Privacy Policy

Last updated: [[EFFECTIVE DATE]]

This policy explains what personal data Sithea ("we", "us") collects, why, and your rights. Sithea processes health data, which is a special category of personal data under the GDPR — we only do so with your explicit consent (see "Lawful bases").

Data controller: [[LEGAL ENTITY]], [[POSTAL ADDRESS]]. Contact: [[CONTACT EMAIL]]. [[DPO CONTACT]]

1. Data we collect

Account

Health & wellbeing data (special category) — the information you choose to log:

AI assistant conversations

Community (optional)

Connected services (optional, only if you enable them)

Preferences & technical

2. How we use your data & lawful bases (GDPR Art. 6 & 9)

3. Sub-processors we share data with

We do not sell your data. We share the minimum necessary with service providers that process data on our behalf under contract:

Sub-processorPurposeData involved
Google (Firebase Authentication)Sign-inEmail, auth identifiers
Google (Gemini AI API)Generate assistant responsesConversation text you send to the assistant
Google (Calendar API)Calendar features (if connected)Calendar events, OAuth tokens
Open-MeteoWeather & air-quality dataApproximate location you provide
SentryError/crash diagnosticsTechnical error data (health content excluded)
Expo (650 Industries)Push notification deliveryDevice push token, notification text
Google Cloud PlatformHosting & storageAll app data, at rest

4. International transfers

We host data in the European Union. Some sub-processors (e.g. Google, Sentry) may process data outside the EU, including in the United States. Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.

5. Retention

We keep your data for as long as your account is active. When you delete your data or account, we remove it from our live systems. Limited exceptions we retain for safety and legal reasons: community moderation reports you filed, and blocks made against you by other members (so their protection survives your deletion). Backups are rotated on a routine schedule.

6. Your rights

Under the GDPR you can:

To exercise rights not available in-app, contact [[CONTACT EMAIL]].

7. Security

No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of health data.

8. Children

Sithea is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact [[CONTACT EMAIL]] and we will delete it.

9. Changes

If we make material changes, we will update this page and ask you to re-accept in the app before you continue using it.

10. Contact

Questions or requests: [[CONTACT EMAIL]] — [[LEGAL ENTITY]], [[POSTAL ADDRESS]].