Privacy policy

This privacy policy explains which personal data we process when you use the Hello Inside app, our website or our online shop, what we use it for, and what rights you have.

Summary

  • The controller is Roots Health GmbH in Vienna. Send questions about data protection to dataprotection@helloinside.com.
  • We store the data of your app account in data centers in Frankfurt am Main (EU).
  • We process health data such as glucose values, meals or sleep data with your explicit consent. You can withdraw it at any time.
  • We pass health data on to other companies only if you explicitly allow it, for example to your coach, your gym or your health insurance fund. Our service providers process data only on our behalf.
  • Marketing emails and the measurement of advertising in the app (AppsFlyer, Meta) are based on your consent.
  • We do not sell personal data.
  • You can delete your account in the app at any time and request access to, correction or deletion of your data, or a copy of it.

Controller and contact

Roots Health GmbH, FN 550059 k, Kopernikusgasse 8/20, 1060 Vienna, Austria (see our Imprint) (“Roots Health”, “we”).

You can reach our Data Protection Officer and us for all data protection questions at dataprotection@helloinside.com or by mail to the address above, attention of the Data Protection Officer.

Account and app

Data. For your account we process your email address, password (not stored in plain text), name, date of birth, gender, language and your settings. When you use the app, we also process device data (device type, operating system, app version, IP address, country), log and error data, and the identifier for push notifications.

Purposes and legal bases. We use this data to provide your account and the app's features, to send you notifications and to inform you about your contract, for example about changes to the terms or to this privacy policy (performance of contract, Article 6(1)(b) GDPR). To protect against misuse and unauthorized access and to analyze errors, we process device data and logs based on our legitimate interest in secure and stable operation (Article 6(1)(f) GDPR).

Required data. To create an account we need your email address and a password, or a sign-in with Apple or Google. Without this data you cannot use the app. If a feature needs further data, the feature is not available without it.

Sign-in with Apple or Google. If you use “Continue with Apple” or “Continue with Google”, we receive from Apple or Google your email address (with Apple, a forwarding address if you choose), your name and an identifier of your Apple or Google account. We never receive your password there. If a Hello Inside account with the same confirmed email address already exists, we link the sign-in to that account. With Apple we store an access key that we use to revoke your Sign in with Apple authorization when you delete your account; Apple tells us when you stop using the sign-in in your Apple settings. Apple (Apple Distribution International Ltd., Ireland) and Google (Google Ireland Limited, Ireland) are independent controllers of their sign-in services and process the data under their own privacy policies (Apple, Google). The legal basis is performance of contract (Article 6(1)(b) GDPR); we store the Apple key based on our legitimate interest in fully ending the connection to Apple when you delete your account (Article 6(1)(f) GDPR).

Health data

Data. Depending on which features you use: glucose values, meals and meal photos, height and weight, sleep, activity and heart rate data, symptoms and cycle information, journal entries, questionnaire answers, face scan results, and the analyses and recommendations calculated from them.

Sources. You enter the data yourself or connect a data source, such as your glucose sensor (via Abbott LibreView or Terra), Garmin, Oura, Apple Health or Health Connect. We only receive the data you share there. You decide what you share with Apple Health or Health Connect in their settings.

Face scan and AI. For the face scan, a specialized service provider analyzes the camera image on our behalf and returns estimates such as your heart rate. To recognize meals and for personal analyses we use AI services as processors. They receive the content needed for this, such as a meal photo or measured values, but not your name or contact details.

Legal basis. Your explicit consent (Article 9(2)(a) in conjunction with Article 6(1)(a) GDPR). You can withdraw it at any time, for example by disconnecting a data source in the app or by deleting your account. Without consent we cannot offer the health-related features.

Sharing health data with your permission

Coaching partners. If you enter a coaching partner's access code (e.g. a nutritionist or health coach) and confirm the sharing, the partner can read your data in our coaching dashboard to advise you. You see the categories (e.g. profile details, glucose values, meals, body measurements, activities, analyses) before you confirm. The data stays on our platform; the partner gets no copy, and Roots Health remains the sole controller.

Gyms. If you enter a gym's studio code and confirm the sharing, the headquarters of the franchise system and the assigned studio see your data in the coaching dashboard. Both are independent controllers and use the data for your support and coaching in the studio (including training and nutrition recommendations and recommendations related to your program participation), for central support, for quality assurance and review of how the program is run in the studios, and for managing and developing the program. For studios in Switzerland, the data is transferred to Switzerland, which is covered by an adequacy decision of the European Commission (Article 45 GDPR).

Legal basis and withdrawal. Your explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR). You can end a sharing at any time under Settings > Data sharing; access ends immediately.

Health insurance funds (prevention courses). If you register through a cooperation page of your statutory health insurance fund (e.g. HelloInside.com/mkk) for a prevention course recognized under § 20 SGB V, we transmit to your fund your health insurance number, your first and last name, your date of birth and your redemption and participation or completion status. The fund does not receive health, usage or app content data. The transmission serves to verify your insurance status, to document the course to the Central Prevention Testing Office (ZPP) and for the reporting agreed with the fund. Because taking part already allows conclusions about your health, we treat this data as health data. Your fund is an independent controller. The legal basis is your explicit consent (Article 6(1)(a) and Article 9(2)(a) GDPR). You can withdraw it at any time free of charge; the fund can then no longer cover the course fee, and the regular course fee under the terms applies. We store the transmitted data for no longer than 2 years after your participation ends or after a deletion request.

Programs of health insurers and partners

If you use Hello Inside through a program of your health insurance fund or a partner (e.g. BARMER or DocMorris), we receive a pseudonymous identifier from them to assign your participation. For BARMER, we prepare progress reports on the program on its behalf that identify you only by this identifier; BARMER is responsible for them.

Payments, subscriptions and online shop

App. Apple (App Store) and Google (Google Play) handle purchases in the app as independent controllers. Through a subscription management service we receive product, term, price, currency and a transaction identifier, but no credit card or bank details.

Online shop. For orders we process your name, address, email address, phone number and order data and pass them on to payment and shipping providers as far as needed to complete the order.

Legal bases. Performance of contract (Article 6(1)(b) GDPR) and statutory retention obligations, for example for invoices (Article 6(1)(c) GDPR).

Cookies on the website. We use technically necessary cookies without consent (§ 165(3) of the Austrian Telecommunications Act 2021). We use cookies and similar technologies for analytics and marketing only with your consent in the cookie banner. There you can see the individual providers and change your choice at any time. These technologies include Hotjar (Hotjar Ltd., Malta), which we use to analyze how the website is used, for example through heatmaps, and UpPromote (Secomapp, USA), which we use to attribute orders placed through referral links to our partners.

Customer support and surveys

Support. If you contact us by chat, email or through our social media channels, we process your contact details, your message and, for questions about the app, the account and device data needed. The legal basis is our legitimate interest in answering your request and improving our service (Article 6(1)(f) GDPR), and for requests about your data protection rights our legal obligation (Article 6(1)(c) GDPR).

Surveys and tests. You take part in surveys and product tests only with your consent (Article 6(1)(a) GDPR). Where possible, we analyze the answers anonymously.

Analytics and product improvement

We analyze how the app and the website are used, which features are popular and where errors occur, to improve our products, content and business. For this we use analytics and error diagnostics services that receive usage and device data with a pseudonymous identifier instead of your name or email address. The legal basis is our legitimate interest in improving our products (Article 6(1)(f) GDPR). You can object to this at any time.

Marketing

Emails and push notifications. With your consent we send you information about offers, programs and news and measure whether you open emails and click links, so that we can tailor content to you. If you have bought from us, we also send you information about similar products based on our legitimate interest, as long as you do not object. Legal bases: Article 6(1)(a) or (f) GDPR. You can unsubscribe at any time through the link in every email or by emailing us; you turn off push notifications in your device settings.

Advertising on other platforms. With your consent we use advertising platforms such as Meta or Google to show you ads there and to measure their success. The platforms match your profile with them for this. You may also see Hello Inside ads without consent, but then not based on the data we hold about you. Legal basis: Article 6(1)(a) GDPR.

Measuring app installs (AppsFlyer, Meta). In the app we use AppsFlyer (AppsFlyer Ltd., 14 Maskit St., Herzliya 4673314, Israel) as a processor to measure which campaign or link led you to install the app and to open links on go.helloinside.com at the right place in the app. AppsFlyer receives device data (e.g. IP address, device type, a device identifier and your device's advertising ID, on iOS only if you allow tracking), information about the ad or link, an identifier of your account without your name or email address, and the events registration (with the sign-in method for Apple or Google), sign-in, opening and purchasing a membership. AppsFlyer does not receive health data and deletes the data after 24 months at the latest. On first launch the app also uses Meta's software development kit to check whether you installed the app from an ad on Facebook or Instagram. In this process Meta Platforms Ireland Ltd. (Merrion Road, Dublin 4, Ireland) receives device data such as IP address, device type and the advertising ID (on iOS only if you allow tracking) and also processes it for its own purposes under its Privacy Policy. The legal basis is your consent (Article 6(1)(a) GDPR; for access to information on your device, § 165(3) of the Austrian Telecommunications Act 2021). You can withdraw it at any time; on iOS you change access to the advertising ID under Settings > “Privacy & Security” > “Tracking”.

Recipients

Service providers working on our behalf. We use processors in these areas; they may only use the data on our instructions:

  • Hosting and infrastructure (data centers in Frankfurt am Main)
  • Analytics, error diagnostics and control of app features
  • AI services for meal recognition and analyses, and the provider of the face scan
  • Email delivery, customer management, push notifications and customer support
  • Subscription management, payment processing and shipping
  • Surveys
  • Measuring app installs (AppsFlyer)
  • Referral program in the online shop

We will send you a list of the service providers on request.

Independent controllers. Apple and Google (sign-in, app stores, in-app payments), Meta (see Marketing), the providers of data sources you connect, and coaching partners, gyms, health insurance funds and program partners to the extent described above. If you share content from the app through social networks or messengers, we pass it on there at your instruction. We disclose data to authorities, courts, lawyers and tax advisors where we are obliged to or where it is needed to enforce or defend legal claims (Article 6(1)(c) or (f) GDPR).

We do not sell personal data.

Transfers to third countries

Some service providers or their group companies are located outside the EU and EEA, mainly in the USA. We transfer data there only on the basis of an adequacy decision of the European Commission (Article 45 GDPR, e.g. for Switzerland, Israel or companies certified under the EU-U.S. Data Privacy Framework) or of standard contractual clauses (Article 46(2)(c) GDPR). You can request a copy of the safeguards. Apple, Google and Meta are responsible for their own transfers.

Retention

We store the data of your account and the app as long as your account exists. When you delete your account in the app, we delete or anonymize your personal data immediately; we complete a deletion request by email within one month. The data disappears from our backups after 7 days at the latest. On deletion we anonymize health and usage data so that it can no longer be linked to you, and continue to use it in this form for analytics and to improve our analyses. Exceptions are invoices and accounting records, which we keep for 7 years under the Austrian Federal Fiscal Code (BAO) and Commercial Code (UGB), and the records of your data protection requests, which we keep for 3 years as proof. Different periods are stated in the sections above.

Your rights

You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). You can withdraw any consent at any time with effect for the future (Article 7(3)).

Objection. Where we process data based on our legitimate interest, you can object at any time on grounds relating to your particular situation. You can object to direct marketing at any time without giving reasons (Article 21 GDPR).

To exercise your rights, write to dataprotection@helloinside.com. You can also delete your account directly in the app.

We do not make automated decisions that have legal effects on you or similarly significantly affect you (Article 22 GDPR).

Complaint. You can lodge a complaint with a data protection authority, in Austria with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, phone +43 1 52152 2550, email dsb@dsb.gv.at, www.dsb.gv.at.

Security and changes

We protect your data with state-of-the-art technical and organizational measures and contractually oblige our service providers to do the same. We update this privacy policy when our processing changes and inform you about material changes.

Last Updated. This Privacy Policy was last amended on October 7, 2026.