Skip to content
HeyBiom!
English
EnglishDeutschEspañolFrançaisNederlandsItalianoPortuguêsPolskiMagyarDanskSuomiNorsk

Your data

Privacy policy

This policy distinguishes between processing on the website and in the HeyBiom! Android app. The app is local-first; account, cloud synchronisation and Health Connect are optional paths.

Last updated: 18 July 2026Version 1.0
ContentsControllerWebsiteApp dataGoogle & FirebaseHealth ConnectExternal servicesRetentionYour rights

1. Controller

Roman Baumhackl
trading under Baumhackl Digital
Herzog-Tassilo-Straße 26
86672 Thierhaupten, Germany
privacy@heybiom.com
+49 1575 1913554

No data protection officer is currently appointed because, based on the current circumstances, there is no statutory appointment obligation.

2. Visiting this website

Hosting and server logs

This static website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. On access, the server processes technically required connection data, including time, requested file, referrer, browser/operating-system details and a host or IP indication anonymised by STRATO. This is necessary for secure, stable delivery and troubleshooting (Article 6(1)(f) GDPR). STRATO provides anonymised access logs for the latest six weeks and error logs for a shorter period.

No analytics or advertising trackers

The website currently uses no analytics, marketing or social-media trackers, creates no advertising profiles and sets no non-essential cookies.

Contact

If you contact us, we process sender and contact details, the message, time and handling history to respond. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters, otherwise Article 6(1)(f) GDPR. Requests are normally deleted no later than three years after closure unless statutory retention or evidence duties require longer storage.

3. Local-first app and data categories

HeyBiom! keeps its immediate working data on your device. Depending on the features you use, this may include:

  • profile and account details such as display name, email, Firebase UID, age, sex, height, goal and day mode;
  • nutrition, product, recipe, quantity, hydration and diary data;
  • body and vital data such as weight, body-fat percentage, BMI, blood pressure, blood glucose, pulse, sleep and temperature;
  • training, exercises, recovery, steps, activity and calorie values;
  • reminders, local notifications, settings and technical sync/time metadata;
  • recipe images you select and OCR text recognised locally from them.

The data supports the features you request: personal documentation, fitness and nutrition guidance, daily values and trends, reminders, export and optional synchronisation. Necessary use is based on Article 6(1)(b) GDPR. Health data is processed on the basis of your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR.

No sale of data: HeyBiom! does not sell personal data and does not use health data for advertising.

4. Google sign-in and optional Firebase cloud

If you enable Google sign-in and cloud synchronisation, Google/Firebase processes authentication information such as your Google-account email, Firebase UID, sign-in state and technical tokens. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Firestore can mirror supported app areas under your UID, including profile and goals, diary, weight history, personal recipes, personal products and vital data. Firebase Storage is limited to intended user-bound file paths. Cloud Functions include the secure account-deletion workflow. Cloud use is optional.

The legal basis is consent (Article 6(1)(a) GDPR and, for health data, Article 9(2)(a) GDPR) and Article 6(1)(b) GDPR where necessary for a connected account you request. Google may process data in third countries, including the United States, using applicable safeguards such as adequacy decisions or EU Standard Contractual Clauses. See Firebase Privacy and Security and the Google Privacy Policy.

5. Health Connect and smartwatch data

Health Connect is a local Android interface. HeyBiom! accesses only data types you explicitly allow and which a connected provider app actually supplies. Depending on permission, these may include steps, active and total calories, heart rate, sleep, exercise and body temperature.

The data supports health, activity, analytics and calculation features you choose. Missing measurements are not invented. Watch activity affects the energy target only after the data-quality checks described in the app. Health Connect data is not sold, used for advertising or used for credit, insurance or employment decisions.

You can revoke permissions at any time in Android or Health Connect. Revocation applies prospectively; values already stored locally or optionally synchronised can be removed through the app, account deletion or a deletion request.

6. Camera, OCR and Open Food Facts

Camera and recipe OCR

Camera or gallery access occurs only after your choice and Android permission. Recipe images are processed locally for OCR and do not need to be sent to a separate OCR cloud provider. Export or file sharing occurs only when you initiate it.

Open Food Facts

Only when you start an online product or barcode search does the app send a request to Open Food Facts. Technically required connection data and the search term or barcode are transmitted. Open database entries can be incomplete and should be checked. See Open Food Facts Privacy.

7. Retention and deletion

DataRetention / deletion rule
Local app dataUntil you delete records, app data or the app, or execute account deletion.
Account-bound Firebase dataUntil individual content or the account is deleted, subject to legally required exceptions.
Technical deletion receiptUID, hashed email, status and timestamps are retained for no more than 30 days after deletion to safely complete and verify the idempotent process, then automatically removed.
Website access logsAnonymised STRATO access logs are available for up to six weeks; error logs for a shorter period.
Contact requestsNormally up to three years after closure unless a longer statutory obligation applies.

Details and the external request path are available at Delete account and data.

8. Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time with future effect. Contact privacy@heybiom.com.

You may also complain to a supervisory authority. The competent authority is in particular the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

Age limit

HeyBiom! is intended only for adults aged 18 or over. It is not designed for children.

Security and updates

Website and online-service transfers use HTTPS. Local and cloud access is technically restricted. We update this policy when features, data flows or legal requirements change.

HeyBiom!

Baumhackl Digital

© 2026 Roman Baumhackl
Legal
Legal noticePrivacy policyTerms of useMedical noticeDelete account & data