← Back to Cardia

Cardia — Privacy

Last updated: May 2026

I'm an indie dev. I make Cardia alone (under the name Koirala Studio), and I don't want your data. This page exists because Apple and various privacy laws want one, and because if you're going to install my app you deserve to know what it does.

Short version

Cardia doesn't collect anything personal about you. It runs on your iPhone. There's no account. There's no cloud sync. There's no server I run that holds your data. Anything you put into the app stays on your device.

What stays on your device

Cardia stores your profile (date of birth and the motivations you pick during onboarding), every resting-HR and heart-rate-recovery reading you take (including timestamps, captured values, and the context Cardia uses to show trends and baseline progress), estimated fitness-age snapshots (early and stable), your baseline checklist state, active and completed goals, weekly activity-checklist entries, reminder preferences, and whether Cardia Premium is active. Small preferences live in iOS UserDefaults — theme, onboarding completion, notification settings. Everything stays in Cardia's sandboxed on-device storage on your iPhone; I don't run a server that holds it.

Delete the app and that data is gone. iPhone backups (iCloud or local) may include it, but that's Apple's backup, not mine.

What I don't collect

I don't sell data to anyone because there's no data to sell.

Permissions Cardia asks for

Cardia asks for two permissions, each only when the feature needs it:

You can turn any of these off anytime in iOS Settings → Privacy & Security, or in Settings → Cardia.

Third-party services

Cardia uses Google Firebase Analytics to understand how the app is used — things like which screens you open, button taps, and basic device info (OS version, app version). It doesn't get your heart-rate readings, fitness-age estimates, goals, or profile. I don't attach your name or email. Firebase may assign an installation ID on Google's side. This helps me spot broken flows and decide what to improve. See Google's privacy notice at policies.google.com/privacy and Firebase's at firebase.google.com/support/privacy.

If you subscribe to Cardia Premium, RevenueCat handles subscription purchases and entitlement tracking. RevenueCat receives an anonymous identifier (a random UUID not tied to your name, email, or personal iOS identifier) and the purchase event from Apple's StoreKit. See RevenueCat's privacy notice at revenuecat.com/privacy.

Apart from Firebase Analytics and RevenueCat (subscribers only): your readings, estimates, goals, and profile never leave your device for analysis or storage. Pulse detection runs on your iPhone; nothing is sent to a wellness or health API.

What Apple sees on its own

When you download Cardia, Apple processes your App Store account, the download itself, and any crash reports you choose to share. That's Apple's deal — see apple.com/legal/privacy. I might see aggregate numbers (total installs, anonymized crash stacks if you opted in), but never anything tied to you personally.

Your rights, briefly

Privacy laws give you the right to know what someone's holding about you, to ask them to fix or delete it, and to complain if they refuse. Email support@koirala.studio and I'll respond within 30 days. (For Cardia specifically the answer is almost always "I don't hold any data about you" — but I'll confirm it for you in writing.)

Kids

Cardia isn't designed for or directed at children under 13. It's a wellness tool for adults tracking trends over time — not for kids, and not a substitute for medical care. The app doesn't connect to a server I run; I don't receive your readings or date of birth. If a parent believes a child under 13 used Cardia and wants help, email support@koirala.studio — I'll explain what's stored on the device and that deleting the app removes local data.

If this policy changes

I'll update the date at the top and surface a notice in Cardia for anything material.

Contact

Koirala Studio · Ontario, Canada
support@koirala.studio