Skip to content
Kvit
Language

KVIT PRIVACY POLICY

Revision: 21 August 2026.

This text matches word for word what the app shows. If this page and the app ever diverge, that is a bug and we want to hear about it.

This is a notice under Article 13 of the General Data Protection Regulation (GDPR). It tells you who is responsible for your data, exactly what data Kvit processes, on what legal basis, who it is shared with, how long it is kept and how you can act on it. It also includes what is inconvenient for us: this policy describes the app as it is today, not as we would like to present it.

1. WHO IS RESPONSIBLE FOR YOUR DATA

The controller of your data — that is, whoever decides how and why it is processed — is the publisher of the Kvit app. The publisher registration details appear on the app page in the App Store and Google Play, where it is named as the seller.

Send privacy questions, requests about your rights and complaints to support@drivecode.ai. We answer within one month at the latest — that deadline is set by Article 12(3) GDPR. There is no form to fill in: an email is enough.

2. WHAT KVIT PROCESSES AND ON WHAT BASIS

2.1. Health data — a special category (Article 9 GDPR).

This means period dates and their intensity, symptoms, mood, notes, marks of sexual activity and whether it was protected, pregnancy dates and the estimated due date, weight, pregnancy diary entries and photos, kick counter and contraction timer readings, and postpartum records.

The legal basis is your explicit consent (Article 9(2)(a) GDPR). You give it during onboarding, when you agree to this policy, and you can withdraw it at any time (section 7).

There is exactly one purpose: to show you your own records, calendar and the forecasts built from them. This data is not used for advertising, not sold, and not passed to anyone for their own purposes.

2.2. Account (optional).

Kvit works without signing in. If you sign in with Google or Apple, we receive from them your account identifier and email address — in order to attach your cloud copy to you and give you access to it from another device. We neither see nor store passwords: sign-in happens only through Google or Apple, and Kvit has no separate password registration.

The legal basis is performance of a contract with you (Article 6(1)(b) GDPR).

2.3. The Kvit+ subscription.

Payment is handled by the App Store or Google Play — we never see or store your card details. To know whether your subscription is active we use the Qonversion service (a processor). It receives exactly three things: your store purchase history, your app and device identifier, and technical device data (model, system version, screen resolution).

This data exists solely to unlock Kvit+ for you and to show the state of the subscription. We collect no advertising identifiers and do not use this data for ad tracking. No health data enters this path at all.

The legal basis is performance of a contract (Article 6(1)(b) GDPR).

2.4. Date of birth (optional).

You can enter it during onboarding or in your Profile. We need it for two things: so that cycle guidance takes your age into account (cycle norms depend on it) and so we can greet you on your day. Nothing else: it unlocks nothing and restricts nothing in the app. It is stored on your device, and it reaches the cloud copy (if you enable one) only as ciphertext — we cannot see it. You can change or remove it at any time: Profile → Date of birth → «Prefer not to say». The legal basis is your consent (Article 6(1)(a) GDPR).

2.5. In-app feedback.

If you send feedback, what reaches our server is: a rating from 1 to 5, your text in the clear, a flag for whether we may reply, and technical data — app version and build number, platform, system version, interface language. Your text is read by the Kvit team — unlike your records, it is not encrypted.

The form deliberately collects neither the app mode nor the screen you write from: «pregnancy» is already a fact about your health. For the same reason we ask you not to put health data in feedback, and we repeat that request here.

No separate copy of your email address is kept with the feedback — if you allowed a reply, we write to your account address.

The legal basis is your consent, given by the act of sending (Article 6(1)(a) GDPR). Feedback is deleted automatically after 90 days.

2.6. App version check.

On launch Kvit reads three things from our server — the minimum and recommended build version and a link to the app page in the store — in order to show you an update banner. This is a one-way read: the app sends no data about you and no identifier while doing it, and if the server is unreachable the banner simply does not appear.

The legal basis is our legitimate interest in not leaving you on a build with a known defect (Article 6(1)(f) GDPR).

2.7. Platform technical identifiers (Google Firebase).

The Google Firebase library is linked into the app — it is needed for community notifications, once those work. Automatic data collection by this library is disabled on both platforms, so in this version of Kvit it should not send Google an app installation identifier.

When the community is switched on and you allow notifications, Google will receive a technical identifier of your installation and a device token — in order to deliver the notification. They contain no health data, and never will.

2.8. Inviting a friend.

If you use the referral programme, the server stores your invitation code, the fact that another account used it, and the bonus awarded. These are account identifiers with no health data whatsoever. Another participant cannot see whose code it is.

The legal basis is performance of a contract (Article 6(1)(b) GDPR).

2.9. Community.

There is no community in this version of the app: the section is switched off, no posts or comments exist, and none of your data is processed for a community. When the community arrives we will update this policy and ask for separate consent before your first post.

3. WHERE THIS DATA SITS AND WHAT EXACTLY IS ENCRYPTED

3.1. On your phone.

All records are created and stay on the device. The database file is encrypted in full (AES-256, with the key held in the system secure store — Keychain on iOS, Keystore on Android). That covers every record in it: period dates and their intensity, marks of sexual activity and protection, pregnancy dates and the app mode.

Some fields — notes, mood, symptoms, custom symptoms, pregnancy diary entries and photos, medical records — have ADDITIONAL encryption of their own on top of that: it is in exactly that form that they travel to the cloud copy, so the server cannot read them.

The key never leaves your device and is not known to us.

In addition to encryption: entry by PIN or biometrics, if you enable it. And the database does not enter system backups — on iOS the database files are marked as excluded from iCloud, and on Android the app does not take part in backup at all.

3.2. The cloud copy (optional).

If you have signed in and enabled the cloud copy, your records are uploaded as ciphertext only. The server stores an opaque blob: it can see neither the content nor the field names. The key stays on your device; a recovery key is stored in an «envelope» encrypted with your passphrase or code, which we do not know either. If you lose both, we cannot restore your data — that is the price of not being able to read it.

4. WHO WE SHARE DATA WITH

Kvit has no servers of its own, so we use providers. We name them:

  • Supabase — database, file storage and authentication. The project is hosted in the European Union, Ireland region. Supabase sees only what is described in section 3.2 and acts as a processor on our instructions.
  • Qonversion — determines whether your Kvit+ subscription is active. It receives technical identifiers and purchase data (section 2.3). It receives no health data.
  • Apple (App Store) and Google (Google Play) — handle payment and manage the subscription. For those operations they act as independent controllers under their own privacy policies.
  • Google (Firebase) — technical installation identifiers and notification delivery, when notifications are on (section 2.7).
  • Google and Apple — if you sign in through them, they process the sign-in itself under their own policies.
  • Cloudflare — hosting for the pages on kvitcare.com (this policy, the terms of use, account deletion). It receives your IP address and technical request data when you open those pages, and nothing from the app.

None of them holds the key to your records. We pass nothing to ad networks or data brokers — Kvit simply has none.

5. TRANSFERS OUTSIDE THE EUROPEAN UNION

Cloud copy data is stored in the EU — Ireland region. The providers in section 4 are US companies, so administration and technical support may take place from outside the European Economic Area. We cover such transfers with the European Commission standard contractual clauses (Article 46(2)(c) GDPR) and data processing agreements with each provider.

What matters in practice is this: your records travel as ciphertext, so access to their content during such a transfer is impossible regardless of any contract.

6. HOW LONG WE KEEP IT

  • Records on the phone — until you delete them or delete the app.
  • The cloud copy — as long as your account exists. A deleted record disappears from the app immediately and is erased from the server permanently within 90 days at the latest (that period is needed for the deletion to reach your other devices).
  • Feedback — 90 days, then deleted automatically.
  • Referral data — as long as the account exists; deleted with it.
  • The account — until you delete it.

We keep no «just in case» periods: we do not store data that is no longer needed for the purpose described here.

7. YOUR RIGHTS AND HOW TO USE THEM

You have the right to: learn what data of yours we process and receive a copy of it (Article 15); correct inaccurate data (Article 16); delete it (Article 17); restrict processing (Article 18); receive the data in a machine-readable form and port it (Article 20); object to processing (Article 21); withdraw consent at any time (Article 7(3)) — withdrawal does not make processing that happened before it unlawful.

You exercise most of these rights yourself, without contacting us: records are edited and deleted where you created them; «More» → «Privacy and data» → «Delete all data» erases everything (section 8); the doctor report produces a copy of your records. For the rest, write to support@drivecode.ai.

One limit is worth knowing in advance: we cannot read your health records, so we can neither send you a copy of them from our side nor correct them at your request. Only your phone has access to them — which is precisely why these rights are exercised in the app rather than through us. In readable form we hold only your account, your subscription state and your feedback — for those, come to us.

If you believe we have infringed your rights, you may lodge a complaint with the data protection supervisory authority in your country of residence (the list of authorities is on the European Data Protection Board site, edpb.europa.eu). We would be grateful if you wrote to us first — it is faster.

8. HOW TO DELETE EVERYTHING

«More» → «Privacy and data» → «Delete all data». One action: it erases the local app database and, if you signed in, deletes the account itself together with the cloud copy, the recovery key, your feedback and referral data. This is also how you withdraw consent to health data processing entirely.

The action is irreversible: we cannot undo it, because afterwards nothing remains with us that could be restored. Deleting the app from your phone removes local data but does not delete the account — for that, use the button above before deleting the app.

9. WHAT KVIT DOES NOT DO

  • It collects no analytics of your behaviour. The app contains no analytics or crash-reporting tool at all — neither our own nor a third party one. A previous revision of this policy contained a line about «anonymised analytics»; it was untrue and has been removed.
  • It shows no advertising and contains no advertising libraries.
  • It does not sell your data or pass it to data brokers.
  • It does not track you across apps and sites.
  • It takes no automated decisions about you with legal consequences (Article 22 GDPR). Cycle forecasts are information for you, not a decision about you, and they come with a confidence level.
  • It is not a medical device, does not diagnose and is not a method of contraception — see the medical disclaimer.

10. AGE

Kvit is intended for people aged 16 and over — you confirm this during onboarding. We deliberately do not process data of younger children. If you believe a child has used the app, write to support@drivecode.ai and we will delete the data.

11. CHANGES TO THIS POLICY

If we change the policy, the new revision will appear in the app with a new revision date at the top. We will announce material changes concerning your health data in the app and ask for consent again — rather than assuming you agreed by saying nothing.

12. THE LANGUAGE OF THIS POLICY

We publish this policy and the Terms of Service in Ukrainian, English and Polish. In case of any discrepancy between the versions, the Ukrainian version prevails — it is the original, and the others are translations. This does not limit your right to contact us in any of the three languages: we will reply in the one you wrote in.

Back to top