Legal
Privacy Policy
Information on the processing of your personal data
This English version is a convenience translation. The legally binding version is the German original available at Datenschutz.
1. Data controller
Simon-Daniel März
Steinweg 2
34376 Immenhausen
E-Mail: [email protected]
Telefon: +49 170 29 12 189
2. Overview of processing activities
The following overview summarises the types of data processed and the purposes of processing, and references the individuals concerned.
Types of data processed
- Inventory data (for example name, email address)
- Usage data (for example pages visited, access times)
- Meta and communication data (for example IP address, device information)
- Health related data (for example cycle data, mood, sleep, nutrition, sport)
- Optional approximate location data (from a city or postal code you select yourself)
- Payment and transaction data (for example product, amount, currency, status and provider reference)
- Content data (for example contact messages and optionally companion conversations or analysis text)
Categories of affected persons
- Users of the web app
- Visitors to the website
- People who contact us or use an optional feature
3. Relevant legal bases
Below you will find an overview of the legal bases under the GDPR on which we process personal data:
- Consent (Art. 6 para. 1 sentence 1 lit. a GDPR) The data subject has given consent to the processing of personal data concerning them.
- Contract performance (Art. 6 para. 1 sentence 1 lit. b GDPR) Processing is necessary for the performance of a contract or for the implementation of pre contractual measures.
- Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) Processing is necessary for secure and reliable provision, abuse prevention, troubleshooting, assertion or defence of legal claims, and broad product improvement, unless the interests or fundamental rights of the data subject prevail.
- Explicit consent for health data (Art. 9 para. 2 lit. a GDPR) Health, cycle, and tracking data is synchronized and processed for optional analyses or sharing only on the basis of the separately described explicit consent.
- Legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR) Processing is necessary where statutory retention, tax, security, or information obligations apply.
4. Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons.
Data is transmitted over HTTPS/TLS. Cloud synchronization stores a compressed copy on our self-managed backend, where it is encrypted server-side at rest with AES-256-GCM. This is not end-to-end encryption. Separately stored analyses and coach projections are also encrypted at rest with AES-256-GCM.
5. Local app and browser storage
BodySeasons stores locally only the app data needed for operation and display. After your express consent, health, cycle, and tracking data is automatically synchronized with your personal account or anonymous backup profile. For automatic weather observations, you can voluntarily choose a city or postal code; device location access is not requested. Optional data flows such as analyses or coach sharing are described in the following sections.
Locally stored app data
- Cycle configuration (phase lengths, cycle start)
- App, notification, and theme settings
- Language choice, non-secret account metadata, and local notice states
You can remove local browser data through the browser or device settings. This does not delete cloud data or your account; use account deletion in the app or contact us for that.
6. Cloud storage
BodySeasons requires a personal account or anonymous backup profile. Only after your express consent, health, cycle, tracking, and settings data is automatically synchronized as a compressed copy with our self-managed backend for app functionality. This enables data backup and cross-device use in particular. Processing is based on Art. 6(1)(a) GDPR and, for health data, additionally on Art. 9(2)(a) GDPR.
You can withdraw your consent for the future at any time. Because automatic synchronization is part of the core operation, withdrawal ends further use of the profile. You can export your data first. Account deletion under Settings, Profile, Account and data removes the account and associated data from active storage; alternatively, contact us with a deletion or withdrawal request. Processing before withdrawal remains lawful.
7. Authentication and profiles
Access is available by email and password, Google OAuth 2.0, Sign in with Apple, or an anonymous backup profile. With Google OAuth 2.0, the following data is transmitted from Google to us:
- Email address
- Name (display name)
- Stable Google user ID
- One-time authorization code for the sign-in process
This data is used exclusively for authentication and assignment of your account. The legal basis is Art. 6 para. 1 sentence 1 lit. b GDPR (contract performance).
For more information on data protection at Google, please see: https://policies.google.com/privacy
If you sign in with your Apple ID (Sign in with Apple), Apple transmits an identity token and, optionally, your name to us. This data is used exclusively for authentication and account assignment. Apple offers to hide your email address behind an anonymized relay address.
8. Local browser storage and cookies
On the web, BodySeasons stores non-secret account metadata in localStorage. Session, refresh, and anonymous recovery tokens are kept only in sessionStorage for the current tab and, as a fallback, in memory; they are not stored persistently in localStorage. In the native apps, these secrets are held in operating-system protected storage. BodySeasons also sets one functional cookie for the language choice. After a tagged campaign visit, we store a minimized first campaign attribution in local browser storage only with your separate consent. BodySeasons uses no third-party advertising trackers or advertising cookies.
Storage technologies used
- Login session and sign-out: On the web, session, refresh, and anonymous recovery tokens survive an ordinary reload only in the current tab. Closing the tab ends that locally restorable session. Non-secret account metadata may remain locally until sign-out. Native apps store the tokens device-bound in Keychain or Keystore. Signing out revokes the current server session and clears local and protected authentication storage.
- Language choice, campaign attribution, and external sign-in: The functional mpb_locale cookie stores the language choice for up to one year. With your consent, localStorage stores the minimized first campaign attribution for no more than 90 days and the consent status until withdrawal. When you sign in through Google or Apple, those providers may process cookies on their own domains under their respective policies.
Storage access required for the requested digital service, especially sign-in, language, operating preferences, and local reminders, does not require additional cookie consent under section 25(2)(2) TDDDG. By contrast, we store the voluntary local campaign attribution only after your consent under section 25(1) TDDDG. You can withdraw it together with voluntary usage and success measurement in settings at any time.
9. Push notifications
After permission on your device or in your browser, BodySeasons can display local reminders. In native apps, they are scheduled on the device; on the web, they appear only while the browser or installed web app is running. You can withdraw permission at any time in the device, browser, or app settings.
BodySeasons does not operate a push server for this and does not process push device tokens. Only your notification settings and the timing and delivery state needed on the relevant device are stored.
10. Provision, logs and contact
We self-manage the application and origin systems for account, cycle, and cloud data. Publicly accessible web requests pass through Cloudflare for DNS, TLS, delivery, WAF, and DDoS protection. Technical access data such as IP address, time, requested path, response status, and device or browser information is processed in the process. Our own technical container logs are rotated by size and overwritten when their configured file limits are exceeded; individual security or evidence events may be retained longer where necessary. Legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.
If you use the contact form, we process your name, email address, category, subject, and message to respond to your request. The message is forwarded through our configured email system to the BodySeasons contact mailbox. We keep it there until the request is completed and afterwards only where statutory retention, abuse prevention, or the assertion or defence of claims requires it. Depending on the request, the legal basis is Art. 6 para. 1 sentence 1 lit. b or f GDPR; statutory retention is based on lit. c.
We do not sell personal data and do not use Google Ads, Meta Pixel, Facebook or Instagram advertising trackers, or third-party web analytics. Links to social networks are ordinary external links; the relevant provider processes the request under its own responsibility only after you open one.
11. Rights of data subjects
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether personal data is being processed.
- Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your data.
- Right to restriction (Art. 18 GDPR): You have the right to request the restriction of processing.
- Right to data portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used and machine readable format.
- Right to object (Art. 21 GDPR): You have the right to object to the processing at any time.
- Right to withdraw consent (Art. 7 para. 3 GDPR): You have the right to withdraw any consent given at any time.
- Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.
12. Deletion of data
The data we process is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations stand in the way. Local data can be deleted by you at any time. Cloud data is removed upon request or when the account is deleted. You can also delete your account and the associated personal data at any time directly in the app under Settings, Profile, Account and data; there you can also export your cycle data as a machine-readable file.
If you disconnect a coach or withdraw sharing permission, the coach immediately loses access. Sharing data stored for that connection is removed from active server storage immediately. Backup copies are not available for regular access and are removed within no more than seven days.
When an account is deleted, its cloud content is cleared first, all active sessions are ended, and the account is removed from active use. Associated data on our servers is then deleted. Technically required deletion, security, and billing evidence, as well as transaction data subject to statutory retention, may remain separately and purpose-bound until the relevant obligation expires.
13. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your next visit.
14. Voluntary usage and success measurement
With your consent, we record the Berlin calendar day, the iOS, Android, or Web platform, the number of app starts on that day, and whether notifications are enabled for product improvement. After a valid tagged campaign contact, the first attribution may also store source, medium, campaign, optional content, provider, platform, and capture time (capturedAt). The dataset is linked to your account in the backend through the internal user ID. We do not add a click ID, advertising ID, referrer address, IP address, browser identifier, user-agent identifier, health or cycle data, or free text as fields; technical connection data may arise separately under section 10.
- The voluntary usage and campaign data is stored on self-managed systems for no more than 90 days. The restricted internal operations dashboard may show the sign-in email address, plain-text account ID, and registration time for account support and campaign attribution. Name, health or cycle data, and free text are not displayed there as part of this measurement.
- The evaluation is used to improve the app and for self-operated success measurement. Missing data is not estimated; in particular, an unrecorded platform is not classified as Web. We measure registrations attributed to an account, not app installations. Cost per attributed registration is calculated only when matching spend data from the advertising provider is available and otherwise remains marked as unavailable.
- This usage and campaign data is not shared with advertising providers or other third parties and is not sold for advertising. In particular, BodySeasons does not send it back to Meta, Microsoft, Google, or Apple. Feature-specific transfers occur only as described in section 17.
- You can withdraw this consent at any time in the settings. Legal basis is Art. 6 para. 1 s. 1 lit. a GDPR.
15. Optional free text in analyses
Analyses are created from structured cycle and tracking data by default. Optionally, you can select copies of individual cycle reflections, notes, custom sport descriptions, and custom foods as additional context. The analysis remains usable without these texts, although it may contain less personal context.
Your own texts are disabled by default. Before each individual analysis, you see the date and source, can edit or deselect every copy, and must then give separate consent for that specific processing run. Stored original entries are not changed, and approval is not reused after cancellation, a purchase interruption, or a retry.
Approved copies are first technically prefiltered on our servers. We then transfer them separately from structured analysis data and without a separately attached user ID, account name, account email, session data, date of birth, or exact age through OpenRouter to an isolated sanitizer. The result is checked on our servers and only then combined with structured data to create the analysis. Sanitizer output itself is not stored as an analysis or original text.
This multi-stage technical process aims for the greatest possible anonymization but cannot guarantee complete anonymity. A residual risk remains, especially when an approved text contains rare or indirectly identifying details. Your consent does not remove our data-protection responsibility; required data-processing and privacy agreements with service providers remain unaffected.
16. Personal AI companion: content, retention and fair use
For allowance management, capacity and abuse prevention, BodySeasons processes operational metadata only: user binding, plan, global weekly-window start and end, used and temporarily reserved character units, visible input and response lengths, technical input/output token counts, redeemed Lotus, a shortened session hash reference, request time, wait time, technical outcome, and warning, throttling, suspension and appeal status. Chat content, health data and the wording of an input are not stored for this counting and fair-use check.
Allowance management is necessary to provide the selected service (Art. 6(1)(b) GDPR). Content-free abuse and availability checks are based on our legitimate interest in a secure service that remains fairly available (Art. 6(1)(f) GDPR). Medically or urgently necessary information and real-world help options are delivered regardless of allowance or fair-use status.
Individual request events are retained for no more than 30 days. Weekly windows are retained for evidence and complaint handling for no more than 400 days. Completed or expired reservations are deleted after 30 days. Fair-use warnings, throttles, suspensions and appeals are deleted no later than 180 days after the last event. Unused Lotus character budget and its purchase allocation remain until used or until the account is deleted.
Chat messages are processed for the requested conversation. The history remains local in the App and is retained encrypted on the server for no more than 30 days for continuity and synchronization; no more than 50 conversations remain. Individual conversations can be deleted in the App. Account deletion also removes the associated companion data. Optional reminders are used only after activation and the required device permission.
An appeal can be requested in the App without submitting explanatory free text. The contact form or [email protected] is available for additional information. Support performs the review; a restriction is not imposed merely because a particular companion variant was selected.
Every personal companion is an AI system and its responses are generated automatically. Before and during use, BodySeasons clearly tells you that you are interacting with an AI system. This also serves the transparency obligation under Article 50 of Regulation (EU) 2024/1689 (AI Act), which has applied since 2 August 2026. Personal companions do not make legally binding or similarly significant automated decisions about you.
All personal companions use a private BodySeasons worker, a locally operated llama.cpp language model, and local Lumi RAG on our own AI server. Companion messages, prompts, conversation history, reminders, and optional tracking-tool results are not transferred to OpenRouter or another third-party model provider. The OpenRouter data flow described in section 17 applies only to a cycle or monthly analysis that you request separately, not to companion conversations.
17. Recipients, service providers and third-country transfers
We use only those recipients and service providers needed for operations or features you deliberately choose. They receive the data described for their function:
- Payment processing (Stripe): Purchases through the web version are processed in Stripe-hosted Checkout. We transmit an internal user reference, product and Lotus information, and optionally an email address or existing Stripe customer ID. Stripe collects payment, billing-address, and where applicable tax-ID data. Card number and security code are entered directly with Stripe and are not processed by BodySeasons. We receive and store Stripe object IDs, product, amount, currency, and purchase, refund, or dispute status. Purchases in the iOS or Android app are processed by Apple or Google; you also manage cancellation there.
- Web delivery and abuse protection (Cloudflare): Cloudflare processes technical connection and security data for DNS, TLS, CDN, WAF, and DDoS protection when public web content is requested. Public tutorial videos are delivered through Cloudflare R2. During web registration and contact-form use, Turnstile processes a short-lived verification token and the IP address for abuse protection. In the current setup, R2 contains no private health or account data.
- Analyses (language-model service): When you request a cycle or monthly analysis, the selected structured cycle data is transmitted through OpenRouter to the documented model provider used for that analysis. Date of birth, birth year, and exact age are not transferred. Only after your separate consent for that analysis are the multi-stage filtered text copies described in section 15 processed as well. Without a requested analysis, no transmission takes place. This external data flow is not used for personal companions or companion conversations.
- Weather data (MET Norway): If you voluntarily choose a weather place and open today, our servers send coarsely rounded coordinates to MET Norway in Norway and receives current weather data. BodySeasons does not request your device location. You can remove the selection from your profile at any time.
- Sign-in (Google and Apple): Google or Apple processes sign-in and technical connection data only if you choose the respective sign-in method. BodySeasons does not use these providers for advertising. Google and Apple act under their own privacy policies for their sign-in area; only the identity data listed in section 7 is sent to BodySeasons.
- Email communication: Contact, confirmation, reset, or invitation messages are transmitted through our configured email system to the relevant mail servers. Sender and recipient address, subject, message, and technically required delivery information are processed.
Cloudflare, Stripe, Google, Apple, OpenRouter, and selected model providers may process data outside the European Economic Area, particularly in the United States. Where personal data is transferred to a third country, we rely on an applicable adequacy decision, especially the EU-US Data Privacy Framework for appropriately certified US recipients, or on appropriate safeguards such as EU Standard Contractual Clauses and any required supplementary measures. We provide information about the specifically applicable basis on request. MET Norway processes data in Norway and therefore within the European Economic Area.
The current integration of these services is feature-specific. There are no permanent advertising, profiling, or third-party analytics SDKs. Within our systems, we continue to treat pseudonymized or technically reduced data as protected and not automatically anonymous.
As of 11 August 2026
The other legal pages
Everything legal about BodySeasons sits together here.