Privacy Policy
Effective date: 09.09.2026 · Version 1.0
This document is available in English only.
At Patternia (“we”, “us”), we value your privacy. This Privacy Policy (“Privacy Policy”) explains how we process personal data and covers everything we collect, store, use, and share when you use the Patternia mobile application (the "App") and our website at https://patternia.app (the "Website"), including all subdomains and related services (together, the "Services").
Patternia, is registered in Germany and is the data controller responsible for the Services. The Services are provided by Patternia UG (haftungsbeschränkt).
When and How We Collect Personal Data
We collect personal data in a few different ways depending on how you use the App and what features you choose to enable.
Information you give us directly
When you create an account and use the App, you share certain information with us, such as your name, email address, and the details you choose to log within the App. Some of this information is necessary to provide the service; other details are optional and help us personalise your experience.
Health apps and wearable devices
With your permission, we can connect to other health apps and wearable devices you use (such as Oura, Apple Watch, Fitbit, Garmin, Apple Health, Google Fit, or menstrual cycle trackers such as Flo, Clue etc) to automatically import your health and activity data into the App. This means you don't have to log everything manually. The data we may receive includes fitness activities, heart rate, sleep patterns, body temperature, cycle information, and other activity details, depending on what the connected app or device tracks and what you choose to share with us.
This information helps us provide a more complete picture of your wellbeing and improves the quality of the insights the App can offer you. You can connect or disconnect any of these services at any time through the App or through your device settings.
Device and technical information
When you use the App or visit our Website, we automatically collect certain technical information about your device and how you interact with our Services. This includes things like your device type, operating system, app version, and general usage patterns. We use this information to keep the App running smoothly, fix issues, and improve the overall experience.
Location information
With your permission, we may collect information about your general location. You can control location access through your device settings at any time.
Information from other sources
We may also receive information about you from other sources, such as third-party partners or publicly available sources, where this is permitted by applicable law. Where we do this, we will always tell you.
Purposes and Legal Grounds for Processing
Depending on the features you use, we process your personal data for different reasons and on different legal grounds. Here is an overview of those grounds, followed by a description of what we actually do with your data and why.
Your consent. For certain types of data (particularly health and activity information) we will only process your data if you have actively given us permission to do so. You can withdraw this consent at any time through the App's privacy settings, and we will stop processing that data going forward. Withdrawing consent does not affect the lawfulness of any processing we carried out before you withdrew it. However, some features of the App may no longer be available.
Contractual necessity. Some processing is simply necessary to provide the App to you. When you create an account, make a purchase, or use a core feature, we need to process certain data to fulfil our side of that relationship.
Legitimate interests. Where the law allows, we may process your data to pursue our legitimate business interests, provided those interests do not override your rights. This includes things like keeping the App secure, understanding how people use it, and making it better over time. We describe these activities in more detail below.
Legal obligation. Sometimes we are required by law to process or retain certain data, for example, to comply with a regulatory request or to meet our financial record-keeping obligations.
Complaint. If you believe we have not handled your data correctly, you can lodge a complaint with your local data protection authority.
| Purpose | Legal basis | Example |
|---|---|---|
| Providing personalised insights. We use the information you log in the App — along with data from any health apps or wearables you connect — to identify patterns and surface insights relevant to your experience. | Consent | We use your logged episodes and connected device data to show you conditions that were similar the last time you had a migraine, and what has helped others in similar situations. |
| Personalising your experience. We use information about how you use the App — such as the features you engage with and the preferences you set — to tailor what you see and make the App more relevant to you over time. | Consent | We may surface content or suggestions based on patterns we have noticed in your data. |
| Managing your account and subscription. We process certain information to keep your account running, handle payments, and send you relevant updates about your subscription or changes to the Service. | Contract | We send you a confirmation when your subscription renews or when your payment details need updating. |
| Keeping the App secure and running smoothly. We process technical data to monitor performance, fix issues, and protect the App from abuse or unauthorised access. | Legitimate interests | We check that account sign-ups are coming from real people, not automated systems. |
| Understanding how the App is used. We analyse overall usage patterns to understand what is working, where people run into difficulties, and how we can improve the App over time. | Legitimate interests | We look at which features are used most and where people tend to drop off, so we can prioritise improvements. |
| Complying with legal obligations. Sometimes we are required by law to process or retain certain data — for example, to respond to a regulatory request or meet financial record-keeping requirements. | Legal obligation | — |
Data Retention
We only keep your personal data for as long as we need it. The table below explains how long we hold each type of data and why.
| Data Category | Retention Period |
|---|---|
| Account identifiers (name, email) | For the duration of your account, plus 30 days after deletion to enable recovery if desired. Permanently deleted thereafter. |
| Health logs, daily entries | Health data is retained while your account is active. If you withdraw consent for a specific data category, the affected data is permanently deleted after a 30-day grace period. If you delete your account, all associated data is permanently deleted after a 30-day grace period. Revoking device or provider access stops new data collection but does not delete previously synced data. |
| App usage and analytics data (pseudonymised) | Up to 25 months |
| Support communications | 3 years from the date of last communication, or until your account is deleted, whichever is earlier. |
| Payment and transaction records | 10 years, as required by law |
You may request early deletion of your data at any time by exercising your right to erasure (see the Your Rights section). Exceptions to erasure are limited and are described in that section.
Who We Share Your Data With
We do not sell your data. We share personal data only in the following circumstances, and only with parties who are contractually bound to protect it.
Service Providers
We use third-party service providers who process personal data on our behalf, under our instructions.
| Provider Type | What they do | Data involved |
|---|---|---|
| Cloud infrastructure | Hosting, storage, and database management | All data categories, we apply appropriate technical and organisational security measures to protect personal data, including encryption of data at rest and in transit where appropriate, together with access controls and other safeguards designed to protect data against unauthorised access, loss, alteration, or disclosure. |
| AI / machine learning provider | Processes pseudonymised health and activity data to identify patterns and generate insights surfaced to you within the App | Pseudonymised health logs, activity data, and wearable readings — no directly identifying information such as your name or email address is included |
| Error monitoring | Crash and API-error reporting and diagnostics | Technical error data only, such as endpoint, request method, status code, and backend error messages. No request bodies, authentication tokens, IP addresses, or health data are sent. |
| Authentication & identity providers | User authentication, sign-in, and account access management | Email address and unique sign-in identifier. For Sign in with Apple, this may include an Apple private-relay email address instead of the user's actual email address. |
| Push notification provider | Push notification delivery | Device push token and app-generated device UUID. |
| Analytics platform | App performance and usage monitoring | Pseudonymised usage data only — no health data |
| Customer support platform | Handling support requests | Name, email, and message content |
| Email delivery service | Sending transactional emails | Name and email address |
| Payment processor | Processing subscription payments | Name and billing details — payment data is handled directly by the processor |
We do not permit any of our processors to use your personal data for their own purposes. We will update this list when we onboard new service providers.
Wearable and Health App Platforms
When you choose to connect a wearable or health app, data flows from that platform to the App based on the permissions you grant within that platform. Once we receive the data, we are responsible for it. We recommend reviewing the privacy policy of any platform you connect.
Legal Obligations and Regulatory Requests
We may disclose personal data where required to do so by applicable law, court order, or at the request of a competent Data Protection Authority. Where legally permitted, we will notify you before complying with such a request.
International Transfers
Some of our service providers are based outside the EEA, including in the United States. Where we transfer personal data to a country that does not have equivalent data protection laws, we put safeguards in place, including:
- Standard Contractual Clauses adopted by the European Commission;
- Transfer Impact Assessments where required; and
- Additional technical measures such as encryption and pseudonymisation where appropriate.
Your Rights
You have rights over your personal data, and we want to make it easy for you to exercise them. You can reach us at hello@patternia.com or through the Privacy section in the App settings. We will respond within one month of receiving your request.
Access and correction. You can ask us at any time to tell you what personal data we hold about you and how we use it. If any of it is inaccurate or incomplete, you can ask us to correct it. Most information can be updated directly in the App.
Deletion. You can ask us to delete your personal data. When you do, we will erase it unless we are required by law to keep it (for example, certain financial records) or unless we need it to resolve an ongoing dispute. You can delete your account and health data directly in the App.
Restricting how we use your data. If you believe data we hold about you is inaccurate, or you have objected to how we use it, you can ask us to pause processing it while we look into your request.
Portability. You can ask us to send you a copy of the personal data you have provided to us in a format that is easy to read and transfer to another service.
Objecting to processing. Where we process your data based on our legitimate interests, you can object at any time. We will stop unless we have compelling reasons to continue that outweigh your interests.
Withdrawing consent. Where we process your data based on your consent (including all health data) you can withdraw that consent at any time through the App's privacy settings.
Automated Decision-Making
We do not use any of the information you provide for automated decision-making purposes.
Cookies
We use cookies and similar technologies (such as pixel tags) on our Website and App. Cookies are small files stored on your device that help the App and Website work, remember your preferences, and understand how people use our Services.
Changes to This Privacy Policy
We review this Privacy Policy regularly and update it when needed to make sure it stays accurate and reflects how we actually work. If we make changes that matter to you, we'll let you know — by email or through the App — before they take effect. The latest version is always available on our Website and in the App.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, you can contact us at hello@patternia.com.