**Privacy Policy | Tonelva**

> How the Tonelva blood pressure diary handles data: no account, no server, no transmitted readings, and what the camera pulse measurement does with every frame it receives.

Source: https://tonelva.com/privacy/ · updated: 2026-08-03

[Home](https://tonelva.com/) /Privacy

# Privacy policy

This covers the Tonelva mobile app on iOS and Android and the website at tonelva.com.
Your blood pressure history is medical information about you, and the shortest honest
description of our approach is that we made sure never to receive it.

Last updated 3 August 2026

## Who we are

Tonelva is published by Vast Flow, LLP, Kunaeva 43, office 303, Almaty, Kazakhstan,
which operates the app and this website and is the data controller for the limited
processing described here. Write to
[support@tonelva.com](mailto:support@tonelva.com) with any question about this
policy, including a request to access or delete data. We answer privacy mail
ourselves; there is no ticket queue and no third-party support platform holding your
message.

## What changed in this version

The app now offers an optional fingertip pulse measurement that uses the rear camera
and its light, so this policy gained a full section on what the camera does and, more
importantly, what it does not do with a single frame. It also gained a section on the
pulse and variability records that measurement creates on your device. Nothing about
the underlying architecture changed: there is still no account, no server and no
transmission of health data, and the App Store privacy label still reads Data Not
Collected. If you want the short answer about the camera, it is that frames are
averaged into three numbers inside the video callback and thrown away, and that no
image ever reaches storage of any kind.

## The short version

Tonelva has no user accounts, no sign-in and no cloud sync. It never asks for your
name, your email address or your date of birth. Every reading you record stays in the
app's own storage on your device, every average and category is calculated locally,
every pulse measurement is processed on the phone, and the PDF report is generated on
the phone. Nothing is transmitted to us at any point. Deleting the app deletes the data
with it.

That is why the App Store privacy label reads Data Not Collected and the Google Play
Data safety section reports no data collected or shared. In a category where several
free apps monetise exactly this kind of information, it is worth stating that the label
is a literal description of the architecture rather than a technicality.

## Every permission the app asks for, and why

The app requests three permissions in total, each at the moment it is first needed and
never at launch. Refusing any of them leaves the diary fully usable: logging a reading
works offline, with no permission granted, and no subscription.

*Every permission the Tonelva app can request*

| Permission | Asked when | Used for | Leaves the device |
| --- | --- | --- | --- |
| Camera | You start a fingertip pulse measurement | Reading the colour of your fingertip through the lens while the light is on | No. Frames are reduced to three averages in memory and discarded |
| Notifications | You turn on a measurement or medication reminder | Scheduling reminders locally on the device | No. There is no push server and no device token |
| Apple Health (iOS) | You turn on Health sync in Settings | Writing your readings and pulse to Health, and importing readings recorded elsewhere | No. The exchange happens on the device between two apps |

The app asks for nothing else. It does not request your location, your contacts, your
photo library, your microphone, your calendar, your files, or the advertising
identifier, and it contains no code that could use them.

## Why we built it this way

A blood pressure history says a great deal about a person: that they have a chronic
condition, roughly how well it is controlled, when they wake, and whether something
changed. It is the sort of record that is valuable to advertisers and to data brokers,
and that becomes a liability the moment it is held anywhere. The most reliable
protection is not to hold it, so there is no server that could be compromised and no
database that could be breached or sold.

The cost is real and we would rather name it than market the absence of a feature as a
virtue: there is no cloud backup, no sync between your phone and your tablet, and no
way for us to recover your history if you lose the device. Apple Health, if you enable
it, effectively becomes your backup, and that is described below.

## What the app stores on your device

Your readings with their date and time, any note you attach, the arm and the device if
you record them, medication reminders, any pulse measurements you take, your chosen
reference scale, and non-sensitive preference flags. Categories are derived from
readings each time rather than stored, so switching between the American and European
scales re-renders your whole history live. None of it is transmitted. It may be
included in your own device backup if you have one enabled, in which case it is
governed by Apple's or Google's terms rather than ours.

## The camera, and what happens to every frame

The app can measure your pulse from a fingertip held over the rear camera and its
light. This is photoplethysmography: with the light shining through the tip of your
finger, the amount of red light reaching the sensor rises and falls slightly with each
heartbeat, and the timing of those rises is the pulse. It is the same principle a
fingertip clip in a clinic uses, implemented with the hardware your phone already has.

The camera opens only on the measurement screen, only after you have started a
measurement, and it closes when that screen closes. There is no background capture, no
capture while the app is not in the foreground, and no other screen in the app that
can turn the camera on.

Each video frame is handled inside the callback that delivers it. A small central
region is sampled, the sampled pixels are averaged into three numbers — a red average,
a green average and a brightness average — and the frame itself is released
immediately. Those three numbers per frame are the entire input to the measurement.
No frame, no buffer, no still image, no video and no raw waveform is written to disk,
to the app's cache, to a temporary directory, to your photo library or to a log file,
in any version of the app. There is nothing to upload because there is nothing kept.

The measurement runs entirely on the phone and needs no network connection at all: it
works in airplane mode, which is the easiest way to verify the claim for yourself. The
light stays on for the length of the measurement, which is thirty seconds for a pulse
reading and two minutes for a variability measurement, and it is turned off when the
measurement ends, when the screen is left, when a call arrives, and when anything else
interrupts the session.

Before the system asks for camera access, the app shows a plain-language screen
explaining what the camera is used for. You can decline, and you can revoke access
later in the operating system's settings. Declining or revoking it hides the pulse
feature and changes nothing else — recording your blood pressure never depends on the
camera, on a permission, or on anything being enabled.

Two things this feature deliberately is not. It is not a face or selfie measurement:
the front camera is never used, and nothing about your face is captured or processed.
And it is not a blood pressure measurement. The camera produces a pulse rate and, for
subscribers, beat-to-beat variability, and it is structurally incapable of producing a
systolic or diastolic value — that is described in full in the
[terms of use](https://tonelva.com/terms/).

## Pulse and variability records

A completed measurement is saved on your device as its own record, separate from your
blood pressure readings. It holds the date and time, how long the measurement ran,
the heart rate in beats per minute, the variability figures if the measurement produced
them, the number of heartbeats counted, an indication of signal quality, and whether it
was a pulse or a pulse-and-variability session. It does not hold the signal itself,
because the signal is discarded as it is processed.

You can delete any single measurement from the pulse history, and Erase all data in
Settings clears pulse measurements alongside your readings and reminders. If a
subscription lapses, variability measurements you already recorded are kept rather than
deleted; they are simply hidden behind the subscription again. We never delete a user's
health record to enforce a paywall.

## Apple Health

On iPhone, with your explicit permission, the app can read and write blood pressure,
heart rate and heart rate variability in Apple Health. Readings you enter can be
mirrored to Health, a pulse measurement can write its heart rate and, when a variability
session reported one, its SDNN value, and readings recorded elsewhere can be imported
with duplicates filtered out. All of that exchange happens on the device under Apple's
HealthKit rules, which prohibit using health data for advertising or for data mining.
We never receive it and we have no way to see it.

Health writing happens only while the Health sync switch in Settings is on, and only
for data the app created. If you delete a reading or a pulse measurement in Tonelva, we
remove the matching sample from Health only when we were the app that wrote it; data
another app or a device put into Health is never touched by us.

Two honest notes carried over from earlier versions. First, iOS deliberately hides
read-permission status from apps, so what Tonelva shows you is our request rather than a
confirmed connection. Second, imported readings are never re-mirrored back, and
switching sync on does not backfill your existing history — both choices exist to
prevent duplicate entries, and both surprise people if unstated.

## Android and Health Connect

On Android the app does not connect to Health Connect or to any other health platform
in this version. It declares no health permissions, reads nothing from Health Connect
and writes nothing to it, and your readings and pulse measurements stay in the app's own
storage on the phone. If we add that integration later it will be opt-in, it will be
described here before it ships, and the Google Play Data safety declaration will be
updated with it.

## The PDF report and export

The PDF report, the readings export and the pulse export are generated on your device.
They leave it only through your own share sheet, to the destination you choose — your
email, your messaging app, your printer, your doctor. We are not part of that transfer,
we never receive a copy, and we have no record that it happened. Once a file has left
your device through someone else's app, it is governed by that app's terms rather than
by this policy, so take the same care you would with any other medical document.

## Notifications

Measurement and medication reminders are scheduled locally by your device. There is no
push server and no token, and nothing leaves the phone to make a reminder fire.
Reminder text never contains a reading, a pulse, a category or a medication name, so a
notification on a lock screen does not disclose anything to somebody glancing at your
phone. That is a deliberate choice for a health app, not an oversight.

## Purchases

Subscriptions are sold and processed by Apple and Google. We never see your payment
details, your card, your billing address or your store account. To decide whether to
unlock Pro features, the app uses RevenueCat, which processes an anonymous identifier
generated on your device and the receipt the store issues. That tells us that a
subscription exists and what state it is in. It does not identify you, and it cannot be
connected to any reading, pulse measurement or note you have recorded, because none of
those ever leave the phone.

One further detail, disclosed because it exists rather than because anyone would notice
it. On iPhone, if you installed the app after tapping an Apple Search Ads advertisement,
iOS provides a short-lived attribution token that tells us which campaign the install
came from. It carries no advertising identifier, it does not require or trigger a
tracking prompt, and it cannot follow you to other apps or sites — it exists so we can
tell whether an advertisement paid for itself. We deliberately do not enable the
alternative identifier collection that RevenueCat also offers, because that path would
involve the advertising identifier and app tracking, and we do not want either.

## Analytics: none in the app

The app contains no analytics SDK. No Firebase Analytics, no Crashlytics, no attribution
SDK beyond the Search Ads token described above, no event tracking and no advertising
identifier. There is no advertising in the app at all. We do not know how often you open
it, which screens you use, whether you measured your pulse today, or what any of your
numbers are. This costs us product insight and we accept that as the price of the
privacy label.

This website is different and you should know it. It loads Microsoft Clarity, which
records aggregate site usage — pages viewed, approximate region, device and browser, and
anonymised interaction patterns such as scroll depth — so we can find pages that are
broken or confusing. It is not connected to any app data, it does not follow you to
other sites, and it cannot see anything you type into the tools. It sets cookies and
honours the Global Privacy Control signal where your browser sends one. A content
blocker will stop it and every tool here works normally without it.

## The tools on this site

Readings you type into the category checker, the average calculator or any other tool on
this website stay in your browser. They are never transmitted, never logged and never
stored, because the arithmetic runs on your own machine in JavaScript. Closing the tab
discards everything. There is no form submission anywhere on this site, which is also
why none of these tools can email you a result.

## What we never collect

We do not collect your name, email address, contacts, photos, location, advertising
identifier, camera images or any health data. We do not sell data and we do not share it
with data brokers. There is no mechanism by which we could build a profile of an
individual, because there is no identity to attach one to.

## Health data is never used for advertising, and never sold

We state this separately because it is the single question worth asking of any health
app. Blood pressure readings, pulse measurements, variability figures and anything read
from or written to Apple Health are used for one purpose only: showing you your own
record inside the app on your own device. They are never used for advertising or
marketing, never used to build a profile, never used to train a model, never sold,
rented or licensed, and never disclosed to a third party. Apple's HealthKit terms
prohibit several of these outright, and Google Play's health apps policy prohibits
others; both prohibitions are easy for us to honour, because the data never reaches us
in the first place.

## Legal bases, for readers in the EEA and the UK

Because the app processes your data on the device rather than transmitting it, most of
it never becomes processing that we perform as a controller. Where the app does process
health data on your device — your readings, and any pulse measurement you take — the
basis is your explicit consent under Article 9(2)(a), given by choosing to record the
data and, for the camera, by granting the permission that a measurement requires. That
consent is withdrawn by revoking the permission, by deleting the records, or by deleting
the app. Purchase-receipt validation is necessary to perform the contract you entered
into when subscribing. Website analytics rest on our legitimate interest in improving a
free resource, balanced against the fact that they do not identify you and cannot see
your readings.

## A note on special category data

Blood pressure and pulse readings are health data, which several privacy regimes treat
as a special category attracting stricter protection. Our answer is architectural: we do
not receive it. We hold no special category data about any user, we cannot be compelled
to produce records we do not have, and no breach of our systems could expose your
history. If that ever changed we would say so prominently rather than amending a clause
on this page.

## Requests from courts and authorities

We can only produce what we hold. If we received a lawful demand for a user's health
records we would have nothing to give, because those records exist on that person's
phone and nowhere else, and we have no key, no copy and no route to them. The only user
data we could produce at all is a subscription state attached to an anonymous
identifier, which identifies nobody.

## Retention

App data is retained on your device until you delete it or delete the app. We hold no
copy and cannot retrieve or restore it. Camera frames are retained for the fraction of a
second between arriving and being averaged. Purchase records are retained for as long as
store receipt validation requires. Website analytics follow Microsoft Clarity's own
retention schedule.

## Your rights

You may have the right to access, correct, delete or port your personal data, and to
object to certain processing. In practice the app satisfies all of them directly:
editing a reading corrects it, deleting one deletes it, deleting a pulse measurement
removes it, the export function provides portability in PDF and CSV, Erase all data
clears everything at once, and deleting the app removes the lot. For written
confirmation of what we hold — which for an app user is a receipt state and nothing else
— write to [support@tonelva.com](mailto:support@tonelva.com) and we will respond
within thirty days.

## Cookies

The app uses no cookies. On this website the only cookies are those set by Microsoft
Clarity for the analytics described above. There is no advertising cookie, no
remarketing pixel, no social login and no embedded third-party widget that could set
one.

## If you are in the United States

We do not sell personal information and we do not share it for cross-context behavioural
advertising as those terms are defined in the California Consumer Privacy Act. You have
the right to know what we hold, to request deletion, and not to be discriminated against
for exercising either — and because there is no account, exercising them usually
requires nothing more than deleting the app.

For readers in states with dedicated health-privacy statutes, including the Washington
My Health My Data Act and Nevada's SB 370: we collect no consumer health data as those
laws define it. Your readings and pulse measurements are not shared with us, not sold,
and not used to infer anything about you; there is no consumer health data for us to
disclose, share or sell, and no separate authorisation for us to seek.

## Children

Tonelva is not directed at children and we do not knowingly collect data from anyone
under 13, or under the applicable age of digital consent where that is higher. The app
is intended for adults keeping their own record, and the reference categories it uses are
adult thresholds.

## Security

The strongest security property of this app is that there is nothing central to attack:
no account to compromise, no password to steal, no server to breach, no database of user
records to leak. Data on your device is protected by the operating system's own storage
protections and by your device passcode, which is worth having enabled. If the app's own
storage is ever damaged it is quarantined rather than deleted, so a fault cannot silently
take your history with it. Website traffic is served over an encrypted connection.

## International transfers

We hold no user health data to transfer. Apple, Google, RevenueCat and Microsoft process
data in the regions described in their own policies, which may include the United States,
under the transfer mechanisms those providers publish.

## Changes

If the way data is handled changes, this page changes and the date at the top changes
with it. Material changes will also be announced in the app. If we ever added a server
component or cloud sync, we would say so prominently rather than quietly amending a
clause here. Previous versions of this policy are available on request.

## Contact

Questions, deletion requests and complaints go to
[support@tonelva.com](mailto:support@tonelva.com), or by post to Vast Flow, LLP,
Kunaeva 43, office 303, Almaty, Kazakhstan. If you are in the EEA or the UK and are not
satisfied with our response, you may complain to your national data protection
authority.

---

HTML version: https://tonelva.com/privacy/
Structured data for this site: https://tonelva.com/api/v1/openapi.json · https://tonelva.com/llms.txt
Free to quote and reuse with a link back to the source URL above (CC BY 4.0).
