1. Who we are & how to contact us
This Privacy Policy explains how SHPATIK STUDIO S.R.L. (“Owlova”, “we”, “us”), the data controller, collects and uses your personal data. You can reach us at privacy@owlova.com; our registered address is Alexandru Hâjdeu 86/1, Chișinău MD-2001, Republic of Moldova. For data-protection questions you may also contact dpo@owlova.com.
2. Scope
This policy applies to the Owlova mobile apps (iOS and Android), the Owlova web app, and owlova.com.
3. The data we collect
We collect the following categories of data. This includes health data — your medications, dosages, schedules, instructions/notes, and adherence history — which we treat as special-category data (see legal basis below).
| Category | Examples | Source |
|---|---|---|
| Identity & account | name, email, avatar, account id | You / Google or Apple (social sign-in), password |
| Health data (special category) | medication names, dosage, form, schedules, instructions/notes, adherence history (taken/missed/skipped), reminder times | You |
| Device & technical | push token (Expo), platform, device id, app version, timezone, locale | Your device |
| Usage & analytics | screens viewed, feature usage, paywall interactions (no medication names) | PostHog |
| Diagnostics | crash logs, error traces (scrubbed of PII) | Sentry |
| Billing | Stripe customer id, subscription status, billing country, card last-4/expiry (held by Stripe, not us) | Stripe (web checkout) |
| Acceptance records | which legal-doc versions you accepted, when, and from where | App / Web |
4. How we use your data (purposes) & legal basis
We rely on the following legal bases under the GDPR. For health data, our lawful basis is your explicit consent (Art. 9(2)(a)), captured at onboarding; you can withdraw it at any time by deleting your account.
| Purpose | GDPR Art. 6 basis | Art. 9 basis (health data) |
|---|---|---|
| Deliver reminders & track adherence (core service) | Contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| Account, authentication, security | Contract / legitimate interest | n/a |
| Billing & subscription | Contract / legal obligation (tax) | n/a |
| Product analytics & crash diagnostics | Legitimate interest / consent (where required) | excluded (no health data sent) |
| Legal compliance, breach notification | Legal obligation | as required |
5. Notifications & lock-screen exposure
By default, push notifications contain no medication name — they are generic (“Time for your medication”). If you turn on “show medication names in notifications” (off by default), the medication name and dose appear on your lock screen and may be visible to anyone who can see your screen.
6. Legal bases summarized (GDPR)
We process your data under: consent (health data; analytics where required), performance of a contract (delivering the service you signed up for), legitimate interests (security, diagnostics), and legal obligation (tax records, breach notification), mapped per purpose above.
7. Sharing & disclosure / Subprocessors
We do not sell your personal data. We share data with the service providers (subprocessors) below, each acting under a data-processing agreement (DPA). DigitalOcean, Sentry, and PostHog are configured to the EU region.
| Subprocessor | Role / purpose | Data categories | Region | Transfer mechanism |
|---|---|---|---|---|
| DigitalOcean Managed Postgres | Primary database, avatar storage | all app data incl. health data | EU / FRA1 (Frankfurt) | DigitalOcean DPA + SCCs |
| Stripe | Payments, subscriptions (web only) | billing, customer id, payment method (held by Stripe) | US / global | SCCs / Stripe DPA |
| Expo (EAS) + Google FCM + Apple APNs | Push notification delivery | push token, generic notification payload (no medication name by default) | US | SCCs / Apple & Google DPAs |
| PostHog | Product analytics, feature flags | usage / analytics, device (no health data, no medication names) | EU Cloud | SCCs / region selection |
| Sentry | Error & crash tracking | diagnostics (PII-scrubbed) | EU | SCCs / region |
| Brevo | Transactional email (verification, password reset, trial / billing) | email, name | FR / EU | EU region (transfer minimized) |
| DigitalOcean (Kubernetes + Managed Redis + Container Registry) | API + worker hosting + job queue | all app data transiting the API; transient queue payloads (no medication name in push payload) | EU / FRA1 (Frankfurt) | DigitalOcean DPA + SCCs |
| Vercel | Web app + marketing hosting | technical, requests | US / global | SCCs |
8. Health Breach Notification (FTC HBNR)
Owlova is a covered “health app” under the FTC’s Health Breach Notification Rule. In the event of a breach of unsecured health data, we will notify affected individuals, the FTC, and — for large breaches — the media, within the timelines the Rule requires.
9. International transfers
Some data may be processed in the United States. For users in the EU/EEA and UK we rely on Standard Contractual Clauses (and the UK IDTA / adequacy where available); the transfer mechanism per provider is named in the subprocessor table above.
10. Data retention
We keep each category of data only as long as needed. In particular, your reminder/dose history is retained for 13 months, then purged; it is also deleted or anonymized earlier when you delete your account.
| Data | Retention |
|---|---|
| Account + health data | Until account deletion. On deletion, PII is anonymized and medication/adherence rows are deleted or anonymized. |
| Reminder / dose history | Retained for 13 months, then purged; deleted/anonymized earlier on account deletion. |
| Billing records (anonymized) | Retained for the legally required tax/accounting period (typically up to 7 years). |
| Acceptance records | Retained for the life of the account and a reasonable period after, as proof of consent. |
| Analytics (PostHog) | Per retention config (≤ 12 months); excludes health data. |
| Crash logs (Sentry) | Per Sentry retention (default 90 days). |
| Push tokens | Until logout / uninstall or marked invalid. |
11. Security
We protect your data with encryption in transit (TLS) and at rest (DigitalOcean Managed Postgres, EU/FRA1), access controls, and app-layer authorization. Medication data is never included in push notification payloads by default.
12. Your rights (GDPR / UK)
You have the right to:
- access, rectify, erase, restrict, and port your data;
- object to processing and withdraw consent at any time;
- lodge a complaint with a supervisory authority.
You can exercise these in-app via Settings → Download my data (GET /v1/users/me/export) and Delete account (DELETE /v1/users/me), or by emailing privacy@owlova.com. Your statutory data export is always free.
13. Your rights (California — CCPA/CPRA)
California residents have the right to know, delete, and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and to non-discrimination for exercising these rights. Your health/medical data is “sensitive personal information.” We do not sell or share your personal information. To make a request, contact privacy@owlova.com.
14. Children's privacy
Owlova is not directed to children under 16. We do not knowingly collect data from anyone under 16 and will delete it on discovery.
15. Cookies & analytics
We use PostHog (product analytics) and Sentry (error tracking). On the marketing site, EU visitors are shown a cookie/consent banner. Analytics events are configured to exclude medication names and PII.
16. Changes to this policy
We will post changes here and update the effective date; material changes re-prompt acceptance in the app.
17. Contact & complaints
Email privacy@owlova.com. EU/EEA users may complain to their local supervisory authority; California users may contact the Attorney General. Governing law for any related terms is the Republic of Moldova.
18. Effective date / version
Version 2026-08-18 · effective 2026-08-18.