The protection of your personal data, and in particular your health data, is important to us. This Privacy Policy informs you about which personal data are processed when you use the Elara Health App (“Elara”), for what purposes this processing takes place, and what rights you have.
1. Controller and Data Protection Officer
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
MS Nucleus GmbH
Gundelfinger Straße 5
10318 Berlin
Germany
Commercial Register of the Local Court of Berlin (Charlottenburg), HRB 243388
Represented by Managing Director Frederik Marquart
Email: frederik@elara-health.de
A Data Protection Officer has been appointed for MS Nucleus GmbH.
You can contact our Data Protection Officer at:
Gundelfinger Straße 5
10318 Berlin
Germany
Email: datenschutz@elara-health.de
For questions regarding data protection and for exercising your data protection rights, you may contact our Data Protection Officer directly.
2. Scope
This Privacy Policy applies to the Elara Health App and the services directly associated with it.
Elara is intended exclusively for persons aged 18 and over and serves the personal documentation, presentation and reflection of health-related information.
Elara does not replace medical advice, diagnosis or treatment.
3. What data do we process?
Depending on which functions you use, the following data in particular may be processed:
- account and profile data, in particular email address, user ID and settings;
- health data, in particular symptoms, energy, sleep, mood, exertion, activities, medications, cycle information, information on Post-Exertional Malaise (PEM), questionnaire results and laboratory values;
- wearable and sensor data, for example heart rate, resting heart rate, heart rate variability, steps, activity and sleep data;
- meal photos and meal information derived from them if you voluntarily use the meal photo scan;
- location information insofar as you voluntarily use local functions such as weather information;
- technical data, for example IP address, device type, operating system, app version, technical identifiers as well as error and diagnostic data;
- push identifiers insofar as these are required for notifications activated by you;
- communication data if you contact us;
- derived data, for example trends, scores and statistical analyses.
The data are predominantly provided directly by you. Where wearable and sensor data are not collected directly from you, they originate from the health or wearable services that you have voluntarily connected. The categories of data we receive from such a service depend on the respective integration and the permissions you have granted. We do not receive wearable or health data from services that you have not connected to Elara yourself.
4. Purposes and legal bases
4.1 User account and provision of Elara
Account data and required technical data are processed in order to set up and manage your user account, authenticate you and provide you with the functions of Elara.
Legal basis: Art. 6(1)(b) GDPR.
4.2 Health functions and personal analyses
Health data are processed in order to provide the health functions requested by you. These include, in particular, the documentation of your information, the presentation of developments over time, personal analyses, scores, trends as well as reports and exports.
We obtain your explicit consent for the processing of your health data.
Legal bases: Art. 6(1)(b) GDPR in conjunction with Art. 9(2)(a) GDPR.
You may withdraw your consent to the processing of health data at any time with effect for the future. Functions that require the processing of such data may then no longer be available.
4.3 Wearables and external health services
You may voluntarily connect Elara to supported health and wearable services, in particular:
- Apple Health / HealthKit;
- Google Health Connect;
- Garmin;
- Fitbit;
- Oura.
Which data are transferred depends on the respective integration and the permissions you have granted. Where the data do not originate directly from you, the service connected by you is the source of the data. Elara receives only those categories of data that have been authorised for the integration activated by you.
A connection can be disconnected at any time or revoked via your device or the respective provider.
Legal bases: Art. 6(1)(a) GDPR and, for health data, Art. 9(2)(a) GDPR.
4.4 Meal photo scan
If you voluntarily use the meal photo scan, the photo selected by you is transmitted to OpenAI Ireland Ltd. for automated analysis. To the extent that OpenAI processes personal data on our behalf, this takes place on the basis of a data processing agreement.
We do not transmit your email address, user ID or other account data to OpenAI. However, the photo itself may contain personal information, for example if persons, documents or other identifying content are visible. Technical image metadata may also be part of an image file insofar as they have not already been removed prior to transmission.
The photo is used by Elara exclusively to carry out the analysis requested by you and is not permanently stored by us as an image. Meal information derived from the photo may be stored within Elara.
For the OpenAI API project currently used by Elara, no data residency restricted to the European Economic Area has been configured. Processing of content transmitted via the API may therefore take place outside the EEA, in particular in the United States or other processing regions used by OpenAI or its subprocessors. Further information on international data transfers can be found in Section 9.
OpenAI does not use customer data provided via the API by default to train or improve its general models unless the API customer expressly agrees to such use. The specific retention period may also depend on the API endpoint used and its configuration. As part of standard abuse monitoring, API content and technical information derived from it may generally be retained for up to 30 days unless different data retention controls enabled by OpenAI apply to the API project being used. In exceptional cases required by law or for security reasons, longer retention may occur.
Where possible, please only upload photos of meals that do not contain persons, documents or other identifying information.
Legal bases: Art. 6(1)(b) GDPR and, insofar as the photo or the information derived from it constitutes health data, Art. 9(2)(a) GDPR.
4.5 Weather information
If you use local weather information, the approximate location reference required for the weather query is processed. The location reference may be derived from an approximate device location.
Precise GPS location of your device is not required for this function. For the weather query, in particular a location reference at city level or approximate geographical coordinates derived from it may be transmitted to Open-Meteo.
In addition, technically required connection data may be generated by the weather service. Open-Meteo states that server logs may contain, among other things, IP addresses and geographical coordinates and that individual log files are deleted after 90 days.
Legal basis: Art. 6(1)(b) GDPR.
4.6 Notifications
Elara may trigger notifications locally on your device or via our technical backend and push infrastructure.
In this context, technically required device or push identifiers may be processed. Where required, technical delivery is carried out via the push or platform services of the respective operating system provider.
We do not transmit specific health data such as diagnoses, symptoms, measurements or medication information via external push services. Where notifications are generated locally on the device, they may display health-related information depending on the function selected by you.
Where the notification function is voluntarily activated, you may deactivate the corresponding permission at any time via your device settings.
Legal basis: Art. 6(1)(b) GDPR or, where voluntary consent is required, Art. 6(1)(a) GDPR.
4.7 Technical operation and security
To ensure the security, integrity and availability of Elara, we process technically required log and security data. These may include, in particular, IP address, timestamps, authentication and access events as well as technical status and error information. The processing serves, in particular, system security, error detection and the prevention of misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of Elara.
With your voluntary consent, we use Sentry for technical error diagnosis and to improve the stability of the app. The provider is Functional Software, Inc. (Sentry).
Sentry is only activated if you have consented to error reporting. In this context, technical diagnostic data may in particular be processed, for example app version, operating system and device type, the time and type of an error as well as technical information relating to program execution (e.g. stack traces).
Error reporting is focused on technical diagnostic data. Health-related content entered by you in Elara is not intended to be transmitted to Sentry. Functions such as Session Replay and the automatic transmission of screenshots are disabled.
Our Sentry project uses the EU data region; the data provided by Sentry for this purpose are stored in Germany. To the extent that Sentry uses group companies or subcontractors outside the European Economic Area in connection with the provision of its services, corresponding transfers are carried out on the basis of the relevant data protection safeguards, in particular the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses.
The legal basis for the use of Sentry is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw this consent at any time with effect for the future in the app settings. Elara can also be used without error reporting.
4.8 Emails and communication
For technically required emails relating to your user account, we use Resend, a service provided by Plus Five Five, Inc. (USA). This includes, in particular, messages relating to registration, authentication, account recovery and other communications required for the operation or security of your user account.
In this context, your email address, the content of the respective message, technical delivery information, timestamps as well as delivery and error status may in particular be processed. Resend processes these data on our behalf for the technical provision and delivery of the respective email. Information on transfers outside the EEA can be found in Section 9.
We have disabled open and click tracking for these emails. We therefore do not record whether you have opened a message or clicked on a link contained in it.
Health data such as symptoms, diagnoses, medications, measurements or diary entries are not included by us in technical account, authentication or security emails.
If you contact us by email, via a support function or through another communication channel, we process the data provided by you insofar as this is necessary to process and respond to your request.
For general contact and support requests, we generally do not require health data. Please therefore do not transmit information about diagnoses, symptoms, medications, measurements or other health information via general contact or support channels.
If processing a specific request should exceptionally require the processing of health data, we process such information only insofar as this is necessary for handling the request and an additional condition under Art. 9(2) GDPR is fulfilled. Where explicit consent is required for this purpose, we obtain it before further processing.
Legal bases: The processing of account, login, authentication and other emails necessary to provide the service used by you is based on Art. 6(1)(b) GDPR. Where technical security communications serve to secure our systems, prevent misuse or protect your user account, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the security and integrity of our service and user accounts.
For contract-related contact and support requests, Art. 6(1)(b) GDPR is the legal basis. For other contact and support requests, processing is based on Art. 6(1)(f) GDPR; our legitimate interest lies in the appropriate, secure and traceable handling of requests and communication with users.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are processed, this takes place only if an applicable condition under Art. 9(2) GDPR is additionally fulfilled, in particular on the basis of explicit consent pursuant to Art. 9(2)(a) GDPR.
4.9 Research
Participation in medical and scientific research is entirely voluntary and independent of the normal use of Elara.
If you provide separate consent to participate in research, this decision is initially stored in association with your user account. This allows us to identify which users have consented to the use of their data for research purposes.
The research serves, in particular, the scientific investigation of ME/CFS, Long COVID, other post-infectious diseases as well as associated symptoms, exertion and activity patterns and disease progression. Depending on the respective research question, data entered by you, questionnaire results as well as voluntarily connected wearable and sensor data may in particular be used for this purpose. Only the data required for the respective research question are processed.
For research analyses, we may create research datasets from the data of participating users. In doing so, directly attributable account and identification data are removed or replaced with separate research identifiers. As long as attribution to an individual remains possible, we continue to treat these data as personal or pseudonymised health data.
On the basis of the general research consent, we disclose research data to external parties or publish them only if sufficient anonymisation has first taken place and attribution to an identified or identifiable individual is no longer possible by means reasonably likely to be used.
If sufficient anonymisation cannot be ensured and pseudonymised health data are to be processed for a specific research project or transferred to research partners, this will take place only on the basis of an applicable data protection legal basis. Before such processing, insofar as required by law, you will receive additional information about the specific research project, the parties involved, the data used, the research purpose, the retention period and your rights. Where required, we will obtain additional explicit consent for this purpose.
The legal bases for personal data processing based on your general research consent are Art. 6(1)(a) GDPR and, for health data, Art. 9(2)(a) GDPR.
You may withdraw your research consent at any time with effect for the future via the app. The lawfulness of processing carried out prior to withdrawal remains unaffected.
Data that have already been effectively anonymised can no longer be associated with your user account after anonymisation. Subsequent deletion relating to an individual or withdrawal relating to an individual is therefore no longer possible with respect to such anonymised data.
The mere use of Elara does not constitute participation in research.
5. No advertising and no sale of health data
We do not sell personal data or health data.
Health data are not used for personalised advertising for third parties, Cross-Context Behavioral Advertising or comparable advertising profiles.
If you have consented to this, we use PostHog for product analytics. In this context, usage and technical data are processed in order to better understand the use of individual functions and improve Elara. PostHog is only activated after you have provided your consent. Processing takes place on servers within the European Union. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw this consent at any time with effect for the future.
PostHog is not used for advertising or the creation of advertising user profiles.
Personal health data are not used for the general training of AI or other models.
Data are disclosed only insofar as this is necessary to provide a function requested by you, you have provided consent, or a legal obligation exists.
6. Automated analyses
Elara may use rule-based, statistical or algorithmic methods to show you, for example, trends, scores or possible relationships within your data.
To the extent that such methods automatically evaluate personal aspects, for example relating to exertion, sleep or activity, this may constitute profiling within the meaning of Art. 4(4) GDPR.
These analyses serve your personal information.
No decisions are made solely by automated means that produce legal effects concerning you or similarly significantly affect you.
Automated decision-making within the meaning of Art. 22 GDPR does not currently take place.
7. Device access and permissions
Depending on the function used, Elara may access certain functions or information on your device and may require device permissions for this purpose. These may include, in particular, permissions for health and fitness data, photos or camera access, and notifications. Additional device permissions are requested only insofar as they are required for the respective function used by you.
Device permissions are generally requested only in connection with the respective function. You may change or revoke permissions granted at any time via the settings of your device or the connected service. Where processing is additionally based on data protection consent, you may withdraw such consent independently at any time with effect for the future.
Where Elara stores information on your device or accesses information already stored there, this is governed by Section 25 of the German Telecommunications-Digital Services Data Protection Act (TDDDG). Consent pursuant to Section 25(1) TDDDG is not required where the storage or access is strictly necessary in order to provide a digital service expressly requested by you (Section 25(2) No. 2 TDDDG). Where no statutory exception applies, storage or access takes place only after you have provided consent. Where personal data are processed in this context, the requirements of the GDPR additionally apply.
Non-essential analytics or tracking technologies are not used without prior consent where such consent is required.
8. Service providers, recipients and data sources
Within MS Nucleus GmbH, access to personal data is granted only to persons who require such access in order to perform their tasks.
We use, in particular, the following technical service providers or recipients or obtain data — in the case of voluntarily activated integrations — from the following sources:
- Supabase: backend, database, authentication, storage and technical infrastructure. The production project containing personal user data is operated in the EU region Frankfurt;
- OpenAI Ireland Ltd.: processing of the meal photo voluntarily transmitted by you for automated image analysis;
- Sentry: optional technical error, stability and login analysis following consent; use of the European data region with data storage in Germany;
- Resend / Plus Five Five, Inc., USA: sending technically required account and login emails as well as processing the delivery and log data required for this purpose;
- Open-Meteo / OpenMeteo GmbH, Switzerland: provision of local weather information;
- Apple Health / HealthKit, Google Health Connect, Garmin, Fitbit and Oura: data sources for health and wearable data insofar as you voluntarily activate a corresponding connection; transmission of data from Elara to such a provider takes place only insofar as this is technically предусмотрено by the respective integration and initiated or authorised by you;
- PostHog: optional product analytics following your consent; the project used by Elara is operated in the EU region;
- push and platform services of the respective operating system provider: insofar as these are required for the delivery of push notifications activated by you.
Where service providers process personal data on our behalf, we contractually bind them in accordance with the statutory requirements, in particular Art. 28 GDPR.
Data may also be transmitted to authorities, courts, legal advisers or other bodies where we are legally required to do so or where the transmission is necessary for the establishment, exercise or defence of legal claims and is legally permissible. Depending on the case, the legal bases are Art. 6(1)(c) GDPR in conjunction with the respective legal obligation or Art. 6(1)(f) GDPR; our legitimate interest lies in safeguarding, enforcing and defending our rights. Where health data are concerned, such processing takes place only where an additional exception under Art. 9(2) GDPR applies, in particular where processing is necessary for the establishment, exercise or defence of legal claims (Art. 9(2)(f) GDPR).
9. Transfers outside the EEA
We prefer the processing of personal data within the European Union or the European Economic Area (EEA) and, where available and configured accordingly, select European data regions.
For the OpenAI API used by Elara, no data residency restricted to the EEA is currently configured. Processing of data transmitted in connection with the voluntary meal photo scan may therefore take place outside the EEA, in particular in the United States. To the extent that OpenAI processes personal data on our behalf, this takes place on the basis of a data processing agreement with OpenAI Ireland Ltd. International transfers are based, in accordance with OpenAI's contractual provisions, in particular on the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
Processing outside the EEA may also take place when technically required emails are sent by Resend / Plus Five Five, Inc., USA. In particular, the European Commission's Standard Contractual Clauses and the EU-U.S. Data Privacy Framework are available for corresponding data transfers.
Open-Meteo is operated in Switzerland. The European Commission has adopted an adequacy decision for Switzerland.
Where personal data are processed outside the EEA, this takes place in compliance with Art. 44 et seq. GDPR. As a basis for transfers, we use in particular adequacy decisions pursuant to Art. 45 GDPR or appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission's Standard Contractual Clauses.
Further information on the safeguards used is available at datenschutz@elara-health.de.
10. Retention period and account deletion
We store personal data only for as long as this is necessary for the respective processing purpose or statutory retention obligations or other legally permissible grounds for continued storage apply.
Health, diary, activity and wearable data are generally stored for as long as your user account exists, unless you delete individual data earlier.
You can delete your user account at any time directly via the corresponding function in the app. Personal data associated with the account are subsequently deleted from our active production systems, unless statutory retention obligations or other legal grounds for continued storage apply. Files associated with the account as well as connection and access tokens to external services that are no longer required are also deleted or invalidated.
Daily backups are created for our Supabase database. Under the plan currently used, backups are retained for up to 7 days. Data already deleted from the production system may still be contained in backups during this period. They are not used there for operational purposes and are removed when the respective backup retention period expires.
For the meal photo scan, the uploaded photo is not permanently stored by us. Any retention in connection with processing by OpenAI is subject to the retention configuration of our API project described in Section 4.4.
Open-Meteo may process server logs containing connection or geographical query data as part of its technical operation. According to information published by Open-Meteo, individual log files are deleted after 90 days.
Error and diagnostic data processed in our Sentry project are stored for up to 90 days in accordance with the retention period configured by us.
For email and log data processed in connection with email delivery by Resend, a retention period of 30 days applies under the plan currently used by us.
Support and other communication data retained by us in our communication systems are not automatically deleted when a user account is deleted. They may continue to be stored, in particular, for the processing and traceability of requests, the documentation of security- or data-protection-related incidents and for the establishment, exercise or defence of legal claims. There is currently no fixed automatic standard deletion period for such data. Statutory retention and deletion obligations remain unaffected.
Where research data are merely pseudonymised and can still be associated with an individual, they continue to constitute personal data. Their retention period is governed by the conditions communicated for the respective research project. Data that have been effectively anonymised and can no longer be associated with an identified or identifiable individual can, by contrast, no longer be associated with an individual user account or deleted on a personal basis on the basis of such account.
11. Data security
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR in order to protect personal data, in particular against unauthorised access, loss, alteration or disclosure.
These include, in particular, access restrictions, secured data transmissions, technical safeguards for our infrastructure, backup and recovery procedures as well as regular review of the measures implemented.
12. Your data protection rights
Subject to the statutory requirements, you have in particular the following rights:
- right of access pursuant to Art. 15 GDPR;
- right to rectification pursuant to Art. 16 GDPR;
- right to erasure pursuant to Art. 17 GDPR;
- right to restriction of processing pursuant to Art. 18 GDPR;
- right to data portability pursuant to Art. 20 GDPR;
- right to object pursuant to Art. 21 GDPR;
- right to withdraw consent pursuant to Art. 7(3) GDPR.
Withdrawal applies with effect for the future and does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise your rights, you may contact datenschutz@elara-health.de.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority particularly responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
You may also contact the competent supervisory authority of your habitual residence, place of work or the place of the alleged data protection infringement.
13. Required and voluntary information
Certain account data, in particular an email address, are required to create a user account.
The entry of health data, connection of wearables, use of local weather information, uploading of a meal photo and participation in research are voluntary.
If corresponding data are not provided or required consent or device permissions are not granted, only the functions dependent on them cannot be used.
14. App stores
Elara is made available, among other places, through the Apple App Store and Google Play.
Apple or Google may, in connection with the download, installation, updates and use of their platforms, process in their own responsibility under data protection law, in particular, account, device, download or technical information.
The privacy notices of the respective platform operator apply to such processing.
15. Users outside the European Union
Elara may also be offered outside the European Union.
Where the data protection law of another country additionally applies, we comply with the resulting obligations.
Supplementary privacy notices may apply to certain jurisdictions.
For consumers to whom the Washington My Health My Data Act applies, we provide a separate Washington Consumer Health Data Privacy Policy.
16. Changes to this Privacy Policy
We amend this Privacy Policy if our processing activities, service providers, functions or legal requirements change.
We will inform you of material changes in an appropriate manner.
Where additional consent is required for a new purpose or new processing activity, we obtain such consent before the corresponding processing takes place.
Last updated: 27 August 2026