CARDIOMATE
Privacy Policy.
1. Who we are
Cardiomate is published by CodeEnsis Ltd. ("we", "our", "us"), the data controller for the limited data described below. This policy explains what the app stores on your device, what leaves your device and to whom, and what rights you have. Questions or requests: [email protected].
2. What Cardiomate stores on your device
The following lives only in the app's private storage on your phone. It is never uploaded to CodeEnsis, never sold, and never used to target advertising:
- Your blood pressure readings - systolic and diastolic values, pulse, and the date and time of each entry.
- Notes you attach to a reading.
- Optional context tags - which arm you used, your posture, whether the reading was taken around a medication dose, and your activity state.
- Derived figures the app calculates from the above, such as mean arterial pressure, pulse pressure, and morning / evening averages.
- Reminder settings - the times and cadence of your measurement reminders.
- App preferences such as units, theme, onboarding state, and whether the biometric lock is on.
- Your record of accepting these documents, with the version and app build at the time.
If you uninstall Cardiomate, all of this is removed with the app. There is no server-side copy of your health data, because we never receive it.
3. What we never do with your health data
- No account. We never ask for your real name, email address, phone number, date of birth, password, or a social login.
- No ads. Cardiomate contains no advertising SDK, requests no advertising identifier, and shows no ads. Your health data could not be used for ad targeting even in principle, because no advertising code exists in the app.
- No sale or sharing. We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are used under California and comparable laws.
- No readings in analytics. Your systolic, diastolic, and pulse values, your notes, and your context tag choices are never sent to Firebase or any other third party. See section 5 for exactly what is sent.
- No unnecessary permissions. Cardiomate does not request contacts, microphone, camera, photo library, or location of any kind.
4. Apple Health and Android Health Connect
Cardiomate can synchronise readings with Apple Health (iOS) or Health Connect (Android). This is off by default and does nothing until you enable it in Settings → Health sync.
Reading and writing are deliberately separate, and you grant them independently - writing your own numbers out never requires handing over read access to the rest of your health record:
- Write (optional). When enabled, readings you save in Cardiomate are written to your health store as blood pressure records, so they appear alongside the rest of your health data.
- Read (optional). When enabled, Cardiomate imports blood pressure records - and the heart rate that cuffs record alongside them - written by other sources, such as a Bluetooth cuff, a watch, or another app, so you do not have to type them in twice.
This exchange happens entirely on your device, between Cardiomate and the operating system's health store. No health data is transmitted to CodeEnsis or to any third party as part of the sync, and health data obtained this way is used only to display, chart, and export your history inside the app. It is never used for advertising, never shared with data brokers, never used for analytics, and never transferred to anyone else. You can revoke either permission at any time in iOS Settings → Health or in Health Connect, and turn the feature off inside Cardiomate.
5. Analytics (Google Firebase)
To understand which features are worth keeping and where people get stuck, Cardiomate includes Google Firebase Analytics. It receives events describing that something happened, never what your health data says - for example: a screen was opened, a reading was saved (with flags for whether a pulse, a note, or a context tag was filled in, but not their values), an export was run, the paywall was shown, or a purchase was restored. It also receives limited technical data such as your app and OS version, device model, coarse IP-derived region, and a resettable app-instance identifier that Google generates.
Firebase Analytics never receives your systolic or diastolic values, your pulse, your notes, your context tag values, or anything imported from Apple Health or Health Connect. Google processes this data as our service provider under the Google Privacy Policy.
Analytics collection starts only after you accept this policy and the Terms of Use on first launch. Cardiomate contains no crash-reporting SDK and no advertising SDK.
6. Purchases (RevenueCat, Apple, Google)
Cardiomate Pro is a one-time purchase - there is no subscription. Payment is handled entirely by Apple or Google; we never see your card, billing address, or any payment credential.
To validate the receipt and let you restore your purchase on a new device, purchase events are processed by RevenueCat, Inc. acting as our service provider. RevenueCat receives the store receipt, the product identifier, your country and platform, a randomly generated anonymous user identifier that we create on your device, and technical device data. It does not receive your name, email address, or any of your health data. RevenueCat's handling is described in the RevenueCat Privacy Policy; Apple and Google handle the transaction itself under their own policies.
7. Exporting and sharing your data
You can export your history as a CSV file or a PDF report from within the app. The file is generated on your device. When you choose to share or save it, your device's standard share sheet hands it to whatever destination you pick - email, a messaging app, cloud storage, your doctor. That action, and where the file goes, is entirely under your control; CodeEnsis is not involved and never receives a copy. Once a file leaves the app it is governed by the privacy practices of wherever you sent it.
8. Reminders and notifications
If you enable measurement reminders, Cardiomate schedules local notifications on your device at the times you choose. They are generated on-device; there are no push servers, no remote message content, and nothing about your readings is included in a reminder. You can turn reminders off in the app or revoke the notification permission in your system settings at any time.
9. Biometric lock
You can require Face ID, Touch ID, or your Android biometric to open the app. The check is performed by the operating system, which returns only a success or failure. Your fingerprint or face data never leaves the secure hardware on your device, is never accessible to Cardiomate, and is never transmitted anywhere.
10. Permissions Cardiomate asks for
- Health data (optional) -
READ_BLOOD_PRESSURE,WRITE_BLOOD_PRESSURE, andREAD_HEART_RATEon Android; the equivalent HealthKit read and write scopes on iOS. Requested only when you enable Health sync, and only for the purposes in section 4. - Notifications (optional) - to deliver the measurement reminders you schedule. Local only.
- Exact alarms (Android, where applicable) - so a reminder fires at the time you set rather than being deferred by the system. Used only for reminders.
- Biometric (optional) - to unlock the app, if you turn on the biometric lock.
- Internet / network access - for the analytics in section 5, the purchase validation in section 6, and loading this policy. Your readings are never sent over the network by the app.
11. Legal bases (EEA and UK)
Where the GDPR applies: health data is processed solely on your device under your explicit consent, given when you enable Health sync, and we are not a recipient of it. Analytics and purchase-validation data are processed on the basis of your consent, given when you accept this policy on first launch, and our legitimate interest in operating and improving the app and in preventing purchase fraud. You may withdraw consent at any time by revoking the relevant permission or uninstalling the app.
12. Children
Cardiomate is a general-audience health tool intended for adults and is not directed at children under 13 (or under 16 where local law sets that threshold). We do not knowingly collect personal data from children. If you believe a child has provided us with data, write to [email protected] and we will address it.
13. Your rights
- Access / portability: All of your data is visible to you directly inside the app and can be exported to CSV or PDF at any time (section 7).
- Deletion: Delete individual readings in the app, or uninstall Cardiomate to remove everything stored locally. There is no server-side health profile for us to delete, because we never had one.
- Health sync: Revoke read and write access independently in iOS Settings → Health or in Health Connect. Data already written to your health store belongs to you and is managed there.
- Data held by our providers: For the limited analytics and purchase data described above, you can exercise your rights with Google and RevenueCat under their policies, or write to us and we will pass the request on.
- Complaints: If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority.
- Contact: [email protected] - a human reads every message.
14. Data retention
On-device data is retained until you delete it in the app, uninstall the app, or clear it from your device's app settings - we cannot delete it for you, and we cannot recover it for you. Analytics data is retained by Google under the retention window configured for our Firebase project; purchase records are retained by RevenueCat and by Apple or Google for as long as needed to honour restores and to meet tax and accounting obligations.
15. Not a medical device
Cardiomate is not a medical device. It records numbers you enter or import and presents them back to you; it does not diagnose, treat, or give medical advice. Category labels and averages are informational and follow general published guidance, not a judgement about you. Always consult a qualified healthcare professional about your blood pressure, and never change or stop medication based on what this app shows. See the Terms of Use.
16. Changes to this policy
We may update this policy as Cardiomate evolves. Material changes will be reflected here with an updated "Effective" date above, and the app will ask you to review and accept the new version on next launch. Continuing to use the app after a change means you accept the updated policy.
17. Contact
Questions or requests about this policy: [email protected]. A human reads every message.