CARDIOMATE

Privacy Policy.

Effective: August 17, 2026

The short version. Every blood pressure reading you log - the numbers, your notes, and the context tags - is stored only on your phone. CodeEnsis never receives it, and it is never used for analytics. Cardiomate shows no ads and has no advertising SDK at all. It uses Google Firebase Analytics for anonymous usage statistics (which screens get opened, which features get used - never your readings), Firebase Crashlytics to report crashes so we can fix them, and RevenueCat to validate the one-time Pro purchase. Apple Health / Health Connect sync is off until you turn it on, and reading and writing are two separate permissions you grant independently.

1. Who we are

Cardiomate is published by CodeEnsis Ltd. ("we", "our", "us"), the data controller for the limited data described below. This policy explains what the app stores on your device, what leaves your device and to whom, and what rights you have. Questions or requests: [email protected].

2. What Cardiomate stores on your device

The following lives only in the app's private storage on your phone. It is never uploaded to CodeEnsis, never sold, and never used to target advertising:

If you uninstall Cardiomate, all of this is removed with the app. There is no server-side copy of your health data, because we never receive it.

3. What we never do with your health data

4. Apple Health and Android Health Connect

Cardiomate can synchronise readings with Apple Health (iOS) or Health Connect (Android). This is off by default and does nothing until you enable it in Settings → Health sync.

Reading and writing are deliberately separate, and you grant them independently - writing your own numbers out never requires handing over read access to the rest of your health record:

This exchange happens entirely on your device, between Cardiomate and the operating system's health store. No health data is transmitted to CodeEnsis or to any third party as part of the sync, and health data obtained this way is used only to display, chart, and export your history inside the app. It is never used for advertising, never shared with data brokers, never used for analytics, and never transferred to anyone else. You can revoke either permission at any time in iOS Settings → Health or in Health Connect, and turn the feature off inside Cardiomate.

5. Analytics and crash reports (Google Firebase)

To understand which features are worth keeping and where people get stuck, Cardiomate includes Google Firebase Analytics. It receives events describing that something happened, never what your health data says - for example: a screen was opened, a reading was saved (with flags for whether a pulse, a note, or a context tag was filled in, but not their values), an export was run, the paywall was shown, or a purchase was restored. It also receives limited technical data such as your app and OS version, device model, coarse IP-derived region, and a resettable app-instance identifier that Google generates.

Firebase Analytics never receives your systolic or diastolic values, your pulse, your notes, your context tag values, or anything imported from Apple Health or Health Connect. Google processes this data as our service provider under the Google Privacy Policy.

Analytics collection starts only once you continue past the app's first screen. Both this policy and the Terms of Use are linked directly under the button on that screen, and continuing past it is what records your acceptance of them.

Crash reports. Cardiomate also includes Firebase Crashlytics. When the app crashes or hits an unrecoverable error, it sends a report describing the failure itself: the error and the stack trace of the code that failed, the app and OS version, the device model, whether the device was jailbroken or rooted, how long the app had been running, and a randomly generated installation identifier that Crashlytics creates and that is reset when you reinstall the app. It does not send your readings, your notes, your context tags, anything from Apple Health or Health Connect, or a screenshot of what you were looking at, and we attach no custom keys or log messages containing your data.

Unlike analytics, crash reporting is active from the moment the app starts, including before you accept this policy. This is deliberate and narrow: a crash on the very first launch is exactly the one we would otherwise never hear about, because the app never reaches the screen where you could consent. A crash report says which build broke and where in our code - it does not describe what you were doing or what your health data says. Google processes it as our service provider under the Google Privacy Policy. If you would rather not send crash reports at all, uninstalling the app stops them; we have no way to identify or link them back to you.

Cardiomate contains no advertising SDK.

6. Purchases (RevenueCat, Apple, Google)

Cardiomate Pro is a one-time purchase - there is no subscription. Payment is handled entirely by Apple or Google; we never see your card, billing address, or any payment credential.

To validate the receipt and let you restore your purchase on a new device, purchase events are processed by RevenueCat, Inc. acting as our service provider. RevenueCat receives the store receipt, the product identifier, your country and platform, a randomly generated anonymous user identifier that we create on your device, and technical device data. It does not receive your name, email address, or any of your health data. RevenueCat's handling is described in the RevenueCat Privacy Policy; Apple and Google handle the transaction itself under their own policies.

7. Exporting and sharing your data

You can export your history as a CSV file or a PDF report from within the app. The file is generated on your device. When you choose to share or save it, your device's standard share sheet hands it to whatever destination you pick - email, a messaging app, cloud storage, your doctor. That action, and where the file goes, is entirely under your control; CodeEnsis is not involved and never receives a copy. Once a file leaves the app it is governed by the privacy practices of wherever you sent it.

8. Reminders and notifications

If you enable measurement reminders, Cardiomate schedules local notifications on your device at the times you choose. They are generated on-device; there are no push servers, no remote message content, and nothing about your readings is included in a reminder. You can turn reminders off in the app or revoke the notification permission in your system settings at any time.

9. Biometric lock

You can require Face ID, Touch ID, or your Android biometric to open the app. The check is performed by the operating system, which returns only a success or failure. Your fingerprint or face data never leaves the secure hardware on your device, is never accessible to Cardiomate, and is never transmitted anywhere.

10. Permissions Cardiomate asks for

11. Legal bases (EEA and UK)

Where the GDPR applies: health data is processed solely on your device under your explicit consent, given when you enable Health sync, and we are not a recipient of it. Analytics and purchase-validation data are processed on the basis of your consent, given when you continue past the app's first screen, where both documents are linked, and our legitimate interest in operating and improving the app and in preventing purchase fraud. The crash reports described in section 5 are processed on the basis of our legitimate interest in keeping the app from crashing on the people using it; they contain no health data and no identifier that we can trace to a person, and they are the only processing that begins before you accept this policy. You may withdraw consent at any time by revoking the relevant permission or uninstalling the app.

12. Children

Cardiomate is a general-audience health tool intended for adults and is not directed at children under 13 (or under 16 where local law sets that threshold). We do not knowingly collect personal data from children. If you believe a child has provided us with data, write to [email protected] and we will address it.

13. Your rights

14. Data retention

On-device data is retained until you delete it in the app, uninstall the app, or clear it from your device's app settings - we cannot delete it for you, and we cannot recover it for you. Analytics data is retained by Google under the retention window configured for our Firebase project; crash reports are retained by Crashlytics for 90 days; purchase records are retained by RevenueCat and by Apple or Google for as long as needed to honour restores and to meet tax and accounting obligations.

15. Not a medical device

Cardiomate is not a medical device. It records numbers you enter or import and presents them back to you; it does not diagnose, treat, or give medical advice. Category labels and averages are informational and follow general published guidance, not a judgement about you. Always consult a qualified healthcare professional about your blood pressure, and never change or stop medication based on what this app shows. See the Terms of Use.

16. Changes to this policy

We may update this policy as Cardiomate evolves. Material changes will be reflected here with an updated "Effective" date above, and the app will ask you to review and accept the new version on next launch. Continuing to use the app after a change means you accept the updated policy.

17. Contact

Questions or requests about this policy: [email protected]. A human reads every message.