Controller: REILIN TREE SRL · VAT no.: RO31699074 · Trade Register: ROONRC.J2014001104232 · Registered office: Intrarea Mărgăritarului nr. 2, ground floor, room 1, Otopeni, Ilfov County, Romania · Email: hello@myhistamate.com

This policy explains, in plain language, what personal data we process through the MyHistamate app, for what purposes, on what legal basis, who we share it with, how long we keep it and what rights you have. MyHistamate processes health data — a special category of data, given additional protection by Article 9 of Regulation (EU) 2016/679 (the “GDPR”). We wrote this policy to be read, not just ticked: please go through it.

This page covers the mobile app. For data processed through the myhistamate.com website (newsletter, waiting list, guides), see the website privacy policy.

This is an English translation of the Romanian original, available at myhistamate.ro/confidentialitate-aplicatie.html. It is provided for your convenience; in the event of any discrepancy, the Romanian version prevails.

1. The data controller and how to reach us

The controller of your data is REILIN TREE SRL, a Romanian company registered with the Trade Register under ROONRC.J2014001104232, VAT no. RO31699074, with its registered office at Intrarea Mărgăritarului nr. 2, ground floor, room 1, Otopeni, Ilfov County (“we”).

For any question or request about your data, write to us at hello@myhistamate.com.

We have assessed whether we are required to appoint a data protection officer (DPO) under Article 37 GDPR. We process health data as a core activity but, given the number of users of the App, we consider that this processing does not take place “on a large scale” within the meaning of Article 37(1)(c) GDPR. We review this position periodically and will appoint a DPO once that threshold is reached. Until then, your requests are handled directly by the controller.

2. What data we process and where it comes from

All the data below comes directly from you — you enter it in the app. We do not collect data about you from other sources and we do not use advertising tracking technologies.

  • Account data: your email address, your first name (if you choose to enter it) and your password — stored only in encrypted form (hashed), never in plain text.
  • Health data (special category, Article 9 GDPR): the condition you are tracking (histamine intolerance / MCAS / both / unsure), sex, age group, treatments and doses, the symptoms you track (including ones you define yourself), the habits you monitor, menstrual cycle data (only if you turn tracking on), other conditions or allergies you mention, everything you write in your daily diary, as well as the results the AI generates from all of this (diary structuring, correlations, menu estimates).
  • Menu photos: the images you send for scanning. They are transmitted for analysis and are not stored permanently by us; we keep only the result of the analysis, in your account.
  • Technical AI usage data: the number of requests, the type of feature used and the volume of tokens consumed — without the content of the messages. We use this to apply plan limits, prevent abuse and control costs.
  • Subscription data: your active plan, the status of your trial period and technical transaction identifiers received from the app stores. We never see or store your card details.
  • Feedback: the messages you voluntarily send us through the feedback form.

Providing account data is necessary in order to create an account. Providing health data is voluntary — but without it the app's core features cannot work, because they are built precisely on that data.

3. Purposes and legal bases

  • Creating and administering your account, running the app — basis: performance of the contract with you, Article 6(1)(b) GDPR.
  • Processing your health data (diary, profile, AI features) — basis: your consent, Article 6(1)(a), together with your explicit consent for special categories of data, Article 9(2)(a) GDPR. You give it at sign-up, through a distinct affirmative action, separate from accepting the Terms. You can withdraw it at any time, directly from Settings (section 9).
  • Applying limits, security, preventing abuse — basis: our legitimate interest, Article 6(1)(f) GDPR.
  • Managing subscriptions and tax and accounting obligations — basis: performance of the contract and our legal obligations, Article 6(1)(b) and (c) GDPR.
  • Processing feedback to improve the App — basis: our legitimate interest, Article 6(1)(f) GDPR.
  • Service communications — basis: performance of the contract and legitimate interest. We do not send you marketing without separate consent.

We do not sell your data. We do not use it for advertising. We do not pass it to third parties for any purpose other than those above.

4. AI, profiling and automated decisions

You are interacting with an artificial intelligence system. MyHistamate uses an AI model (Claude, provided by Anthropic) to structure your diary text, analyse menu photos and generate observations about possible correlations between food, habits and how you feel. AI-generated content is marked as such in the App.

This is a form of profiling within the meaning of the GDPR, but it produces no legal effects and no effects that similarly significantly affect you, and it is not an automated decision within the meaning of Article 22 GDPR: the results are indicative observations you are free to ignore, they do not restrict your access to any service, and the app makes no decision on your behalf. Even if a feature were to fall under Article 22, the processing would be based on explicit consent, in accordance with Article 22(2)(c) and (4) GDPR. You can ask for human intervention at any time, by writing to hello@myhistamate.com.

AI observations may contain errors. Correlation is not causation. They are not a diagnosis and do not replace your doctor.

Safeguards (Article 3 of Romanian Law no. 190/2018, which requires explicit consent and appropriate safeguards for profiling based on health data):

  • we send the AI provider only what is strictly necessary for each feature; we do not send your name, email, password or account identifiers;
  • data is technically isolated between users (Row Level Security);
  • administrative access to the database is logged, justified and reviewed periodically;
  • the AI assistant is prevented, by server-side filters, from commenting on doses, evaluating treatments or issuing diagnoses; a server-side emergency filter stops processing and directs you to 112 / support lines when it detects signals of a medical emergency or crisis;
  • you can ask for human intervention and contest any result;
  • you can withdraw your consent at any time, from Settings.

What happens to the data at the AI provider. Under Anthropic's commercial terms, data sent through the API is not used to train AI models. Its retention is governed by Anthropic's commercial retention policy in force at the time of processing, which our contract refers to.

By way of exception, if a request is automatically flagged by Anthropic's safety systems as a possible violation of its usage policy, the content of the request and of the response may be retained by Anthropic for up to 2 years, and classification scores for up to 7 years. We do not control this exception and we cannot delete that data.

5. Who we share data with (processors)

We share data only with the providers strictly necessary to run the app, each bound by contract (Article 28 GDPR) to process it only on our instructions and to protect it:

  • Supabase — database hosting and authentication. Data is stored on servers in Frankfurt, Germany (European Union). Supabase Inc. is a United States company; administrative or support access may take place from outside the EU, under the conditions in section 6.
  • Anthropic — the AI features. We send it, strictly as needed per feature: your health profile (the condition tracked, sex, age group, treatments, symptoms, other conditions), extracts from your diary (up to 30 days, depending on the feature) and menu photos when you scan. We do NOT send your name, email, password or account identifiers.
  • RevenueCat — technical management of subscriptions; it receives a technical user identifier and transaction data, never health data.
  • Apple App Store / Google Play — they process subscription payments (they are the merchant of record for the transaction); the payment relationship is also governed by their own privacy policies.
  • Sentry — automatic reporting of technical errors. It receives only technical data: phone model, operating system version, app version and the technical details of the error. It does NOT receive diary content, conversations with Histamate or any other health data.

We announce in the App any addition of a provider that has access to health data, before it happens.

We may also disclose data where the law requires it, strictly to the extent required.

6. Transfers outside the European Union

The database is located in the EU (Frankfurt). Anthropic, RevenueCat and Sentry may process data in the United States, and Supabase administrative access may take place from the US.

These transfers take place with the safeguards provided for in Chapter V GDPR:

ProviderCountry of processingTransfer mechanism
SupabaseEU (storage) / US (administrative access)Standard Contractual Clauses (Decision (EU) 2021/914), Module 2, incorporated in the Supabase data processing addendum
AnthropicUSStandard Contractual Clauses (Decision (EU) 2021/914), Module 2, incorporated in the Anthropic data processing addendum
RevenueCatUSStandard Contractual Clauses (Decision (EU) 2021/914), Module 2, incorporated in the RevenueCat data processing addendum
SentryUSData Privacy Framework (EU–US), with Standard Contractual Clauses (Decision (EU) 2021/914), Module 2, as a fallback safeguard

We have carried out a Transfer Impact Assessment, in line with Recommendations 01/2020 of the European Data Protection Board. You can request a copy of the safeguards at the contact address.

7. How long we keep data

  • While your account is active: we keep your data in order to provide the service.
  • Inactive accounts: if you do not sign in for 24 months, we send you a warning email. If you do not come back within 30 days, we delete the account and the data.
  • When you delete your account: personal data is deleted immediately from live systems, and backups are fully cleared within 30 days at the latest.
  • When you withdraw consent for health data: that data (diary, health profile) is deleted and the AI features stop; your account, email and subscription remain.
  • Limited exceptions: technical AI usage data (without content) may be kept in aggregated form for internal statistics; accounting records are kept for 10 years, in accordance with Article 25 of Romanian Accounting Law no. 82/1991.
  • Copies held by our providers: we cannot instantly delete temporary technical copies held by our providers; these are cleared according to their contractual retention periods (see section 4).

8. How we protect your data

Data is encrypted in transit (TLS) and at rest. Access between users is technically isolated (Row Level Security). Limits and safety checks are enforced on the server, not only in the app.

To be straight with you: our administrators, holding technical keys, can access the database when strictly necessary — for example to provide support at your request or to fix a fault — and only for that purpose. Every administrative access is logged, justified and reviewed periodically. The people with access are contractually bound to confidentiality (Article 29 GDPR).

We keep an internal register of security incidents (Article 33(5) GDPR). If we suffered a personal data breach that creates a high risk to you, we will inform you without undue delay and will notify the supervisory authority within the legal deadline of 72 hours, in accordance with Articles 33–34 GDPR.

9. Your rights

Under the GDPR you have the following rights, free of charge:

  • Access (Article 15): to find out what data we hold about you — most of it you can see directly in the app — and to receive a copy.
  • Rectification (Article 16): you edit your profile, treatments, symptoms and diary directly in the app.
  • Erasure (Article 17): the “Delete account” button in Settings removes your account and data from live systems, immediately. Backups are cleared within 30 days at the latest. Certain accounting records are kept for the period required by law.
  • Portability (Article 20): on request, we provide the data in your account in a structured, commonly used, machine-readable format (JSON or CSV), within one month. Separately, you can export a PDF report of your diary for a chosen period from within the app — that is a convenience tool, not the portability format.
  • Restriction (Article 18) and objection (Article 21): you can ask us to restrict processing, or object to processing based on legitimate interest.
  • Withdrawing consent (Article 7): at any time, for health data, from a dedicated button in Settings → Privacy → Withdraw consent. After withdrawal, the features that depend on health data stop and that data is deleted; your account stays active. Withdrawing is as easy as giving consent and does not affect processing lawfully carried out beforehand.
  • Human intervention: you can ask at any time for a person to review a result generated by the AI.

Send any request to hello@myhistamate.com. We respond within one month at the latest (extendable by two months for complex requests, in which case we let you know). If we have reasonable doubts about the identity of the person making the request, we may ask for identity verification (Article 12(6) GDPR).

If you are not satisfied with our response, you have the right to lodge a complaint with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing, B-dul G-ral Gheorghe Magheru 28-30, Bucharest, anspdcp.ro) or with the supervisory authority in your EU country of residence, as well as the right to a judicial remedy.

10. Minimum age

MyHistamate is intended for people aged 16 and over. We do not offer the App directly to children. A child under 16 cannot create an account, cannot sign in and does not use the App.

If you find out that someone under 16 has created an account on their own, write to us and we will delete it.

11. Cookies and tracking

The app does not use advertising cookies, advertising tracking SDKs or commercial profiling tools. The only technical data stored on your device is what is needed for the app to work (for example, your sign-in session).

12. Changes to this policy

We may update this policy when the app or the law changes. We announce significant changes — especially those concerning health data — in the app before they take effect. If we extend the purposes for which we use health data, we will ask for your consent again, before any new processing. The version in force, with its update date, is always available here.

Important note — we are not a medical service

MyHistamate is a self-observation diary. It is NOT a medical device, it does NOT diagnose, it does NOT predict reactions, it does NOT monitor a disease and it does NOT replace your doctor's advice. The correlations it shows are not causes. For any medical decision, consult a professional. Details in the Terms & conditions.