π¬π§ English | π·πΊ Π ΡΡΡΠΊΠ°Ρ Π²Π΅ΡΡΠΈΡ
Tenora is a personal blood pressure, pulse, blood glucose and weight diary. This policy explains what information the app works with, where it is stored, when it can ever leave your device, and what choices and rights you have. Tenora is not a medical device and does not provide medical advice, diagnosis or treatment recommendations.
neverForLocation flag, which Tenora uses.Tenora does not collect your precise location, contacts, microphone audio, or files outside its own storage, and it has no analytics or crash-reporting SDK collecting usage data at this time.
All health readings, profile information, medications and settings are stored only on your device,
in a local database encrypted with SQLCipher (AES-256). The encryption key itself is protected by the Android
Keystore. This data is deliberately excluded from Android's automatic device backup and from device-to-device
transfer (allowBackup="false"), so it is never copied anywhere by the operating system without your own
action.
Tenora has no server of its own. Your health data can only leave your device when you take one of these actions:
| Where it goes | What is sent | When |
|---|---|---|
| Your own Google Drive | A JSON backup (optionally password-encrypted) and, if you choose, PDF/CSV copies of your last 30 days | Manual backup, or scheduled auto-backup you turned on. Tenora only requests the drive.file and drive.appdata scopes β it can read/write only the files it created itself, never your other Drive content. |
| A folder you choose on your device | The same export files | Auto-export to a folder, if you turned it on |
| Another app, or a printer | An export file (CSV/PDF/JSON) | When you tap Share or Print |
| Health Connect | The health types you approved, in the direction you chose | Sync you turned on. Stays on your device. |
| Google Play | Purchase/subscription data | When you buy or check your Pro status |
| Google AdMob (free version only) | Advertising/device identifiers, per Google's SDK | When a full-screen ad is shown |
Your health data is never sent to the advertising module: in Tenora's own code architecture, the ads component has no dependency on the database or data layer, so it has no technical means to access your readings.
The first time you use Tenora, the app asks for your explicit consent to process health data on your device, consistent with GDPR's approach to special-category data. You can withdraw this consent at any time from Privacy settings, which also lets you delete all data stored by the app.
Tenora relies on the following services, each governed by its own provider's privacy policy:
General information about how Google uses data from apps that use its services: policies.google.com/privacy and policies.google.com/technologies/ads.
Health data is encrypted at rest (SQLCipher, AES-256, Android-Keystore-protected key) and Tenora only communicates over encrypted connections (HTTPS) β the app's network security configuration does not permit unencrypted ("cleartext") traffic.
Tenora is not directed at children and its intended audience is adults. A profile's date of birth is used only to select the correct health-classification scale for that profile (for example, whether paediatric or adult blood pressure ranges apply) β it does not change who may use the app.
Tenora helps you keep a personal diary and shows general, internationally recognised classification ranges (such as ESC/AHA/ADA) for context. It does not diagnose any condition, does not replace professional medical advice, and you should always consult a qualified healthcare professional about your health.
If Tenora starts using a new data-processing service (for example, crash reporting or analytics), this policy will be updated before that change ships, and the effective date above will change accordingly.
Questions about this policy or your data: ua.mixerapps@gmail.com