Legal

Privacy Policy

Last updated: July 5, 2026

1. Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) for this website (pmos-daily.com) and the PMOS Daily Android app is:

Lukas Maus
Eichenstraße 13
86504 Merching, Germany
Email: support@pmos-daily.com

A data protection officer is not legally required and has not been appointed.

2. The short version

  • Your journal data stays on your device. The app works without an account or registration. There is no cloud run by us, and we have no access to your entries.
  • No tracking, no ads. Neither the website nor the app uses analytics, advertising or tracking services. There are no advertising IDs, no profiling and no sale of data.
  • Optional online features are opt-in. Food lookup, photo recognition and AI reports only transmit data when you actively use them — and only what is needed, without your name or an account.
  • Waitlist: if you sign up, we store your email address (and optionally your first name) until you unsubscribe.

The sections below explain all of this in detail.

3. Website: hosting and server logs

This website and our backend services are hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) on servers located in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner.

When you visit the website, the web server automatically processes technically necessary data: IP address, date and time, requested page, HTTP status code and browser/OS identifier (user agent). These server logs are used solely to operate the site securely and reliably (e.g. error analysis, defending against attacks) and are automatically deleted after at most 14 days. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). All traffic is encrypted (TLS/HTTPS).

4. Website: no cookies, no tracking

This website does not set cookies and does not use any analytics, tracking or marketing services. No data is shared with advertising networks or social media platforms.

The only thing stored is your language choice (German/English), kept in your browser's local storage so the site appears in your language on your next visit. This entry never leaves your browser and is technically required for the display you requested (§ 25(2) no. 2 of the German TDDDG). You can delete it at any time via your browser settings.

If we ever want to introduce analytics or crash-reporting tools, we will update this policy first.

5. Waitlist (early access)

If you join the waitlist via the form, we process: your email address, optionally your first name, your language choice, and the time and fact of your consent. The sole purpose is to inform you about the Android early access launch and important product news about PMOS Daily.

The legal basis is your consent (Art. 6(1)(a) GDPR), given via the checkbox in the form. You can withdraw it at any time with effect for the future — via the unsubscribe option in our emails or informally by writing to support@pmos-daily.com. After withdrawal we delete your entry.

The data is stored on our server in Germany (Hetzner). After signing up you receive a welcome email; we use the service Resend to send such automated emails (see section 14). To prevent abuse, we limit sign-ups per IP address; the IP address is only processed briefly for this purpose and is not linked to your entry.

6. Contacting us by email

If you contact us by email (e.g. at support@ or hello@pmos-daily.com), we process your email address and the contents of your message in order to handle your request (Art. 6(1)(b) or (f) GDPR). Our mailboxes are hosted by the Swiss provider Migadu (see section 14). We delete correspondence once it is no longer needed and no statutory retention obligations apply.

7. App: your journal data stays local — no account

PMOS Daily is deliberately built so that your sensitive content never leaves your device. The app requires no account and no registration. Everything you log in the app is stored exclusively locally on your device, including:

  • morning and evening check-ins (mood, energy, sleep),
  • symptoms and their intensity,
  • cycle and period data,
  • meals and food entries,
  • routines, experiments and free-text notes,
  • your onboarding answers and app settings.

This locally stored data is not transmitted to us or to third parties; we have no access to it and do not process it. You can delete individual entries or all data at any time within the app; uninstalling the app also removes the local data. Data is only transmitted when you actively use the optional online features described in sections 10–12 — and only the specific items listed there.

The app is not directed at children under 16.

8. App: Health Connect (optional)

You can optionally allow the app to read individual health values from Google Health Connect: sleep, steps, weight, heart rate and exercise. Permissions are requested individually per data type and are never on by default; the app does not write any data back to Health Connect.

The values read are stored exclusively locally on your device, just like your manual entries, and are used there for the journal and pattern views. They are not used for advertising and are not shared with third parties — with one exception: if you actively request an AI report (section 12), sleep and step values for the relevant period are included in the data transmitted for that report.

The legal basis is your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), given via the Health Connect permissions. You can revoke it at any time in your device's Health Connect settings; values already imported can be deleted in the app.

9. App: Android device backup

If you have enabled Android backup on your device, Android backs up the app's local data (including your journal entries) to your Google account in encrypted form and transfers it when you set up a new device. This backup is handled entirely by Google and your Google account; we have no access to it. Google's privacy policy applies. You can disable the backup or manage backed-up data in your Android settings.

10. App: food lookup and barcode scan (optional)

When you look up a food in the app by name or barcode, your search query or the barcode is sent to our server in Germany. The server queries the public databases Open Food Facts (France) and USDA FoodData Central (USA) and caches the product data — nothing about you is stored, and the request contains no name, account or device identifiers. Your IP address is processed only technically for the transfer and for abuse protection (section 13). Legal basis: providing the feature you requested (Art. 6(1)(b) GDPR).

11. App: food photo recognition (optional)

The app offers two optional photo features: photographing a nutrition label (instead of barcode/search) and recognising a prepared meal. When you actively trigger one of these features, the photo you take is transmitted to our server over an encrypted connection and forwarded to OpenAI for analysis (see section 14). What comes back is purely neutral nutrition data (e.g. name, energy, protein, sugar), which you can review and edit before saving.

  • We neither store nor log the photo or the analysis result on our server; processing is strictly transient.
  • Under OpenAI's API terms, submitted content is not used to train AI models and is deleted after at most 30 days (abuse monitoring).
  • Tip: make sure the photo only shows the food or label — no people or personal items.

The legal basis is your consent (Art. 6(1)(a) GDPR), given by deliberately triggering the feature; you can always fall back to manual entry instead.

12. App: AI reports (optional)

On request, the app generates AI-assisted daily, weekly, monthly and experiment reports. When you request such a report, the structured values needed for it are transmitted to OpenAI via our server — depending on the report type, e.g.: date or period, mood and energy values, sleep duration, step count, logged symptoms and their intensity, period days, food entries with nutrition values, and pattern insights or experiment metrics already computed within the app.

What is not transmitted: your free-text notes, your name, your email address or any other contact, account or device identifiers. Apart from the technically necessary IP address, the request contains nothing that would identify you to us or to OpenAI.

  • Our server stores neither the transmitted values nor the generated report; only anonymous usage counters are recorded (section 13).
  • Under OpenAI's API terms, the content is not used for training and is deleted after at most 30 days.
  • AI reports are general, non-binding observations — not diagnoses and not medical advice.

Because these values may constitute health data, we process them only with your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), which you give by actively requesting a report. If you don't use the feature, no data is transmitted.

13. Abuse protection (IP-based usage limits)

Our online services (waitlist, food lookup, photo recognition, AI reports) can be used without an account. To prevent abuse and uncontrolled costs, we limit usage per IP address and time period. For this, our server stores your IP address together with a plain counter for the respective period (day, week or month) — without any content and without linking it to other data. Once the period has passed, these counters are automatically deleted. The legal basis is our legitimate interest in protecting the service (Art. 6(1)(f) GDPR).

14. Recipients and processors

We do not sell data and only share it with the following service providers, to the extent necessary for the respective purpose:

  • Hetzner Online GmbH (Gunzenhausen, Germany) — hosting of the website and backend services; data processing agreement under Art. 28 GDPR.
  • Migadu (Switzerland) — hosting of our email mailboxes (support@, hello@). An EU Commission adequacy decision is in place for Switzerland.
  • Resend (Resend, Inc., USA) — sending automated emails (e.g. the waitlist welcome email) via noreply@updates.pmos-daily.com; processing based on the EU Standard Contractual Clauses.
  • OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C., USA) — analysis for the optional photo recognition and generation of the optional AI reports (sections 11–12); processing under a data processing agreement with EU Standard Contractual Clauses; no use for training, deletion after at most 30 days.

Open Food Facts (France) and USDA FoodData Central (USA) only receive anonymous product queries (barcode/search term) from our server — no personal data about you.

15. Transfers to third countries

Your data is generally processed on servers in Germany. Transfers to third countries only occur in the cases described above: to Resend (USA) for automated emails and to OpenAI (USA) for the optional AI features — each safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) — and to Migadu in Switzerland (adequacy decision, Art. 45 GDPR).

16. Retention periods

  • Journal data in the app: lives only on your device — you decide how long; delete in the app or by uninstalling.
  • Waitlist: until you withdraw consent or request deletion.
  • Email correspondence: until your request is resolved and no statutory retention obligations remain.
  • Server logs: automatically deleted after at most 14 days.
  • Usage counters (IP limits): only relevant for the respective protection period, then deleted automatically.
  • Photo/AI requests: not stored on our server (transient); deleted by OpenAI after at most 30 days.

17. Your rights

Where we process personal data about you (e.g. waitlist, email contact), you have the following rights under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3)). Simply write to support@pmos-daily.com.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de. You may also contact the supervisory authority where you live.

Note: we have no access to the journal data stored locally in the app — only you can view, export or delete it.

18. Deleting your data

You delete journal data directly in the app or by uninstalling it — it only exists on your device. We delete your waitlist entry and stored email correspondence on request to support@pmos-daily.com, usually within 30 days. A step-by-step guide is available at data deletion.

19. No automated decision-making, no obligation to provide data

We do not make automated decisions with legal effect and do not carry out profiling (Art. 22 GDPR). You are under no statutory or contractual obligation to provide any data — the app's core features work completely offline without sharing anything with us, and all online features are optional.

20. Changes to this privacy policy

We update this policy when the app, the website or the legal situation changes — in particular before introducing any new data processing (such as analytics or an optional account system). The current version is always available on this page; the date of the last update is shown at the top.

21. Contact

For any privacy-related questions, you can reach us at support@pmos-daily.com or by post at the address given in section 1.