Privacy Policy
Effective Date: January 30, 2026 Version: 1.0
1. Introduction
Selfmax ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data in compliance with the General Data Protection Regulation (GDPR).
2. Data Controller
The data controller responsible for your personal data is:
- Company: Selfmax
- Email: privacy@selfmax.app
3. Data We Collect
3.1 Account Information
- Email address
- Display name (optional)
- Password (hashed)
- Authentication tokens
3.2 Health & Wellness Data
- Supplement intake logs
- Workout records
- Body measurements
- Sleep data (if provided)
- Nutrition information (if provided)
3.3 Usage Data
- Device information
- IP address
- Browser type
- App usage patterns
- Feature interactions
3.4 Communication Data
- AI chat history
- Support communications
- Feedback submissions
4. Legal Basis for Processing
We process your data based on:
- Consent: For health data collection and marketing communications
- Contract: To provide the Service you requested
- Legitimate Interests: For security, fraud prevention, and service improvement
5. How We Use Your Data
- Provide and personalize the Service
- Generate AI-powered health insights
- Send service notifications
- Improve and develop new features
- Ensure security and prevent fraud
- Comply with legal obligations
6. Data Sharing
We may share data with:
- Cloud Infrastructure: For hosting and storage
- AI Providers: For generating insights (anonymized where possible)
- Analytics: For service improvement (aggregated data)
- Legal Authorities: When required by law
We do NOT sell your personal data.
7. International Transfers
Your data may be transferred to servers outside the EEA. We ensure appropriate safeguards through Standard Contractual Clauses or equivalent mechanisms.
8. Data Retention
- Account Data: Retained while your account is active, plus 30 days after deletion
- Health Data: Retained while your account is active
- Usage Logs: Retained for 12 months
- AI Chat History: Retained for 90 days
9. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured format
- Object: Object to certain processing activities
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact: privacy@selfmax.app
10. Data Security
We implement appropriate technical and organizational measures:
- Encryption in transit and at rest
- Regular security audits
- Access controls and authentication
- Incident response procedures
11. Cookies & Tracking
We use essential cookies for:
- Authentication and session management
- Security (CSRF protection)
- User preferences
We do NOT use advertising or tracking cookies.
12. Children's Privacy
Selfmax is not intended for users under 16 years of age. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
14. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority.
15. Contact
For privacy-related inquiries:
- Email: privacy@selfmax.app
- Subject: Privacy Inquiry
This Privacy Policy was last updated on January 30, 2026.