Legal
Privacy Policy
Cardivo (“we”, “us”, “the app”) is a wellness and fitness app. It is not a medical device and must not be used to diagnose, treat, cure, or monitor disease.
Contact: info@gocardivo.com
1. Summary
- We collect the health and account data described below so you can measure, journal, sync, and see wellness insights in Cardivo.
- Weekly “AI summary” insights are generated on your device from your Cardivo data. We do not send your personal or health data to a third-party generative AI provider (for example OpenAI, Google Gemini, Anthropic, or similar) to create those summaries.
- If you use an account session, some data may sync to our cloud hosted by Google Firebase.
- Apple Health (HealthKit) data is read or written only after you grant permission in iOS, only for the types you allow, and only to power Cardivo’s wellness features. We do not sell HealthKit data or use it for advertising or data mining.
2. What data we collect
A. Data you create in Cardivo
- Camera-based wellness readings (for example heart rate / BPM, estimated blood pressure, estimated SpO₂, HRV, and related values shown in the app)
- Journal entries (mood tags, notes, optional vitals, blood sugar values and context you enter yourself)
- Health-plan progress and reminder preferences
- Profile details you provide (for example display name, optional age and sex)
- App settings (for example whether Apple Health sync is enabled, notification preferences)
B. Account and authentication data
- If you continue as a guest: a technical account identifier needed to run the session
- If you Sign in with Apple: identifiers and any name/email Apple shares with us based on your Apple choices
- If you Sign in with Google: identifiers and basic profile information Google shares with us based on your Google choices
C. Apple Health (HealthKit) data — only if you connect Apple Health
With your permission in the iOS Health permission sheet, Cardivo may:
- Read: heart rate, resting heart rate, heart-rate variability (HRV / SDNN), step count, oxygen saturation (SpO₂), and body temperature
- Write: heart-rate samples from Cardivo camera measurements back into Apple Health
We request only the HealthKit types needed for Cardivo’s wellness features. You can change or revoke Health access anytime in iOS Settings → Privacy & Security → Health → Cardivo (or Health → Sharing → Apps).
D. Device permissions
- Camera: used only for fingertip photoplethysmography (PPG) measurements. We process the live camera signal to estimate vitals. We do not upload or permanently store raw video or photos of your finger.
- Notifications: used only if you enable reminders.
E. Technical data
- Basic app diagnostics needed to operate authentication and cloud sync (for example Firebase user ID and timestamps). We do not use your data for third-party advertising.
3. How we collect data
- Directly from you when you measure, journal, edit your profile, or choose settings
- From the device camera during a measurement you start
- From Apple Health only after you grant HealthKit permission
- From Apple or Google when you choose those sign-in options
- From on-device processing for weekly insight summaries (no third-party AI API call)
4. How we use data
We use your data to:
- Provide measurements, journal, charts, health plans, widgets, and related wellness features
- Generate on-device weekly insight / “AI summary” text from your recent Cardivo measurements and journal notes
- Optionally sync your Cardivo profile, measurements, and journal across devices via our cloud
- Authenticate your account (guest, Apple, or Google)
- Optionally enrich on-screen wellness context with Apple Health values you allowed (for example steps or SpO₂)
- Optionally write Cardivo heart-rate readings to Apple Health when Health sync is on
- Respond to support or deletion requests
- Comply with law where required
We do not sell your personal data. We do not use HealthKit data for advertising, marketing, or data brokering. We do not share HealthKit data with third parties for advertising, data mining, or unrelated research.
5. Weekly insights / “AI summary”
Cardivo’s weekly insight feature (labeled “AI summary” in the app) is produced by on-device logic using data already stored in Cardivo (recent measurements and journal entries).
What is sent to a third-party generative AI service for this feature: nothing. Who receives your measurement or journal content for generative AI processing: nobody outside your device for that feature.
If we ever offer a feature that sends personal data to an external AI provider, we will disclose what data would be sent, identify the recipient, ask for your permission before sending, and update this Privacy Policy.
6. Sharing with service providers
We share data only as needed to run Cardivo, and only with the parties below. We require that they protect the data with protections that are the same or equal to those described in this policy for the services they provide to us.
| Party | Role | What may be shared |
|---|---|---|
| Google Firebase (Google LLC) | Authentication and cloud database (Firestore) so signed-in / guest sessions can sync profile, measurements, and journal | Account identifiers; profile fields; measurement and journal records you create in Cardivo |
| Apple Inc. | Sign in with Apple; App Store subscriptions; Apple Health / HealthKit on your device | Sign-in identifiers / relay email as you choose; subscription status via Apple; Health data stays under Apple’s HealthKit permissions on your device |
| Google LLC (Sign in with Google) | Optional account sign-in | Sign-in identifiers and basic profile info Google provides |
We do not share your Cardivo content with advertising networks. We do not share HealthKit data with third-party AI companies. We may disclose data if required by law, legal process, or to protect users and the service.
Cloud sync happens when you use a Cardivo account session (including guest). By creating or continuing a session and using sync-enabled features, you instruct us to store that Cardivo app data with Firebase for backup/sync. Using “Delete all data” in Profile removes measurements, journal entries, and related synced records from this device and from Cardivo cloud sync for your current account session. You can also email info@gocardivo.com for additional deletion requests.
Apple Health data that Cardivo reads is used on device for Cardivo features. Cardivo app records (measurements/journal) may sync to Firebase as described above; we do not sell or separately transfer raw HealthKit databases to other companies.
7. Apple Health (HealthKit)
Purpose: wellness and fitness only (trends, optional comparison with watch/phone Health data, optional save of Cardivo heart rate into Health).
Permission: Cardivo asks for Health access before reading or writing HealthKit data. You can refuse. If you refuse, Cardivo still works without Health integration.
Control: Turn off Health sync in Cardivo Profile and/or revoke types in iOS Health settings.
Retention in Health: Samples written to Apple Health are stored by Apple Health under your Apple ID / device Health database according to Apple’s rules. Deleting Cardivo app data does not automatically delete samples already saved in Apple Health; remove those in the Health app if you wish.
No secondary use: HealthKit data is not used for advertising or sold.
8. Retention
- On device: until you delete entries or use “Delete all data” in Profile, or uninstall the app
- In our cloud (Firebase): while your account session exists, or until we complete a deletion request
- Apple Health samples: controlled by you / Apple Health
9. Your choices and rights
- Delete Cardivo data in Profile (device + cloud sync for your session)
- Email info@gocardivo.com to request access, correction, or further deletion of cloud account data
- Revoke camera, notifications, or Health permissions in iOS Settings
- Sign out or stop using Sign in with Apple / Google
- In the EU/EEA/UK and similar regions: rights of access, rectification, erasure, restriction, objection, and portability where applicable; withdraw consent by changing permissions or contacting us
If you are in a region with a supervisory authority, you may lodge a complaint there.
10. Children
Cardivo is not intended for children under 16. We do not knowingly collect data from children under 16.
11. International processing
Cloud providers (including Google Firebase) may process data in the United States or other countries where they operate. Where required, we rely on appropriate safeguards for such transfers.
12. Changes
We may update this policy. The effective date above will change when we do. Material changes about new third-party AI sharing will be disclosed in-app and will require permission before that sharing begins.
13. Contact
Privacy and support: info@gocardivo.com
Terms of Use: gocardivo.com/terms