process the email address or number you write from and the content of the message.
Purpose: answering queries, incidents or complaints.
Legal basis: where the query concerns a purchase, the contract or pre-contractual measures requested by you, article 6(1)(b) GDPR; otherwise, the legitimate interest in attending to communications addressed to the controller, article 6(1)(f) GDPR.
We do not need to know diagnoses, illnesses or treatments in order to provide technical support. Please avoid including health data about yourself or third parties unless it is essential.
If we incidentally receive health information we do not need, we will try not to bring it into other systems and will minimise or delete it once it is no longer necessary.
If it were exceptionally necessary to go on deliberately processing data concerning your health in order to resolve a request, we will tell you so and, where necessary, seek your explicit consent under article 9(2)(a) GDPR.
As an internal rule, ordinary support messages will be kept for a maximum of 12 months from the closure of the query, unless they must be kept longer to handle a complaint, evidence a contractual relationship or meet a legal obligation. In those cases use will be limited to that purpose.
WhatsApp is an external Meta service. If you use that channel, Meta's processing is also governed by its own terms. You may use email if you prefer not to communicate via WhatsApp.
Pautia can generate a file or events for you to add to your device's calendar. That file is generated locally and does not need to pass through a Pautia server.
By default, events need not include the medicine's name. If you choose to include it and your calendar syncs with Google, Apple, Microsoft or another provider, that information may end up stored in the calendar service you use. Pautia does not control any subsequent processing by that provider.
To scan a medicine code, the browser may request temporary access to the camera. The image used to read the code is processed locally and is not sent to Pautia as a photograph.
Once the code has been read, the application queries CIMA to obtain the available data about the medicine. The request to CIMA contains the term or code needed to perform the lookup and, as with any communication over the Internet, the destination server may receive the technical data needed to establish the connection, including the IP address.
Pautia does not send CIMA the full treatment history or the identity of the person you have associated the medicine with inside the application. Camera use is optional and you can enter the medicine manually.
When we issue a free licence directly we may record the email address, the issue date, the expiry date, the language and a brief note of why it was given.
Purpose: administering the licences issued, evidencing their validity and being able to handle incidents.
Legal basis: legitimate interest in managing the licences we have issued, article 6(1)(f) GDPR.
The record is deleted automatically one year after the licence expiry date, under the current configuration.
We may send two messages relating to its ending: one shortly before the expiry date and one when it ends. Each message includes a simple objection mechanism. These messages do not add you to the newsletter. Where they include promotional information about similar services of our own, the conditions of article 21 LSSI-CE and the corresponding right to object will apply.
At most once a day, if there is a connection and you have not switched this option off, Pautia sends our server an event intended to produce aggregated usage statistics.
The content sent is: usage age band, application version, language and whether it is installed.
The message contains no user or device identifier and includes no medicines, treatments, people, doses, times or dose history. What we keep are aggregated daily counters. The date of the last send is stored on the device to prevent more than one per day.
The network connection inevitably generates technical data such as the IP address; its processing and the infrastructure logs are explained in section 3.5. The IP is not part of the statistical content we keep as an app-open counter.
You can switch this feature off in Settings → Count app opens without losing any Pautia functionality.
The measurement is designed to meet the conditions of a limited, first-party, aggregated audience measurement, with no tracking across sites or applications and no advertising reuse.
Family sharing is optional and switched off by default. When you turn it on, Pautia uses a temporary mailbox to make it easier for authorised devices to exchange information.
Purpose and legal basis for the technical data needed for the feature: providing the functionality you have turned on, article 6(1)(b) GDPR where it forms part of the requested service, and maintaining its security and preventing abuse, article 6(1)(f) GDPR.
Pautia does not use the encrypted health content for advertising, profiling, analytics or any purpose of its own.
If you share information belonging to another adult with capacity, you must have their authorisation to do so. If you legitimately manage the medication of a minor or a person under your responsibility, you must act within the powers legally available to you.
The following providers or services are involved in delivering the service:
Providers do not, as a general rule, receive the treatment history in a form Pautia can read. Exceptions depend on actions the user expressly takes — for example sending a day report through a messaging service — or on information they voluntarily write in a query.
Some of our providers belong to groups established outside the European Economic Area or may carry out certain international operations.
Where an international transfer of personal data requires safeguards under Chapter V GDPR, we use the contractual and adequacy mechanisms applicable to the provider and to the specific processing.
As at the date of this policy:
You can write to hola@mipautia.com to request further information about the safeguards applicable to a specific processing operation.
The reference to these safeguards does not change the specific fact that the R2 bucket used for the encrypted Family sharing content is currently configured with EU jurisdiction.
Unless another period is expressly stated:
Where a rule requires certain data to be kept for a longer period, it will be kept solely to meet that obligation or possible liabilities.
In relation to the personal data for which we are the controller, you may request, where applicable: access, rectification, erasure, restriction of processing, objection, portability and the withdrawal of consent, where that is the legal basis, without affecting the lawfulness of prior processing.
You can exercise them by writing to hola@mipautia.com. We may ask for the information strictly necessary to check that the request comes from the data subject.
You may also lodge a complaint with the Spanish Data Protection Agency (AEPD).
As for the treatments, medicines and history that exist only on your device, you can access, correct, delete and export the information directly from the application itself, without having to ask us.
If you ask us to access encrypted Family sharing information, we may technically be unable to identify or decrypt the content without information that only the participating devices hold. This does not limit your ability to manage or delete it from the feature itself.
Pautia does not use your data to take automated decisions producing legal effects on you, nor to build advertising profiles.
We do not sell personal data and we do not show third-party advertising inside the application.
We apply technical and organisational measures aimed at reducing processing risks, including, depending on the feature:
No system can guarantee absolute security. The local architecture and encryption particularly reduce the impact an incident in Pautia's infrastructure could have, but they do not remove the risks present on the device itself, the user's cloud account, email, messaging services or the people information is shared with.
We will update this policy when the way we process personal data changes significantly or when legal changes make it necessary. Where a change is significant for the user, it will be communicated appropriately within the application or by another suitable means.
The Privacy Policy is information about processing and does not need to be "accepted" as if it were a contract. Where a specific feature needs consent, that consent will be sought separately and must be capable of being withdrawn.
For any privacy query or to exercise your rights: hola@mipautia.com.
The other documents: Medical Notice · Terms of Sale · Legal Notice · Cookies
Any questions? Write to us at hola@mipautia.com.