Privacy and Data Protection Policy
Effective date: August 21, 2026
Mounjari helps GLP‑1 medication users track doses, weight, and side effects. We built it on a clear principle: the health history you create inside Mounjari belongs to you. It stays on your device and may also be stored in your private iCloud account if you enable sync. It is never copied into a health database controlled by Mounjari. Mounjari does not attach or send that history to us automatically. If you deliberately type health information into a support or feedback message, we receive only what you chose to include.
This policy applies to the Mounjari iOS and Android apps, the Mounjari website, and any contact with us by email or through the support form.
Data Controller
Name: Accelerate Technology Establishment
Unified National Number: 7049940450
Website: https://mounjari.app
Data Protection Officer: dpo@accelerate.sa
Your In-App Health History Is Not Stored on Mounjari Servers
Inside the app, you may enter dose records, injection sites, symptoms, weight, daily notes, and medication information.
This data is stored locally on your device. On iOS, it may also be stored in your private iCloud account if you enable sync. On Android, we do not create a Mounjari cloud account or server sync. Your health data is not sent to servers operated by us, and we cannot view, retrieve, or access it.
This data is used to provide tracking, progress display, and export features.
Apple Health and Health Connect Data
With your explicit consent, the iOS app can import the data you choose to track from Apple Health, and the Android app can import it from Health Connect. This can include weight, height, steps, calories, protein, and water. The data is saved in Mounjari's local record on your device, and you can revoke permission at any time in your device's privacy settings.
Subscription Data
We use RevenueCat to manage subscriptions. RevenueCat processes a random App User ID that we do not link to your health history, subscription status and purchase data, basic technical and locale data, and IP address. On iOS, it also receives a record each time a subscription screen is shown. The internal screen ID can identify the paywall context, such as onboarding, dose, weight, more options, or a follow-up offer, but it does not include the health value you entered. RevenueCat may also receive Apple Ads data showing whether the install came from an App Store ad, so we can measure our campaigns. Mounjari does not request App Tracking Transparency permission or collect IDFA for this.
Subscription data does not include health data. The purchase information here is transaction history such as product ID, purchase date, and renewal date; Mounjari and RevenueCat do not receive your card number or bank details. Google Play may summarize purchase history under its broad Financial info label.
Google Play's Data Safety form uses fixed categories. RevenueCat's guidance says an app using its service declares purchase history, not a separate App activity category, and declares Device or other identifiers only if it uses an Android advertising or device identifier. Mounjari uses neither and sets no identifiable RevenueCat customer attributes. We still name RevenueCat's random internal App User ID, locale, subscription-screen records, and basic operational data here so this policy is more specific than the store summary.
Support, Feedback, and Website Data
If you contact us by email or through the support form, we process your name, email address, message topic, and message content. If you send feedback from inside the app, we process the feedback type or satisfaction rating when present, message text, app version, device model, operating system version, app language, platform, and RevenueCat support ID when available. The form tells you that technical diagnostics are included before you send. We do not send your doses, weight, symptoms, notes, or health log. If you put health data in the message itself, we use it only to help you.
The Mounjari website runs on Cloudflare to serve pages, operate the support form, deliver in-app feedback, and protect the form from automated spam. On the getmounjari.accelerate.sa download-link page only, we use a private analytics tool hosted on Convex to measure link performance. It creates random visitor and session IDs in browser local storage and records the page URL and path, referrer, screen dimensions, browser language, UTM tags, time on page, and scroll depth. It cannot access the Mounjari app or any health data inside it.
Operational App Configuration
When the app opens, it asks a Mounjari-operated service for the current configuration. The request contains one fixed key shared by every installation, platform, app version and build, language, locale, and network metadata Cloudflare needs to deliver and protect the request, such as IP address.
The request contains no RevenueCat ID, advertising identifier, or health entry. We do not write the request's contents to a user database or use them to build a usage profile. Cloudflare keeps an operational request log that may include the IP address, request method and URL, response status, and network metadata needed for security and troubleshooting. Under Cloudflare's current Workers Logs limits, it is kept for no more than 7 days. We do not export these logs or write them to a Mounjari user database.
Data We Do Not Collect
We do not send the health values you record—the dose amount, symptom, weight, nutrition, or note—to product analytics, and we do not send a general log of the screens you open. On iOS, RevenueCat’s subscription-screen ID can identify the paywall context, but it does not include the health value you entered. RevenueCat receives only the data listed in the Subscription Data section above. We do not use an advertising network, IDFA, or cross-app behavioral tracking. We do not use external crash monitoring, request location, collect contacts or phone numbers, or fingerprint your device.
Storage and Retention
Health data: on your device until you delete it, and on iOS in your private iCloud account if you enable sync.
Subscription data: with RevenueCat according to its policy, with separate transaction records controlled by Apple or Google. You can ask us to delete data controlled by us or RevenueCat, but the stores may retain their records for legal, accounting, security, or fraud-prevention reasons.
Support and feedback data: in our email inbox and Cloudflare services when you use the website form or send in-app feedback, for no longer than 12 months after the ticket is closed.
Operational app configuration: processed by Cloudflare and not written to a Mounjari user database. Cloudflare may keep a limited operational request log for no more than 7 days; we do not export it to another service.
Download-link analytics: in Convex for no longer than 12 months after collection. You can request deletion at dpo@accelerate.sa. To let us locate the associated records, open https://getmounjari.accelerate.sa/?privacy=1 in the same browser and include the random privacy ID shown there; your email address alone cannot identify these records.
Third Parties
We share limited data by purpose with RevenueCat for subscription management, subscription-screen impression records, and measuring Apple Ads campaigns on iOS; Cloudflare for the website, support, feedback, and app configuration; and Convex for download-link analytics. Health data stored inside the app is not shared.
We do not sell your data or share your health data for advertising.
Your Rights
You can view, edit, and delete your health data inside the app. You can also export it as PDF, CSV, or JSON.
For subscription, support, feedback, or download-link analytics data, or to exercise your rights under Saudi personal data protection law, contact dpo@accelerate.sa. We respond within 30 days. A request to us cannot delete purchase records controlled independently by Apple or Google.
Security and Incidents
Data on your device is protected by native iOS or Android encryption, and iCloud data on iOS is encrypted by Apple. Because the health history stored inside the app does not pass through our systems, a breach of our systems cannot expose it. This does not include health information you deliberately type into a support or feedback message.
Children and Users Outside Saudi Arabia
Mounjari is designed and marketed for adults using prescription medication and is not intended for children under 18. App Store and Google Play age labels are content ratings, not a statement that Mounjari is directed to children. The app is available worldwide, but Saudi personal data protection law is the primary framework for this policy, and we treat your data the same wherever you are.
Changes and Contact
We may update this policy from time to time. For material changes, we will notify you in the app.
Data Protection Officer: dpo@accelerate.sa