Draft pending final legal review. This text accurately describes, from a technical standpoint, how the app handles data, but has not yet been reviewed by a qualified legal professional.
Privacy Policy – Schmerztagebuch
Applies to the "Schmerztagebuch" iPhone app. This website itself is covered by aix-hsg.de's general privacy policy.
1. Controller
AIX HSG UG (haftungsbeschränkt)
Pfarrer-Gursky-Ring 11, 52499 Baesweiler
Email: info@aix-hsg.de
2. Core principle: local processing
The app processes your health data on your own device by default. There is no server of its own, no backend, and no user account. The app does not, on its own, send any data to the publisher or any other third party. We do not receive, store, or process the contents of your pain diary.
For selected, optional intelligent features you can additionally enable Apple Private Cloud Compute (see section 5) — which is why we avoid the blanket statement "all data always stays on this device" here: that remains true without exception for the default state and all core features, but not necessarily once you enable that optional feature yourself.
3. Categories of data processed
- Timestamp of an entry
- Pain intensity (0–10 scale)
- Optional: body region, pain quality, possible triggers, whether medication was taken, a free-text note
- Technically necessary: a random identifier (UUID) generated per entry, which allows no conclusions about your identity
No contact details, name, or account data are processed unless you voluntarily enter them into a free-text field.
4. Storage
You choose the storage location yourself: via Apple HealthKit (encrypted by iOS to Apple's own standards) or purely on-device, outside Apple Health. If you have enabled iCloud sync for "Health", iOS automatically synchronizes your entries — end-to-end encrypted per Apple's statements — across your own devices; this is entirely controlled by iOS, not by this app.
5. Intelligent features and Apple Intelligence
The app offers optional, intelligent add-on features in three selectable modes (Settings → Intelligent Features):
- "On this device only" (default): diary data and analyses stay entirely on your device. No language model is used at all, not even locally.
- "Apple Intelligence on device": supported features use the Apple model available on your device. Your content is not transmitted to us or any cloud model — processing happens entirely offline, on your device.
- "Extended Apple Intelligence": if you additionally enable Apple Private Cloud Compute, the data required for a feature you specifically triggered — and which is clearly labeled as such — may be transmitted, encrypted, to Apple Private Cloud Compute for processing. Per Apple's own statements, this data is used only for the request and not stored. We do not receive this data. This feature is disabled by default, requires separate, revocable-at-any-time consent, and is never used automatically as a substitute for local processing.
6. Legal basis
Health data is a special category of personal data (Art. 9(1) GDPR). Processing is based on your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR), which you give by actively entering your own data and by granting the relevant iOS permission.
7. Exports and shares you trigger
A JSON/CSV export or a PDF medical report initially stays only on your device. It only leaves your device once you actively send, save, print, or hand it to another app via iOS's share function — and only to the destination you choose yourself.
8. Complete deletion and withdrawal
In the app's settings you can, at any time, irreversibly remove all stored entries, separately delete locally stored AI results, and withdraw a given Private Cloud Compute consent with immediate effect. Withdrawal does not affect the lawfulness of processing carried out before it.
9. Your rights as a data subject
Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20 — already directly implemented via the app's export function), and objection (Art. 21). Since all data resides exclusively on your device, you can exercise most of these rights directly within the app itself.
10. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement — for Baesweiler: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.