Privacy Policy
This Privacy Policy explains how Eltria UG (haftungsbeschränkt) ("we", "us"), operator of the Vetraya mobile application (the "Service"), collects, uses, shares, and protects personal data. It applies whenever you use the Service.
We are the data controller for the personal data described below. For questions about this policy or your rights, contact us at privacy@eltria.de.
1. Information We Collect
1.1 Information you give us directly
- Account information: your email address (obtained when you sign in with Apple, Google, or an email magic link — required to register your account), your name (required during onboarding; pre-filled from your Apple or Google profile if your provider supplies it, otherwise you enter it on the onboarding screen), and your date of birth (required because the Service is restricted to users 18 or older).
- Consent records: when you accept these policies, we record the version, timestamp, IP address, user agent, device information (platform, OS version, app version), the device locale at the time of acceptance, and the URL of the document version you could have viewed. This list is what GDPR Article 7 requires us to be able to demonstrate; the locale and document URL help us answer "which version of the policy did this user actually see?" if it is ever asked.
- Onboarding records: when you complete onboarding (entering your name and date of birth), we write an internal record noting the timestamp, the age that was implied by the date of birth you entered, and a non-reversible hash of the name. We do not store a second copy of the name itself in this record. If you later change your date of birth, we record both the previous and new values so a future support question can be reconstructed. These records are kept for 90 days and then deleted.
- Communications: messages you send us (support emails, feedback).
- Deletion feedback: if you provide a reason when deleting your account, we store it in pseudonymised form for product improvement.
1.2 Information from services you connect
You can optionally connect third-party services so the Service can analyse your digital footprint. We request only the minimum OAuth scopes needed and only fetch the data types listed:
| Source | Data fetched | Scopes requested |
|---|---|---|
| Apple Music (iOS only) | Your storefront (country), your recently-played tracks (up to 100), artists in your library (up to 100), and your "heavy rotation" content (up to 20 items). | MusicKit media-library permission via Apple's on-device prompt (a Music User Token; no OAuth scopes). We never see your Apple ID credentials. |
| Your username, account age, the subreddits you subscribe to, and up to 100 of your most recent comments and posts (text content included). | identity, read, history, mysubreddits |
|
| YouTube | Your channel ID (if you have one), channels you subscribe to, and up to 100 of your most recent liked videos (titles only). | youtube.readonly |
| Health (Apple Health on iOS, Google Health Connect on Android) | The last 90 days of your sleep records (total time asleep per night) and activity records (steps, distance, active energy, exercise minutes, workout types). We do not read sleep stage detail (REM, deep, core), heart rate, HRV, mindfulness, or mental-health data. | HealthKit permission on iOS (Apple's on-device prompt); Health Connect permission on Android (Google's on-device prompt). Same five categories on either platform. |
You choose which sources to connect. None is required. You can disconnect any source at any time; on disconnect we (a) delete the data we have stored from that source, (b) wipe our stored copy of your access tokens, and (c) where the provider offers a token-revoke endpoint, call it so the token is invalidated at the provider too. Reddit and Google (YouTube) both offer such endpoints and we use them. Apple Music does not offer a server-side revoke — deleting our stored Music User Token is what we control; to withdraw the permission at the source, disable media-library access for the app in iOS Settings → Privacy & Security → Media & Apple Music. The Service only accesses the data types listed and does not post, modify, or delete anything on the source platform.
YouTube API Services. The YouTube connection uses YouTube API Services. By connecting YouTube you are also agreeing to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy. We access, use, and store only the YouTube data items listed in the table above (channel ID, subscribed channels, liked-video titles); we retain them as described in §4 (24-hour cache, deleted on disconnect or account deletion) and share them only with the processors listed in §3. In addition to disconnecting in the app, you can revoke our access to your YouTube data at any time via Google's security settings page at myaccount.google.com/permissions.
Sharing your analysis. You can share an analysis with another person in two ways. (1) In-app sharing: generate a one-time code and give it to someone you trust out-of-band (text, messaging app, in person). When they enter the code in their app while signed in, they see the specific analysis you chose to share, frozen at the time you generated the code — later analyses you run are not shared automatically. The recipient must have a Vetraya account to redeem; codes do not work without one. Unredeemed codes expire after 7 days. (2) Public link: generate a URL anyone can view in a browser without an account. We do not index public links and they are not searchable, but anyone with the URL can view it (including someone the recipient forwards it to). You can revoke either kind of access at any time. We record share, redeem, and revoke events in our internal audit log so we can answer support questions about who could see what and when. We also record opens of shared analyses, de-duplicated to at most one record per hour per session — enough to evidence that an open occurred without accumulating a row per scroll.
1.3 Information we generate
- Your personality profile and any insights we derive
- Prompts we send to the AI provider and the responses we receive (used to generate your profile and to debug errors)
- Usage metadata (timestamps of analyses run, credit balances, subscription status)
1.4 Technical data
- Device data: device type, operating system, app version, push-notification token (if you enable notifications)
- Diagnostics: crash reports and error traces via Sentry, where enabled; these include stack traces and device context but are scrubbed of personally identifying fields
- Access tokens: a short-lived JWT access token (30 minutes) and a refresh token (7 days). Both are stored only on your device in encrypted local storage.
Product analytics (first-party). The mobile app records basic usage events so we can understand which parts of the Service work and which confuse people — for example "connect screen opened", "first-run step 2 reached", "footprint sheet opened". Each event consists of an event name, a small set of non-content properties (for example the step number or the screen name), your pseudonymous account identifier, a per-launch session identifier, the app version, and timestamps. Events never include the content of your connected sources, your profile text, your messages, or your health records. This is entirely first-party: the events go only to our own API and are stored in our own database (AWS Ireland); we use no third-party analytics SDK or service, no advertising identifiers, and no cross-app tracking, and the events are never sold, shared, or used for advertising. We process these events on the basis of our legitimate interest in improving the Service (Art. 6(1)(f) GDPR; see §2). Analytics is on by default; you can turn it off at any time in the app under Profile → Settings → Privacy Preferences → Product analytics — the off switch is enforced on our servers, which then refuse to store events from your account. Receiving a Global Privacy Control signal for your account also turns it off (see below). Stored events are deleted when you delete your account.
Cookies and tracking technologies. The mobile Service does not use cookies, IDFA, the Android Advertising ID, or cross-app tracking identifiers. The hosted web pages where this Privacy Policy, the Terms of Service, the Consumer Health Data Privacy Policy, the Security page, and the Accessibility statement live (the legal-pages/ static site) set no cookies of any kind — no analytics, no advertising, no session, no consent-banner. We have a continuous-integration test that asserts the hosted-policy pages remain cookie-clean after every deploy; if you ever observe a cookie being set on these pages, please report it to security@eltria.de.
Global Privacy Control (GPC). The Service honours the Global Privacy Control signal (`Sec-GPC: 1`). When we receive this header on an authenticated request from your browser or operating system, we record the receipt against your account. The signal is processed once per account; subsequent requests with the same header have no additional effect. We do not sell or share personal information for cross-context behavioural advertising, and there is no advertising in the Service. The one processing the signal can disable is our first-party product analytics described above: when we receive a GPC signal on an authenticated request from your account, we turn product analytics off for your account, exactly as if you had used the in-app toggle. You can turn it back on afterwards in Profile → Settings → Privacy Preferences if the signal did not reflect your preference. We keep the GPC receipt on file so that if we ever add a further feature the signal could disable, your recorded preference will apply to it automatically. The mobile app does not send Sec-GPC by default (in-app webviews and native fetches are excluded by the GPC specification).
2. How We Use Your Information
We process personal data for the following purposes and legal bases (GDPR Article 6):
| Purpose | Data used | Legal basis |
|---|---|---|
| Register and authenticate your account | Email address, date of birth, refresh tokens. When you sign in with Apple or Google, their server-side verification of your identity token (email + stable user identifier). | Performance of contract (Art. 6(1)(b)) |
| Generate your personality profile | Data from connected sources | Consent (Art. 6(1)(a)) — you choose to connect each source |
| Process payments | Billing records via Apple App Store (iOS) or Google Play (Android) | Performance of contract (Art. 6(1)(b)) |
| Comply with legal obligations | Audit records, consent history | Legal obligation (Art. 6(1)(c)) — GDPR Art. 7, Art. 30 |
| Diagnose crashes, improve the Service | Error traces, performance metrics | Legitimate interests (Art. 6(1)(f)) |
| Understand how the app is used (first-party product analytics, §1.4) | In-app usage events: event name, screen or step, pseudonymous account identifier, session identifier, app version, timestamps. Never the content of connected sources, profiles, or health records. | Legitimate interests (Art. 6(1)(f)) — you can object at any time via the in-app toggle (Profile → Settings → Privacy Preferences) or a GPC signal, and our servers then refuse to store events from your account |
| Compatibility reports between two consenting users (optional feature) | Your personality profile themes and headline traits, compared with those of one other user who invited you or whom you invited. Never health data, never raw connected-source data. | Consent (Art. 6(1)(a)) — creating an invite or redeeming one is the explicit consent of each participant; either participant can delete the joint report at any time |
| Detect abuse, prevent fraud | Rate-limit counters, IP addresses at signup | Legitimate interests (Art. 6(1)(f)) |
For health data specifically, we rely on your explicit consent under GDPR Article 9(2)(a). You can withdraw this consent at any time from within the Service, which deletes all stored health data immediately.
We do not:
- Sell your personal data to anyone
- Use your data to train our own or any third-party AI models
- Use your data for advertising or marketing you products from third parties
- Share your data with data brokers
- Re-identify pseudonymised audit records
3. Who We Share Data With
We share the minimum data necessary with the following categories of recipient, each under a written agreement requiring confidentiality and GDPR-compliant processing:
| Recipient | Role | What they receive | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI processor (model provider) | Structured prompts built from the data you connected — for Apple Music, Reddit, YouTube and your health data integration this includes the items listed in §1.2 (e.g. your recently-played tracks and library artists, your Reddit comment text, your liked-video titles, your daily sleep and activity records). Under our API agreement, OpenAI is contractually prohibited from training its models on our API inputs or outputs. | United States |
| Amazon Web Services (AWS) | Infrastructure provider (database, storage, messaging) | All production data at rest | Ireland (eu-west-1) |
| Apple | Sign in with Apple (identity verification) + App Store billing (iOS) + Apple Music (MusicKit, if you connect it) | For sign-in: your Apple identity token (signed by Apple), which reveals to us your verified email address and a stable Apple-specific user identifier. For billing: subscription purchase records. For Apple Music: Apple issues the app a Music User Token on your device; Apple does not receive your analysis data from us. | Ireland / US |
| Google Sign-In (identity verification) + Google Play billing (Android) + Health Connect (Android-side health-data store, on-device only) | For sign-in: your Google identity token (signed by Google), which reveals to us your verified email address and a stable Google-specific user identifier. For billing: subscription purchase records. Health Connect is the on-device data store from which we read your health records on Android — Google does not receive the records we read; the data leaves your device only to reach our AWS-hosted database, the same way it does on iOS via HealthKit. | Ireland / US | |
| Amazon Web Services (SES) | Delivers the sign-in link for the email magic-link option | Your email address and a single-use sign-in URL at the moment of sending. The link expires in 15 minutes and is single-use. | Ireland (eu-west-1) |
| RevenueCat | Subscription management / entitlement reconciliation | Pseudonymous user identifier, purchase receipts from Apple / Google | United States |
| Expo (650 Industries, Inc.) | Push-notification relay (forwards to APNs on iOS, FCM on Android) and over-the-air mobile app updates | Pseudonymous device push token, push payload contents (e.g. "Your analysis is ready") | United States |
| Sentry | Error tracking (where enabled) | Stack traces, device context | European Union (Frankfurt region) |
AI processor: OpenAI receives the structured prompts described in the table above. The prompt contains the content items listed in §1.2 (e.g. track and subreddit names, your Reddit comment text, liked-video titles, your per-night sleep records and per-day activity records). We do not include your email address, date of birth, account name, IP address, device identifiers, or any other account-level identifier in the prompt. Under our API agreement with OpenAI, OpenAI is not authorised to use our API inputs or outputs to train its models. Our ability to enforce this depends on the provider honouring its contractual commitments; we have no technical control over what happens inside the provider's systems. If we ever change our AI provider or add an additional one, we will update this policy and obtain your re-consent through the in-app flow described in §9 before the change takes effect. Link: OpenAI Privacy Policy.
International transfers: Some of the processors above are located in the United States. Transfers to these processors rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework (adopted under Article 45(3) GDPR by Commission Implementing Decision (EU) 2023/1795), to provide an adequate level of protection under GDPR Chapter V. Sentry, our error-tracking provider, is configured for the European data region (Frankfurt), so error traces from EU users do not leave the EU; for users elsewhere, traces are imported into the EU region rather than exported, which does not require a transfer mechanism under GDPR.
If you use the Service from outside the EEA (for example from India, Singapore, Malaysia, Australia, New Zealand, or the Philippines), your data is transferred to and stored in the European Union (AWS Ireland) and processed by the US sub-processors listed above. The same written agreements described in this section — confidentiality, processing only on our documented instructions, GDPR-grade contractual clauses — are what we rely on to satisfy the cross-border transfer requirements of your local law (e.g. the Transfer Limitation Obligation under Singapore's PDPA, section 129 of Malaysia's PDPA, APP 8 in Australia, and IPP 12 in New Zealand). India's DPDP Act permits transfers to any country the Indian government has not restricted; we do not transfer personal data to any restricted country.
Sub-processor list freshness. The list above is the current set of sub-processors. We commit to keeping it accurate. When we add a new sub-processor that handles personal data in a materially new way, or remove one, we will update this policy at least 30 days in advance of the change taking effect (security-driven failover is the only carve-out where we may act first and disclose immediately after). Material changes to this list trigger a new policy version, which you will be asked to review and accept on next launch through the in-app re-consent flow described in §9. Previous versions of the sub-processor list are archived and available on request to privacy@eltria.de.
Sharing with another user (Compatibility): if you use the optional Compatibility feature, the joint report — a compatibility score and statements drawing on your profile themes and headline traits — is visible to both you and the other participant. Both of you consented to the comparison: one by creating the invite, one by redeeming it. Your underlying analysis, connected-source data and health data are never shared — only the joint report is. Either participant can delete the joint report at any time, which removes it for both; deleting your account removes it too. The comparison is generated by our AI processor (OpenAI, table above) from both participants’ profile themes and headline traits only.
Legal disclosures. We may disclose personal data when we are legally required to do so (e.g. a valid court order from a competent jurisdiction), and only the minimum data necessary. We will notify you unless legally prohibited.
4. How Long We Keep Data
| Category | Retention |
|---|---|
| Account profile | Until you delete your account |
| Connected-service data — Apple Music, Reddit | Cached for 24 hours; re-fetched when you run an analysis. Deleted when you disconnect the source or delete your account. |
| Connected-service data — YouTube | Stored in our database and refreshed when you run an analysis. Deleted when you disconnect the source or delete your account. |
| Health data (whether sourced from Apple Health on iOS or Google Health Connect on Android) | Rolling 90-day window: records older than 90 days are deleted by a daily retention job. When you disconnect the health source or delete your account, your health data is removed from our live systems as part of that action; backup copies follow the rotation described under "Backups" below. |
| Personality profiles and analysis records | Until you delete your account |
| Billing records | Retained as required by German tax and accounting law: invoices and accounting vouchers for 8 years, and books, inventories and commercial letters for the periods set by § 147 AO and § 257 HGB (up to 10 years). The record is kept in pseudonymised form and the personal link is severed on account deletion; we restrict rather than erase these records until the statutory period expires. |
| Audit logs (GDPR Art. 30, Art. 32) | Differentiated by event class: authentication events (login, sign-in-link request, token refresh) 30 days; routine operational events (analysis lifecycle, cache invalidation, profile views) 90 days; rights-exercise evidence (consent records, deletion confirmations, Art. 22 human-review requests) and admin actions 7 years. Enforced by a daily retention-purge job. |
| Product analytics events (§1.4) | Until you delete your account; removed by the same deletion cascade as the rest of your data. No events are stored at all while your analytics toggle is off. |
| Access tokens / refresh tokens | 30 min / 7 days respectively; stored only on your device |
| Crash reports (Sentry, where enabled) | Per Sentry's retention (typically 90 days) |
Backups. We take daily encrypted database backups and retain them for seven days before they are overwritten. When you delete your account or disconnect a source, the deletion runs across our live systems as part of that action; backup copies may remain for up to seven days until that backup cycle overwrites them. We do not selectively restore individual rows from backup; backups exist only to recover the whole database after a disaster. If we ever restore from a backup that still contains data you asked us to delete, we re-apply the deletion to the restored data.
5. Your Rights
If the GDPR applies to you (you are in the European Economic Area, the UK, or Switzerland), you have the following rights. These rights apply regardless of location to the extent required by local law:
- Access — ask for a copy of the personal data we hold about you (Art. 15)
- Rectification — ask us to correct inaccurate data (Art. 16)
- Erasure — ask us to delete your data; we provide this as an in-app "Delete my account" option that runs a deletion cascade across the data stores we control (Art. 17). The cascade removes your records from our production databases and stored files (including your profile photo), clears cached copies, and where a connected source offers a token-revocation endpoint (currently Reddit and YouTube) revokes our access at the source. Where we use a processor that holds a copy of your data on our behalf (for example our AI provider, our subscription-reconciliation provider, or our crash-reporting provider), we rely on the deletion terms in our contract with them and on their own retention limits to erase that copy, and where a processor offers a per-user deletion instruction we send one (Art. 19; Art. 28(3)). If a step in the cascade fails, our internal audit log records it. For Apple Music, which has no server-side token-revoke API, the deletion of our own copy of your data and Music User Token is what we control; to withdraw the permission at the source, disable media-library access for the app in iOS Settings → Privacy & Security → Media & Apple Music.
- Restriction — ask us to pause processing in certain situations (Art. 18)
- Portability — ask for your data in a machine-readable format (Art. 20). We provide this in the Service under Profile → Settings → Download My Data, which produces, in the format you choose, either a human-readable PDF report or a structured, machine-readable JSON file containing the personal data we hold. If part of the export cannot be assembled at the moment of your request (e.g. a transient outage on our side, or a section large enough that we cap it), the export marks this with a
partialflag and lists the affected sections, so you always know whether you received a complete copy. You can re-request a full export later, or contact us if the issue persists. - Object — object to processing we have based on legitimate interests (Art. 21). For product analytics you do not need to email us: the toggle in Profile → Settings → Privacy Preferences → Product analytics is the objection mechanism, takes effect immediately, and is enforced server-side.
- Withdraw consent — where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3))
- Complain — lodge a complaint with your local data protection authority. For EU users, a full list is at edpb.europa.eu.
To exercise any of these rights, contact privacy@eltria.de. We respond within one month as required by GDPR Article 12.
Users in the United States, Canada, India, Singapore, Malaysia, Australia, New Zealand, and the Philippines have rights described in §10 (Regional Addenda) below; those rights apply in addition to anything else in this policy that is more protective of you. If you live anywhere else, we voluntarily extend the rights in this §5 to you as a matter of policy (see §10.10).
5.1 How long we actually take to respond
We commit to the statutory turnaround windows above. We also commit to publishing our actual measured response time, annually, in this section. Until we have a full year of operating data after launch, the table below shows our target rather than our actuals; we will replace target with actual on the first anniversary of launch.
| Request type | Target turnaround | Statutory limit |
|---|---|---|
| Right to know / access (Art. 15) | Within 14 days | 1 month (GDPR), 45 days (CCPA, MHMDA) |
| Right to delete (Art. 17) | Within 7 days | 1 month (GDPR), 45 days (CCPA, MHMDA) |
| Right to correct (Art. 16) | Within 14 days | 1 month (GDPR), 45 days (CCPA) |
| Right to portability (Art. 20) | Within 14 days | 1 month (GDPR) |
| Withdraw consent (Art. 7(3)) | Immediate (in-app) | "As easy to withdraw as to give" |
| Object to processing (Art. 21) | Within 14 days | 1 month (GDPR) |
| Automated-decision human review (Art. 22(3)) | Within 14 days | 1 month (GDPR) |
If we miss a target, we will tell you why and when we expect to respond, within the statutory window.
6. Security
We take security seriously. Technical and organisational measures include:
- Encryption at rest: OAuth tokens and your health data are encrypted in the database using authenticated AES-128 (Fernet specification: AES-128 in CBC mode with HMAC-SHA256 for integrity; keys held in AWS Secrets Manager with IAM-scoped access). This application-layer encryption runs on top of AWS-managed disk-level AES-256 encryption on the database volumes, so a single-layer compromise does not expose plaintext.
- Encryption in transit: All API traffic uses TLS 1.2 or higher. Internal services (database, message queue, cache) communicate over TLS.
- Access control: Production infrastructure uses least-privilege IAM roles. Engineer access to production data is through an audited break-glass workflow that requires an explicit reason, logs the actor and the session duration, and is subject to review. Direct long-lived database credentials are not distributed to individuals.
- Authentication: JWT access tokens expire after 30 minutes. Refresh tokens are rotated on every use; any re-use of an already-rotated token revokes the session immediately.
- Monitoring: Errors and suspicious activity are logged and reviewed.
- Backups: Daily encrypted backups retained for 7 days.
No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
7. Children
The Service is restricted to users 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it.
8. Automated Decision-Making
The personality profile and, if you use the optional Compatibility feature, the joint compatibility report are generated by automated means (large language models). We consider that neither produces legal or similarly significant effects on you within the meaning of GDPR Article 22(1): both are framed and marketed for entertainment and self-reflection, are not shared by us with third parties for decisioning, and are not used by us to decide credit, employment, insurance, or other consequential matters. A compatibility score is a playful, AI-generated reading of two profiles, not a measurement, an assessment, or advice about any relationship decision. We are aware that the CJEU in SCHUFA Holding (Case C-634/21, 7 December 2023) read "similarly significant" broadly; out of an abundance of caution we nevertheless provide the full set of Article 22(3) safeguards below, and we encourage any user who believes an automated output has materially affected them to invoke them. You retain the right to (a) obtain human review of any automated output, (b) express your point of view on the output, and (c) contest the output. To exercise these rights, email privacy@eltria.de with the analysis date or share link, your view of the output, and what you would like us to reconsider. A reviewer will respond within one month as required by GDPR Article 12.
9. Changes to This Policy
We may update this policy to reflect changes in the Service, applicable law, or our practices. When we make material changes, we will notify you in-app and require you to review and accept the new version before continuing. You can always see the current version and effective date at the top of this page. Previous versions are archived and available on request.
10. Regional Addenda
This section is additive: everything elsewhere in the policy still applies. The items below spell out rights and interfaces required by specific jurisdictions.
10.1 United States — California (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights over the personal information we hold about you.
Categories of personal information we collect. We collect the categories listed in §1.1 and §1.2 (identifiers, internet or other electronic network activity, commercial information for billing, and where you connect a health source (Apple Health on iOS or Google Health Connect on Android), categories that qualify as sensitive personal information under CPRA §1798.140(ae)). We do not collect geolocation, precise location, genetic, or biometric data.
Sources, purposes, and sharing. Sources are you (account information, sign-in via Apple / Google / email magic link, uploaded data) and the third-party services you choose to connect. Purposes are generating your personality profile, authenticating you, and billing (see §2). Recipients are the sub-processors listed in §3.
We do not sell or share your personal information. CCPA defines "sale" as an exchange of personal information for monetary or other valuable consideration, and "sharing" as a transfer for cross-context behavioural advertising. We do neither. There is no advertising in the Service and we have no agreements that provide personal information to third parties for their own marketing or advertising.
Where we engage vendors to help us deliver the Service (the sub-processors listed in §3 — for example, OpenAI as our AI processor, AWS for infrastructure and email delivery, Apple and Google for sign-in and billing, RevenueCat for subscription reconciliation), those relationships fall within the CCPA service provider exception at §1798.140(ag). Each vendor processes your data only on our documented written instructions, under a contract that prohibits them from selling the data, from retaining or using it outside the scope of our instructions, or from combining it with data from other sources. Service-provider relationships are not a "sale" or "share" under California law.
Your California rights.
- Right to know what personal information we hold (§1798.100).
- Right to delete personal information (§1798.105).
- Right to correct inaccurate personal information (§1798.106).
- Right to opt out of sale or sharing — not applicable, but we provide a Do Not Sell or Share My Personal Information control anyway.
- Right to limit use of sensitive personal information (§1798.121) — exercise via the Limit the Use of My Sensitive Personal Information control below.
- Right to non-discrimination (§1798.125) — we will not deny service, charge different prices, or provide a different level of service for exercising any of these rights.
How to exercise. Email privacy@eltria.de with the subject line "California privacy rights — [right name]". We respond within 45 days as required by CCPA §1798.130. We verify your request by matching the email address to your account and, where the request is for sensitive information or deletion, by requiring you to authenticate in the app.
Do Not Sell or Share My Personal Information. We do not sell or share your personal information. This link exists because California law requires a clearly labelled control on our privacy policy. Clicking through records your opt-out preference; we will continue not to sell or share.
Limit the Use of My Sensitive Personal Information. The sensitive personal information we process is the health data you choose to connect through your device's health framework (see §1.2). To limit our use of that data, open the app, go to the Connect tab, find the health card (labelled Apple Health on iOS or Health Connect on Android), and tap Disconnect. This stops further processing and removes the stored health records as part of that action. If you cannot access the app, email privacy@eltria.de with "CCPA: limit sensitive" in the subject line and we will apply the limit on your behalf within 15 business days, as required by CPPA regulation §7027.
10.2 United States — Washington and Nevada (consumer health data)
If you connect your device's health source (Apple Health on iOS or Google Health Connect on Android), the resulting sleep and activity records qualify as consumer health data under Washington's My Health My Data Act (RCW 19.373) and Nevada's Consumer Health Data Privacy Act (NRS 603A.300–360). The full set of disclosures, rights, and procedures for consumer health data is in our Consumer Health Data Privacy Policy, which supplements this policy.
Headline commitments from that policy:
- We do not sell consumer health data, unconditionally.
- We do not implement geofences around health-care facilities or anywhere else.
- The only categories we touch are sleep records and activity records; the other twelve MHMDA categories (heart rate, mental-health data, reproductive data, etc.) are not collected.
- You can withdraw authorization at any time via the Connect tab → the health card (Apple Health on iOS, Health Connect on Android) → Disconnect.
- You can appeal a denial to
privacy@eltria.deand, if unsuccessful, to the Washington Attorney General or the Nevada Attorney General.
For consumer-health-data-specific requests, contact privacy@eltria.de.
10.3 United States — Other state privacy laws
Comparable rights exist under the state privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other states as they take effect. To exercise rights under any of these laws, email privacy@eltria.de. We honour the Global Privacy Control (GPC) signal (`Sec-GPC: 1`) on authenticated requests, recording receipt against the affected user's account — see §1.4 for the full mechanism. We do not sell or share personal information for cross-context behavioural advertising and run no advertising of any kind. We do run first-party product analytics (in-app usage events, described in §1.4); receiving a GPC signal turns that off for your account, and the in-app toggle does the same.
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (Children's Online Privacy Protection Act — COPPA). The Service is additionally restricted to users 18 and older per §7.
10.4 Canada — PIPEDA (federal)
If you are a Canadian resident, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies. Your rights include access to your personal information, correction, and the right to withdraw consent for further processing. Cross-border transfers to the United States for AI processing and sub-processors are disclosed in §3; you consent to those transfers by using the Service. PIPEDA requires that personal information transferred to another jurisdiction receives "comparable protection" — for our US transfers, this is established through contractual safeguards with each sub-processor.
To exercise PIPEDA rights, email privacy@eltria.de. If you are dissatisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC).
10.5 Quebec — not available at launch
The Service is not available to residents of the Canadian province of Quebec at this time. Quebec's Law 25 requires that user-facing services be presented in French first and includes specific provisions on automated decision-making; we will launch in Quebec in a future release with the full French-language surface. If you believe you received the Service in Quebec in error, contact privacy@eltria.de.
10.6 India — Digital Personal Data Protection Act (DPDP Act)
If you are in India, the Digital Personal Data Protection Act, 2023 and its rules apply to our processing of your digital personal data in connection with offering the Service to you. Under that Act, we are the Data Fiduciary and you are the Data Principal.
- Consent and notice. We process your connected-source data on the basis of your consent, given through the in-app connect flow, accompanied by this notice describing the personal data and the purpose. You can withdraw consent at any time in the app (disconnect a source, or delete your account); withdrawing is as easy as giving it, as the Act requires.
- Your rights. You may (a) request a summary of the personal data we process about you and the processing activities (we provide this via Profile → Settings → Download My Data or on request); (b) request correction, completion, updating, or erasure of your personal data; (c) use our grievance-redressal mechanism below; and (d) nominate another individual to exercise your rights in the event of your death or incapacity — email
privacy@eltria.dewith the subject "DPDP nomination" to record a nominee. - Grievance redressal. Email
privacy@eltria.dewith the subject "DPDP grievance". We respond within the timelines in §5.1. If you are not satisfied after exhausting this mechanism, you may complain to the Data Protection Board of India. - Children. The Service is restricted to users 18 and older (§7), so we do not process children's personal data and the Act's verifiable-parental-consent requirements do not arise.
- Transfers. See §3 — your data is stored in the EU and processed by the sub-processors listed there; we do not transfer personal data to any country restricted by the Indian central government.
10.7 Singapore — Personal Data Protection Act (PDPA)
If you are in Singapore, the Personal Data Protection Act 2012 applies. This policy serves as the notification of purposes required by the PDPA, and the in-app connect flow is how we obtain your consent.
- Access and correction. You may request access to and correction of your personal data (Part IV PDPA) — in-app via Download My Data, or by email to
privacy@eltria.de. - Withdrawal of consent. You may withdraw consent at any time by disconnecting a source or deleting your account; we will not use or disclose the data thereafter.
- Transfer Limitation Obligation. Your data leaves Singapore (EU storage, US sub-processors). We ensure a standard of protection comparable to the PDPA through the legally enforceable agreements described in §3.
- Data protection contact. As the PDPA requires, we have designated an individual responsible for data-protection compliance, reachable at
privacy@eltria.de(see §11). - Breach notification. We notify the PDPC and affected users of notifiable data breaches as required by Part VIA of the PDPA.
- Complaints. Personal Data Protection Commission (PDPC).
10.8 Malaysia — Personal Data Protection Act (PDPA 2010, as amended)
If you are in Malaysia, and to the extent the Personal Data Protection Act 2010 (including the 2024 amendments) applies to our processing, we act as the data controller. As required by section 7(3) of the PDPA, this notice is also available in Bahasa Malaysia: Notis Privasi (Bahasa Malaysia).
- Sensitive personal data. Health-derived data you connect (sleep and activity records) is processed only with your explicit consent, given through the on-device health permission prompt and the in-app connect flow.
- Your rights. Access and correction of your personal data, and withdrawal of consent at any time (disconnect the source or delete your account). As the 2024 amendments' data-portability provisions take effect, the in-app Download My Data export satisfies them.
- Transfers. Your data is transferred outside Malaysia as described in §3, with contractual safeguards ensuring substantially similar protection, per section 129 of the PDPA as amended.
- Breach notification. We notify the Commissioner and affected users of significant breaches as required by the 2024 amendments.
- Complaints. Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).
10.9 Australia and New Zealand
Australia. If you are in Australia, we handle your personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988, whether or not the Act's small-business threshold makes them mandatory for us. This policy is our APP 1 privacy notice; APP 8 cross-border disclosures are described in §3; you may request access and correction (APPs 12–13) via privacy@eltria.de or the in-app tools; and we notify eligible data breaches under the Notifiable Data Breaches scheme. Complaints: Office of the Australian Information Commissioner (OAIC).
New Zealand. If you are in New Zealand, the Privacy Act 2020 applies. You may request access to and correction of your personal information (IPPs 6–7) via the in-app tools or privacy@eltria.de; cross-border disclosures rely on the contractual safeguards in §3 (IPP 12); and we report notifiable privacy breaches to the Office of the Privacy Commissioner, to whom you may also complain.
10.10 Philippines — Data Privacy Act, and all other jurisdictions
Philippines. If you are in the Philippines, the Data Privacy Act of 2012 (RA 10173) applies. We process your sensitive personal information (health-derived records) only with your consent. You have the rights to be informed, to access, to rectification, to erasure or blocking, to data portability, and to damages — exercisable via the in-app tools or privacy@eltria.de. Complaints: National Privacy Commission (NPC).
Everywhere else. If you use the Service from a jurisdiction not named in this §10, we voluntarily extend the rights described in §5 (access, correction, erasure, portability, objection, withdrawal of consent) to you as a matter of policy, exercisable through the same in-app tools and email contacts. Where your local law grants you additional non-waivable rights, nothing in this policy limits them.
10.11 Supervisory authorities
Complaints or inquiries may be directed to the following authorities depending on where you live:
- EU / EEA: your national data protection authority. Lead authority for us: Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59–61, 10555 Berlin.
- United Kingdom: Information Commissioner's Office (ICO).
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
- United States — California: California Attorney General; California Privacy Protection Agency.
- United States — Washington: Washington Attorney General.
- United States — federal / deceptive practices: US Federal Trade Commission (FTC).
- Canada: Office of the Privacy Commissioner of Canada.
- India: Data Protection Board of India.
- Singapore: Personal Data Protection Commission (PDPC).
- Malaysia: Personal Data Protection Commissioner (JPDP).
- Australia: Office of the Australian Information Commissioner (OAIC).
- New Zealand: Office of the Privacy Commissioner.
- Philippines: National Privacy Commission (NPC).
11. Contact and Data Protection Officer
For any privacy question, request, or complaint, contact Eltria UG (haftungsbeschränkt):
| What | |
|---|---|
| General privacy questions, GDPR rights requests, complaints | privacy@eltria.de |
| Consumer health data (MHMDA / Nevada CHDPA) — see CHD Policy | privacy@eltria.de |
| Privacy escalations — appeals, complex matters | privacy@eltria.de |
| Vulnerability reports — see Security page | security@eltria.de |
| Accessibility issues — see Accessibility statement | contact@eltria.de |
Postal address: Eltria UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany.
Data protection responsibility. We have not appointed a formal Data Protection Officer: we are below the threshold of § 38 (1) of the German Federal Data Protection Act (BDSG) (fewer than 20 persons regularly engaged in processing personal data), and at our current scale our processing does not constitute large-scale processing of special-category data within the meaning of Article 37(1)(c) GDPR. Responsibility for data protection sits directly with our management. Our contact for all data-protection matters is privacy@eltria.de. We will appoint a Data Protection Officer, and update this policy, if and when either threshold is met.
Our EU/UK data-protection lead authority is Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59–61, 10555 Berlin.