Legal

Privacy Policy

Effective 24 July 2026

Cardivo (“we”, “us”, “the app”) is a wellness and fitness app. It is not a medical device and must not be used to diagnose, treat, cure, or monitor disease.

Contact: info@gocardivo.com

1. Summary

2. What data we collect

A. Data you create in Cardivo

B. Account and authentication data

C. Apple Health (HealthKit) data — only if you connect Apple Health

With your permission in the iOS Health permission sheet, Cardivo may:

We request only the HealthKit types needed for Cardivo’s wellness features. You can change or revoke Health access anytime in iOS Settings → Privacy & Security → Health → Cardivo (or Health → Sharing → Apps).

D. Device permissions

E. Technical data

3. How we collect data

4. How we use data

We use your data to:

We do not sell your personal data. We do not use HealthKit data for advertising, marketing, or data brokering. We do not share HealthKit data with third parties for advertising, data mining, or unrelated research.

5. Weekly insights / “AI summary”

Cardivo’s weekly insight feature (labeled “AI summary” in the app) is produced by on-device logic using data already stored in Cardivo (recent measurements and journal entries).

What is sent to a third-party generative AI service for this feature: nothing. Who receives your measurement or journal content for generative AI processing: nobody outside your device for that feature.

If we ever offer a feature that sends personal data to an external AI provider, we will disclose what data would be sent, identify the recipient, ask for your permission before sending, and update this Privacy Policy.

6. Sharing with service providers

We share data only as needed to run Cardivo, and only with the parties below. We require that they protect the data with protections that are the same or equal to those described in this policy for the services they provide to us.

PartyRoleWhat may be shared
Google Firebase (Google LLC) Authentication and cloud database (Firestore) so signed-in / guest sessions can sync profile, measurements, and journal Account identifiers; profile fields; measurement and journal records you create in Cardivo
Apple Inc. Sign in with Apple; App Store subscriptions; Apple Health / HealthKit on your device Sign-in identifiers / relay email as you choose; subscription status via Apple; Health data stays under Apple’s HealthKit permissions on your device
Google LLC (Sign in with Google) Optional account sign-in Sign-in identifiers and basic profile info Google provides

We do not share your Cardivo content with advertising networks. We do not share HealthKit data with third-party AI companies. We may disclose data if required by law, legal process, or to protect users and the service.

Cloud sync happens when you use a Cardivo account session (including guest). By creating or continuing a session and using sync-enabled features, you instruct us to store that Cardivo app data with Firebase for backup/sync. Using “Delete all data” in Profile removes measurements, journal entries, and related synced records from this device and from Cardivo cloud sync for your current account session. You can also email info@gocardivo.com for additional deletion requests.

Apple Health data that Cardivo reads is used on device for Cardivo features. Cardivo app records (measurements/journal) may sync to Firebase as described above; we do not sell or separately transfer raw HealthKit databases to other companies.

7. Apple Health (HealthKit)

Purpose: wellness and fitness only (trends, optional comparison with watch/phone Health data, optional save of Cardivo heart rate into Health).

Permission: Cardivo asks for Health access before reading or writing HealthKit data. You can refuse. If you refuse, Cardivo still works without Health integration.

Control: Turn off Health sync in Cardivo Profile and/or revoke types in iOS Health settings.

Retention in Health: Samples written to Apple Health are stored by Apple Health under your Apple ID / device Health database according to Apple’s rules. Deleting Cardivo app data does not automatically delete samples already saved in Apple Health; remove those in the Health app if you wish.

No secondary use: HealthKit data is not used for advertising or sold.

8. Retention

9. Your choices and rights

If you are in a region with a supervisory authority, you may lodge a complaint there.

10. Children

Cardivo is not intended for children under 16. We do not knowingly collect data from children under 16.

11. International processing

Cloud providers (including Google Firebase) may process data in the United States or other countries where they operate. Where required, we rely on appropriate safeguards for such transfers.

12. Changes

We may update this policy. The effective date above will change when we do. Material changes about new third-party AI sharing will be disclosed in-app and will require permission before that sharing begins.

13. Contact

Privacy and support: info@gocardivo.com

Terms of Use: gocardivo.com/terms