Symkura is committed to protecting your data. This policy explains what we process, on which legal basis, for how long, and what your rights are.
1. Controller
Benjamin Straatmann, MakeByte, Thamaschstraße 2, 86687 Kaisheim, Germany. Email: [email protected]
2. Core principle
Symkura is privacy-first. Your health data is stored on your device and, if you use an account, synced to our own server in Germany. We never use your health data for advertising or profiling and never pass it to third parties.
3. What we process and why
Health data (special category, Art. 9 GDPR): symptom entries, pain intensity, body regions, triggers, mood, sleep, medications, notes, photos, optionally cycle and weight. Purpose: your personal symptom diary and the patient report for doctor visits. Legal basis: your explicit consent (Art. 9(2)(a) GDPR), given during setup and revocable at any time by deleting your account.
Account data: email address and password (stored only as a hash). Purpose: sign-in, cross-device sync, password reset. Legal basis: performance of contract (Art. 6(1)(b) GDPR).
Apple Health / Health Connect (optional): if you enable it in settings, Symkura reads steps, heart rate, sleep and activity from Apple Health or Health Connect to display them next to your entries. This data stays on your device only. It is not uploaded to our servers, not shared with third parties and not used for advertising. You can revoke access at any time in settings or in Apple Health / Health Connect. Symkura never writes to Apple Health or Health Connect.
Doctor appointments (optional): if you import appointments, Symkura reads the device calendars you select, read-only and with your permission. Title, time and location of the selected appointments are stored as part of your account data so the app can remind you and show your next appointment. Calendar data is never shared with third parties; Symkura never changes your calendar. Legal basis: performance of contract (Art. 6(1)(b) GDPR).
Weather data (optional): if you set a location, we query Open-Meteo (open-meteo.com) for temperature, humidity and pressure. Only the coordinates of the chosen place are sent, never account or health data. Legal basis: Art. 6(1)(b) GDPR.
Purchase data: Symkura Pro purchases are processed by Apple or Google. To verify entitlements we use RevenueCat (RevenueCat Inc., USA), which receives a pseudonymous user ID and the purchase status, no health and no payment data. Transfers to the USA are covered by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Usage statistics (optional, opt-in): with your consent we store technical events (e.g. "entry created", "export created", selected theme). These events are linked to your account, i.e. pseudonymous, not anonymous. They never contain symptoms, values, notes or photos. Legal basis: consent (Art. 6(1)(a) GDPR), revocable in settings at any time. Retention: 12 months.
Community data (optional, opt-in): with your consent we transmit, at most once a day, aggregated statistics per condition (average intensity, most frequent triggers and body regions, averages for air pressure, sleep and mood). The transmission uses a random device token that is not linked to your account; its only purpose is to update your contribution instead of duplicating it. Only the app's built-in condition names are transmitted, never your own text and never individual entries. Insights are shown only from 10 contributions per condition upwards. Legal basis: consent (Art. 6(1)(a) GDPR), revocable in settings at any time.
Feedback (optional): messages sent through the feedback form are relayed to us by a Cloudflare Function (Cloudflare Inc., USA, certified under the EU-US Data Privacy Framework) and delivered by email. Please do not include health details you do not wish to share. Legal basis: Art. 6(1)(f) GDPR (improving the app).
Email delivery: password-reset and confirmation emails are sent through Brevo (Sendinblue SAS, Paris, France) as our processor; Brevo receives your email address for this purpose.
Technical data: when your device contacts our server, IP address, timestamp and request type are processed briefly in logs to keep the service secure and prevent abuse (Art. 6(1)(f) GDPR).
4. What we do not do
No advertising, no cross-app or cross-site tracking, no sale of data, no automated decision-making, no analysis of your health data for our own purposes.
5. Storage location and security
Account and health data are stored on our own server in Germany (IONOS SE, Montabaur). We do not use US cloud services for this data. Transfers are TLS-encrypted; row-level security limits access to your own account. On your device you can additionally lock the app with a PIN or biometrics; the PIN is kept in the operating system's protected storage. App data is excluded from Google device backups.
6. Retention
Health and account data are kept until you delete your account. Account deletion removes all server data including photos; data on your device remains until you delete it in the app or remove the app. Usage statistics: 12 months. Server logs: 14 days.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to withdraw consent at any time. In the app you can view your data, export it as CSV and PDF and delete your account with all server data without contacting us. For anything else: [email protected].
You may lodge a complaint with a supervisory authority; the authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
8. Children
Symkura is not directed at persons under 16. We do not knowingly process data of children under 16.
9. Changes
We update this policy when the app or the legal situation changes and notify you of material changes in the app.
10. Contact
[email protected]
MakeByte, Thamaschstraße 2, 86687 Kaisheim, Germany