This Privacy Policy explains how Shiver ("Shiver", "the app", "we", "us", or "our") handles information in connection with your use of the Shiver: Cold Shower Challenge iOS application (bundle identifier xyz.bogtsi.shiver). Shiver is developed and operated by an individual developer based in Israel (the "Developer").
We built Shiver to be private by design. Shiver has no user accounts, no login, and no backend server operated by us. The data you create in the app stays on your device. The only information leaving your device is handled by the third-party service described below, under its own privacy policy.
Shiver is operated by a solo developer based in Israel. For any privacy question or request, contact us at bogdan.tsiganiyk@gmail.com.
The following information is created and stored only on your device, in a local SQLite database inside the app's own sandbox. It is never transmitted to us — we operate no server to receive it — and we cannot access it:
Because this data lives only on your device, it is removed when you delete the app, or when you use Clear all data in Shiver's Developer/Settings tools. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's policies.
If you enable the daily reminder, Shiver schedules a local notification on your device only, generated and delivered on-device. We use no push tokens and send no remote push notifications.
Shiver Pro can export your session history as a CSV file. When you tap Export, the app writes the file to its own temporary storage on your device and hands it to the standard iOS share sheet. Where the file goes next is entirely your choice — Files, Mail, another app — and that destination's handling of the file is governed by whatever app or service you choose. The file is not sent anywhere by us.
Shiver relies on a small number of third-party services. When you use the app, some of these services may collect or process data directly, under their own privacy policies. We map each one below.
| Service | When it applies | What it processes | Purpose |
|---|---|---|---|
| RevenueCat | When you start, restore, or manage a Shiver Pro subscription | Purchase and subscription data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No session, mood, or health data is ever sent to RevenueCat. | To process purchases, validate receipts, and unlock Pro features |
| Apple / App Store | Download, updates, and in-app purchases | Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. | App distribution and payment processing |
| Expo / EAS | App build, distribution, and over-the-air updates | Used to build and ship the app and to deliver JavaScript updates; the app sends no personal data to Expo at runtime as part of Shiver's features | To build and ship app updates |
We use no analytics or crash-reporting SDKs of our own (no Firebase, Sentry, Amplitude, or similar), and Shiver's own code makes no network requests to any server we operate.
Shiver Pro includes an optional, write-only Apple Health sync, off by default. If you turn it on in Settings, Shiver asks Apple Health for permission to write only — it requests no permission to read any Health data, and no such permission is ever granted or used. Each time you complete a shower session, Shiver writes a single "mindful minutes" sample (Apple's HKCategoryTypeIdentifierMindfulSession category) covering that session's duration to Apple Health, stored in your device's own Health app. Data flows one way only — from Shiver into Health — and only while the toggle is on; we never read your Health data, your Health data is never sent to us or to any third party, and you can turn the toggle off, or delete any of these entries directly in the Health app, at any time.
Shiver contains no advertising and no advertising SDK. The app displays no ads, contains no third-party ad or tracking framework, and does not collect or use the advertising identifier (IDFA). Because nothing in the app tracks you, Shiver never presents Apple's App Tracking Transparency prompt. If advertising were ever introduced in a future version, this Privacy Policy would be updated before it shipped.
The services above process data under their own privacy policies, which we encourage you to review:
We ourselves do not collect or receive your personal data on any server. Information is used only for the purposes described above: providing app features on-device (the timer, session log, plan progress, streaks, stats, reminders) and processing subscriptions. We do not sell your personal data, and we do not use it for advertising or profiling.
Data stored locally on your device is retained until you delete it in the app, use Clear all data, or uninstall the app. Data processed by third parties (RevenueCat, Apple) is retained according to their respective policies.
Shiver is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). We do not knowingly collect personal information from children. In line with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's protections for children (GDPR-K), if you believe a child has provided personal information through the app, please contact us at bogdan.tsiganiyk@gmail.com and we will take appropriate steps.
The Developer is based in Israel. Shiver is available through the Apple App Store internationally. The third-party services we use (RevenueCat, Apple) may process data in various countries, including the United States, in accordance with their own policies and legal safeguards. Your session and settings data are not part of any such transfer — they never leave your device.
Because your app data stays on your device, its security is tied to your device's own protections (passcode, encryption, biometric lock). Data handled by third-party services is protected under their respective security practices. No method of storage or transmission is 100% secure.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.
Questions about this Privacy Policy or your data? Email bogdan.tsiganiyk@gmail.com.