Datenschutzerklärung
Stand: 30. Juli 2026
Liventra ist so gebaut, dass Datenschutz nicht die Ausnahme, sondern die Architektur ist. Deine Gesundheitsakte — Befunde, Werte, Medikamente, Termine, Dokumente — liegt auf deinem Gerät und optional in deiner eigenen iCloud. Es gibt keine Konten, kein Tracking, keine Werbung, keinen Verkauf oder keine Weitergabe deiner Daten. Diese Erklärung beschreibt die wenigen Fälle, in denen Informationen dein Gerät verlassen, und warum.
Was wir speichern — und wo
- Auf deinem Gerät: sämtliche Einträge deiner Akte sowie fotografierte oder gescannte Original-Dokumente. Der Datenbestand ist mit vollständigem Dateischutz (Apple Data Protection) abgelegt; der Zugriff auf die App ist durch Face ID/Code gesichert.
- In deiner iCloud (optional, Ende-zu-Ende-verschlüsselt): aktivierst du den iCloud-Sync, wandern deine Einträge als CloudKit encryptedValues und deine Dokumente als zusätzlich client-seitig verschlüsselte Anhänge (AES-GCM) in deine private iCloud. Die Schlüssel liegen ausschließlich in deinem iCloud-Schlüsselbund. Weder Apple noch wir können die Inhalte lesen — wir betreiben keinen eigenen Speicher.
Texterkennung von Dokumenten
Das Auslesen von Befunden (Texterkennung und Werte-Extraktion) passiert ausschließlich auf deinem Gerät. Kein Dokument wird dafür jemals an einen Server geschickt — das ist eine feste Regel der App, keine Einstellung.
KI-Chat
Für Fragen an deine Akte gibt es zwei Wege, die du in den Einstellungen wählst:
- Auf dem Gerät: Antworten entstehen offline mit Apple Intelligence. Nichts verlässt das Gerät.
- Liventra AI (Cloud, Pro): Vor jedem Senden zeigt dir die App exakt, welche Einträge in die Anfrage eingehen; du kannst einzelne entfernen und auf Wunsch Name und Geburtsdatum automatisch entfernen lassen. Nur diese bestätigten Angaben werden über unseren Proxy (einen Cloudflare Worker) an Googles Gemini-API weitergeleitet und die Antwort zurückgestreamt. Der Proxy ist zustandslos und inhalts-blind: Er speichert und protokolliert weder Anfragen noch Antworten, sondern führt nur anonyme Zähler pro Gerät für Fair-Use-Limits. Google verarbeitet die Daten gemäß den Gemini-API-Bedingungen und der Google-Datenschutzerklärung.
Missbrauchsschutz (Apple App Attest)
Anfragen an Liventra AI werden mit Apples App Attest verifiziert. Das bestätigt, dass die Anfrage von einer echten, unveränderten Kopie der App stammt. Dabei kommt ein gerätegebundener kryptografischer Schlüssel zum Einsatz — er identifiziert weder dich noch gibt er persönliche Informationen preis.
Pro-Abo
Liventra Pro ist ein optionaler Kauf, den vollständig Apple abwickelt; Zahlungsdaten erreichen uns nie. Zum Freischalten der Liventra-AI-Kontingente sendet dein Gerät Apples kryptografisch signierte Kaufbestätigung an unseren Proxy, der sie prüft und nur eine anonyme Geräte-Kennung samt Kontingent-Zählern speichert — ohne Bezug zu Name, E-Mail oder Apple-ID.
Apple Health
Verbindest du Apple Health, liest Liventra die von dir freigegebenen Werte (z. B. Puls, Gewicht) nur lesend und speichert sie lokal in deiner Akte. Es findet keine Übertragung von Health-Daten an uns oder Dritte statt. Hochfrequente Werte werden als Tagesmittelwerte übernommen.
Was wir nicht tun
- Keine Konten, keine Registrierung.
- Keine Analyse-, Tracking- oder Werbe-SDKs; keine Telemetrie.
- Kein Verkauf, keine Vermietung, keine Weitergabe deiner Daten.
- Keine Server, auf denen deine Akte liegt.
Löschen & Mitnahme
Du kannst deine gesamte Akte jederzeit in der App vollständig löschen (Einstellungen → Gefahrenzone) — das entfernt Datenbank, Dokumente und Schlüssel vom Gerät; bei aktiviertem Sync auch die Daten in deiner iCloud. Über den FHIR-Export und das verschlüsselte Backup nimmst du deine Daten jederzeit vollständig mit.
Deine Rechte & Kontakt
Da deine Daten bei dir liegen, übst du Auskunft, Berichtigung und Löschung direkt in der App aus. Für alle Fragen zum Datenschutz erreichst du uns unter hello.liventra@picode.at.
Verantwortlich: Patrick Bergmann · picode, Österreich.
Privacy Policy
Last updated: 30 July 2026
Liventra is built so that privacy is the architecture, not an exception. Your health record — reports, values, medication, appointments, documents — lives on your device and, optionally, in your own iCloud. There are no accounts, no tracking, no ads, and no selling or sharing of your data. This policy explains the few cases where information leaves your device, and why.
What we store, and where
- On your device: every entry of your record plus photographed or scanned original documents, stored with full file protection (Apple Data Protection); app access is guarded by Face ID/passcode.
- In your iCloud (optional, end-to-end encrypted): with iCloud sync enabled, your entries travel as CloudKit encryptedValues and your documents as additionally client-side encrypted attachments (AES-GCM) into your private iCloud. The keys live exclusively in your iCloud keychain. Neither Apple nor we can read the contents — we operate no storage of our own.
Document text recognition
Reading out reports (text recognition and value extraction) happens exclusively on your device. No document is ever sent to a server for this — a hard rule of the app, not a setting.
AI chat
There are two ways to ask questions about your record, selectable in Settings:
- On-device: answers are generated offline with Apple Intelligence. Nothing leaves the device.
- Liventra AI (cloud, Pro): before every send, the app shows you exactly which entries enter the request; you can remove individual ones and optionally strip your name and date of birth. Only these confirmed details are forwarded through our proxy (a Cloudflare Worker) to Google's Gemini API, and the answer is streamed back. The proxy is stateless and content-blind: it neither stores nor logs requests or responses, keeping only anonymous per-device counters for fair-use limits. Google processes the data per the Gemini API terms and the Google Privacy Policy.
Abuse prevention (Apple App Attest)
Requests to Liventra AI are verified with Apple's App Attest, confirming they come from a genuine, unmodified copy of the app. This uses a device-bound cryptographic key that neither identifies you nor reveals personal information.
Pro subscription
Liventra Pro is an optional purchase handled entirely by Apple; payment details never reach us. To unlock Liventra AI allowances, your device sends Apple's cryptographically signed receipt to our proxy, which verifies it and stores only an anonymous device identifier plus allowance counters — with no link to your name, email or Apple ID.
Apple Health
If you connect Apple Health, Liventra reads the values you grant (e.g. heart rate, weight) read-only and stores them locally in your record. No Health data is transmitted to us or third parties. High-frequency values are imported as daily averages.
What we do not do
- No accounts, no registration.
- No analytics, tracking or advertising SDKs; no telemetry.
- No selling, renting or sharing of your data.
- No servers holding your record.
Deletion & portability
You can wipe your entire record in the app at any time (Settings → Danger zone) — removing database, documents and keys from the device, and with sync enabled also the data in your iCloud. The FHIR export and the encrypted backup let you take your complete data with you at any time.
Your rights & contact
Since your data stays with you, access, correction and deletion happen directly in the app. For any privacy questions, reach us at hello.liventra@picode.at.
Responsible: Patrick Bergmann · picode, Austria.