Privacy Policy
1. Scope
This policy applies to the bauchgefühl app, published on Google Play as Period Tracker & Cycle Diet (package ID com.bauchgefuehl.ios, developer hamstr) and on the Apple App Store as bauchgefühl, and to bauchgefuehl.app (together, the “service”). The app provides menstrual cycle tracking, symptom recording and personalized dietary suggestions based on the cycle phase.
2. Controller
The controller under the GDPR is Josef Haras, operating under the developer name hamstr.
Josef Haras (hamstr)
Dr.-Adolf-Schärf-Platz 10/309
1220 Vienna, Austria
VAT ID: ATU75469459
Email: josef.haras@hamstr.me
Public developer email: office@hamstr.me
Telephone: +43 680 5019637
Website: bauchgefuehl.app
3. Data collected and purposes
3.1 App usage data
We process the following categories:
- Cycle data, including the start and end of menstruation and cycle days.
- Symptoms and wellbeing, such as pain, mood and energy.
- Dietary preferences and intolerances.
- Ingredients and recipes entered by users.
- Email address when registering an account.
- Device information and anonymized usage statistics.
The purpose is to provide app functions: cycle tracking, dietary suggestions and personalized content. Legal bases: Article 6(1)(b) GDPR (performance of a contract) and Article 9(2)(a) GDPR (explicit consent) for health data.
3.2 Website usage data
When you visit the website, technical data is collected automatically: IP address, browser type, operating system, referrer URL and time of access. This data is required to operate the website and is deleted within 30 days. Legal basis: Article 6(1)(f) GDPR (legitimate interests).
The French and Spanish pages use the same analytics and advertising tools as the German and English pages, with the same cookie banner and only with your consent (see the sections on Google Analytics, PostHog, Facebook Pixel and Google Tag Manager). When you change language, the NEXT_LOCALE cookie remembers your choice for one year. Temporary session storage restores your reading position. The contact form stores a draft locally on your device, which is restored only for 7 days. You can remove this data in your browser settings. Dates entered in the French and Spanish calculators are processed in your browser and are not sent to our server.
3.3 Contact
When you contact us by email, we store your details to handle the enquiry and possible follow-up questions. We do not share this data without your consent. Legal basis: Article 6(1)(f) GDPR (legitimate interests).
3.4 Newsletter and email communication
Website newsletter. With your consent, we send newsletter emails through Brevo (formerly Sendinblue). You can unsubscribe at any time using the link in each email or by contacting office@bauchgefuehl.app. Legal basis: Article 6(1)(a) GDPR (consent).
App service messages. When you start a trial or free access in the app, we send individual service messages to your account email: confirmation at the start and a reminder before access ends. If you have provided a payment method, the reminder precedes the start of a paid subscription and includes the price and cancellation option. These messages form part of contract performance and contain no advertising. Legal basis: Article 6(1)(b) GDPR.
Accompanying emails, only with consent. You may additionally consent in the app to occasional cycle tips and product updates. We record the time and wording of your consent. For these personalized emails, we use your email address and selected account usage details, such as the number of saved recipes and your access expiry date. Your health data—cycle entries and symptoms—is never used for emails. You can withdraw consent at any time through the unsubscribe link or by contacting office@bauchgefuehl.app. Withdrawal does not affect the lawfulness of processing before withdrawal. Legal basis: Article 6(1)(a) GDPR.
Email provider. All these emails are sent through Sendinblue GmbH (Brevo), Köpenicker Str. 126, 10179 Berlin, Germany, acting as a processor under Article 28 GDPR. Processing takes place in the EU. Recipient data is stored while your account exists or until consent is withdrawn and is deleted when the account is deleted.
3.5 Push notifications and automatic backups
We use Google Firebase Cloud Messaging (FCM) to deliver push notifications; see section 4. Visible notifications, such as cycle reminders, are sent only if you enable notifications, which you can disable in settings at any time.
We also send invisible system pushes to all devices on which you are signed in, regardless of notification settings. These never display anything and contain no content or health data. They briefly wake the app in the background to prepare an encrypted backup and, if you enabled “Proactive messages”, prepare a proactive message; see the Google Vertex AI subsection below. The backup leaves your device only in encrypted form; section 3.7 explains how it is encrypted and how you can restore it.
Legal bases: Article 6(1)(b) GDPR (contract performance: providing backups); for visible reminders, your consent through notification settings under Article 6(1)(a) GDPR.
3.6 Recipe suggestions based on swipes
When you save a recipe by swiping right or dismiss it by swiping left, our server uses these signals to suggest more suitable recipes in the AI chat. Among similarly suitable recipes, saved recipes are preferred and dismissed recipes avoided. Safety exclusions, such as allergens and intolerances, always apply. This is your own app usage behavior, used only in the recipe function you actively request. The swipes themselves are not transmitted to the AI service. Legal basis: Article 6(1)(b) GDPR.
3.7 Encrypted backup, recovery key vault and restore
Local storage. The app stores your cycle and diary data in an encrypted database (SQLCipher) on your device.
Encrypted backup. So that your data is not lost if you lose or change your device, the app creates backups automatically. Each backup is encrypted on your device with a backup key before upload and then stored with Supabase (EU, Frankfurt). Your app generates the backup key; it is never stored with us in plain text. Technical details required for storage are not encrypted, such as the link to your account and the time and version details of the backup files.
Ways to restore. To make a backup readable on a new device, the app needs the backup key. The following ways exist:
- Platform key sync, where available: the app stores the backup key in iCloud Keychain (iOS) or Google Block Store (Android). Apple or Google make it available on your other devices, depending on your device and account settings; we have no access to it. The app uses Block Store cloud backup only where Google offers it end-to-end encrypted.
- Personal recovery code, optional: if you set up a recovery code in the app, the backup key is encrypted with this code and stored with Supabase. Only you know the code; without it, we cannot decrypt this copy.
- Recovery key vault, default: as described below.
Rollout note. The recovery key vault, release by email code, the related security emails and the backup status report arrive with an upcoming app update. Until you have installed that update, the app does not store a backup key in the vault and sends no status report; your backup can then only be restored with your recovery code or via platform key sync. We start the automatic deletion of older backups (section 5) on our server when the vault is introduced.
Recovery key vault, default. By default, the app also deposits an encrypted copy of your backup key with us, so you can get your backup back even if your device is lost and no other way is available—for example when switching between iPhone and Android. On your device, the app encrypts the backup key together with your account identifier using the public key of a hardware security module (HSM) in Google Cloud Key Management Service, EU region europe-west3 (Frankfurt). We store this encrypted package with Supabase; it is bound to your account and released only for that account. The matching private key exists only inside the HSM and cannot be exported.
Release only with a code sent to your email. Your app receives the backup key from the vault only if you start the restore in the app and enter a one-time code that we send to your account email address. The code is valid for 15 minutes; we store only a hash and delete it 7 days after expiry. At most 3 codes can be requested within 24 hours; after 5 wrong entries within 60 minutes, release is blocked for 60 minutes. After a correct entry, our server has the HSM decrypt the package and transmits the backup key to your app over an encrypted (TLS) connection. We record every deposit, code request, wrong entry, block, release and every switch of “Only I have the key” on or off in a separate log (event, time and, where available, platform and an identifier of the affected key); every decryption in the HSM is also recorded in Google Cloud's audit log. We notify you by email of every release.
Email delivery check. Once this check is available in the app, we store a timestamp on your account at which we could confirm that our emails reach you—for example because you entered a test code from one of our emails in the app (if the app asks you to run this check) or used a sign-in link from an email. This is meant to ensure that release by a code sent to your email address works when you need it. As with release codes, we store test codes only as a hash; they are valid for 15 minutes and deleted 7 days after expiry. We delete the timestamp together with your account.
What is technically possible. We do not read your backups. As long as your backup key is deposited in the vault, access by us is, however, not technically ruled out: using our server's credentials for the HSM, we as the operator could have a deposited backup key decrypted. Nobody can copy the private key out of the HSM, and any such decryption would be recorded in Google Cloud's audit log. If you want to rule this out, use “Only I have the key”.
“Only I have the key” (opt-out). You can switch off the deposit at any time in the app settings, provided you have set up a current recovery code. We then delete all vault packages for your account; your backup can no longer be decrypted through the vault. Restoring is then possible only with your recovery code or through platform key sync—if all ways are lost, your backup can no longer be restored. If you switch “Only I have the key” off again, the app deposits a new package. We notify you by email of every change, so you notice a change you did not make.
Backup status report. To detect backup problems, such as devices on which the database can no longer be opened, the app sends a technical status report to our server at launch, at most once per hour: platform, app version, whether the local database could be opened, whether database and backup keys are present on the device, whether Block Store cloud backup is available, whether a vault package and a current recovery code exist, time of the last backup and last restore, and an overall status. The report contains no cycle or health content and no device identifiers. We keep only the latest report per account.
Emails. One-time codes, release notifications and notices about “Only I have the key” are sent through Brevo; see section 4. Replies go to office@bauchgefuehl.app.
Legal bases: Article 6(1)(b) GDPR (contract performance: providing backup and restore, including related security emails) and, where health data is concerned, Article 9(2)(a) GDPR (explicit consent; see section 3.1); for the backup status report, Article 6(1)(f) GDPR (legitimate interest in a working backup and in detecting problems).
4. Services and recipients
Supabase
Supabase provides database infrastructure, authentication and storage for encrypted backups (section 3.7). Data is stored in the EU, in Frankfurt, Germany, and is subject to the GDPR. A data processing agreement is in place.
Google Vertex AI: recipe suggestions
To generate personalized recipes, we transmit your cycle phase, symptoms, dietary preferences, entered ingredients and requested preparation time to Google Vertex AI. The data is used only to generate the requested response and is not used to train AI models. A data processing agreement, including EU standard contractual clauses, applies under the Google Cloud Data Processing Addendum.
Legal bases: Article 6(1)(b) GDPR (contract performance) and Article 9(2)(a) GDPR (explicit consent given through active, voluntary use of the AI recipe function by submitting your request).
Google Vertex AI: proactive messages
If you enable “Proactive messages” in settings, which is off by default, the app occasionally prepares a personal push message, for example about a cycle phase transition or your activity. Unlike other reminders calculated entirely on your device, these messages are generated on the server. In the background, including when closed, the app transmits your current cycle phase and, if you additionally enabled Health access, a summary of recent activity and sleep to Google Vertex AI in the EU region europe-west3. At most one such message is generated per day.
This processes health data: your cycle phase already qualifies as a special category of personal data under Article 9 GDPR, and activity and sleep add further health data when Health access is enabled. Processing relies solely on your explicit consent through the switch. You can withdraw it at any time by switching the setting off; no further data is then transmitted for this purpose. Data is used only to generate the individual message, not to train AI models, either by us or Google. The Google Cloud data processing agreement, including EU standard contractual clauses, applies.
Legal bases: Article 6(1)(a) and Article 9(2)(a) GDPR (explicit consent).
Google Cloud Key Management Service: recovery key vault
For the recovery key vault (section 3.7), we use Google Cloud Key Management Service with a hardware security module in the EU region europe-west3 (Frankfurt). At the moment of a release, Google processes the encrypted package and returns the decrypted backup key to our server; Google also records key operations in an audit log. Your backups themselves are not transmitted to Google. A data processing agreement, including EU standard contractual clauses, applies under the Google Cloud Data Processing Addendum. Legal bases: as stated in section 3.7.
Brevo, formerly Sendinblue
We use Brevo (Sendinblue GmbH, Berlin) for the website newsletter, the app service and accompanying emails described in section 3.4, and the recovery key vault security emails described in section 3.7. Data is stored in the EU. A data processing agreement is in place.
Google Analytics
On website pages where it is enabled, Google Analytics analyzes website usage. IP addresses are anonymized before storage. Processing relies on your consent through the cookie banner, Article 6(1)(a) GDPR. You can object to collection by installing Google’s Analytics opt-out browser add-on.
PostHog: website analytics and session replay
On pages where it is enabled, PostHog uses EU hosting in Frankfurt. Before consent, we collect only anonymous usage data without device storage, cookies or recognition; your IP address is anonymized and not stored. After consent through the cookie banner, PostHog uses cookies for audience and funnel analysis and session replay: anonymized page interactions, with masked input fields and no recordings of sensitive areas such as quiz, login or checkout. Replay retention is 30 days. A data processing agreement is in place.
Legal bases: before consent, Article 6(1)(f) GDPR (legitimate interest in anonymous reach measurement without accessing your device); after consent, Article 6(1)(a) GDPR. Consent can be withdrawn through the cookie banner.
PostHog: app usage analytics
We use PostHog Inc. to understand app usage, with processing exclusively on EU servers in Frankfurt, at eu.posthog.com. IP addresses are anonymized before storage.
We never collect health data for analytics. Cycle data, symptoms, moods and other health information are never transmitted to analytics systems. We collect only usage behavior, such as which functions are used or where problems occur, at two levels:
- Anonymous statistics without consent. During installation, onboarding and registration, technical events are fully anonymous. No identifier is stored on your device, the data cannot be assigned to a person, and each app launch starts a new, unlinkable session. This shows, for example, where users leave onboarding. Since the data is anonymous, no personal data is processed.
- Statistics with consent. Only with your explicit consent after registration do we link usage events pseudonymously to your account—for example, that a function was used or an entry created, never the entry’s content. You can withdraw consent at any time using “Usage statistics” in app settings. Collection stops and the analytics identifier is discarded.
Legal bases: Article 6(1)(a) and Article 9(2)(a) GDPR. Recipient: PostHog Inc. as processor, with EU hosting and a data processing agreement including EU standard contractual clauses.
Google Firebase: app notifications and crash reports
The app uses Firebase Cloud Messaging for push delivery and Crashlytics and Performance Monitoring for crash and performance reports. These process technical device details, such as device token, model, operating system and app versions and crash logs, without health data. Classical scheduled cycle reminders are calculated entirely on your device; server-generated proactive messages are described above. Firebase Analytics is not used.
Legal bases: Article 6(1)(b) GDPR for app functions you enable and Article 6(1)(f) GDPR for the legitimate interest in stability and troubleshooting.
Facebook Pixel
On website pages where it is enabled, Facebook Pixel supports conversion tracking and remarketing with your consent under Article 6(1)(a) GDPR. You can withdraw consent through the cookie banner.
Google Tag Manager
On pages where tracking is enabled, Google Tag Manager manages our tracking tools. The Tag Manager itself does not collect personal data.
App stores
The app is distributed through Google Play and the Apple App Store. When downloading and using those stores, Google’s and Apple’s respective privacy policies apply. We have no influence over their processing.
5. Retention and deletion
We retain personal data only as required for the relevant purpose or statutory retention obligations:
- Account and app data: until account deletion or upon request.
- Backups: per account, we keep the 60 most recent backup versions, the 10 top versions in restore order and all backups from the last 30 days; older backups are deleted automatically every day. We introduce this automatic deletion together with the recovery key vault (section 3.7); until then, backups are kept until your account is deleted.
- Vault packages: until you switch on “Only I have the key” or delete your account. The copy encrypted with your recovery code, the vault log and the backup status report (latest only): until account deletion.
- Vault release codes: 7 days after their 15-minute validity ends.
- Newsletter data: until unsubscription.
- Contact enquiries: 2 years after correspondence ends.
- Technical website logs: at most 30 days.
- Accounting data: 7 years under Austrian tax law.
You can delete your account and associated data in the app under “Profile → Delete account” or through our website. A 7-day grace period applies: signing in again during that period cancels deletion. Afterwards, the account and associated personal data—including all backups, the key copy encrypted with your recovery code, vault packages, the vault log and the backup status report—are automatically and irreversibly deleted from our systems and those of the processors listed in section 4. Deletion is fully completed within 30 days at the latest. Data subject to statutory retention, such as accounting records, is excluded. Deleting your account does not cancel an App Store or Google Play subscription; cancel any active subscription separately in the store settings.
6. Your rights
Under the GDPR, you have the following rights:
- Access to your personal data: Article 15.
- Rectification of incorrect or incomplete data: Article 16.
- Erasure, unless statutory retention applies: Article 17.
- Restriction of processing: Article 18.
- Data portability in a machine-readable format: Article 20.
- Objection to processing based on legitimate interests: Article 21.
- Withdrawal of consent for the future: Article 7(3).
To exercise these rights, contact office@bauchgefuehl.app. You also have the right to complain to the Austrian data protection authority:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
dsb@dsb.gv.at
www.dsb.gv.at
7. Data security
We implement technical and organizational safeguards against accidental or deliberate manipulation, loss, destruction and unauthorized access. All data transmissions use TLS/HTTPS encryption. Safeguards are continuously improved as technology develops.
8. Updates
This translation reflects the German policy dated October 1, 2026, including the French and Spanish website behavior as of that date, when those pages adopted the same consent banner and consent-based tools as the rest of the website. We may update it to reflect changes in our services or applicable requirements. The new version applies on your next visit.