This Privacy Policy explains what personal data the Elly app ("we", "the app") processes, for what purpose, on what legal basis, and what rights you have. Elly is built around one principle: your health data belongs to you alone — the app does not require registration via email or password, and the server is designed to see as little as possible about the content of your data.
Personal data controller: Individual Entrepreneur Sierozhym Yevhen Oleksandrovych, Taxpayer ID (RNOKPP) 3376509759, Ukraine. Contact address for questions about this Policy — support@elly-medkit.com.
We do not collect usage analytics, advertising identifiers, or profiling data.
| Purpose | Legal basis |
|---|---|
| Storing and organizing health-related data in the app | Your explicit consent (Art. 9(2)(a) GDPR — processing of a special category of data; Art. 6(1)(a) GDPR for the rest of the data) |
| Syncing between your own devices and your family's devices | Your consent to use the feature + performance of an action at your request |
| Rate-limiting and protecting the server from abuse | Legitimate interest (Art. 6(1)(f) GDPR) in infrastructure security |
You can withdraw your consent at any time — by deleting your data and the app. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
There is no central user database with linked profiles. For paid plans and syncing between devices, the app automatically creates an anonymous technical account (no email, name, or other personal identifiers — just a random identifier and a cryptographic key derived from it). The server links only the subscription status and already-encrypted data to it — a deliberate architectural choice that minimizes risk in the event of a breach.
Where the app does need a server (transferring data between your own devices, confirming a subscription), the server only ever sees encrypted data and technical identifiers — the decryption key exists only on your own devices. The server never sees your name, entry titles, quantities, reminder schedules, photos, or health status in decrypted form.
Everything you enter into Elly is stored only locally, in an encrypted database on your device. Photos and documents are encrypted separately. Encryption keys are stored in the operating system's secure hardware storage (Keychain on iOS, Keystore on Android) and never leave the device unencrypted.
Access to the app can be additionally protected with biometrics (Face ID / fingerprint) or a device passcode.
| Feature | What the server sees | How long it's kept |
|---|---|---|
| Device pairing | Hash of the access code + encrypted data block | Up to 30 minutes or until first download, then deleted |
| Update sync (relay) | Push token + encrypted payload, which is only forwarded | Not stored — instant delivery via Firebase |
The server does not log the content of these requests and does not link them to any specific individual.
To deliver reminders, the app uses Firebase Cloud Messaging. Google only receives the device's push token and an encrypted payload it cannot read.
If you choose to, you can create a backup in your own Google Drive (Android) or iCloud (iOS) — in a hidden application-only storage area that only the app can see.
Data in the backup is already encrypted the same way as on your device, and additionally protected with a password you create yourself. Neither Elly, Google, nor Apple can read the content of the backup without this password. The password is never sent to our servers — the app may remember it only locally on your device (in secure OS storage), so scheduled automatic backups don't have to ask for it every time. If you reinstall the app or switch devices, you'll need to enter the password manually — if you've forgotten it, the backup cannot be restored. You manage your backups yourself — storage and deletion happen in your own cloud storage, outside our control.
To share data between your own devices or with family members' devices, the devices exchange a one-time code. Data is encrypted with a key derived from this code and can only be decrypted on a device that entered the same code. The server only temporarily stores the encrypted block — it cannot be read without the code.
In the "Family Visibility" section, the "Sync this profile's data to other devices" toggle lets you turn off sharing this profile's reminders and attachments with other family devices. Please note: if your device and this member's device have already been synced as family devices, data shared before you turned off the toggle is still physically stored (encrypted) on both devices — turning it off is not a retroactive, device-level access barrier.
Automatic introduction within a group. When a new member joins your family group, the paying member's app automatically shares only a "business card" of each existing member (name, avatar, technical identifier) — with no health-related data whatsoever. This lets the new member see who else is in the group and, if they choose, enable visibility with them. An actual encrypted channel (and, accordingly, an exchange of real data) between two specific members is only created once one of them explicitly enables visibility for the other.
Elly lets you add profiles for family members (such as children or elderly parents) managed by the device owner. These are not separate accounts — dependent profiles have no login of their own and no direct access to the app unless the profile owner sets that up themselves.
A child's profile data is entered and controlled by the parent/guardian exercising parental responsibility; they are responsible for the accuracy and appropriateness of that data. We do not address children directly, and we do not offer the app as a service directed at a child.
| Data | Retention period |
|---|---|
| Data in the app on your device | Until you delete it or delete the app |
| Backups in your own Drive/iCloud | Until you delete them yourself — outside our control |
| Pairing blocks and relay payloads on the server | Up to 30 minutes or until first download |
| Push token | As long as the app is installed and notifications are enabled |
Since the bulk of your data lives only on your device, most rights are exercised directly within the app. Under the GDPR and Ukraine's Law "On Personal Data Protection", you have the right to:
Regarding temporary technical data on the server (pairing blocks, push tokens) — write to us at support@elly-medkit.com; most of it is automatically deleted within minutes or hours anyway.
We apply technical and organizational measures appropriate to the sensitivity of health-related data: encryption of data on the device and in transit, storage of encryption keys in the device's secure hardware storage, optional biometric login protection, encrypted communication with the server (HTTPS/TLS), and rate-limiting against abuse.
In the event of a personal data breach that creates a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where necessary, you personally — without undue delay, in accordance with applicable law.
We may update this Policy over time — for example, when adding new features. We will notify you of material changes within the app and ask you to re-confirm the updated version. The date and version of the latest update are always shown at the top of the document.
Questions about this Policy, or requests regarding your rights — at support@elly-medkit.com.