Magno

Privacy Policy

Last updated September 2, 2026

The short version. Magno stores the health data you type in, on your device and in your private account. We don't run analytics or ad trackers, we don't sell or share your data, and you can export or delete everything yourself from Settings at any time. Questions: hello@theos.studio.

1. Who this covers

This policy applies to the Magno app at magnohq.pages.dev, including the installed home-screen version, and to the account you create to use it. "We" and "us" means Magno, based in the United Kingdom. You can reach us at hello@theos.studio.

2. What we collect

Account details. Your email address, a hashed version of your password (we never store the password itself), and an optional display name.

Where you came from. If you arrived from one of our own links, such as the Read my bloods page or a guide, we store a short tag saying which one. It is a plain word like "read", not a tracker, and it is the only thing we keep about where you came from. Our public pages also count how many times each page was opened per day, as a number, with no cookie, IP address or browser details attached.

Health data you enter. Everything you log in the app: compounds and doses, injections and injection sites, blood pressure and pulse, weight and body measurements, symptom check-ins, lab results, notes, and any lab report PDFs you upload. You choose what to enter. We never collect health data from anywhere else.

Security records. When you sign in, sign up, reset a password or make a similar change, we keep a short log entry with the time, the type of action, a shortened hash of your IP address and your browser type. We use it to throttle abuse and investigate problems. We don't store raw IP addresses.

Feedback. If you send feedback from Settings, we keep the message along with your account email and browser type so we can reply.

Billing. If you subscribe to Magno Pro, payment is handled by Stripe. We store your Stripe customer and subscription identifiers and your plan status. We never see or store your card number.

3. What we don't do

4. How we use your data

We don't use your data to train models, build profiles, or for marketing.

5. Where your data lives

Magno is local-first: your data is kept in your browser's storage on each device you use, and a copy is synced to your private account so you can recover it and use it on other devices.

The account copy is stored on Cloudflare's infrastructure (database and file storage). All traffic uses HTTPS, and Cloudflare encrypts stored data at rest. Cloudflare runs a global network, so your data may be stored or processed outside the United Kingdom under Cloudflare's standard contractual safeguards for international transfers.

We rely on a small number of service providers, each of which only receives what it needs to do its job:

6. How long we keep it

We keep your data for as long as your account exists. When you delete your account, everything tied to it is permanently removed from our servers right away, and the app clears the copy on the device you deleted it from. Encrypted infrastructure backups may hold a copy for up to 30 days before it is purged automatically.

If you use the app on more than one device, clear it from the others too by signing out and removing the app or its site data.

7. Your rights and controls

Under the UK GDPR (and the EU GDPR if you live in the European Union) you also have the right to access, correct, delete, restrict or object to how we use your data, and to receive a copy in a portable format. The tools above cover most of this; for anything else, email us and we'll help within a month. If you're unhappy with how we handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to sort it out first.

Our lawful basis for processing your account and health data is your consent, which you give by creating an account and choosing what to log, and you can withdraw it at any time by deleting your account. Keeping the security log and processing payments is in our legitimate interest in running a safe, working service and meeting our legal obligations.

8. Security

Passwords are hashed with Argon2id. Sessions use secure, HttpOnly cookies. The app is served only over HTTPS with strict security headers. Sign-in attempts are rate-limited. No system is perfectly secure, so please use a strong, unique password. If you believe your account has been compromised, or you find a security issue, write to hello@theos.studio.

9. Age

Magno is for adults. You must be at least 18 years old to create an account. We don't knowingly collect data from anyone younger; if you think that has happened, tell us and we'll delete it.

10. Not medical advice

Magno is a personal tracking tool. Nothing in the app, including lab interpretations, ranges, reminders and charts, is medical advice. Talk to a licensed clinician about your health decisions. See the Terms of Service for more.

11. Changes

If we change this policy, we'll update the date at the top and, for anything significant, tell you in the app. Continuing to use Magno after a change means you accept the updated policy.

12. Contact

Email hello@theos.studio for anything about your data or this policy.