We never sell your personal information.
Controller (EEA, UK & Switzerland): SenseMe GmbH, [Registered office address to be confirmed], Munich, Germany
Controller (United States & rest of world): SenseMe, Inc., 8383 Wilshire Blvd Suite 800, Beverly Hills CA 90211
Email: privacy@sensemyhealth.com
SenseMe GmbH (Munich) is the data controller for users in the EEA, the United Kingdom and Switzerland. Until SenseMe GmbH is fully operational as controller, SenseMe, Inc. (Delaware, USA) has appointed a representative in the European Union pursuant to Article 27 GDPR. You may address the EU representative or SenseMe GmbH on any data protection matter, and you may lodge a complaint with the supervisory authority of your country of habitual residence.
EU representative (Art. 27 GDPR): [Name and address of appointed representative to be confirmed]
Data Protection Officer: [To be appointed; registration with the Bavarian Data Protection Authority (BayLDA) pending] — privacy@sensemyhealth.com
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account creation and login | Contract (Art. 6(1)(b) GDPR) | Until account deletion + 30 days |
| Display name | Personalisation | Contract | Until account deletion + 30 days |
| Date of birth (optional) | Age-appropriate reference ranges | Consent (Art. 6(1)(a) GDPR) | Until account deletion + 30 days |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Heart rate variability (HRV) | Stress and recovery scoring | Explicit consent (Art. 9(2)(a) GDPR) | 5 years, or until account deletion |
| Electrodermal activity (EDA) | Stress and nervous system scoring | Explicit consent | 5 years |
| Skin temperature | Inflammation and recovery scoring | Explicit consent | 5 years |
| Sleep staging (movement + HRV) | Sleep domain scoring | Explicit consent | 5 years |
| SpO₂ (blood oxygen, optional) | Respiratory health indicator | Explicit consent | 5 years |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Face scan image (in transit for analysis) | Real-time skin analysis | Explicit consent | Free users: not stored — deleted immediately after analysis |
| Stored face scan images (subscribers only) | Longitudinal skin tracking (before/after comparison) | Explicit consent | Duration of subscription; deleted within 30 days of account deletion; deletable anytime from your account |
| Skin analysis metrics (output) | Skin domain scoring and tracking | Explicit consent | 5 years |
Lab samples are handed to laboratory partners exclusively with a pseudonymous barcode UUID (kit_id). Name, email address, and date of birth are not transmitted to the lab. The link between kit_id and your account exists exclusively within SenseMe infrastructure.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Blood panel results (LDL, HDL, hsCRP, ApoB, Lp(a), etc.) | Heart and inflammation scoring | Explicit consent | 10 years |
| Hormone panel (cortisol, DHEA, etc.) | Stress and energy scoring | Explicit consent | 10 years |
| GI Map results | Gut health scoring | Explicit consent | 10 years |
| Skin microbiome results | Skin domain scoring | Explicit consent | 10 years |
| Skin pH strip readings | Skin acid mantle tracking | Explicit consent | 10 years |
10-year retention is because longitudinal tracking is the core value of SenseMe. You can request deletion at any time (30-day turnaround).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Health questionnaire responses | Personalised baselines and scoring context | Explicit consent | Until account deletion + 30 days |
| Supplement and medication log | Correlation and scoring context | Explicit consent | Until account deletion + 30 days |
SenseMe's Advisor system generates personalized supplement, skincare, and lifestyle recommendations based on your profile data, assessment responses, lab results, and scan data. This processing is performed by SenseMe's own recommendation engine using a clinical knowledge base. Legal basis: GDPR Art. 9(2)(a) (explicit consent) for health data; Art. 6(1)(b) for service delivery.
Certain features of the SenseMe app use Claude, an AI assistant provided by Anthropic, PBC (USA). Where Claude processes your data, Anthropic acts as a sub-processor under a data processing agreement. Data sent to Claude is limited to non-identifiable context required to generate a response. Legal basis: GDPR Art. 6(1)(b). You may opt out of AI-assisted features in Settings → Privacy.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Device type and OS version | Compatibility and debugging | Legitimate interest (Art. 6(1)(f) GDPR) | 90 days |
| Crash reports (anonymised) | Bug fixing | Legitimate interest | 90 days |
| App session metadata | Product improvement | Legitimate interest | 12 months, then aggregated |
No advertising identifiers (IDFA/GAID) collected.
We retain your Stripe customer identifier (stripe_customer_id) for 3 years after subscription termination in accordance with § 257 HGB for subscription management purposes. Full payment and invoice records are retained for 10 years in accordance with § 147 AO (German Fiscal Code).
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Subscription status | Access control | Contract | Until account deletion |
| Stripe customer identifier (stripe_customer_id) | Subscription management | Contract; § 257 HGB | 3 years after subscription termination |
| Invoices and transaction records | Billing support and statutory bookkeeping | Legal obligation (§ 147 AO) | 10 years |
SenseMe may — with your voluntary, separate consent — use pseudonymised health data to improve its own scoring models, e.g. more accurate HRV reference ranges, more precise skin scoring models, or improved biomarker correlations. This consent is voluntary.
What this means:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Pseudonymised biometric, lab, and skin data | Improving internal SenseMe algorithms | Explicit, separate consent (Art. 9(2)(a) GDPR) | Until withdrawal or account deletion |
If you have reserved a SenseMe Band device, we process your name, email address, shipping address, and payment reservation details for the purpose of fulfilling your device pre-order. Legal basis: GDPR Art. 6(1)(b) (pre-contractual measures). You have the right to withdraw your reservation at any time — see our Widerrufsbelehrung for statutory withdrawal rights.
We use data to: deliver SenseMe scores and insights, AI skin analysis, push notifications (opt-in only), customer support, and legal compliance.
We do NOT
All AI-generated insights are informational and do not replace medical advice. No decision with legal or similarly significant effect is made solely on the basis of automated processing (Art. 22 GDPR).
Marketing emails. If you opt in to marketing emails, you can unsubscribe at any time via the unsubscribe link in every email or by emailing support@sensemyhealth.com — we process opt-outs within 5 business days. We never use your health scores, biomarker data, or scan results to target or personalise marketing content.
AI and model training. SenseMe uses aggregated and de-identified data to improve, train, and develop the AI models that power the Advisor feature and our own recommendation engine. No individually identifiable health data is used to train any external or third-party AI models (for example, Anthropic's Claude). Any use of your data to improve SenseMe's own models beyond aggregated and de-identified data is done only on pseudonymised data and only with your separate, voluntary consent, as described in Section 2.9.
Only sub-processors under data processing agreements. We do not share data with employers, insurers, pharmaceutical companies, or advertisers. See Section 6 for the full sub-processor list.
SenseMe's core infrastructure is EU-based. Transfers outside the EU/EEA use Standard Contractual Clauses (SCCs). Anthropic (US) is covered by SCCs; face scan images are not retained at rest.
| Sub-processor | Country | Data processed | Purpose | Safeguard |
|---|---|---|---|---|
| Anthropic, PBC | USA | Face scan images (ephemeral), AI prompt context | AI skin analysis, health insights | SCC; zero-training policy |
| Supabase, Inc. | USA (EU region hosted) | All app data (encrypted at rest) | Database & backend infrastructure | SCCs |
| Stripe, Inc. | USA | Subscription status, transaction IDs | Payment processing | SCCs + EU-U.S. DPF |
| Klaviyo, Inc. | USA | Email address, marketing engagement | Email marketing & lifecycle automation | SCCs + EU-U.S. DPF |
| Expo (Expo.io) | USA | Push tokens, app delivery metadata | App delivery & push notifications | SCCs |
| RevenueCat, Inc. | USA | Device identifier, purchase history, subscription entitlements | In-app purchase management | SCCs + EU-U.S. DPF |
| Crash analytics provider | EU | Anonymised crash reports | Bug fixing | Adequacy decision |
| Synlab / Bioscientia | DE | kit_id + blood and hormone readings | Lab analysis | DPA (Art. 28 GDPR); pseudonymised via kit_id |
| Nordic Laboratories EU | DK / EU | kit_id + GI-MAP results | Lab analysis | DPA; pseudonymised via kit_id |
| Eurofins Genomics | DE | kit_id + skin microbiome NGS data | Genome sequencing | DPA; pseudonymised via kit_id |
| Logistics provider | EU | Shipping address (kits only) | Sample shipping | DPA; no health data transmitted |
Lab partners receive only the barcode UUID (kit_id). Name, email, and date of birth never enter the laboratory information system (LIS). The link is made exclusively within SenseMe infrastructure.
Legal bases we rely on
Access
Get a copy of all data we hold on you
Rectification
Correct inaccurate or incomplete data
Erasure
Delete your account and data within 30 days, except records we are legally required to retain (see below).
Restriction
Pause processing while a dispute is resolved
Portability
Where processing is based on consent or contract and carried out by automated means, receive a copy of the data you provided in a structured, commonly used, machine-readable format (Art. 20 GDPR). Request an export by emailing privacy@sensemyhealth.com; an in-app self-service export (Profile → Data & Privacy) is being rolled out.
Objection
Object to processing based on legitimate interest
Withdraw consent
Withdraw consent for special category data at any time — including the optional consent for algorithm improvement (Section 2.9)
Complaint
Lodge a complaint with your local data protection authority
Limits on erasure. Some records must be retained even after account deletion — for example, billing and transaction data kept for 7 years under applicable tax law (Section 2.8), and lab results kept for 10 years to support your longitudinal health record (Section 2.4). Where we cannot delete data, we restrict it to that sole legal purpose and do not use it for any other processing. We will tell you what was kept and why when we process your deletion request.
To exercise your rights, contact privacy@sensemyhealth.com. We respond within 30 days.
Identity verification. To protect your health data, we verify your identity before actioning any access, export, correction, or deletion request. We may ask you to confirm your registered email address or complete an in-app verification step. We will never action a data request without confirming you are the account holder.
TLS 1.2+ in transit. AES-256 at rest. Access restricted to authorised personnel. Security reviews conducted regularly. In the event of a breach, we will notify you and the competent supervisory authority within 72 hours.
SenseMe is intended for users aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If you are under 18, please do not use SenseMe or provide any personal data to us. If you believe a child has created an account, contact privacy@sensemyhealth.com to have it removed.
Under Article 8 GDPR, as applied in Germany, a child may give valid consent to the processing of their personal data from the age of 16. Because access to SenseMe is limited to users aged 18 and over, we do not rely on the consent of anyone under 18, and we do not knowingly process the personal data of anyone below that age.
California (CCPA)
California residents have the right to: Know, Delete, Opt out of sale (we don't sell data — auto-satisfied), and Non-discrimination.
To make a request, email privacy@sensemyhealth.com with the subject line "CCPA Request". We respond within 45 days.
Washington, Nevada and other states — Consumer Health Data
Certain information SenseMe collects — for example biometric readings, face scan analysis, lab results, and self-reported health inputs — may qualify as "consumer health data" under the Washington My Health My Data Act (MHMDA), the Nevada Consumer Health Data Privacy Law, and similar US state laws. Where these laws apply, we collect, use, and share such data only with your affirmative, opt-in consent, obtained separately at sign-up and before collection. We do not sell consumer health data, and we do not share it for cross-context behavioural advertising. You may withdraw your consent at any time and request access to, or deletion of, this data by emailing privacy@sensemyhealth.com.
We use cookies and similar technologies, including browser local storage, in three categories. Essential cookies are required to run the website and to remember your choices, such as your cookie preferences, language, and currency; they are always active and do not require consent. Analytics cookies, used only with your consent, help us understand how the site is used so we can improve it. Marketing cookies, used only with your consent, let us send you relevant updates, for example through Klaviyo. Non-essential cookies and marketing tags are not loaded until you have given consent.
When you first visit our website, a cookie banner lets you accept all cookies, reject all non-essential cookies, or choose categories individually. You can review or change your choice at any time using the Cookie settings link in the website footer. The legal basis for non-essential cookies is your consent (Article 6(1)(a) GDPR and Section 25 TTDSG), which you may withdraw at any time with effect for the future. We do not use cross-site advertising cookies, and the SenseMe app contains no advertising SDKs.
Our app and website may contain links to third-party services we do not operate. Their own privacy policies govern your use of those services. We are not responsible for the privacy practices of third-party sites.
For material changes, we will provide in-app notice and obtain fresh consent for any new special category uses. The "Last updated" date at the top of this page always reflects the latest revision.
This policy is written in English. In case of conflict between this and any translation, the English version governs.
We use cookies to run and improve SenseMe. Privacy