Cadence mark Cadence ← back
Legal

Privacy policy

Version 1.0 · Effective 8 August 2026 · Last updated 8 August 2026

At a glance

This is the short version. It is not a substitute for the full policy below, but nothing below contradicts it.

QuestionAnswer
Where does my bowel-health data live?On your phone. Only. It is never transmitted to us, and we have no server that could receive it.
Do you have an account system?No. There is nothing to sign into and no user record for us to hold.
What do you actually collect?Your email address, if you choose to give it to us for the waitlist or by writing to support. That is the whole list.
Do you use analytics or advertising SDKs?No. No Google Analytics, no Firebase Analytics, no advertising identifiers, no attribution SDKs, no session recording.
Do you sell or share my data?No. We have never done so and this policy commits us not to.
Can you read my logs if you are asked to by a court?No. We cannot produce what we do not hold. A lawful order could only compel us to hand over waitlist emails and support correspondence.
Who do I complain to?Us first — [email protected]. Then your national data protection authority. Details in §11.
Is this a medical device?No. See §18.

1. Who we are

[CADENCE LEGAL ENTITY NAME] (“Cadence”, “we”, “us”, “our”) is the controller of the personal data described in this policy, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the GDPR).

Legal entity[FULL REGISTERED NAME, e.g. Cadence Health B.V.]
Company number[REGISTRATION NUMBER]
Registered address[STREET, POSTCODE, CITY, EU MEMBER STATE]
Privacy contact[email protected]
General contact[email protected]
Data protection officer[See §1.1]
UK representative[See §1.2]
Lead supervisory authority[NATIONAL DPA, e.g. the Irish Data Protection Commission / the Dutch Autoriteit Persoonsgegevens]

1.1 Data protection officer

Article 37 GDPR requires a DPO where an organisation’s core activities consist of processing special category data (which includes health data) on a large scale.

We have assessed our position under Article 37 GDPR and concluded that we are not required to appoint a data protection officer. The health data our app generates is processed solely on your own device and never reaches us, so we do not process special category data on a large scale, or on any scale, as a controller. The only personal data we hold centrally is a list of email addresses. We keep this assessment under review and will appoint a DPO and update this policy if that position changes. Privacy questions can be sent to [email protected] and are handled by [ROLE, e.g. our founder / Head of Engineering].

1.2 Representatives

We are established in the EU, so we do not need an Article 27 GDPR representative for the EU.

If we offer Cadence to users in the United Kingdom, Article 27 of the UK GDPR requires us to appoint a UK representative. Ours is:

[UK REPRESENTATIVE NAME], [UK ADDRESS], [UK REP EMAIL].

You may contact our UK representative about anything in this policy instead of contacting us directly, if you prefer.


2. What this policy covers

This policy applies to:

This policy does not apply to:

Two supplementary documents form part of our published privacy information and should be read alongside this one:


3. The architecture, in plain terms

Almost every privacy question about Cadence has the same answer, and it comes from how the product is built rather than from a promise we are making.

Cadence has no server that stores user data. There is no database of bowel movements, no user table, no sync endpoint, no backup service. The app is a local application that reads from and writes to a database file inside its own private storage area on your Android device.

Concretely, this means:

The remainder of this policy describes the small amount of personal data that does reach us, and the rights you have in relation to it.


4. Personal data we process

4.1 Waitlist email address

WhatThe email address you type into the waitlist form, and the date and time you submitted it.
WhyTo send you a single email when Cadence launches, and to apply the free Plus unlock we promised waitlist members.
Legal basisArticle 6(1)(a) GDPR — consent. You give it by submitting the form. You can withdraw it at any time (§11.7) and withdrawal is as easy as giving it.
Is it special category data?No. An email address on a bowel-health waitlist could arguably suggest an interest in a health topic, but it does not reveal information about your health. We nevertheless treat this list with the same care as health data: it is access-restricted, never enriched, never used for lookalike audiences, and never disclosed.
RetentionUntil 90 days after launch email is sent, or until you unsubscribe or ask us to delete it, whichever is sooner. Then permanently deleted. If we abandon the product, deleted within 30 days of that decision.
Consequence of not providing itYou will not receive the launch email or the Plus unlock. Nothing else is affected; the app does not require it.

We do not add waitlist addresses to a newsletter, use them for any purpose other than the one above, or share them with anyone other than the processors named in §7.1.

4.2 Support and other correspondence

WhatYour email address, your name if you give it, the content of your message, and any attachments or screenshots you choose to send.
WhyTo answer you, to diagnose bugs, and to keep a record of complaints and data rights requests as our accountability obligations require.
Legal basisArticle 6(1)(f) GDPR — legitimate interests (running a support function and being able to evidence what we were asked and how we responded). Where you send us health information voluntarily, Article 9(2)(a) — explicit consent, given by your act of sending it. Where the message is a data rights request, Article 6(1)(c) — legal obligation.
Retention24 months from the last message in the thread. Data rights requests and complaints: 6 years, because we must be able to demonstrate compliance.

Please do not send us screenshots of your logs, your reports, or details of your symptoms unless it is genuinely necessary to answer your question. We do not need them and we would rather not hold them. If you do send health information, we will use it only to answer you and delete it as soon as the thread is closed.

4.3 Website server logs

Our site is served by Cloudflare, Inc. (Cloudflare Pages). Serving any web page necessarily involves the host processing a request, which includes your IP address.

WhatIP address, user agent string, requested URL, timestamp, response code.
WhyTo deliver the page, and to protect the site against denial-of-service and abuse.
Legal basisArticle 6(1)(f) GDPR — legitimate interests in operating and securing our own website. Our balancing assessment is that this is data you necessarily disclose to reach us, held briefly, never linked to you as an individual, and never used to build a profile.
RetentionAs configured by our host — currently [N] days. We do not download, aggregate, export or analyse these logs.

We do not operate any analytics on top of these logs. We do not know how many people visited the site except in the crudest aggregate terms our host shows us, and we do not track individuals across pages.

4.4 In-app data — processed on your device only

The app records what you tell it to record. Depending on which modes you enable, that may include:

All of this is special category data concerning health under Article 9(1) GDPR. It is also “consumer health data” under Washington and Nevada law, and “sensitive personal information” under California law.

We are not the controller of this data while it sits on your device, because we do not determine the means or purposes of your private record-keeping and we have no access to it. You are. The app is a tool you operate. To the extent any regulator takes a different view, our legal basis for the app’s local processing of health data would be Article 9(2)(a) — your explicit consent, given by choosing to record each entry — and Article 6(1)(b), performance of the contract to supply you the app.

The app’s correlation and flagging features run entirely as local computation on your device. No data is sent anywhere to produce them. See §12 on automated decision-making.

4.5 Purchases

If you buy Cadence Plus, the transaction is processed by Google LLC through Google Play Billing.

What we receiveAn anonymised, aggregated sales and payout report. Purchase tokens and order identifiers sufficient to validate an entitlement and to process a refund if you ask for one.
What we never receiveYour card number, bank details, full billing address, or any payment credential. These go to Google and never touch our systems.
Legal basisArticle 6(1)(b) — performance of a contract. For the financial records we must keep, Article 6(1)(c) — legal obligation.
RetentionTransaction records for the statutory period in our member state (typically 7–10 years), as required by [MEMBER STATE] tax and accounting law.

4.6 Crash and diagnostic reporting

Cadence contains no crash reporting or diagnostic SDK. If the app crashes, we learn about it only if you tell us. Android may offer to send a crash report to Google as an operating-system function; that is a transaction between you and Google under Google’s own policy, and we do not receive the report.

4.7 What we never collect

For the avoidance of doubt, Cadence does not collect, and contains no code capable of collecting:

We have never bought personal data about anybody and we do not intend to.


5. Health data: the detail

5.1 Why this section exists

Bowel-health data is unusually sensitive. It can reveal chronic illness, pregnancy, disability, eating disorders, the effects of medication, and — through the timing and content of entries — a great deal about somebody’s daily life. Article 9 GDPR prohibits processing this category of data unless a specific condition applies. Several US states now regulate it separately from other personal data. We think it deserves its own section rather than a line in a table.

5.2 The commitment

No health data recorded in Cadence is transmitted off your device by us, for any purpose, ever. Not in aggregate. Not anonymised. Not for research. Not for product improvement. Not for training a model. Not under a “we may share de-identified data” clause, which this policy deliberately does not contain.

If we ever wanted to change this, we would need your explicit, specific, freely given, unbundled opt-in consent under Article 9(2)(a), and we would have to ask you for it in the app in plain language, with a genuine option to say no and keep using the product. We are not asking now and have no plan to.

5.3 What “on device” means technically

5.4 The backup caveat — please read this

If Android Auto Backup or Google One device backup is enabled on your phone, Android may copy application data — potentially including Cadence’s database — to your personal Google Drive. This is an operating-system feature under your control and your agreement with Google, not something we transmit.

Our configuration: Cadence sets android:allowBackup="false" and defines android:dataExtractionRules to exclude the Cadence database from both cloud backup and device-to-device transfer. Your entries are therefore not copied to Google Drive, and they do not travel when you set up a new phone.


6. Purposes and legal bases, in one table

Article 13(1)(c) GDPR requires us to tell you the purpose and the legal basis for each processing activity, specifically rather than generically. Regulators have repeatedly found generic statements inadequate.

#Processing activityPurposeLegal basis (Art. 6)Special category condition (Art. 9)Retention
1Storing your waitlist emailSend one launch email; apply Plus unlock6(1)(a) consentn/aUntil 90 days post-launch or withdrawal
2Sending the launch emailDeliver what you signed up for6(1)(a) consentn/an/a
3Answering support emailRespond to you6(1)(f) legitimate interests9(2)(a) explicit consent, where you volunteer health information24 months
4Handling a data rights requestComply with Arts. 15–226(1)(c) legal obligation9(2)(f) legal claims, if disputed6 years
5Serving the websiteDeliver the page you requested6(1)(f) legitimate interestsn/aHost log period
6Securing the websitePrevent abuse and DoS6(1)(f) legitimate interestsn/aHost log period
7Supplying the app; validating a Plus purchasePerform our contract with you6(1)(b) contractn/aDuration of entitlement
8Keeping accounting records of salesTax and company law6(1)(c) legal obligationn/aThe statutory period in our member state (typically 7–10 years)
9On-device logging, correlation and flaggingYour own record-keeping and pattern-spotting6(1)(b) contract (and see §4.4)9(2)(a) explicit consentUntil you delete it

Where we rely on legitimate interests (rows 3, 5, 6) we have carried out a balancing assessment weighing our interest against your rights and freedoms. You can request a summary of that assessment at [email protected], and you have an unconditional right to object under Article 21 (§11.6).


7. Who we share data with

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to advertisers, data brokers, insurers, employers, or health systems.

The complete list of third parties who process personal data on our behalf is below. This is an exhaustive list, not an illustrative one.

7.1 Our processors

ProcessorWhat they processRoleLocationSafeguard
Cloudflare, Inc.Website hosting and delivery (request logs including IP); waitlist email addresses (stored in Cloudflare KV)Processor (Art. 28 DPA in place)[Global edge network; EU data localisation configured: yes/no][SCCs; Cloudflare Data Localisation Suite]
[EMAIL INBOX PROVIDER]Support correspondenceProcessor (Art. 28 DPA in place)[COUNTRY][Adequacy / SCCs]

No email-sending provider is appointed yet, because no email has ever been sent. One will be named here, with an Article 28 data processing agreement in place, before the launch email goes out.

Every processor above is bound by a written data processing agreement meeting Article 28(3) GDPR, including obligations of confidentiality, security, assistance with data subject rights, and deletion or return at the end of the engagement. We do not authorise sub-processors without a contractual right to object.

7.2 Independent controllers

Google LLC / Google Ireland Limited, in respect of the Google Play Store and Google Play Billing, acts as a separate and independent controller, not our processor. What Google collects when you browse the Play Store, download an app or make a purchase is governed by the Google Privacy Policy at https://policies.google.com/privacy. We cannot vary it and we do not receive most of it.

7.3 Other disclosures

We may disclose personal data:

We publish a transparency note at [/transparency] recording the number of government or law enforcement requests we have received, updated annually. As at the date of this policy that number is 0.


8. International transfers

Where a processor named in §7.1 is located outside the European Economic Area, or may access data from outside it, we rely on one of the following Chapter V GDPR safeguards:

The specific countries to which personal data may be transferred are: [NAME THE COUNTRIES — the ICO and EDPB expect countries to be named, not described as “countries outside the EEA”].

You may request a copy of the relevant safeguards, with commercial terms redacted, at [email protected].

No health data is transferred anywhere, internationally or otherwise, because it never leaves your device.


9. Retention

We keep personal data only as long as we need it, and we state actual periods rather than saying “as long as necessary”.

DataPeriodThen
Waitlist emailUntil 90 days after the launch email, or withdrawalPermanently deleted from live systems and from backups on the next backup rotation
Support correspondence24 months from last messagePermanently deleted
Data rights requests and complaints6 yearsPermanently deleted
Purchase and accounting recordsThe statutory period in our member state (typically 7–10 years), per [MEMBER STATE] lawPermanently deleted
Website server logs[N] days, per host configurationOverwritten
On-device app dataUntil you delete itRemoved with the app, subject to §5.4

Where we are required to keep something for a statutory period, we restrict access to it for the remainder of that period rather than continuing to use it.


10. Security

No system is perfectly secure, and we do not claim otherwise. What we can say is that a breach of Cadence’s systems would expose a list of email addresses and a support mailbox, not anybody’s health record.


11. Your rights

Under Articles 15 to 22 GDPR you have the following rights in relation to personal data we hold about you. Because we hold so little, most of these will resolve quickly.

11.1 Access (Art. 15)

A copy of your personal data and information about how we process it.

11.2 Rectification (Art. 16)

Correction of inaccurate data and completion of incomplete data.

11.3 Erasure (Art. 17)

Deletion, where the data is no longer needed, you withdraw consent, you object successfully, or it has been processed unlawfully. We may keep what a legal obligation requires us to keep.

11.4 Restriction (Art. 18)

Suspension of processing while accuracy or an objection is being resolved.

11.5 Portability (Art. 20)

Data you provided to us, on consent or contract grounds, in a structured, commonly used, machine-readable format, and transmitted to another controller where technically feasible.

In-app data: portability is built in and does not require a request. Export your full history as CSV, free, forever, from Settings → Export. This is deliberately more than Article 20 requires.

11.6 Objection (Art. 21)

To processing based on legitimate interests, on grounds relating to your particular situation — and absolutely, with no balancing test, to any processing for direct marketing.

11.7 Withdraw consent (Art. 7(3))

At any time, as easily as you gave it, without affecting the lawfulness of processing before withdrawal. Every marketing email carries a working one-click unsubscribe, and you can email us instead.

11.8 Complain (Art. 77)

To a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. Our lead authority is [NATIONAL DPA + WEBSITE + ADDRESS]. You do not have to come to us first — but we would appreciate the chance to put it right, and we will not treat you any differently for complaining.

11.9 Judicial remedy (Arts. 79, 82)

You may bring proceedings against us in the courts of the member state where we are established or where you are habitually resident, and you may seek compensation for material or non-material damage.

How to exercise any of these

Email [email protected], or write to the registered address in §1.


12. Automated decision-making, profiling and flags

The app screens your entries and surfaces two kinds of output: suspected food–symptom associations, and red flags such as visible blood or a prolonged gap between movements.

We want to be precise about what this is and is not:

If we ever introduce a feature that would constitute automated decision-making under Article 22, we will tell you before it launches, explain the logic and consequences, and provide the safeguards Article 22(3) requires including human intervention and a route to contest.


13. Children

Cadence is not directed at children and we do not knowingly collect personal data from anyone under 16 through the website or the waitlist.

Which age applies. Article 8 GDPR sets a default of 16 but permits member states to set lower ages for services offered directly to children; Cadence applies 16 to every user regardless of location.

However, the app has an infancy mode designed for a parent or carer to log an infant’s bowel movements. That is data about a child, entered by an adult, and it stays on the adult’s device. It is dealt with in full in the Children’s and Caregiver Data Addendum, which forms part of this policy.

If you believe a child has given us personal data — a waitlist signup, for instance — contact [email protected] and we will delete it promptly.


14. Logging data about other people

The caregiver, infancy and shared-diary modes let you record health information about somebody else. When you do that, you become responsible for that person’s data under applicable law, not us — we still cannot see it.

The short version: only log another person’s health data if you are their parent or legal guardian, hold a lawful authority such as a power of attorney or deputyship, or have their informed agreement. Tell them it exists and let them see it if they ask.

The full version, including what to do when a child grows up or a person you care for regains or loses capacity, is in the Children’s and Caregiver Data Addendum.


15. Cookies, local storage and similar technologies

We use no cookies for analytics, advertising, personalisation or tracking. There is no consent banner on cadencegut.com because, under Article 5(3) of the ePrivacy Directive as implemented in [MEMBER STATE], none is required for what we do.

TechnologyPurposeTypeDurationConsent needed?
[__cf_bm or equivalent, if your host sets one]Bot management / abuse preventionStrictly necessary[30 minutes]No — Art. 5(3) exemption
[Any preference stored in localStorage]Remembering [e.g. reduced-motion preference]Strictly necessaryUntil clearedNo

The app itself uses no cookies and no web views that would set them.


16. Marketing

We send one email: the launch announcement, to people who joined the waitlist.

We do not operate a newsletter, we do not send drip campaigns, promotional sequences, re-engagement emails, “we miss you” emails, or in-app promotional notifications. The app sends at most one quiet reminder per day, only if you enable reminders, and that is a product feature rather than marketing.

Every email we send carries a one-click unsubscribe honoured immediately. You can also email [email protected] at any time.

We do not use email open tracking pixels or click-tracking redirects.


17. Your rights if you are in the United States

The following applies in addition to the rest of this policy if you are a resident of a US state with a comprehensive privacy law. As at the date of this policy that includes California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, among others.

17.1 Notice at collection (California)

CCPA category (Cal. Civ. Code §1798.140(v)(1))Do we collect it?SourcePurposeDisclosed for a business purpose toSold or shared?Retention
A. Identifiers (email address)YesDirectly from youLaunch email; supportEmail provider; inbox providerNo§9
B. Customer records (Cal. Civ. Code §1798.80)NoNo
C. Protected classificationsNoNo
D. Commercial information (purchases)Yes, limitedGoogle PlayEntitlement; refunds; accountingGoogle (independent controller)No§9
E. Biometric informationNoNo
F. Internet activityYes, server logs onlyAutomaticallyDeliver and secure the siteHosting providerNo§9
G. GeolocationNoNo
H. Sensory dataNoNo
I. Employment informationNoNo
J. Education informationNoNo
K. Inferences / profilesNoNo
Sensitive personal information (health)Not by us. Generated and held on your device only.YouYour own record-keepingNobodyNoUntil you delete it

17.2 We do not sell or share

We have not sold personal information, and have not shared personal information for cross-context behavioural advertising, in the preceding twelve months, and we do not do so now. This includes the personal information of minors under 16, for which the CCPA requires opt-in consent that we have never sought because we have never had a reason to.

Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link on our site, and no Global Privacy Control signal to honour — although if a GPC signal is sent, we will treat it as an opt-out request regardless.

17.3 We do not use or disclose sensitive personal information beyond permitted purposes

Under CPRA you may limit the use of sensitive personal information. We do not use sensitive personal information for any purpose other than those permitted by §7027(m) of the CCPA regulations, so this right has nothing to bite on. We do not offer a “Limit the Use of My Sensitive Personal Information” link for that reason.

17.4 Your state rights

Depending on your state you have the right to know / access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising and profiling, appeal a refused request, and not be discriminated against for exercising any of them.

17.5 Consumer health data

Washington residents (My Health My Data Act) and Nevada residents (SB 370) — and, we apply the same treatment to everyone — should read our stand-alone Consumer Health Data Privacy Policy, which those statutes require to be a separate document containing only the information they specify. It is linked from our homepage as those laws require.

17.6 California “Shine the Light”

We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to request under Cal. Civ. Code §1798.83. You may confirm this by writing to [email protected].


18. Cadence is not a medical device

Cadence is a wellness journal. It records what you tell it, arranges it, and highlights patterns worth raising with a clinician.

The assessment, following the decision steps in MDCG 2019-11:

StepQuestionOur position
1Is the product software within the meaning of the guidance?Yes — it is a set of instructions processing data.
2Is it an accessory to a medical device?No. It neither drives nor influences the use of any device.
3Does it perform an action on data beyond storage, archival, communication, simple search, or lossless compression?No. Cadence stores user-entered entries, retrieves and displays them, computes descriptive summary statistics (frequency, SBM/CSBM rates, interquartile Bristol range, means), and applies fixed deterministic rules that signpost to a clinician. It performs no interpretation, no scoring against a clinical threshold, no classification, and no calculation whose output is intended to inform a diagnostic or therapeutic decision.
4Is the action for the benefit of an individual patient?Not in the qualifying sense — output is a personal record for discussion, not a clinical determination.
5Does it fall within a medical purpose in Art. 2(1)?No — no diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease.

Annex VIII Rule 11 is therefore not reached, because Rule 11 classifies software that is a device, and step 3 concludes it is not.

We re-run this assessment before any feature release that changes how the app analyses entries.

If you have blood in your stool, unexplained weight loss, persistent abdominal pain, or a lasting change in bowel habit, contact a doctor. Do not wait for an app to tell you to.


19. Other jurisdictions


20. Changes to this policy

We will update this policy when the product or the law changes.


21. Contact

PurposeAddress
Privacy questions, data rights requests[email protected]
Data protection officer (if appointed)[[email protected]]
Security vulnerabilities[[email protected]]
Everything else[email protected]
Post[FULL REGISTERED ADDRESS]
Supervisory authority[NATIONAL DPA NAME, ADDRESS, WEBSITE]

We aim to acknowledge privacy correspondence within 3 working days and to resolve it within the statutory period.


22. Definitions

Consumer health data — personal information linked to a consumer that identifies past, present or future physical or mental health status, as defined in Washington’s My Health My Data Act and Nevada SB 370.

Controller — the person who determines the purposes and means of processing (Art. 4(7) GDPR).

Personal data — information relating to an identified or identifiable natural person (Art. 4(1) GDPR).

Processor — a person who processes personal data on behalf of a controller (Art. 4(8) GDPR).

Sell / Share — as defined in the CCPA as amended by the CPRA. “Share” specifically means disclosure for cross-context behavioural advertising.

Special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, data concerning health, or data concerning sex life or sexual orientation (Art. 9(1) GDPR).


23. Version history

VersionDateChange
1.08 August 2026First publication.