Privacy Policy
Last updated: August 15, 2026 · Applies to the Nivolo iOS app and nivolo.app
Nivolo is a habit and goal app built to be private by default. It has no accounts, no analytics, no advertising, and no trackers. Almost everything you create lives only on your iPhone. This policy explains the exceptions in detail — what leaves your device, when, who processes it, how long it is kept, and what you can ask us to do about it.
The short version
Your goals, actions, streaks, Pecks, gems, name, birthday and any email you enter are stored on your device only and are never sent to us.
The current release sends nothing at all. Two optional AI features are planned — an AI plan and an AI weekly insight; when they arrive, the only data that ever leaves your phone is what you type into them and the aggregate weekly numbers behind the insight, tied to a random ID rather than to you. Section 3 describes exactly how that will work.
We do not run analytics, ads, or trackers. We do not sell or share personal information. We have no way to identify you.
1. Who we are
Nivolo is an independent iOS app made by Jack Dai. For the purposes of the GDPR, the developer is the data controller for the limited data described in this policy. There is no company sign-in, no user database, and no customer record — the only way to reach us, and the only way we can reach you, is by email at jackdai259@gmail.com.
This policy covers the Nivolo iOS app and the website at nivolo.app. It does not cover Apple's own services (the App Store, iCloud Backup, Apple ID), which are governed by Apple's privacy policy.
2. Data that stays on your device
Nivolo has no accounts and no sign-in. Everything below is written to your iPhone's app storage — the app sandbox and an App Group container shared with the Nivolo home-screen widget — and is never transmitted to us:
| What | Why the app has it |
|---|---|
| Profile details — the name and birthday you enter during onboarding, and an email or handle if you choose to add one at the "save your journey" prompt | To greet you by name and to show a birthday theme on your birthday. The email field is a local reminder for your own records — it is not an account, it is not verified, and nothing is ever sent to it or to us. |
| Goals and actions — goal titles, your reasons, steps, milestones, logged actions, notes and dates | The core of the app. |
| Progress — streaks, streak freezes, rest days, Pecks, gems, achievements, trophy shelf, season history | Streaks, rewards and the season review. |
| Collection and cosmetics — owned items, equipped outfits, worlds, chosen app icon | Nivo's look and your unlocks. |
| Settings — language (English or 中文), reminder times, notification preferences, sound and haptics | To keep the app the way you set it. |
| Purchase state — which membership tier is active, as reported by Apple | To unlock that tier’s features offline. |
| A random app ID — a UUID generated on your device the first time an AI feature is used | Used only to apply fair-use limits on our AI server. It is generated randomly, is not derived from your Apple ID, email, name, phone number, or any device identifier, and is not connected to anything else. |
Because this data lives on your device, it is included in your normal iPhone backup (iCloud or a computer), where it is handled under Apple's backup and encryption terms. Deleting the app deletes this data from your device; a backup you have already made may still contain a copy until that backup is deleted or overwritten.
3. Data sent when you use AI features
Nivolo has two optional AI features, which are not switched on in the current release — until they are, nothing described in this section is sent. Neither runs on its own — each one sends data only at the moment you tap to use it. Requests go over an encrypted HTTPS connection to our own server (a Cloudflare Worker), carrying a short-lived signed token derived from the random app ID described above.
AI goal plan
When you ask Nivolo to draft a plan for a goal, the following is sent:
- The goal text you typed, your "why", and any specifics you added.
- A general category label for the goal icon (for example "Fitness" or "General").
- Your random app ID, a session identifier, and a flag saying whether your tier includes the AI features.
This text is used once, to generate that plan, and is returned to your device. Please avoid typing anything you would not want processed by a third-party AI provider — health details, financial details, or other people's personal information — into a goal you send to the AI. Writing goals by hand instead sends nothing at all.
AI weekly insight
The weekly "Nivo's take" card sends aggregate numbers only — never your goal text or your name. Specifically: your current streak length, how many actions you logged this week and last week, your most active weekday, how many goals are active, how many goals you completed this week, your total Pecks earned, and your language setting.
What our server keeps
Our server does not store your goal text, does not log request bodies, and does not build a profile. Against your random app ID it keeps only small counters needed to stop abuse and to enforce free-plan limits: recent request timestamps for rate limiting, a one-day session marker, and a usage count. These entries expire automatically (see retention).
If a future version of the app adds a feature that transmits anything else, this policy will be updated before that version ships.
4. Third parties we rely on
These are the only companies that can come into contact with data related to your use of Nivolo. We have no advertising, attribution, analytics or crash-reporting SDKs in the app.
| Provider | Role | What it receives |
|---|---|---|
| Apple | App distribution, in-app purchases, notifications framework, backups | Your purchase and subscription details, which we never see in identifiable form. Apple gives us only aggregated sales reports and, if you have opted in to sharing with developers, aggregated crash and performance diagnostics. |
| Cloudflare | Hosts our AI server (Workers + KV) and provides DNS for nivolo.app | The AI request contents in transit, your IP address as an ordinary part of making a network connection, and the fair-use counters described above. |
| Anthropic (Claude API) | Generates the plan text and the weekly insight text | Only the AI request contents described in section 3, forwarded by our server. Under Anthropic's commercial API terms, inputs and outputs are not used to train their models, and they are deleted from Anthropic's systems within their published retention window. Anthropic does not receive your IP address, your name, or any identifier from your device. |
| GitHub (GitHub Pages) | Hosts this website | Standard web server information when you visit nivolo.app — see section 16. |
We do not sell, rent, trade or share your personal information with anyone else. We would disclose data only if legally compelled to do so — and in practice we hold almost nothing that could be disclosed.
5. What we never do
- No accounts, no passwords, no user database.
- No analytics SDK, no attribution SDK, no advertising SDK, no ad network.
- No tracking across other apps or websites, and no use of the advertising identifier (IDFA). Nivolo will never show you an App Tracking Transparency prompt because it does not track.
- No sale or sharing of personal information, and no targeted advertising.
- No access to your location, contacts, photos, microphone, camera, calendar, or Health data.
- No profile-building, scoring, or automated decision-making that produces legal or similarly significant effects.
- No email marketing. We do not have your email unless you write to us first.
6. Permissions the app requests
Notifications. If you allow them, Nivolo schedules local notifications — reminders, streak warnings, and encouragement — directly on your device using iOS. They are composed on your phone and never pass through any server, so no one but you can see them. Turn them off any time in the app's settings or in iOS Settings.
Motion. Nivolo reads device motion so that falling pebbles and other on-screen elements react when you tilt your phone. Motion data is used only to animate the current screen; it is never recorded, stored, or transmitted. Declining this permission simply makes those animations static.
Home-screen widget. The Nivolo widget reads your streak and progress from a shared container on your device. Widget data stays on the device.
Rating prompt. The app may occasionally ask you to rate it using Apple's standard review prompt. Apple handles that entirely; we receive no information about whether or how you responded.
7. Purchases and memberships
All in-app purchases and subscriptions are processed by Apple through your Apple ID. We never see or handle your name, card number, billing address, or any other payment detail. Apple tells the app only whether an entitlement is active, and that answer is stored on your device.
Restoring purchases uses your Apple ID through Apple's servers. Managing or cancelling a subscription happens in your Apple ID settings, not with us. Refunds are handled by Apple.
8. How long data is kept
| Data | Retention |
|---|---|
| Everything stored on your device (section 2) | Until you delete it in the app, reset the app, or delete the app. We cannot delete it for you, and we cannot see it. |
| AI prompt text and weekly stats | Not stored by us. Processed in memory to produce a response, then discarded. Anthropic holds it only for the short period described in their API retention policy. |
| Rate-limit records against your random app ID | Expire automatically after about one hour. |
| Daily session marker | Expires automatically after 24 hours. |
| Weekly insight quota counter | Expires automatically after 14 days. |
| Free-plan usage count | Kept against the random app ID while it is needed to apply the free-plan limit. It contains a number and nothing else. |
| Emails you send us for support | Kept in the developer's mailbox for as long as needed to help you and to keep a record of the conversation; you can ask us to delete the thread. |
9. Legal bases (GDPR)
If you are in the EEA, the UK or Switzerland, we process the limited data described above on these bases:
- Performance of a contract — sending your goal text to generate the plan you asked for, and delivering Pro features you paid for.
- Legitimate interests — keeping the AI server available and preventing abuse and runaway costs through rate limiting and fair-use counters, using the least identifying method we could find (a random ID with short-lived counters).
- Consent — notifications and motion access, each of which you grant through an iOS prompt and can withdraw at any time in iOS Settings without losing the rest of the app.
- Legal obligation — where we are required to retain or disclose information by law.
10. International transfers
Cloudflare Workers run at edge locations worldwide, so an AI request is typically handled near you; Anthropic processes the request text on infrastructure in the United States. If you are in the EEA or the UK, this means the request text you submit to an AI feature may be transferred outside your region. These transfers rely on the providers' Standard Contractual Clauses and equivalent safeguards. All other data never leaves your device, so it is never transferred anywhere.
11. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to withdraw consent, and to data portability. Here is how each one works in practice for an app with no accounts:
- Access and portability — your data is already in your possession, on your device, visible in the app. We hold no copy to send you.
- Correction — you can edit or remove any goal, action, name, birthday or email directly in the app.
- Deletion — deleting the app removes everything it stored. Our fair-use counters are keyed to a random ID that we cannot link to you; they also expire on their own, and reinstalling the app generates a new random ID, permanently orphaning the old counters.
- Objection and restriction — simply do not use the AI features, and nothing at all is transmitted.
- Withdrawing consent — turn off notifications or motion access in iOS Settings at any time.
- Complaint — you may lodge a complaint with your local data protection authority. We would appreciate the chance to address it first.
Email jackdai259@gmail.com to exercise any of these rights and we will respond within 30 days. Because we hold no identifying information, we may not be able to locate any data that belongs to you specifically — which is, deliberately, the whole design.
12. California / US state rights
For California residents under the CCPA/CPRA, and residents of other US states with comparable laws: in the last twelve months we have collected the categories of identifiers (a randomly generated app identifier only), user content (the goal text you choose to submit to an AI feature), and commercial information (whether an Apple purchase is active, which stays on your device). These are collected for the business purposes described in this policy and are not retained beyond the periods in section 8.
- We have not sold or shared personal information, and we do not use personal information for cross-context behavioral advertising. We do not knowingly sell the personal information of anyone under 16.
- We do not collect sensitive personal information or use it to infer characteristics.
- You have the right to know, delete, and correct, and to not be discriminated against for exercising those rights. We offer no financial incentives for data.
- You may use an authorized agent to submit a request. Email us at the address below.
13. Children
Nivolo is a general-audience app and is not directed to children under 13 (or under 16 in the EEA and UK). We do not knowingly collect personal information from children — in fact we collect virtually no personal information from anyone. The birthday entered during onboarding is stored on the device solely to show a birthday theme and is never transmitted. If you believe a child has entered something into an AI feature that should be removed, email us and we will do what we can.
14. Security
- Your content lives inside the iOS app sandbox, protected by your device passcode and iOS file encryption.
- AI requests travel over TLS and are authenticated with a short-lived, cryptographically signed token, so our server cannot be used as an open endpoint.
- API keys and signing secrets are held server-side and are never shipped inside the app.
- There is no user database and no password store — the most common causes of a data breach do not exist here.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever affected data covered by this policy, we would post a notice on this page.
15. App Store privacy labels
Nivolo's App Store privacy label reports that data is not collected, or in the case of the optional AI features, that user content is not linked to your identity and is not used for tracking. This policy describes the same practices in full; if you ever spot a discrepancy between the two, please tell us and we will correct it.
16. This website
nivolo.app is a static site hosted on GitHub Pages with DNS provided by Cloudflare. It sets no cookies, runs no analytics, has no sign-up form, and does not attempt to identify you.
Every file the site needs — fonts, scripts, images — is served from nivolo.app itself. There are no third-party CDNs, no externally hosted web fonts, and no embedded widgets, so visiting this site makes no request to any company other than our host.
As with any website, the hosting provider automatically processes technical connection data — your IP address, browser type and requested page — in order to serve the page and defend against abuse, and retains it briefly under its own policies. We receive none of this information.
17. Changes to this policy
We will update this page whenever our practices change, and always before shipping an app version that handles data differently. The "last updated" date at the top always reflects the current version. For material changes — anything that would newly send data off your device — we will also note the change inside the app.
18. Contact
Questions about privacy, a rights request, or something in this policy that reads wrong to you?
We aim to reply within a couple of days, and within 30 days for formal requests.