Privacy Policy

Your data lives on your phone.
Not ours.

Last updated: 9 August 2026 · Effective: 9 August 2026

The short version. Kriva is local-first. You can use the entire app without creating an account. Your symptom logs, cycle data, and patterns are stored on your device. If you choose to enable optional cloud backup with Apple Sign In, we store an encrypted copy, we cannot read its contents. We never sell your data. We do not advertise to you.

1. Who we are

Kriva.ai ("Kriva", "we", "our", "us") provides a women's health and symptom-tracking application available on iOS. This policy explains how we handle information when you visit our website or use our mobile app.

2. What we collect, and what we don't

On your device (local storage)

When you use Kriva, the following information is stored locally on your device and is not transmitted to us by default:

This data never leaves your device unless you take a specific action (such as enabling backup or contacting support and choosing to attach data).

Cross-device sync (your iCloud, never ours)

If you're signed into iCloud on your device, your logs sync across your own devices (iPhone, iPad, future Mac) through Apple's CloudKit private database. To be clear about what this means:

Daily AI readings

The morning, afternoon, and evening readings are generated by a third-party AI provider (Anthropic). For each reading:

Optional sign-in

Sign in with Apple is optional. When you use it, Apple gives the app a stable pseudonymous user identifier and (if you allow it) an email or Apple's private-relay address. These are stored in the device Keychain only. Kriva does not currently send sign-in data to any server. If we later introduce a paid plan, the identifier may be used for entitlement verification at that point, never for marketing.

Information we collect automatically

You can turn analytics off in Profile → Analytics. The setting is remembered per install.

What we do not collect

Per-feature data flow, every surface, plainly

The categories above describe our overall posture. This table walks through it feature by feature, using the same words you'll see inside the app and on /how-ai-works.

Legend: on device the data never leaves your iPhone. your iCloud syncs across your own Apple devices via CloudKit, we cannot read it. sent to AI an anonymous payload goes to Anthropic Claude, is used to generate the response, and is forgotten. never stored the payload has no lifetime on Kriva's servers.

Feature Data flow
Daily read
Kriva writes your morning card.
on device when supported sent to AI when not never stored
Cycle log
Periods, symptoms, mood, flow.
on device your iCloud
HRT tracker
Dose, site, application, side effects.
on device your iCloud
Ask Kriva
Freeform questions.
sent to AI never stored
Lab report import
Photo, PDF, or manual entry. OCR runs on-device via Vision.
source file on device only
Lab values in daily read + Ask Kriva
Sanitized biomarker names and values from your most recent report.
sent to AI never stored
Biomarker trend charts
Per-biomarker history across reports.
on device your iCloud
Visit prep PDF
Doctor-ready 2-page export.
on device only
Patterns & insights
Correlations, weekly shifts.
on device only
Preventive care schedule
Screening dates, guideline citations.
on device your iCloud
Widgets
Home + lock screen daily read.
on device (App Group container, same phone)
Subscription
Kriva+ billing.
Apple handles. Kriva sees a token that says "this device paid", no email, no name, no card.

Not in this table: analytics that identify you, ads, third-party trackers, marketing pixels. None of it exists in Kriva. For the full architecture of the AI path, including the exact payload structure, see How AI works in Kriva.

3. How we use information

4. Sensitive health data

Information about your menstrual cycle, mood, symptoms, and related signals is sensitive personal data. We treat it accordingly:

5. Sharing with third parties

The only third parties involved in Kriva are infrastructure providers that strictly process data on our behalf:

Each is bound by data-processing agreements. We do not share data with advertisers, data brokers, or analytics vendors that build user profiles.

6. Your rights

You have the right to:

If you are in the EU/UK, India, California, or another jurisdiction with applicable data protection law, these rights are guaranteed under that law. To exercise them, open the app and go to Settings → Privacy → Submit a request, or DM us on X at @kriva_ai.

7. Data retention

Local data persists until you delete the app or wipe it from Settings. Encrypted cloud backups persist until you disable backup or delete your account. Anonymised diagnostics are retained for up to 90 days, then aggregated or deleted.

8. Children's privacy

Kriva is intended for users aged 13 and over. We do not knowingly collect data from children under 13. If you believe a child under 13 is using Kriva, please contact us so we can remove their data.

9. International users

Kriva is available worldwide and our team is based in India. If you use Kriva from outside India, your data, if you enable optional backup, may be processed in India or in the region where our cloud provider operates. We apply the same privacy protections to all users, everywhere.

10. Security

We use modern encryption (AES-256 at rest, TLS 1.3 in transit) for all backed-up data. Local-only data is protected by your device's own security model. No system is perfectly secure, but our local-first design means there is very little of yours on our servers to protect in the first place.

11. Changes to this policy

If we materially change this policy, we will notify you inside the app before the changes take effect and update the date above. We will not retroactively reduce your rights without your explicit consent.

12. Contact us

The fastest way to reach us:

Kriva.ai, available worldwide, team based in India.