Tray
Home Terms Support עברית

Privacy Policy

Tray - Pill & Vitamin Reminder · Effective 16 September 2026

The one-sentence version. Everything you put into Tray - the pills, the schedule, the notes, the history - lives in a database on your own device and is never sent anywhere. There is no account, no login, no cloud and no server of ours. The only data that leaves your device is anonymous product analytics, and only after you have logged your first dose.

1. Who we are

Tray is made by Ben Basha (the "developer", "we"). This policy covers the Tray mobile app for iOS and Android and this website. Questions: tray@benbasha.com.

2. What Tray never collects

None of the following is collected, transmitted or stored by us - not in analytics, not in crash reports, not anywhere:

  • Your name, email, phone number, address or any account identifier. There is no account. Nothing in the app asks for one.
  • Your pill names, dosages, strengths, notes, routine names, schedules, times and history. This is the health data, and it never leaves your device. The app enforces this in code: analytics events may only carry parameters from a fixed list, and anything else is stripped before an event is sent.
  • Your location, precise or coarse. No location permission is requested.
  • Contacts, photos, calendar, microphone, camera, or health records. Tray does not connect to Apple Health or Google Fit.
  • Any advertising identifier (IDFA, GAID, Android ID). There are no ads, no attribution SDK and no App Tracking Transparency prompt, because Tray does not track you.
  • Purchase history tied to you. The app store handles the payment; Tray records only that this installation owns Tray Pro.

3. What Tray does collect

Everything below is anonymous, is not linked to your identity, and is not used for tracking or advertising.

WhatWhere it goesWhy
App usage events - screen views, and counts or flags for taking, skipping, snoozing, adding a pill, viewing the paywall and purchase outcomes Mixpanel, Google Analytics for Firebase Analytics - understanding whether the product works
Crash and diagnostic data - stack traces, device model, OS version Firebase Crashlytics App functionality - finding and fixing crashes
Purchase events - started, completed, cancelled, failed, restored. No price, no receipt, no store account. Mixpanel, Firebase Analytics - the purchase funnel

An event may carry only a closed list of fourteen parameter names, every one of which is a count, a true/false value or a fixed option. There is no free-text parameter anywhere, so a pill name or a note cannot be attached to an event even by mistake.

4. Analytics do not start until you log your first dose

If you install Tray, look at it and delete it, you are never counted: no analytics profile, no session, no crash reporting registration. This is not a setting layered over a running SDK - the analytics and crash SDKs are not started at all until you have logged a dose for the first time. The automatic collection that these SDKs normally perform from app launch is turned off in the app's shipped configuration and switched on only by that first logged dose.

Once started, analytics stay on for that installation. Deleting the app removes the flag along with everything else.

5. Identifiers

Tray sends no identifier of its own. The Mixpanel and Firebase SDKs each generate their own per-installation identifier. Both reset if you reinstall the app, and neither is joined to any other data set. The app never calls the SDKs' identify functions, so these identifiers are never associated with a person.

6. Where your data lives, and how to delete it

  • Where: a database inside the app's own private storage, plus - on iOS - a small shared snapshot so the widget and Lock Screen can display your tray without opening the app. Nothing is written outside the app's sandbox.
  • Encryption: at rest, by your operating system (iOS Data Protection, Android per-app encryption). In transit, the analytics SDKs use HTTPS. Tray itself opens no network connection.
  • Retention: for as long as you keep it. We hold nothing, so there is nothing to retain on our side.
  • Deletion: deleting the app deletes all of it. Because there is no account and no server, there is no deletion request to make - and no way for us to recover anything for you.
  • Export: you can export your whole history as a CSV spreadsheet (free), and a JSON backup file (Tray Pro). Both are handed to your device's share sheet. Tray never uploads either. A backup file deliberately excludes your Tray Pro entitlement and your analytics state, so it can never unlock Pro or carry someone else's settings.

7. Purchases

Tray Pro is a single non-consumable purchase - one payment, once. There is no subscription, no auto-renewal and no trial. Your entitlement is re-checked with the app store each time the app launches and whenever you tap Restore Purchases; Tray keeps only a yes/no flag on the device. No price, receipt, store account or transaction identifier is ever sent to an analytics service.

8. Advertising

There are none. Tray contains no ad network, no attribution SDK, no A/B testing service, no session-replay tool and no remote configuration. Nothing is ever placed between a reminder and you taking your pills.

9. Children

Tray is not directed at children and collects nothing that would identify one. It is rated 4+ on the App Store and Everyone on Google Play. It has no user-generated content, no social features, no chat and no links out other than the app stores and these policy pages.

10. Third parties

WhoWhat they receiveTheir policy
MixpanelThe anonymous events described in section 3mixpanel.com/legal/privacy-policy
Google (Firebase Analytics and Crashlytics)The same events, plus crash diagnosticsfirebase.google.com/support/privacy
Apple and Google (billing)The purchase itself. Tray never sees your payment details.Their own policies

No other service receives anything from Tray.

11. Your rights

Under the GDPR, the CCPA and similar laws, you have rights of access, correction, deletion and portability over personal data a company holds about you. We hold no personal data about you. In practical terms: your data is already in your hands on your device, you can export it yourself at any time, and deleting the app erases it. If you want the anonymous analytics for your installation to stop, delete the app; because the events carry no identifier of yours, we cannot single them out afterwards.

12. Changes to this policy

If this policy changes, the new version is published here with a new effective date. Any change that would make Tray collect more than it does today will be described plainly at the top of this page.

13. Contact

Email tray@benbasha.com. There is no account to look up, so please describe what you need in the message.

Tray
Home Privacy Terms Support עברית

© 2026 Ben Basha. tray@benbasha.com