Your data
Privacy policy
This policy distinguishes between processing on the website and in the HeyBiom! Android app. The app is local-first; account, cloud synchronisation and Health Connect are optional paths.
1. Controller
Roman Baumhackltrading under Baumhackl Digital
Herzog-Tassilo-Straße 26
86672 Thierhaupten, Germany
privacy@heybiom.com
+49 1575 1913554
No data protection officer is currently appointed because, based on the current circumstances, there is no statutory appointment obligation.
2. Visiting this website
Hosting and server logs
This static website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. On access, the server processes technically required connection data, including time, requested file, referrer, browser/operating-system details and a host or IP indication anonymised by STRATO. This is necessary for secure, stable delivery and troubleshooting (Article 6(1)(f) GDPR). STRATO provides anonymised access logs for the latest six weeks and error logs for a shorter period.
No analytics or advertising trackers
The website currently uses no analytics, marketing or social-media trackers, creates no advertising profiles and sets no non-essential cookies.
Contact
If you contact us, we process sender and contact details, the message, time and handling history to respond. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters, otherwise Article 6(1)(f) GDPR. Requests are normally deleted no later than three years after closure unless statutory retention or evidence duties require longer storage.
3. Local-first app and data categories
HeyBiom! keeps its immediate working data on your device. Depending on the features you use, this may include:
- profile and account details such as display name, email, Firebase UID, age, sex, height, goal and day mode;
- nutrition, product, recipe, quantity, hydration and diary data;
- body and vital data such as weight, body-fat percentage, BMI, blood pressure, blood glucose, pulse, sleep and temperature;
- training, exercises, recovery, steps, activity and calorie values;
- reminders, local notifications, settings and technical sync/time metadata;
- recipe images you select and OCR text recognised locally from them.
The data supports the features you request: personal documentation, fitness and nutrition guidance, daily values and trends, reminders, export and optional synchronisation. Necessary use is based on Article 6(1)(b) GDPR. Health data is processed on the basis of your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR.
4. Google sign-in and optional Firebase cloud
If you enable Google sign-in and cloud synchronisation, Google/Firebase processes authentication information such as your Google-account email, Firebase UID, sign-in state and technical tokens. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Firestore can mirror supported app areas under your UID, including profile and goals, diary, weight history, personal recipes, personal products and vital data. Firebase Storage is limited to intended user-bound file paths. Cloud Functions include the secure account-deletion workflow. Cloud use is optional.
The legal basis is consent (Article 6(1)(a) GDPR and, for health data, Article 9(2)(a) GDPR) and Article 6(1)(b) GDPR where necessary for a connected account you request. Google may process data in third countries, including the United States, using applicable safeguards such as adequacy decisions or EU Standard Contractual Clauses. See Firebase Privacy and Security and the Google Privacy Policy.
5. Health Connect and smartwatch data
Health Connect is a local Android interface. HeyBiom! accesses only data types you explicitly allow and which a connected provider app actually supplies. Depending on permission, these may include steps, active and total calories, heart rate, sleep, exercise and body temperature.
The data supports health, activity, analytics and calculation features you choose. Missing measurements are not invented. Watch activity affects the energy target only after the data-quality checks described in the app. Health Connect data is not sold, used for advertising or used for credit, insurance or employment decisions.
You can revoke permissions at any time in Android or Health Connect. Revocation applies prospectively; values already stored locally or optionally synchronised can be removed through the app, account deletion or a deletion request.
6. Camera, OCR and Open Food Facts
Camera and recipe OCR
Camera or gallery access occurs only after your choice and Android permission. Recipe images are processed locally for OCR and do not need to be sent to a separate OCR cloud provider. Export or file sharing occurs only when you initiate it.
Open Food Facts
Only when you start an online product or barcode search does the app send a request to Open Food Facts. Technically required connection data and the search term or barcode are transmitted. Open database entries can be incomplete and should be checked. See Open Food Facts Privacy.
7. Retention and deletion
| Data | Retention / deletion rule |
|---|---|
| Local app data | Until you delete records, app data or the app, or execute account deletion. |
| Account-bound Firebase data | Until individual content or the account is deleted, subject to legally required exceptions. |
| Technical deletion receipt | UID, hashed email, status and timestamps are retained for no more than 30 days after deletion to safely complete and verify the idempotent process, then automatically removed. |
| Website access logs | Anonymised STRATO access logs are available for up to six weeks; error logs for a shorter period. |
| Contact requests | Normally up to three years after closure unless a longer statutory obligation applies. |
Details and the external request path are available at Delete account and data.
8. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time with future effect. Contact privacy@heybiom.com.
You may also complain to a supervisory authority. The competent authority is in particular the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
Age limit
HeyBiom! is intended only for adults aged 18 or over. It is not designed for children.
Security and updates
Website and online-service transfers use HTTPS. Local and cloud access is technically restricted. We update this policy when features, data flows or legal requirements change.