Legal
Privacy policy
This English version is provided for convenience. Only the German version (Datenschutzerklärung) is legally binding.
This policy describes which data are processed when using “Biohacking Kompakt” – completely and without glossing over anything. The app uses several external services; which ones they are and when they come into play is described in detail below.
1. Controller
Paul Höser
Lohengrinstraße 8
81925 München
Deutschland
E-mail: kontakt@biohackingkompakt.de
A data protection officer is not required by law.
2. Principle: what happens without login
The app can be used without registration. No cookies for analytics or advertising purposes are set and no user profiles are created. To measure reach, a cookieless statistics service is used that does not recognize individual visitors – see section 2a. A user account is only required for the “MyData” area (section 7).
Certain functions do, however, transmit data to external services – in particular the AI functions, the daily check and the voice coach. These transmissions are described individually below.
2a. Reach measurement (Cloudflare Web Analytics)
To evaluate the use of the site, Cloudflare Web Analytics of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA is used.
In doing so, no cookies are set and there is no recognition of individual users – neither on this site nor across sites. No identifiers are stored on or read from your device; consent under § 25 TDDDG is therefore not required.
The following are processed: the page accessed, the referrer (the previously visited page), the time, information on browser, operating system and device type, the approximate country of origin and technical metrics on loading speed. The IP address is processed by Cloudflare only temporarily to determine this information and is not stored.
The purpose is the statistical evaluation of which content is used, in order to improve the service. The legal basis is my legitimate interest in data-minimizing reach measurement pursuant to Art. 6 Abs. 1 lit. f GDPR (DSGVO).
Cloudflare is certified under the EU-U.S. Data Privacy Framework; for transfers to the USA there is therefore an adequacy decision of the EU Commission. Further information: cloudflare.com/de-de/web-analytics-privacy
3. Hosting and server log files
The app is delivered via GitHub Pages (GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA – a subsidiary of Microsoft Corporation). When it is accessed, technically necessary access data are processed, in particular IP address, date and time, file retrieved, browser type and operating system.
The legal basis is Art. 6 Abs. 1 lit. f GDPR (DSGVO) (legitimate interest in secure and functional provision). The transfer of data to the USA is based on the standard contractual clauses or the certification under the EU-US Data Privacy Framework. Details: GitHub Privacy Statement.
4. Fonts
The fonts used (Inter, Space Grotesk) are delivered from the same server as the app. There is no connection to Google Fonts servers; consequently, no data are transmitted to Google in the process.
5. AI functions (supplement check, symptom search)
If you use an AI function, the text you enter is transmitted via a proxy service operated by me at Cloudflare to Google’s Gemini interface and processed there.
The following are transmitted: your search term or question and technical connection data (IP address vis-à-vis the proxy). A personal reference only arises insofar as you yourself write personal information into the input field – please do not enter any health data or names there.
Legal basis: Art. 6 Abs. 1 lit. b and f GDPR (DSGVO) (provision of the function you have called up). Providers: Google Ireland Limited or Google LLC (USA), Cloudflare, Inc. (USA).
6. Daily check: camera, selfie and vital measurement
Camera access takes place only if you start the function yourself and your browser has asked you for permission.
Vital measurement (pulse, respiratory rate, blink rate): The calculation runs entirely in your browser. The video material does not leave your device. For the optional face detection, a program library (MediaPipe) is loaded from the jsDelivr and Google Storage servers; in the process, your IP address is transmitted to these providers.
Image analysis: For the evaluation, individual still images are selected and transmitted to Google’s Gemini interface. These images show your face. They are not stored by me; Google decides on the storage period at Google. The legal basis is your consent pursuant to Art. 6 Abs. 1 lit. a and – insofar as the evaluation allows conclusions about health-related characteristics – Art. 9 Abs. 2 lit. a GDPR (DSGVO), which you give by deliberately starting the analysis. You can withdraw it at any time by no longer using the function.
Results (score, partial values, estimated BMI) are stored by the app exclusively locally in your browser (see section 10). You can delete the history there yourself at any time.
7. MyData: account, wearables and health values
The “MyData” area requires registration. Firebase (Google Ireland Limited / Google LLC) is used; server location of the database: europe-west1 (Belgium).
- Registration: Google login. Your user ID and e-mail address are processed.
- WHOOP: If you connect your WHOOP account, daily values such as recovery, heart rate variability, resting heart rate, sleep duration and strain are retrieved and stored assigned to your account.
- Apple Health: If you set up the shortcut, your iPhone transmits the values you have selected (e.g. steps, resting heart rate, heart rate variability, sleep) to an interface operated by me at Google Cloud (europe-west1) and from there to your account.
- Supplement log: Intakes you enter are stored assigned to your account.
These are health data within the meaning of Art. 9 GDPR (DSGVO). The legal basis is your explicit consent under Art. 9 Abs. 2 lit. a GDPR (DSGVO), which you give by creating the account and connecting the respective source. The data are technically secured in such a way that only your own account can read them.
You can disconnect at any time and request the deletion of your data (section 12). Storage period: until your withdrawal or the deletion of your account.
8. Voice coach (ElevenLabs)
The app integrates an AI voice assistant from ElevenLabs Inc. (USA). The control element is loaded from unpkg.com when the page is accessed; in the process, your IP address is transmitted. If you start a conversation, your voice input is transmitted to ElevenLabs and processed there.
Legal basis: Art. 6 Abs. 1 lit. a GDPR (DSGVO) (consent by actively starting the conversation). Please do not disclose any sensitive health data in the conversation.
Voice analysis for choosing the speaking voice
The voice coach answers in different speaking voices. So that it does not have to guess, at the start of a conversation the app estimates from your voice whether a male or a female voice is speaking. For this purpose, a separate microphone access is opened for a maximum of 14 seconds and the pitch of your voice is evaluated.
This evaluation runs entirely in your browser. Nothing is recorded, nothing is stored and nothing is uploaded – the audio used for this does not leave your computer. Only the result is transmitted to ElevenLabs, that is, a single word: männlich (male), weiblich (female) or unbestimmt (undetermined). The sole purpose is the selection of the speaking voice.
There is no identification: no voice profile, no voiceprint and no other identifying feature is created or stored, and the estimate is not linked to an account or a person. It applies only to the ongoing conversation and is gone afterwards. The estimate may be wrong; it has no effect on the answers, only on how they sound.
The voice analysis only runs during an actively started conversation. On iPhone, iPad and in the Safari browser it does not take place at all. Legal basis: Art. 6 Abs. 1 lit. a GDPR (DSGVO) (consent by actively starting the conversation).
9. Podcast embed (Spotify)
Podcast episodes are embedded as a Spotify player. The player is only loaded when you actively click on it – until then there is no connection to Spotify. After the click, Spotify (Spotify AB, Sweden) processes your IP address and possibly further usage data. Legal basis: Art. 6 Abs. 1 lit. a GDPR (DSGVO). Spotify’s privacy policy applies.
10. Local storage in the browser
The app stores some data in your browser’s local storage. These data do not leave your device and are not read by me:
- Cache of the news (about one hour) so that the page loads faster
- Cache of AI answers to symptom questions
- History of your daily check results
- Height and age entered by you for the BMI estimate
Legal basis: § 25 Abs. 2 TDDDG (technically necessary or a function you have expressly requested) and Art. 6 Abs. 1 lit. f GDPR (DSGVO). You can remove these data at any time via your browser settings or – for the daily check history – via the “Verlauf löschen” (delete history) button.
11. Contact
If you write to me by e-mail, I process your information to handle the enquiry. Legal basis: Art. 6 Abs. 1 lit. b or f GDPR (DSGVO). The data are deleted as soon as the enquiry has been conclusively dealt with and no retention obligations stand in the way.
12. Experience reports and affiliate links
Submitted reports. If you submit your own experience report, I store the text of your report, the display name you have chosen, your user ID and your e-mail address from the Google account used, in the same Firebase environment as the MyData function. Reports are checked by me before publication; only then are they publicly visible. Reports that have not been approved remain accessible only to you and me.
The legal basis is your consent under Art. 6 Abs. 1 lit. a GDPR (DSGVO), which you give when submitting. Since an experience report typically contains information about your own well-being, it may include health data within the meaning of Art. 9 GDPR (DSGVO). Your consent expressly extends to this as well (Art. 9 Abs. 2 lit. a GDPR (DSGVO)). Please only publish what you really want to make public, and do not name other persons.
You can withdraw your consent at any time with effect for the future and request the deletion of your report – an informal e-mail to the address given above is sufficient. Processing remains lawful until the withdrawal.
Affiliate links. In the experience reports area there may be links to shops for which I receive a commission in the event of a purchase. Such links are labelled in the app as Anzeige (advertisement). When you click on such a link, you leave this site; the respective provider may then set its own cookies or identifiers in order to attribute the purchase. The respective provider is responsible for this under data protection law – please inform yourself there. No tracking is set on this site itself, and the price does not change for you.
12a. Interface for AI assistants (MCP server, plugin and extension)
At mcp.biohackingkompakt.de I operate an interface according to the Model Context Protocol (MCP). Through it, AI assistants such as Claude or Gemini can query the content of this site – for example via the plugin or extension “Biohacking Kompakt” (github.com/phoeser/biohacking-kompakt) or if you enter the address yourself as a connector. The interface is read-only and can be used without registration.
What is processed: only the individual tool request that your AI assistant sends – for example a search term, a topic ID or an episode number – and technical connection data (IP address, time, path accessed, response code). Your conversation with the assistant, your name or your account with the AI provider do not reach the interface. There are no cookies, no user identifiers and no profiling.
Purpose and storage period: The request is answered and not stored; search terms are not logged. The IP address serves to limit requests per sender (protection against overload and misuse) and for technical operation. The interface runs on Cloudflare Workers (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA), which keeps technical operating logs only briefly and then deletes them automatically. The legal basis is Art. 6 Abs. 1 lit. f GDPR (DSGVO) (legitimate interest in secure, stable operation); the transfer to the USA is based on the certification under the EU-US Data Privacy Framework.
Which data the AI provider itself processes (for example Anthropic for Claude or Google for Gemini) is governed by its own privacy provisions.
13. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and a right to object to processing based on legitimate interests (Art. 21 GDPR (DSGVO)). You can withdraw any consent given at any time with effect for the future.
For all concerns, an informal e-mail to the address given above is sufficient.
Irrespective of this, you have the right to lodge a complaint with a supervisory authority. The competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
14. Changes
This policy is adjusted when the app or the legal situation changes. The version published here applies in each case.
Last updated: September 2026 · Legal notice · To the app (German)