Privacy Policy

Last updated: 1 July 2026 · Version 2026-07-01

Draft — pending independent legal review. This document describes how the platform is built to handle your data. It is not yet a final, lawyer-reviewed policy and is not legal advice.

Cardiometabolic ("we", "us") provides a personal, preventive cardiometabolic monitoring platform. This policy explains what data we process, why, how we protect it, and the choices you have. We process your health data — a special category of personal data under GDPR Article 9 — only with your explicit consent and only to provide the service to you.

1. Who is responsible (controller)

The operator of Cardiometabolic is the data controller for the personal data of all users of the service. For any privacy question or to exercise your rights, contact us at support@cardiometabolic.ai. (A registered legal entity + postal address will be named here on launch.)

2. Data we process

  • Account data: your email, an optional display name, and your timezone.
  • Health profile you provide during onboarding: sex, birth year, self-reported conditions (e.g. hypertension, type 2 diabetes), goals and notes — special-category health data.
  • Connected-device health data retrieved from providers you link (e.g. Withings, Garmin): body weight and composition, height, and — where available — heart rate, HRV, sleep, stress, activity, ECG and related wellness metrics.
  • Consent records: which policy version you accepted, when, and minimal request evidence (IP address, browser user-agent) kept as proof of consent.
  • Provider access tokens (OAuth), stored encrypted.
  • Technical data: minimal logs (timestamps, request IDs) for reliability and security. We do not log token values or raw health payloads in plaintext.

3. How we use it

  • Display your measurements and body composition.
  • Compute trends and aggregates (daily, multi-day, long-term).
  • Generate advisory, non-diagnostic insights (with AI assistance) to support preventive awareness and questions for your clinician.

We do not sell your data, use it for advertising, or use it to train third-party AI models.

4. Legal basis

We rely on your explicit consent (GDPR Art. 9(2)(a)) to process your health data, recorded when you create your account and when you connect a provider. Basic account operation also relies on the necessity of performing our contract with you (Art. 6(1)(b)). You may withdraw consent at any time (see "Your rights"); withdrawal does not affect processing already carried out.

5. Sub-processors we share data with

We share the minimum data needed with the service providers below. Each processes data under a data-processing agreement and only on our instructions. We do not sell data or share it with advertisers.

ProviderPurposeDataLocation
AnthropicAI-assisted insightsDe-identified health metrics for the analysis promptUS (SCCs)
ResendTransactional emailEmail addressEU
HetznerHosting & databaseAll service data (encrypted at rest)EU (Germany)
Google DriveEncrypted off-site backupEncrypted backup archivesEU region
Withings / GarminDevice data source you connectMeasurements you authorisePer provider

Withings and Garmin are the sources you connect; you grant and can revoke their access from your own provider account.

6. Storage & security

  • All traffic uses HTTPS; the database and cache are reachable only over an internal network.
  • The database volume is encrypted at rest; provider tokens are additionally encrypted (AES-256-GCM).
  • Encrypted, off-site backups are kept in the EU.
  • Every record is scoped to your account id; users cannot see each other's data.

7. Data retention

We keep your data while your account is active. When you delete your account, all your health data, profile, device links and sessions are erased immediately (cascade delete); consent records may be retained only as long as needed to evidence past lawful processing. Backups roll off on their normal cycle.

8. Your rights

Under the GDPR (EU/EEA) and similar laws you can exercise the following — most are self-service in Account settings:

  • Access & portability — download a machine-readable copy of all your data ("Export my data").
  • Erasure — permanently delete your account and all data ("Delete account").
  • Rectification — edit your profile and account details.
  • Withdraw consent — disconnect a provider to stop collection, or delete your account.
  • Object / complain — contact us, and you may lodge a complaint with your national data-protection authority.

For anything not self-service, contact support@cardiometabolic.ai.

9. International transfers

Our hosting and backups are in the EU. Some sub-processors (e.g. our AI provider) may process data outside the EEA; where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. (Exact mechanisms confirmed at legal review.)

10. AI & medical disclaimer

Insights are produced with AI assistance and are advisory and non-diagnostic. Cardiometabolic does not diagnose disease, provide medical advice, or replace a healthcare professional. Always consult a qualified clinician about your health, and seek urgent care for any emergency.

11. Cookies

We use only essential cookies needed to operate the app (sign-in session). We do not use advertising or third-party tracking cookies.

12. Children

The service is not directed to children under 16, and we do not knowingly collect their data.

13. Changes

We may update this policy. Material changes bump the version above and, where required, we will ask you to re-accept before you continue.

14. Contact

Questions or requests: support@cardiometabolic.ai. See also our Terms of Service.