Privacy Policy

Effective May 6th, 2026Updated August 27th, 2026

Contents

This Privacy Policy applies to your use of the Outcurve mobile application (the "Services").

Outcurve is operated by Health Cloud GmbH ("Health Cloud", "we", "us", or "our"). We are the controller of personal data processed through the Services.

1) Introduction

Outcurve is an AI-powered coaching app for healthy adults that supports cognitive performance, longevity, and general wellness. The app helps users aggregate and reflect on data they choose to share with us — including consumer wearables and health platforms (such as Apple Health, Google Fit, Oura, Fitbit, Garmin, Whoop and others) through a single aggregator, lab results or medical records they upload from their device, and in-app entries. Outcurve uses artificial intelligence, including generative AI models, to analyse information you choose to provide, generate personalised wellness content, maintain long-term personalization across interactions, and support adaptive daily plans. Our Services are for wellness purposes and do not provide medical diagnosis or treatment, are not a medical device and do not replace professional medical advice. We process personal data under the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz—BDSG), and other applicable laws.

2) Our Privacy Principles

  • Your data, your choice. We process health-related data only with your explicit consent; you can withdraw consent at any time (see Section 8). Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
  • Transparency. We explain what data we collect, why we use it, the legal bases we rely on, and who receives it.
  • Data minimization. We collect only what’s needed to deliver and improve the Services.
  • No sale of personal data. We do not sell or sell access to your personal data.
  • Security by design. We implement appropriate technical and organizational measures consistent with Art. 32 GDPR.

3) What we collect & why

a) Account & identity data

What we collect

  • Email address;
  • Display name (where provided by an identity provider, such as Apple or Google when you sign in using your account with those providers);
  • Persistent user identifier;
  • Authentication and consent records (e.g., the time and date of your consent, and relevant identifiers such as IP address and user agent);
  • Push notification tokens; and
  • Basic session and feature-usage events.

Why

To create and manage your account, authenticate you, record consent, and deliver the Services, maintain security, and provide account-related communications.

Legal basis

Art. 6(1)(b) GDPR (contract)

b) Program Data

This data includes special category data under Art. 9 GDPR, specifically data related to your health. We only process this data with your explicit consent.

What we collect

  • Logged and self-reported data:
    • Meals (photos, voice, text, barcodes), nutrition estimates
    • Caffeine, hydration, supplements
    • Workouts and activity
    • Daily check-ins (energy, mood, stress, sleep quality)
    • Menstrual-cycle events and reproductive-health context
    • Free-text reflections and coach interactions
  • Wearables / device data:
    • Sleep, activity, heart rate, HRV, recovery/strain scores, body metrics
    • Data synced via connected wearables and health platforms through our aggregator partner
  • User-uploaded files:
    • Lab reports, biomarker results, medical records, PDFs, images
    • Meal photos and other files you attach in the app
  • Voice and audio:
    • Voice input streamed to an AI provider for transcription and interpretation
    • Transcripts are stored as messages; raw audio is not retained
  • Derived and inferred data:
    • Scores, trends, modelled curves (e.g., caffeine or hydration estimates)
    • AI generated explanations, summaries, plans, recommendations, recipes, workouts, and guided audio sessions
  • Long-term AI memory:
    • Profile memory: structured facts and preferences
    • Episodic memory: short summaries of past interactions
    • Used to personalize future AI interactions and outputs

Derived data and AI-generated content inherit the sensitivity of the underlying inputs.

Cycle data

If you connect Apple Health, Outcurve reads your menstrual-flow records to anchor cycle-aware coaching and — if you enable it — writes the period days you log in Outcurve back to Health. We store period dates, flow days, and derived cycle statistics only; we never collect sexual-activity data, fertility intentions, or free-text cycle notes. Cycle data is never used for advertising, sold, or shared with third parties for their own purposes; like the rest of your Program Data, it is processed by the sub-processors listed in Annex A, including the AI providers that generate your coaching. Cycle predictions are informational and are not a form of contraception.

Why

To provide the Services, including to:

  • Deliver and personalise AI-driven coaching content, plans, insights, and recommendations;
  • Display lab and wearable trends; generate scores, trends, insights, and adaptive daily plans; and
  • Maintain continuity and personalisation across interactions

With your consent, we also use pseudonymized Program Data, including health-related data, for product improvement and safety.

Legal basis

  • Art. 6(1)(b) GDPR (contract) to provide the base service.
  • Art. 6(1)(f) GDPR (legitimate interests) for personalisation, including long-term personalisation through AI memory.
  • Arts. 6(1)(a) GDPR (consent) and 9(2)(a) GDPR (explicit consent) for the processing of health-related data, including for product improvement and safety purposes.

c) Payment-related information

What we collect

  • Transaction and subscription-status information provided by app stores

What we do not collect

  • Payment card data or billing details

Why

  • To manage subscriptions and grant access to paid features

Legal basis

Art. 6(1)(b) GDPR (contract)

d) Device & Usage

What we collect

  • App version, device and OS type
  • Time zone and coarse locale
  • Crash reports and performance diagnostics
  • Minimal, non-content product analytics

Why

  • To ensure the security, reliability, and technical performance of the Services;
  • To prevent abuse;
  • To understand how the Services are used and improve app functionality, where permitted by law and your choices; and
  • To comply with consent rules for analytics, diagnostics or similar technologies where applicable, including under §25 TDDDG.

Legal basis

  • Art. 6(1)(a) GDPR (consent) to the extent that this data is not strictly necessary to provide a service you have requested (e.g., for analytics and performance diagnostics)
  • Art. 6(1)(b) GDPR (contract) to the extent that it is necessary to provide the Services (e.g., to ensure the app displays properly on your device).

e) Support & Feedback

What we collect

  • Emails or messages sent to customer support
  • Feedback, surveys, or interviews (recorded only with consent)

Why

  • To respond to inquiries and improve the Services

Legal basis

  • Art. 6(1)(b), where processing is necessary to respond to your request or provide support related to the Services;
  • Art. 6(1)(f) GDPR, where processing is necessary for our legitimate interests in responding to user inquiries, improving the Services, managing support operations.

f) Location data

What we collect

  • Precise location (GPS) and related motion and sensor data while you record a run or bike activity in the app, including — where you have granted the relevant device permission — in the background while a tracked activity is in progress
  • Routes, distance, pace, elevation and similar activity metrics derived from that location data

Background location is collected only while a run or bike activity you have started is being tracked, and stops when you end or discard the activity. You can withdraw location permissions at any time in your device settings; if you do, activity tracking features may be limited or unavailable.

Why

  • To record and display your run and bike activities, including routes, distance, pace and elevation; and
  • To generate activity metrics, trends, training insights and personalised coaching based on those activities.

Legal basis

  • Art. 6(1)(b) GDPR (contract), where processing is necessary to provide an activity-tracking feature you have requested;
  • Art. 6(1)(a) GDPR (consent), given through your device’s location permission, which you can withdraw at any time in your device settings; and
  • Art. 9(2)(a) GDPR (explicit consent), to the extent workout location data reveals health-related information. Location data collected as part of your activities is treated as Program Data.

We also process personal data to comply with legal obligations, including tax/accounting or regulatory compliance duties. Our legal basis for this processing is Article 6(1)(c) GDPR (legal obligation).

4) Sharing & disclosure

We do not sell personal data. We share only as necessary with:

a) Service providers (processors)

  • Cloud infrastructure & hosting
  • Authentication & notifications
  • Wearable aggregation
  • AI processing
  • Analytics & diagnostics

b) Independent controllers

  • App stores (e.g., Apple, Google): distribution, platform permissions, in-app purchase processing and subscription management.
  • User-directed sharing (optional): You may share selected data with a Data Recipient (e.g., your physician, trainer, employer). We’ll show what, who, and for how long before you consent; you can revoke in-app. The recipient becomes an independent controller for their copy.

5) Sources of Personal Data

Most personal data we process is provided directly by you through the Services. We may also receive personal data from third-party sources where you choose to connect those sources or use them with the Services. These sources may include identity providers, app stores, wearable and health-platform providers, and our wearable aggregation partner. We do not intentionally collect personal data about you from publicly accessible sources unless we tell you otherwise.

Whether you must provide personal data

Some personal data is necessary for us to provide the Services. For example, we need account and authentication data to create and manage your account, authenticate you and provide the Services. Some Program Data is necessary where you ask us to generate personalised coaching, insights, plans, recommendations, scores or trends.

Other data is optional, including connected wearable or health-platform data, location data for run and bike activity tracking, uploaded documents, free-text reflections, voice inputs, survey responses, optional push notifications and optional sharing with Data Recipients.

If you do not provide data that is necessary for a requested feature, we may be unable to provide that feature, or the feature may be less personalised or unavailable. If you do not provide optional data, you may still use the Services, but some features may be limited.

6) International data transfers

We primarily store/process data in the EEA. If data is transferred outside the EEA (e.g. AI inference or wearable aggregation), we use EU Standard Contractual Clauses (SCCs) and, where applicable, rely on vendor participation in the EU-U.S. Data Privacy Framework (DPF) (e.g., Apple, Google). Supplementary measures include encryption, minimization, and enterprise contractual restrictions. If you have any questions or would like to see a copy of the safeguards we rely on, please contact us using the details below.

7) Security (Art. 32 GDPR)

We apply proportionate technical and organisational measures such as encryption in transit and at rest (where supported), access controls, audit logging, secure development practices, vendor due diligence, and incident-response procedures (Arts. 32–34 GDPR).

8) Your rights

You have the right to:

  • Access, rectify, or erase personal data;
  • Restrict our processing of your personal data in certain circumstances;
  • Object to our processing of personal data that we carry out on the basis of the legitimate interests legal basis under Article 6(1)(f) GDPR;
  • Delete your account at any time, which results in the deletion of your personal data;
  • Data portability;
  • Withdraw any consent you have given at any time;
  • Lodge a complaint with your local supervisory authority.

Outcurve uses automated processing, including profiling, to generate wellness insights and scores. These do not produce legal or similarly significant effects under Art. 22 GDPR.

Requests can be sent to privacy@outcurve.ai.

9) Retention

We keep data only as long as necessary, then delete or anonymize it, subject to legal holds.

  • Account & program data (including health data, workout location data and AI memory)

    Retention
    Up to 36 months after last activity
  • Uploaded lab documents

    Retention
    Deleted on request or account closure
  • Support communications

    Retention
    18 months
  • Crash/performance logs (beta)

    Retention
    120 days
  • Payment records/invoices

    Retention
    Up to 10 years, as required to comply with our legal obligations

10) AI-assisted features

Outcurve uses AI to generate personalised wellness content, insights, plans, and recommendations. AI providers process data under enterprise/API terms that prohibit training general-purpose models on customer data. Where feasible, we pseudonymize or minimize data before AI processing. We do not permit providers to use your identifiable personal data to train their own generalized AI models.

11) Not medical care

Health Cloud provides wellness coaching and does not diagnose, treat, or provide medical care. The Services are not a medical device. If you need medical advice, consult a qualified healthcare professional.

12) Children

The Services are for adults aged 18+. We don’t knowingly collect data from children.

13) Changes

We may update this policy periodically. We’ll post updates here and notify you in-app or by email when appropriate.

14) Contact & DPO

Health Cloud GmbH
Karl-Liebknecht-Str. 29A
10178 Berlin, Germany

Privacy & rights: privacy@outcurve.ai
Data Protection Officer: David Carey

Annex A — Sub-processors

  • Apple

    Purpose
    App distribution; in-app purchases and subscription management; Sign in with Apple; HealthKit and (if enabled) Clinical Health Records permissions
    Processing location(s)
    EU / US
    Transfer mechanism
    Independent controller for payments and platform services. EU-U.S. DPF participation where applicable; SCCs as relevant
  • Google Cloud Platform

    Purpose
    Application hosting; database and file storage; backend infrastructure
    Processing location(s)
    EEA (EU regions where available)
    Transfer mechanism
    n/a (EEA processing)
  • Firebase (Google)

    Purpose
    Authentication (email link, Sign in with Apple, Sign in with Google); push notifications
    Processing location(s)
    EU / US
    Transfer mechanism
    SCCs and, where applicable, EU-U.S. DPF
  • Sentry (EEA region)

    Purpose
    Crash and error reporting, performance tracing, and backend application logs. Carries a pseudonymous account identifier (no name or email address); the content of coach conversations is not sent.
    Processing location(s)
    EEA (de.sentry.io)
    Transfer mechanism
    n/a (EEA processing)
  • Google (Gemini / Vertex AI)

    Purpose
    Generative AI processing for coaching content, explanations, plans, recommendations, transcription, and audio narration
    Processing location(s)
    EU / US
    Transfer mechanism
    SCCs; EU-U.S. DPF where applicable
  • Anthropic

    Purpose
    Generative AI processing (listed for multi-provider roadmap / redundancy)
    Processing location(s)
    US
    Transfer mechanism
    SCCs
  • Langfuse

    Purpose
    LLM tracing and evaluation for the AI coach — stores coach prompts and responses so we can debug and improve coaching quality, keyed to a pseudonymous account identifier
    Processing location(s)
    EU (cloud.langfuse.com)
    Transfer mechanism
    SCCs where applicable
  • OpenAI

    Purpose
    Generative AI and transcription (future-facing / contingency listing)
    Processing location(s)
    US
    Transfer mechanism
    SCCs; EU-U.S. DPF where applicable
  • Terra (Tryterra Inc.)

    Purpose
    Aggregation of wearable and health-platform data (e.g. Apple Health, Google Fit, Oura, Fitbit, Garmin, Whoop, Ultrahuman, Strava)
    Processing location(s)
    US
    Transfer mechanism
    SCCs
  • PostHog (EU)

    Purpose
    Product analytics, diagnostics, and performance monitoring
    Processing location(s)
    EEA
    Transfer mechanism
    Consent under §25 TDDDG; no transfer
  • Passio Inc.

    Purpose
    Food recognition and nutrition lookup for meal logging (non-identified queries)
    Processing location(s)
    US
    Transfer mechanism
    SCCs
  • Spoonacular (intelliWebConcepts)

    Purpose
    Recipe grounding and nutrition reference data (non-identified queries)
    Processing location(s)
    US
    Transfer mechanism
    SCCs

Back to top