Legal

Privacy Policy

How Cardiogram handles your data. Last updated 7 September 2026.

Who we are

Cardiogram is made by Qaly, Inc. ("Qaly", "we", "us", "our"). Qaly, Inc. is the data controller for the limited processing described below. You can reach us at support@cardiogram.pro.

Cardiogram is not a medical device and does not provide medical advice or a diagnosis. See our Terms of Service.

Health data from Apple Health

With your permission, Cardiogram reads two things from Apple Health (HealthKit) on your device:

Access is read-only. Cardiogram never writes any data back into Apple Health. You grant this access in iOS, and you can withdraw it at any time in Settings → Privacy & Security → Health → Cardiogram, or in the Health app under Sharing → Apps.

All analysis happens on your device. Health data read from HealthKit is not transmitted to us or to anyone else, and, per Apple's requirements, it is never used for advertising or marketing and is never sold.

If you enable heart-rate alerts, iOS may wake Cardiogram in the background to check new heart-rate samples against your thresholds. This happens locally on your device.

Data you enter in the app

Cardiogram lets you log symptoms, free-text notes, medications and doses, hydration, salt, sleep and temperature triggers, and stand test results. This information is stored in the app's local database and, if you have iCloud enabled on your device, synced through your own private iCloud database so it is available on your other devices.

That iCloud storage belongs to your Apple Account, not to us. Qaly, Inc. does not have access to your private iCloud journal through the Firebase dashboard or a company-operated journal server. Apple's handling of iCloud data is governed by Apple's Privacy Policy. You can turn the sync off by disabling iCloud for Cardiogram in iOS Settings, and you can delete the synced data by deleting the app data from iCloud storage settings.

Cardiogram also caches computed daily heart-rate summaries in a file inside its own app container on your device, and stores your preferences (such as alert thresholds and whether onboarding is complete) in local app settings. Both are removed when you delete the app. Note that, like other app data, these may be included in your device backups if you back up to iCloud or a computer.

Notifications

If you allow notifications, Cardiogram schedules them locally on your device. Apple also delivers silent CloudKit notifications for private iCloud sync. We do not operate an alert push server or add alert contents to diagnostic reports. Alert notifications can contain a heart rate value, which means it may appear on your lock screen — if that concerns you, you can hide notification previews in iOS Settings → Notifications.

Reports you export

Cardiogram can generate a PDF report from your data for a timeframe you choose. The report is created on your device and handed to the standard iOS share sheet. Where it goes next — Mail, Files, a messaging app, your doctor — is entirely your choice. We never receive a copy.

Subscriptions and payments

Cardiogram offers a paid subscription through the Apple App Store. Apple processes the purchase and handles billing; your payment method, card details, and billing address go to Apple, not to us. Cardiogram checks your subscription status locally against the App Store and stores only a yes/no flag on your device.

We receive from Apple the same aggregate and pseudonymised sales and subscription reporting that Apple provides to every developer. It is not linked to your health data, which we do not have. Apple's handling of your data is governed by Apple's Privacy Policy, and you can manage or cancel your subscription in the App Store.

Crash reporting and technical diagnostics

Release versions of Cardiogram automatically use Firebase Crashlytics, a Google service, to send crash reports and selected nonfatal errors. We use these reports to investigate crashes, failed database opening, and reliability problems. Reports can include stack traces, app version and build, operating-system version, device model, timestamps, and installation identifiers that associate reports from the same app installation. These reports are not anonymous.

We attach fixed startup-stage labels and database error domains and codes. We do not assign an account identifier or intentionally add heart-rate samples, workouts, symptoms, medications, journal notes, or database paths to custom reports. Original database error details are stripped before we report caught storage errors.

Reports are sent to Google and available to us in the Firebase Crashlytics dashboard. Reporting is automatic in release builds; there is currently no in-app switch to disable it. For questions or requests about diagnostics, contact support@cardiogram.pro. See Firebase's privacy and security information for its processing practices.

No accounts, no advertising, no cross-app tracking

To state plainly what the app does not do:

No sale or sharing for advertising

Qaly, Inc. does not sell your personal information, and does not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). We have not done so in the preceding twelve months. We also do not sell or share the personal information of anyone under 16.

This website

cardiogram.pro is a marketing website. It is separate from the app and does not have access to any app data. When you visit:

The website has no login, no newsletter sign-up, and no forms that collect personal information.

When you email us

If you write to support@cardiogram.pro, we receive your email address and whatever you choose to tell us, which may include health information you decide to share while describing a problem. We use it only to answer you, and we keep support correspondence no longer than we need it for that purpose and for our records.

Legal bases for processing (UK/EU)

Where the GDPR applies, we rely on: your explicit consent for the app to access health data through HealthKit, which you can withdraw at any time in iOS Settings; our legitimate interests in operating a secure website, understanding aggregate traffic, and diagnosing app crashes and reliability problems; the performance of a contract for providing the app and your subscription; and legitimate interests in responding to support requests you send us.

Retention

Data in the app stays on your device and in your iCloud for as long as you keep it. Deleting an entry deletes it; deleting the app removes its local data, and removing its iCloud data removes the synced copy. We do not hold a copy of those health records or journals. Deleting the app does not immediately remove reports already sent to Firebase. Firebase states that it retains crash traces and associated installation identifiers for 90 days before starting removal from live and backup systems. Website analytics follows our configured retention period, and support emails are kept only as long as needed.

International transfers

Qaly, Inc. is based in the United States. Your health records and journals stay on your device and in your private iCloud. Firebase diagnostics, website analytics, and email are handled by providers who may process data in the United States and other countries, using the safeguards those providers offer, such as the EU Standard Contractual Clauses.

Security

Your app data is protected primarily by your device and your Apple Account: your passcode or biometric lock, device encryption, and your iCloud security settings, including two-factor authentication. We encourage you to keep those enabled. No system is perfectly secure, but the architecture here is deliberate — the less data that leaves your device, the less there is to lose.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, to withdraw consent, and — under the CCPA/CPRA — to know what is collected, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

In practice, most of these you exercise directly on your device, because that is where your data lives: view and edit entries in the app, export a PDF for portability, revoke HealthKit access in iOS Settings, and delete data by removing entries, the app, or its iCloud storage.

For diagnostic reports, support correspondence, or questions about this policy, contact support@cardiogram.pro and we will respond within the timeframe the applicable law requires. We may need to verify your identity before acting on a request. You may also authorise an agent to make a request on your behalf. If you are in the EEA or UK, you have the right to complain to your local data protection authority.

Children

Cardiogram is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information — for example by emailing support — contact us and we will delete it.

Do Not Track

This website does not respond to Do Not Track browser signals. Because we do not sell or share personal information, an opt-out preference signal such as Global Privacy Control has nothing to act on here.

Changes to this policy

If we change how Cardiogram handles data, we will update this page and change the "Last updated" date at the top. For material changes, we will make the change prominent in the app or on this site before it takes effect.

Contact us

Questions about this policy or your data: support@cardiogram.pro.

Qaly, Inc. — maker of Cardiogram.