Privacy Notice
Version 1.12 · Last updated 6 October 2026 · QuoVira Health Ltd
Striova does not diagnose ADHD or any condition and is not a medical device or a substitute for professional medical advice.
This notice explains what personal data Striova collects about you and your child, why, how we protect it, and the rights you have. It is written to align with UK GDPR, the Data Protection Act 2018, and the ICO Children's Code.
1. Who we are
Striova is operated by QuoVira Health Ltd, a company registered in England and Wales (company number 17322340), registered office 128 City Road, London, United Kingdom, EC1V 2NX. We are the data controller for the personal data in this notice.
Privacy / data protection contact: [email protected]. We are registered with the Information Commissioner's Office (ICO), registration number ZC190656. General contact: [email protected].
2. Who this is about
Your child is the 'data subject' — the person the information is about — even though you provide most of it and make choices for them. Because their information reaches us from you, and from any teacher you invite, rather than from your child directly, section 3 sets out both what we collect and where it comes from. We also publish a short, plain-English summary written for children — you'll find it linked at the end of this notice, and we'd encourage you to read it with your child.
This notice covers:
- You — the parent or legal guardian who uses the account.
- Your child — whose observations you record; you make choices on their behalf.
- Teachers — if you invite one to add observations via a secure link.
3. The data we collect
Account data about you: name, email, securely hashed password, subscription status, and a payment-provider reference (we never store your card number).
Child data — including special-category health data: minimised identity (first name, last initial, optional date of birth, year group, optional sex, referral status, optional UK nation — so we use the right name for your child's plan); observations and health-related data (the SOR, behaviour check-ins, food/additive logs, sleep & activity from a wearable, medication & supplement records, blood-test values and uploads, teacher observations); your referral details (which service, and the dates you give us) and your answers to the referral check-ins; any referral date a clinician you have shared with confirms; and summaries Striova derives from these.
Ethnicity — only if you choose to give it. This is special-category data (racial or ethnic origin). We ask for it in broad ONS groups for one purpose only: so that anonymised research can check whether support is reaching families fairly. It is never required, you can leave it blank or remove it at any time, and it is never used to make decisions about your child.
Consent records (what you agreed to, when, and the version) and limited technical/security data. We do not use advertising or third-party tracking cookies — section 11 lists the few we do set, and why.
Where it comes from: most of this comes from you. Observations about your child may also come from a teacher you invite, and sleep or activity data may come from a wearable you connect. Nothing comes from anywhere else — we don't buy data or collect it from third parties.
Do you have to provide it? Your name, email and password are needed to create and secure your account — without them we can't provide Striova. Everything else about your child is your choice: optional details (date of birth, sex, ethnicity, school, which UK nation you live in), wearable data, and research sharing can all be left out or turned off, and Striova still works.
4. Why we use it & our lawful bases
We use data only where the law allows. For your child's health data we rely on your EXPLICIT consent (UK GDPR Article 9(2)(a)).
You can withdraw any consent at any time, and it's as easy to withdraw as it was to give. Withdrawing stops us using your data that way from then on — it doesn't make what we did beforehand unlawful, and it doesn't affect processing that rests on a different basis, such as keeping financial records we're legally required to hold.
- Run your account & provide the service — contract.
- Process your child's health observations — contract + explicit consent.
- Payment & subscription — contract; financial records — legal obligation.
- Security, abuse prevention, fixing faults — legitimate interests.
- Improving Striova with anonymised data — optional consent, off by default.
- Counting your entries in combined statistics for the NHS and local councils — optional explicit consent (Articles 6(1)(a) and 9(2)(a)), off by default and separate from the research consent. Nothing is shared yet (see section 8).
5. Decision-support, not diagnosis
Striova calculates summaries, insights and a plain-language 'morning summary' from what you enter. These are prompts to help you reflect and prepare — never a diagnosis, and not solely-automated decisions with legal or similarly significant effects.
6. Who we share data with
We do not sell your data. We share it only with:
- Service providers acting on our instructions under contract — hosting (DigitalOcean, London region), content delivery and bot protection (Cloudflare), payments (Stripe; Apple and Google for in-app purchases), transactional email (Microsoft 365) and error monitoring (Sentry). Messages you send our support team are held in our own systems, not a third-party helpdesk.
- Teachers you invite — what they need to record an observation. Separately, you can switch on a read-only snapshot of today's food and last night's sleep for a particular teacher; it is off unless you turn it on, covers nothing else, and you can switch it off at any time.
- Your child's school, if you connect it — only the items you switch on for that school, each off until you turn it on. That can include section 19 documents you upload (a council referral form, letters from your child's doctors), which the school's SEN staff can download to send to your council; a copy the school has saved is then held by the school under its own records policy.
- Clinicians you grant access to — read-only, one child, revocable by you. A clinician you have shared with can also confirm a referral date, such as the day their service received the referral; you see it beside your own dates, attributed to them, and it never changes what you entered.
- Where required by law or to protect someone's safety.
7. Where it's stored, and when it leaves the UK
Your child's record is stored in the United Kingdom. Messages you send our support team are stored there too, and so is any picture you attach to one.
Two things involve processing outside the UK. Payments are handled by Stripe (US/global) — this covers your billing details only, never your child's health data. And if you use the optional AI features — identifying a food from a photo, or drafting a summary — that content is sent to our AI provider (Anthropic, US) to produce the result. You can use Striova without those features.
Where personal data leaves the UK we use the transfer protections UK law requires — the UK International Data Transfer Agreement, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified — together with an assessment of the risks of that transfer.
Error monitoring (Sentry) is hosted in the EEA, which the UK recognises as offering equivalent protection, so no additional transfer safeguard is needed.
8. Anonymised research
Only if you give the optional research consent, your data may help improve Striova — and only as anonymised, aggregated statistics where no individual can be identified (no names or IDs; small groups suppressed). Once anonymised, this is no longer personal data, so it may be kept even after you leave. You can withdraw this consent at any time.
Statistics for the NHS and local councils — separately, and only if you tick the optional consent "Help improve services for families like yours", your entries may be counted in combined statistics about where families are waiting and what support is missing, to be shared with the NHS and local councils. They would only ever see totals from many families — never your name, your child's name, or anything that could identify you. Nothing is shared yet: this is a later piece of work, and this notice will be updated before anything is. You can change your mind at any time in Settings.
9. How long we keep it
Account and child data: while active, plus a short wind-down; deleted promptly on erasure. Financial records: as required by law (typically up to 6 years), billing metadata only. Consent and erasure-confirmation records: kept as proof we acted lawfully (no health content). Backups: short rolling cycle. Anonymised aggregates: retained (not personal data).
If you stop using Striova entirely, we delete your account and your child's records 36 months after your last activity. We email you 30 days before that happens, and signing in keeps everything.
Support requests: kept for 24 months after the request is closed, so we can recognise a recurring problem. Pictures you attach to a request are deleted sooner — 30 days after it is closed.
Security records: a record of each attempt to sign in to your account (when, what kind of device and network address, and whether it worked — never your password or code), and a record of the emails we send you and whether they were delivered. Kept for 90 days, then deleted automatically.
10. How we protect it
We use measures appropriate to children's health data — encryption of sensitive tokens, private storage with time-limited access, access controls, and UK hosting. We work to detect and respond to incidents, including notifying the ICO and affected people where the law requires.
If you send us a picture with a support request, we store it in our own UK storage. Only our support team can open it, every time one of them does it is recorded, and we delete it 30 days after your request is closed. You can delete it yourself at any time from your request, and nothing automated ever reads it.
11. Cookies and similar technologies
We use a small number of cookies, and only ones that are needed to make Striova work. We do not use cookies for advertising, and we do not use any analytics or tracking service — the usage figures we look at are counted inside our own database and never leave it.
Because every cookie below is strictly necessary to provide a service you asked for, UK law does not require us to ask your permission for them, and you will not see a cookie pop-up. If we ever add anything that is not strictly necessary, we will ask first — and it will be as easy to decline as to accept.
- Sign-in — keeps you signed in as you move between pages. Deleted when you sign out.
- Private preview — while Striova is invitation-only, remembers that you entered the preview password so you are not asked on every page.
- Bot protection (Cloudflare) — a short-lived cookie that helps tell real visitors from automated traffic. It expires after about half an hour and cannot be read by scripts.
- Anti-spam check (Cloudflare Turnstile) — runs on our contact form only, to stop automated submissions. It is a privacy-preserving alternative to the usual 'pick the traffic lights' test and is not used to track you.
12. Children's data
An adult uses Striova on a child's behalf. We follow the ICO Children's Code: data minimisation, high-privacy defaults, no detrimental use, and clear transparency. We don't use nudges to weaken privacy, and the optional research consent is off by default.
13. Your rights
You have the right to:
- Be informed (this notice) and access a copy — download it in Privacy & consent.
- Rectify inaccurate data — edit in the app.
- Erase your data — Privacy & consent → Delete your account.
- Portability — the export is machine-readable JSON.
- Restrict or object to certain processing, and withdraw consent at any time.
- We respond within one month, normally free of charge.
14. Complaints
If you think we have handled your or your child's personal data wrongly, you can complain to us. Use the support form in the app or at striova.co.uk/contact, email [email protected], or write to QuoVira Health Ltd, 128 City Road, London EC1V 2NX.
We will acknowledge your complaint within 30 days of receiving it, look into it, keep you informed if it takes time, and tell you the outcome without undue delay. This is our duty under section 164A of the Data Protection Act 2018.
You can also complain to the Information Commissioner's Office (ICO) at any time: ico.org.uk/make-a-complaint, helpline 0303 123 1113. You do not have to complain to us first.
15. Changes
We may update this notice. If changes are material — for example new ways we use children's data — we'll tell you in the app and, where appropriate, ask for fresh consent.
For children and young people
We publish a short, plain-English version of this notice written for children. Read “Privacy, explained simply”.