Legal

Privacy Policy

This Privacy Policy explains how the Tervi Android app handles information. The developer identified on Tervi’s Google Play listing is responsible for the app and is referred to below as the Developer.

1. Privacy at a glance

Tervi has no Android internet permission. The app has no account system, advertising SDK, analytics SDK, tracking SDK, telemetry, medication cloud synchronization, or developer-operated backend. Tervi cannot automatically transmit medication records, profiles, usage events, identifiers, or crash logs to the Developer.

2. Information stored locally

Depending on the features you use, Tervi stores the following in private app storage on your device:

This information is used on the device to provide the features you request. It is not received by the Developer through Tervi.

3. Storage and security

Medication data and recorded activity are stored in an encrypted SQLCipher database. Sensitive preferences and database key material are protected using Android Keystore-backed encryption. PIN verification material is salted and hashed. So that reminders can still fire after a restart before the phone is unlocked for the first time, Tervi keeps a minimal reminder copy in Android device-protected storage: internal medication identifiers, weekdays, times, and which scheduled doses are already handled. Medicine names, doses, profile details, supply values, and history are not part of that copy, and it stays on the device. Android cloud backup is disabled for Tervi. No security measure is absolute, so protect the device with a screen lock and install security updates.

4. Permissions and Android services

Tervi may request notification, exact-alarm, full-screen-intent, vibration, wake-lock, boot-event, biometric, and foreground-service permissions. The foreground service is declared for media playback and is used only to play reminder sound. These permissions are used to schedule and present reminders or protect access to the app. Android performs biometric matching; Tervi does not receive biometric templates. Android and Google Play may process device or store information under their own terms, independently of Tervi.

5. Notifications

Tervi asks Android to treat notification content as private and uses generic public lock-screen text. The full-screen alarm reminder style is different: when you choose it for a reminder, the alarm screen can appear over a locked device and shows the medicine name so the reminder is usable. Choose a different reminder style if you do not want that. Your Android and device settings ultimately control what is displayed, whether sound is played, and when a notification is delivered.

6. Files you export or share

Backups, PDF reports, crash logs, screenshots, and other files are created or shared only after you choose the relevant action. The Android system picker or share sheet sends the selected file to the destination you choose. After export, the file is outside Tervi’s private encrypted storage and may be handled by another app, storage provider, or recipient under their own privacy terms.

7. External links

If you open a community, source-code, store, or other external link, Android passes that link to a browser or another app. That service may collect information under its own privacy policy. Tervi does not receive the resulting browsing information.

8. Support communications

Tervi does not automatically send diagnostics. If you voluntarily contact the Developer through email, Google Play, a community, or another external service, the Developer may receive the contact details and content you choose to provide. That external service processes the communication under its own terms. The Developer may use it to respond, investigate the issue, prevent abuse, or meet legal obligations, and retain it only as long as reasonably needed for those purposes.

9. Retention and deletion

Local information remains until you edit it, delete it, clear Tervi’s storage, or uninstall Tervi. Delete all data removes Tervi’s database, preferences, cached exports, and local crash log from that device. Files already exported elsewhere must be deleted separately from their destination.

10. Your controls

You can view and correct records in Tervi, export a portable backup, delete individual records, or delete all app data. Because the Developer does not possess the local records, the Developer cannot inspect, recover, correct, export, or remotely erase them for you.

11. Other people’s information and children

Enter another person’s information only when you have authority to do so. Tervi is not directed to children under 13 or a higher minimum age required where they live. A parent or authorized guardian is responsible for any dependent profile they create.

12. Sale, sharing, profiling, and automated decisions

Tervi does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile users. The guided Assistant follows fixed local navigation and does not make automated clinical or eligibility decisions.

13. International transfers and privacy requests

Tervi does not transfer local app records to the Developer or to another country. A service you independently choose for export, sharing, browsing, or support may process information in other countries under its own terms. Privacy requests concerning information held by such a service must be directed to that service.

14. Changes to this Policy

This Policy will be updated before Tervi introduces materially different collection, telemetry, accounts, advertising, sharing, or cloud features. The effective date appears at the top. Material changes may be shown in the app.

15. Contact

For privacy questions, use the Developer contact published on Tervi’s Google Play listing.