Node Health
← Back to home
EN

Privacy Policy

The protection of your personal data is of particular importance to us. We process your data confidentially and in accordance with legal data protection regulations, in particular the General Data Protection Regulation (GDPR), and this privacy policy.

1. Controller

Node Health UG
Kastanienallee 98A
10435 Berlin
Email: legal@nodehealth.de

Data Protection Officer

We have appointed a Data Protection Officer for our company. You can contact them as follows:

legal.solutions GmbH
Sophienstraße 1
10178 Berlin
Email: g.wirtz@pagestreet.de

Use by minors: The app is not intended for persons under 18 years of age. We do not knowingly process personal data of minors.

2. Principles of Data Processing and Categories of Data

2.1. Local Storage and Device-Based Processing

The app is designed so that your data is generally processed and stored locally on your device. Core functionalities operate directly on your iPhone or iPad. Certain Premium features require secure processing via Google Cloud infrastructure, as described below.

Locally stored data categories:

Health-related data constitute special categories of personal data within the meaning of Art. 9 GDPR. All such data remain stored locally on your device until you delete them within the app. If you enable iCloud sync (see Section 2.3), a copy is additionally stored in your personal iCloud account; in that case, uninstalling the app on a device does not delete the data from iCloud (see Section 5).

No tracking, no advertising, no behavioral profiles: The app does not use tracking technologies, third-party analytics tools, advertising technologies, or behavioral profiling.

2.2. App Analytics and Crash Reports (Apple — optional)

If you have enabled device analytics in your iOS settings (Settings → Privacy & Security → Analytics & Improvements), Apple may collect pseudonymized diagnostic and crash data. We may receive aggregated technical reports from Apple to improve stability.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability).

Your control: You can disable this transmission at any time in your system settings.

2.3. iCloud Sync (optional)

The app offers an optional iCloud sync feature that lets you keep your data in sync across your own Apple devices and restore it after reinstalling the app. If you enable this feature, your app data — including health-related data within the meaning of Art. 9 GDPR — is stored in your personal iCloud account (Apple's CloudKit private database) under your Apple ID.

Node Health does not operate the iCloud storage and has no access to it. Apple provides the iCloud service to you directly under your Apple ID, governed by Apple's own terms and privacy policy. The data stored in iCloud is under your control through your Apple ID and iCloud settings.

Legal basis: Your explicit consent pursuant to Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. iCloud sync is activated when you sign in with your Apple ID in the app — either during onboarding or later via the app's settings. You can stop further synchronization at any time by signing out within the app; signing out stops further synchronization but does not, by itself, delete data already stored in iCloud (see Section 5).

Service provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. For details on how Apple processes iCloud data, please refer to Apple's Privacy Policy.

3. Data Processing for Laboratory Data and AI Analysis

The app allows you to extract biomarkers from PDF documents or photos and to generate AI-supported analyses. In doing so, health data within the meaning of Art. 9(1) GDPR are processed.

3.1. Legal Basis: Explicit Consent

Processing of health data is carried out exclusively on the basis of your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR). Consent is obtained prior to using AI-supported features.

Withdrawal: You may withdraw your consent at any time pursuant to Art. 7(3) GDPR with effect for the future by discontinuing use of the AI features. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

3.2. Technical Processing Structure

Uploaded documents are first processed locally on your device for text extraction. For AI-supported analysis, the extracted text data are transmitted to Google AI services hosted on Google Cloud infrastructure.

The sole purpose of using Google AI is to match your biomarkers and measurement units against our internal reference database — for example, to correctly interpret laboratory values from your blood test results. No interpretation, diagnosis, or medical advice is generated.

We operate our own backend which communicates with Google solely for the purpose of performing this matching analysis. The transmitted data are processed temporarily for this purpose only and are automatically deleted after processing is complete. No uploaded files, images, or documents are retained on our servers or by Google. The data are not used for AI model training, and Google does not use the data for its own purposes.

3.3. External Processing by Google

Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Role: Google acts as a processor pursuant to Art. 28 GDPR.

We have concluded a Data Processing Agreement including EU Standard Contractual Clauses where required. Due to the global corporate structure of Google, access from third countries (including the United States) cannot be entirely excluded.

What Google does not do with your data:

3.4. Backend Logging and Technical Error Analysis

To ensure technical stability and resolve errors (e.g., failed uploads or matching issues), we maintain limited backend logs. These logs may include technical metadata, error messages, and limited portions of uploaded data where necessary to identify the cause of failure.

Logs are used exclusively for debugging and troubleshooting purposes and are automatically deleted after 48 hours. Where error logs temporarily contain excerpts of uploaded data, this occurs solely for the purpose of identifying technical failures and is subject to the same 48-hour deletion policy.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability and security), and Art. 9(2)(a) GDPR where health data are affected.

3.5. No Automated Decision-Making

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. AI-generated analyses are informational only and do not produce legally binding effects.

3.6. Strictly Opt-In — No Data Transmitted Without Your Consent

The use of Google AI for laboratory analysis is strictly opt-in. No data is transmitted to Google or our backend unless you have explicitly given your consent prior to using this feature. You will be clearly informed before any transmission occurs and may decline at any time without affecting other app functionality.

4. Subscription Services (Apple App Store)

Premium subscriptions are offered exclusively via the Apple App Store. Payments are processed solely by Apple. We do not receive or store credit card data, banking details, or Apple ID credentials.

Subscription validation is performed locally on your device using Apple's receipt validation mechanisms.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

5. Forms and Surveys (Tally)

For user feedback we occasionally provide online forms and surveys. These are hosted on our behalf by Tally BV, Oudburg 30, 9000 Ghent, Belgium.

When you fill out and submit a form, we process the survey responses you provide (e.g., information about your app usage habits and, where you choose to provide it, your email address). Tally acts as our data processor under a data processing agreement pursuant to Art. 28 GDPR. As Tally is established in Belgium, this data is processed within the EU and no transfer to a third country takes place.

The legal basis for this processing is your consent pursuant to Art. 6(1)(a) GDPR and — insofar as your responses include health-related data — Art. 9(2)(a) GDPR. Participation is voluntary; you may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR), for example by contacting us using the details above. For more information on how Tally processes data, please refer to: tally.so/help/privacy-policy.

6. Deletion of Data

You may delete your data at any time within the app. The effect of uninstalling the app depends on whether iCloud sync (Section 2.3) is enabled:

Independently of the above, you may exercise your right to erasure under Art. 17 GDPR by contacting the controller listed in Section 1.

7. Your Rights as a Data Subject

As a user of the Node Health app, you have the following rights insofar as personal data is processed:

If you wish to exercise your rights, please contact the controller listed above.

8. Competent Data Protection Supervisory Authority

If you consider that the processing of personal data concerning you infringes the GDPR, you have the right – without prejudice to any other administrative or judicial remedy – to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority competent for us is the

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany

9. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy. The latest version can be viewed within the app.

In the event of material changes, we will inform you in advance and — if required — obtain renewed consent.

Berlin, June 2026 (App Version 2.4)