Similia Home Prescriber
Welcome to Similia Home Prescriber. This Privacy Policy explains how SIMILIA LTD ("we," "our," or "us") collects, uses, discloses, and safeguards your information when you use our mobile application Similia Home Prescriber (the "App"). SIMILIA LTD is the data controller for the personal data described in this policy.
Please read this Privacy Policy carefully. Because the App works with health-related information that you choose to provide, we ask for your explicit consent in the App before we process that information (see Section 3). If you do not agree with the practices described in this policy, please do not use the App.
Account Information
Health-Related Information
We treat all of this as health data — "special category" data under the UK GDPR and the EU GDPR — and we process it only as described in this policy, on the basis of your explicit consent (see Section 3).
Device Information
Usage Information
Install Source (Android)
On Android, Google Play tells the App which link or advertisement led to the installation (the "install referrer"). We record this once, for our own campaign attribution and for creator links (Section 5.4). It contains no device identifier and is not sent to Meta.
Advertising Identifiers (only with your permission — see Section 5.7)
If you opt in to advertising measurement, we collect your device's advertising identifier (Apple IDFA, where you have also allowed tracking in iOS; Google Advertising ID on Android), the vendor identifier (IDFV, iOS), and an anonymous app-instance identifier generated by the Meta SDK. Without your opt-in, none of these identifiers are collected.
Voice Input (Speech Recognition)
When you use the voice input feature, your speech is processed by your device's native speech recognition service:
Your voice data is sent to these platform services for transcription. We do not store or transmit your voice recordings to our own servers. The transcribed text (your symptom descriptions) is then processed as described in this policy. For more information about how Apple and Google handle speech data, please refer to their respective privacy policies.
When you choose to sign in using Google or Apple, we receive:
For these improvement purposes we use device and usage information (Section 3.2) — not the content of your health-data sessions. Debugging and quality work that involves session content happens through the session processing logs described in Sections 3.1 and 7, and through the operational and diagnostic logs our backend generates at our cloud infrastructure provider. Those operational logs can include session content — for example, the complaint you described or a question generated in your session — and are retained for a limited period under the provider's log-retention settings.
If you opt in to advertising measurement, we use a small set of app-usage events — never your health information — to learn which of our Facebook and Instagram ads bring people to the App and to improve how our ads are shown. This is optional and described in full in Section 5.7.
The health-related information described in Section 1.1 is "special category" data under Article 9 of the UK GDPR and the EU GDPR. We process it on the basis of your explicit consent under Article 9(2)(a), which is the lawful basis we rely on for this processing. Your explicit consent also provides the corresponding lawful basis under Article 6(1)(a).
Advertising measurement (Section 5.7) uses only app-usage and purchase events — for example that the App was opened, an account was created, or a subscription was bought — and only if you opt in. It never uses, includes or is derived from the symptoms, answers, remedies or results you see in the App.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. If you opt in to advertising measurement (Section 5.7), we share limited app-usage events with Meta, which uses them for its own advertising purposes as well as ours; under some US state laws this counts as "sharing" or a "sale", and you can opt out at any time in Profile → Privacy choices.
We share information with third-party service providers only so that they can perform services for us in operating the App:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Firebase (Google) | Authentication, database & backend hosting | Account data, user ID, App data including your session content |
| OpenRouter, Inc. | AI processing: routes your session content to the AI model that generates your results | The assembled session prompt described in Section 5.3: your symptom description, questionnaire answers, the working remedy shortlist and hypotheses, retrieved literature excerpts, and session reasoning (without your name, email, or account identifier) |
| Google (Gemini AI models, via OpenRouter) | AI processing: the AI model provider that generates your session results | The same session content routed by OpenRouter |
| Pinecone Systems, Inc. | Vector search: hosts our index of homeopathic literature and matches your session against it | Numerical representations (embeddings) of search queries derived from your session content (without your name, email, or account identifier) |
| Google Sign-In | Authentication | Email, name (if you choose this sign-in method) |
| Apple Sign-In | Authentication | Email, name (if you choose this sign-in method) |
| Apple Speech Recognition | Voice-to-text transcription (iOS) | Voice audio for transcription |
| Google Speech Recognition | Voice-to-text transcription (Android) | Voice audio for transcription |
| RevenueCat | Subscription management; if you opt in to advertising measurement, forwarding subscription events to Meta on our behalf (Section 5.7) | Purchase and subscription status, pseudonymous app user ID; if you opt in: your advertising identifier (where available), vendor identifier (iOS), IP address, and the Meta anonymous app-instance identifier |
| Sentry (Functional Software, Inc.) | Crash and error reporting for the App | Device and app information (device model, OS version, app version) and technical error data |
| Brevo | Email delivery for the support and feedback messages you send us | Your email address, the content of your message, the message's category and subcategory, and your app version and platform |
We share with each provider only the information it needs for its function, and we engage these providers to process that information in order to perform services for us. How our AI processing providers handle session text — including retention — is described in Section 5.3.
To generate your session results, the App assembles a working prompt from your session and sends it to our AI processing providers: OpenRouter, Inc., which routes the request, and the underlying AI model provider — currently Google, whose Gemini models generate the results. The assembled prompt contains your symptom description, your questionnaire answers, the working shortlist of candidate remedies and the hypotheses developed during your session, retrieved excerpts of traditional homeopathic literature (together with the search queries used to retrieve them), and the reasoning produced during your session. This content is health-related information, and this processing is covered by the explicit consent described in Section 3.
If you redeem a creator's (influencer's) promo code or sign up through their link, we show that creator a record of the redemption in their creator dashboard, so that sign-ups can be attributed and creators can be paid. The record shown in the dashboard contains a stable pseudonym (not your name or email), the date, the code or link used, and a general status derived from your subscription (registered, subscribed, or churned). The dashboard never displays your name, your email address, or any of your health data.
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
We advertise the App on Facebook and Instagram. To measure which ads bring people to the App and improve how our ads are shown, the App can share a small set of app-usage events with Meta Platforms Ireland Ltd (for users in the EEA) or Meta Platforms, Inc. (for users in the UK and elsewhere). This happens only if you opt in — by ticking "I agree to share app-usage data for marketing purposes" on the notices screen shown when you first use the App (or after an update to these texts), or later in Profile → Privacy choices — and you can withdraw at any time in Profile → Privacy choices. Advertising measurement is off by default and is not offered in every region.
What is shared. (1) Events: that the App was opened; that an account was created (and whether by email, Google or Apple); that a promo code started a trial; and that a subscription was bought or renewed, with its price and currency. (2) Identifiers and device details: an anonymous app-instance identifier created by the Meta SDK; your device's advertising identifier (on iOS only if you also allow tracking in the iOS prompt; on Android unless you have turned off ads personalisation); the iOS vendor identifier; your IP address; device model, operating-system version, app version, language, time zone and screen size. Subscription events are sent by RevenueCat on our behalf, with the identifiers listed above.
What is never shared: your symptom descriptions, questionnaire answers, remedies, results, session history, name, e-mail address, or anything you type in the App.
Who is responsible. For the collection of these events in the App and their transmission to Meta, we and Meta are joint controllers (EEA: Meta Platforms Ireland Ltd; UK: Meta Platforms, Inc.) under Article 26 GDPR / UK GDPR. We have agreed with Meta that we are responsible for giving you this information and obtaining your consent, and that Meta is responsible for the security of its systems and for answering requests about the data it holds. The essence of that agreement is Meta's Controller Addendum (facebook.com/legal/controller_addendum). After transmission, Meta processes the data as an independent controller for its own purposes, including measuring and improving its advertising and its products; the information about Meta required by Articles 13(1)(a)–(b) is in Meta's Privacy Policy (facebook.com/about/privacy).
Legal basis. Your consent (Article 6(1)(a) and, to the extent that using a health app reveals information about your health, Article 9(2)(a) GDPR / UK GDPR; Article 5(3) of the ePrivacy Directive / regulation 6 PECR for storing and reading identifiers on your device). Withdrawing does not affect the lawfulness of processing before withdrawal.
Retention and deletion. Meta retains these events for up to two years. We cannot delete individual events at Meta once sent; withdrawing consent stops all further sharing, including subscription renewals, from that moment. RevenueCat deletes the identifiers it holds when you withdraw or delete your account. You can also ask Meta directly about data it holds about you through the options in Meta's Privacy Policy, and you can ask us at info@similia.io — we forward requests concerning this joint processing to Meta within seven days.
International transfers. Meta Platforms Ireland Ltd transfers data to Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework (and, in reserve, the Standard Contractual Clauses); for UK users the UK Data Transfer Addendum applies. RevenueCat, Inc. is in the United States under the Standard Contractual Clauses and the UK Addendum.
iOS tracking permission. On iOS, sharing the advertising identifier also requires your permission in Apple's "Allow tracking" prompt, which we show only after you have opted in here. If you decline that prompt (or iOS does not show it), we do not send measurement events from the App on that device; only Apple's privacy-preserving SKAdNetwork attribution, which contains no data about you personally, may still tell Meta that an ad led to an install.
Test builds. Development and test versions of the App never share anything with Meta.
Your data is stored on secure servers provided by Firebase (Google Cloud Platform). Data may be processed in the United States and other countries where our service providers maintain facilities.
You have the right to access the personal information we hold about you and request a copy of your data in a portable format.
You can update or correct your account information at any time through the App settings.
You have the right to request deletion of your personal data. You can delete your account directly in the App, or contact us at the email below, and we will process your request within 30 days.
You may withdraw your consent to the processing of your health data at any time, as described in Section 3.1. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
You may withdraw your consent to advertising measurement at any time in Profile → Privacy choices (Section 5.7 and 8.8).
If you are located in the United Kingdom, the European Union, or the European Economic Area, you have the following additional rights:
Right to complain to a supervisory authority: you also have the right to lodge a complaint with a data protection supervisory authority — in the UK, the Information Commissioner's Office (ICO, ico.org.uk); in the EU/EEA, the data protection authority of your country. We would appreciate the chance to address your concerns first, but you may contact a supervisory authority at any time.
If you are a California resident, you have the right to know what personal information we collect, to request its deletion and correction, to opt out of the "sale" or "sharing" of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell personal information. If you opt in to advertising measurement (Section 5.7), the sharing of app-usage events with Meta may be "sharing" for cross-context behavioural advertising under California law; you can opt out at any time in Profile → Privacy choices, which also serves as our "Do Not Sell or Share My Personal Information" control. Because this is a mobile app without a web browser, it does not receive Global Privacy Control signals; the in-app control is the opt-out.
You can withdraw your consent, and object to any further sharing with Meta, at any time in Profile → Privacy choices. For data Meta already holds, Meta's Privacy Policy explains your rights towards Meta; you can also write to us and we will forward your request (Section 5.7).
Similia Home Prescriber is not intended for children under the age of 16. We do not knowingly collect personal information from children under this age, and the App asks you to confirm that you meet the age requirement when you first use it.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@similia.io. If we discover that we have collected information from a child under the applicable age, we will delete it promptly.
If you are accessing the App from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
For users in the EEA, UK, or Switzerland: where we transfer personal data outside the EEA, the UK, or Switzerland, we rely on safeguards recognised by applicable data protection laws — such as Standard Contractual Clauses (or the UK International Data Transfer Addendum) in our providers' data processing terms, or a relevant adequacy decision. Session text sent to our AI processing providers (Section 5.3) may be processed on servers located outside the UK/EEA under those providers' terms. The transfer safeguards for advertising measurement (Meta and RevenueCat) are described in Section 5.7.
The App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any personal information.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the App and updating the "Last Updated" date at the top of this policy.
If a change materially affects how we process your health data, we will ask for your renewed explicit consent in the App before that change applies to you.
Each version of this policy takes effect when it is published, and applies to you as follows. If you are a new user, the version published at the time of your first acceptance is the one that applies to you. If you are an existing user and a change requires your renewed acceptance or consent — in particular, a change that materially affects how we process your health data — the version you last accepted continues to govern that processing until you accept the new version in the App. Each version carries the consent bundle version number shown at the top of this page; when you explicitly accept in the App, that number is recorded with your acceptance (Section 3.1) — and, if you opt in to advertising measurement, with that separate consent too (Section 5.7) — so both you and we can identify exactly which text you explicitly accepted. A non-material update that applies through your continued use is not recorded as a separate acceptance; it is identified by the published version and its publication date.
We publish an updated version together with the release of the App version whose data practices it describes — so where this policy describes notices, consents, or confirmations presented when you first use the App, it describes the App version published alongside this version of the policy.
If you have any questions about this Privacy Policy or our data practices, please contact us:
SIMILIA LTD
71-75 Shelton Street, Covent Garden
London, United Kingdom, WC2H 9JQ
Email: info@similia.io
We will respond to your inquiry within 30 days.
For transparency, here is a summary of our data practices:
| Data Type | Collected | Shared | Purpose |
|---|---|---|---|
| Email address | Yes | No | Account creation, authentication |
| Name | Yes (optional) | No | Personalization |
| Health information | Yes | No | App functionality (session results) |
| App activity (app interactions) | Yes | Yes — opt-in only* | App functionality, analytics; advertising measurement if you opt in |
| Device or other IDs | Yes | Yes — opt-in only* | Analytics, security; advertising measurement if you opt in |
| User IDs (pseudonymous) | Yes | Yes — opt-in only* | Account functionality; advertising measurement if you opt in |
| Purchase history | Yes | Yes — opt-in only* | Subscription management; advertising measurement if you opt in |
| Crash logs and diagnostics | Yes | No | App stability |
"Collected" and "Shared" in this summary follow Google Play's Data safety definitions: transfers to service providers that process data on our behalf (for example, our hosting and AI processing providers listed in Section 5) are not "sharing" under those definitions. *"Shared" rows marked opt-in apply only if you enable advertising measurement (Section 5.7).