Privacy Policy
Last updated: August 2026
This privacy policy informs you, pursuant to Art. 13 and 14 GDPR, about the processing of your personal data when using Inself. The German version is authoritative.
1. Controller
The controller within the meaning of the GDPR and other data protection provisions is:
Inself UG (haftungsbeschränkt)
Madame-Blanc-Straße 2i
61381 Friedrichsdorf, Deutschland
Represented by: Liran Golan
Email: support@inself.io
2. Data Protection Officer
Because we process health data (special categories of personal data), we assume that the appointment of a data protection officer under § 38 BDSG is required.
Data protection contact:
Liran Golan
Email: support@inself.io
The formal appointment of a data protection officer under § 38 BDSG is required and is currently being arranged. The person named above is our data protection contact under Art. 13 GDPR, but is not (yet) the formally appointed data protection officer. Until the appointment is made, please direct data-protection requests to this contact.
3. Legal Bases for Processing
We process personal data only on one of the following legal bases, depending on the respective purpose:
- Consent (Art. 6(1)(a), Art. 9(2)(a) GDPR): e.g. for processing health data, analytics and marketing cookies, and optional features.
- Performance of a contract (Art. 6(1)(b) GDPR): to provide the account, subscriptions (Pro/Elite), blood panels, and the supplement store.
- Legal obligation (Art. 6(1)(c) GDPR): e.g. commercial and tax retention obligations.
- Legitimate interest (Art. 6(1)(f) GDPR): e.g. IT security, fraud prevention, and technical operation of the platform.
4. Processing Activities
Account creation and management
When you register, we process your name, email address, and credentials. The legal basis is performance of a contract (Art. 6(1)(b) GDPR).
Orders and payments
For subscriptions, blood panels, and supplement orders, we process order, invoicing, and payment data. Payments are handled via Stripe; full card data is not stored on our systems.
Server log files and security
When you access the platform, technical access data (e.g. IP address, time, requested resource) is processed. The legal basis is our legitimate interest in IT security and stability (Art. 6(1)(f) GDPR).
Support and communication
When you contact us, we process the information you provide to handle your request (Art. 6(1)(b) or (f) GDPR).
5. Health Data (special categories, Art. 9 GDPR)
Health data is a special category of personal data under Art. 9 GDPR and enjoys special protection. We process it solely on the basis of your explicit consent.
Within the longevity and wellness features, the following health data may be processed:
- biomarkers and blood values from blood panels (e.g. lipids, metabolism, hormones, inflammation markers)
- calculated biological age and derived analyses
- data from wearables and CGM/glucose measurements (if connected)
- self-reported health, nutrition, and training data
Legal basis: explicit consent under Art. 9(2)(a) GDPR. Without this consent, the health-related features cannot be provided.
For the OCR of the blood-test documents you upload, the analysis of biomarkers and biological age, the AI coach, and the generation of training and nutrition plans, health data (including biomarkers, information on medical history, medications, and allergies) as well as blood-test documents you upload are transmitted to our AI processor Microsoft (Azure OpenAI Service). This processing takes place within the European Union (Microsoft's Sweden Central region / EU Data Zone); your data is not transferred to a third country for it. Details are set out in Section 12. For research questions in the coach, only de-identified, health- and identifier-free queries are sent to Perplexity in the USA; how this is technically enforced is described in Section 12. Three further features transmit health-related information to providers in the USA: food-photo recognition, and email and SMS/WhatsApp notifications. The details are set out in the highlighted note below the table in Section 6. The processing is based on your explicit consent under Art. 9(2)(a) GDPR.
Scope of the data transmitted and uploaded documents: We transmit only the data required for the respective feature. The text inputs for generating training and nutrition plans do not contain your name; in the AI coach your first name is transmitted so that the coach can address you personally. Documents you upload — in particular lab reports — are, by contrast, transmitted to the AI service exactly as you upload them: we do not redact or pseudonymise them beforehand. They may therefore contain all the details the laboratory printed on them, such as name, date of birth, address, insurance number, and the referring physician. If you do not want this, you can obscure identifying details yourself before uploading.
Wearable data (recovery, sleep, workouts, cycles, profile and body measurements) is — where you connect a device such as WHOOP, Oura, Garmin, or Fitbit — integrated via our processor Junction (formerly Vital). Connecting a device is optional and based on your consent; you can disconnect it at any time.
You can withdraw your consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
6. Processors and Recipients
We use the service providers named individually below. Where they process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR. For each provider the table states the purpose, the data categories transmitted, the location of processing and — for processing outside the EU — the safeguard relied on.
| Provider | Purpose | Data categories | Location of processing | Third-country transfer / safeguard |
|---|---|---|---|---|
| Hosting & infrastructure | ||||
| Supabase Inc. | Primary database and file storage (avatars, infographics, exercise GIFs, recipe images) | all application data, including health data (Art. 9) | EU (AWS Frankfurt eu-central-1 and Stockholm eu-north-1) | EU/EEA — no third-country transfer |
| Railway Corp. | Backend hosting | all application-side processed data, including health data (Art. 9), while it passes through our API | EU (EU West) | EU/EEA — no third-country transfer |
| Vercel Inc. | Frontend hosting / delivery | technical access data (incl. IP address, timestamp, requested resource, browser and device data) | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Wearables & sensors | ||||
| Junction (vormals Vital) | Integration of wearables and sensors (incl. WHOOP, Oura, Garmin, Fitbit, Withings, Dexcom, FreeStyle Libre) — only if you connect a device | wearable and sensor data (sleep, recovery/HRV, heart rate, activity, workouts, body composition, glucose) plus, as a reference for the analysis, your internal Inself user ID, your date of birth and your gender. Name, email address, postal address and phone number are not transmitted. | EU (EU endpoint api.eu.tryvital.io) | EU/EEA — no third-country transfer |
| AI services | ||||
| Microsoft (Azure OpenAI Service) | Blood-test OCR, biomarker and biological-age analysis, AI coach, training and nutrition plans, speech-to-text in the coach, AI assistant in support, and food-photo recognition as a fallback | health data (Art. 9): biomarkers, medical history, medications, allergies, wearable values; uploaded blood-test documents (unaltered, including the details printed on them by the laboratory) and food photos; first name in the AI coach; voice recordings | EU (Sweden — Sweden Central / EU Data Zone) | EU/EEA — no third-country transfer |
| Microsoft (Azure AI Speech) | Text-to-speech voice output for the AI coach | the text of the coach reply that is read aloud; it may contain health-related statements. No voice recordings of you are transmitted here. | EU (Sweden — Sweden Central / EU Data Zone) | EU/EEA — no third-country transfer |
| Perplexity AI, Inc. | AI coach: questions about current research, current studies and current developments only | only the free-text question, de-identified before transmission, plus your display language and your selected goal (e.g. longevity). No health values, no name, no identifier — details in Section 12. | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Nutrition & recipes | ||||
| FatSecret (FatSecret Platform) | Food-photo recognition (queried first) and food/nutrition lookup | the food photo you upload and your food search terms — health-related nutrition data within the meaning of Section 5; no name and no user ID are sent along | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses; for the health-related data involved, additionally your explicit consent (Art. 49(1)(a) GDPR) |
| Spoonacular | Recipe search and nutrition data for the recipe library | recipe search terms plus, where stored, your diet type (e.g. vegetarian, vegan, ketogenic) and your intolerances or allergies. That is health-related information; no name and no user ID are sent along. | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Payments & store | ||||
| Stripe | Payment processing (subscriptions, blood panels) | payment, invoicing, and identity data, plus your internal Inself user ID as a reference | USA / EU (Ireland) | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Shopify | Supplement store (not yet active) | order and delivery data (name, email, phone, address) | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Supliful | Supplement fulfillment (currently disabled) | order and delivery address | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Communication | ||||
| Twilio Inc. (SMS) | SMS notifications (optional), phone verification and two-factor authentication | phone number, first name and message content. The notifications no longer contain any health values - they only point you to the app. | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses; for the health-related data involved, additionally your explicit consent (Art. 49(1)(a) GDPR) |
| Twilio SendGrid (E-Mail) | Sending transactional and notification emails | email address, first name and email content. Depending on the data available, the daily summary contains your biological age, your health score and your resting heart rate; the lab-results notification states the number of critical values. | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses; for the health-related data involved, additionally your explicit consent (Art. 49(1)(a) GDPR) |
| Tawk.to Inc. | Live-chat support; not currently in use. The chat is disabled by default and loads only if you give explicit consent to the “Live chat” category | name, email address and internal user ID, plus the chat transcript and the connection and device data generated when the widget loads (incl. IP address). Your phone number is not transmitted | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Analytics & identity | ||||
| PostHog | Product analytics; loaded only after you consent to analytics | usage and event data, device and session data, and — after you sign in — your internal Inself user ID | EU (EU endpoint eu.i.posthog.com) | EU/EEA — no third-country transfer |
| Google (Anmeldung mit Google) | Sign in with Google (optional; loaded only when you select it) | Google ID, email address, name, profile picture | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
| Google Maps Platform | Map display in the lab finder and geolocation | the postal code or address you enter, or the search coordinates; additionally your IP address and browser and device data when the map loads in your browser | USA | USA — EU-US Data Privacy Framework or EU standard contractual clauses (Art. 45 or Art. 46(2)(c) GDPR) |
Health-related data in the USA: the AI analysis of your health data takes place in the EU. Two places can still transmit health-related information to providers in the USA. First, food-photo recognition: your photo goes to Microsoft in the EU first, and only reaches FatSecret in the USA if that recognition returns no result. Before any such transfer we remove the additional data stored inside the image, in particular location coordinates, device details and the time it was taken. Second, the lab-results notification sent by email via Twilio SendGrid: it states the number of critical values. Our other notifications - the daily summary by email and the SMS - no longer contain any health values and only point you to the app. For the transfers named above we additionally rely on your explicit consent under Art. 49(1)(a) GDPR. You can switch the notifications off at any time in your settings and you do not have to use photo recognition; the other features are unaffected.
On the safeguards for third-country transfers: where a provider is certified under the EU-US Data Privacy Framework, the transfer is based on the European Commission's adequacy decision (Art. 45 GDPR). Otherwise we base it on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR), which for most providers are incorporated through their data-processing or usage terms and are not signed separately. We will tell you which mechanism applies to which provider on request at support@inself.io.
Analytics, marketing, and chat services are only activated after your consent via the consent banner. Necessary providers (hosting, payment, wearable integration) are required for the performance of the contract or for the features you choose.
Content services without personal data
We transmit no personal data to the following services, only generic requests: ExerciseDB (accessed via RapidAPI) for the exercise library and exercise GIFs — only exercise names and paging parameters are sent — and Google Gemini in an internal editorial process for generating recipe images, which receives only generic recipe descriptions. Both requests run from our servers; the requesting IP address is ours, not yours.
Inactive and discontinued services
These services currently receive no personal data and are therefore not in the table: OpenAI (direct US access; AI processing has run via Microsoft Azure OpenAI in the EU since July 2026), Anthropic (AI assistant in support), Groq and Together AI (AI text generation), ElevenLabs (voice output; via Microsoft Azure AI Speech in the EU since August 2026), as well as Terra (alternative wearable integration) and Chance2Brand (planned EU fulfillment). For the planned lab fulfillment with Remi Labs the technical interfaces are prepared but switched off in the production environment; Remi Labs currently receives no data. Before it goes live we will conclude the required agreement on the processing of special categories of personal data and update this list.
This table is our authoritative disclosure of the processors we use. In addition, you can request the current version at any time at support@inself.io. We notify you of changes by updating this page.
7. Cookies and Consent Management
Details on the cookies used and their categories (necessary, functional, analytics, marketing) can be found in our Cookie Policy.
8. International Transfers
Some of the providers listed above process data outside the EU/EEA, in particular in the USA. This applies to Vercel, Perplexity, FatSecret, Spoonacular, Stripe (depending on the region), Shopify, Supliful, Twilio and Twilio SendGrid, Tawk.to, and Google (Sign in with Google and Google Maps Platform). The following, by contrast, stay in the EU: the AI processing of your health data and the coach's voice output via Microsoft (Azure OpenAI Service and Azure AI Speech, Sweden Central region), the primary database and file storage (Supabase, Frankfurt and Stockholm), the wearable integration (Junction via its EU endpoint), and product analytics (PostHog via its EU endpoint).
For transfers to the USA we rely — depending on the provider — on an adequacy decision of the EU Commission (EU-US Data Privacy Framework, where the provider is certified) or on the EU Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Where health-related data is transmitted in the process — in food-photo recognition, in recipe search, and in email and SMS/WhatsApp notifications — we additionally rely on your explicit consent under Art. 49(1)(a) GDPR. Upon request, we will provide you with information on the appropriate safeguards.
9. Retention Period
We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations:
- account data: until the account is deleted
- health data (Art. 9 GDPR): until you withdraw your consent or delete your account. When you delete your account it is removed from our live systems immediately and permanently — there is no recovery or grace period. It may remain in our database backups for up to seven days: backups are created daily and automatically deleted after seven days.
- invoicing and accounting data: up to 10 years (commercial/tax obligations)
- server log files: generally short-term, then deleted or anonymized
10. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Access (Art. 15 GDPR): information about the data stored about you.
- Rectification (Art. 16 GDPR): correction of inaccurate data.
- Erasure (Art. 17 GDPR): deletion of your data, unless retention obligations apply.
- Restriction (Art. 18 GDPR): restriction of processing.
- Data portability (Art. 20 GDPR): receipt of your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21 GDPR): objection to processing based on legitimate interests.
- Withdrawal (Art. 7(3) GDPR): withdrawal of consent at any time with effect for the future.
Exercise your rights
Email: support@inself.io
11. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work, or place of the alleged infringement.
12. Automated Analyses and AI
Inself uses algorithms and AI to create personalized analyses and recommendations (e.g. training, nutrition, and supplement plans). These serve wellness purposes only and do not constitute medical diagnosis or treatment. There is no solely automated decision with legal effect within the meaning of Art. 22 GDPR.
All AI features that process health data run via Microsoft (Azure OpenAI Service) in the EU (see below). Voice output for the coach likewise runs via Microsoft (Azure AI Speech) in the EU; ElevenLabs, the US service previously used for it, is no longer used. Perplexity receives only de-identified research queries with no health data and no identifying reference; how this is technically enforced is described below. The services previously used — Groq, Together AI and Anthropic — no longer receive any data. Details of the data categories transmitted in each case can be found in the table in Section 6.
AI processing via Microsoft Azure OpenAI Service (EU)
The following features use AI models that we operate via Microsoft's Azure OpenAI Service:
- extracting values from the blood-test documents you upload (OCR)
- analysing biomarkers and biological-age indicators
- generating personalised nutrition, training, sleep/recovery, and supplement guidance through the AI coach
Microsoft acts as our processor for this. When you use an AI feature, the data required for it — including special categories of personal data under Art. 9 GDPR (health data) — is transmitted to this service in order to generate the result. Microsoft's data processing agreement (Microsoft Products and Services Data Protection Addendum, Art. 28 GDPR, including the EU standard contractual clauses) is incorporated via the Azure agreement; it is not signed separately.
Location of processing: exclusively within the European Union (Microsoft's Sweden Central region / EU Data Zone). Your data is not transferred outside the EU for this processing.
Not used to train AI models: Microsoft does not use your prompts or the generated outputs to train or improve its own models.
Retention at Microsoft: Microsoft may retain the data sent to the service for up to 30 days solely for security and abuse-monitoring purposes, after which it is deleted. How long we ourselves retain your results is described in Section 9 (Retention Period).
Data minimisation: We transmit only the data needed for the respective feature. Documents you upload are, however, transmitted unaltered and may contain the identifying details printed on them by the laboratory — see Section 5 for details.
Legal basis: your explicit consent under Art. 9(2)(a) GDPR, together with Art. 6(1)(b) GDPR for providing the features you have chosen.
Research questions via Perplexity (USA)
If you ask the coach about current studies, current research or current developments, that one question is answered by Perplexity with source citations. To ensure no health data leaves the EU for this, the path is technically tightly bounded:
- Structured health and profile data is never transmitted. Technically, only two items may go along: your display language and your selected goal (e.g. longevity). All other fields — such as biomarkers, medications, allergies or age — are dropped before sending, and an upstream check aborts the request if they were present nonetheless.
- Your free-text question is de-identified before transmission: specific values and identifying details are removed and the question is generalised.
- If a question cannot be generalised safely, it is not sent to Perplexity but answered by our AI processor in the EU (Microsoft Azure OpenAI Service). In case of doubt, processing therefore ends in the EU.
Perplexity acts as a processor for us on the basis of its API terms of service; the data processing agreement under Art. 28 GDPR, including the EU standard contractual clauses (Modules 2 and 3), is incorporated through them and is not signed separately. The content transmitted is not used to train AI models.
13. Changes to This Privacy Policy
We update this privacy policy if processing or the legal situation changes. The version published on this page applies.
This privacy policy is a structurally complete draft. The binding version requires review by a German lawyer. (German text controls.)