Omniq | Last updated: 2026-07-15, revision 2

Privacy Policy

1. Controller

Omniq UG (haftungsbeschränkt)
Represented by its Managing Director: Alexey Schafheutle
Fillibachstraße 35
79104 Freiburg im Breisgau
Email: support@omniq-health.de

Given the company's current size, there is presently no statutory requirement to appoint a data protection officer. For questions about data protection, please contact the controller named above directly.

2. Data protection requests

For all data protection requests, including access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21 GDPR), please contact:

support@omniq-health.de

Omniq operates as a UG (haftungsbeschränkt). The controller can be reached for all data protection matters at the address above. As a rule, we respond to requests within the period set out in Art. 12(3) GDPR.

3. Collection and storage of personal data when visiting the website

When you visit our website, the hosting provider automatically records the following data in server log files:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • IP address
  • Time of the server request
  • Requested path, HTTP status, and technical request ID

These log data can technically be associated with a connection or a signed-in account. We use them only to deliver the service, diagnose errors, prevent abuse, and maintain security; we do not build advertising profiles from them. The legal basis is Art. 6(1)(f) GDPR (secure and reliable service delivery). Data are retained only for as long as necessary for these purposes, troubleshooting, or statutory evidence. The provider's specific configuration is reviewed regularly as part of our deletion policy.

4. Orders and customer account

When you place an order, we collect:

  • First and last name
  • Shipping and billing address
  • Email address
  • Telephone number
  • Payment information (processed by Stripe)

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). We retain order and contract data only for as long as required to perform the contract, meet warranty obligations, and establish, exercise, or defend legal claims. Documents required under tax and commercial law are then retained for those limited purposes: commercial and business correspondence is generally retained for six years, invoices and accounting records for eight years, and certain books, annual financial statements, and organisational records for ten years. Longer periods apply only where required by law or an ongoing proceeding in a particular case.

If you create a customer account, we store your data so that you can use it conveniently for future orders. You can request deletion of your account at any time through the account settings (see also the section "Your rights").

When an account is created, we record your declaration that you are aged 16 or older, your acceptance of the linked version of these Terms and Conditions, and your acknowledgement of this Privacy Policy. The evidence contains the applicable document version, the selected language, the time reported by the browser as user-supplied information, and the authoritative server-side receipt time. Its purpose is to perform and provide tamper-resistant evidence of the account and contract formation and of the information supplied. The legal bases are Art. 6(1)(b) GDPR and our legitimate interests in accountability and legal defence under Art. 6(1)(f) GDPR. Acknowledging this Privacy Policy is not consent, in particular not consent to the processing of health data or the use of AI features; those choices are made separately in the app.

This evidence remains linked to your account while the account exists and is included in your data export. When the account is deleted, we remove the account UUID from the evidence. We delete the resulting unlinked evidence on the first 1 January after six full calendar years have elapsed since its server-side receipt. If that date has already passed when the account is deleted, deletion takes place during the next regular deletion run.

5. Processing of health data (Art. 9 GDPR)

The core function of our app is to collect and analyse health data measured by your Omniq Ring. These data are special categories of personal data within the meaning of Art. 9(1) GDPR. We process them only on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide during onboarding in the app. You may withdraw consent at any time with effect for the future by using the privacy controls in the app, deleting your account, or contacting us at support@omniq-health.de. Following withdrawal, we stop processing based on that consent and erase the affected data unless another legal basis or statutory retention obligation applies. Withdrawal does not affect the lawfulness of processing carried out before it.

Specifically, we process the following categories of health data:

  • Heart rate (BPM), resting heart rate, and heart-rate zones
  • Heart-rate variability (HRV) and the recovery and readiness values derived from it
  • Oxygen saturation (SpO2) and respiratory rate
  • Skin temperature and derived body temperature
  • Sleep stages (deep, light, REM, and awake), sleep duration, sleep quality, and sleep debt
  • Activity data (steps, calories, active minutes, workouts, and heart-rate zones)
  • Optional profile data (age, sex, height, weight, and cycle data) to personalise calculations
  • Derived scores and insights (such as sleep, readiness, and effort scores and circadian recommendations)

Storage and location:Health data are processed locally in the app database and, after you provide health-data consent, additionally in our Supabase database in the Frankfurt region. Data are transferred using TLS encryption, and Supabase encrypts data at rest. Locally, the operating system's protection mechanisms apply (Android File-Based Encryption or Apple Data Protection); access tokens are stored separately from other app state in access-protected storage. Raw individual heart-rate, HRV, temperature, sleep, stress, step, activity, and GPS data are automatically erased locally and on the server after 90 days. Daily metrics calculated from those data, workouts, and entries you create are generally retained until the account is deleted or the purpose no longer applies. When an account is deleted, we remove health data from Omniq's active systems. Technically isolated backups are overwritten according to the documented provider cycles and are not restored to active processing in the meantime.

The web health dashboard is currently disabled. Consequently, health data are not processed by our Vercel-hosted Server Components. Retrieval in the mobile app and data exports take place directly between your device or browser and Supabase.

No diagnosis: Our app is a consumer wellness product and not a medical device within the meaning of the MDR. Measurements and derived scores are intended for personal guidance and are not a substitute for medical advice or diagnosis.

6. AI Coach and automated insights

Within Omniq Pro, we offer features clearly identified as AI, such as the AI Coach, weekly summaries, workout reviews, and AI-supported nutrition features. Basic does not use these features and therefore sends no data to OpenAI. Even with Pro, no request is made to OpenAI before your explicit, separately recorded AI activation. Premium status and valid AI consent are also checked on the server before every provider request. New accounts complete AI-centred onboarding only after separate, explicit AI activation. This declaration is not bundled with acceptance of the Terms and Conditions or with general health-data consent.

Depending on the feature used, Omniq sends the message or recording you provide (your prompts and conversations) and the selected health and profile data required for that request. This may include extracts from daily metrics, sleep, activity, workouts, journal and nutrition data, optional contexts you have enabled, and stored Coach memories. An optional meal image is transmitted only when you choose photo analysis for that meal; Omniq does not store the raw image. We minimise the context and do not send authentication data. Free text and images may nevertheless contain information that makes you identifiable.

The recipient and processor for customers in the EEA is explicitly OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI Ireland Ltd. may engage other OpenAI entities and approved subprocessors for the API under the OpenAI Data Processing Addendum. Which providers are actually involved in infrastructure, content moderation, or a support case initiated by us depends on the request and configuration. The current entities, purposes, and processing locations are listed in the OpenAI subprocessor list.

Legal basis: Art. 6(1)(b) GDPR for the requested Pro service and Art. 9(2)(a) GDPR for the AI-based processing of health data to which you have explicitly consented. AI consent is collected independently of general health-data consent and can be withdrawn with effect for the future in the Coach privacy settings. Following withdrawal, the app and server block all new AI requests and the Omniq core service remains locked until AI processing is explicitly enabled again. Sign-out, data export, and account deletion remain available. Withdrawal cannot recall data already transmitted to OpenAI or technically stop processing that was already in flight when the withdrawal reached us. The deletion and retention rules described below continue to apply to such data. Stored Coach data can also be deleted in the privacy settings.

Under the terms of the OpenAI API, API inputs and outputs are not used to train models by default unless the API customer explicitly opts in to data sharing. For eligible API endpoints, content may by default be retained in abuse-monitoring logs for up to 30 days. Longer retention required by law and specific feature exceptions may apply. Any onward transfer outside the EEA is based, under the OpenAI Data Processing Addendum, on an adequacy decision or Standard Contractual Clauses. We review the applicable account configuration and contractual evidence in our processor register.

Automated decision-making (Art. 22 GDPR): Recommendations generated by the AI Coach do not constitute legally binding or similarly significant decisions within the meaning of Art. 22(1) GDPR. They are intended solely for personal guidance. You may disable AI features at any time in the app settings and contact human support at support@omniq-health.de.

7. Payment processing - Stripe

We use Stripe for payment processing (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, for European customers; parent company Stripe, Inc., USA). Your payment data (card PAN, CVV, and expiry date) are collected directly and in encrypted form within Stripe's PCI DSS-certified environment. Omniq never has access to the complete card details.

After you enter your card for an Omniq Premium subscription, Stripe stores a payment-method token (a pseudonymous identifier) linked to your Stripe customer record. In our database, we store only this token and the non-sensitive metadata needed for display (card brand, last four digits, and expiry month/year), allowing the app to show "Visa •••• 4242". Stripe uses the token to charge recurring subscription payments to your card without Omniq ever processing the complete card number.

Other subscription-related data processed in our Supabase database are your Stripe customer ID, subscription ID, plan (monthly or annual), status (active, trial, cancelled, or past_due), the start and end of the current billing period, and the trial expiry date. Invoice history itself is held exclusively by Stripe. We use the Stripe API only to show links to the PDF invoices hosted there.

Account deletion and Stripe: If you delete your Omniq account, your Stripe subscription is ended so that no further renewal charges are made. Stored payment methods and the recurring-payment link are removed unless another legal basis requires otherwise. Statutory rights of withdrawal, refund, and warranty remain unaffected. Required invoices and accounting records are generally retained for eight years from the end of the relevant calendar year for limited statutory purposes under Section 257 HGB, Section 147 AO, and Section 14b UStG; a ten-year period continues to apply to certain books and annual financial statements.

The legal basis for payment and subscription processing is Art. 6(1)(b) GDPR (performance of a contract), and additionally Art. 6(1)(c) GDPR (legal obligation) for retaining invoice data. Any transfers outside the EEA take place only under the conditions described in section 11. Further information about Stripe's data processing is available in the Stripe Privacy Policy.

8. Email delivery - Resend

We use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) to send transactional emails such as order confirmations, shipping notices, password resets, and account confirmations. Your email address is transmitted to Resend for this purpose.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Any transfers outside the EEA take place only under the conditions described in section 11. Further information is available in the Resend Privacy Policy.

9. Hosting and database - Vercel and Supabase

Our website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). To deliver the website, provide account and subscription functions, and prevent abuse, Vercel processes in particular connection, session, and request metadata. The web health dashboard is disabled, and health-data exports are not routed through Vercel. Vercel may also process system and support data outside the EEA.

Our database is operated by Supabase Inc. (970 Toa Payoh North, #07-04, Singapore 318992). The primary production database is provisioned in Frankfurt, Germany. Supabase provides authentication, database, storage, and Edge Functions. Support, billing, and technical metadata may be processed outside the EEA in accordance with the contractual documents and subprocessor list.

The legal bases are Art. 6(1)(b) GDPR for account and contract functions, Art. 6(1)(f) GDPR for secure operation, and additionally your explicit consent under Art. 9(2)(a) GDPR for health data. International transfer mechanisms and data processing agreements are documented in our provider and transfer register.

10. Error diagnostics - Sentry

We use Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA) to monitor technical errors and application stability. Sentry is used only for strictly minimised crash diagnostics. Performance tracing, profiling, session replay, and screen recording are disabled; we do not use Sentry for advertising or user profiling.

Data processed may include a sanitised stack trace, browser type, a sanitised non-health URL path, timestamp, release, and narrowly limited technical tags. User identity, request data, query parameters, cookies, headers, bodies, extras, custom contexts, email addresses, access tokens, free-form exception text, and local variables are removed before transmission. Events from health, sensor, sleep, workout, nutrition, ETL, and AI areas are discarded entirely. Tracing, profiling, session replay, screenshots, and network or UI breadcrumbs are disabled.

Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in reliable and secure operation of our services). Any transfers outside the EEA take place only under the conditions described in section 11. Further information is available in the Sentry Privacy Policy.

10a. Voluntary ring battery diagnostics

In the profile settings, you can voluntarily enable the transmission of technical ring battery diagnostics. This function is disabled by default and is used to investigate unusual battery consumption and BLE or connection problems.

Data transmitted may include battery and voltage values, charging status, firmware and app versions, technical BLE and connection states, configured measurement intervals, and technical ring power counters. The ring address is truncated and hashed before transmission. Raw heart-rate, HRV, sleep, or other health values, GPS routes, names, email addresses, AI content, and the unchanged Bluetooth address are not transmitted.

Legal basis:Your consent under Art. 6(1)(a) GDPR. You may disable the function at any time in the profile settings, which stops future transmissions. You can remove battery diagnostics already uploaded by selecting "Delete uploaded diagnostics". Independently of this, server-side data are automatically erased after no more than 24 months and are included in the account deletion process.

11. Transfers to third countries

Some of the service providers named above (Stripe, Resend, Sentry, OpenAI, and Vercel) have corporate structures based in the USA. Where data are processed outside the EEA, we rely on the applicable adequacy decision under Art. 45 GDPR or Standard Contractual Clauses under Art. 46(2)(c) GDPR and assess any required supplementary measures. Before a provider is used in production, its data processing agreement, transfer mechanism, subprocessors, and actual account configuration are documented in our internal provider register. You can request information about these safeguards at support@omniq-health.de.

12. Cookies and local storage

Our website uses only cookies or local storage that are technically necessary within the meaning of Section 25(2) no. 2 TDDDG:

  • Supabase session cookies (sb-*) keep you signed in. The account does not work without them.
  • NEXT_LOCALE stores the language selected in the footer (DE/EN), so you do not need to select it again on your next visit.
  • Shopping cart state (LocalStorage) keeps items in your cart between page views.
  • Stripe cookiesare set by Stripe during checkout for fraud prevention. The legal basis is Art. 6(1)(f) GDPR; details are provided in Stripe's Privacy Policy.

We use no tracking cookies, marketing or reach analytics, remarketing, or social-media pixels. The data-minimised error diagnostics described in section 10 are used only for secure technical operation. A consent banner is therefore not required for the cookies and storage access currently in use.

13. Your rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR): You may request information about the personal data we process about you.
  • Rectification (Art. 16 GDPR): You may request correction of inaccurate data.
  • Erasure (Art. 17 GDPR): You may request erasure of your data unless statutory retention duties apply. You can delete your account through the app settings; other erasure requests can be sent to our data protection address.
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR): You may request your data in a structured, commonly used format. A machine-readable JSON export can be downloaded directly from your account or the app. Where data are held independently by payment, email, or error-diagnostics providers, we supplement the information as necessary through our manual data-subject rights process.
  • Objection (Art. 21 GDPR): On grounds relating to your particular situation, you may object at any time to processing based on Art. 6(1)(f) GDPR, in particular Sentry error diagnostics and hosting logs.
  • Withdrawal of consent (Art. 7(3) GDPR): Consent you have given, in particular for processing health data under Art. 9(2)(a) GDPR and for AI Coach use, may be withdrawn at any time with effect for the future without affecting the lawfulness of earlier processing.
  • Not to be subject to automated decisions (Art. 22 GDPR): Although our AI analyses do not make legally significant decisions, you have the right to disable the AI Coach at any time in the app settings.

To exercise your rights, contact support@omniq-health.de. We generally process your request within one month (Art. 12(3) GDPR).

14. Right to lodge a complaint with a supervisory authority

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

15. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy so that it continues to meet current legal requirements or reflects changes to our services. The updated Privacy Policy will apply to your next visit.

Last updated: July 15, 2026