Legal
Joriva is a metabolic health platform built for diabetes patients managing serious illness and the family members who support them. We take the privacy of your health information seriously. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and what rights you have over it.
Please read this policy carefully before using the Joriva app. By creating an account and using Joriva, you agree to the practices described here.
Joriva is operated by Our Goose Community LLC, a South Carolina limited liability company doing business as Joriva. We are a direct-to-consumer health technology company — not a healthcare provider, health insurance plan, or healthcare clearinghouse.
Joriva is not covered by HIPAA. We say this not to disclaim responsibility for your health data, but to be transparent about the legal framework that applies to us.
HIPAA applies to healthcare providers, health insurance plans, healthcare clearinghouses, and their business associates. Joriva is none of these things. You enter your own health data into Joriva voluntarily, using your own device, for your own personal management and caregiving purposes. This is confirmed by HHS guidance.
What law does apply to us: The FTC Health Breach Notification Rule (as amended July 29, 2024) explicitly covers health apps like Joriva. We are also subject to the FTC Act and applicable state privacy laws.
We have voluntarily adopted data security practices — encrypted transit, access controls, secure credential storage — consistent with responsible health data stewardship.
This is the core of what Joriva stores. You enter this data voluntarily or it is read from your device's health platform with your explicit permission:
Background glucose collection: If you grant Joriva permission to read glucose data from Apple HealthKit, Joriva registers a background-delivery observer for blood glucose. With your permission, your device may wake Joriva in the background — including while the app is in the background or suspended and not actively open on your screen — when a new glucose reading becomes available, so that Joriva can read that reading and sync it to our servers. This keeps any linked caregiver's view current without requiring you to open the app. Background collection applies to blood glucose only, occurs only while you have granted Joriva HealthKit permission, and stops if you revoke that permission in your device's Health settings.
When you search for foods in the meal log, your search terms are sent to the USDA FoodData Central API and/or the Open Food Facts API. No personal health information is sent to these services — only the food name you search for.
If you purchase a Joriva subscription, we collect and process:
We use a subscription-management service, RevenueCat, to process this information (see Section 6). Your health data is never sent to RevenueCat, Apple, or Google as part of subscription processing, and we do not enable advertising identifiers (IDFA/IDFV) or advertising integrations in our subscription tooling. Payment card details are handled entirely by Apple or Google — Joriva never sees them.
We use your health and account information for the following purposes, and no others:
We do not sell your health data. We do not share it with advertisers. We do not share it with data brokers. We never send health-related information — glucose readings, food logs, medications, or any other health metric — to advertising or marketing technologies.
We share information only in the following limited circumstances:
| Recipient | What They Receive | Why |
|---|---|---|
| Your linked caregiver | Your glucose readings, logs, and alerts | You explicitly authorized this by accepting the caregiver link |
| Render | Your encrypted data stored on PostgreSQL servers in the United States | Our database host |
| RevenueCat | Subscription status and purchase history for Joriva subscriptions, a pseudonymous subscriber identifier, and your device's locale and currency code | Subscription management (tier entitlement, trials, renewals); RevenueCat never receives your health data, and we do not enable its advertising-identifier or analytics integrations |
| Apple / Google | In-app purchase transaction records | Required for App Store and Google Play billing |
| Expo | Your device push token and notification content (glucose value and alert type) | Delivery of glucose alerts to your device |
| Google Workspace (Google LLC) | Your account email address and the content of transactional emails we send you (for example, a one-time password reset code) | Transactional email delivery. If you request a password reset, we send a one-time code to your account email through our Google Workspace email service. We do not send marketing email through this or any other service. |
| USDA FoodData Central | Food search terms only | Retrieving nutritional data for meal logging |
| Open Food Facts | Food search terms only | Retrieving nutritional data for meal logging |
We may also disclose information if required by law or court order, but we will notify you before doing so unless legally prohibited.
If you link a caregiver to your account, that caregiver can view your glucose readings as they sync from your device, your historical readings, and your logged medications, insulin, meals, exercise, symptoms, blood pressure, weight, and treatment events, as well as your glucose alerts.
Linked caregivers can also create health log entries on your behalf — for example, logging a meal or medication when you are unable to do so yourself. Every entry created by a caregiver is attributed to them so you can always see who logged what.
You control this relationship. You initiated it by accepting a caregiver invite, and you can terminate it at any time from the Settings screen. Termination immediately revokes your caregiver's access to your data and their ability to log entries on your behalf.
Your health data is stored in a PostgreSQL database hosted by Render in the United States. We use the following security practices:
No system is perfectly secure. We encourage you to use a strong, unique password and to notify us at privacy@joriva.health if you suspect unauthorized access.
We retain your health data as long as your account is active. If you delete your account, we will delete your health records, log entries, caregiver links, and device registrations within 30 days. Account deletion can be requested by emailing privacy@joriva.health.
De-identified data (which cannot reasonably be linked back to you) may be retained and used after account deletion for product development, as described in Section 5.
Server logs (which do not contain health data) are retained for up to 90 days for debugging purposes.
Joriva is intended for adults. You must be at least 18 years old to create an account, consistent with our Terms of Service. We do not knowingly collect personal information from anyone under 18 as an account holder. The App may be used to manage the health of a minor patient by a parent, legal guardian, or authorized caregiver who maintains the account.
Consistent with the Children's Online Privacy Protection Act (COPPA), we additionally do not knowingly collect personal information directly from children under 13. If you believe a child under 13 has created an account, please contact us at privacy@joriva.health and we will delete the account.
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:
To exercise these rights, email privacy@joriva.health with the subject line "CCPA Request."
If you are a Washington resident, the Washington My Health My Data Act (MHMDA) provides specific rights regarding your "consumer health data" — information that identifies your past, present, or future physical or mental health status. The health data you enter into Joriva falls within this category.
Under MHMDA, you have the right to:
We collect consumer health data only with your consent and only to provide the Joriva service to you. We obtain your consent to collect this data separately from any consent to share it. We do not sell consumer health data, and we do not collect geolocation data or use geofencing around health care facilities.
To exercise these rights, email privacy@joriva.health with the subject line "Washington Health Data Request." We will respond to verified requests within 45 days, as MHMDA provides. If we decline all or part of a request, you may appeal our decision — the appeal process is described in our standalone policy below.
Our full Consumer Health Data Privacy Policy for Washington residents — the categories of consumer health data we collect, our sources and purposes, our sharing practices, and the appeal process — is published as a standalone document.
We may update this Privacy Policy as the app evolves or as laws change. If we make material changes, we will notify you by email or through a prominent notice in the app at least 14 days before the change takes effect. Continued use of Joriva after the effective date constitutes your acceptance of the updated policy.
Questions about this policy or your data:
Our Goose Community LLC (Joriva)
privacy@joriva.health
joriva.health
We will acknowledge privacy requests promptly and respond within the timeframes required by applicable law (generally within 45 days).