Privacy Policy

Last updated: 12 August 2026

1. What this policy covers

This policy explains how we process personal data when you visit kessa.health and when you use the Kessa: Endo & PCOS Tracker mobile app. It applies alongside the privacy information shown on the App Store and Google Play listings.

2. Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:

Bytes & Pixels GmbH
Gröbenzeller Str. 40, 80997 München, Deutschland
Represented by: Benjamin Robert Bachhuber
E-mail: kontakt@bytes-and-pixels.de
Phone: 089-15002979

For questions about data protection, including requests to exercise your rights, write to kontakt@bytes-and-pixels.de.

3. Hosting and server log files

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you access the site, the hosting provider automatically processes technical information (IP address, browser type, operating system, referrer URL, time of access) in server log files to deliver the website and ensure its stability and security (Art. 6 (1) (f) GDPR). We have concluded a data processing agreement with Vercel. Log data is deleted or anonymised after a short period.

4. Analytics and marketing on this website

This website currently uses no analytics or marketing tracking tools and sets no cookies beyond those technically required to deliver the pages.

5. Data we process in the Kessa app

Kessa is a symptom and cycle tracker for people living with endometriosis, PCOS and related conditions: you record how you feel, and the app turns those entries into trends and reports you can take to an appointment. To do that, the App processes the following data, each for the stated purpose and on the stated legal basis:

  • Account data (e-mail address and password, or your Apple or Google sign-in)to create your account, sign you in and sync your entries between your devices. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
  • Health entries (symptoms, pain levels, bleeding and cycle data, medication, treatments, notes and attached photos)to store your diary, show your trends and generate the reports you ask for. Legal basis: Art. 9 (2) (a) GDPR (explicit consent) together with Art. 6 (1) (a) GDPR.
  • Subscription status (purchase receipt and store identifier)to unlock paid features and to prevent misuse of free trials. Legal basis: Art. 6 (1) (b) GDPR.
  • Device and diagnostic data (device model, operating system and app version, crash reports)to find and fix errors and keep the app stable. Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in a working app).
  • Usage data (which screens and features you use, pseudonymous)to understand how the app is used and improve it. Legal basis: Art. 6 (1) (a) GDPR (consent — you can decline without losing any feature).
  • Push notification tokento send the reminders you switch on. Legal basis: Art. 6 (1) (a) GDPR (consent).
  • Support correspondence (your message and contact details)to answer your request. Legal basis: Art. 6 (1) (b) and (f) GDPR.

Where processing is based on your consent, you may withdraw it at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out beforehand. Where data is needed to provide a feature, not providing it means that feature cannot work.

6. Sensitive data (Art. 9 GDPR)

Kessa: Endo & PCOS Tracker processes data about your health — symptoms, pain levels, bleeding and cycle data, medication and treatments, and anything you write in your notes. Under Art. 9 GDPR this is a special category of personal data, so we process it only on the basis of your explicit consent (Art. 9 (2) (a) GDPR), which you give when you start using the relevant feature and can withdraw at any time by deleting the data or your account.

We do not use this data for advertising, we do not sell it, and we do not share it with advertising networks or data brokers. It is shared only with the service providers listed below, which act as our processors under Art. 28 GDPR and are bound to use it solely to run the service, and only when that is necessary for a feature you use.

Anything you export or share yourself — for example a report you send to your doctor — leaves our control once you send it. Please share such exports only with people you trust.

7. Advertising and profiling

We do not show third-party advertising in the app, we do not sell personal data, and we never share your health entries with advertising networks or data brokers.

Nothing in the app makes an automated decision that produces legal effects for you or similarly significantly affects you within the meaning of Art. 22 GDPR. Trends and summaries are simply calculated from your own entries.

8. Service providers

We use the following providers to operate the App. They process data on our behalf as processors under Art. 28 GDPR, on the basis of a data processing agreement, and only on our instructions:

  • Apple App Store and Google Play (Apple Distribution International Ltd., Ireland and Google Ireland Ltd., Ireland) — distribution of the app and processing of in-app purchases.
  • RevenueCat (RevenueCat, Inc., USA) — management and validation of subscriptions.
  • Google Firebase (Google Ireland Ltd., Ireland) — account sign-in, encrypted storage of your entries and delivery of push notifications.
  • Sentry (Functional Software, Inc., USA) — crash reports and error diagnostics.
  • PostHog (PostHog, Inc., EU Cloud) — pseudonymous product analytics, only if you consent.

Apple and Google additionally act as independent controllers for the store and payment data they collect when you download the App or make a purchase; their own privacy policies apply to that processing.

9. Transfers outside the EU

Some of the providers named above are based outside the European Economic Area, or process data there. In those cases the transfer is safeguarded by the European Commission’s standard contractual clauses, by the provider’s certification under the EU-US Data Privacy Framework, or by your explicit consent (Art. 44 ff. GDPR). Despite these safeguards, we cannot rule out that authorities in those countries access data.

10. How long we keep data

Your entries stay in the app until you delete them or delete your account; we then remove them from our live systems within 30 days and from encrypted backups within a further 30 days. Crash reports are kept for 90 days, pseudonymous usage data for 12 months, and support correspondence for up to two years after your request is closed.

Website server log data is kept only briefly for security purposes. Beyond that we keep personal data only as long as it is needed for the purpose it was collected for, or as long as statutory retention periods require — invoices and accounting records, for instance, must be kept for up to ten years under German tax and commercial law.

11. Deleting your data

You can delete your data at any time: open Settings → Account → Delete account in the app, which permanently removes your entries together with your account. You can also ask us to do it by writing to ben@bytes-and-pixels.de — we confirm deletion within 30 days.

Deletion removes your data from our live systems. Encrypted backups are overwritten on their normal rotation, and data we must keep for legal reasons — invoices, for instance — is blocked from further use instead of deleted until the retention period ends.

12. Children

The App is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it. Where we rely on consent, users under 16 in the EU need the consent of a parent or guardian (Art. 8 GDPR).

13. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future. To exercise your rights, contact kontakt@bytes-and-pixels.de.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany. You may also contact the authority where you live.

14. Changes to this policy

We may update this privacy policy to reflect legal or technical changes. The current version is always available at https://kessa.health/privacy.