At a glance
This is the short version. It is not a substitute for the full policy below, but nothing below contradicts it.
| Question | Answer |
|---|---|
| Where does my bowel-health data live? | On your phone. Only. It is never transmitted to us, and we have no server that could receive it. |
| Do you have an account system? | No. There is nothing to sign into and no user record for us to hold. |
| What do you actually collect? | Your email address, if you choose to give it to us for the waitlist or by writing to support. That is the whole list. |
| Do you use analytics or advertising SDKs? | No. No Google Analytics, no Firebase Analytics, no advertising identifiers, no attribution SDKs, no session recording. |
| Do you sell or share my data? | No. We have never done so and this policy commits us not to. |
| Can you read my logs if you are asked to by a court? | No. We cannot produce what we do not hold. A lawful order could only compel us to hand over waitlist emails and support correspondence. |
| Who do I complain to? | Us first — [email protected]. Then your national data protection authority. Details in §11. |
| Is this a medical device? | No. See §18. |
1. Who we are
[CADENCE LEGAL ENTITY NAME] (“Cadence”, “we”, “us”, “our”) is the controller of the personal data described in this policy, within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the GDPR).
| Legal entity | [FULL REGISTERED NAME, e.g. Cadence Health B.V.] |
| Company number | [REGISTRATION NUMBER] |
| Registered address | [STREET, POSTCODE, CITY, EU MEMBER STATE] |
| Privacy contact | [email protected] |
| General contact | [email protected] |
| Data protection officer | [See §1.1] |
| UK representative | [See §1.2] |
| Lead supervisory authority | [NATIONAL DPA, e.g. the Irish Data Protection Commission / the Dutch Autoriteit Persoonsgegevens] |
1.1 Data protection officer
Article 37 GDPR requires a DPO where an organisation’s core activities consist of processing special category data (which includes health data) on a large scale.
We have assessed our position under Article 37 GDPR and concluded that we are not required to appoint a data protection officer. The health data our app generates is processed solely on your own device and never reaches us, so we do not process special category data on a large scale, or on any scale, as a controller. The only personal data we hold centrally is a list of email addresses. We keep this assessment under review and will appoint a DPO and update this policy if that position changes. Privacy questions can be sent to [email protected] and are handled by [ROLE, e.g. our founder / Head of Engineering].
1.2 Representatives
We are established in the EU, so we do not need an Article 27 GDPR representative for the EU.
If we offer Cadence to users in the United Kingdom, Article 27 of the UK GDPR requires us to appoint a UK representative. Ours is:
[UK REPRESENTATIVE NAME], [UK ADDRESS], [UK REP EMAIL].
You may contact our UK representative about anything in this policy instead of contacting us directly, if you prefer.
2. What this policy covers
This policy applies to:
- cadencegut.com and any subdomain we operate, including the waitlist signup form;
- the Cadence Android application and any future iOS application;
- email you send us, at [email protected], [email protected], or any other address we publish;
- any beta, testing or early-access programme we run.
This policy does not apply to:
- Google Play. When you download or purchase through the Google Play Store, Google processes your data as a separate controller under its own privacy policy. We do not control that processing. See §7.2.
- Third-party websites we link to.
- Your own device. Data stored locally in the app is subject to your device’s own security and your own backup settings. See §5.4 for the important consequences of this.
Two supplementary documents form part of our published privacy information and should be read alongside this one:
- Consumer Health Data Privacy Policy — a stand-alone notice required by Washington State’s My Health My Data Act and Nevada SB 370. It repeats information found here in the specific form those laws require.
- Children’s and Caregiver Data Addendum — how the infancy, caregiver and shared-diary modes work, and your responsibilities when you log information about another person.
3. The architecture, in plain terms
Almost every privacy question about Cadence has the same answer, and it comes from how the product is built rather than from a promise we are making.
Cadence has no server that stores user data. There is no database of bowel movements, no user table, no sync endpoint, no backup service. The app is a local application that reads from and writes to a database file inside its own private storage area on your Android device.
Concretely, this means:
- We cannot show you your own data, because we do not have it.
- We cannot lose your data in a breach of our systems, because our systems do not contain it.
- We cannot be compelled by a court, regulator or government to produce your logs, because we cannot produce what we do not hold.
- We cannot restore your data if you lose your phone, unless you made your own export. This is a genuine trade-off and we would rather state it plainly than bury it.
- Deleting the app deletes the data, subject to your own device backups (§5.4).
The remainder of this policy describes the small amount of personal data that does reach us, and the rights you have in relation to it.
4. Personal data we process
4.1 Waitlist email address
| What | The email address you type into the waitlist form, and the date and time you submitted it. |
| Why | To send you a single email when Cadence launches, and to apply the free Plus unlock we promised waitlist members. |
| Legal basis | Article 6(1)(a) GDPR — consent. You give it by submitting the form. You can withdraw it at any time (§11.7) and withdrawal is as easy as giving it. |
| Is it special category data? | No. An email address on a bowel-health waitlist could arguably suggest an interest in a health topic, but it does not reveal information about your health. We nevertheless treat this list with the same care as health data: it is access-restricted, never enriched, never used for lookalike audiences, and never disclosed. |
| Retention | Until 90 days after launch email is sent, or until you unsubscribe or ask us to delete it, whichever is sooner. Then permanently deleted. If we abandon the product, deleted within 30 days of that decision. |
| Consequence of not providing it | You will not receive the launch email or the Plus unlock. Nothing else is affected; the app does not require it. |
We do not add waitlist addresses to a newsletter, use them for any purpose other than the one above, or share them with anyone other than the processors named in §7.1.
4.2 Support and other correspondence
| What | Your email address, your name if you give it, the content of your message, and any attachments or screenshots you choose to send. |
| Why | To answer you, to diagnose bugs, and to keep a record of complaints and data rights requests as our accountability obligations require. |
| Legal basis | Article 6(1)(f) GDPR — legitimate interests (running a support function and being able to evidence what we were asked and how we responded). Where you send us health information voluntarily, Article 9(2)(a) — explicit consent, given by your act of sending it. Where the message is a data rights request, Article 6(1)(c) — legal obligation. |
| Retention | 24 months from the last message in the thread. Data rights requests and complaints: 6 years, because we must be able to demonstrate compliance. |
Please do not send us screenshots of your logs, your reports, or details of your symptoms unless it is genuinely necessary to answer your question. We do not need them and we would rather not hold them. If you do send health information, we will use it only to answer you and delete it as soon as the thread is closed.
4.3 Website server logs
Our site is served by Cloudflare, Inc. (Cloudflare Pages). Serving any web page necessarily involves the host processing a request, which includes your IP address.
| What | IP address, user agent string, requested URL, timestamp, response code. |
| Why | To deliver the page, and to protect the site against denial-of-service and abuse. |
| Legal basis | Article 6(1)(f) GDPR — legitimate interests in operating and securing our own website. Our balancing assessment is that this is data you necessarily disclose to reach us, held briefly, never linked to you as an individual, and never used to build a profile. |
| Retention | As configured by our host — currently [N] days. We do not download, aggregate, export or analyse these logs. |
We do not operate any analytics on top of these logs. We do not know how many people visited the site except in the crudest aggregate terms our host shows us, and we do not track individuals across pages.
4.4 In-app data — processed on your device only
The app records what you tell it to record. Depending on which modes you enable, that may include:
- date, time and Bristol Stool Scale type for each entry;
- completeness of evacuation, straining, urgency, leakage, and time spent;
- abdominal pain and bloating ratings;
- presence of blood or unusual stool colour;
- free-text notes;
- food and drink entries you type in;
- medications, doses and start/stop dates you enter;
- photographs, if and only if you turn that feature on (it is off by default);
- reminder settings and app preferences;
- in caregiver, infancy and shared-diary modes, the same categories recorded about another person (see the Caregiver Addendum).
All of this is special category data concerning health under Article 9(1) GDPR. It is also “consumer health data” under Washington and Nevada law, and “sensitive personal information” under California law.
We are not the controller of this data while it sits on your device, because we do not determine the means or purposes of your private record-keeping and we have no access to it. You are. The app is a tool you operate. To the extent any regulator takes a different view, our legal basis for the app’s local processing of health data would be Article 9(2)(a) — your explicit consent, given by choosing to record each entry — and Article 6(1)(b), performance of the contract to supply you the app.
The app’s correlation and flagging features run entirely as local computation on your device. No data is sent anywhere to produce them. See §12 on automated decision-making.
4.5 Purchases
If you buy Cadence Plus, the transaction is processed by Google LLC through Google Play Billing.
| What we receive | An anonymised, aggregated sales and payout report. Purchase tokens and order identifiers sufficient to validate an entitlement and to process a refund if you ask for one. |
| What we never receive | Your card number, bank details, full billing address, or any payment credential. These go to Google and never touch our systems. |
| Legal basis | Article 6(1)(b) — performance of a contract. For the financial records we must keep, Article 6(1)(c) — legal obligation. |
| Retention | Transaction records for the statutory period in our member state (typically 7–10 years), as required by [MEMBER STATE] tax and accounting law. |
4.6 Crash and diagnostic reporting
Cadence contains no crash reporting or diagnostic SDK. If the app crashes, we learn about it only if you tell us. Android may offer to send a crash report to Google as an operating-system function; that is a transaction between you and Google under Google’s own policy, and we do not receive the report.
4.7 What we never collect
For the avoidance of doubt, Cadence does not collect, and contains no code capable of collecting:
- advertising identifiers (GAID / AAID) or any advertising SDK;
- analytics or product-telemetry SDKs;
- location data of any kind, including coarse, IP-derived or inferred location;
- contacts, calendar, SMS, call logs, or the device’s photo library beyond a single image you explicitly pick;
- device fingerprints, MAC addresses, IMEI, or persistent hardware identifiers;
- microphone or camera access, except the camera when you deliberately take a photo for an entry;
- health data from Health Connect, Google Fit, wearables, or any other app;
- data about you from data brokers, social networks, or any other third-party source.
We have never bought personal data about anybody and we do not intend to.
5. Health data: the detail
5.1 Why this section exists
Bowel-health data is unusually sensitive. It can reveal chronic illness, pregnancy, disability, eating disorders, the effects of medication, and — through the timing and content of entries — a great deal about somebody’s daily life. Article 9 GDPR prohibits processing this category of data unless a specific condition applies. Several US states now regulate it separately from other personal data. We think it deserves its own section rather than a line in a table.
5.2 The commitment
No health data recorded in Cadence is transmitted off your device by us, for any purpose, ever. Not in aggregate. Not anonymised. Not for research. Not for product improvement. Not for training a model. Not under a “we may share de-identified data” clause, which this policy deliberately does not contain.
If we ever wanted to change this, we would need your explicit, specific, freely given, unbundled opt-in consent under Article 9(2)(a), and we would have to ask you for it in the app in plain language, with a genuine option to say no and keep using the product. We are not asking now and have no plan to.
5.3 What “on device” means technically
- App data is stored in the app’s private storage directory, which Android’s application sandbox makes inaccessible to other apps on a non-rooted device.
- [The database is additionally encrypted at rest using [SQLCipher / Android EncryptedFile / Jetpack Security], with the key held in the Android Keystore and, where the device supports it, bound to hardware-backed storage and your device unlock credential.]
- The app declares [the INTERNET permission / no INTERNET permission] in its merged manifest.
- Exports you generate are written to a location you choose. Once a PDF or CSV leaves the app, it is an ordinary file on your device and this policy no longer controls what happens to it.
5.4 The backup caveat — please read this
If Android Auto Backup or Google One device backup is enabled on your phone, Android may copy application data — potentially including Cadence’s database — to your personal Google Drive. This is an operating-system feature under your control and your agreement with Google, not something we transmit.
Our configuration: Cadence sets android:allowBackup="false" and defines android:dataExtractionRules to exclude the Cadence database from both cloud backup and device-to-device transfer. Your entries are therefore not copied to Google Drive, and they do not travel when you set up a new phone.
6. Purposes and legal bases, in one table
Article 13(1)(c) GDPR requires us to tell you the purpose and the legal basis for each processing activity, specifically rather than generically. Regulators have repeatedly found generic statements inadequate.
| # | Processing activity | Purpose | Legal basis (Art. 6) | Special category condition (Art. 9) | Retention |
|---|---|---|---|---|---|
| 1 | Storing your waitlist email | Send one launch email; apply Plus unlock | 6(1)(a) consent | n/a | Until 90 days post-launch or withdrawal |
| 2 | Sending the launch email | Deliver what you signed up for | 6(1)(a) consent | n/a | n/a |
| 3 | Answering support email | Respond to you | 6(1)(f) legitimate interests | 9(2)(a) explicit consent, where you volunteer health information | 24 months |
| 4 | Handling a data rights request | Comply with Arts. 15–22 | 6(1)(c) legal obligation | 9(2)(f) legal claims, if disputed | 6 years |
| 5 | Serving the website | Deliver the page you requested | 6(1)(f) legitimate interests | n/a | Host log period |
| 6 | Securing the website | Prevent abuse and DoS | 6(1)(f) legitimate interests | n/a | Host log period |
| 7 | Supplying the app; validating a Plus purchase | Perform our contract with you | 6(1)(b) contract | n/a | Duration of entitlement |
| 8 | Keeping accounting records of sales | Tax and company law | 6(1)(c) legal obligation | n/a | The statutory period in our member state (typically 7–10 years) |
| 9 | On-device logging, correlation and flagging | Your own record-keeping and pattern-spotting | 6(1)(b) contract (and see §4.4) | 9(2)(a) explicit consent | Until you delete it |
Where we rely on legitimate interests (rows 3, 5, 6) we have carried out a balancing assessment weighing our interest against your rights and freedoms. You can request a summary of that assessment at [email protected], and you have an unconditional right to object under Article 21 (§11.6).
7. Who we share data with
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to advertisers, data brokers, insurers, employers, or health systems.
The complete list of third parties who process personal data on our behalf is below. This is an exhaustive list, not an illustrative one.
7.1 Our processors
| Processor | What they process | Role | Location | Safeguard |
|---|---|---|---|---|
| Cloudflare, Inc. | Website hosting and delivery (request logs including IP); waitlist email addresses (stored in Cloudflare KV) | Processor (Art. 28 DPA in place) | [Global edge network; EU data localisation configured: yes/no] | [SCCs; Cloudflare Data Localisation Suite] |
| [EMAIL INBOX PROVIDER] | Support correspondence | Processor (Art. 28 DPA in place) | [COUNTRY] | [Adequacy / SCCs] |
No email-sending provider is appointed yet, because no email has ever been sent. One will be named here, with an Article 28 data processing agreement in place, before the launch email goes out.
Every processor above is bound by a written data processing agreement meeting Article 28(3) GDPR, including obligations of confidentiality, security, assistance with data subject rights, and deletion or return at the end of the engagement. We do not authorise sub-processors without a contractual right to object.
7.2 Independent controllers
Google LLC / Google Ireland Limited, in respect of the Google Play Store and Google Play Billing, acts as a separate and independent controller, not our processor. What Google collects when you browse the Play Store, download an app or make a purchase is governed by the Google Privacy Policy at https://policies.google.com/privacy. We cannot vary it and we do not receive most of it.
7.3 Other disclosures
We may disclose personal data:
- Where you ask us to, or with your consent.
- To professional advisers — lawyers, accountants, auditors — bound by professional confidentiality, where genuinely necessary.
- Where legally required, in response to a valid, binding order from a court or competent authority with jurisdiction over us. We will assess every request for validity and proportionality, will challenge overbroad requests, and will notify you unless legally prohibited from doing so. Note again that this can only ever reach the data described in §4 — we hold no bowel-health data to disclose.
- To establish, exercise or defend legal claims.
- In a corporate transaction. If Cadence is acquired, merged or its assets sold, personal data may transfer to the acquirer. We would notify affected users before any transfer takes effect and any acquirer would take the data subject to this policy. If an acquirer wished to change the on-device architecture or begin transmitting health data, that would require fresh explicit consent from each user — it could not be effected by a change of ownership or a policy update.
We publish a transparency note at [/transparency] recording the number of government or law enforcement requests we have received, updated annually. As at the date of this policy that number is 0.
8. International transfers
Where a processor named in §7.1 is located outside the European Economic Area, or may access data from outside it, we rely on one of the following Chapter V GDPR safeguards:
- an adequacy decision of the European Commission under Article 45, where one covers the destination country; or
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) under Article 46(2)(c), supplemented by a documented transfer impact assessment and, where indicated, additional technical measures.
The specific countries to which personal data may be transferred are: [NAME THE COUNTRIES — the ICO and EDPB expect countries to be named, not described as “countries outside the EEA”].
You may request a copy of the relevant safeguards, with commercial terms redacted, at [email protected].
No health data is transferred anywhere, internationally or otherwise, because it never leaves your device.
9. Retention
We keep personal data only as long as we need it, and we state actual periods rather than saying “as long as necessary”.
| Data | Period | Then |
|---|---|---|
| Waitlist email | Until 90 days after the launch email, or withdrawal | Permanently deleted from live systems and from backups on the next backup rotation |
| Support correspondence | 24 months from last message | Permanently deleted |
| Data rights requests and complaints | 6 years | Permanently deleted |
| Purchase and accounting records | The statutory period in our member state (typically 7–10 years), per [MEMBER STATE] law | Permanently deleted |
| Website server logs | [N] days, per host configuration | Overwritten |
| On-device app data | Until you delete it | Removed with the app, subject to §5.4 |
Where we are required to keep something for a statutory period, we restrict access to it for the remainder of that period rather than continuing to use it.
10. Security
- Architectural. The strongest security control we have is not holding the data. See §3.
- Encryption in transit. The website and all processor connections use TLS 1.2 or higher. HSTS is enabled.
- Encryption at rest. [Describe accurately — see §5.3.]
- Access control. Access to the waitlist and the support inbox is limited to [NUMBER] people who need it, protected by multi-factor authentication, and reviewed [quarterly].
- Least data. We collect the minimum that makes the product work, which is the most effective breach mitigation available.
- Vulnerability reporting. If you find a security issue, please tell us at [[email protected]]. We will acknowledge within 3 working days and we will not pursue legal action against good-faith researchers who follow our disclosure policy at [/security].
- Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify our supervisory authority within 72 hours under Article 33, and notify you without undue delay under Article 34 where the risk is high.
No system is perfectly secure, and we do not claim otherwise. What we can say is that a breach of Cadence’s systems would expose a list of email addresses and a support mailbox, not anybody’s health record.
11. Your rights
Under Articles 15 to 22 GDPR you have the following rights in relation to personal data we hold about you. Because we hold so little, most of these will resolve quickly.
11.1 Access (Art. 15)
A copy of your personal data and information about how we process it.
11.2 Rectification (Art. 16)
Correction of inaccurate data and completion of incomplete data.
11.3 Erasure (Art. 17)
Deletion, where the data is no longer needed, you withdraw consent, you object successfully, or it has been processed unlawfully. We may keep what a legal obligation requires us to keep.
11.4 Restriction (Art. 18)
Suspension of processing while accuracy or an objection is being resolved.
11.5 Portability (Art. 20)
Data you provided to us, on consent or contract grounds, in a structured, commonly used, machine-readable format, and transmitted to another controller where technically feasible.
In-app data: portability is built in and does not require a request. Export your full history as CSV, free, forever, from Settings → Export. This is deliberately more than Article 20 requires.
11.6 Objection (Art. 21)
To processing based on legitimate interests, on grounds relating to your particular situation — and absolutely, with no balancing test, to any processing for direct marketing.
11.7 Withdraw consent (Art. 7(3))
At any time, as easily as you gave it, without affecting the lawfulness of processing before withdrawal. Every marketing email carries a working one-click unsubscribe, and you can email us instead.
11.8 Complain (Art. 77)
To a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. Our lead authority is [NATIONAL DPA + WEBSITE + ADDRESS]. You do not have to come to us first — but we would appreciate the chance to put it right, and we will not treat you any differently for complaining.
11.9 Judicial remedy (Arts. 79, 82)
You may bring proceedings against us in the courts of the member state where we are established or where you are habitually resident, and you may seek compensation for material or non-material damage.
How to exercise any of these
Email [email protected], or write to the registered address in §1.
- We respond within one month. We may extend by two further months for complex or numerous requests, and will tell you within the first month if we need to, with reasons.
- It is free. We may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and we will explain why in writing if we ever do.
- We may need to verify your identity, proportionately. For a waitlist address, replying from that address is normally enough. We will not demand identity documents for a request that does not warrant it.
- You can use an authorised agent. We will ask for evidence of their authority.
- We will not retaliate. Exercising a right will never degrade your service, price or access.
12. Automated decision-making, profiling and flags
The app screens your entries and surfaces two kinds of output: suspected food–symptom associations, and red flags such as visible blood or a prolonged gap between movements.
We want to be precise about what this is and is not:
- It runs entirely on your device. No data leaves the phone to generate it.
- It is not a decision about you in the Article 22 sense. It produces no legal effect and nothing similarly significant. It changes what a screen shows you; it does not determine access to credit, insurance, employment, healthcare or any service. Article 22(1) GDPR is therefore not engaged.
- It is not a diagnosis, and it is not medical advice. A flag means “this pattern is worth raising with a clinician”, nothing more. Every flag states the rule that produced it so you can judge it for yourself.
- The logic is disclosed. The report prints the rule alongside each flag — for example, “rule: any visible blood · no explaining medication on list”. We do this because an alert you cannot interrogate is not information, it is just an alarm.
- You can turn it off. Correlation and flagging can be disabled in Settings without affecting logging.
- No model is trained on your data. Not ours, not anybody’s. The correlation logic is deterministic statistics computed locally, not a machine learning model, and no data is used to improve any model anywhere.
If we ever introduce a feature that would constitute automated decision-making under Article 22, we will tell you before it launches, explain the logic and consequences, and provide the safeguards Article 22(3) requires including human intervention and a route to contest.
13. Children
Cadence is not directed at children and we do not knowingly collect personal data from anyone under 16 through the website or the waitlist.
Which age applies. Article 8 GDPR sets a default of 16 but permits member states to set lower ages for services offered directly to children; Cadence applies 16 to every user regardless of location.
However, the app has an infancy mode designed for a parent or carer to log an infant’s bowel movements. That is data about a child, entered by an adult, and it stays on the adult’s device. It is dealt with in full in the Children’s and Caregiver Data Addendum, which forms part of this policy.
If you believe a child has given us personal data — a waitlist signup, for instance — contact [email protected] and we will delete it promptly.
14. Logging data about other people
The caregiver, infancy and shared-diary modes let you record health information about somebody else. When you do that, you become responsible for that person’s data under applicable law, not us — we still cannot see it.
The short version: only log another person’s health data if you are their parent or legal guardian, hold a lawful authority such as a power of attorney or deputyship, or have their informed agreement. Tell them it exists and let them see it if they ask.
The full version, including what to do when a child grows up or a person you care for regains or loses capacity, is in the Children’s and Caregiver Data Addendum.
15. Cookies, local storage and similar technologies
We use no cookies for analytics, advertising, personalisation or tracking. There is no consent banner on cadencegut.com because, under Article 5(3) of the ePrivacy Directive as implemented in [MEMBER STATE], none is required for what we do.
| Technology | Purpose | Type | Duration | Consent needed? |
|---|---|---|---|---|
[__cf_bm or equivalent, if your host sets one] | Bot management / abuse prevention | Strictly necessary | [30 minutes] | No — Art. 5(3) exemption |
[Any preference stored in localStorage] | Remembering [e.g. reduced-motion preference] | Strictly necessary | Until cleared | No |
The app itself uses no cookies and no web views that would set them.
16. Marketing
We send one email: the launch announcement, to people who joined the waitlist.
We do not operate a newsletter, we do not send drip campaigns, promotional sequences, re-engagement emails, “we miss you” emails, or in-app promotional notifications. The app sends at most one quiet reminder per day, only if you enable reminders, and that is a product feature rather than marketing.
Every email we send carries a one-click unsubscribe honoured immediately. You can also email [email protected] at any time.
We do not use email open tracking pixels or click-tracking redirects.
17. Your rights if you are in the United States
The following applies in addition to the rest of this policy if you are a resident of a US state with a comprehensive privacy law. As at the date of this policy that includes California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, among others.
17.1 Notice at collection (California)
| CCPA category (Cal. Civ. Code §1798.140(v)(1)) | Do we collect it? | Source | Purpose | Disclosed for a business purpose to | Sold or shared? | Retention |
|---|---|---|---|---|---|---|
| A. Identifiers (email address) | Yes | Directly from you | Launch email; support | Email provider; inbox provider | No | §9 |
| B. Customer records (Cal. Civ. Code §1798.80) | No | — | — | — | No | — |
| C. Protected classifications | No | — | — | — | No | — |
| D. Commercial information (purchases) | Yes, limited | Google Play | Entitlement; refunds; accounting | Google (independent controller) | No | §9 |
| E. Biometric information | No | — | — | — | No | — |
| F. Internet activity | Yes, server logs only | Automatically | Deliver and secure the site | Hosting provider | No | §9 |
| G. Geolocation | No | — | — | — | No | — |
| H. Sensory data | No | — | — | — | No | — |
| I. Employment information | No | — | — | — | No | — |
| J. Education information | No | — | — | — | No | — |
| K. Inferences / profiles | No | — | — | — | No | — |
| Sensitive personal information (health) | Not by us. Generated and held on your device only. | You | Your own record-keeping | Nobody | No | Until you delete it |
17.2 We do not sell or share
We have not sold personal information, and have not shared personal information for cross-context behavioural advertising, in the preceding twelve months, and we do not do so now. This includes the personal information of minors under 16, for which the CCPA requires opt-in consent that we have never sought because we have never had a reason to.
Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link on our site, and no Global Privacy Control signal to honour — although if a GPC signal is sent, we will treat it as an opt-out request regardless.
17.3 We do not use or disclose sensitive personal information beyond permitted purposes
Under CPRA you may limit the use of sensitive personal information. We do not use sensitive personal information for any purpose other than those permitted by §7027(m) of the CCPA regulations, so this right has nothing to bite on. We do not offer a “Limit the Use of My Sensitive Personal Information” link for that reason.
17.4 Your state rights
Depending on your state you have the right to know / access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising and profiling, appeal a refused request, and not be discriminated against for exercising any of them.
- Exercise them at [email protected], or by post to the address in §1.
- We respond within 45 days, extendable once by a further 45 days with notice.
- Appeals: if we refuse, you may appeal by replying to our decision. We will respond in writing within 60 days, and if we deny the appeal we will give you a means of contacting your state Attorney General.
- Authorised agents are accepted with proof of authority.
17.5 Consumer health data
Washington residents (My Health My Data Act) and Nevada residents (SB 370) — and, we apply the same treatment to everyone — should read our stand-alone Consumer Health Data Privacy Policy, which those statutes require to be a separate document containing only the information they specify. It is linked from our homepage as those laws require.
17.6 California “Shine the Light”
We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to request under Cal. Civ. Code §1798.83. You may confirm this by writing to [email protected].
18. Cadence is not a medical device
Cadence is a wellness journal. It records what you tell it, arranges it, and highlights patterns worth raising with a clinician.
- It does not diagnose, treat, cure, prevent or monitor any disease, injury or disability.
- It does not provide medical advice, and nothing it displays is a clinical recommendation.
- Its outputs are labelled for discussion with a clinician and are never presented as findings.
- Under Regulation (EU) 2017/745 (MDR) we have assessed Cadence as falling outside the definition of a medical device, because it does not have a medical purpose within Article 2(1) MDR.
The assessment, following the decision steps in MDCG 2019-11:
| Step | Question | Our position |
|---|---|---|
| 1 | Is the product software within the meaning of the guidance? | Yes — it is a set of instructions processing data. |
| 2 | Is it an accessory to a medical device? | No. It neither drives nor influences the use of any device. |
| 3 | Does it perform an action on data beyond storage, archival, communication, simple search, or lossless compression? | No. Cadence stores user-entered entries, retrieves and displays them, computes descriptive summary statistics (frequency, SBM/CSBM rates, interquartile Bristol range, means), and applies fixed deterministic rules that signpost to a clinician. It performs no interpretation, no scoring against a clinical threshold, no classification, and no calculation whose output is intended to inform a diagnostic or therapeutic decision. |
| 4 | Is the action for the benefit of an individual patient? | Not in the qualifying sense — output is a personal record for discussion, not a clinical determination. |
| 5 | Does it fall within a medical purpose in Art. 2(1)? | No — no diagnosis, prevention, monitoring, prediction, prognosis, treatment or alleviation of disease. |
Annex VIII Rule 11 is therefore not reached, because Rule 11 classifies software that is a device, and step 3 concludes it is not.
We re-run this assessment before any feature release that changes how the app analyses entries.
- Our red-flag rules are deliberately conservative signposts to a clinician, not screening tests, and each states the rule that fired.
If you have blood in your stool, unexplained weight loss, persistent abdominal pain, or a lasting change in bowel habit, contact a doctor. Do not wait for an app to tell you to.
19. Other jurisdictions
- United Kingdom. UK GDPR and the Data Protection Act 2018 apply and give you materially the same rights as §11. Complain to the Information Commissioner’s Office, https://ico.org.uk, 0303 123 1113. Our UK representative is in §1.2.
- Switzerland. The revised Federal Act on Data Protection applies; complain to the FDPIC.
- Canada. PIPEDA applies; complain to the Office of the Privacy Commissioner of Canada.
- Brazil. LGPD applies; you have rights equivalent to §11 and may complain to the ANPD.
- Australia. The Privacy Act 1988 and the Australian Privacy Principles apply; complain to the OAIC.
- Anywhere else. We apply the standards in this policy to everyone, regardless of where you live, because maintaining two tiers of privacy would be more work than doing it properly once.
20. Changes to this policy
We will update this policy when the product or the law changes.
- The version number and effective date at the top always reflect the current text.
- We keep a public changelog at [/privacy/changelog] recording what changed and why, so you can see the history rather than take our word for it.
- For material changes — a new category of data, a new recipient, a new purpose, any change to the on-device architecture — we will give at least 30 days’ notice by email to waitlist members and by in-app notice, before the change takes effect.
- We will never use a policy update to start transmitting health data off your device. That would require fresh, explicit, opt-in consent obtained separately, and continuing to use the app would not count as agreement.
21. Contact
| Purpose | Address |
|---|---|
| Privacy questions, data rights requests | [email protected] |
| Data protection officer (if appointed) | [[email protected]] |
| Security vulnerabilities | [[email protected]] |
| Everything else | [email protected] |
| Post | [FULL REGISTERED ADDRESS] |
| Supervisory authority | [NATIONAL DPA NAME, ADDRESS, WEBSITE] |
We aim to acknowledge privacy correspondence within 3 working days and to resolve it within the statutory period.
22. Definitions
Consumer health data — personal information linked to a consumer that identifies past, present or future physical or mental health status, as defined in Washington’s My Health My Data Act and Nevada SB 370.
Controller — the person who determines the purposes and means of processing (Art. 4(7) GDPR).
Personal data — information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
Processor — a person who processes personal data on behalf of a controller (Art. 4(8) GDPR).
Sell / Share — as defined in the CCPA as amended by the CPRA. “Share” specifically means disclosure for cross-context behavioural advertising.
Special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, data concerning health, or data concerning sex life or sexual orientation (Art. 9(1) GDPR).
23. Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 8 August 2026 | First publication. |