CARDIOMATE

Privacy Policy.

Effective: August 2, 2026

The short version. Every blood pressure reading you log - the numbers, your notes, and the context tags - is stored only on your phone. CodeEnsis never receives it, and it is never used for analytics. Cardiomate shows no ads and has no advertising SDK at all. It uses Google Firebase Analytics for anonymous usage statistics (which screens get opened, which features get used - never your readings) and RevenueCat to validate the one-time Pro purchase. Apple Health / Health Connect sync is off until you turn it on, and reading and writing are two separate permissions you grant independently.

1. Who we are

Cardiomate is published by CodeEnsis Ltd. ("we", "our", "us"), the data controller for the limited data described below. This policy explains what the app stores on your device, what leaves your device and to whom, and what rights you have. Questions or requests: [email protected].

2. What Cardiomate stores on your device

The following lives only in the app's private storage on your phone. It is never uploaded to CodeEnsis, never sold, and never used to target advertising:

If you uninstall Cardiomate, all of this is removed with the app. There is no server-side copy of your health data, because we never receive it.

3. What we never do with your health data

4. Apple Health and Android Health Connect

Cardiomate can synchronise readings with Apple Health (iOS) or Health Connect (Android). This is off by default and does nothing until you enable it in Settings → Health sync.

Reading and writing are deliberately separate, and you grant them independently - writing your own numbers out never requires handing over read access to the rest of your health record:

This exchange happens entirely on your device, between Cardiomate and the operating system's health store. No health data is transmitted to CodeEnsis or to any third party as part of the sync, and health data obtained this way is used only to display, chart, and export your history inside the app. It is never used for advertising, never shared with data brokers, never used for analytics, and never transferred to anyone else. You can revoke either permission at any time in iOS Settings → Health or in Health Connect, and turn the feature off inside Cardiomate.

5. Analytics (Google Firebase)

To understand which features are worth keeping and where people get stuck, Cardiomate includes Google Firebase Analytics. It receives events describing that something happened, never what your health data says - for example: a screen was opened, a reading was saved (with flags for whether a pulse, a note, or a context tag was filled in, but not their values), an export was run, the paywall was shown, or a purchase was restored. It also receives limited technical data such as your app and OS version, device model, coarse IP-derived region, and a resettable app-instance identifier that Google generates.

Firebase Analytics never receives your systolic or diastolic values, your pulse, your notes, your context tag values, or anything imported from Apple Health or Health Connect. Google processes this data as our service provider under the Google Privacy Policy.

Analytics collection starts only after you accept this policy and the Terms of Use on first launch. Cardiomate contains no crash-reporting SDK and no advertising SDK.

6. Purchases (RevenueCat, Apple, Google)

Cardiomate Pro is a one-time purchase - there is no subscription. Payment is handled entirely by Apple or Google; we never see your card, billing address, or any payment credential.

To validate the receipt and let you restore your purchase on a new device, purchase events are processed by RevenueCat, Inc. acting as our service provider. RevenueCat receives the store receipt, the product identifier, your country and platform, a randomly generated anonymous user identifier that we create on your device, and technical device data. It does not receive your name, email address, or any of your health data. RevenueCat's handling is described in the RevenueCat Privacy Policy; Apple and Google handle the transaction itself under their own policies.

7. Exporting and sharing your data

You can export your history as a CSV file or a PDF report from within the app. The file is generated on your device. When you choose to share or save it, your device's standard share sheet hands it to whatever destination you pick - email, a messaging app, cloud storage, your doctor. That action, and where the file goes, is entirely under your control; CodeEnsis is not involved and never receives a copy. Once a file leaves the app it is governed by the privacy practices of wherever you sent it.

8. Reminders and notifications

If you enable measurement reminders, Cardiomate schedules local notifications on your device at the times you choose. They are generated on-device; there are no push servers, no remote message content, and nothing about your readings is included in a reminder. You can turn reminders off in the app or revoke the notification permission in your system settings at any time.

9. Biometric lock

You can require Face ID, Touch ID, or your Android biometric to open the app. The check is performed by the operating system, which returns only a success or failure. Your fingerprint or face data never leaves the secure hardware on your device, is never accessible to Cardiomate, and is never transmitted anywhere.

10. Permissions Cardiomate asks for

11. Legal bases (EEA and UK)

Where the GDPR applies: health data is processed solely on your device under your explicit consent, given when you enable Health sync, and we are not a recipient of it. Analytics and purchase-validation data are processed on the basis of your consent, given when you accept this policy on first launch, and our legitimate interest in operating and improving the app and in preventing purchase fraud. You may withdraw consent at any time by revoking the relevant permission or uninstalling the app.

12. Children

Cardiomate is a general-audience health tool intended for adults and is not directed at children under 13 (or under 16 where local law sets that threshold). We do not knowingly collect personal data from children. If you believe a child has provided us with data, write to [email protected] and we will address it.

13. Your rights

14. Data retention

On-device data is retained until you delete it in the app, uninstall the app, or clear it from your device's app settings - we cannot delete it for you, and we cannot recover it for you. Analytics data is retained by Google under the retention window configured for our Firebase project; purchase records are retained by RevenueCat and by Apple or Google for as long as needed to honour restores and to meet tax and accounting obligations.

15. Not a medical device

Cardiomate is not a medical device. It records numbers you enter or import and presents them back to you; it does not diagnose, treat, or give medical advice. Category labels and averages are informational and follow general published guidance, not a judgement about you. Always consult a qualified healthcare professional about your blood pressure, and never change or stop medication based on what this app shows. See the Terms of Use.

16. Changes to this policy

We may update this policy as Cardiomate evolves. Material changes will be reflected here with an updated "Effective" date above, and the app will ask you to review and accept the new version on next launch. Continuing to use the app after a change means you accept the updated policy.

17. Contact

Questions or requests about this policy: [email protected]. A human reads every message.