Who can see your cycle entries
Not "we care about your privacy" but a list: you, us, Supabase, Qonversion, Apple and Google — who sees what, and how long it is kept.

In short
- A useful privacy answer is a list of parties with each one’s level of access, not a statement of respect for privacy.
- You see the entries in full; we do not see them at all, because the key stays on your device. The database is kept out of your phone’s system backups too.
- Supabase (EU, Ireland) acts as a processor on our instructions and sees only metadata; Qonversion sees subscription status and receives no health data.
- Every retention period is named with its reason: the cloud copy lasts while the account does, a deleted entry up to 90 days, feedback 90 days.
- A clause about "anonymised analytics" was removed from an earlier revision of the policy, and the document itself says why: it was not true.
A list, not a promise
The most useful answer to this question is not "we care about your privacy" but a list: who exactly sees what, and under what circumstances. Below is that list, and every line of it can be checked against the privacy policy rather than only against this article.
The format is deliberate. "We respect your privacy" is a sentence that can be neither confirmed nor contradicted. "Supabase sees the time an entry changed, but not its contents" can be: it either matches the architecture or it does not.
You
Fully. The local database on the phone is encrypted, but the key sits in the secure storage of your device specifically — which means the app opens your entries for you and for nobody else.
If you have turned on a PIN, one more layer is added: without it the app will not open even on an unlocked phone. That protects you not from the server but from the situation where the phone spends a few minutes in someone else's hands.
Us
The entries — no. Not because we promise not to read them, but because we do not have the key: an entry is encrypted on the phone before anything goes to the network.
What we do see, if you have turned on the cloud copy:
- the time each entry was last changed;
- how many of them there are;
- whether you have turned on PIN or biometric entry.
The presence of a file in the journal photo storage reveals the fact that you keep a pregnancy journal — the contents stay ciphertext.
And one more thing that belongs on this list even though it is not metadata: the text of your feedback. If you send feedback from the app it arrives in the clear and we read it — unlike your entries, it is not encrypted. That is why the form deliberately collects neither the app mode nor the screen you write from, and why we ask you not to put health details in it. Kept for 90 days, then deleted automatically.
This is what gets called metadata, and it is usually the part left unsaid. We say it, because a list with something missing is worse than no list at all: it creates an impression of completeness.
Supabase
Database, file storage and authentication. The project is hosted in the European Union, Ireland region. Supabase sees exactly what is described above, and acts as a processor on our instructions — not as a controller in its own right.
The difference between "processor" and "controller" is not a formality here — they are two distinct statuses under the GDPR, and the policy uses exactly those words. A processor may only do with the data what a contract instructs, and has no right to use it for itself. A controller has its own grounds and its own purposes — and that is precisely how advertising networks are described in most apps.
Qonversion
Determines whether your Kvit+ subscription is active. Receives technical identifiers and purchase data. Receives no health data.
This is the classic leak point in health apps: the subscription service gets embedded in a way that also lets it see events inside the app. Here the line is drawn along one edge — subscriptions on one side, entries on the other.
Apple and Google
Handle payment and manage the subscription. For those operations they act as independent controllers, under their own policies: we do not see your card number, and they do not see your entries.
Google (Firebase) and Cloudflare
These two are on the list not because they see much, but because the list has to be complete.
Google (Firebase) — a library in the app, needed for notifications. When notifications are on, Google receives a technical installation identifier and a device token in order to deliver them. No health data is involved.
Cloudflare — hosts the pages on kvitcare.com: this article, the policy, the terms, the deletion page. It sees your IP address and technical request data when you open the site — and nothing from the app.
Who sees nothing at all
This list is shorter but more important, because in most apps this is exactly where you find lines that should not be there:
- advertising networks — there are none in the app;
- data brokers — data is neither sold nor shared;
- behavioural analytics services — not a single tool in the app;
- insurers, employers, any third party — the data does not reach them, because it does not go anywhere beyond the list above.
Your phone and system backups
A question people ask often: do the entries end up in a backup of the phone, where Apple's and Google's rules apply rather than ours?
No. The local database sits in the app's sandbox, so other apps on the phone cannot reach it — and it is deliberately kept out of system backups: on iOS the database files are marked as excluded from iCloud, and on Android the app does not take part in backup at all. That is written into section 3.1 of the policy, not only here.
So a backup of your phone to iCloud or Google One does not carry your entries with it. What it does take from the phone otherwise is between you and Apple or Google, and it is settled in the system settings. But the entries are not in it.
How long it lives
- Entries on the phone — until you delete them or delete the app.
- The cloud copy — as long as the account exists. A deleted entry disappears from the app immediately and is permanently erased from the server within 90 days at the latest: that window exists so the deletion reaches your other devices.
- Feedback text — 90 days, then deleted automatically.
- The account — until you delete it.
There are no "just in case" retention periods. Every period on the list has a reason, and the reason is named next to it.
What you can do right now
GDPR rights sound abstract until someone says which button implements them. Here are the buttons.
- Take your data with you. Export runs from the app, and it has to: your device holds the only key, so it is the only thing that can turn your entries back into readable text.
- Delete everything. The account deletion page works without installing the app — that is exactly why it exists separately.
- Turn the cloud off. The cloud copy is optional. Without it the app works fully, and not even metadata is left on the server.
- Ask. support@drivecode.ai is the same address named in the privacy policy as the contact for requests under Article 12(3) GDPR, not a separate mailbox for letters.
What does not happen
This is a list too, not a mood:
- there is no behavioural analytics — neither our own nor anyone else's, not a single tool in the app;
- there is no advertising and there are no advertising libraries;
- data is not sold and not passed to data brokers;
- there is no cross-app or cross-site tracking;
- there are no automated decisions with legal effect concerning you — a cycle forecast is information for you, not a decision about you.
One line we removed
An earlier revision of the policy had a clause about "anonymised analytics". It was removed, and the policy itself says why: it was not true.
We leave that in the document rather than quietly rewriting history. A policy that never contained a mistake is easy to write — which is exactly why it is worth nothing. A document that shows its own correction gives you what a flawless one cannot: a way to check that anyone rereads it at all.
How to check the same thing in another app
Three actions, a few minutes each:
- 1.Open the privacy policy and look for the list of third parties. If instead of names it says "our partners" or "affiliates", the list is open-ended and someone can be added to it without your knowledge.
- 2.Find what it says about retention. "For as long as necessary" means indefinitely.
- 3.See whether it describes what is visible on the server. If metadata is not mentioned at all, that does not mean there is none.
For the architecture rather than the list, see Is it safe to track your cycle in an app.
Frequently asked
Which third parties receive data from the Kvit app?
Five, and section 4 of the policy names all of them: Supabase (database, storage and authentication; EU, Ireland region — sees only metadata), Qonversion (subscription status, no health data), Apple and Google (payment, subscription management and sign-in), Google (Firebase) (technical installation identifiers and notification delivery) and Cloudflare (hosting for the kvitcare.com pages — it sees your IP address, and nothing from the app).
Does Kvit run behavioural analytics?
In the app, no: not a single analytics or crash-reporting tool, neither its own nor anyone else’s. There is no advertising and there are no advertising libraries, data is not sold or passed to data brokers, and there is no cross-app tracking. The kvitcare.com website is a separate matter: the landing page and the blog may load analytics, but only after you explicitly consent, and before that the page makes no third-party request and sets no cookie. The privacy, terms and account-deletion pages never load it at all.
How long does Kvit keep my data?
Entries on the phone last until you delete them or delete the app. The cloud copy lasts as long as the account; a deleted entry disappears from the app immediately and is permanently erased from the server within 90 days at the latest, so the deletion reaches your other devices. Feedback is kept for 90 days and then deleted automatically.
How do I export or delete my data?
Export runs from the app, because only your device can decrypt the entries. The account can be deleted from a separate page on the website, without installing the app. The cloud copy can be left off entirely — the app works fully without it, and then not even metadata is left on the server. GDPR requests go to support@drivecode.ai.
Can anyone see my entries through an iCloud or Google One backup?
No. The local database sits in the app’s sandbox, so other apps on the phone cannot reach it — and it is deliberately kept out of system backups: on iOS the database files are marked as excluded from iCloud, and on Android the app does not take part in backup at all. That is written into section 3.1 of the privacy policy, not only in the article.