Privacy Policy — Nivela

Version 1.0 · Last updated: 24 July 2026
back to the app page · Italiano

1. Data Controller and Contact Details

Data Controller: Luigi Piscopo, an independent software developer operating under the trade name “LupiFoundry”. Address: Via Cupone 1, 75010 Grottole (MT), Italy. E-mail: [email protected]

For any questions regarding this policy or the processing of your data, please write to: [email protected]


2. Data You Enter and Categories

Nivela is an application for tracking blood glucose levels. The information you may enter includes:

These data fall within the special category of health data under Article 9 of Regulation (EU) 2016/679 (GDPR). Their processing therefore requires enhanced safeguards, described below.

Providing this data is entirely optional: not entering it merely prevents you from using the related features of the app, with no other consequence.


3. Where Your Data Is Stored — Local-First Privacy Architecture

Your health data never leaves your device without your explicit consent and direct action.

In practice:

Practical implication: because your data remains exclusively on your device — and, if you enable backup on iOS, in your personal iCloud space — and the developer has no technical access to it, the app functions essentially as a local tool under your full control. This architectural choice is deliberate and represents the primary privacy guarantee offered by the app.


4. Purposes of Processing

The data you enter into the app is used solely for:

  1. Displaying and analysing your blood glucose values — charts, statistics, trends — directly on your device.
  2. Generating local reminders for measurements (via local notifications, with no data transmission).
  3. Syncing with the system health store — Apple Health (HealthKit) on iOS, Health Connect on Android — only if explicitly enabled by you (see § 6).
  4. Personal backup to iCloud Drive (iOS/iPadOS only) — only if explicitly enabled by you (see § 3).

There is no profiling, marketing, advertising, or server-side aggregate analysis, because the developer does not receive any data.


Under the GDPR:

Note on GDPR applicability in this context: because all data is processed locally on the user’s device and the developer has no access to it, processing takes place entirely under the direct control of the data subject. In this configuration the controller acts as the provider of software that processes data locally on the user’s device: it does not access, receive, or retain that data.


6. System health store integration (Apple Health / Health Connect)

The app can integrate with the operating system’s health data store: Apple Health (HealthKit) on iOS/iPadOS, Health Connect on Android. In both cases the integration is optional, off by default, and covers blood glucose readings only; the app remains fully usable without enabling it.

The following guarantees apply on both platforms:

On iOS/iPadOS (Apple Health — HealthKit)

On Android (Health Connect)


7. Local Notifications

The app may send local notifications to your device as measurement reminders.


8. No Third-Party Sharing — No Tracking

The app does not contain and does not use:

The developer does not share your data with any third party and does not transmit it to any of its own servers: there is no developer-operated infrastructure that receives your data. The only exception is the optional iCloud backup feature (§ 3), available on iOS/iPadOS only: if you enable it, your data is copied in encrypted form to your personal Apple account, governed by Apple’s terms. Apple may store such data outside the EU/EEA: the transfer relies on the safeguards adopted by Apple (an applicable adequacy decision or standard contractual clauses under Art. 46 GDPR), described in Apple’s own privacy policy. The backup remains encrypted with a key neither Apple nor the controller can access. Even then, the controller neither transmits nor accesses it: the copy takes place solely between your device and your own iCloud. On Android there is no exception at all, because the app has no cloud backup.

On both platforms, data that you decide to move off the device naturally remains under your control: the files you export and share (§ 12) and, if you enable it, syncing with the system health store (§ 6).


9. Data Retention and Deletion

The controller retains no data, so no retention period applies on the controller’s side. On your device, data remains until you delete it or uninstall the app: there is no automatic deletion. The app has no accounts or registration, so there is no profile to deactivate.

Because your data resides locally on your device, retention and deletion are entirely under your direct control:


10. Your Rights as a Data Subject

As a data subject under the GDPR (Articles 15–22) you have the right to:

Practical note: given the app’s local architecture, your data is already entirely on your device under your direct control. To exercise your rights of access, rectification, and erasure you may act directly within the app or through your device settings, without needing to contact the developer.

To exercise rights that require the developer’s involvement, or for any queries, please write to: [email protected]


11. Minors

The app is intended for use by adults and offers no features directed at minors. As the controller collects no data, no age verification is performed. If it comes to the attention of a parent or guardian that a minor has entered data into the app, they are advised to manage the situation directly on the device (deleting the data, uninstalling the app). As data is not transmitted to the developer, the developer is not in a position to intervene remotely.


12. Security

App data is stored locally on your device. Security depends in large part on the protections the operating system applies to app data: on iOS/iPadOS, the application sandbox and file system protection tied to the device passcode; on Android, the app’s private storage (readable only by the app itself, isolated from other apps) and the device encryption provided by the system.

Permissions requested on Android: notifications and vibration (for local reminders), biometrics (for the optional app lock), reading and writing blood glucose in Health Connect (§ 6) and — on Android 12 and earlier only — storage access to save or open the files you export and import yourself (§ 12). No permission is used to collect data without your knowledge. The app also declares allowBackup="false": Android’s automatic backup system does not copy the app’s data to Google Drive.

Database encryption (at rest): on devices that support it, the local database is encrypted using SQLCipher (AES-256) — on both iOS and Android. The encryption key is generated on the device and stored in the system secure store, tied to that device only: the Keychain on iOS, without syncing via iCloud Keychain; the Android Keystore on Android. If, in exceptional cases, the encryption engine were unavailable on the device, the app still keeps your data in the private area protected by the operating system so as not to lose it, restoring encryption on the next suitable launch.

Backup encryption:

None of these keys are known to or accessible by the developer. You are still encouraged to protect your device with a strong PIN/biometric lock and to keep the device encryption provided by the operating system enabled, as an additional layer of protection. The app also offers an optional app lock with passcode or biometrics.


13. Changes to This Policy

The developer reserves the right to update this policy. In the event of material changes, a new version will be published with an updated date and, where the processing itself changes, users will be actively informed and, if necessary, asked for renewed consent. Users are encouraged to check this page periodically.


14. Contact

For any privacy-related questions, requests, or complaints:

Luigi Piscopo (LupiFoundry) Via Cupone 1, 75010 Grottole (MT), Italy E-mail: [email protected]


Medical Disclaimer

Nivela is not a medical device. The app is intended solely for personal informational and self-monitoring purposes. It does not replace the diagnosis, treatment, or advice of a physician or other qualified healthcare professional. For any decision relating to your health, always consult your doctor.