Owlova
Owlova

Privacy Policy

Last updated: 2026-08-18

This is a developer template pending legal review. Bracketed items (entity name, address, governing law) are completed before launch.

1. Who we are & how to contact us

This Privacy Policy explains how SHPATIK STUDIO S.R.L. (“Owlova”, “we”, “us”), the data controller, collects and uses your personal data. You can reach us at privacy@owlova.com; our registered address is Alexandru Hâjdeu 86/1, Chișinău MD-2001, Republic of Moldova. For data-protection questions you may also contact dpo@owlova.com.

2. Scope

This policy applies to the Owlova mobile apps (iOS and Android), the Owlova web app, and owlova.com.

3. The data we collect

We collect the following categories of data. This includes health data — your medications, dosages, schedules, instructions/notes, and adherence history — which we treat as special-category data (see legal basis below).

CategoryExamplesSource
Identity & accountname, email, avatar, account idYou / Google or Apple (social sign-in), password
Health data (special category)medication names, dosage, form, schedules, instructions/notes, adherence history (taken/missed/skipped), reminder timesYou
Device & technicalpush token (Expo), platform, device id, app version, timezone, localeYour device
Usage & analyticsscreens viewed, feature usage, paywall interactions (no medication names)PostHog
Diagnosticscrash logs, error traces (scrubbed of PII)Sentry
BillingStripe customer id, subscription status, billing country, card last-4/expiry (held by Stripe, not us)Stripe (web checkout)
Acceptance recordswhich legal-doc versions you accepted, when, and from whereApp / Web

4. How we use your data (purposes) & legal basis

We rely on the following legal bases under the GDPR. For health data, our lawful basis is your explicit consent (Art. 9(2)(a)), captured at onboarding; you can withdraw it at any time by deleting your account.

PurposeGDPR Art. 6 basisArt. 9 basis (health data)
Deliver reminders & track adherence (core service)Contract (6(1)(b))Explicit consent (9(2)(a))
Account, authentication, securityContract / legitimate interestn/a
Billing & subscriptionContract / legal obligation (tax)n/a
Product analytics & crash diagnosticsLegitimate interest / consent (where required)excluded (no health data sent)
Legal compliance, breach notificationLegal obligationas required

5. Notifications & lock-screen exposure

By default, push notifications contain no medication name — they are generic (“Time for your medication”). If you turn on “show medication names in notifications” (off by default), the medication name and dose appear on your lock screen and may be visible to anyone who can see your screen.

We process your data under: consent (health data; analytics where required), performance of a contract (delivering the service you signed up for), legitimate interests (security, diagnostics), and legal obligation (tax records, breach notification), mapped per purpose above.

7. Sharing & disclosure / Subprocessors

We do not sell your personal data. We share data with the service providers (subprocessors) below, each acting under a data-processing agreement (DPA). DigitalOcean, Sentry, and PostHog are configured to the EU region.

SubprocessorRole / purposeData categoriesRegionTransfer mechanism
DigitalOcean Managed PostgresPrimary database, avatar storageall app data incl. health dataEU / FRA1 (Frankfurt)DigitalOcean DPA + SCCs
StripePayments, subscriptions (web only)billing, customer id, payment method (held by Stripe)US / globalSCCs / Stripe DPA
Expo (EAS) + Google FCM + Apple APNsPush notification deliverypush token, generic notification payload (no medication name by default)USSCCs / Apple & Google DPAs
PostHogProduct analytics, feature flagsusage / analytics, device (no health data, no medication names)EU CloudSCCs / region selection
SentryError & crash trackingdiagnostics (PII-scrubbed)EUSCCs / region
BrevoTransactional email (verification, password reset, trial / billing)email, nameFR / EUEU region (transfer minimized)
DigitalOcean (Kubernetes + Managed Redis + Container Registry)API + worker hosting + job queueall app data transiting the API; transient queue payloads (no medication name in push payload)EU / FRA1 (Frankfurt)DigitalOcean DPA + SCCs
VercelWeb app + marketing hostingtechnical, requestsUS / globalSCCs

8. Health Breach Notification (FTC HBNR)

Owlova is a covered “health app” under the FTC’s Health Breach Notification Rule. In the event of a breach of unsecured health data, we will notify affected individuals, the FTC, and — for large breaches — the media, within the timelines the Rule requires.

9. International transfers

Some data may be processed in the United States. For users in the EU/EEA and UK we rely on Standard Contractual Clauses (and the UK IDTA / adequacy where available); the transfer mechanism per provider is named in the subprocessor table above.

10. Data retention

We keep each category of data only as long as needed. In particular, your reminder/dose history is retained for 13 months, then purged; it is also deleted or anonymized earlier when you delete your account.

DataRetention
Account + health dataUntil account deletion. On deletion, PII is anonymized and medication/adherence rows are deleted or anonymized.
Reminder / dose historyRetained for 13 months, then purged; deleted/anonymized earlier on account deletion.
Billing records (anonymized)Retained for the legally required tax/accounting period (typically up to 7 years).
Acceptance recordsRetained for the life of the account and a reasonable period after, as proof of consent.
Analytics (PostHog)Per retention config (≤ 12 months); excludes health data.
Crash logs (Sentry)Per Sentry retention (default 90 days).
Push tokensUntil logout / uninstall or marked invalid.

11. Security

We protect your data with encryption in transit (TLS) and at rest (DigitalOcean Managed Postgres, EU/FRA1), access controls, and app-layer authorization. Medication data is never included in push notification payloads by default.

12. Your rights (GDPR / UK)

You have the right to:

  • access, rectify, erase, restrict, and port your data;
  • object to processing and withdraw consent at any time;
  • lodge a complaint with a supervisory authority.

You can exercise these in-app via Settings → Download my data (GET /v1/users/me/export) and Delete account (DELETE /v1/users/me), or by emailing privacy@owlova.com. Your statutory data export is always free.

13. Your rights (California — CCPA/CPRA)

California residents have the right to know, delete, and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and to non-discrimination for exercising these rights. Your health/medical data is “sensitive personal information.” We do not sell or share your personal information. To make a request, contact privacy@owlova.com.

14. Children's privacy

Owlova is not directed to children under 16. We do not knowingly collect data from anyone under 16 and will delete it on discovery.

15. Cookies & analytics

We use PostHog (product analytics) and Sentry (error tracking). On the marketing site, EU visitors are shown a cookie/consent banner. Analytics events are configured to exclude medication names and PII.

16. Changes to this policy

We will post changes here and update the effective date; material changes re-prompt acceptance in the app.

17. Contact & complaints

Email privacy@owlova.com. EU/EEA users may complain to their local supervisory authority; California users may contact the Attorney General. Governing law for any related terms is the Republic of Moldova.

18. Effective date / version

Version 2026-08-18 · effective 2026-08-18.