Skip to content
Orlivas
Home Legal Center Privacy Policy Terms of Service EN · TR
Legal Center / Privacy Policy

On this page

  • 1. Who we are
  • 2. What Orlivas does
  • 3. The data we collect
  • 4. Data about family members you add ("managed profiles")
  • 5. Why we use data, and our legal bases
  • 6. Optional AI features
  • 7. Who can see your data
  • 8. International transfers
  • 9. How long we keep data (retention)
  • 10. Your rights
  • 11. Security
  • 12. Children
  • 13. Regional privacy information
  • 14. Third-party links
  • 15. Changes to this policy
  • 16. Not medical advice
  • 17. Contact

Orlivas — Privacy Policy

Version 1.0.0 · Effective 2026-07-11 · Last updated 2026-07-11

The short version. Orlivas exists so caregivers can organize their family's health.

Your family's health information is used only to provide the service to you and the

people you invite. **We do not sell it, we do not use it for advertising, and we do not

use it to train third-party AI models.** You can export or permanently delete it at any

time.


1. Who we are

Orlivas ("Orlivas", "we", "us", "our") is a family health companion operated by

Zagru, part of the Zagru group. Zagru is the **data

controller** for the personal data described here.

  • Registered address: postal address available on request at privacy@orlivas.com
  • Privacy / data-protection contact: privacy@orlivas.com
  • Person in charge of the protection of personal information: our Privacy Contact
  • EU/EEA representative (if applicable): privacy@orlivas.com

This policy applies to the Orlivas mobile apps, the Orlivas backend services, and

orlivas.com.

2. What Orlivas does

Orlivas lets a caregiver create a family group, add family members — including

managed profiles for people who never use the app themselves (an elderly parent, a

child, a dependent) — and track medications and dose timelines, vital signs, hydration,

mood/sleep/wellness, symptoms, appointments, health documents, journals and wellness

photos for those members. Invited caregivers see and contribute to the same records

according to their role (Owner, Admin, Caregiver, Member, Viewer).

Health records always belong to a family member and to the family group, not to

an individual login.

3. The data we collect

3.1 Account data

  • Email address, name, password (stored only as a salted bcrypt hash), optional phone

number and avatar, preferred language and timezone.

  • If you sign in with Google or Apple: the subject and verified email from your

provider's identity token. We never receive your provider password.

  • Session tokens and push-notification device tokens.

3.2 Family & health data — special-category data

  • Family groups; member profiles (display name, optional legal name, relationship,

optional date of birth, gender, health flags such as "diabetes", dietary preferences).

  • Health records entered by you or your caregivers: medications and dose logs

(taken / snoozed / skipped / missed), blood pressure, blood sugar (glucose), weight,

heart rate, hydration, mood, sleep, activity, symptoms, daily wellness check-ins,

notes, goals and appointments.

  • Photos and documents you choose to upload (medication-box/blister photos,

prescriptions, lab reports, health documents, photo-journal entries, wellness selfies)

and, where you enable the optional scan feature, the text extracted from them.

This is special-category personal data (health data) under Article 9 GDPR and

"special categories" under the Turkish KVKK. We process it **only because you

deliberately enter it to run your family's care, on the basis of your explicit

consent** (Art. 9(2)(a) GDPR), which you may withdraw at any time by deleting the data

or your account.

3.3 Technical & usage data

  • Anonymous usage analytics (screens visited, features used) — **never health

values, never member names**, with entity ids removed from screen paths. You can turn

this off in the app, and we can disable it globally.

  • Security logs (login attempts, an audit trail of account actions) to protect accounts.
  • If crash reporting is enabled for a release, crash stack traces without personal

identifiers or health data are sent to our error-monitoring processor.

4. Data about family members you add ("managed profiles")

When you add a managed profile or enter health data about another person, **you confirm

that you are entitled to do so** — as their parent or legal guardian, as their carer

with their consent, or with another lawful basis. You are responsible for informing them

(when they are able to understand) that their health information is organized in Orlivas,

and for honoring their wishes if they ask you to remove it. Managed profiles have no

login of their own; the family's account holders control this data together. See the

Children & Dependent Data Notice and the Parent/Guardian Notice.

5. Why we use data, and our legal bases

PurposeDataLegal basis
Provide the service: store/sync records, compute dose timelines, send the reminders and non-diagnostic alerts you configureAccount, family, healthContract (Art. 6(1)(b)); health data on explicit consent (Art. 9(2)(a))
Account security: login throttling, session management, audit trailAccount, technicalLegitimate interest (Art. 6(1)(f))
Transactional email: verification, password resetAccountContract
Optional AI features (Visual Wellness, AI Insights, AI Assistant)Health context / wellness photosExplicit consent — see §6 and the AI Transparency Notice
Improve Orlivas via anonymous usage statisticsUsage (no health)Consent (off per user at any time)
Comply with legal obligations (e.g. tax records for purchases)Billing (no health)Legal obligation

We never sell personal data, use health data for advertising or profiling, or allow

a third party to train AI models on your family's records.

6. Optional AI features

Some optional, plan-gated features can use AI: Visual Wellness (appearance scoring

of a selfie), AI Insights (summaries of logged activity) and the AI Assistant

(answers questions using your family's data).

  • By default, these run on Orlivas' own servers using a built-in, non-diagnostic

engine, and no health data leaves our systems for AI purposes.

  • If we enable an external AI provider (categories: large-language-model / vision-model

providers), the relevant input — a wellness selfie image for Visual Wellness, or a

compact health-activity summary including a member's name for Insights/Assistant —

would be sent to that provider to generate the result shown back to you.

  • Where an external AI provider is used on health data, we will obtain your **separate,

explicit consent** first, and you can decline or disable it.

  • AI output is non-diagnostic and may be wrong or incomplete; never rely on it for

medical decisions. See the AI Transparency Notice and the **Health & Wellness

Disclaimer**.

7. Who can see your data

  • Your family: caregivers you invite see member records according to their role

(Owner, Admin, Caregiver, Member, Viewer). Invites are code-based and expire.

  • Our staff: a small operations team may access records only when strictly necessary

to run the service (support, abuse handling, legal obligation), under confidentiality

duties, with actions audit-logged.

  • Processors that host or deliver parts of the service under data-processing

agreements:

ProcessorPurposeHealth data?Location
DigitalOcean, LLCHosting, database, encrypted backupsYes (as host)our hosting region
Google (Firebase Cloud Messaging)Android push deliveryNo (text only)Global
Apple (APNs)iOS push deliveryNo (text only)Global
RevenueCat, Inc.Subscription/purchase stateNo (UUID + purchase state)USA (SCCs)
Functional Software, Inc. (Sentry)Crash/error monitoringNo (no PII)USA (SCCs)
Google / AppleFederated sign-in token verificationNoGlobal
AI providers (Google Gemini / OpenAI / DeepSeek)Optional AI features only if enabledYes, if enabled (see §6)Global

Push payloads are minimized: they carry the notification text you configured and routing

identifiers, not your full records.

8. International transfers

Where a processor operates outside your region, transfers rely on adequacy decisions or

Standard Contractual Clauses. The primary hosting region is our hosting region

(to be confirmed).

9. How long we keep data (retention)

DataRetention
Account & family health recordsFor as long as the account/family exists (your family's history)
After account closureErased as in §10, at closure (see the Account & Data Deletion page)
Refresh tokensExpire within 30 days; revoked at logout/closure
Usage analytics (no health, no names)Default 365 days, then purged; off if you opt out
Security/audit logs (no health values)Up to 12 months
Billing ledger (no health data)As required by tax/commercial law ((available on request))
Encrypted database backups14 days rolling — deleted data leaves all backups within 14 days

Full detail is in our Data Retention & Deletion reference.

10. Your rights

Depending on where you live, you have rights of **access, correction/rectification,

deletion/erasure, restriction, portability, and objection, and the right to withdraw

consent** at any time. Most are self-service:

  • Export: a machine-readable JSON export of your account data.
  • Deletion: full account closure (password-confirmed) and per-record deletion.
  • To exercise other rights, or if a self-service tool is unavailable to you, email

privacy@orlivas.com. We respond within the time your law requires (generally 30

days). You may also complain to your local supervisory authority.

See the Account & Data Deletion page for exactly what happens to family and

managed-profile data on closure.

11. Security

  • All traffic is encrypted in transit (TLS). Passwords are bcrypt-hashed; sessions use

short-lived signed access tokens (15 minutes) with rotating refresh tokens.

  • Access to member health data is enforced **server-side by family role on every

request**.

  • Uploads are validated and stored outside the web root; files are served only to

authenticated family members.

  • Production secrets are never stored in code; databases are backed up encrypted with

tested restore procedures.

No method of transmission or storage is perfectly secure; we protect your data using

measures appropriate to its sensitivity. See the Security & Responsible Disclosure

page.

12. Children

Orlivas accounts are for adults (16+). Children appear in Orlivas only as **managed

profiles** created and controlled by a parent or legal guardian, who is responsible for

that data as described in §4. We do not knowingly let children hold their own accounts,

and we show no advertising to anyone.

13. Regional privacy information

These sections apply only where the relevant law applies to you.

13.1 Québec (Law 25) & Canada (PIPEDA)

If you are in Québec or elsewhere in Canada, Zagru handles your personal

information under Québec's Law 25 and/or PIPEDA. The person in charge of the protection

of personal information is our Privacy Contact (privacy@orlivas.com). We will inform

you of any confidentiality incident presenting a risk of serious injury and notify the

Commission d'accès à l'information where required. You may request access, correction,

withdrawal of consent, and information about any automated processing (see §6). French is

offered as a first-class language of this service.

13.2 European Economic Area / United Kingdom (GDPR) — if applicable

If you are in the EEA or UK, you have the rights in §10, our legal bases are in §5, and

health data is processed on your explicit consent (Art. 9(2)(a)). You may lodge a

complaint with your supervisory authority. Our EU representative, where required, is

privacy@orlivas.com.

13.3 Türkiye (KVKK)

If you are in Türkiye, we process personal data under Law No. 6698 (KVKK). Health data is

a "special category" requiring your explicit consent, which you may withdraw. You have

the rights in Article 11 of the KVKK, exercisable at privacy@orlivas.com.

13.4 California (CCPA/CPRA) — if applicable

If you are a California resident: we do not sell or "share" (for cross-context

behavioural advertising) your personal information, and we do not use health data for

advertising. You may request access and deletion and will not be discriminated against

for exercising your rights.

14. Third-party links

Our apps and site may link to third-party services (e.g. app stores). Their privacy

practices are their own; review their policies.

15. Changes to this policy

If we change this policy in a way that matters, we will notify you in the app or by email

before the change takes effect and update the date above. Earlier versions are available

on request.

16. Not medical advice

Orlivas is a personal organization and reminder tool. It does not provide medical

advice, diagnosis or treatment, and its alerts are informational, rule-based and

non-diagnostic. Always follow the guidance of a qualified healthcare professional and

call emergency services in an emergency. See the Health & Wellness Disclaimer.

17. Contact

Privacy questions and rights requests: privacy@orlivas.com

General support: support@orlivas.com

Security reports: security@zagru.com

Postal: Zagru, postal address available on request at privacy@orlivas.com

Legal & privacy contact

privacy@orlivas.com

Other legal documents

  • Terms of Service
  • Account & Data Deletion
  • Subscription Terms
  • Health & Wellness Disclaimer
  • AI Transparency Notice
  • Children & Dependent Data Notice
  • Parent & Guardian Notice
  • Cookie Policy
  • Security & Responsible Disclosure

← All legal documents

© 2026 Orlivas. All rights reserved. · Privacy Policy · Terms of Service

Orlivas does not provide medical advice, diagnosis, or treatment.