1. Operator and scope
Nivora is operated by Nevo Iflah, an individual developer based in Israel ("Nivora," "we," "us," or "our"). You can contact us using the form below.
Nivora is independent companion software compatible with supported SHR Ring hardware. We do not manufacture the connected ring. This policy covers the mobile app, its supporting cloud services, and this website. It does not cover the hardware manufacturer's own app, firmware, website, or privacy practices.
2. Information we process
Account and profile
Email address, authentication identifier, display name, age, gender selection, height, weight, units, language, goals, settings, onboarding state, and account status.
Wellness and activity
Depending on your hardware and choices, this can include sleep and sleep stages, heart rate, resting heart rate, heart-rate variability, blood-oxygen saturation, skin temperature, stress estimates, steps, calories, readiness scores and contributors, workouts, routes, distance, pace, and timestamps. Measurements can be incomplete or inaccurate.
Connected device
Bluetooth-advertised identifiers, connection and binding state, battery level, firmware information, synchronization times, and information supplied by the compatible ring SDK.
Technical and notification data
Push tokens, app installation or device keys, notification preferences, locale, time zone, platform, app version, network request metadata, synchronization markers, rate-limit records, and diagnostic information. Production error reports can include your user identifier, error scope and message, related diagnostic details, app version, and platform.
Local storage
The app stores preferences, wellness caches, synchronization queues, workout recovery data, ring state, and a limited diagnostic buffer on your device. Authentication persistence and protected values use platform-provided storage mechanisms where available.
Website and support
This website does not use advertising trackers, analytics, or non-essential cookies. The support form creates a draft in your email application. The website does not submit or store the form contents, but your email provider and ours process the message when you send it.
3. Why we process information
- Authenticate accounts and provide app functions.
- Connect compatible hardware and synchronize measurements.
- Calculate and display wellness summaries, baselines, goals, trends, readiness and sleep scores, and reports.
- Record workouts and routes you initiate.
- Synchronize with Apple Health or Health Connect when enabled.
- Send requested verification, operational, and reminder messages.
- Secure, diagnose, maintain, and improve the service.
- Handle support, deletion, legal requests, and legal obligations.
Depending on applicable law, we rely on performing our agreement with you, your consent, our legitimate interests in operating and securing the service, and compliance with legal obligations. You can withdraw permission through the app or device settings, but this may disable the related feature.
4. Providers and sharing
We use Google Firebase Authentication, Firestore, and Cloud Functions for accounts, profiles, configuration, app operations, and push-token records; MongoDB Atlas for wellness, sleep, readiness, workout, route, and diagnostic records; Render for backend hosting; Expo and Apple or Google platform services for notifications; Resend for account emails; Apple HealthKit and Android Health Connect for optional health synchronization; Google Maps for map features; and third-party ring SDK technology for compatible hardware communication.
We disclose information to these providers only as needed to operate their function. We may also disclose information when legally required, to protect users and the service, or during a merger, acquisition, financing, reorganization, or sale, subject to appropriate notice and safeguards.
We do not sell personal information, use health information for advertising, share it with data brokers, or use third-party advertising or behavioral analytics SDKs.
5. Apple Health and Health Connect
Health integration is optional. Subject to the permission profile you choose, the app may read heart rate, HRV, oxygen saturation, resting heart rate, steps, sleep, and body temperature.
It may write workouts, heart rate, steps, sleep, body temperature, and distance to Apple Health. On Health Connect it may write exercise sessions, heart rate, HRV, oxygen saturation, steps, sleep, body temperature, distance, and total calories burned. Platform availability can vary. Health data is used only to provide health and fitness functionality, not for advertising or sale.
6. Location and workout routes
If you start a route-based workout and grant permission, the app processes precise foreground location and, if separately allowed, background location. Coordinates are stored locally during an active workout and uploaded with the completed workout route to cloud storage. Background access lets recording continue while the app is not visible or the phone is locked. You can deny or revoke location access, but route and distance features may be limited.
7. Retention and deletion
Account, profile, wellness, and workout information is generally kept while your account is active and until you delete it or request deletion. Push tokens are kept until replaced, invalidated, or deleted. Remote production diagnostic entries are configured to expire after 30 days. Local information remains until cleared by the app, account deletion, the operating system, or app uninstall.
You can start account deletion from the app's profile controls. The app attempts to delete associated MongoDB wellness records, Firestore information, local caches, and the Firebase Authentication account. If a deletion step fails or you cannot access the app, contact us so we can complete or verify the request. Limited records may be retained when legally necessary. Provider backups can persist temporarily until overwritten through normal backup cycles.
8. Security
We use measures intended to protect information, including authenticated API access, Firestore access rules, transport encryption, platform storage, rate limiting, restricted administrative operations, and controlled account deletion. No system is completely secure, and absolute security cannot be guaranteed.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing; withdraw consent; and appeal or complain to a regulator. The app provides profile controls, permission controls, export tools, and account deletion. We do not discriminate against users for exercising applicable privacy rights.
Residents of the European Economic Area or United Kingdom may contact their local data-protection authority. California and other US residents can exercise any applicable access, correction, deletion, and opt-out rights. Because we do not sell personal information or use it for cross-context behavioral advertising, there is no sale or advertising sharing to opt out of.
Use the contact form below to make a request. We may verify your identity before acting.
10. Children
Nivora is not directed to anyone under 16, and users must be at least 16 to create an account. We do not knowingly collect personal information from children under 16. Contact us if you believe a younger child has created an account.
11. International transfers
We operate from Israel and use providers that may process information in Israel, the United States, and other countries. These countries may have different privacy laws. Where applicable, transfers are handled using provider contractual protections, adequacy decisions, or other legally recognized safeguards.
12. Changes to this policy
We may update this policy when the service, providers, or law changes. The revised policy will show a new effective date, and we will provide additional notice when required.
13. Contact and privacy requests
Contact Nevo Iflah for support, privacy questions, or rights requests. This form opens your email application and does not transmit information through this website.