Privacy
What we keep, and why.
Last updated: 9 September 2026
HormoTize processes health data: your blood values, your sleep, your heart-rate variability, what you record about yourself each day. That is special category data under Article 9 of the General Data Protection Regulation (GDPR), and stricter rules apply to it than to a name and an email address.
This statement sets out exactly which data we process, what for, on which legal basis, who we share it with, how long we keep it and what rights you have. It covers the HormoTize.com website, the HormoTize app, and the servers both run on.
1.Who we are
The controller for the processing described below is:
- Actus Rens, trading as HormoTize (a sole proprietorship under Dutch law)
- Chamber of Commerce number: [Chamber of Commerce number]
- Registered address: [registered address]
- Email: [contact address]
- Website: HormoTize.com
Being the controller means we decide what your data is used for and how, and that we are who you come to with questions and requests. To ask, see, correct or delete something, the email address above is the address.
2.What data we process
We process the following categories of personal data. Not all of it applies to everyone: what you do not fill in and do not connect, we do not process either.
- Account data: your email address, your password (stored only as an encrypted hash — we cannot read it), your name, and the language, units and theme you use the app in.
- Contact and billing data: first name, last name, address, postcode, town, country and optionally your phone number. Your postcode is also used to find the nearest draw location; your phone number only if the lab needs to reach you about your appointment.
- Profile data: date of birth, sex, height, weight, waist circumference and body-fat percentage, your goal, your activity level, training days per week, how much you usually sleep, your average stress level, and any physical complaint you describe during intake.
- Health data from bloodwork: the measured value per biomarker, its unit, the date of the draw, the reference range and the optimal range, and the status that follows from them.
- Data from your daily check-in: libido, mood, morning, afternoon and evening energy, stress level with any causes and a free note, alcohol, caffeine, water, type of training, bedtime and wake time, and the behaviours you chose to track yourself (daylight, supplements, breathwork, cold exposure, screens late in the evening, and whatever else you add to your list).
- Data from a connected wearable: sleep duration and when your night began and ended, sleep, recovery, stress and activity scores, heart-rate variability, resting heart rate, strain, steps, VO₂max and energy expenditure.
- Data we calculate: your Hormonal Recovery Index and the subscores beneath it, your biological age per body system, your streak, your daily snapshots, and the actions the app suggests and you tick off.
- Payment data: the fact of and reason for your payment, the amount, the status of your subscription and the transaction reference at our payment provider. Full card details never reach us.
- Technical data: the IP address you reach our server from, sign-in and sync timestamps, error messages and log files, and the device token needed to send you a push notification.
3.Where that data comes from
- From you: everything you enter when creating your account, during onboarding, at checkout and in the daily check-in.
- From the laboratory: the results of your bloodwork, attached to your account after analysis.
- From your wearable: only if you connect one yourself, and only the data listed under 'Wearables' below.
- From our own calculations: your scores, your biological ages and your guidance are derived from the data above.
4.What we use it for, and on which legal basis
Every processing operation has a purpose and a legal basis. Health data additionally requires a condition under Article 9 GDPR; that is covered in the next section.
| Purpose | Which data | Legal basis (GDPR) |
|---|---|---|
| Creating your account and signing you in on the site and in the app | Account and contact data | Performance of the contract (Art. 6(1)(b)) |
| Processing your order, arranging your blood draw and issuing your invoice | Contact, billing and payment data | Performance of the contract (Art. 6(1)(b)) |
| Showing your results and calculating your biological age per system | Health data and profile data | Performance of the contract (b) and explicit consent (Art. 9(2)(a)) |
| Calculating your daily Hormonal Recovery Index and giving you guidance | Check-in, wearable data, profile and biomarkers | Performance of the contract (b) and explicit consent (Art. 9(2)(a)) |
| Retrieving data from a wearable you connect | Wearable data and that connection's access keys | Consent (Art. 6(1)(a)) and explicit consent (Art. 9(2)(a)) |
| Answering your question to the AI coach | The limited summary of your own figures described below | Performance of the contract (b) and explicit consent (Art. 9(2)(a)) |
| Showing your data to a personal trainer you have chosen | Your scores, your markers and the notes in that relationship | Explicit consent (Art. 9(2)(a)), per trainer and revocable |
| Sending you reminders and notifications | Device token, email address and your notification preferences | Performance of the contract (b), or consent where you switch it on yourself |
| Securing the service, diagnosing faults and preventing abuse | Technical data and log files | Legitimate interests (Art. 6(1)(f)) |
| Meeting our legal obligations, including tax record-keeping | Payment and invoice data | Legal obligation (Art. 6(1)(c)) |
We do not use your data for advertising, we do not sell it, and we do not trade it with third parties for their own purposes.
5.Health data and your explicit consent
Blood values, sleep, heart-rate variability, stress, libido: that is data about your health. The GDPR prohibits processing it unless an exception applies. We rely on the exception in Article 9(2)(a): your explicit consent.
We ask for that consent visibly and separately — when you create your account, for your blood results and your daily data, and again at the moment you connect a wearable or give a trainer access. Giving consent is voluntary.
You can withdraw your consent at any time, and doing so is as easy as giving it: disconnect the wearable, end the relationship with your trainer, or delete your account in the app. Withdrawal does not work retroactively: what we lawfully processed before that moment remains lawfully processed. From that point on we stop the processing and delete the data concerned in line with the retention periods below.
If you withdraw consent for the processing of your health data entirely, we can no longer deliver the core of the service: without that data there is no score, no biological age and no guidance.
6.Wearables: what we read and what we do not
Connecting a wearable is optional. The app works without one; your daily score then rests entirely on what you enter yourself. If you do connect one, we read the following per measured day:
- Sleep: how long you slept and when your night began and ended, and where the vendor provides one, a sleep score.
- Recovery and stress: heart-rate variability, resting heart rate, and where available a recovery or stress score.
- Exertion: steps, strain or load, energy expenditure and VO₂max.
We do not read second-by-second heart rate, the location or route of your workouts, messages, contacts or any other data on your phone, and no data about other people.
There are two kinds of connection. With WHOOP, Oura and Fitbit you give permission on that vendor's own site; we then receive a key our server uses to fetch your daily figures periodically. We store that key encrypted (AES-256-GCM) and it is valid only for the data you approved. With Apple Health and Google Health Connect everything happens on your phone: you grant permission there per type of data, the app reads it and sends only the daily values above to our server. In both cases you can end the connection in the app; we then stop using the key and delete it.
Your wearable's vendor is independently responsible for its own platform. What that company does with your data is set out in its own privacy statement, over which we have no control.
7.The AI coach
The app has a coach that answers questions about your own figures in plain language. To do that, a limited summary of your data is sent to our supplier's language model (Anthropic), which acts as a processor.
That summary contains: your first name, your goal, your current HRI and its trend, your five subscores, which factors are helping your score and which are holding it back, the names and status of biomarkers outside their range, the most recent values from your wearable, and the date of your last check-in. Nothing more.
What is not sent: your email address, your address, your phone number, your payment details, your date of birth, your free-text notes and your full history. Under the commercial terms of the programming interface used, this data is not used to train models.
Every answer from the coach passes a check before you see it: if the model names a medicine, a dose or a diagnosis, the answer is replaced by a message referring you to a doctor. The coach is explicitly not a doctor and does not diagnose.
To substantiate guidance we verify references to scientific publications against PubMed (NCBI). Only the publication's identifier leaves our server — never anything about you.
8.Sharing with your personal trainer
If you work with a personal trainer who uses HormoTize, you can give them access to your data. That only happens if you confirm the link yourself; we record the moment of your consent.
A linked trainer sees your scores, how they move over time and the biomarkers outside their range, plus the notes the two of you write to each other in that relationship. They do not see your payment data, your address or your password.
You can end the link at any time. The trainer immediately loses access to your data.
9.Who else processes your data
We engage other parties in order to deliver the service. With parties that process on our behalf we conclude a processing agreement as required by Article 28 GDPR. They may use your data only for the purpose we supply it for.
| Party | Role | What they receive |
|---|---|---|
| Labplusarts and affiliated draw locations | Laboratory and blood draw | Your name, date of birth, sex, contact details and the requested panel; they return the results |
| Railway | Hosting and database | All data the service stores, as the operator of the infrastructure |
| Stripe | Payment provider | Your name, email address, billing address and the amount due; your card or bank details go directly to Stripe and never pass through us |
| Resend | Email delivery | Your email address and the content of transactional messages, such as a link to reset your password |
| Expo | Push notifications | Your phone's device token and the text of the notification |
| Anthropic | Language model behind the AI coach | The limited summary described under 'The AI coach' above |
| WHOOP, Oura, Fitbit, Apple, Google | Your wearable's vendor, independently responsible | Only if you connect: the read permissions you grant them; we receive the daily figures |
We may also disclose data to a supervisory authority, law-enforcement body or court where we are legally required to do so.
10.Transfers outside the European Economic Area
Several of the parties above are established in the United States or process data outside the EEA: Stripe, Railway, Expo, Anthropic and the wearable vendors.
For those transfers we ensure an appropriate safeguard under Chapter V GDPR: an adequacy decision of the European Commission where one applies (such as the EU-US Data Privacy Framework for participating parties), and otherwise the Commission's standard contractual clauses, supplemented by technical measures such as encryption in transit and at rest.
If you want to know which safeguard applies to a specific party, ask us and we will send you that information.
11.How long we keep your data
We do not keep data longer than is necessary for the purpose we obtained it for.
| Category | Retention period |
|---|---|
| Account, profile and contact data | For as long as you have an account. After you delete your account: removed from the live database immediately, and from backups within 30 days at the latest |
| Health data: blood results, check-ins, wearable data and calculated scores | For as long as you have an account, because your trend across the years is the heart of the service. Delete your account and it goes with it — without exception and without a retained copy |
| Payment and invoice data | 7 years after the end of the financial year, under Dutch tax record-keeping rules (Art. 52 AWR) |
| Access keys for a connected wearable | Until you disconnect it or delete your account |
| Sync logs | 90 days |
| Technical and security log files | 30 days, unless an incident requires a longer investigation |
| A link to reset your password | 1 hour, and it expires the moment it is used once |
12.How we secure your data
We take appropriate technical and organisational measures as required by Article 32 GDPR. Concretely, rather than as a general promise:
- All traffic between your phone, your browser and our server is encrypted over TLS.
- Your password is stored only as an irreversible hash. We cannot read it and will never ask you for it.
- Access keys for connected wearables are stored encrypted in the database with AES-256-GCM, under a key managed separately from the database.
- Every request to the server is checked for a valid, time-limited session, and every data lookup is bound to the user making it, so nobody can reach someone else's account.
- Access to the production environment is limited to those who need it, and is logged.
- Answers from the AI coach are screened before they reach you, so no medication or diagnostic advice comes out.
13.Automated decision-making and profiling
The app automatically calculates your Hormonal Recovery Index, your subscores and your biological age per body system, and derives guidance from them. That is profiling within the meaning of the GDPR: a picture of your health is built from your data.
It is not automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22 GDPR. No decision is taken about you that affects your legal position: nothing is granted or refused, and the outcome is not shared with insurers, employers or anyone else.
The logic behind it is deliberately traceable: for each score the app shows which factors feed it and with what weight. If something is wrong in the data a score rests on, you can correct it and the app recalculates.
14.Your rights
Under the GDPR you have the following rights. You exercise them by emailing us, and several of them you can do faster yourself in the app.
- Access: you may know what data we process about you and receive a copy of it.
- Rectification: if data is wrong, we correct it. Your profile and your check-ins you edit yourself in the app.
- Erasure: you may have your data deleted. In the app you can delete your account; that removes your profile, your results, your check-ins, your wearable data and your calculated scores in one go. What we are legally required to keep — the invoice data — remains until that period has passed.
- Restriction: you may ask us to pause processing, for instance while we investigate a correction.
- Objection: you may object to processing that rests on our legitimate interests.
- Portability: you may receive your data in a common, machine-readable format to take to another service. Ask us and you will get an export.
- Withdrawing consent: at any time, and as easily as you gave it.
We respond to your request within one month. If the request is complex we may extend that by two months, and we will tell you so within the first month.
To avoid handing over or erasing the wrong person's data, we may ask you to identify yourself.
15.Data breaches
If a security breach occurs involving your data, we report it to the Dutch Data Protection Authority within 72 hours of discovery, unless the breach is unlikely to result in a risk. If it presents a high risk to your rights and freedoms, we will also tell you, in plain language, what happened and what you can do.
16.Age
HormoTize is meant for adults. You must be eighteen or older to create an account and buy a package. If we discover we have processed data belonging to someone younger, we delete it.
17.Cookies
The website stores a small amount of data in your browser: your session, so you stay signed in, and your language choice, so the site comes back in the same language. The cookie policy sets out exactly what is stored, for how long, and how to remove it.
18.Changes to this statement
When the service changes, this statement changes with it. The date at the top says when that last happened. For a material change — a new purpose, a new category of data or a new recipient — we will tell you through the app or by email before it takes effect.
19.Questions or a complaint
If you have a question about this statement or about what we do with your data, email [contact address]. We answer ourselves; there is no form in between.
If you disagree with how we handle your data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl. We would rather hear it first so we can put it right — but that route is always open to you.
HormoTize processes special category data. This statement describes the processing as it actually takes place in the software; the legal qualifications in it are made to the best of our knowledge and are being reviewed by a privacy lawyer. Missing company details will be filled in once registration is final.