Privacy Policy
The protection of your personal data is of particular importance to us. We process your data confidentially and in accordance with legal data protection regulations, in particular the General Data Protection Regulation (GDPR), and this privacy policy.
1. Controller
Node Health UGKastanienallee 98A
10435 Berlin
Email: legal@nodehealth.de
Data Protection Officer
We have appointed a Data Protection Officer for our company. You can contact them as follows:
legal.solutions GmbHSophienstraße 1
10178 Berlin
Email: g.wirtz@pagestreet.de
Use by minors: The app is not intended for persons under 18 years of age. We do not knowingly process personal data of minors.
2. Principles of Data Processing and Categories of Data
2.1. Local Storage and Device-Based Processing
The app is designed so that your data is generally processed and stored locally on your device. Core functionalities operate directly on your iPhone or iPad. Certain Premium features require secure processing via Google Cloud infrastructure, as described below.
Locally stored data categories:
- Basic profile data (e.g., name, age, gender, smoking status)
- Manually entered health data and biomarkers
- Extracted laboratory values from PDF or photo uploads
- AI-generated analyses and evaluations
Health-related data constitute special categories of personal data within the meaning of Art. 9 GDPR. All such data remain stored locally on your device until you delete them within the app. If you enable iCloud sync (see Section 2.3), a copy is additionally stored in your personal iCloud account; in that case, uninstalling the app on a device does not delete the data from iCloud (see Section 5).
No tracking, no advertising, no behavioral profiles: The app does not use tracking technologies, third-party analytics tools, advertising technologies, or behavioral profiling.
2.2. App Analytics and Crash Reports (Apple — optional)
If you have enabled device analytics in your iOS settings (Settings → Privacy & Security → Analytics & Improvements), Apple may collect pseudonymized diagnostic and crash data. We may receive aggregated technical reports from Apple to improve stability.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability).
Your control: You can disable this transmission at any time in your system settings.
2.3. iCloud Sync (optional)
The app offers an optional iCloud sync feature that lets you keep your data in sync across your own Apple devices and restore it after reinstalling the app. If you enable this feature, your app data — including health-related data within the meaning of Art. 9 GDPR — is stored in your personal iCloud account (Apple's CloudKit private database) under your Apple ID.
Node Health does not operate the iCloud storage and has no access to it. Apple provides the iCloud service to you directly under your Apple ID, governed by Apple's own terms and privacy policy. The data stored in iCloud is under your control through your Apple ID and iCloud settings.
Legal basis: Your explicit consent pursuant to Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. iCloud sync is activated when you sign in with your Apple ID in the app — either during onboarding or later via the app's settings. You can stop further synchronization at any time by signing out within the app; signing out stops further synchronization but does not, by itself, delete data already stored in iCloud (see Section 5).
Service provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. For details on how Apple processes iCloud data, please refer to Apple's Privacy Policy.
3. Data Processing for Laboratory Data and AI Analysis
The app allows you to extract biomarkers from PDF documents or photos and to generate AI-supported analyses. In doing so, health data within the meaning of Art. 9(1) GDPR are processed.
3.1. Legal Basis: Explicit Consent
Processing of health data is carried out exclusively on the basis of your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR). Consent is obtained prior to using AI-supported features.
Withdrawal: You may withdraw your consent at any time pursuant to Art. 7(3) GDPR with effect for the future by discontinuing use of the AI features. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
3.2. Technical Processing Structure
Uploaded documents are first processed locally on your device for text extraction. For AI-supported analysis, the extracted text data are transmitted to Google AI services hosted on Google Cloud infrastructure.
The sole purpose of using Google AI is to match your biomarkers and measurement units against our internal reference database — for example, to correctly interpret laboratory values from your blood test results. No interpretation, diagnosis, or medical advice is generated.
We operate our own backend which communicates with Google solely for the purpose of performing this matching analysis. The transmitted data are processed temporarily for this purpose only and are automatically deleted after processing is complete. No uploaded files, images, or documents are retained on our servers or by Google. The data are not used for AI model training, and Google does not use the data for its own purposes.
3.3. External Processing by Google
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Role: Google acts as a processor pursuant to Art. 28 GDPR.
We have concluded a Data Processing Agreement including EU Standard Contractual Clauses where required. Due to the global corporate structure of Google, access from third countries (including the United States) cannot be entirely excluded.
What Google does not do with your data:
- Retain uploaded files, images, or documents beyond temporary processing
- Use your data for marketing or advertising purposes
- Use your data for analytics or behavioral profiling
- Share your data with third parties for any purpose
- Use your data to train or improve AI models
3.4. Backend Logging and Technical Error Analysis
To ensure technical stability and resolve errors (e.g., failed uploads or matching issues), we maintain limited backend logs. These logs may include technical metadata, error messages, and limited portions of uploaded data where necessary to identify the cause of failure.
Logs are used exclusively for debugging and troubleshooting purposes and are automatically deleted after 48 hours. Where error logs temporarily contain excerpts of uploaded data, this occurs solely for the purpose of identifying technical failures and is subject to the same 48-hour deletion policy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability and security), and Art. 9(2)(a) GDPR where health data are affected.
3.5. No Automated Decision-Making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. AI-generated analyses are informational only and do not produce legally binding effects.
3.6. Strictly Opt-In — No Data Transmitted Without Your Consent
The use of Google AI for laboratory analysis is strictly opt-in. No data is transmitted to Google or our backend unless you have explicitly given your consent prior to using this feature. You will be clearly informed before any transmission occurs and may decline at any time without affecting other app functionality.
4. Subscription Services (Apple App Store)
Premium subscriptions are offered exclusively via the Apple App Store. Payments are processed solely by Apple. We do not receive or store credit card data, banking details, or Apple ID credentials.
Subscription validation is performed locally on your device using Apple's receipt validation mechanisms.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
5. Forms and Surveys (Tally)
For user feedback we occasionally provide online forms and surveys. These are hosted on our behalf by Tally BV, Oudburg 30, 9000 Ghent, Belgium.
When you fill out and submit a form, we process the survey responses you provide (e.g., information about your app usage habits and, where you choose to provide it, your email address). Tally acts as our data processor under a data processing agreement pursuant to Art. 28 GDPR. As Tally is established in Belgium, this data is processed within the EU and no transfer to a third country takes place.
The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR and — insofar as your responses include health-related data — Art. 9(2)(a) GDPR. Participation is voluntary; you may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR), for example by contacting us using the details above. For more information on how Tally processes data, please refer to: tally.so/help/privacy-policy.
6. Deletion of Data
You may delete your data at any time within the app. The effect of uninstalling the app depends on whether iCloud sync (Section 2.3) is enabled:
- iCloud sync disabled: uninstalling the app removes all locally stored data on that device completely and irretrievably, unless you have created your own backup.
- iCloud sync enabled: uninstalling the app removes the local copy on that device, but the synced copy remains in your personal iCloud account and will be restored if you reinstall the app or install it on another device signed in to the same Apple ID. To delete the iCloud copy as well, delete your data within the app before uninstalling, or remove the app's data from iCloud via your device's iCloud settings.
Independently of the above, you may exercise your right to erasure under Art. 17 GDPR by contacting the controller listed in Section 1.
7. Your Rights as a Data Subject
As a user of the Node Health app, you have the following rights insofar as personal data is processed:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure / restriction of processing (Art. 17, 18 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
If you wish to exercise your rights, please contact the controller listed above.
8. Competent Data Protection Supervisory Authority
If you consider that the processing of personal data concerning you infringes the GDPR, you have the right – without prejudice to any other administrative or judicial remedy – to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority competent for us is the
Berlin Commissioner for Data Protection and Freedom of InformationAlt-Moabit 59–61
10555 Berlin
Germany
9. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy. The latest version can be viewed within the app.
In the event of material changes, we will inform you in advance and — if required — obtain renewed consent.
Berlin, June 2026 (App Version 2.4)