1. Introduction

Joriva is a metabolic health platform built for diabetes patients managing serious illness and the family members who support them. We take the privacy of your health information seriously. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and what rights you have over it.

Please read this policy carefully before using the Joriva app. By creating an account and using Joriva, you agree to the practices described here.

2. Who We Are

Joriva is operated by Our Goose Community LLC, a South Carolina limited liability company doing business as Joriva. We are a direct-to-consumer health technology company — not a healthcare provider, health insurance plan, or healthcare clearinghouse.

3. Important Note on HIPAA

Joriva is not covered by HIPAA. We say this not to disclaim responsibility for your health data, but to be transparent about the legal framework that applies to us.

HIPAA applies to healthcare providers, health insurance plans, healthcare clearinghouses, and their business associates. Joriva is none of these things. You enter your own health data into Joriva voluntarily, using your own device, for your own personal management and caregiving purposes. This is confirmed by HHS guidance.

What law does apply to us: The FTC Health Breach Notification Rule (as amended July 29, 2024) explicitly covers health apps like Joriva. We are also subject to the FTC Act and applicable state privacy laws.

We have voluntarily adopted data security practices — encrypted transit, access controls, secure credential storage — consistent with responsible health data stewardship.

4. What Information We Collect

4.1 Health and Wellness Data

This is the core of what Joriva stores. You enter this data voluntarily or it is read from your device's health platform with your explicit permission:

  • Glucose readings: CGM readings via Apple HealthKit or Android Health Connect, manual finger-prick readings, and historical readings imported via CSV
  • Medications: Name, dose, unit, timing, and notes
  • Medication schedule in your calendar (optional): If you turn on "Add to my calendar" in the medication schedule screen, Joriva creates a "Joriva Medications" calendar on your device and adds an entry for each scheduled dose (medication name, dose, and time). These entries are written to your device's calendar and are then handled by your calendar account (for example iCloud or Google) under that provider's terms — including any calendar sharing you have set up. Joriva does not receive or read your other calendar entries. Turning the feature off removes the entries Joriva created.
  • Insulin: Dose, type, administration timing, injection site
  • Meals: Food items, portion sizes, and macronutrient data (calories, carbohydrates, protein, fat, fiber, sugar)
  • Exercise: Type, duration, intensity, and estimated calories burned
  • Symptoms: Type, severity, and timing
  • Mood (optional): A self-reported mood rating on a 1–5 scale with an optional note, if you choose to log it. Mood entries can only be logged by you (never by a caregiver on your behalf) and, like your other log entries, are visible to your linked caregiver
  • Blood pressure: Systolic/diastolic readings and pulse
  • Weight: Recorded weight entries over time
  • Sleep and passive health signals (optional): If you turn on "Sleep & Activity" in Settings, Joriva reads the following from Apple Health (iOS) or Android Health Connect to display alongside your glucose: sleep sessions (minutes asleep and in bed), heart rate variability (HRV), resting heart rate, respiratory rate, and workouts (the exercise type, duration, and active energy burned). These are shown for informational context only — they are not a stress score or a medical measurement — and are read only while the feature is enabled. You can turn it off at any time to stop this collection.
  • Treatment events: Cancer treatment cycles, procedures, medications administered by your care team, and other clinical events you choose to log
  • Notes: Free-text notes you attach to any log entry
  • Entry attribution: When a linked caregiver logs a health entry on your behalf, we record which user created the entry so you can distinguish between your own entries and those entered by your caregiver
  • Computed analytics data: Joriva derives and stores analytical outputs calculated from your logged data, including: your personal glucose percentile curves by hour of day (glucotype profile), per-meal glucose response scores (peak rise, area under curve, impact category), behavioral comparison insights (e.g. average glucose on days with vs. without exercise), and personalized dietary and behavioral suggestions. These are computed values derived from your data and stored to power the Insights screen — they are not entered by you directly

Background glucose collection: If you grant Joriva permission to read glucose data from Apple HealthKit, Joriva registers a background-delivery observer for blood glucose. With your permission, your device may wake Joriva in the background — including while the app is in the background or suspended and not actively open on your screen — when a new glucose reading becomes available, so that Joriva can read that reading and sync it to our servers. This keeps any linked caregiver's view current without requiring you to open the app. Background collection applies to blood glucose only, occurs only while you have granted Joriva HealthKit permission, and stops if you revoke that permission in your device's Health settings.

4.2 Account Information

  • Email address, name, and password (stored as a one-way cryptographic hash — we cannot recover or read it)
  • Your role: patient, caregiver, or both
  • Account creation date and last active timestamp

4.3 Caregiver Linking Information

  • The caregiver invite code you use to link accounts
  • The linked caregiver's name and relationship to you, if you provide it
  • Alert preferences and notification settings for the caregiver relationship

4.4 Clinical Profile Information

  • Your diagnosed conditions and treatment context (e.g., cancer type and treatment stage)
  • Your personal glucose target range (low and high thresholds you set in onboarding)
  • Your doctor's name and appointment dates, if you enter them for report generation

4.5 Device Information

  • Your device's push notification token (used only to deliver glucose alerts)
  • Device name as registered in the app
  • Date of last active session
  • Your device's time zone, which updates when you sign in (used to deliver daily summaries at the right local time and to show log times in the correct local time)

4.6 Food Database Query Terms

When you search for foods in the meal log, your search terms are sent to the USDA FoodData Central API and/or the Open Food Facts API. No personal health information is sent to these services — only the food name you search for.

4.7 Information We Do Not Collect

  • We do not collect your location
  • We do not use advertising networks
  • We do not use third-party analytics SDKs that collect behavioral data
  • Beyond blood glucose, we read additional Apple HealthKit (iOS) / Android Health Connect data only when you turn on the optional "Sleep & Activity" feature — currently sleep sessions, heart rate variability (HRV), resting heart rate, respiratory rate, and workouts (exercise type, duration, and active energy burned) (see Section 4.1). We do not read any other health data types from Apple HealthKit or Android Health Connect without your explicit permission

5. How We Use Your Information

We use your health and account information for the following purposes, and no others:

  • Displaying your data to you in the Patient View
  • Sharing with your caregiver if you have linked one — you control this relationship
  • Sending glucose alerts when readings cross your personal thresholds
  • Sending operational and reminder notifications — in addition to glucose alerts, we may send push notifications that help you and your caregiver stay informed and keep your records current: a daily summary of your recent glucose data; a notice if your glucose data stops updating (so a gap is not mistaken for a stable reading); and gentle, optional reminders to log entries — for example, a morning prompt to log your medications, generated from your own past log entries, a dose-time reminder generated from a medication schedule you define, or a suggestion generated from a workout detected through the optional Sleep & Activity feature. Dose-time reminders and workout suggestions are created locally on your device and are not sent through a notification service. These reminders are rule-based (no automated profiling or decision-making about you) and are delivered through the same push-notification service as glucose alerts. A caregiver can control which of these they receive in their notification settings, and you can turn off notifications at the operating-system level at any time.
  • Generating doctor reports on request — reports are not stored after delivery
  • Improving system reliability via server error logs that do not contain your health data
  • Responding to your support requests sent to support@joriva.health
  • Product development (de-identified data): We may create, retain, and use de-identified data derived from your logged data to develop and improve Joriva's features, including future analytics capabilities. It is processed using recognized standards (Safe Harbor or Expert Determination) so it cannot reasonably be linked back to you, and may be retained even if you later delete your account.
  • Future research contributions (opt-in only): De-identified data may in the future be shared with academic or non-profit research institutions. No such sharing is currently active. You will be given a clear opt-in opportunity before any of your data is included.

6. How We Share Your Information

We do not sell your health data. We do not share it with advertisers. We do not share it with data brokers.

We share information only in the following limited circumstances:

Recipient What They Receive Why
Your linked caregiver Your glucose readings, logs, and alerts You explicitly authorized this by accepting the caregiver link
Render Your encrypted data stored on PostgreSQL servers in the United States Our database host
RevenueCat Subscription status and a pseudonymous user identifier Subscription management; no health data shared
Apple / Google In-app purchase transaction records Required for App Store and Google Play billing
Expo Your device push token and notification content (glucose value and alert type) Delivery of glucose alerts to your device
Google Workspace (Google LLC) Your account email address and the content of transactional emails we send you (for example, a one-time password reset code) Transactional email delivery. If you request a password reset, we send a one-time code to your account email through our Google Workspace email service. We do not send marketing email through this or any other service.
USDA FoodData Central Food search terms only Retrieving nutritional data for meal logging
Open Food Facts Food search terms only Retrieving nutritional data for meal logging

We may also disclose information if required by law or court order, but we will notify you before doing so unless legally prohibited.

7. Caregiver Access

If you link a caregiver to your account, that caregiver can view your glucose readings as they sync from your device, your historical readings, and your logged medications, insulin, meals, exercise, symptoms, blood pressure, weight, and treatment events, as well as your glucose alerts.

Linked caregivers can also create health log entries on your behalf — for example, logging a meal or medication when you are unable to do so yourself. Every entry created by a caregiver is attributed to them so you can always see who logged what.

You control this relationship. You initiated it by accepting a caregiver invite, and you can terminate it at any time from the Settings screen. Termination immediately revokes your caregiver's access to your data and their ability to log entries on your behalf.

8. Data Storage and Security

Your health data is stored in a PostgreSQL database hosted by Render in the United States. We use the following security practices:

  • Passwords: Stored only as a one-way cryptographic hash. We cannot read or recover your password.
  • Authentication tokens: Session tokens are stored securely on your device using the platform's protected storage (iOS Secure Enclave / Android Keystore).
  • Data in transit: All communication between the app and our backend occurs over encrypted connections (HTTPS/TLS).
  • Access controls: Only authenticated, authorized accounts can access data.

No system is perfectly secure. We encourage you to use a strong, unique password and to notify us at privacy@joriva.health if you suspect unauthorized access.

9. Data Retention

We retain your health data as long as your account is active. If you delete your account, we will delete your health records, log entries, caregiver links, and device registrations within 30 days. Account deletion can be requested by emailing privacy@joriva.health.

De-identified data (which cannot reasonably be linked back to you) may be retained and used after account deletion for product development, as described in Section 5.

Server logs (which do not contain health data) are retained for up to 90 days for debugging purposes.

10. Age Requirement and Children's Privacy

Joriva is intended for adults. You must be at least 18 years old to create an account, consistent with our Terms of Service. We do not knowingly collect personal information from anyone under 18 as an account holder. The App may be used to manage the health of a minor patient by a parent, legal guardian, or authorized caregiver who maintains the account.

Consistent with the Children's Online Privacy Protection Act (COPPA), we additionally do not knowingly collect personal information directly from children under 13. If you believe a child under 13 has created an account, please contact us at privacy@joriva.health and we will delete the account.

11. California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:

  • Right to know: You may request a summary of the categories of personal information we have collected and the purposes for which we use it.
  • Right to delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to opt out of sale: We do not sell personal information. There is nothing to opt out of.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, email privacy@joriva.health with the subject line "CCPA Request."

12. Washington Residents — Consumer Health Data (My Health My Data Act)

If you are a Washington resident, the Washington My Health My Data Act (MHMDA) provides specific rights regarding your "consumer health data" — information that identifies your past, present, or future physical or mental health status. The health data you enter into Joriva falls within this category.

Under MHMDA, you have the right to:

  • Confirm whether we collect, share, or sell your consumer health data, and to access that data
  • Withdraw consent to our collection and sharing of your consumer health data
  • Delete your consumer health data, including from our affiliates and processors
  • Obtain a list of the third parties and affiliates with whom we have shared your consumer health data

We collect consumer health data only with your consent and only to provide the Joriva service to you. We obtain your consent to collect this data separately from any consent to share it. We do not sell consumer health data, and we do not collect geolocation data or use geofencing around health care facilities.

To exercise these rights, email privacy@joriva.health with the subject line "Washington Health Data Request."

13. Changes to This Policy

We may update this Privacy Policy as the app evolves or as laws change. If we make material changes, we will notify you by email or through a prominent notice in the app at least 14 days before the change takes effect. Continued use of Joriva after the effective date constitutes your acceptance of the updated policy.

14. Contact Us

Questions about this policy or your data:

Our Goose Community LLC (Joriva)
privacy@joriva.health
joriva.health

We will acknowledge privacy requests promptly and respond within the timeframes required by applicable law (generally within 45 days).