Privacy Policy
Last updated: [[EFFECTIVE DATE]]
This policy explains what personal data Sithea ("we", "us") collects, why, and your rights. Sithea processes health data, which is a special category of personal data under the GDPR — we only do so with your explicit consent (see "Lawful bases").
Data controller: [[LEGAL ENTITY]], [[POSTAL ADDRESS]]. Contact: [[CONTACT EMAIL]]. [[DPO CONTACT]]
1. Data we collect
Account
- Email address and display name (via Google Firebase Authentication).
Health & wellbeing data (special category) — the information you choose to log:
- Symptoms, pain, energy, sleep, food, and flare entries.
- Health conditions and medications you tell us about.
- Free-text you write to the AI assistant about how you feel.
AI assistant conversations
- The messages you send to and receive from the assistant, and short AI-generated "memory" summaries derived from them, so it can respond in context.
Community (optional)
- Your community display name, posts, comments, reactions, follows, and any reports or blocks you make.
- Direct messages you send to other members. These are encrypted at rest on our servers.
Connected services (optional, only if you enable them)
- Google Calendar: event details and access tokens (tokens are encrypted at rest), used to show and add events. You can disconnect at any time.
- Location: a city name you provide, or — only if you turn on auto location — your device's location (coordinates and the nearest city name), refreshed when you open the app. Either is used solely to fetch local weather and environmental conditions relevant to your symptoms. You can turn auto location off at any time in Profile; we then keep only the last saved location until you change or clear it.
- Push notifications: a device push token, used to send check-ins and medication reminders.
Preferences & technical
- Language, timezone, and check-in preferences.
- Limited technical diagnostics for reliability and error tracking. Our error reports are configured to exclude health content and personal identifiers (see "Security").
2. How we use your data & lawful bases (GDPR Art. 6 & 9)
- Provide the core service (store your logs, run the assistant, show your data back to you) — *performance of a contract* (Art. 6(1)(b)).
- Process your health data for the above — *your explicit consent* (Art. 9(2)(a)). You give this at the consent screen and can withdraw it at any time by deleting your data or your account (see "Your rights").
- AI features — to generate responses we send the relevant conversation text to our AI sub-processor (Google; see below). We do not use your data to train third-party foundation models.
- Optional integrations (calendar, location, notifications) — *your consent*, which you can withdraw by disabling the feature.
- Safety, security, moderation, and abuse prevention in the community — *legitimate interests* (Art. 6(1)(f)).
3. Sub-processors we share data with
We do not sell your data. We share the minimum necessary with service providers that process data on our behalf under contract:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Google (Firebase Authentication) | Sign-in | Email, auth identifiers |
| Google (Gemini AI API) | Generate assistant responses | Conversation text you send to the assistant |
| Google (Calendar API) | Calendar features (if connected) | Calendar events, OAuth tokens |
| Open-Meteo | Weather & air-quality data | Approximate location you provide |
| Sentry | Error/crash diagnostics | Technical error data (health content excluded) |
| Expo (650 Industries) | Push notification delivery | Device push token, notification text |
| Google Cloud Platform | Hosting & storage | All app data, at rest |
4. International transfers
We host data in the European Union. Some sub-processors (e.g. Google, Sentry) may process data outside the EU, including in the United States. Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep your data for as long as your account is active. When you delete your data or account, we remove it from our live systems. Limited exceptions we retain for safety and legal reasons: community moderation reports you filed, and blocks made against you by other members (so their protection survives your deletion). Backups are rotated on a routine schedule.
6. Your rights
Under the GDPR you can:
- Access / port your data — export it in-app (Profile → data export).
- Erase your data or account — delete it in-app (Profile → delete). This is immediate and irreversible.
- Rectify inaccurate data — edit it in-app.
- Restrict or object to processing, and withdraw consent at any time.
- Lodge a complaint with your supervisory authority ([[SUPERVISORY AUTHORITY]]).
To exercise rights not available in-app, contact [[CONTACT EMAIL]].
7. Security
- All traffic is encrypted in transit (TLS).
- Direct messages and Google Calendar tokens are encrypted at rest.
- Access to your data is isolated per-user at the database level.
- Error/diagnostic reports are scrubbed of health content and identifiers before they leave our servers.
No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of health data.
8. Children
Sithea is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact [[CONTACT EMAIL]] and we will delete it.
9. Changes
If we make material changes, we will update this page and ask you to re-accept in the app before you continue using it.
10. Contact
Questions or requests: [[CONTACT EMAIL]] — [[LEGAL ENTITY]], [[POSTAL ADDRESS]].