Privacy policy
This covers the Tonelva mobile app on iOS and Android and the website at tonelva.com. Your blood pressure history is medical information about you, and the shortest honest description of our approach is that we made sure never to receive it.
Who we are
Tonelva is published by Vast Flow, LLP, Kunaeva 43, office 303, Almaty, Kazakhstan, which operates the app and this website and is the data controller for the limited processing described here. Write to [email protected] with any question about this policy, including a request to access or delete data. We answer privacy mail ourselves; there is no ticket queue and no third-party support platform holding your message.
What changed in this version
The app now offers an optional fingertip pulse measurement that uses the rear camera and its light, so this policy gained a full section on what the camera does and, more importantly, what it does not do with a single frame. It also gained a section on the pulse and variability records that measurement creates on your device. Nothing about the underlying architecture changed: there is still no account, no server and no transmission of health data, and the App Store privacy label still reads Data Not Collected. If you want the short answer about the camera, it is that frames are averaged into three numbers inside the video callback and thrown away, and that no image ever reaches storage of any kind.
The short version
Tonelva has no user accounts, no sign-in and no cloud sync. It never asks for your name, your email address or your date of birth. Every reading you record stays in the app's own storage on your device, every average and category is calculated locally, every pulse measurement is processed on the phone, and the PDF report is generated on the phone. Nothing is transmitted to us at any point. Deleting the app deletes the data with it.
That is why the App Store privacy label reads Data Not Collected and the Google Play Data safety section reports no data collected or shared. In a category where several free apps monetise exactly this kind of information, it is worth stating that the label is a literal description of the architecture rather than a technicality.
Every permission the app asks for, and why
The app requests three permissions in total, each at the moment it is first needed and never at launch. Refusing any of them leaves the diary fully usable: logging a reading works offline, with no permission granted, and no subscription.
| Permission | Asked when | Used for | Leaves the device |
|---|---|---|---|
| Camera | You start a fingertip pulse measurement | Reading the colour of your fingertip through the lens while the light is on | No. Frames are reduced to three averages in memory and discarded |
| Notifications | You turn on a measurement or medication reminder | Scheduling reminders locally on the device | No. There is no push server and no device token |
| Apple Health (iOS) | You turn on Health sync in Settings | Writing your readings and pulse to Health, and importing readings recorded elsewhere | No. The exchange happens on the device between two apps |
The app asks for nothing else. It does not request your location, your contacts, your photo library, your microphone, your calendar, your files, or the advertising identifier, and it contains no code that could use them.
Why we built it this way
A blood pressure history says a great deal about a person: that they have a chronic condition, roughly how well it is controlled, when they wake, and whether something changed. It is the sort of record that is valuable to advertisers and to data brokers, and that becomes a liability the moment it is held anywhere. The most reliable protection is not to hold it, so there is no server that could be compromised and no database that could be breached or sold.
The cost is real and we would rather name it than market the absence of a feature as a virtue: there is no cloud backup, no sync between your phone and your tablet, and no way for us to recover your history if you lose the device. Apple Health, if you enable it, effectively becomes your backup, and that is described below.
What the app stores on your device
Your readings with their date and time, any note you attach, the arm and the device if you record them, medication reminders, any pulse measurements you take, your chosen reference scale, and non-sensitive preference flags. Categories are derived from readings each time rather than stored, so switching between the American and European scales re-renders your whole history live. None of it is transmitted. It may be included in your own device backup if you have one enabled, in which case it is governed by Apple's or Google's terms rather than ours.
The camera, and what happens to every frame
The app can measure your pulse from a fingertip held over the rear camera and its light. This is photoplethysmography: with the light shining through the tip of your finger, the amount of red light reaching the sensor rises and falls slightly with each heartbeat, and the timing of those rises is the pulse. It is the same principle a fingertip clip in a clinic uses, implemented with the hardware your phone already has.
The camera opens only on the measurement screen, only after you have started a measurement, and it closes when that screen closes. There is no background capture, no capture while the app is not in the foreground, and no other screen in the app that can turn the camera on.
Each video frame is handled inside the callback that delivers it. A small central region is sampled, the sampled pixels are averaged into three numbers — a red average, a green average and a brightness average — and the frame itself is released immediately. Those three numbers per frame are the entire input to the measurement. No frame, no buffer, no still image, no video and no raw waveform is written to disk, to the app's cache, to a temporary directory, to your photo library or to a log file, in any version of the app. There is nothing to upload because there is nothing kept.
The measurement runs entirely on the phone and needs no network connection at all: it works in airplane mode, which is the easiest way to verify the claim for yourself. The light stays on for the length of the measurement, which is thirty seconds for a pulse reading and two minutes for a variability measurement, and it is turned off when the measurement ends, when the screen is left, when a call arrives, and when anything else interrupts the session.
Before the system asks for camera access, the app shows a plain-language screen explaining what the camera is used for. You can decline, and you can revoke access later in the operating system's settings. Declining or revoking it hides the pulse feature and changes nothing else — recording your blood pressure never depends on the camera, on a permission, or on anything being enabled.
Two things this feature deliberately is not. It is not a face or selfie measurement: the front camera is never used, and nothing about your face is captured or processed. And it is not a blood pressure measurement. The camera produces a pulse rate and, for subscribers, beat-to-beat variability, and it is structurally incapable of producing a systolic or diastolic value — that is described in full in the terms of use.
Pulse and variability records
A completed measurement is saved on your device as its own record, separate from your blood pressure readings. It holds the date and time, how long the measurement ran, the heart rate in beats per minute, the variability figures if the measurement produced them, the number of heartbeats counted, an indication of signal quality, and whether it was a pulse or a pulse-and-variability session. It does not hold the signal itself, because the signal is discarded as it is processed.
You can delete any single measurement from the pulse history, and Erase all data in Settings clears pulse measurements alongside your readings and reminders. If a subscription lapses, variability measurements you already recorded are kept rather than deleted; they are simply hidden behind the subscription again. We never delete a user's health record to enforce a paywall.
Apple Health
On iPhone, with your explicit permission, the app can read and write blood pressure, heart rate and heart rate variability in Apple Health. Readings you enter can be mirrored to Health, a pulse measurement can write its heart rate and, when a variability session reported one, its SDNN value, and readings recorded elsewhere can be imported with duplicates filtered out. All of that exchange happens on the device under Apple's HealthKit rules, which prohibit using health data for advertising or for data mining. We never receive it and we have no way to see it.
Health writing happens only while the Health sync switch in Settings is on, and only for data the app created. If you delete a reading or a pulse measurement in Tonelva, we remove the matching sample from Health only when we were the app that wrote it; data another app or a device put into Health is never touched by us.
Two honest notes carried over from earlier versions. First, iOS deliberately hides read-permission status from apps, so what Tonelva shows you is our request rather than a confirmed connection. Second, imported readings are never re-mirrored back, and switching sync on does not backfill your existing history — both choices exist to prevent duplicate entries, and both surprise people if unstated.
Android and Health Connect
On Android the app does not connect to Health Connect or to any other health platform in this version. It declares no health permissions, reads nothing from Health Connect and writes nothing to it, and your readings and pulse measurements stay in the app's own storage on the phone. If we add that integration later it will be opt-in, it will be described here before it ships, and the Google Play Data safety declaration will be updated with it.
The PDF report and export
The PDF report, the readings export and the pulse export are generated on your device. They leave it only through your own share sheet, to the destination you choose — your email, your messaging app, your printer, your doctor. We are not part of that transfer, we never receive a copy, and we have no record that it happened. Once a file has left your device through someone else's app, it is governed by that app's terms rather than by this policy, so take the same care you would with any other medical document.
Notifications
Measurement and medication reminders are scheduled locally by your device. There is no push server and no token, and nothing leaves the phone to make a reminder fire. Reminder text never contains a reading, a pulse, a category or a medication name, so a notification on a lock screen does not disclose anything to somebody glancing at your phone. That is a deliberate choice for a health app, not an oversight.
Purchases
Subscriptions are sold and processed by Apple and Google. We never see your payment details, your card, your billing address or your store account. To decide whether to unlock Pro features, the app uses RevenueCat, which processes an anonymous identifier generated on your device and the receipt the store issues. That tells us that a subscription exists and what state it is in. It does not identify you, and it cannot be connected to any reading, pulse measurement or note you have recorded, because none of those ever leave the phone.
One further detail, disclosed because it exists rather than because anyone would notice it. On iPhone, if you installed the app after tapping an Apple Search Ads advertisement, iOS provides a short-lived attribution token that tells us which campaign the install came from. It carries no advertising identifier, it does not require or trigger a tracking prompt, and it cannot follow you to other apps or sites — it exists so we can tell whether an advertisement paid for itself. We deliberately do not enable the alternative identifier collection that RevenueCat also offers, because that path would involve the advertising identifier and app tracking, and we do not want either.
Analytics: none in the app
The app contains no analytics SDK. No Firebase Analytics, no Crashlytics, no attribution SDK beyond the Search Ads token described above, no event tracking and no advertising identifier. There is no advertising in the app at all. We do not know how often you open it, which screens you use, whether you measured your pulse today, or what any of your numbers are. This costs us product insight and we accept that as the price of the privacy label.
This website is different and you should know it. It loads Microsoft Clarity, which records aggregate site usage — pages viewed, approximate region, device and browser, and anonymised interaction patterns such as scroll depth — so we can find pages that are broken or confusing. It is not connected to any app data, it does not follow you to other sites, and it cannot see anything you type into the tools. It sets cookies and honours the Global Privacy Control signal where your browser sends one. A content blocker will stop it and every tool here works normally without it.
The tools on this site
Readings you type into the category checker, the average calculator or any other tool on this website stay in your browser. They are never transmitted, never logged and never stored, because the arithmetic runs on your own machine in JavaScript. Closing the tab discards everything. There is no form submission anywhere on this site, which is also why none of these tools can email you a result.
What we never collect
We do not collect your name, email address, contacts, photos, location, advertising identifier, camera images or any health data. We do not sell data and we do not share it with data brokers. There is no mechanism by which we could build a profile of an individual, because there is no identity to attach one to.
Health data is never used for advertising, and never sold
We state this separately because it is the single question worth asking of any health app. Blood pressure readings, pulse measurements, variability figures and anything read from or written to Apple Health are used for one purpose only: showing you your own record inside the app on your own device. They are never used for advertising or marketing, never used to build a profile, never used to train a model, never sold, rented or licensed, and never disclosed to a third party. Apple's HealthKit terms prohibit several of these outright, and Google Play's health apps policy prohibits others; both prohibitions are easy for us to honour, because the data never reaches us in the first place.
Legal bases, for readers in the EEA and the UK
Because the app processes your data on the device rather than transmitting it, most of it never becomes processing that we perform as a controller. Where the app does process health data on your device — your readings, and any pulse measurement you take — the basis is your explicit consent under Article 9(2)(a), given by choosing to record the data and, for the camera, by granting the permission that a measurement requires. That consent is withdrawn by revoking the permission, by deleting the records, or by deleting the app. Purchase-receipt validation is necessary to perform the contract you entered into when subscribing. Website analytics rest on our legitimate interest in improving a free resource, balanced against the fact that they do not identify you and cannot see your readings.
A note on special category data
Blood pressure and pulse readings are health data, which several privacy regimes treat as a special category attracting stricter protection. Our answer is architectural: we do not receive it. We hold no special category data about any user, we cannot be compelled to produce records we do not have, and no breach of our systems could expose your history. If that ever changed we would say so prominently rather than amending a clause on this page.
Requests from courts and authorities
We can only produce what we hold. If we received a lawful demand for a user's health records we would have nothing to give, because those records exist on that person's phone and nowhere else, and we have no key, no copy and no route to them. The only user data we could produce at all is a subscription state attached to an anonymous identifier, which identifies nobody.
Retention
App data is retained on your device until you delete it or delete the app. We hold no copy and cannot retrieve or restore it. Camera frames are retained for the fraction of a second between arriving and being averaged. Purchase records are retained for as long as store receipt validation requires. Website analytics follow Microsoft Clarity's own retention schedule.
Your rights
You may have the right to access, correct, delete or port your personal data, and to object to certain processing. In practice the app satisfies all of them directly: editing a reading corrects it, deleting one deletes it, deleting a pulse measurement removes it, the export function provides portability in PDF and CSV, Erase all data clears everything at once, and deleting the app removes the lot. For written confirmation of what we hold — which for an app user is a receipt state and nothing else — write to [email protected] and we will respond within thirty days.
Cookies
The app uses no cookies. On this website the only cookies are those set by Microsoft Clarity for the analytics described above. There is no advertising cookie, no remarketing pixel, no social login and no embedded third-party widget that could set one.
If you are in the United States
We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act. You have the right to know what we hold, to request deletion, and not to be discriminated against for exercising either — and because there is no account, exercising them usually requires nothing more than deleting the app.
For readers in states with dedicated health-privacy statutes, including the Washington My Health My Data Act and Nevada's SB 370: we collect no consumer health data as those laws define it. Your readings and pulse measurements are not shared with us, not sold, and not used to infer anything about you; there is no consumer health data for us to disclose, share or sell, and no separate authorisation for us to seek.
Children
Tonelva is not directed at children and we do not knowingly collect data from anyone under 13, or under the applicable age of digital consent where that is higher. The app is intended for adults keeping their own record, and the reference categories it uses are adult thresholds.
Security
The strongest security property of this app is that there is nothing central to attack: no account to compromise, no password to steal, no server to breach, no database of user records to leak. Data on your device is protected by the operating system's own storage protections and by your device passcode, which is worth having enabled. If the app's own storage is ever damaged it is quarantined rather than deleted, so a fault cannot silently take your history with it. Website traffic is served over an encrypted connection.
International transfers
We hold no user health data to transfer. Apple, Google, RevenueCat and Microsoft process data in the regions described in their own policies, which may include the United States, under the transfer mechanisms those providers publish.
Changes
If the way data is handled changes, this page changes and the date at the top changes with it. Material changes will also be announced in the app. If we ever added a server component or cloud sync, we would say so prominently rather than quietly amending a clause here. Previous versions of this policy are available on request.
Contact
Questions, deletion requests and complaints go to [email protected], or by post to Vast Flow, LLP, Kunaeva 43, office 303, Almaty, Kazakhstan. If you are in the EEA or the UK and are not satisfied with our response, you may complain to your national data protection authority.