Privacy Policy for Nuvo

Effective date: August 10, 2026

This Privacy Policy explains how the Nuvo app ("the App", "we", "us") handles your information. Nuvo is designed to be private by default: your habit data stays on your device and in your personal iCloud account, and no diagnostic data is collected unless you explicitly opt in.

1. Controller / Responsible party

The data controller responsible for the App within the meaning of the EU General Data Protection Regulation (GDPR) is:

Benjamin Waibel
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-Mail hi@benjaminwaibel.com

2. Summary

3. Data we process and why

3.1 Habit data (stored on your device and in your iCloud)

The habits you create, including names, colors, schedules, completion history, and reminder settings, are stored: Your CloudKit data is stored in the private database associated with your Apple Account. It is encrypted in transit and at rest by Apple. We have no access to it. Only you can read it through your devices. Syncing is performed by Apple's iCloud service under Apple's terms and privacy policy (see Section 5).

Legal basis (GDPR): Art. 6(1)(b), processing necessary to provide the service you request (storing and syncing your habits).

You can disable iCloud sync at any time in iOS Settings → [your name] → iCloud, in which case data remains only on your device.

3.2 Reminders (local notifications)

If you set reminders for a habit, notifications are scheduled locally on your device by iOS. Reminder times and contents are not transmitted to us or to any third party. Notification permission is requested from you by iOS and can be revoked at any time in iOS Settings.

3.3 Sync notifications (silent push)

To keep your data in sync across devices, Apple's iCloud service sends silent push notifications to your devices when your habit data changes on another device. This uses the Apple Push Notification service (APNs) and involves a device push token processed by Apple. These notifications contain no personal content and are not visible to you.

Legal basis (GDPR): Art. 6(1)(b), processing necessary to provide cross-device sync.

3.4 Crash reports (opt-in only)

The App includes Firebase Crashlytics, a crash-reporting service provided by Google. Crash reporting is disabled by default. It is activated only if you explicitly opt in, and you can disable it again at any time in the App's Settings.

When enabled, the following may be transmitted to Google if the App crashes: Crash reports never include your habit data. Google processes this data on our behalf as a processor. Crashlytics crash data is retained by Google for a limited period (currently 90 days) before deletion. Firebase Analytics is disabled in the App.

Legal basis (GDPR): Art. 6(1)(a), your consent. You may withdraw consent at any time via the toggle in Settings; withdrawal does not affect the lawfulness of processing before withdrawal.

3.5 In-app purchases (RevenueCat)

The App offers optional paid features via in-app purchases and subscriptions. Payment itself is processed entirely by Apple through the App Store; we never receive your name, billing address, or payment card details.

To manage entitlements (i.e., to know whether your purchase is active on your devices), we use RevenueCat, a subscription-management service provided by RevenueCat, Inc. When you use the App, RevenueCat processes: RevenueCat does not receive your habit data and acts as our processor. We use this information solely to unlock the features you purchased, restore purchases across your devices, and handle billing-related support.

Legal basis (GDPR): Art. 6(1)(b), processing necessary to perform the purchase contract and deliver the features you bought.

3.6 Support requests by email

If you choose to contact us by email, for example via the contact option in the App's Settings, we process the personal data you provide in your message: your email address, the contents of your message, and any name or other information you include.

The contact option in Settings pre-fills the email draft with your App version and your anonymous RevenueCat app user identifier (see Section 3.5) so that we can help you with purchase-related issues without asking for them separately. Both values are plainly visible in the draft and you can delete them before sending. Note that if you send them, the otherwise anonymous identifier becomes linked to your email address in our support correspondence.

We use this information solely to handle your request. It is not shared with third parties beyond the email providers involved in delivering the message.

Legal basis (GDPR): Art. 6(1)(b) where your request relates to a purchase or the use of the App, otherwise Art. 6(1)(f), our legitimate interest in answering your inquiry.

4. What we do NOT do

5. Service providers (processors) and international transfers

We rely on the following providers to deliver the App's functionality:
ProviderPurposePrivacy information
Apple Inc. (iCloud/CloudKit, APNs, App Store) Data sync in your private iCloud, push delivery, app distribution apple.com/legal/privacy
Google LLC / Google Ireland Ltd. (Firebase Crashlytics) Crash reporting (only with your consent) firebase.google.com/support/privacy
RevenueCat, Inc. In-app purchase and subscription management revenuecat.com/privacy
These providers may process data on servers outside the European Economic Area, including in the United States. Transfers are safeguarded through the EU–U.S. Data Privacy Framework (where the provider is certified) and/or the European Commission's Standard Contractual Clauses (Art. 46 GDPR).

6. Data retention

7. Your rights under the GDPR (EU/EEA and UK users)

You have the right to: Note that because your habit data is stored only on your device and in your personal iCloud account, you can exercise access, correction, and deletion for that data directly yourself at any time. For anything else, contact us at the address in Section 1. We do not require you to create an account, so we may ask for reasonable information to verify a request where applicable.

8. California privacy rights (CCPA/CPRA)

This section applies to California residents and serves as our Notice at Collection.

Categories of personal information collected: We collect no sensitive personal information as defined by the CPRA. Your habit data in iCloud is processed by Apple as your service provider and is not accessible to us. RevenueCat processes purchase information as our service provider. To exercise these rights, contact us at hi@benjaminwaibel.com.

9. Children's privacy

The App is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Since the App collects no personal data without opt-in consent and stores habit data only locally and in the user's own iCloud, no child-specific data collection occurs.

10. Data security

Your habit data is protected by iOS's built-in app sandboxing and, when synced, by Apple's iCloud encryption in transit and at rest. Crash reports (if enabled) are transmitted to Google over encrypted connections.

11. Disclaimers

We make no guarantees as to the suitability of this app for the user, or for any of its functionality, product price, accuracy, or usefulness, and will not be held responsible in the event that damage is incurred. As the app continues to evolve and new technologies are implemented, it may become necessary to update this Privacy Policy. We therefore recommend that you review this Privacy Policy regularly.

12. Contact

For any questions about privacy or to exercise your rights:

Benjamin Waibel
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-Mail hi@benjaminwaibel.com