Privacy Policy for Nuvo
Effective date: August 10, 2026
This Privacy Policy explains how the Nuvo app ("the App", "we", "us") handles your information. Nuvo is designed to be private by default: your habit data stays on your device and in your personal iCloud account, and no diagnostic data is collected unless you explicitly opt in.
1. Controller / Responsible party
The data controller responsible for the App within the meaning of the EU General Data Protection Regulation (GDPR) is:
Benjamin Waibel
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-Mail hi@benjaminwaibel.com
2. Summary
- We do not require an account. You never provide us with your name, email address, or any other identity information to use the App unless you choose to contact us by email (see Section 3.6).
- Your habit data never reaches our servers. We do not operate any servers of our own.
- We do not use advertising, tracking, or analytics for profiling purposes.
- We do not sell or share your personal information with anyone for money or other consideration.
- Crash reporting is strictly opt-in and disabled by default.
- Payments are handled by Apple. For in-app purchases, we only receive anonymous entitlement information (via RevenueCat), never your payment details.
3. Data we process and why
3.1 Habit data (stored on your device and in your iCloud)
The habits you create, including names, colors, schedules, completion history, and reminder settings, are stored:- Locally on your device, in the App's private storage; and
- In your private iCloud database (CloudKit), if you are signed in to iCloud with iCloud enabled for the App, so that your data syncs across your own devices.
Legal basis (GDPR): Art. 6(1)(b), processing necessary to provide the service you request (storing and syncing your habits).
You can disable iCloud sync at any time in iOS Settings → [your name] → iCloud, in which case data remains only on your device.
3.2 Reminders (local notifications)
If you set reminders for a habit, notifications are scheduled locally on your device by iOS. Reminder times and contents are not transmitted to us or to any third party. Notification permission is requested from you by iOS and can be revoked at any time in iOS Settings.3.3 Sync notifications (silent push)
To keep your data in sync across devices, Apple's iCloud service sends silent push notifications to your devices when your habit data changes on another device. This uses the Apple Push Notification service (APNs) and involves a device push token processed by Apple. These notifications contain no personal content and are not visible to you.Legal basis (GDPR): Art. 6(1)(b), processing necessary to provide cross-device sync.
3.4 Crash reports (opt-in only)
The App includes Firebase Crashlytics, a crash-reporting service provided by Google. Crash reporting is disabled by default. It is activated only if you explicitly opt in, and you can disable it again at any time in the App's Settings.When enabled, the following may be transmitted to Google if the App crashes:
- Crash stack traces and the state of the App at the time of the crash
- Device model, operating system version, device orientation, free memory/disk space
- A Crashlytics installation identifier (a random identifier not tied to your identity)
- Timestamps of the crash and of App launches
Legal basis (GDPR): Art. 6(1)(a), your consent. You may withdraw consent at any time via the toggle in Settings; withdrawal does not affect the lawfulness of processing before withdrawal.
3.5 In-app purchases (RevenueCat)
The App offers optional paid features via in-app purchases and subscriptions. Payment itself is processed entirely by Apple through the App Store; we never receive your name, billing address, or payment card details.To manage entitlements (i.e., to know whether your purchase is active on your devices), we use RevenueCat, a subscription-management service provided by RevenueCat, Inc. When you use the App, RevenueCat processes:
- A random, anonymous app user identifier generated for your App installation (not tied to your name or Apple Account)
- Purchase and subscription information from the App Store receipt (product identifiers, purchase dates, renewal/expiration status, transaction identifiers)
- Basic device information such as device model, iOS version, locale, and IP address (used transiently for request handling and fraud prevention)
Legal basis (GDPR): Art. 6(1)(b), processing necessary to perform the purchase contract and deliver the features you bought.
3.6 Support requests by email
If you choose to contact us by email, for example via the contact option in the App's Settings, we process the personal data you provide in your message: your email address, the contents of your message, and any name or other information you include.The contact option in Settings pre-fills the email draft with your App version and your anonymous RevenueCat app user identifier (see Section 3.5) so that we can help you with purchase-related issues without asking for them separately. Both values are plainly visible in the draft and you can delete them before sending. Note that if you send them, the otherwise anonymous identifier becomes linked to your email address in our support correspondence.
We use this information solely to handle your request. It is not shared with third parties beyond the email providers involved in delivering the message.
Legal basis (GDPR): Art. 6(1)(b) where your request relates to a purchase or the use of the App, otherwise Art. 6(1)(f), our legitimate interest in answering your inquiry.
4. What we do NOT do
- We do not collect your name, email address, contacts, location, photos, or health data (your email address and the details you provide are processed only if you choose to contact us by email, see Section 3.6).
- We do not use advertising networks or advertising identifiers (IDFA).
- We do not track you across apps or websites.
- We do not sell, rent, or share your personal information.
- We do not use your data for profiling or automated decision-making.
5. Service providers (processors) and international transfers
We rely on the following providers to deliver the App's functionality:| Provider | Purpose | Privacy information |
|---|---|---|
| Apple Inc. (iCloud/CloudKit, APNs, App Store) | Data sync in your private iCloud, push delivery, app distribution | apple.com/legal/privacy |
| Google LLC / Google Ireland Ltd. (Firebase Crashlytics) | Crash reporting (only with your consent) | firebase.google.com/support/privacy |
| RevenueCat, Inc. | In-app purchase and subscription management | revenuecat.com/privacy |
6. Data retention
- Habit data: retained on your device and in your iCloud until you delete individual habits, delete the App's iCloud data, or uninstall the App. Deleting the App removes local data; iCloud data can be removed in iOS Settings → [your name] → iCloud → Manage Account Storage.
- Crash reports: retained by Google Crashlytics for approximately 90 days.
- Purchase/entitlement records: retained by RevenueCat for as long as needed to manage your active purchases and subscriptions and to meet legal (e.g., financial record-keeping) obligations.
- Support emails: retained until your request has been resolved, after which they are deleted unless a legal obligation requires longer retention.
- We keep no other records about you, because we receive no other data.
7. Your rights under the GDPR (EU/EEA and UK users)
You have the right to:- Access (Art. 15): obtain a copy of the personal data we process about you
- Rectification (Art. 16): correct inaccurate data
- Erasure (Art. 17): have your data deleted
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object (Art. 21): object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)): at any time, e.g., by disabling crash reporting in Settings
- Lodge a complaint (Art. 77) with a supervisory authority, in particular in the EU member state of your residence or workplace
8. California privacy rights (CCPA/CPRA)
This section applies to California residents and serves as our Notice at Collection.Categories of personal information collected:
- Identifiers: a random, anonymous app user ID for purchase management (RevenueCat) and, only if you opt in to crash reporting, a random Crashlytics installation ID. Source: your device. Purpose: unlocking purchased features; diagnosing App defects.
- Commercial information: in-app purchase and subscription records (product, purchase date, renewal status). Source: the App Store receipt on your device. Purpose: delivering and restoring the features you purchased.
- Internet or network activity / device information: crash logs and device characteristics, only if you opt in to crash reporting. Purpose: diagnosing and fixing App defects. Retention: approximately 90 days (see Section 6).
- We do not sell your personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. Because we do not sell or share personal information, no "Do Not Sell or Share" opt-out is needed.
- You have the right to know/access, delete, and correct personal information, and the right to limit use of sensitive personal information (not applicable, as we collect none).
- You have the right to non-discrimination: we will never treat you differently for exercising your privacy rights.
9. Children's privacy
The App is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Since the App collects no personal data without opt-in consent and stores habit data only locally and in the user's own iCloud, no child-specific data collection occurs.10. Data security
Your habit data is protected by iOS's built-in app sandboxing and, when synced, by Apple's iCloud encryption in transit and at rest. Crash reports (if enabled) are transmitted to Google over encrypted connections.11. Disclaimers
We make no guarantees as to the suitability of this app for the user, or for any of its functionality, product price, accuracy, or usefulness, and will not be held responsible in the event that damage is incurred. As the app continues to evolve and new technologies are implemented, it may become necessary to update this Privacy Policy. We therefore recommend that you review this Privacy Policy regularly.12. Contact
For any questions about privacy or to exercise your rights:
Benjamin Waibel
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-Mail hi@benjaminwaibel.com