1. Who we are (data controller)
Helix (the "Application") is published by [TO BE COMPLETED: company name, legal form, company number, address]. Data Protection Officer (DPO) / privacy contact: dpo@helix-health.app. Any request relating to your data is answered within 30 days.
2. Our principle: data sovereignty and minimisation
Helix is designed to hold as little data as possible, especially your health data. The rule: your sensitive health data stays on your device(encryptable local storage) and, if you choose, in your own personal cloud (iCloud / Google Drive), not on our servers. We can neither read it, sell it, nor lose it on your behalf.
3. Data we process
3.1 Health data (special category, art. 9 GDPR), stored LOCALLY
Supplements/stack, physical characteristics, comorbidities/conditions, blood tests and biomarkers, biological age, sleep/movement data (watch), menstrual cycle phase, challenges. This data is stored locally on your device (IndexedDB database) and, optionally, backed up encrypted (AES-256) in your personal cloud. It does not transit through our servers.
- Legal basis: explicit consent (art. 9.2.a), collected in the app before any health data is stored.
3.2 Account and service data, server (Supabase, EU)
- Identification: e-mail address and authentication (password managed and hashed by the authentication service).
- Public profile: username, display name, avatar, bio, profile type.
- Social content: posts, comments, reactions, stories, private messages, events, community challenges, notifications.
- Daily journal: simple daily indicators (sleep yes/no, exercise yes/no, supplements taken yes/no).
- Nutrition: logged foods (products, quantities): no calories displayed.
- Legal basis: performance of the contract (providing the service) and consent (social features, nutrition).
3.3 Location
- Weather: your approximate coordinates are sent to the weather API (Open-Meteo) to contextualise your score (heat, pollution, UV). No account data is attached.
- Events: optional location to find events near you (opt-in, can be disabled).
- Legal basis: consent (browser/OS prompt).
3.4 Payment ("Founder" offer)
Purchases are handled by the App Store / Google Play and RevenueCat. We receive no banking data, only a purchase status (is_founder) linked to your identifier.
- Legal basis: performance of the contract.
3.5 Technical data
Authentication session, device type, timestamps, IP address (transient, for connection security). No advertising cookies, no third-party trackers.
- Legal basis: legitimate interest (security) / contract.
4. Processors and recipients
| Processor | Role | Location | Transfer safeguards |
|---|---|---|---|
| Supabase | Database hosting, authentication, social content storage | EU region | n/a (EU) |
| RevenueCat | In-app purchase management (Founder status) | United States | Standard Contractual Clauses (SCC) |
| Apple / Google | In-app purchase billing | United States | Store policies |
| Open-Meteo | Weather/pollution from coordinates | EU (Germany) | n/a (EU) |
| Transactional e-mail provider | Authentication e-mails | [TO BE COMPLETED] | [TO BE COMPLETED] |
We use no large language model (LLM) or external AI service: the scoring engine is a local algorithm. No data is sent to any AI third party.
5. Retention periods
- Local health data: for as long as you keep it on your device; you can erase everything at any time (uninstall, local wipe, or deletion within the app).
- Account and server content: for the life of the account. Deletion = 30-day grace period (cancellable), then permanent cascading purge (accounts, content, logs).
- Automatic retention: purge after prolonged total inactivity.
6. Your rights (GDPR)
- Access & portability: readable JSON export of your local data + ZIP export of server data, from Settings → Data.
- Rectification: edit your profile and data in the app.
- Erasure: account deletion (30-day soft-delete then purge); immediate local erasure.
- Objection / restriction: contact the DPO.
- Withdrawal of consent: at any time (disable health tracking, geolocation, etc.).
- Complaint: to the CNIL: cnil.fr/fr/plaintes.
7. Security
Encryption in transit (HTTPS), Row Level Security on all tables (each user can only access their own data), AES-256 encrypted local backups, signed URLs for private message media. Sensitive health data never leaves the device.
8. Minors
Helix is intended for people aged 18 and over (health optimisation content). We do not knowingly collect data from minors.
9. Changes
This policy may evolve. Any substantial change will be notified in the app.
10. Contact
Questions or to exercise your rights: dpo@helix-health.app.