Privacy Policy
Thyrivo is designed so that information about your health never leaves your iPhone. This policy explains exactly what data is created, where it is stored and what your rights are.
Effective: 8 October 2026
1. Who is responsible
The controller for the processing described in this policy is Nazwa firmy / imię i nazwisko przedsiębiorcy, Adres siedziby, tax ID NIP, REGON / KRS lub wpis do CEIDG ("we").
For privacy matters, write to privacy@thyrivo.com. For anything else: support@thyrivo.com.
2. In short
- You do not create an account and do not give us your name, email address or phone number.
- Everything you enter in the app (medications, dose labels, journal, lab results, weight, check-ups) is stored only on your device.
- We have no server to which the app sends your data, so we have no access to your entries.
- We use no analytics, ads, trackers or third-party SDKs that collect data.
- Data leaves your phone only when you choose, for example when you save a backup or share a PDF report.
3. Data in the app
The app stores, locally, the data you enter: medication names and dose labels, reminder schedules, whether a dose was taken or skipped, wellbeing journal entries (energy, mood, symptoms, notes), lab results with ranges you copy from your report, weight, check-up dates, lesson progress, and settings such as your condition and weight unit.
Some of this is health data. You process it yourself, on your own device, for your own purposes. We do not receive, store or analyse it.
The data is kept in the app's database on your device, in a container shared only between Thyrivo and its widgets (App Group) so that a widget can show and mark a dose. It is protected by your iPhone's encryption and passcode.
Device data may be included in iCloud or computer backups if you have enabled them in iPhone settings. Apple creates and stores such backups under your agreement with Apple.
4. Apple system features
- Notifications. Medication, check-up and trial-ending reminders are scheduled locally on your phone. We do not send server push notifications.
- Widgets and Live Activities. They show data from your device on the Home Screen, Lock Screen and Dynamic Island. People who can see your screen may see this content.
- Siri and Shortcuts. If you use a voice command, Apple handles speech recognition under its own privacy policy. The app carries out the command locally.
- Apple Health (optional, Thyrivo Pro). With your permission the app reads body weight from Health and, if you switch it on, writes weight entered in Thyrivo to Health. Data from Apple Health is never shared with us or anyone else, is not used for advertising or profiling, and is used only to show it in the app. You can revoke access at any time in the Health app.
5. Backups, export and reports
A backup is a file you create yourself in Settings and save wherever you choose, for example in iCloud Drive. It contains all your app data and is not additionally encrypted by Thyrivo. Keep it somewhere safe; in iCloud Drive it is protected by your Apple Account, and end-to-end if Advanced Data Protection is turned on.
The PDF visit report is created on your phone. You decide whether and with whom to share it.
6. Subscription and payments
You buy Thyrivo Pro in the App Store. Apple handles payment and billing details; we do not receive your payment information or personal data.
The app checks on your device, using Apple mechanisms (StoreKit), whether you have an active subscription. Apple provides us with aggregated, non-identifying sales reports in App Store Connect.
7. Contacting us
If you email us, we process your email address and the content of your message to reply. The legal basis is our legitimate interest in handling enquiries (Art. 6(1)(f) GDPR) and, for subscription matters, the performance of a contract (Art. 6(1)(b) GDPR). We keep correspondence for up to 2 years after the matter is closed unless longer retention is needed to defend legal claims.
Please do not send us health information. A description of the steps and the app version are usually enough to solve a technical issue.
8. The thyrivo.com website
The website uses no cookies, analytics or third-party scripts. The hosting provider may briefly keep technical server logs (e.g. IP address, date, page address, browser type) to keep the service secure and running, based on our legitimate interest.
9. Recipients and transfers
Data we process (email correspondence, website logs) may be accessible to our service providers for email and hosting, acting on our behalf. If any of them processes data outside the European Economic Area, we rely on GDPR safeguards such as standard contractual clauses or an adequacy decision.
We do not sell data or share it for marketing.
10. Your rights
For data we process, you have the right of access, rectification, erasure, restriction, portability and the right to object to processing based on legitimate interest. Write to privacy@thyrivo.com.
You may also lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl) or the authority in your country of residence.
You fully control the data stored in the app: in Settings you can export it ("Save a backup") or permanently delete it ("Delete all data"). Deleting the app also removes its data from the device.
11. Children
Thyrivo is intended for adults. People under 16 should use the app under the supervision of a parent or guardian.
12. Changes
If we change how data is processed, for example by adding a feature that requires sending data, we will update this policy first and tell you in the app. The current version is always available on this page.