Last Updated: January 14, 2026
Your body, your data. At Haily, privacy is our top priority. We will never sell your data. We are based in Germany, and comply with the highest global standards of data protection laws, including the GDPR. This means that no matter where you are in the world, you can trust that Haily is committed to keeping your personal data safe.
This policy explains how we handle your personal data. Here's a quick summary. You should still read the full policy as well as our Terms of Service.
When you use Haily, you trust us with your personal data. We promise to always be clear about how your personal data is used, protect your rights and respect your data. We implement industry-standard security measures to protect your information, including encryption in transit and at rest, secure authentication mechanisms, and regular security assessments.
When you use Haily, we collect your personal data to make your experience better. This includes ensuring the safety of our Services, improving the accuracy of your insights and giving you relevant content and personalized recommendations based on your unique health patterns.
You can reach out to us anytime. You can access, change, correct, delete and update your personal data by emailing us at support@hailyhealth.de. Or you can get in touch with our data protection officer at privacy@hailyhealth.de. If you gave us consent to process your personal data, you can take your consent back at any point. If you have any questions about this Privacy Policy, let us know.
You must be at least 16 years old to use the app. See our Terms of Service for more information.
This Privacy Policy explains how App Werkstatt Taudt, operated by Aaron Taudt ("Haily" or "we" or "us") follows privacy laws such as the General Data Protection Regulation ("GDPR") and any other laws that protect your personal data. It also describes how Haily collects, stores, uses, and shares personal data from you through the Haily mobile application (the "App"), including all subdomains, products and services (together, the "Services").
App Werkstatt Taudt is a sole proprietorship (Einzelunternehmen) registered in Germany and the registered data controller of the Services.
We may update this Privacy Policy and any addendums from time to time. We review them at least once a year and make updates if needed to ensure they remain accurate. If there are material changes to this policy that we need to tell you about, we will let you know by email or through the App.
The latest updates to this policy are available in the App.
We collect personal data about you when you use the Services. This can come directly from you or from other sources and third parties.
General information: When you sign up for our Services, we collect personal data like your name, email, password (via authentication provider), and time zone. Based on how you use the Services, we may also infer your sex or gender.
Health and wellbeing data: When using our Services, you may enter personal data (including 'special category data' as defined in the GDPR) about yourself through natural language entries (voice or text). Our App enables effortless data entry through dialogue-based tracking, allowing you to log various health and lifestyle aspects in your own words.
The categories of information you may track include, but are not limited to:
Diary entries and tracks: You create natural language entries (voice or text) that capture your daily activities, meals, sleep, and how you feel. These entries are processed using AI technologies to extract structured information and provide insights.
Images: You may associate images with your entries, such as food photos for nutritional analysis. These images help enhance the accuracy of our nutritional insights and recommendations.
User configuration: You may provide physical characteristics (weight, height), demographic information (year of birth, gender), dietary preferences and restrictions, allergies, cycle configuration (if applicable), activity level, and other personalization settings that help us tailor the Services to your needs.
Third-party health services (including wearables): With your permission, we can connect to third-party services like Apple Health and Google Fit. This allows us to automatically import your health and activity data into the app, so you don't have to log it yourself. The imported data may include fitness activities, sleep patterns, body measurements (weight, height, BMI), heart rate, steps taken, distance traveled, calories burned, body temperature, and other activity and health details.
This information helps provide insights into your activities and improves our ability to provide personalized recommendations. We process this data to enhance the App's features and functionality.
Importing data is subject to the privacy policies and terms of Apple Health and Google Fit. If you use a wearable device to connect to Haily, please review its terms and privacy policies as well. Your device provider may collect usage data for its own purposes, such as improving its services.
When you use the Services, we may automatically collect certain information:
Device information: device model; information about the operating system and its version; unique device identifiers; enabled device accessibility features (e.g., display features, hearing features, and physical and motor features); mobile operator and network information; device storage information or version of your device system.
Location information: IP address for an approximate location; country; time zone or information about your mobile service provider. We do not collect your exact location. We only use location details for the reasons listed below.
Data about your use of the Services, including: frequency of use; areas and features of the Services that you access or use; payment transaction information (excluding full payment card details) or engagement with features.
To collect this and other information, we may use cookies and other similar technologies. See more in our Cookie Policy (if applicable).
Data from external sources: We may receive your personal data from third parties. For example, they may provide additional information to enhance your existing data, personalise your experience, and support analytics and statistics.
Depending on which features of the Services you use, we will process your personal data based on one or more of the following legal bases (we have included some examples):
Your consent: you can give us permission to process your health data to provide the Services, including AI-powered analysis and personalized recommendations.
To fulfill our contractual obligations to you in order to provide the Services to you: we may process your personal data to fulfill our contractual obligation to you for activities such as management of your Haily account, service delivery, subscription management, and other administrative purposes.
Legitimate interest: we may process your personal data based on our legitimate interests in order to manage our Services better. For example, we may use your personal data in order to:
Further examples of our legitimate interests are outlined in the table below. When relying on this legal basis, we first determine that we have a legitimate interest in conducting and managing our business. We then consider and balance potential impacts to you and your rights, to ensure that our interests do not override them.
Legal obligation: We may be obligated to process some of your personal data to comply with applicable laws and regulations.
| Purpose | Legal Basis |
|---|---|
| To support the App's features, including tailored content, insights and materials in the App | Consent |
| We use natural language processing technologies to parse and understand your diary entries and tracks, analyze your personal data to offer new features and Services, and suggest personalized health and wellbeing recommendations based on pattern recognition across health dimensions. | Consent |
| We customize product and service recommendations and insights to you, such as through emails or push notifications. We may also contact you about third-party products and offers (with your consent). | Consent |
| We process transactions and send related information, including confirmations and reminders about your subscription, for account management reasons and other administrative purposes. | Contract |
| To respond to your comments, questions, requests and to provide you with customer service. | Legitimate interest |
| To review App content, feedback and complaints to ensure the App's clinical safety and medical accuracy. | Legitimate interest |
| To send you technical notices and updates; security alerts, ensure the safety of our App and investigate incidents; support and administrative messages; and customer satisfaction surveys. | Legitimate interest |
| To monitor and analyse trends, usage and activities in connection with our App. | Legitimate interest |
| Promotional communications regarding our Services. | Consent |
| To enable you to participate in surveys and promotions. | Consent |
Data minimisation and purpose limitation: we only process personal data for the specific purposes for which it was collected or authorised by you.
No sale of personal data: we do not sell or rent your personal data for money. We will only share your personal data as outlined in this Privacy Policy. This includes sharing your personal data with our service providers who help us operate our Services. We will not use information from Apple Health or Google Fit for advertising or sell it to advertising platforms, data brokers or resellers.
Haily uses advanced AI technologies, including Large Language Models (LLMs), to process your natural language entries and provide personalized insights. This section explains how we handle AI processing of your data.
Use of AI Technologies: We work with leading AI service providers to process your natural language entries. These AI technologies enable us to:
How Data is Sent to AI Providers: When you create diary entries or tracks using natural language, this data is sent to our AI service providers for processing. We maintain strict controls over how AI providers handle your information through:
AI-Generated Insights: The AI technologies we use analyze your health data to identify patterns, correlations, and insights that help provide personalized recommendations. These insights are generated based on your unique health patterns and are designed to help you understand what makes you feel better.
User Control: You have control over AI processing of your data. You can:
Important Note: Your health data is processed to provide personalized insights, but we maintain strict controls over how AI providers handle your information. We do not allow AI providers to use your health data for training their models or for any purpose other than providing the Services to you, unless you have explicitly consented to such use.
We will not share your personal data with third parties except as specified within this Privacy Policy.
Sometimes, we work with other companies to process your personal data on our behalf. We call these companies or service providers "processors."
Processors are companies that help us operate our Services. We are responsible for any actions of these processors ensuring they follow the law and our instructions by entering into data processing agreements with them.
Here are some of the main processors we rely on:
For details about the processors we use in connection with cookies, please see our Cookie Policy (if applicable).
Haily's approach to analytics and marketing is designed to respect your privacy. Any analytics services we use are clearly disclosed, and we provide opt-out options where available. We do not share your health data with third parties for marketing purposes.
We may aggregate, anonymise or de-identify your personal data so that it cannot be used to identify you. This personal data might be shared with third parties, like research institutions or used for statistical purposes. For example, we may share general age and demographic information, along with aggregated statistics about activities or health patterns to identify trends across users and support scientific research. This helps us create articles, blog posts and scientific publications that advance research on health and wellbeing.
If we want to include you in specific research studies, we will ask for your consent. You can withdraw your consent at any time by emailing us at privacy@hailyhealth.de.
We may also preserve or share some of your personal data in the following limited circumstances:
Research: We may share anonymized or aggregated data with research partners for scientific purposes, but only with your explicit consent and in a form that cannot identify you.
Business transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.
We take various technical and organisational steps to protect your personal data from loss, theft, misuse, and unauthorised access, disclosure, alteration, and destruction. These measures are designed based on the nature of the personal data we handle and the risks associated with special categories of personal data we collect. This includes:
Database security: We implement Row Level Security (RLS) policies to ensure that users can only access their own data, providing an additional layer of protection for your personal information.
Please keep your password secure and don't share it with others. Consider adding a passcode or enabling biometric authentication for an extra layer of protection.
While we strive to protect your information, we cannot guarantee absolute security, nor can we ensure that your personal data won't be intercepted during transmission to us.
If there is a security breach and where required by law, we will either post a notice or try to contact you by email. We will take reasonable steps to fix the issue according to applicable laws and this Privacy Policy. For potential personal data breaches, we may take additional actions, such as logging you out from all the devices, resetting your password and other necessary steps to address the situation.
If you want to report a security incident related to the Services, please email us at privacy@hailyhealth.de.
Regardless of where you live, we're committed to providing you the same privacy rights afforded under the GDPR, which is generally regarded as the highest standard for data protection globally.
You have rights in relation to your personal data. Only you or someone authorised to act on your behalf can make a request about your personal data. If you authorise someone to act on your behalf, we may need to verify their authorisation.
If you think your personal data that we hold is incorrect, you can contact us to request a correction.
You can request that we limit the processing of your personal data in certain circumstances. For example, if you believe your personal data is inaccurate, you can ask us to restrict the processing while we verify it.
You have the right to know what personal data we process about you. You can request access to all your personal data and to receive a copy of it, including in a structured and portable form (we use .json files).
You can request your personal data in a format that lets you easily move, copy or transfer it to third parties for other services or purposes.
You can ask us to delete your personal data at any time. Keep in mind that deleting some personal data might affect your experience with certain features that depend on historic information.
You can object to the processing of your personal data, such as if we use it for direct marketing purposes.
To exercise your privacy rights, you can email us at support@hailyhealth.de or privacy@hailyhealth.de.
You can request to delete your account or make certain changes directly in the App's settings.
We will handle your request within one month of receiving it. In some cases, such as for complete deletion of your personal data stored in our backup systems, it may take 90 days. If we need more time to action your request, we will let you know and explain the reason for the delay. Please be aware that once the deletion process begins, it can't be undone. This is because your personal identifiers are immediately unlinked from your App information, which means we can no longer identify you, even if some data temporarily remains in our backup systems.
Your consent is required for us to use your health data. You can withdraw this consent at any time by either contacting us or deleting your account through the App.
If your request is unclear, we might reach out to you for clarification. We may also refuse or charge a reasonable fee for requests that are clearly unfounded and/or excessive.
To process your request, we'll need to verify your identity. Usually, this involves confirming that the request is coming from the email you used to register. If you haven't registered, we may ask you for additional verification to ensure we respond appropriately.
Depending on local laws, you may have the right to lodge a complaint with your local data protection authority about any of our activities. If you have any concerns about our privacy practices, please let us know by emailing our support team at support@hailyhealth.de or by emailing our data protection officer at privacy@hailyhealth.de.
We will keep your personal data for as long as necessary to provide you with the Services or fulfill the purposes for which it was collected (except as noted below).
Impact of account deactivation/requests to erase personal data: You can deactivate your account at any time by following instructions in the 'How to exercise your privacy rights' section. We will process your request within one month. In some cases, it will take up to 90 days to completely erase your personal data from our backup systems. If you choose to deactivate your account, Haily will delete your personal data, and it will not be recoverable should you later create another account.
Deleting the App or inactivity: If you delete the App from your device or your account becomes inactive, we will retain your personal data for three years in case you decide to reactivate the Services or reinstall the App. After three years of inactivity, your personal data will be deleted. Haily will apply this standard retention policy. However, you can still request earlier deletion by contacting us at any time.
Limitations: Even after your account is deleted, we may need to retain certain personal data and other information. This is required or permitted by applicable law, like the GDPR, and may include situations like:
We use industry-standard methods to securely and permanently delete your personal data from our systems, making it impossible to recover. This process may include sending automated notifications to our processors who process your personal data on our behalf.
Age limitation: our Services are not for children, and we do not knowingly collect personal data from anyone under 16. You must be at least 16 years old to use the App and access Haily's content. If you know of someone under 16 using the Services, please email us at support@hailyhealth.de. See our Terms of Service for more information.
Haily is based in Germany. The personal data we collect may be transferred to and processed in countries other than your own, including the United States and other countries where our service providers operate. These transfers are usually cloud-based and occur when you use our Services. Please note, the laws in these countries may not offer the same protections as those in your country.
Personal data in the EEA is protected by the GDPR. When we transfer personal data outside of the EEA, we apply appropriate safeguards to ensure your personal data is protected. For example, we use data transfer agreements that include the European Commission's Standard Contractual Clauses and conduct transfer risk assessments.
For further information, please email us at privacy@hailyhealth.de.
If applicable, we may participate in data transfer frameworks that provide additional protections for your personal data when transferred internationally.
If you live in the United States, we comply with applicable U.S. state privacy laws. Please contact us at privacy@hailyhealth.de if you have questions about your rights under U.S. privacy laws.
Our app may request the following permissions to provide you with the best possible experience:
Note: You can manage these permissions in your device settings at any time. Granting or revoking permissions may affect certain features of the app, but you can always use the core functionality of Haily regardless of your permission settings.
We might contact you via email, pop-ups or push notifications to share updates with you about Services, offers, promotions, rewards and events. These messages will be based on the Services you have chosen from Haily and the features you interact with.
Opt-out options: You can unsubscribe from marketing emails by clicking the "Unsubscribe" link in the email. Opting out of these marketing emails or notifications will not stop essential Service-related emails. To stop receiving push notifications, adjust your settings on your device. In some cases, we might ask for additional consent for certain communications.
Please note we may contact you through third-party platforms (like social media) with information about our Services, offers, promotions, rewards and events.
Essential communications: We may send you important service-related communications that you cannot opt out of, such as security alerts, account verification messages, and critical service updates.
We may use social media to promote Haily and interact with our customers. When you engage with us on these platforms, we process information about you, like your username, profile picture and any comments or posts related to Haily. This information is used solely for engagement purposes.
We may update this Privacy Policy from time to time. We review it at least once a year and make updates if needed to ensure it remains accurate. If there are material changes to this policy that we need to tell you about, we will let you know by email or through the App.
The latest updates to this policy are available in the App. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
Material changes: If we make material changes to this Privacy Policy, we will:
If you have any questions or concerns about your privacy, you may contact us or our data protection officer by writing to us at:
App Werkstatt Taudt
Am Kurpark 2A
93077 Bad Abbach
Germany
You can also reach us by email at:
If needed, you may also contact your local data protection authority. A list of local data protection authorities is available here.