Last updated: 29/09/2026 · Courtesy translation – the German version is legally binding.
1. Controller
2. Overview
The Health Diary is a web app in which you record your own blood pressure, pulse, weight and medication. Your entries are private: only you can see them. Even the operator only sees account details in the admin area (username, e-mail address, date of registration and last sign-in, number of entries) – never any health values.
3. What data is processed
- Account data: username, e-mail address, password (stored only as a secure hash), chosen language, time of registration, consent and last sign-in.
- Health data (special category under Art. 9 GDPR): blood pressure and pulse readings, weight, height, medication and intake records, as well as tags and notes you enter yourself.
- Technical data: to prevent abuse (e.g. mass registrations) your IP address is stored only as an irreversible hash for no more than 24 hours. The hosting provider also keeps standard server logs (IP address, time, requested address, browser).
4. Purposes and legal bases
- Health data is processed solely so that you can keep, evaluate and export your personal diary – based on your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR).
- Account data is required to provide your account, sign you in and send confirmation or password e-mails (Art. 6(1)(b) GDPR).
- Technical data serves security and stable operation (Art. 6(1)(f) GDPR).
There is no advertising, tracking, profiling or automated decision-making. The colour categories in the app are for guidance only and are not a diagnosis.
5. Consent and withdrawal
You give your consent when registering. It is voluntary. You can withdraw it at any time with effect for the future by deleting your account under “My account” or by e-mailing the controller. This does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR). The service may be used from the age of 16.
6. Hosting and recipients
The app and all data are stored on servers of ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, in Germany. The provider processes data solely on our behalf (data processing agreement under Art. 28 GDPR). E-mails are sent via this provider’s mail server. Data is not passed on to any other third parties or to countries outside the EU. Charts and fonts are not loaded from third-party servers.
7. Cookies
Only strictly necessary cookies are used – no analytics or advertising cookies:
gt_sitzung– keeps you signed in during your visit (deleted when the browser is closed).gt_merken– only if you choose “Keep me signed in”; valid for 90 days.gt_sprache– remembers your chosen language; valid for 1 year.
8. Retention
- Account and health data are kept until you delete individual entries or your account. Deleting your account removes all related data immediately and permanently.
- Unconfirmed registrations are deleted automatically after 7 days.
- One-time links (e-mail confirmation, password) expire after 48 and 2 hours respectively.
- The provider’s server logs are deleted after a short period according to its policies.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can exercise many of these rights directly in the app: edit and delete entries, download all data as CSV and delete your account. You also have the right to lodge a complaint with a data protection supervisory authority.
10. Security
The connection is always encrypted via HTTPS. Passwords are stored only as hashes. Every database query is restricted to your own account. Repeated failed sign-ins are temporarily blocked.