Privacy Policy

Elly — a family reminders app
event Effective: July 2026 description Version 2.0 language English

Contents

  1. Introduction and data controller
  2. What data we process
  3. Purpose of processing and legal basis
  4. The "blind server" architecture
  5. Data stored only on your device
  6. Data that passes through the server
  7. Third-party providers
  8. Backups (Google Drive / iCloud)
  9. Family access and dependent profiles
  10. Data retention period
  11. Your rights
  12. Security and breach notification
  13. Changes to this Policy and contacts
description

1. Introduction and data controller

This Privacy Policy explains what personal data the Elly app ("we", "the app") processes, for what purpose, on what legal basis, and what rights you have. Elly is built around one principle: your health data belongs to you alone — the app does not require registration via email or password, and the server is designed to see as little as possible about the content of your data.

Personal data controller: Individual Entrepreneur Sierozhym Yevhen Oleksandrovych, Taxpayer ID (RNOKPP) 3376509759, Ukraine. Contact address for questions about this Policy — support@elly-medkit.com.

This is not medical advice. Elly is a tool for reminders and organization. If you use it to help track your own medication routine, please note: the app is not a medical device and does not replace a doctor, pharmacist, or emergency assistance. See the Terms of Use for details.
folder_shared

2. What data we process

Data you enter yourself (stored locally on your device)

  • Profile: name, date of birth (optional), family member profiles;
  • Reminders, Shelves entries, and mood check-ins that you create yourself — free-form names, quantities, dates, notes, tags, and photos, entirely at your own discretion. These fields are free-form: the app does not offer predefined categories and does not analyze or structure their content. If you choose to enter health-related data there (a special category of data), that is entirely your choice, and we handle it with the same care: locally, encrypted.

Technical data (may temporarily pass through the server)

  • Random technical identifiers for the device and sync channel;
  • Device push token (Firebase Cloud Messaging);
  • For paid plans — a technical account identifier, platform (iOS/Android), subscription product identifier, and purchase receipt — to confirm payment via the App Store/Google Play;
  • Technical request metadata (time, payload size) — for rate-limiting purposes.

We do not collect usage analytics, advertising identifiers, or profiling data.

rule

3. Purpose of processing and legal basis

PurposeLegal basis
Storing and organizing health-related data in the appYour explicit consent (Art. 9(2)(a) GDPR — processing of a special category of data; Art. 6(1)(a) GDPR for the rest of the data)
Syncing between your own devices and your family's devicesYour consent to use the feature + performance of an action at your request
Rate-limiting and protecting the server from abuseLegitimate interest (Art. 6(1)(f) GDPR) in infrastructure security

You can withdraw your consent at any time — by deleting your data and the app. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

visibility_off

4. The "blind server" architecture

No registration via email or password

There is no central user database with linked profiles. For paid plans and syncing between devices, the app automatically creates an anonymous technical account (no email, name, or other personal identifiers — just a random identifier and a cryptographic key derived from it). The server links only the subscription status and already-encrypted data to it — a deliberate architectural choice that minimizes risk in the event of a breach.

Where the app does need a server (transferring data between your own devices, confirming a subscription), the server only ever sees encrypted data and technical identifiers — the decryption key exists only on your own devices. The server never sees your name, entry titles, quantities, reminder schedules, photos, or health status in decrypted form.

phone_android

5. Data stored only on your device

Everything you enter into Elly is stored only locally, in an encrypted database on your device. Photos and documents are encrypted separately. Encryption keys are stored in the operating system's secure hardware storage (Keychain on iOS, Keystore on Android) and never leave the device unencrypted.

Access to the app can be additionally protected with biometrics (Face ID / fingerprint) or a device passcode.

Consequence: if you delete the app without first creating a backup, your data will be lost permanently. We keep no server-side copy that could restore it for you.
dns

6. Data that passes through the server

FeatureWhat the server seesHow long it's kept
Device pairingHash of the access code + encrypted data blockUp to 30 minutes or until first download, then deleted
Update sync (relay)Push token + encrypted payload, which is only forwardedNot stored — instant delivery via Firebase

The server does not log the content of these requests and does not link them to any specific individual.

hub

7. Third-party providers

Push notifications — Firebase Cloud Messaging (Google)

To deliver reminders, the app uses Firebase Cloud Messaging. Google only receives the device's push token and an encrypted payload it cannot read.

International data transfer. Google processes data on servers located outside Ukraine/the EEA (including in the US). In such cases, the transfer is protected by appropriate safeguards — Standard Contractual Clauses approved by the European Commission, or an equivalent mechanism provided for in the agreement with the provider.
cloud

8. Backups (Google Drive / iCloud)

If you choose to, you can create a backup in your own Google Drive (Android) or iCloud (iOS) — in a hidden application-only storage area that only the app can see.

Data in the backup is already encrypted the same way as on your device, and additionally protected with a password you create yourself. Neither Elly, Google, nor Apple can read the content of the backup without this password. The password is never sent to our servers — the app may remember it only locally on your device (in secure OS storage), so scheduled automatic backups don't have to ask for it every time. If you reinstall the app or switch devices, you'll need to enter the password manually — if you've forgotten it, the backup cannot be restored. You manage your backups yourself — storage and deletion happen in your own cloud storage, outside our control.

family_restroom

9. Family access and dependent profiles

Syncing between family devices

To share data between your own devices or with family members' devices, the devices exchange a one-time code. Data is encrypted with a key derived from this code and can only be decrypted on a device that entered the same code. The server only temporarily stores the encrypted block — it cannot be read without the code.

In the "Family Visibility" section, the "Sync this profile's data to other devices" toggle lets you turn off sharing this profile's reminders and attachments with other family devices. Please note: if your device and this member's device have already been synced as family devices, data shared before you turned off the toggle is still physically stored (encrypted) on both devices — turning it off is not a retroactive, device-level access barrier.

Automatic introduction within a group. When a new member joins your family group, the paying member's app automatically shares only a "business card" of each existing member (name, avatar, technical identifier) — with no health-related data whatsoever. This lets the new member see who else is in the group and, if they choose, enable visibility with them. An actual encrypted channel (and, accordingly, an exchange of real data) between two specific members is only created once one of them explicitly enables visibility for the other.

Profiles of children and other dependent family members

Elly lets you add profiles for family members (such as children or elderly parents) managed by the device owner. These are not separate accounts — dependent profiles have no login of their own and no direct access to the app unless the profile owner sets that up themselves.

A child's profile data is entered and controlled by the parent/guardian exercising parental responsibility; they are responsible for the accuracy and appropriateness of that data. We do not address children directly, and we do not offer the app as a service directed at a child.

hourglass_bottom

10. Data retention period

DataRetention period
Data in the app on your deviceUntil you delete it or delete the app
Backups in your own Drive/iCloudUntil you delete them yourself — outside our control
Pairing blocks and relay payloads on the serverUp to 30 minutes or until first download
Push tokenAs long as the app is installed and notifications are enabled
balance

11. Your rights

Since the bulk of your data lives only on your device, most rights are exercised directly within the app. Under the GDPR and Ukraine's Law "On Personal Data Protection", you have the right to:

  • Access your data — view it directly in the app, or use the "Data Export" section in your profile to get a copy in a readable format;
  • Rectification of inaccurate data — edit entries directly;
  • Erasure ("the right to be forgotten") — delete individual entries, family member profiles, or the entire app;
  • Restriction of processing and objection to processing — turn off the relevant feature in settings;
  • Data portability — export your data in a structured format via "Data Export";
  • Withdrawal of consent at any time, with no effect on the lawfulness of prior processing;
  • Lodging a complaint with a data protection supervisory authority — in Ukraine, this is the Ukrainian Parliament Commissioner for Human Rights; for EU residents, the data protection authority of your country of residence.

Regarding temporary technical data on the server (pairing blocks, push tokens) — write to us at support@elly-medkit.com; most of it is automatically deleted within minutes or hours anyway.

shield

12. Security and breach notification

We apply technical and organizational measures appropriate to the sensitivity of health-related data: encryption of data on the device and in transit, storage of encryption keys in the device's secure hardware storage, optional biometric login protection, encrypted communication with the server (HTTPS/TLS), and rate-limiting against abuse.

In the event of a personal data breach that creates a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where necessary, you personally — without undue delay, in accordance with applicable law.

edit_note

13. Changes to this Policy and contacts

We may update this Policy over time — for example, when adding new features. We will notify you of material changes within the app and ask you to re-confirm the updated version. The date and version of the latest update are always shown at the top of the document.

Questions about this Policy, or requests regarding your rights — at support@elly-medkit.com.