Privacy Policy
Information on the processing of your personal data
1. Data controller
Simon-Daniel März
Steinweg 2
34376 Immenhausen
E-Mail: [email protected]
Telefon: +49 170 29 12 189
2. Overview of processing activities
The following overview summarises the types of data processed and the purposes of processing, and references the individuals concerned.
Types of data processed
- Inventory data (for example name, email address)
- Usage data (for example pages visited, access times)
- Meta and communication data (for example IP address, device information)
- Health related data (for example cycle data, mood, sleep, nutrition, sport)
Categories of affected persons
- Users of the web app
- Visitors to the website
3. Relevant legal bases
Below you will find an overview of the legal bases under the GDPR on which we process personal data:
- Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) The data subject has given consent to the processing of personal data concerning them.
- Contract performance (Art. 6 para. 1 sentence 1 lit. b GDPR) Processing is necessary for the performance of a contract or for the implementation of pre contractual measures.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) Processing is necessary to protect the legitimate interests of the controller or of a third party.
4. Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons.
Data is transmitted over HTTPS/TLS. Cloud synchronization stores a compressed copy on our self-managed backend, where it is encrypted server-side at rest with AES-256-GCM. This is not end-to-end encryption. Separately stored AI reports and coach projections are also encrypted at rest with AES-256-GCM.
5. Local data storage
BodySeasons stores your cycle data, tracking entries and settings primarily locally in your browser (localStorage). Data is transferred only when you use a connected feature such as cloud sync, an AI report, optional weather data, or coach sharing; the relevant data flows are described in the following sections.
Data stored in localStorage
- Cycle configuration (phase lengths, cycle start)
- Daily entries (mood, sport, nutrition, sleep, energy, body data)
- App settings and theme preferences
You can delete this data at any time by removing the browser data for this website.
6. Cloud storage
If you activate the optional cloud storage feature, your data is compressed and stored on our servers. This is used exclusively for cross device synchronisation and data backup. Processing is based on your consent (Art. 6 para. 1 sentence 1 lit. a GDPR).
You can delete your cloud data at any time via the app settings.
7. Authentication with Google and Apple
We use Google OAuth 2.0 for login. The following data is transmitted from Google to us:
- Email address
- Name (display name)
- Profile picture URL
- Google user ID
This data is used exclusively for authentication and assignment of your account. The legal basis is Art. 6 para. 1 sentence 1 lit. b GDPR (contract performance).
For more information on data protection at Google, please see: https://policies.google.com/privacy
If you sign in with your Apple ID (Sign in with Apple), Apple transmits an identity token and, optionally, your name to us. This data is used exclusively for authentication and account assignment. Apple offers to hide your email address behind an anonymized relay address.
8. Local browser storage and cookies
On the web, BodySeasons persistently stores only non-secret account metadata in the browser; session, refresh, and anonymous recovery tokens remain in memory only. In the native apps, these secrets are held in operating-system protected storage. BodySeasons also sets one functional cookie for the language choice and no first-party tracking or advertising cookies.
Storage technologies used
- Login session and sign-out: On the web, session, refresh, and anonymous recovery tokens are lost when the page reloads; non-secret account metadata may remain locally until sign-out. Native apps store the tokens device-bound in Keychain or Keystore. Signing out revokes the current server session and clears local and protected authentication storage.
- Language choice and external sign-in: The functional mpb_locale cookie stores the language choice for up to one year. When you sign in through Google or Apple, those providers may process cookies on their own domains under their respective policies.
9. Push notifications
With your explicit consent, we may send you push notifications to remind you of daily entries. You can revoke consent at any time via your browser settings or the app settings.
Device tokens are processed for the delivery of push notifications. These are not used for any other purpose.
10. Hosting
The website and all associated services run on servers that we manage ourselves; we do not use external cloud platforms to store your cycle and account data. We do not sell your personal data and do not pass it on for advertising or tracking purposes. Technically necessary service providers receive only the data required for their respective function (see section 16). When you access the site, access data (IP address, time of access, requested page) is processed in server log files. This is done on the basis of our legitimate interests in efficient and secure provision (Art. 6 para. 1 sentence 1 lit. f GDPR).
11. Rights of data subjects
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether personal data is being processed.
- Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your data.
- Right to restriction (Art. 18 GDPR): You have the right to request the restriction of processing.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used and machine readable format.
- Right to object (Art. 21 GDPR): You have the right to object to the processing at any time.
- Right to withdraw consent (Art. 7 para. 3 GDPR): You have the right to withdraw any consent given at any time.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.
12. Deletion of data
The data we process is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations stand in the way. Local data can be deleted by you at any time. Cloud data is removed upon request or when the account is deleted. You can also delete your account and the associated personal data at any time directly in the app under Settings, Profile, Account and data; there you can also export your cycle data as a machine-readable file.
If you disconnect a coach or withdraw sharing permission, the coach immediately loses access. Sharing data stored for that connection is removed from active server storage immediately. Backup copies are not available for regular access and are removed within no more than seven days.
13. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your next visit.
14. Anonymized data usage & product improvement
With your consent we use your tracked content exclusively in anonymized, aggregated form to improve BodySeasons. You can grant or withdraw this consent at any time in the settings.
- Voluntary product improvement uses only anonymized, aggregated evaluations. Feature-specific transfers described in section 16 remain unaffected.
- The evaluation primarily serves to improve the app, the content and the AI reports for all users.
- We reserve the right to share anonymized aggregated datasets with third parties in the future (e.g. health insurers, research, health partners). Personal data is not sold; feature-specific transfers occur only as described in section 16.
- You can withdraw this consent at any time in the settings. Legal basis is Art. 6 para. 1 s. 1 lit. a GDPR.
15. Optional free text in AI reports
AI reports are created from structured cycle and tracking data by default. Optionally, you can select copies of individual cycle reflections, notes, custom sport descriptions, and custom foods as additional context. The report remains usable without these texts, although it may contain less personal context.
Your own texts are disabled by default. Before each individual report, you see the date and source, can edit or deselect every copy, and must then give separate consent for that specific processing run. Stored original entries are not changed, and approval is not reused after cancellation, a purchase interruption, or a retry.
Approved copies are first technically prefiltered in the BodySeasons middleware. The middleware then transfers them separately from structured report data and without a separately attached user ID, account name, account email, session data, date of birth, or exact age through OpenRouter to an isolated sanitizer. The result is checked locally in the middleware and only then combined with structured data for report creation. Sanitizer output itself is not stored as a report or original text.
This multi-stage technical process aims for the greatest possible anonymization but cannot guarantee complete anonymity. A residual risk remains, especially when an approved text contains rare or indirectly identifying details. Your consent does not remove our data-protection responsibility; required data-processing and privacy agreements with service providers remain unaffected.
16. Third-party services
For individual features we use carefully selected service providers. They receive only the data required for their respective function:
- Payment processing (Stripe): Purchases through the available web version are processed in Stripe-hosted Checkout. The email address and other information required for the purchase are transmitted to Stripe; card details are entered directly with Stripe and do not pass through BodySeasons. The iOS and Android store versions are in preparation; purchases and cancellations through Apple or Google are only available after the relevant store version is released and enabled.
- Weather data (Open-Meteo): Only if you enable the optional weather feature with location, your location coordinates are transmitted to the Open-Meteo weather service to retrieve the current weather. Without an enabled location, no transmission takes place.
- Spam protection (Cloudflare Turnstile): Web registration and the contact form are protected against automated abuse by Cloudflare Turnstile; a verification token is processed in the process.
- AI reports (language-model service): When you request an AI report, the selected structured cycle data is transmitted through OpenRouter to the documented model provider used for that report. Date of birth, birth year, and exact age are not transferred. Only after your separate consent for that report are the multi-stage filtered text copies described in section 15 processed as well. Without a requested report, no transmission takes place.
Last updated: July 2026 (Revised)