Skip to content
Kvit

Who can see your cycle entries

The Kvit editorsPublished 7 min

Not "we care about your privacy" but a list: you, us, Supabase, Qonversion, Apple and Google — who sees what, and how long it is kept.

Five rounded rectangles nested inside one another, each outer layer softer than the one it holds

In short

  • A useful privacy answer is a list of parties with each one’s level of access, not a statement of respect for privacy.
  • You see the entries in full. The ones that stayed on the phone we do not see: the local database key never leaves the device. The ones uploaded to the cloud copy we can technically see, because its key is ours. The database is kept out of your phone’s system backups too.
  • Supabase (EU, Ireland) acts as a processor on our instructions and sees only metadata; Qonversion sees subscription status and receives no health data.
  • Every retention period is named with its reason: the cloud copy lasts while the account does, a deleted entry up to 90 days, feedback 90 days.
  • The app does run analytics — Google Analytics, measuring which screens get used. It does not see the contents of entries: those are encrypted with a key that stays on the phone.

A list, not a promise

The most useful answer to this question is not "we care about your privacy" but a list: who exactly sees what, and under what circumstances. Below is that list, and every line of it can be checked against the privacy policy rather than only against this article.

The format is deliberate. "We respect your privacy" is a sentence that can be neither confirmed nor contradicted. "Supabase sees the time an entry changed, but not its contents" can be: it either matches the architecture or it does not.

You

Fully. The local database on the phone is encrypted, but the key sits in the secure storage of your device specifically — which means the app opens your entries for you and for nobody else.

If you have turned on a PIN, one more layer is added: without it the app will not open even on an unlocked phone. That protects you not from the server but from the situation where the phone spends a few minutes in someone else's hands.

Us

It depends where the entry is. One that stayed on the phone only — no: the local database key lives on your device and is not known to us. One that went to the cloud copy — yes: it is encrypted on the phone before anything goes to the network, but the key to that ciphertext is kept by us. We do have technical access to uploaded entries, and that is exactly why the copy can hand them back to you on a new phone by itself.

What we do see, if you have turned on the cloud copy:

  • the time each entry was last changed;
  • how many of them there are;
  • whether you have turned on PIN or biometric entry.

The presence of a file in the journal photo storage reveals the fact that you keep a pregnancy journal — the contents stay ciphertext.

And one more thing that belongs on this list even though it is not metadata: the text of your feedback. If you send feedback from the app it arrives in the clear and we read it — unlike your entries, it is not encrypted. That is why the form deliberately collects neither the app mode nor the screen you write from, and why we ask you not to put health details in it. Kept for 90 days, then deleted automatically.

This is what gets called metadata, and it is usually the part left unsaid. We say it, because a list with something missing is worse than no list at all: it creates an impression of completeness.

Supabase

Database, file storage and authentication. The project is hosted in the European Union, Ireland region. Supabase sees exactly what is described above, and acts as a processor on our instructions — not as a controller in its own right.

The difference between "processor" and "controller" is not a formality here — they are two distinct statuses under the GDPR, and the policy uses exactly those words. A processor may only do with the data what a contract instructs, and has no right to use it for itself. A controller has its own grounds and its own purposes — and that is precisely how advertising networks are described in most apps.

Qonversion

Determines whether your Kvit+ subscription is active. Receives technical identifiers and purchase data. Receives no health data.

This is the classic leak point in health apps: the subscription service gets embedded in a way that also lets it see events inside the app. Here the line is drawn along one edge — subscriptions on one side, entries on the other.

Apple and Google

Handle payment and manage the subscription. For those operations they act as independent controllers, under their own policies: we do not see your card number, and they do not see your entries.

Google (Firebase) and Cloudflare

These two are on the list not because they see much, but because the list has to be complete.

Google (Firebase) — a library in the app, needed for two things. The first is notifications: when they are on, Google receives a technical installation identifier and a device token in order to deliver them. The second is Google Analytics: the app sends events about which screens get used, so that we can see what works and what does not. Neither of the two sees the contents of your entries — those are encrypted with a key that stays on the phone.

Cloudflare — hosts the pages on kvitcare.com: this article, the policy, the terms, the deletion page. It sees your IP address and technical request data when you open the site — and nothing from the app.

Who sees nothing at all

This list is shorter but more important, because in most apps this is exactly where you find lines that should not be there:

  • advertising networks — there are none in the app;
  • data brokers — data is neither sold nor shared;
  • insurers, employers, any third party — the data does not reach them, because it does not go anywhere beyond the list above.

Analytics is no longer on this list, and that is a deliberate correction: the app uses Google Analytics — it is named above, together with what it actually sees. The contents of your entries are not among them.

Your phone and system backups

A question people ask often: do the entries end up in a backup of the phone, where Apple's and Google's rules apply rather than ours?

No. The local database sits in the app's sandbox, so other apps on the phone cannot reach it — and it is deliberately kept out of system backups: on iOS the database files are marked as excluded from iCloud, and on Android the app does not take part in backup at all. That is written into section 3.1 of the policy, not only here.

So a backup of your phone to iCloud or Google One does not carry your entries with it. What it does take from the phone otherwise is between you and Apple or Google, and it is settled in the system settings. But the entries are not in it.

How long it lives

  • Entries on the phone — until you delete them or delete the app.
  • The cloud copy — as long as the account exists. A deleted entry disappears from the app immediately and is permanently erased from the server within 90 days at the latest: that window exists so the deletion reaches your other devices.
  • Feedback text — 90 days, then deleted automatically.
  • The account — until you delete it.

There are no "just in case" retention periods. Every period on the list has a reason, and the reason is named next to it.

What you can do right now

GDPR rights sound abstract until someone says which button implements them. Here are the buttons.

  • Take your data with you. Export runs from the app, and it has to: entries that never left the phone can be turned back into readable text only there, with the key your device holds.
  • Delete everything. The account deletion page works without installing the app — that is exactly why it exists separately.
  • Turn the cloud off. The cloud copy is optional. Without it the app works fully, not even metadata is left on the server — and the key to your entries exists only on your phone.
  • Ask. Requests about your own data go to contact@kvitcare.com — access, correction, export, deletion — and are answered within the month Article 12(3) GDPR allows. Anything else about the app goes to support@kvitcare.com.

What does not happen

This is a list too, not a mood:

  • your entries are not part of the analytics — it measures use of the app, not what you wrote in it;
  • there is no advertising and there are no advertising libraries;
  • data is not sold and not passed to data brokers;
  • there are no automated decisions with legal effect concerning you — a cycle forecast is information for you, not a decision about you.

One line we removed

An earlier revision of the policy had a clause about "anonymised analytics". It was removed, and the policy itself says why: it was not true.

We leave that in the document rather than quietly rewriting history. A policy that never contained a mistake is easy to write — which is exactly why it is worth nothing. A document that shows its own correction gives you what a flawless one cannot: a way to check that anyone rereads it at all.

This article has just done the same. It used to state that the app runs no analytics at all; that stopped being true, and the line was corrected rather than quietly dropped. The analytics is named above — together with what it does not see.

How to check the same thing in another app

Three actions, a few minutes each:

  1. 1.Open the privacy policy and look for the list of third parties. If instead of names it says "our partners" or "affiliates", the list is open-ended and someone can be added to it without your knowledge.
  2. 2.Find what it says about retention. "For as long as necessary" means indefinitely.
  3. 3.See whether it describes what is visible on the server. If metadata is not mentioned at all, that does not mean there is none.

For the architecture rather than the list, see Is it safe to track your cycle in an app.

Frequently asked

Which third parties receive data from the Kvit app?

Five, and section 4 of the policy names all of them: Supabase (database, storage and authentication; EU, Ireland region — sees only metadata), Qonversion (subscription status, no health data), Apple and Google (payment, subscription management and sign-in), Google (Firebase) (technical installation identifiers and notification delivery) and Cloudflare (hosting for the kvitcare.com pages — it sees your IP address, and nothing from the app).

Does Kvit run analytics?

Yes — in the app and on the website both, but in neither place does it see your entries. In the app it is Google Analytics: it measures which screens get used; the contents of entries are not part of that, because they are encrypted with a key that stays on the phone. There is no advertising and there are no advertising libraries, and data is neither sold nor passed to data brokers. On the kvitcare.com website every page runs a Cloudflare visit counter: it counts page views, but it sets no cookie, stores nothing in your browser and does not recognise you on other sites — which is exactly why it asks for no consent. Analytics that does require consent may load on the landing page and the blog only, and only after you explicitly allow it; the privacy, terms and account-deletion pages will never load it.

How long does Kvit keep my data?

Entries on the phone last until you delete them or delete the app. The cloud copy lasts as long as the account; a deleted entry disappears from the app immediately and is permanently erased from the server within 90 days at the latest, so the deletion reaches your other devices. Feedback is kept for 90 days and then deleted automatically.

How do I export or delete my data?

Export runs from the app, because only your device can decrypt the entries. The account can be deleted from a separate page on the website, without installing the app. The cloud copy can be left off entirely — the app works fully without it, and then not even metadata is left on the server. Requests about your own data — a copy, a correction, deletion — go to contact@kvitcare.com, and are answered within the month Article 12(3) GDPR allows.

Can anyone see my entries through an iCloud or Google One backup?

No. The local database sits in the app’s sandbox, so other apps on the phone cannot reach it — and it is deliberately kept out of system backups: on iOS the database files are marked as excluded from iCloud, and on Android the app does not take part in backup at all. That is written into section 3.1 of the privacy policy, not only in the article.

Read next