This privacy policy applies to the Naova app (hereinafter referred to as "Application") for iOS and Android mobile devices, developed by Vadim Plămădeală (hereinafter referred to as "Service Provider") as a Freemium service. This service is provided "AS IS".
Naova is offline-first and works without an account for its core features. The health information you log — attacks, intensity, symptoms, pain location, medications, relief methods, possible triggers, notes, daily check-ins (sleep, stress, hydration and other lifestyle factors), menstrual-cycle entries, standardised questionnaire responses (such as MIDAS), and any weather readings you save — together with the profile details (a name or label, relationship, birth year) of anyone you choose to track — is stored only on your device. It is not uploaded to the Service Provider (unless you turn on the optional Cloud Backup, which uploads only an encrypted copy the Service Provider cannot read) and is not sold or shared for advertising. Naova shows no ads. The only information that may leave your device is described below (optional weather look-ups, anonymous diagnostics, optional encrypted Cloud Backup, and, if you subscribe, purchase validation).
You do not create an account and you are not asked for your name, email, or any identifier to use Naova's core features. Everything you log is entered by you and kept locally in the app's on-device database. You may export a backup file yourself (see "Backups" below); you choose where that file goes. The one exception is the optional Cloud Backup feature (Naova Plus), which asks you to sign in with Google (on Android) or Apple (on iOS) only so your encrypted backup can be linked to you — see "Optional Cloud Backup" below.
Naova is designed around health information, which is a special category of personal data. This data (your migraine/attack logs, symptoms, cycle entries, standardised questionnaire responses such as MIDAS, the profile details of anyone you track, and anything you import from Apple Health or Health Connect) stays on your device and is processed locally to show you your own history, calendar, patterns, and doctor report. It is never transmitted to the Service Provider's servers in readable form, and it is never used for advertising or marketing. The only exception is the optional Cloud Backup feature (off by default): if you turn it on, your data is uploaded only as an encrypted file that the Service Provider cannot read — see "Optional Cloud Backup" below.
Apple Health / Health Connect (optional): If you choose to connect it, Naova reads only what you approve — sleep and menstruation data — on a read-only basis, to save you re-typing it. This data is used solely to fill your check-in and cycle view on your device. In line with Apple and Google platform rules, health data obtained from HealthKit / Health Connect is never used for advertising, marketing, or data-mining, and is never sold or shared. You can disconnect at any time in the app or revoke access in your system Health settings.
Naova lets you keep separate profiles — for yourself and, if you wish, for someone in your care (for example a child or a family member). The details you add for a profile (a name or label, relationship, and birth year) and that person's logs are stored on your device just like your own data (and, if you enable Cloud Backup, in your encrypted backup). If you track someone else, you are responsible for doing so appropriately and, where relevant, with that person's or their guardian's agreement.
Weather/barometric-pressure context is entirely opt-in. If you enable it, Naova either uses your device location or a city you search for, and sends the coordinates to the Open-Meteo weather service to retrieve that day's barometric pressure, temperature, and humidity, which are then stored locally as neutral context next to your logs. Naova does not continuously track your location, does not store a location history for tracking, and does not share your location for advertising. If you never enable weather, no location data is used or sent.
If you turn on a reminder (for example, a daily check-in reminder), it is scheduled locally on your device by the operating system. There is no push server and no account involved. You can turn reminders off at any time in the app or in your device's notification settings.
You may create a backup file of your data from within the app. The backup is generated on your device and handed to your operating system's share sheet, so you decide where it goes (for example your own Google Drive, iCloud/Files, or email). Unless you turn on the optional Cloud Backup feature described next, the Service Provider does not receive or store your backup. Please keep your backup file somewhere private that only you can access.
Cloud Backup is an optional, off-by-default feature. If you turn it on, Naova signs you in with Google (on Android) or Apple (on iOS) — used only to link a backup to you — then encrypts your data on your device and stores the encrypted file on Google Firebase Cloud Storage. The data is encrypted with a key derived from a recovery phrase that only you hold; the Service Provider does not have that key and therefore cannot read the contents of your backup. A pseudonymous sign-in identifier is processed so your device can find and restore your own backup. Backups run automatically when you leave the app (and only if something changed) or when you tap "Back up now". You can turn Cloud Backup off and delete the stored backup at any time from within the app. If you never enable it, nothing is uploaded and the on-device-only behaviour above applies. Please note that if you lose your recovery phrase, an encrypted backup cannot be decrypted or recovered by anyone, including the Service Provider.
To keep the Application stable and understand which features are used, the Service Provider uses Google Firebase (Firebase Analytics and Firebase Crashlytics). This may collect a pseudonymous app-instance identifier, your device model and operating-system version, general app-usage events, performance data, and crash/diagnostic logs. This information is not used to identify you personally, and your logged health content is not included in it. This diagnostic and usage data is the main information that leaves your device, and it is processed by Google as described in its privacy documentation (linked below).
Only if you opt into the weather feature and grant location permission, and only at the moment you request a reading, to obtain that day's weather for your area. Naova does not run location tracking in the background.
No. Naova does not use AI to process your data or generate features. Patterns and the doctor report are produced by simple, deterministic calculations on your own logged data on your device — they are observations, not predictions or medical advice.
Logging is always free. If you choose an optional subscription (Naova Plus), payment is processed by the app store (Apple App Store or Google Play Billing), and entitlements are managed through RevenueCat. The Service Provider does not receive or store your payment-card details; those are handled by the app-store payment processors, who adhere to PCI-DSS. A pseudonymous purchase identifier may be processed to validate and restore your subscription.
The Service Provider does not sell your personal information. Your logged health data is not shared with third parties in readable form; if you enable Cloud Backup it is uploaded only in an encrypted form that the storage provider cannot read. Limited data is processed by the service providers strictly needed to run optional features — a weather provider (coordinates only, when you use weather), anonymous diagnostics (Firebase), purchase management (RevenueCat and the app stores, if you subscribe), and, if you enable Cloud Backup, sign-in and encrypted storage (Firebase Authentication and Firebase Cloud Storage). Each has its own privacy policy:
The Service Provider may also disclose information: as required by law (e.g. to comply with a subpoena or similar legal process); when they believe in good faith it is necessary to protect their rights, protect your safety or that of others, investigate fraud, or respond to a government request; and to the trusted service providers above, who act on the Service Provider's behalf and have agreed to protect your information.
Because Naova stores your data on your own device — and, unless you opt into Cloud Backup, without an account — you remain in direct control of it. You can view, edit, or delete any entry in the app, export it as a backup, and permanently remove all local data by deleting the Application (and, if you used Cloud Backup, delete the stored encrypted backup as described above). Where the Service Provider processes any personal data (for example the pseudonymous diagnostics described above), you have the rights to access, rectification, erasure, restriction, objection, and data portability, and the right to lodge a complaint with your local data protection supervisory authority (in Romania, the ANSPDCP).
Legal bases (EEA / UK users): The on-device processing of your health data is carried out by you, locally, to provide the app's core function; where the Service Provider processes data it relies on your consent for optional features (weather/location, Apple Health/Health Connect import, reminders, Cloud Backup — each of which you switch on yourself and can withdraw at any time), on its legitimate interest to keep the app stable and secure (anonymous diagnostics/crash reporting), on contract (to provide a subscription you purchase), and on legal obligation where applicable. For special-category (health) data processed by the Service Provider, processing is based on your explicit consent.
Data you log stays on your device until you delete it or uninstall the Application. The Service Provider does not hold your health data on any server in readable form. If you enable Cloud Backup, your encrypted backup is retained until you delete it or turn the feature off (the Service Provider keeps only the most recent few encrypted copies so a bad backup can be recovered). Pseudonymous diagnostic and analytics information is retained for up to 14 months and thereafter may be kept only in aggregated form.
Some service providers used for optional features (including Google/Firebase, RevenueCat, Apple, and Open-Meteo) may process data in countries outside your own, including the United States. Where data is transferred out of the EEA or the UK, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
Naova is not directed to children. The Service Provider does not knowingly collect personal information from children under 13 (or under 16 in the European Union, or the minimum age of digital consent in your country, whichever is higher). If you are a parent or guardian and believe a child has provided personal information, please contact the Service Provider at vitp.work@gmail.com so it can be removed.
Your data is stored in the Application's private, sandboxed storage on your device, protected by your device's own security. The Service Provider applies reasonable safeguards to the limited data it processes. However, no method of electronic storage or transmission is completely secure, and you are responsible for the security of your device and of any backup file you export.
You can stop all collection of information by uninstalling the Application using your device's standard uninstall process. You can also individually turn off optional features (weather/location, Health import, reminders, Cloud Backup) in the app at any time. Turning Cloud Backup off also deletes the encrypted backup stored for you.
This Privacy Policy may be updated from time to time. The Service Provider will notify you of any changes by updating this page with the new policy. You are advised to review it regularly; continued use of the Application is deemed acceptance of the changes.
This privacy policy is effective as of 2026-07-12.
By using the Application, you consent to the processing of your information as set out in this Privacy Policy.
If you have any questions about privacy while using the Application, please contact the Service Provider by email at vitp.work@gmail.com.