Elara Logo
Elara-HealthYour pacing diary
Legal

Privacy Policy

This policy applies to the Elara Health website. The app has a separate Privacy Policy.

1. Controller and contact

MS Nucleus GmbH
Gundelfinger Straße 5
10318 Berlin, Germany
Local Court Berlin (Charlottenburg), HRB 243388
Managing Director: Frederik Marquart
E-Mail: frederik@elara-health.de

For privacy enquiries, access, erasure and withdrawal: datenschutz@elara-health.de.

2. Website access and hosting

Vercel hosts the website. Connection and technical data such as IP address, timestamp, requested resource, browser information and technical status data are processed to deliver, secure and troubleshoot the site. The legal basis is Art. 6(1)(f) GDPR. Opening a self-check page creates these connection data even though its answers remain local.

3. Contact form and email

When you contact us, we process your name, email address, optional subject and message to respond. Depending on the request, Art. 6(1)(b) or (f) GDPR applies. Resend handles email delivery. Required form details are needed to process the request; the form cannot be sent without them. Contacting us does not subscribe you to advertising.

Please do not send medical reports, diagnoses or other sensitive health details through this general contact form. Technical app support only needs a description of the problem without medical details. This notice does not rule out unsolicited receipt of such data; they are not intended for routine handling.

4. Questionnaires and self-checks

Public self-checks work without an account. Answers and results are calculated in your browser and temporarily encrypted in that tab’s session storage. Results are valid for 30 minutes; expired records are discarded on subsequent access or cleanup. Session storage normally ends with the tab session, though browser session restoration may restore it. You can also clear the site’s storage yourself.

The normal questionnaire flow does not send answers or results to our server. Questionnaire, contact, OAuth, password and API sections are excluded from website analytics. Results are not a medical diagnosis.

The website provides no iframe/embed routes and no postMessage interface for transmitting questionnaire answers or results to third-party sites.

5. One-time app-link email

After a self-check, you may optionally request a single email with an app link and general pacing tips. The basis is your separate consent under Art. 6(1)(a) GDPR. Without consent, no such email is sent; the self-check remains available. This is not a newsletter subscription.

Supabase stores the email address, language, the general source “website email request”, time, version and wording of consent. Questionnaire type, answers and results are not stored in this record. Resend receives the email address and general message needed for delivery. The request is normally removed after 30 days in a daily cleanup. This does not automatically delete separate provider delivery logs or backups, which have their own purpose-limited deletion rules.

You can withdraw consent or request erasure using the privacy contact above. Withdrawal applies prospectively and cannot recall an email already delivered.

6. Abuse prevention

Form limits use salted, pseudonymous hashes instead of raw IP addresses as keys. Upstash processes keys, counters and expiry times: IP-based limits last one hour. An additional recipient-address hash lasts up to 24 hours to prevent repeated app-link emails. This is pseudonymous, not anonymous processing. The basis is Art. 6(1)(f) GDPR and our interest in preventing spam and misuse.

7. Consent and limited website analytics

PostHog loads only after affirmative statistics consent. We capture general website sections and explicitly allowed app-link clicks with a temporary pseudonymous identifier. Detailed article or health-page URLs, query strings, URL fragments, referrers, form contents and questionnaire data are excluded from analytics events. Automatic click capture, session replay, performance capture, surveys and person profiles are not used for this website analytics setup.

The analytics identifier is kept only in the page’s memory. Technical connection data still arise when communicating with the provider. The decision is stored in the browser with its time, version and expiry for 180 days, a period chosen by us. Optional analytics relies on Art. 6(1)(a) GDPR and Section 25(1) TDDDG. We do not use Google Analytics or Google Tag Manager for website analytics.

You can accept, reject or withdraw via “Cookie Settings” in the footer. Rejection is available at the same level as acceptance. Withdrawal is also respected in other open tabs of this site. Earlier consent versions and expired decisions are not treated as fresh consent. Storage inventory in the Cookie Policy.

8. Technical error diagnosis

Sentry is used for limited technical error diagnosis, not usage analytics, based on Art. 6(1)(f) GDPR and our interest in a secure, working website. Only minimized errors with error type and permitted technical code locations are sent. Free-text errors, form data, user profiles, request contents, breadcrumbs and attachments are not included. Sensitive sections are excluded. Performance transactions, session replay and automatic session reports are disabled.

Technical transmission can produce connection data, including the IP address, at the provider. Omitting an IP field in an event does not guarantee that the provider processes no IP address.

9. Recipients and international transfers

Depending on the feature, providers include Vercel (hosting), PostHog (consented statistics), Sentry (error diagnosis), Supabase (email requests), Resend (delivery) and Upstash (abuse prevention). Providers may use subprocessors. A European server region does not automatically exclude access or processing outside the EEA.

Processing on our behalf is governed by Art. 28 GDPR. Transfers to third countries require the conditions of Arts. 44 et seq. GDPR, such as an applicable adequacy decision or Standard Contractual Clauses with necessary supplementary measures. The applicable safeguard depends on provider, contract and processing activity. Contact us for details and a copy of the safeguards applicable to your data. The provider documents below explain contractual terms, not the particular configuration used.

Vercel · PostHog · Sentry · Supabase · Resend

10. Retention and erasure

Browser data and email requests have the periods described above. Contact requests are deleted after handling is complete unless contract performance, statutory retention or a specific legal claim requires retention. Technical-log retention depends on whether a record is still needed to investigate an error or security incident; closed cases do not justify indefinite retention. Personal analytics data cease to be retained once the relevant analysis can continue without individual events. Separate provider logs and backups must be considered in their respective systems. Your erasure rights remain unaffected.

11. Your rights

Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, portability and objection under Arts. 15–21 GDPR. You may withdraw consent for the future without affecting prior lawful processing. You may object to processing based on legitimate interests for reasons relating to your particular situation. You may complain to a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.

12. No decisions with legal effect

This website does not make solely automated decisions under Art. 22 GDPR with legal or similarly significant effects. Self-check calculations only generate the displayed result.

Last updated: 15 September 2026