Updated: 17 September 2026
1. Controller
Christian Hermann & Martina Hermann GbR, An Rainen 3, 72525 Münsingen, Germany; email: apps@bitbeans.de.
2. Data processed
All journal data stays on the device. Entries, symptoms, readings, medication, meals, notes, episodes, profile, drafts, reminders and settings are stored locally, encrypted with AES-256-GCM. The key is held in the device key store (Android Keystore or the iOS keychain, bound to this device) and never leaves the device. There is no account, no registration and no cloud sync. Android system backup and device transfer are switched off for Oriveli, and on iOS the app files are excluded from the device backup.
Two small stores sit outside that encryption and therefore deliberately hold no health information: the home screen widget store, which the launcher has to be able to read, holding the day of the last daily check-in and three labels, and the queue for medication confirmations tapped in a notification, which holds only the reminder id, the planned time and the time of the tap. Neither a medication name nor a symptom, reading or note is kept there.
If you switch on the import from Health Connect (Android) or Apple Health (iOS), Oriveli reads only the data types you release individually: sleep duration, resting heart rate, steps, weight, blood pressure and oxygen saturation. The operating system is asked for each data type separately, and everything is off as shipped. Oriveli only reads and never writes anything back; at most the last 30 days are read. The values are stored encrypted on the device like your own entries; we do not receive them. You can switch the import off in the app and withdraw the permission in Health Connect or in the iOS settings under Health. Entries already imported remain until you delete them in the history.
Weather and pollen stay off until you switch them on. You pick the place yourself from a list shipped inside the app; that search runs entirely on the device and sends nothing. Oriveli requests no location permission. While the feature is on, the place rounded to 0.1 degrees – roughly 10 kilometres – goes to MET Norway in Norway at most once a day, together with an identification of the app consisting of name, version and a contact address, as that service’s terms require. The pollen file of the German weather service is fetched as a whole and without any location; the device works out the pollen region itself, and pollen values exist only for regions in Germany. As with any network request, your IP address is technically visible to both. No health information and no identifier is transmitted. If you switch the feature off, nothing is sent any more and the stored place is forgotten.
For purchase, restoration and the AI analysis quota, the app creates a random anonymous guest identifier and keeps it in the device key store. It holds no name and no email address and is not an advertising or manufacturer device ID. Together with the store platform, the product ID and the store receipt it is sent to our AppCore backend so that the subscription can be verified and the entitlement stored.
During purchase and restoration the app also sends fixed technical events to the same backend: event name, flow step, fixed error reason, platform, app version and product ID. They help us spot abandoned or failed purchases. No health information is included.
An AI analysis only transfers data after you have given consent, seen the preview and confirmed that single request. The preview shows every item verbatim, and the app aborts if the packet does not match the confirmed preview. What is sent is a summary: period, selected areas, field labels, counts of values and days, source labels such as “Health Connect”, and the units used. For the “connections” comparison, the group values of one single question you asked are added: the number of days per group, mean, median, lowest and highest value, the difference and the length of the compared period. The lowest and the highest value are real measurements of yours, though without a date and without a link to any single entry. Note texts, photos, individual dated entries, name, email address, location and purchase data are not sent; field and entry identifiers are replaced by sequential numbers beforehand. The comparison itself is computed on the device; the model only phrases the result.
Reminders and medication reminders are scheduled solely by the operating system on the device. Nothing is sent to a server for this. As shipped the text names neither a condition nor a medication, because it can appear on a lock screen; medication names show only if you switch that on explicitly. Tapping “Taken” in the notification creates an entry in the encrypted journal. The home screen widget shows only whether today has been logged, and not a single health value. The suggestion cards on “Today” are produced entirely on the device by comparing fixed keyword lists with your own notes; nothing is sent in the process.
The PDF doctor report, the CSV and text export and the backup are produced on the device; no server is involved. You decide through the share sheet where the file goes. The backup is encrypted with your own passphrase (PBKDF2-HMAC-SHA256 with 600,000 iterations, AES-256-GCM); without that passphrase nobody can open it, including us. The report and the CSV export are deliberately unencrypted so that a practice can read them – treat them like a medical document. Values imported from Health Connect or Apple Health and the stored weather and pollen values are ordinary entries and are therefore included as far as they fall inside the chosen period and area.
The app contains no advertising, no analytics or tracking SDKs, no advertising tracking and no usage profile. We build no profiles about you, sell no personal data and pass no health information to ad networks or data brokers.
3. Purposes and legal bases
The journal features run on the device; we process no data for you there. The same applies to values from Health Connect or Apple Health: they are read and stored by your device alone. Purchase, restoration and subscription entitlement are processed to perform the contract (Article 6(1)(b) GDPR). The anonymous guest session, the fixed purchase events and the quota counters serve security, abuse prevention and correct operation (Article 6(1)(f) GDPR). Weather and pollen are only fetched if you switch the feature on; the basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by switching it off. The AI analysis processes health information and happens solely on the basis of your explicit consent (Article 9(2)(a) in conjunction with Article 6(1)(a) GDPR), which you give before the first analysis and can withdraw at any time with effect for the future. Without these consents, every other feature keeps working.
4. Recipients and service providers
We use Cloudflare for our AppCore backend in the EU. It runs the anonymous guest session, the store receipt check, the AI analysis quota and the forwarding of a confirmed analysis. To phrase the analysis we use xAI (Grok, api.x.ai) in the USA as a processor. If you switch weather and pollen on, the app contacts the Norwegian Meteorological Institute (MET Norway, api.met.no) and the German weather service (opendata.dwd.de); MET Norway receives the rounded place, the DWD no location at all, and neither receives any health information. Apple and Google handle purchase and payment as independent providers. Health Connect and Apple Health are services of your operating system; the values read there stay on the device and never reach us. We use no ad networks, data brokers or analytics services.
5. International transfers
Our backend runs on Cloudflare in the EU. MET Norway is based in Norway and the German weather service in Germany; both are inside the European Economic Area, so no third-country transfer takes place. Only the AI summary you confirmed is transferred to xAI in the USA to be phrased. We base that transfer on a data-processing agreement with EU Standard Contractual Clauses and on your explicit consent. Without consent no transfer to a third country takes place.
6. Advertising and tracking
The app contains no advertising, no analytics or tracking SDKs and no advertising tracking. We do not build advertising profiles, do not sell personal data and pass no health information to ad networks or data brokers.
7. Retention and security
Local data stays on the device until you delete it in the app or through system settings. Cached weather data older than 48 hours is discarded by the app itself. On the server we keep the anonymous guest session and the subscription entitlement for as long as they are needed for verification, restoration, abuse prevention and statutory evidence. The AI packet and the answer are neither stored nor logged; only usage and cost counters without content are kept. All transfers are encrypted in transit, local journal data with AES-256-GCM.
8. Delete data and account
“Delete all data” in the settings removes entries, profile, drafts, reminders, settings, the backup and export files inside the app and the key on the device; anything left over is then unreadable. Scheduled reminders are cancelled, the queue of medication confirmations is emptied and the home screen widget forgets the day of the last check-in. There is no account that would have to be deleted. Files you already shared stay where you saved them. For requests about the anonymous guest session or the subscription entitlement, email apps@bitbeans.de and include the platform and the approximate purchase date so that we can locate the record. The subscription itself is managed at Apple or Google.
9. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. You may also lodge a complaint with a data-protection authority; the LfDI Baden-Württemberg is the authority responsible for our registered office.
10. Health Connect and Apple Health
Oriveli uses values from Health Connect and Apple Health solely for the features you switched on yourself: recording, showing and reviewing your values in your own journal on this device. In doing so we comply with the Limited Use requirements for Health Connect permissions on Google Play and with Apple’s rules for HealthKit.
Concretely: we do not transfer these values to our servers or to third parties. We do not use them for advertising, marketing or resale and do not pass them to data brokers, information services, insurers or employers. Nobody here reads them; they are technically inaccessible to us. Oriveli only reads and writes nothing back to Health Connect or Apple Health.
If imported values become part of an AI analysis, that happens only when you confirm that analysis individually, and only the summarised information described in section 2 is transferred. You can withdraw the release per data type at any time: in the app with the respective switch and in the system through Health Connect or the iOS settings under Health.
11. Sources and licences
Weather: based on data from MET Norway (CC BY 4.0), combined into daily means. Pollen forecast index and pollen regions: Quelle: Deutscher Wetterdienst (CC BY 4.0). Place list: GeoNames (CC BY 4.0).
This information supports your own observation. These are forecast and index values for a region, not a measurement at your location, and we do not verify their accuracy.
