Privacy Policy
The short version. Orlivas exists so caregivers can organize their family's health. Your family's health information is used only to provide the service to you and the people you invite. We do not sell it, we do not use it for advertising, and you can export or permanently delete it at any time.
1. Who we are
Orlivas ("Orlivas", "we", "us") operates the Orlivas family health companion. Orlivas is the data controller for the personal data described in this policy. You can reach us about anything in this policy at privacy@orlivas.com.
2. What Orlivas does
Orlivas lets a caregiver create a family group, add family members — including managed profiles for people who do not use a phone themselves (an elderly parent, a child) — and track medications, dose schedules, vital signs, hydration, wellness, symptoms, appointments, documents and journals for those members. Invited family members see and contribute to the same records according to their role.
3. Data we collect
3.1 Account data
- Email address, name, password (stored only as a salted bcrypt hash), optional phone number and avatar.
- If you sign in with Google or Apple: your provider identity token's subject and verified email. We never receive your provider password.
- Preferred language and timezone.
3.2 Family & health data (special-category data)
- Family groups, member profiles (name/nickname, relationship, optional date of birth, health flags, dietary preferences).
- Health records entered by you or your family: medications and dose logs, blood pressure, blood sugar, weight, heart rate, hydration, mood, sleep, activity, symptoms, wellness check-ins, notes, goals and appointments.
- Photos and documents you choose to upload (e.g. medication-box photos, prescriptions, lab reports) and the text extracted from them when you use the optional scan feature.
Health data is special-category personal data under Article 9 GDPR. We process it only because you deliberately enter it to run your family's care, on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you may withdraw at any time by deleting the data or your account.
3.3 Technical data
- Push-notification device tokens (so reminders and alerts can reach your device).
- Security logs (login attempts, audit trail of account actions) — kept to protect your account.
- Optional, anonymous usage analytics (screens visited, feature used — never health values, never member names). You can turn this off in the app, and we can disable it globally.
- If crash reporting is enabled for a release, crash stack traces without personal identifiers are sent to our error-monitoring processor.
4. Data about family members you add ("managed profiles")
When you add a managed profile or enter health data about another person, you confirm that you are entitled to do so — as their parent or legal guardian, as their carer with their consent, or with another lawful basis. You are responsible for telling them (when they are able to understand) that their health information is organized in Orlivas, and for honoring their wishes if they ask you to remove it. Managed profiles have no login of their own; the family's account holders control this data together.
5. What we use data for
- Providing the service: storing and syncing your family's records, computing dose timelines, sending the reminders and non-diagnostic alerts you configure (contract, Art. 6(1)(b) GDPR; health data under Art. 9(2)(a)).
- Account security: login throttling, session management, audit trail (legitimate interest, Art. 6(1)(f)).
- Transactional email: verification, password reset (contract).
- Improving Orlivas through anonymous usage statistics (consent — off per user at any time).
We never sell personal data, use health data for advertising or profiling, or train third-party AI models on your family's records. Optional AI-assisted summaries run only over your own family's data to show results back to you.
6. Who can see your data
- Your family: people you invite see member records according to the role you give them (Owner, Admin, Caregiver, Member, Viewer). Invites are code-based and expire.
- Our staff: a small operations team can access records only when strictly needed to run the service (support, abuse, legal obligation), under confidentiality duties, with actions audit-logged.
- Processors that host or deliver parts of the service under data-processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application & database hosting, encrypted backups | EU region datacenter |
| Google (Firebase Cloud Messaging) | Push notification delivery to Android devices | Global |
| Apple (APNs) | Push notification delivery to iOS devices | Global |
| RevenueCat, Inc. | Subscription/purchase management (receives your user id and purchase state — never health data) | USA (SCCs) |
| Functional Software, Inc. (Sentry) | Crash/error monitoring (no health data, no PII) | USA (SCCs) |
Push notification payloads are minimized: they carry the notification text you configured and routing identifiers, not your full records. Where processors are outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
7. How long we keep data (retention)
| Data | Retention |
|---|---|
| Account & family health records | For as long as your account exists (that's the product: your family's history). |
| After account closure | Erased as described in section 8, immediately upon closure. |
| Encrypted database backups | Rolled off automatically within 14 days; deleted data disappears from all backups within that window. |
| Security/audit logs (no health values) | Up to 12 months, for account security and abuse prevention. |
| Billing ledger (plan grants/revocations — no health data) | As required by tax/commercial law. |
8. Deleting your data
- Individual records can be deleted in the app at any time and are removed immediately.
- Closing your account (Profile → Settings → Privacy, or by email) immediately anonymizes your identity, revokes every session and device token, and hard-deletes your personal reminders, private uploads, notification inbox and analytics trail.
- Families where you are the last remaining account holder are erased entirely — every member profile, health record, photo and document — because no controller remains for that data.
- Families with other caregivers are kept for them: the records belong to the family group, and the remaining account holders continue to control them. Ask any remaining Owner/Admin to delete specific member data, or contact us.
9. Your rights
Under the GDPR (and equivalent laws such as the Turkish KVKK) you have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. Most of these are self-service: the app includes a one-tap data export (machine-readable JSON) and full account deletion. For anything else, email privacy@orlivas.com — we respond within 30 days. You may also lodge a complaint with your local supervisory authority.
10. Security
- All traffic is encrypted in transit (TLS). Passwords are bcrypt-hashed; sessions use short-lived signed tokens with rotating refresh tokens.
- Access to member health data is enforced server-side by family role on every request.
- Uploads are validated (type and content) and stored outside the web root; files are only served to authenticated family members.
- Production secrets are never stored in code; databases are backed up encrypted with tested restore procedures.
11. Children
Orlivas accounts are for adults (16+). Children appear in Orlivas only as member profiles created and controlled by their parent or legal guardian, who is responsible for that data as described in section 4. We do not knowingly let children hold accounts, and we show no advertising to anyone.
12. Not medical advice
Orlivas is a personal organization and reminder tool. It does not provide medical advice, diagnosis or treatment, and its alerts are informational, rule-based and non-diagnostic. Always follow the guidance of a qualified healthcare professional.
13. Changes to this policy
If we change this policy in a way that matters, we will notify you in the app or by email before the change takes effect and update the date at the top. Earlier versions are available on request.
14. Contact
Privacy questions and rights requests: privacy@orlivas.com
General support: support@orlivas.com