Privacy Policy — Nivela
1. Data Controller and Contact Details
Data Controller: Luigi Piscopo, an independent software developer operating under the trade name “LupiFoundry”. Address: Via Cupone 1, 75010 Grottole (MT), Italy. E-mail: [email protected]
For any questions regarding this policy or the processing of your data, please write to: [email protected]
2. Data You Enter and Categories
Nivela is an application for tracking blood glucose levels. The information you may enter includes:
- Blood glucose readings (date, time, value)
- Optional contextual data: unit of measurement, measurement type, meal timing, an indication of a high-carbohydrate meal, symptoms, custom tags, free-text notes, medication name and dose and whether/when it was taken, recent physical activity, apnea episodes, bowel movements, as well as any other optional details of the reading
These data fall within the special category of health data under Article 9 of Regulation (EU) 2016/679 (GDPR). Their processing therefore requires enhanced safeguards, described below.
Providing this data is entirely optional: not entering it merely prevents you from using the related features of the app, with no other consequence.
3. Where Your Data Is Stored — Local-First Privacy Architecture
Your health data never leaves your device without your explicit consent and direct action.
In practice:
- Local database on your device: all data is stored in a database on your device (iPhone, iPad or Android device), which is normally encrypted (see § 12). There is no central server operated by the developer, no proprietary cloud infrastructure, no remote database managed by the developer. The developer does not receive, access, or retain your health data.
- Backup to personal iCloud Drive (optional, iOS/iPadOS only): if you choose to enable backup, your data is copied to your own personal iCloud Drive — the Apple account you already own and manage — in encrypted form. The encryption key is held in your iCloud Keychain, accessible only to your own Apple devices: the developer has no access to it and cannot read the contents of the backup. This backup is also subject to Apple’s own terms and privacy policy, not the controller’s. The backup contains only the data you entered in the app: readings read from Apple Health are never copied into Nivela’s database nor included in any backup (see § 6).
- On Android there is no cloud backup at all: the app does not copy your data to Google Drive or to any other cloud service. Only the encrypted local backup on the device and the manual export of a file — which you choose where to save or whom to share it with — are available (see § 12).
Practical implication: because your data remains exclusively on your device — and, if you enable backup on iOS, in your personal iCloud space — and the developer has no technical access to it, the app functions essentially as a local tool under your full control. This architectural choice is deliberate and represents the primary privacy guarantee offered by the app.
4. Purposes of Processing
The data you enter into the app is used solely for:
- Displaying and analysing your blood glucose values — charts, statistics, trends — directly on your device.
- Generating local reminders for measurements (via local notifications, with no data transmission).
- Syncing with the system health store — Apple Health (HealthKit) on iOS, Health Connect on Android — only if explicitly enabled by you (see § 6).
- Personal backup to iCloud Drive (iOS/iPadOS only) — only if explicitly enabled by you (see § 3).
There is no profiling, marketing, advertising, or server-side aggregate analysis, because the developer does not receive any data.
5. Legal Basis
Under the GDPR:
- Art. 6(1)(a) — Consent: the user installs the app and voluntarily enters their own data, freely configuring optional features (iCloud backup and Apple Health on iOS; Health Connect on Android).
- Art. 9(2)(a) — Explicit consent for health data: at first launch the app collects explicit consent to this policy (a non-pre-ticked checkbox, with a link to the policy), recording its version and date; the user thereby consents to the voluntary local entry and processing of their own health data.
Note on GDPR applicability in this context: because all data is processed locally on the user’s device and the developer has no access to it, processing takes place entirely under the direct control of the data subject. In this configuration the controller acts as the provider of software that processes data locally on the user’s device: it does not access, receive, or retain that data.
6. System health store integration (Apple Health / Health Connect)
The app can integrate with the operating system’s health data store: Apple Health (HealthKit) on iOS/iPadOS, Health Connect on Android. In both cases the integration is optional, off by default, and covers blood glucose readings only; the app remains fully usable without enabling it.
The following guarantees apply on both platforms:
- Integration is activated only upon your explicit request, via the standard authorisation prompt of the operating system.
- Writing (
WRITE_BLOOD_GLUCOSEpermission on Android): the app copies the readings you recorded in Nivela to the system health store, so they are available to the other health apps you authorise. - Reading (
READ_BLOOD_GLUCOSEpermission on Android): used solely to (a) avoid creating duplicates when the app writes your readings and (b) show you how many readings are already synced. Values read are never imported or saved into Nivela’s database, never appear in backups, and are not used for any other purpose. - This data stays on the device and is not transmitted to the controller, who has no access to it.
- Health data read from these stores is never used for advertising, marketing, or commercial profiling purposes, nor for any form of data mining other than providing you the app’s features; it is never used to determine credit worthiness, insurance eligibility, or employment suitability; it is never transmitted to any third party by the controller, nor sold or transferred to anyone.
On iOS/iPadOS (Apple Health — HealthKit)
- HealthKit data is managed by Apple in accordance with its own privacy policies.
- You may revoke authorisation at any time via Settings → Health → Data Access & Devices on iOS.
On Android (Health Connect)
- Health Connect is Google’s platform that keeps health data locally on the device; the app accesses it through the
READ_BLOOD_GLUCOSEandWRITE_BLOOD_GLUCOSEpermissions, limited to blood glucose only. - Data held in Health Connect is subject to the terms and privacy policies of Google/Health Connect, not the developer’s.
- You may grant or revoke permissions at any time from the Health Connect app → Permissions and data → Nivela, or via Settings → Security & privacy → Privacy → Health Connect (the exact path may vary with your Android version).
- Revoking the permission does not delete readings already recorded in the app’s own local diary, which remain under your control (see § 9).
7. Local Notifications
The app may send local notifications to your device as measurement reminders.
- Notifications are generated and delivered entirely on-device, with no data transmission to external servers.
- We do not use push notification services that involve the transmission of health data.
- On Android only, the notification library bundles the Google Firebase Cloud Messaging component, which remains inactive in Nivela: the app registers no push token and sends no data to Google through it.
- You may disable notifications at any time from the system settings: Settings → Notifications on iOS, Settings → Notifications → Nivela on Android.
8. No Third-Party Sharing — No Tracking
The app does not contain and does not use:
- Analytics SDKs (e.g. Firebase Analytics, Mixpanel, etc.)
- Crash reporting SDKs (e.g. Sentry, Crashlytics, etc.)
- Advertising or targeting SDKs
- Cookies or advertising identifiers (IDFA)
- Any form of behavioural tracking
The developer does not share your data with any third party and does not transmit it to any of its own servers: there is no developer-operated infrastructure that receives your data. The only exception is the optional iCloud backup feature (§ 3), available on iOS/iPadOS only: if you enable it, your data is copied in encrypted form to your personal Apple account, governed by Apple’s terms. Apple may store such data outside the EU/EEA: the transfer relies on the safeguards adopted by Apple (an applicable adequacy decision or standard contractual clauses under Art. 46 GDPR), described in Apple’s own privacy policy. The backup remains encrypted with a key neither Apple nor the controller can access. Even then, the controller neither transmits nor accesses it: the copy takes place solely between your device and your own iCloud. On Android there is no exception at all, because the app has no cloud backup.
On both platforms, data that you decide to move off the device naturally remains under your control: the files you export and share (§ 12) and, if you enable it, syncing with the system health store (§ 6).
9. Data Retention and Deletion
The controller retains no data, so no retention period applies on the controller’s side. On your device, data remains until you delete it or uninstall the app: there is no automatic deletion. The app has no accounts or registration, so there is no profile to deactivate.
Because your data resides locally on your device, retention and deletion are entirely under your direct control:
- In-app deletion: you can delete individual readings or all data directly from within the app.
- Uninstalling the app: uninstalling the app removes the local database from your device.
- iCloud backup (iOS/iPadOS only): if you have enabled iCloud backup, associated data can be deleted from your iCloud Drive via Apple’s settings (Settings → [your name] → iCloud → Manage Account Storage).
- Data in the system health store: any readings written to Apple Health or Health Connect are deleted from those system apps, not from Nivela.
- Exported files: backup or export files you have saved or shared stay wherever you put them; deleting them is up to you.
- The developer does not hold copies of your data and is not in a position to delete it on your behalf, nor is required to do so, given the local architecture of the app.
10. Your Rights as a Data Subject
As a data subject under the GDPR (Articles 15–22) you have the right to:
- Access your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing
- Withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Lodge a complaint with a supervisory authority — in Italy: Garante per la protezione dei dati personali (www.garanteprivacy.it); in your country of residence if different
Practical note: given the app’s local architecture, your data is already entirely on your device under your direct control. To exercise your rights of access, rectification, and erasure you may act directly within the app or through your device settings, without needing to contact the developer.
To exercise rights that require the developer’s involvement, or for any queries, please write to: [email protected]
11. Minors
The app is intended for use by adults and offers no features directed at minors. As the controller collects no data, no age verification is performed. If it comes to the attention of a parent or guardian that a minor has entered data into the app, they are advised to manage the situation directly on the device (deleting the data, uninstalling the app). As data is not transmitted to the developer, the developer is not in a position to intervene remotely.
12. Security
App data is stored locally on your device. Security depends in large part on the protections the operating system applies to app data: on iOS/iPadOS, the application sandbox and file system protection tied to the device passcode; on Android, the app’s private storage (readable only by the app itself, isolated from other apps) and the device encryption provided by the system.
Permissions requested on Android: notifications and vibration (for local reminders), biometrics (for the optional app lock), reading and writing blood glucose in Health Connect (§ 6) and — on Android 12 and earlier only — storage access to save or open the files you export and import yourself (§ 12). No permission is used to collect data without your knowledge. The app also declares allowBackup="false": Android’s automatic backup system does not copy the app’s data to Google Drive.
Database encryption (at rest): on devices that support it, the local database is encrypted using SQLCipher (AES-256) — on both iOS and Android. The encryption key is generated on the device and stored in the system secure store, tied to that device only: the Keychain on iOS, without syncing via iCloud Keychain; the Android Keystore on Android. If, in exceptional cases, the encryption engine were unavailable on the device, the app still keeps your data in the private area protected by the operating system so as not to lose it, restoring encryption on the next suitable launch.
Backup encryption:
- Automatic local backups on the device are encrypted (AES-256-GCM) with the same device-bound key as the database when database encryption is active; in the fallback case described above they remain in cleartext within the app’s private, OS-protected area. The same happens, so that you do not lose the backup, in the rare case where the encryption key is temporarily unreadable from the device’s secure store. This applies on both platforms.
- The iCloud backup — iOS/iPadOS only, if enabled — is encrypted with AES-256-GCM; its key is held in your iCloud Keychain and securely synced across your own Apple devices, so that you can restore the backup on another of your devices — without the developer having any access to it. On Android this feature does not exist: the app uploads no backup to Google Drive or any other cloud service.
- The full backup you export or share manually (JSON file) can, at your choice, be protected with a passphrase you define (AES-256-GCM with key derivation via scrypt). By default no passphrase is set and the exported file is not encrypted; if you set one in the settings, every subsequent export is encrypted, cannot be read without the passphrase and, if you forget it, the contents are unrecoverable. This applies on both platforms.
- The medical export in CSV and PDF, intended for sharing with your doctor, is not encrypted: it is always generated in cleartext and shared via the system share sheet. Choose the channel and the recipient carefully. This applies on both platforms.
None of these keys are known to or accessible by the developer. You are still encouraged to protect your device with a strong PIN/biometric lock and to keep the device encryption provided by the operating system enabled, as an additional layer of protection. The app also offers an optional app lock with passcode or biometrics.
13. Changes to This Policy
The developer reserves the right to update this policy. In the event of material changes, a new version will be published with an updated date and, where the processing itself changes, users will be actively informed and, if necessary, asked for renewed consent. Users are encouraged to check this page periodically.
14. Contact
For any privacy-related questions, requests, or complaints:
Luigi Piscopo (LupiFoundry) Via Cupone 1, 75010 Grottole (MT), Italy E-mail: [email protected]
Medical Disclaimer
Nivela is not a medical device. The app is intended solely for personal informational and self-monitoring purposes. It does not replace the diagnosis, treatment, or advice of a physician or other qualified healthcare professional. For any decision relating to your health, always consult your doctor.