← Back to site

Legal

Privacy Policy

SenseMe, Inc. · Last updated: July 2026 (v1.2) · sensemyhealth.com/privacy

We never sell your personal information.

Our Commitments

  • ✓We never sell your health data. Not to advertisers. Not to data brokers. Not to anyone.
  • ✓We never use your data to target ads. Your biomarkers, your scores, your lab results — none of it is used for advertising purposes.
  • ✓Your face scan images are stored securely — and only to track your skin over time. Our AI partner deletes its copy after analysis and never trains on them. We keep your images on EU infrastructure to compare your baseline with future scans, and you can delete them anytime.
  • ✓You are in control. Export everything, correct anything, or delete your account at any time.
  • ✓We tell you exactly who handles your data. See the sub-processor table below.
  • ✓We do not train third-party models (e.g. Anthropic's Claude) on your data. Improving our own algorithms is always done on pseudonymised data and only with your separate, voluntary consent.
  • ✓We collect data only directly from you. We do not buy it, obtain it from data brokers, or pull it from third-party sources.
1

Who We Are

Controller (EEA, UK & Switzerland): SenseMe GmbH, [Registered office address to be confirmed], Munich, Germany
Controller (United States & rest of world): SenseMe, Inc., 8383 Wilshire Blvd Suite 800, Beverly Hills CA 90211
Email: privacy@sensemyhealth.com

SenseMe GmbH (Munich) is the data controller for users in the EEA, the United Kingdom and Switzerland. Until SenseMe GmbH is fully operational as controller, SenseMe, Inc. (Delaware, USA) has appointed a representative in the European Union pursuant to Article 27 GDPR. You may address the EU representative or SenseMe GmbH on any data protection matter, and you may lodge a complaint with the supervisory authority of your country of habitual residence.

EU representative (Art. 27 GDPR): [Name and address of appointed representative to be confirmed]
Data Protection Officer: [To be appointed; registration with the Bavarian Data Protection Authority (BayLDA) pending] — privacy@sensemyhealth.com

2

What Data We Collect and Why

2.1 Account Data

DataPurposeLegal basisRetention
Email addressAccount creation and loginContract (Art. 6(1)(b) GDPR)Until account deletion + 30 days
Display namePersonalisationContractUntil account deletion + 30 days
Date of birth (optional)Age-appropriate reference rangesConsent (Art. 6(1)(a) GDPR)Until account deletion + 30 days

2.2 Biometric and Sensor Data (Special category — Art. 9 GDPR)

DataPurposeLegal basisRetention
Heart rate variability (HRV)Stress and recovery scoringExplicit consent (Art. 9(2)(a) GDPR)5 years, or until account deletion
Electrodermal activity (EDA)Stress and nervous system scoringExplicit consent5 years
Skin temperatureInflammation and recovery scoringExplicit consent5 years
Sleep staging (movement + HRV)Sleep domain scoringExplicit consent5 years
SpO₂ (blood oxygen, optional)Respiratory health indicatorExplicit consent5 years

2.3 Face Scan Images and AI Skin Analysis (Special category — Art. 9 GDPR)

For free users, face scan images are transmitted for analysis and deleted immediately — we do not store the image.

For subscribers, face scan images are stored securely in your account to enable longitudinal skin tracking (before/after comparison). These images are stored for the duration of your subscription and deleted within 30 days of account deletion. You can also delete individual scan images at any time from your account.
DataPurposeLegal basisRetention
Face scan image (in transit for analysis)Real-time skin analysisExplicit consentFree users: not stored — deleted immediately after analysis
Stored face scan images (subscribers only)Longitudinal skin tracking (before/after comparison)Explicit consentDuration of subscription; deleted within 30 days of account deletion; deletable anytime from your account
Skin analysis metrics (output)Skin domain scoring and trackingExplicit consent5 years

2.4 Lab and Biomarker Data (Special category — Art. 9 GDPR)

Lab samples are handed to laboratory partners exclusively with a pseudonymous barcode UUID (kit_id). Name, email address, and date of birth are not transmitted to the lab. The link between kit_id and your account exists exclusively within SenseMe infrastructure.

DataPurposeLegal basisRetention
Blood panel results (LDL, HDL, hsCRP, ApoB, Lp(a), etc.)Heart and inflammation scoringExplicit consent10 years
Hormone panel (cortisol, DHEA, etc.)Stress and energy scoringExplicit consent10 years
GI Map resultsGut health scoringExplicit consent10 years
Skin microbiome resultsSkin domain scoringExplicit consent10 years
Skin pH strip readingsSkin acid mantle trackingExplicit consent10 years

10-year retention is because longitudinal tracking is the core value of SenseMe. You can request deletion at any time (30-day turnaround).

2.5 Self-Reported Health Data (Special category — Art. 9 GDPR)

DataPurposeLegal basisRetention
Health questionnaire responsesPersonalised baselines and scoring contextExplicit consentUntil account deletion + 30 days
Supplement and medication logCorrelation and scoring contextExplicit consentUntil account deletion + 30 days

2.6a Personalized Recommendations (Advisor Engine)

SenseMe's Advisor system generates personalized supplement, skincare, and lifestyle recommendations based on your profile data, assessment responses, lab results, and scan data. This processing is performed by SenseMe's own recommendation engine using a clinical knowledge base. Legal basis: GDPR Art. 9(2)(a) (explicit consent) for health data; Art. 6(1)(b) for service delivery.

2.6b AI-Assisted Features (Claude by Anthropic)

Certain features of the SenseMe app use Claude, an AI assistant provided by Anthropic, PBC (USA). Where Claude processes your data, Anthropic acts as a sub-processor under a data processing agreement. Data sent to Claude is limited to non-identifiable context required to generate a response. Legal basis: GDPR Art. 6(1)(b). You may opt out of AI-assisted features in Settings → Privacy.

2.7 Technical and Usage Data

DataPurposeLegal basisRetention
Device type and OS versionCompatibility and debuggingLegitimate interest (Art. 6(1)(f) GDPR)90 days
Crash reports (anonymised)Bug fixingLegitimate interest90 days
App session metadataProduct improvementLegitimate interest12 months, then aggregated

No advertising identifiers (IDFA/GAID) collected.

2.8 Payment Data

We retain your Stripe customer identifier (stripe_customer_id) for 3 years after subscription termination in accordance with § 257 HGB for subscription management purposes. Full payment and invoice records are retained for 10 years in accordance with § 147 AO (German Fiscal Code).

DataPurposeLegal basisRetention
Subscription statusAccess controlContractUntil account deletion
Stripe customer identifier (stripe_customer_id)Subscription managementContract; § 257 HGB3 years after subscription termination
Invoices and transaction recordsBilling support and statutory bookkeepingLegal obligation (§ 147 AO)10 years

2.9 Improving Our Own Algorithms (Optional Consent)

SenseMe may — with your voluntary, separate consent — use pseudonymised health data to improve its own scoring models, e.g. more accurate HRV reference ranges, more precise skin scoring models, or improved biomarker correlations. This consent is voluntary.

What this means:

  • —Your direct identifiers (name, email, date of birth) are replaced with an internal UUID before processing in the training pipeline.
  • —Your data is never shared with third parties for their model training.
  • —You can withdraw this consent at any time — with no effect on your access to the Service.
  • —If you withdraw consent, your data is excluded from future training runs within 30 days.
DataPurposeLegal basisRetention
Pseudonymised biometric, lab, and skin dataImproving internal SenseMe algorithmsExplicit, separate consent (Art. 9(2)(a) GDPR)Until withdrawal or account deletion
This consent is obtained separately and is not bundled with the Terms of Use. It is not pre-filled. Declining has no effect whatsoever on the functionality of the app.

2.10 SenseMe Band Reservation

If you have reserved a SenseMe Band device, we process your name, email address, shipping address, and payment reservation details for the purpose of fulfilling your device pre-order. Legal basis: GDPR Art. 6(1)(b) (pre-contractual measures). You have the right to withdraw your reservation at any time — see our Widerrufsbelehrung for statutory withdrawal rights.

3

How We Use Your Data

We use data to: deliver SenseMe scores and insights, AI skin analysis, push notifications (opt-in only), customer support, and legal compliance.

We do NOT

  • Serve targeted advertising
  • Build advertising profiles
  • Sell data
  • Train third-party models (e.g. Anthropic's Claude) on your data
  • Improve our own algorithms with your data — unless you have explicitly consented in Section 2.9
  • Make automated decisions with legal or similarly significant effect

All AI-generated insights are informational and do not replace medical advice. No decision with legal or similarly significant effect is made solely on the basis of automated processing (Art. 22 GDPR).

Marketing emails. If you opt in to marketing emails, you can unsubscribe at any time via the unsubscribe link in every email or by emailing support@sensemyhealth.com — we process opt-outs within 5 business days. We never use your health scores, biomarker data, or scan results to target or personalise marketing content.

AI and model training. SenseMe uses aggregated and de-identified data to improve, train, and develop the AI models that power the Advisor feature and our own recommendation engine. No individually identifiable health data is used to train any external or third-party AI models (for example, Anthropic's Claude). Any use of your data to improve SenseMe's own models beyond aggregated and de-identified data is done only on pseudonymised data and only with your separate, voluntary consent, as described in Section 2.9.

4

Who We Share Your Data With

Only sub-processors under data processing agreements. We do not share data with employers, insurers, pharmaceutical companies, or advertisers. See Section 6 for the full sub-processor list.

5

International Data Transfers

SenseMe's core infrastructure is EU-based. Transfers outside the EU/EEA use Standard Contractual Clauses (SCCs). Anthropic (US) is covered by SCCs; face scan images are not retained at rest.

6

Sub-Processors

Sub-processorCountryData processedPurposeSafeguard
Anthropic, PBCUSAFace scan images (ephemeral), AI prompt contextAI skin analysis, health insightsSCC; zero-training policy
Supabase, Inc.USA (EU region hosted)All app data (encrypted at rest)Database & backend infrastructureSCCs
Stripe, Inc.USASubscription status, transaction IDsPayment processingSCCs + EU-U.S. DPF
Klaviyo, Inc.USAEmail address, marketing engagementEmail marketing & lifecycle automationSCCs + EU-U.S. DPF
Expo (Expo.io)USAPush tokens, app delivery metadataApp delivery & push notificationsSCCs
RevenueCat, Inc.USADevice identifier, purchase history, subscription entitlementsIn-app purchase managementSCCs + EU-U.S. DPF
Crash analytics providerEUAnonymised crash reportsBug fixingAdequacy decision
Synlab / BioscientiaDEkit_id + blood and hormone readingsLab analysisDPA (Art. 28 GDPR); pseudonymised via kit_id
Nordic Laboratories EUDK / EUkit_id + GI-MAP resultsLab analysisDPA; pseudonymised via kit_id
Eurofins GenomicsDEkit_id + skin microbiome NGS dataGenome sequencingDPA; pseudonymised via kit_id
Logistics providerEUShipping address (kits only)Sample shippingDPA; no health data transmitted

Lab partners receive only the barcode UUID (kit_id). Name, email, and date of birth never enter the laboratory information system (LIS). The link is made exclusively within SenseMe infrastructure.

7

Your Rights Under GDPR

Legal bases we rely on

  • —Your consent. Art. 6(1)(a) GDPR — which you may withdraw at any time, with effect for the future.
  • —Performance of the contract. Art. 6(1)(b) GDPR — to provide the Service you signed up for under our Terms of Service.
  • —Our legitimate interests. Art. 6(1)(f) GDPR — for service improvement and security, weighed against your rights.
  • —Special category (health) data. Art. 9(2)(a) GDPR — your explicit consent only. We never process health data on any other basis.

Access

Get a copy of all data we hold on you

Rectification

Correct inaccurate or incomplete data

Erasure

Delete your account and data within 30 days, except records we are legally required to retain (see below).

Restriction

Pause processing while a dispute is resolved

Portability

Where processing is based on consent or contract and carried out by automated means, receive a copy of the data you provided in a structured, commonly used, machine-readable format (Art. 20 GDPR). Request an export by emailing privacy@sensemyhealth.com; an in-app self-service export (Profile → Data & Privacy) is being rolled out.

Objection

Object to processing based on legitimate interest

Withdraw consent

Withdraw consent for special category data at any time — including the optional consent for algorithm improvement (Section 2.9)

Complaint

Lodge a complaint with your local data protection authority

Limits on erasure. Some records must be retained even after account deletion — for example, billing and transaction data kept for 7 years under applicable tax law (Section 2.8), and lab results kept for 10 years to support your longitudinal health record (Section 2.4). Where we cannot delete data, we restrict it to that sole legal purpose and do not use it for any other processing. We will tell you what was kept and why when we process your deletion request.

To exercise your rights, contact privacy@sensemyhealth.com. We respond within 30 days.

Identity verification. To protect your health data, we verify your identity before actioning any access, export, correction, or deletion request. We may ask you to confirm your registered email address or complete an in-app verification step. We will never action a data request without confirming you are the account holder.

8

Data Security

TLS 1.2+ in transit. AES-256 at rest. Access restricted to authorised personnel. Security reviews conducted regularly. In the event of a breach, we will notify you and the competent supervisory authority within 72 hours.

9

Children

SenseMe is intended for users aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If you are under 18, please do not use SenseMe or provide any personal data to us. If you believe a child has created an account, contact privacy@sensemyhealth.com to have it removed.

Under Article 8 GDPR, as applied in Germany, a child may give valid consent to the processing of their personal data from the age of 16. Because access to SenseMe is limited to users aged 18 and over, we do not rely on the consent of anyone under 18, and we do not knowingly process the personal data of anyone below that age.

10

United States — State Privacy Disclosures

California (CCPA)

California residents have the right to: Know, Delete, Opt out of sale (we don't sell data — auto-satisfied), and Non-discrimination.

To make a request, email privacy@sensemyhealth.com with the subject line "CCPA Request". We respond within 45 days.

Washington, Nevada and other states — Consumer Health Data

Certain information SenseMe collects — for example biometric readings, face scan analysis, lab results, and self-reported health inputs — may qualify as "consumer health data" under the Washington My Health My Data Act (MHMDA), the Nevada Consumer Health Data Privacy Law, and similar US state laws. Where these laws apply, we collect, use, and share such data only with your affirmative, opt-in consent, obtained separately at sign-up and before collection. We do not sell consumer health data, and we do not share it for cross-context behavioural advertising. You may withdraw your consent at any time and request access to, or deletion of, this data by emailing privacy@sensemyhealth.com.

11

Cookies and Tracking

We use cookies and similar technologies, including browser local storage, in three categories. Essential cookies are required to run the website and to remember your choices, such as your cookie preferences, language, and currency; they are always active and do not require consent. Analytics cookies, used only with your consent, help us understand how the site is used so we can improve it. Marketing cookies, used only with your consent, let us send you relevant updates, for example through Klaviyo. Non-essential cookies and marketing tags are not loaded until you have given consent.

When you first visit our website, a cookie banner lets you accept all cookies, reject all non-essential cookies, or choose categories individually. You can review or change your choice at any time using the Cookie settings link in the website footer. The legal basis for non-essential cookies is your consent (Article 6(1)(a) GDPR and Section 25 TTDSG), which you may withdraw at any time with effect for the future. We do not use cross-site advertising cookies, and the SenseMe app contains no advertising SDKs.

Our app and website may contain links to third-party services we do not operate. Their own privacy policies govern your use of those services. We are not responsible for the privacy practices of third-party sites.

12

Changes to This Policy

For material changes, we will provide in-app notice and obtain fresh consent for any new special category uses. The "Last updated" date at the top of this page always reflects the latest revision.

13

Contact

Privacy requests:privacy@sensemyhealth.com
Support:support@sensemyhealth.com
Address:SenseMe, Inc., 8383 Wilshire Blvd Suite 800, Beverly Hills CA 90211

This policy is written in English. In case of conflict between this and any translation, the English version governs.

We use cookies to run and improve SenseMe. Privacy