clarimeno
Legal

Privacy Policy

Last updated: August 12, 2026

1. Controller

The controller responsible for data processing on clarimeno.app and in the Clarimeno iOS and watchOS apps is sydacos GmbH, Hasenböge 17, 21514 Klein Pampau, Germany ("we"). You can reach us at contact@clarimeno.app.

This policy covers two things: this website, and the Clarimeno app. They handle very different data, so they are described separately below.

2. This website: no cookies, no tracking

clarimeno.app sets no cookies and loads no third-party advertising or tracking scripts. Because no cookies or comparable identifiers are used, no consent banner is required (§ 25 TDDDG).

The site is hosted by Vercel Inc. Web servers process technical connection data (IP address, requested page, user agent, timestamp) to deliver the site securely; this is our legitimate interest under Art. 6 (1)(f) GDPR. Server logs are retained only briefly by our hosting provider.

We use Vercel Web Analytics, a cookieless, privacy-preserving measurement tool. It counts page views and referrers in aggregate using a temporary hash that cannot identify you across sites or days; no cross-site profile is built and no cookie is set.

3. Waitlist

If you join the waitlist, your email address, language and the time of your consent are stored on our EU servers (AWS Frankfurt) and used for one purpose only: to tell you when Clarimeno becomes available. The legal basis is your consent (Art. 6 (1)(a) GDPR). You can withdraw at any time by emailing contact@clarimeno.app, and the address is then deleted.

Signing up uses double opt-in: we first send you a confirmation email (via Amazon Web Services in Frankfurt) containing a link that is valid for 14 days; the link opens a confirmation page, and only pressing the confirm button there completes the signup. To be able to prove your consent, we also record the time of the confirmation and the IP address and browser information of the confirming request. If you do not confirm, your address is deleted automatically after 180 days at the latest.

4. The Clarimeno app: account data

When you create an account, our authentication provider Clerk Inc. processes your sign-in data (email address or Apple ID identifier). Clerk never receives health data. The legal basis is performance of the contract (Art. 6 (1)(b) GDPR).

5. The Clarimeno app: health data

Health data is special-category data under Art. 9 GDPR. Clarimeno processes it only with your explicit consent (Art. 9 (2)(a) GDPR), which the app asks for separately during onboarding — one consent for health-data processing, one for AI processing. Each consent is recorded with its policy version, language and timestamp, and you can withdraw by deleting your account at any time.

Data minimization is built in: raw Apple Health samples never leave your iPhone. The app aggregates them on-device into daily summaries (for example: hours slept, resting heart rate, wrist-temperature deviation, cycle phase), and only these daily aggregates sync to our servers.

All backend data is stored and processed exclusively in the EU (AWS Frankfurt, eu-central-1), encrypted in transit and at rest with dedicated keys. Our server logs never contain symptom values, health values or insight text.

6. AI-generated insights

To generate insights, a pseudonymous extract — a compact 14-day table of your symptom and health aggregates, without your name, email or any identifier — is processed by Anthropic (Claude model) on our behalf. Insights are labeled as AI-generated in the app, together with the model and provider, and they are never medical advice.

The legal basis is your separate, explicit AI-processing consent (Art. 9 (2)(a) GDPR). If you do not consent, the rest of the app remains fully usable.

7. Subscriptions

Purchases and subscriptions are handled entirely by Apple through the App Store; Apple is the merchant of record. We receive transaction confirmations but never your payment details.

8. Your rights: export and deletion built in

You can export a complete copy of your data as a machine-readable bundle directly in the app (Art. 15 and 20 GDPR). Export downloads are time-limited links and the export files are automatically removed after 7 days.

Deleting your account in the app erases everything — your profile, logs, health aggregates, insights and consents — on our servers and at our processors, including your Clerk account (Art. 17 GDPR). Access is revoked immediately and the purge completes shortly afterwards.

You additionally have the rights to rectification (Art. 16), restriction (Art. 18) and objection (Art. 21), and the right to lodge a complaint with a supervisory authority — for us: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD).

9. Processors and transfers

We use the following processors: Amazon Web Services (hosting, Frankfurt/Germany), Clerk Inc. (authentication, USA), Anthropic PBC (AI insight generation, USA), Vercel Inc. (website hosting and cookieless analytics, USA/EU) and Apple Inc. (App Store purchases).

Where processors are located outside the EEA, transfers are safeguarded by EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Your health aggregates are stored only in the EU; the pseudonymous insight extracts described in section 6 are the only health-related data processed by a non-EEA processor.

10. Changes

We will update this policy as Clarimeno evolves, and material changes to app-data processing will be re-consented in the app. The current version always lives at clarimeno.app/privacy.