Privacy Policy
HivRa does not sell your data or use it for advertising. All data collected is used solely to provide the features of the app -personalised meal recommendations, workout tracking, grocery list sharing, and AI-assisted suggestions.
1. Overview
HivRa is a personal wellness application that helps users track meals, workouts, nutrition, and grocery lists. This Privacy Policy explains what data we collect, why we collect it, how it is stored, and your rights regarding that data. By creating an account and using HivRa, you agree to the practices described in this policy.
2. Data We Collect
- Account Credentials -Your email address and password are stored via Firebase Authentication. Your password is never stored in plain text -it is managed entirely by Firebase's secure authentication infrastructure. Your email is used for login and for grocery list sharing only.
- Profile Data -When you set up your profile, you provide age, height, weight, sex, and fitness goal. This information is used solely to calculate your estimated daily calorie needs (TDEE) and personalise meal and workout recommendations. This data is stored in Google Firestore under your user account.
- Health and Fitness Data -HivRa reads step count, active calories burned, and heart rate from Apple HealthKit with your explicit permission. This data is used to inform workout summaries and AI meal recommendations. It is never stored on our servers -it is read from HealthKit at the time of use only. Workout sessions you log manually -exercises, sets, reps, weight, and session intensity rating -are stored in Firestore under your account.
- Nutrition and Meal Data -Meal logs, recipes you create or save, meal plans, and custom food entries are stored in Firestore under your account.
- Grocery List Data -Grocery lists you create, including item names and checked status, are stored in Firestore. If you share a list, your email address is visible to users you invite, and their email is visible to you.
- Usage Data -Workout streak history and planning day patterns (used to calculate your smart reminder day) are stored locally on your device via Core Data. Planning pattern data is not uploaded to our servers.
- AI Recommendation Context -When you request an AI meal recommendation, HivRa sends the following to our backend server: your fitness goal, estimated TDEE, remaining daily macros, workout intensity, and meal type preference. No personally identifiable information -including your name, email, or exact profile data -is transmitted to the AI provider.
3. How We Use Your Data
All data collected by HivRa is used exclusively to provide the features of the app. Specifically:
- Account credentials are used for authentication and account management
- Profile data is used to personalise calorie targets and recommendations
- HealthKit data is used to enrich workout summaries and AI meal context
- Workout and nutrition data is used to track progress and inform recovery suggestions
- Grocery list data is used to power shared list functionality
- Usage patterns are used to schedule smart reminders
We do not use your data for advertising. We do not sell your data to third parties. We do not use your data to build advertising profiles.
4. Third-Party Services
- Google Firebase -Account credentials and app data are stored in Google Firebase infrastructure (Authentication and Firestore). Firebase is subject to Google's privacy policy at policies.google.com/privacy.
- Groq API -Anonymised meal context is processed by the Groq API using the Llama language model. Only non-identifiable nutritional context is transmitted. Groq's privacy policy is available at groq.com/privacy-policy.
- Render -Our backend server is hosted on Render. Render processes requests between the app and the Groq API. No user data is stored on Render servers beyond the duration of a single request.
- Apple HealthKit -HealthKit data is accessed under Apple's HealthKit framework terms. HealthKit data is never used for advertising, never shared with third parties beyond what is described in this policy, and never sold.
5. Data Sharing
Your data is not shared with third parties except as described in Section 4. The only case where your data is visible to another user is grocery list sharing: when you invite someone to a shared list, they can see the list name, items, and your email address. You control who you invite.
6. Data Retention
Your data is retained as long as your account exists. If you delete your account, all data associated with your account -including profile data, workout history, meal plans, recipes, and grocery lists -is permanently deleted from Firestore and Firebase Authentication. Deletion is irreversible.
Local data stored on your device via Core Data is removed when you uninstall the app.
7. Your Rights
You have the right to:
- Access the data stored under your account by contacting hivrasupport@gmail.com
- Request correction of inaccurate data
- Request deletion of your account and all associated data via Profile → Settings → Delete Account
- Withdraw HealthKit permission at any time via iOS Settings → Privacy → Health → HivRa
- Withdraw notification permission at any time via iOS Settings → Notifications → HivRa
8. Children's Privacy
HivRa is intended for users 16 years of age and older. We do not permit users under 16 to create accounts. Date of birth is collected during onboarding solely to verify age eligibility and calculate personalized wellness metrics. If you believe a user under 16 has created an account, contact us at hivrasupport@gmail.com and we will delete the account.
9. Data Security
We use industry-standard security measures including Firebase Authentication token verification on all API requests, server-side per-user rate limiting enforced via Firestore transactions, and HTTPS encryption for all data in transit. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy. For significant changes, we will make reasonable efforts to notify users.
11. Contact
For privacy questions, data requests, or concerns: hivrasupport@gmail.com