Privacy Policy
Effective May 6th, 2026Updated August 27th, 2026
Contents
This Privacy Policy applies to your use of the Outcurve mobile application (the "Services").
Outcurve is operated by Health Cloud GmbH ("Health Cloud", "we", "us", or "our"). We are the controller of personal data processed through the Services.
1) Introduction
Outcurve is an AI-powered coaching app for healthy adults that supports cognitive performance, longevity, and general wellness. The app helps users aggregate and reflect on data they choose to share with us — including consumer wearables and health platforms (such as Apple Health, Google Fit, Oura, Fitbit, Garmin, Whoop and others) through a single aggregator, lab results or medical records they upload from their device, and in-app entries. Outcurve uses artificial intelligence, including generative AI models, to analyse information you choose to provide, generate personalised wellness content, maintain long-term personalization across interactions, and support adaptive daily plans. Our Services are for wellness purposes and do not provide medical diagnosis or treatment, are not a medical device and do not replace professional medical advice. We process personal data under the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz—BDSG), and other applicable laws.
2) Our Privacy Principles
- Your data, your choice. We process health-related data only with your explicit consent; you can withdraw consent at any time (see Section 8). Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
- Transparency. We explain what data we collect, why we use it, the legal bases we rely on, and who receives it.
- Data minimization. We collect only what’s needed to deliver and improve the Services.
- No sale of personal data. We do not sell or sell access to your personal data.
- Security by design. We implement appropriate technical and organizational measures consistent with Art. 32 GDPR.
3) What we collect & why
a) Account & identity data
What we collect
- Email address;
- Display name (where provided by an identity provider, such as Apple or Google when you sign in using your account with those providers);
- Persistent user identifier;
- Authentication and consent records (e.g., the time and date of your consent, and relevant identifiers such as IP address and user agent);
- Push notification tokens; and
- Basic session and feature-usage events.
Why
To create and manage your account, authenticate you, record consent, and deliver the Services, maintain security, and provide account-related communications.
Legal basis
Art. 6(1)(b) GDPR (contract)
b) Program Data
This data includes special category data under Art. 9 GDPR, specifically data related to your health. We only process this data with your explicit consent.
What we collect
- Logged and self-reported data:
- Meals (photos, voice, text, barcodes), nutrition estimates
- Caffeine, hydration, supplements
- Workouts and activity
- Daily check-ins (energy, mood, stress, sleep quality)
- Menstrual-cycle events and reproductive-health context
- Free-text reflections and coach interactions
- Wearables / device data:
- Sleep, activity, heart rate, HRV, recovery/strain scores, body metrics
- Data synced via connected wearables and health platforms through our aggregator partner
- User-uploaded files:
- Lab reports, biomarker results, medical records, PDFs, images
- Meal photos and other files you attach in the app
- Voice and audio:
- Voice input streamed to an AI provider for transcription and interpretation
- Transcripts are stored as messages; raw audio is not retained
- Derived and inferred data:
- Scores, trends, modelled curves (e.g., caffeine or hydration estimates)
- AI generated explanations, summaries, plans, recommendations, recipes, workouts, and guided audio sessions
- Long-term AI memory:
- Profile memory: structured facts and preferences
- Episodic memory: short summaries of past interactions
- Used to personalize future AI interactions and outputs
Derived data and AI-generated content inherit the sensitivity of the underlying inputs.
Cycle data
If you connect Apple Health, Outcurve reads your menstrual-flow records to anchor cycle-aware coaching and — if you enable it — writes the period days you log in Outcurve back to Health. We store period dates, flow days, and derived cycle statistics only; we never collect sexual-activity data, fertility intentions, or free-text cycle notes. Cycle data is never used for advertising, sold, or shared with third parties for their own purposes; like the rest of your Program Data, it is processed by the sub-processors listed in Annex A, including the AI providers that generate your coaching. Cycle predictions are informational and are not a form of contraception.
Why
To provide the Services, including to:
- Deliver and personalise AI-driven coaching content, plans, insights, and recommendations;
- Display lab and wearable trends; generate scores, trends, insights, and adaptive daily plans; and
- Maintain continuity and personalisation across interactions
With your consent, we also use pseudonymized Program Data, including health-related data, for product improvement and safety.
Legal basis
- Art. 6(1)(b) GDPR (contract) to provide the base service.
- Art. 6(1)(f) GDPR (legitimate interests) for personalisation, including long-term personalisation through AI memory.
- Arts. 6(1)(a) GDPR (consent) and 9(2)(a) GDPR (explicit consent) for the processing of health-related data, including for product improvement and safety purposes.
c) Payment-related information
What we collect
- Transaction and subscription-status information provided by app stores
What we do not collect
- Payment card data or billing details
Why
- To manage subscriptions and grant access to paid features
Legal basis
Art. 6(1)(b) GDPR (contract)
d) Device & Usage
What we collect
- App version, device and OS type
- Time zone and coarse locale
- Crash reports and performance diagnostics
- Minimal, non-content product analytics
Why
- To ensure the security, reliability, and technical performance of the Services;
- To prevent abuse;
- To understand how the Services are used and improve app functionality, where permitted by law and your choices; and
- To comply with consent rules for analytics, diagnostics or similar technologies where applicable, including under §25 TDDDG.
Legal basis
- Art. 6(1)(a) GDPR (consent) to the extent that this data is not strictly necessary to provide a service you have requested (e.g., for analytics and performance diagnostics)
- Art. 6(1)(b) GDPR (contract) to the extent that it is necessary to provide the Services (e.g., to ensure the app displays properly on your device).
e) Support & Feedback
What we collect
- Emails or messages sent to customer support
- Feedback, surveys, or interviews (recorded only with consent)
Why
- To respond to inquiries and improve the Services
Legal basis
- Art. 6(1)(b), where processing is necessary to respond to your request or provide support related to the Services;
- Art. 6(1)(f) GDPR, where processing is necessary for our legitimate interests in responding to user inquiries, improving the Services, managing support operations.
f) Location data
What we collect
- Precise location (GPS) and related motion and sensor data while you record a run or bike activity in the app, including — where you have granted the relevant device permission — in the background while a tracked activity is in progress
- Routes, distance, pace, elevation and similar activity metrics derived from that location data
Background location is collected only while a run or bike activity you have started is being tracked, and stops when you end or discard the activity. You can withdraw location permissions at any time in your device settings; if you do, activity tracking features may be limited or unavailable.
Why
- To record and display your run and bike activities, including routes, distance, pace and elevation; and
- To generate activity metrics, trends, training insights and personalised coaching based on those activities.
Legal basis
- Art. 6(1)(b) GDPR (contract), where processing is necessary to provide an activity-tracking feature you have requested;
- Art. 6(1)(a) GDPR (consent), given through your device’s location permission, which you can withdraw at any time in your device settings; and
- Art. 9(2)(a) GDPR (explicit consent), to the extent workout location data reveals health-related information. Location data collected as part of your activities is treated as Program Data.
We also process personal data to comply with legal obligations, including tax/accounting or regulatory compliance duties. Our legal basis for this processing is Article 6(1)(c) GDPR (legal obligation).
5) Sources of Personal Data
Most personal data we process is provided directly by you through the Services. We may also receive personal data from third-party sources where you choose to connect those sources or use them with the Services. These sources may include identity providers, app stores, wearable and health-platform providers, and our wearable aggregation partner. We do not intentionally collect personal data about you from publicly accessible sources unless we tell you otherwise.
Whether you must provide personal data
Some personal data is necessary for us to provide the Services. For example, we need account and authentication data to create and manage your account, authenticate you and provide the Services. Some Program Data is necessary where you ask us to generate personalised coaching, insights, plans, recommendations, scores or trends.
Other data is optional, including connected wearable or health-platform data, location data for run and bike activity tracking, uploaded documents, free-text reflections, voice inputs, survey responses, optional push notifications and optional sharing with Data Recipients.
If you do not provide data that is necessary for a requested feature, we may be unable to provide that feature, or the feature may be less personalised or unavailable. If you do not provide optional data, you may still use the Services, but some features may be limited.
6) International data transfers
We primarily store/process data in the EEA. If data is transferred outside the EEA (e.g. AI inference or wearable aggregation), we use EU Standard Contractual Clauses (SCCs) and, where applicable, rely on vendor participation in the EU-U.S. Data Privacy Framework (DPF) (e.g., Apple, Google). Supplementary measures include encryption, minimization, and enterprise contractual restrictions. If you have any questions or would like to see a copy of the safeguards we rely on, please contact us using the details below.
7) Security (Art. 32 GDPR)
We apply proportionate technical and organisational measures such as encryption in transit and at rest (where supported), access controls, audit logging, secure development practices, vendor due diligence, and incident-response procedures (Arts. 32–34 GDPR).
8) Your rights
You have the right to:
- Access, rectify, or erase personal data;
- Restrict our processing of your personal data in certain circumstances;
- Object to our processing of personal data that we carry out on the basis of the legitimate interests legal basis under Article 6(1)(f) GDPR;
- Delete your account at any time, which results in the deletion of your personal data;
- Data portability;
- Withdraw any consent you have given at any time;
- Lodge a complaint with your local supervisory authority.
Outcurve uses automated processing, including profiling, to generate wellness insights and scores. These do not produce legal or similarly significant effects under Art. 22 GDPR.
Requests can be sent to privacy@outcurve.ai.
9) Retention
We keep data only as long as necessary, then delete or anonymize it, subject to legal holds.
| Dataset | Retention |
|---|---|
| Account & program data (including health data, workout location data and AI memory) | Up to 36 months after last activity |
| Uploaded lab documents | Deleted on request or account closure |
| Support communications | 18 months |
| Crash/performance logs (beta) | 120 days |
| Payment records/invoices | Up to 10 years, as required to comply with our legal obligations |
Account & program data (including health data, workout location data and AI memory)
- Retention
- Up to 36 months after last activity
Uploaded lab documents
- Retention
- Deleted on request or account closure
Support communications
- Retention
- 18 months
Crash/performance logs (beta)
- Retention
- 120 days
Payment records/invoices
- Retention
- Up to 10 years, as required to comply with our legal obligations
10) AI-assisted features
Outcurve uses AI to generate personalised wellness content, insights, plans, and recommendations. AI providers process data under enterprise/API terms that prohibit training general-purpose models on customer data. Where feasible, we pseudonymize or minimize data before AI processing. We do not permit providers to use your identifiable personal data to train their own generalized AI models.
11) Not medical care
Health Cloud provides wellness coaching and does not diagnose, treat, or provide medical care. The Services are not a medical device. If you need medical advice, consult a qualified healthcare professional.
12) Children
The Services are for adults aged 18+. We don’t knowingly collect data from children.
13) Changes
We may update this policy periodically. We’ll post updates here and notify you in-app or by email when appropriate.
14) Contact & DPO
Health Cloud GmbH
Karl-Liebknecht-Str. 29A
10178 Berlin, Germany
Privacy & rights: privacy@outcurve.ai
Data Protection Officer: David Carey
Annex A — Sub-processors
| Processor | Purpose | Processing location(s) | Transfer mechanism |
|---|---|---|---|
| Apple | App distribution; in-app purchases and subscription management; Sign in with Apple; HealthKit and (if enabled) Clinical Health Records permissions | EU / US | Independent controller for payments and platform services. EU-U.S. DPF participation where applicable; SCCs as relevant |
| Google Cloud Platform | Application hosting; database and file storage; backend infrastructure | EEA (EU regions where available) | n/a (EEA processing) |
| Firebase (Google) | Authentication (email link, Sign in with Apple, Sign in with Google); push notifications | EU / US | SCCs and, where applicable, EU-U.S. DPF |
| Sentry (EEA region) | Crash and error reporting, performance tracing, and backend application logs. Carries a pseudonymous account identifier (no name or email address); the content of coach conversations is not sent. | EEA (de.sentry.io) | n/a (EEA processing) |
| Google (Gemini / Vertex AI) | Generative AI processing for coaching content, explanations, plans, recommendations, transcription, and audio narration | EU / US | SCCs; EU-U.S. DPF where applicable |
| Anthropic | Generative AI processing (listed for multi-provider roadmap / redundancy) | US | SCCs |
| Langfuse | LLM tracing and evaluation for the AI coach — stores coach prompts and responses so we can debug and improve coaching quality, keyed to a pseudonymous account identifier | EU (cloud.langfuse.com) | SCCs where applicable |
| OpenAI | Generative AI and transcription (future-facing / contingency listing) | US | SCCs; EU-U.S. DPF where applicable |
| Terra (Tryterra Inc.) | Aggregation of wearable and health-platform data (e.g. Apple Health, Google Fit, Oura, Fitbit, Garmin, Whoop, Ultrahuman, Strava) | US | SCCs |
| PostHog (EU) | Product analytics, diagnostics, and performance monitoring | EEA | Consent under §25 TDDDG; no transfer |
| Passio Inc. | Food recognition and nutrition lookup for meal logging (non-identified queries) | US | SCCs |
| Spoonacular (intelliWebConcepts) | Recipe grounding and nutrition reference data (non-identified queries) | US | SCCs |
Apple
- Purpose
- App distribution; in-app purchases and subscription management; Sign in with Apple; HealthKit and (if enabled) Clinical Health Records permissions
- Processing location(s)
- EU / US
- Transfer mechanism
- Independent controller for payments and platform services. EU-U.S. DPF participation where applicable; SCCs as relevant
Google Cloud Platform
- Purpose
- Application hosting; database and file storage; backend infrastructure
- Processing location(s)
- EEA (EU regions where available)
- Transfer mechanism
- n/a (EEA processing)
Firebase (Google)
- Purpose
- Authentication (email link, Sign in with Apple, Sign in with Google); push notifications
- Processing location(s)
- EU / US
- Transfer mechanism
- SCCs and, where applicable, EU-U.S. DPF
Sentry (EEA region)
- Purpose
- Crash and error reporting, performance tracing, and backend application logs. Carries a pseudonymous account identifier (no name or email address); the content of coach conversations is not sent.
- Processing location(s)
- EEA (de.sentry.io)
- Transfer mechanism
- n/a (EEA processing)
Google (Gemini / Vertex AI)
- Purpose
- Generative AI processing for coaching content, explanations, plans, recommendations, transcription, and audio narration
- Processing location(s)
- EU / US
- Transfer mechanism
- SCCs; EU-U.S. DPF where applicable
Anthropic
- Purpose
- Generative AI processing (listed for multi-provider roadmap / redundancy)
- Processing location(s)
- US
- Transfer mechanism
- SCCs
Langfuse
- Purpose
- LLM tracing and evaluation for the AI coach — stores coach prompts and responses so we can debug and improve coaching quality, keyed to a pseudonymous account identifier
- Processing location(s)
- EU (cloud.langfuse.com)
- Transfer mechanism
- SCCs where applicable
OpenAI
- Purpose
- Generative AI and transcription (future-facing / contingency listing)
- Processing location(s)
- US
- Transfer mechanism
- SCCs; EU-U.S. DPF where applicable
Terra (Tryterra Inc.)
- Purpose
- Aggregation of wearable and health-platform data (e.g. Apple Health, Google Fit, Oura, Fitbit, Garmin, Whoop, Ultrahuman, Strava)
- Processing location(s)
- US
- Transfer mechanism
- SCCs
PostHog (EU)
- Purpose
- Product analytics, diagnostics, and performance monitoring
- Processing location(s)
- EEA
- Transfer mechanism
- Consent under §25 TDDDG; no transfer
Passio Inc.
- Purpose
- Food recognition and nutrition lookup for meal logging (non-identified queries)
- Processing location(s)
- US
- Transfer mechanism
- SCCs
Spoonacular (intelliWebConcepts)
- Purpose
- Recipe grounding and nutrition reference data (non-identified queries)
- Processing location(s)
- US
- Transfer mechanism
- SCCs