Privacy Policy

Effective date: 21 May 2026
Last updated: 31 May 2026

This Privacy Policy explains how the Evora iOS app ("Evora", "we", "us") processes information when you use it. Evora is a calm AI wellness companion that helps you log meals, hydration, sleep and body data and provides personalized insights. Privacy is a core design principle: most of your data stays on your device, and AI processing happens on‑device whenever possible.

1. Who we are

Controller:
KSol.IT
Maximilian Kenfenheuer
maximilian.kenfenheuer@ksol.it

If you have any question about this policy or your data, please contact us at the address above.

2. Summary at a glance

What Where it lives Shared with third parties?
Profile, goals, diet, allergies On your device (SwiftData) + your private iCloud (CloudKit) No
Meals, drinks, sleep, weight you log On your device + your private iCloud (optional) + Apple Health (optional) No
Apple Health data we read Apple Health on your device only No
Meal photo for recognition Sent to our analysis service only for one-off analysis, not stored AI sub-processors — see §6
Free-text meal description Sent to our analysis service for one-off analysis, not stored AI sub-processors — see §6
Barcode Sent to Open Food Facts (public food database) Open Food Facts
Push token Apple Push Notification service Apple
Purchases Apple (App Store / StoreKit) Apple
Device-integrity attestation (App Attest) Apple + our API, for app authentication only Apple
Analytics / advertising / tracking None

Evora does not use analytics, advertising SDKs, or cross‑app/cross‑site tracking. We do not sell your data.

3. Data we process

3.1 Data you enter into the app

This data is stored locally on your device using Apple's SwiftData framework. If you have iCloud enabled, it can sync via CloudKit to your private iCloud database. We have no access to your CloudKit data — only you (signed in with your Apple ID) do.

3.2 Apple Health (HealthKit)

If you grant permission, Evora reads from Apple Health:

Evora writes to Apple Health (so your logs stay in one place):

Background delivery is enabled to keep the home view current. HealthKit data never leaves your device — it is not sent to our servers or any third party. Samples that Evora writes to Apple Health are tagged so they can be cleaned up if you delete the corresponding entry in the app.

3.3 Camera and photos

If you use meal capture by photo, the camera is used to take a picture (with your permission). The photo is then either processed locally on the device by Apple's on‑device AI (Apple Foundation Models) or, where on‑device recognition is unavailable or fails, sent to our analysis service (see §3.6) for one‑off analysis. Photos are not stored on our servers after analysis. You may optionally keep the photo locally with the meal entry.

3.4 Barcode scanning

When you scan a product barcode, only the barcode number is sent to Open Food Facts — a free, public, crowd-sourced food database — to look up product name, brand and nutrition. No personal data is sent. Open Food Facts' privacy policy is available on their website.

3.5 On‑device AI (Apple Foundation Models)

For meal planning suggestions and coach insights, Evora primarily uses Apple Foundation Models, which run entirely on your device. No prompt, input or output leaves your device for this processing.

3.6 Cloud AI analysis service

Some features require server-side processing. The Evora analysis service is operated by KSol.IT in the EU and is used for:

What we do not send to the service: your name, email, Apple ID, device identifiers used for tracking, raw HealthKit samples, your full meal history, your profile (allergies/diet are only sent when needed for the specific request), photos that are not part of an analysis request.

The service does not have user accounts; we do not maintain a server-side profile of you. Request data is processed transiently and not persisted beyond what is technically necessary to fulfil the request and short-term operational logs (see §7).

Server-side AI inference is performed by trusted sub-processors (LLM and vision providers) under data-processing terms that prohibit use of submitted content for training their models. See §6.

3.7 Push notifications

If you enable notifications, Apple Push Notification service (APNs) assigns a device token. We use it only to deliver Evora's own reminders (hydration, daily briefing). We do not share it.

3.8 In‑app purchases

Purchases (Plus / Pro subscriptions) are handled by Apple via StoreKit 2. We do not receive your payment information. We only receive a receipt confirming whether you have an active subscription.

3.9 Diagnostics

Evora does not use third-party analytics or crash-reporting SDKs (no Firebase, no Sentry, no Mixpanel, no Meta/Google SDKs). If you opted in to share crash data with Apple via iOS Settings, Apple may share aggregate, anonymized crash reports with us via App Store Connect.

3.10 Device integrity (app authentication)

To protect the analysis service from abuse and to control the cost of AI processing, the app verifies that it is a genuine, unmodified copy of Evora running on a real Apple device before it calls our API. This uses Apple's App Attest (DeviceCheck) framework:

Where GDPR applies, we rely on the following legal bases (Art. 6 / Art. 9 GDPR):

Health data is Article 9 special-category data. It is processed only on the basis of your explicit consent and, with respect to HealthKit data, never leaves your device.

5. How long we keep data

6. Sub-processors and third parties

Provider Purpose Data
Apple (iCloud / CloudKit) Private sync of your app data Your app data, end‑to‑end under your Apple ID
Apple (HealthKit) Local health data store Health data (never leaves device via Evora)
Apple (APNs) Push notifications Push token
Apple (App Store / StoreKit) Purchases Purchase receipt
Apple (App Attest / DeviceCheck) App & device integrity for API authentication Per-install attestation (no personal data)
Open Food Facts Barcode → product lookup Barcode only
Trusted AI sub-processors LLM / vision inference for meal analysis and coaching Submitted text/image, transient, no training
EU cloud hosting provider Run the Evora analysis service Request data, transient

We use the zero data retention / no training modes of AI providers where available.

7. International transfers

Evora's analysis service is operated by KSol.IT in the EU. AI sub-processors may process content outside the EU/EEA (e.g. in the United States). Where applicable, transfers are protected by EU Standard Contractual Clauses and additional safeguards. Apple processes data according to its own terms; iCloud data is stored in regions chosen by Apple.

8. Security

No system is perfectly secure. Please keep your device updated and protect it with a passcode/Face ID.

9. Your rights

Under GDPR (and equivalent rights in other regions, including the UK GDPR and CCPA in California), you have the right to:

Because most of your data is stored locally on your device or in your private iCloud, you can exercise most of these rights directly:

For any request that cannot be fulfilled directly in iOS, contact maximilian.kenfenheuer@ksol.it. We respond within 30 days.

10. Children

Evora is not directed at children under 16. We do not knowingly process data of children under 16. If you believe a child has provided data, please contact us so we can delete it.

11. Automated decision-making

Evora's AI features produce informational suggestions about meals, hydration and recovery. They are not medical advice and have no legal or similarly significant effect on you. You can ignore any suggestion. Evora does not perform profiling within the meaning of Art. 22 GDPR.

12. Not a medical device

Evora is a wellness and self-tracking app. It is not a medical device and does not diagnose, treat, cure or prevent any disease. Always consult a qualified healthcare professional for medical decisions.

13. Changes to this policy

We may update this policy as the app evolves. When we do, we will update the "Last updated" date above and, for material changes, notify you in-app.

14. Contact

KSol.IT — Maximilian Kenfenheuer
Email: maximilian.kenfenheuer@ksol.it