Live Biofeedback app
Live Biofeedback: privacy policy
Last updated: 26 September 2026
This policy explains what the Live Biofeedback app does with your data. It covers the app on iPhone and Android. We have tried to write it in plain language.
If anything is unclear, write to us at data-protection@selfscience.tech.
1. Who we are
The app is made and run by Self Science Institute ApS, a company registered in Denmark (CVR 43627287), Eremitageparken 213, 2D, 2800 Kongens Lyngby, Denmark.
We are the data controller for the personal data described here.
Privacy contact: data-protection@selfscience.tech
2. The short version
- You can join a session without an account. The app then does not know your name, email or phone number.
- During a session, your heart sensor's data goes from your phone to the facilitator's tablet in the room over the room's Wi-Fi. The room screen shows your heart rate under a short ID, such as i57, not your name.
- We ask for your consent before anything is recorded. If the facilitator keeps the session, the recording is stored on our server and in our cloud storage under random IDs, so that you and your practitioner can look back at it. It is not used for anything else unless you say so.
- Contributing your session data to Self Science is a separate choice, asked after you agree to join: you answer Yes or No, and your session is exactly the same either way. A Yes lets us use the data to improve the app and the models behind it, and to help your practitioner improve their sessions. A No means the session is kept only for your own record, and for no other use.
- If you are signed in when you join, the session is linked to your account and appears in My sessions. If you delete your account, we delete that link; the session data stays, under its random IDs, and can no longer be connected to you.
- If you join without an account, your phone keeps the session for 3 days so that you can still add it to an account. After that, the phone deletes it. The session data on our server stays, but nobody, including us, can connect it to you any more.
- You can hide yourself from the room screen, or withdraw from a session, at any time during the session.
- An account is optional. If you create one, we store the details you enter. You can delete your account in the app or ask us by email.
- The app has no ads and no tracking. We do not sell your data.
- The app is not a medical device.
3. What the app does
Live Biofeedback lets you take part in a live group biofeedback session led by a facilitator. You wear a Polar heart-rate sensor (a Polar H10 chest strap or a Polar Verity Sense armband). Your phone connects to the sensor over Bluetooth, calculates your heart rate and heart-rate variability, and sends them to the facilitator's tablet in the room. The room screen shows the group's signals together.
There is also a demo mode ("Try a demo"). It uses a made-up heart signal on your phone. Nothing from the demo is recorded or sent.
4. What data we process, and why
4.1 Session data (when you join a live session)
What:
- Data from your heart sensor: heart rate, the time between heartbeats (beat-to-beat intervals), and the sensor's own quality and skin-contact signals, with timestamps from your phone's clock.
- Values your phone calculates from that: heart rate, heart-rate variability (RMSSD and SDNN), a signal-quality score, and whether you are hidden from the room screen.
- "Mark" events: when you tap Mark, a time marker is sent to the facilitator's tablet.
- Random identifiers: a session ID, and a participant ID that your phone creates for you in each session. The room screen shows a short ID, such as i57, that the facilitator's tablet gives you for that session, not your name.
- The kind of sensor signal (for example, chest strap or armband).
Where it goes:
1. During the session, the calculated values, the beat-to-beat intervals and your markers go from your phone to the facilitator's tablet over the room's Wi-Fi. The tablet shows them on the room screen. This live stream stays on the room's local network.
2. At the end of the session, the facilitator decides to keep or discard the session. Kept: your phone uploads its recording of your sensor data (the beat-to-beat intervals and heart-rate readings listed above) to our server. The facilitator's tablet uploads the calculated values. Both are stored with the random IDs, not with your name. Discarded: your phone deletes its recording and uploads nothing. No decision received: your phone keeps the recording and does not upload it.
3. On your phone: if you joined signed in, a compressed copy of a kept recording stays in the app's private storage until you uninstall the app. If you joined without an account, the phone keeps the session, including its copy of the recording, for 3 days after the session so that you can add it to an account. Then it deletes it (section 4.5).
Why: to run the live session and show it in the room, and to keep a record of the session so that you and your practitioner can look back at it. That is all a kept session is used for, whether you joined with an account or without one, unless you say Yes to the separate question in section 4.2.
How long: as long as the record is needed: while the session is linked to your account, or for 3 days if you joined without one and did not add it to an account. Then it is deleted (section 7). If you answered Yes in section 4.2, the session is kept for 7 years for those purposes instead.
Legal basis: your consent, given on the "Before you join" screen. Heart data is health data, so this is explicit consent under GDPR Articles 6(1)(a) and 9(2)(a).
4.2 Contributing your session data to Self Science (optional)
When you tap "I agree — join", the app asks "Help us improve?": whether you want to contribute the data from that session to Self Science. You answer Yes or No. Your session is exactly the same either way, and you are asked again in each session you join.
If you answer Yes, we may keep your session data for 7 years and use it for two things:
- To improve the app and the models behind it, including developing and training the models (algorithms) behind our analyses.
- To help your practitioner improve their sessions. "Your practitioner" is the practitioner, and the centre they work for, who ran the session you joined. We analyse the session data and give them the results: for the group as a whole, and for each participant under the ID shown on the room screen in that session. We never give them your name. In a small group, your practitioner may be able to tell which results are yours. They use the results to evaluate and improve the sessions and services they offer.
This data is stored under the random session and participant IDs, not under your name. It is not sold, and it is not used for any purpose other than these two.
If you answer No, your data is not used for either of these: no analysis, no model and no practitioner result includes your session. It is kept only as your own record, as described in section 4.1, and deleted when that record is no longer needed (section 7).
Legal basis: your explicit consent (GDPR Articles 6(1)(a) and 9(2)(a)). You can withdraw it at any time; see section 8.
4.3 Consent records
What: for each session, one record for taking part and one for improving our product and your practitioner's sessions. Each says yes or no, the time you decided, the random session and participant IDs, and which version of the consent text you saw.
Why: we must be able to show that you gave consent, and when.
What happens if you withdraw: the records are not deleted. They are marked as withdrawn, with the time.
Legal basis: our legal obligation to be able to demonstrate consent (GDPR Articles 6(1)(c) and 7(1)).
4.4 Your account (optional)
You never need an account to join a session.
If you create an account, we store what you enter:
- first name
- email address
- phone number (optional)
- date of birth
- sex (male or female)
- height and weight
- the password you choose
If you sign in, you do so with your email address or your phone number and a one-time code that we send by email or text message.
Your phone stores your sign-in session (access tokens), your user ID and your email address in the app's storage, so you stay signed in. Signing out removes them from the phone.
Why: to give you an account, to show the sessions linked to it in My sessions and, once our report service starts, to send you a personal report of them.
Legal basis: performance of a contract with you (GDPR Article 6(1)(b)). Height and weight may be health data; for those, your explicit consent (Article 9(2)(a)).
4.5 Your sessions and your account
Whether a session is connected to you depends on whether you are signed in when you join.
Signed in when you join: the session is linked to your account. The app sends our server that session's random session ID and participant ID together with your sign-in, and the server notes on that participant record that it is yours. Linked sessions appear in My sessions and, once our report service starts, you receive a personal report of them. If you do not want a session linked to your account, sign out before you join.
Joined without an account: the session is not linked to anyone. Only your phone knows which random participant ID was yours in that session. It keeps that, for 3 days after the session, so that you can still add the session to an account:
- At the end of the session, the app invites you to sign in or create an account.
- If you sign in within 3 days, the app shows the sessions on this phone that are not yet linked, and asks which of them to add to your account. None is selected for you. The sessions you choose are linked as described above; the others are not.
- After 3 days, the phone deletes the IDs, and its copy of the recording, of every session you did not add. There is no report for those sessions. If you said No to contributing, their data on our server is deleted as well; if you said Yes, it stays for its 7 years (section 4.2), and nobody, including us, can connect it to you any more.
Linking a session sends only the two IDs. Your heart data is not sent again, and it never contains your name or your account: only the participant record connects the two.
Our report service has not started yet. Until it does, linking requests wait on your phone and are sent when it starts.
If you delete your account, we delete these links: the server removes your account from those participant records. Session data you contributed (a Yes in section 4.2) stays, under its random IDs, for the rest of its 7 years, and can no longer be connected to you. Sessions you did not contribute are deleted with the link.
Legal basis: performance of a contract (linking your sessions to the account you created, and your report).
4.6 Withdrawal and erasure requests
If you withdraw from a session, the app stops sending your data, deletes the recording on your phone for that session, and sends an erasure request to our server. The request contains the random session and participant IDs and the time.
Erasure is carried out after the session by our system and staff. See section 7 for what is erased and when.
4.7 Account deletion requests
If you ask to delete your account in the app, the app sends a request with your user ID, your email address and the source ("live_biofeedback"). Our server then immediately blocks the account and erases its personal details, and we delete the links between your account and your sessions. The session data itself stays under its random IDs (section 4.1). We keep the request, including your email address, only to confirm the deletion to you and as a record that it was done. See section 8.
4.8 Technical data
Like any server, our server receives your phone's IP address and the time of each request. These request logs are kept for 30 days.
Legal basis: our legitimate interest in running a secure service (GDPR Article 6(1)(f)).
We do not use analytics, crash reporting, advertising or tracking tools in this app.
5. Data that stays on your phone
Some things the app uses never leave your phone:
- Camera: used only to scan QR codes (the session code and your sensor's sticker). Camera images are not stored or sent.
- Your sensor's ID: used to connect to your sensor. It is not sent to us.
- Wi-Fi name and location permission (optional): iPhone and Android only show an app the Wi-Fi network's name if the app has location permission. In Profile, under "Check the session Wi-Fi", you can choose Off (the default), "Only while joining a session", or "During the whole session". The app asks for location permission only if you choose one of the last two. It then reads the Wi-Fi name and compares it with the session's network, on your phone. It does not read your GPS position, and it does not store or send the Wi-Fi name or your location.
- Joining the room's Wi-Fi: the session QR code can contain the room's Wi-Fi name and password. The app asks your phone to join that network; your phone shows its own prompt, and you decide. The app does not keep the password; your phone saves the network like any other.
- Sessions not yet added to an account: for a session you joined without an account, the phone keeps its random IDs, its date and duration, your ID in it and how it ended (completed, discarded or withdrawn), for 3 days after the session, so that you can add it to an account (section 4.5). Then it deletes them.
- Settings: for example whether you have seen the introduction, and your Wi-Fi check choice.
6. Who receives your data
We do not sell your data. We do not share it with advertisers.
- People in the room: the room screen shows everyone's heart signals with short IDs, not names. In a small group, others may be able to guess which signal is yours. You can hide yourself at any time.
- The facilitator's tablet: receives your live values and markers, and uploads them if the session is kept.
- Your practitioner and their centre: if you answered Yes to the question in section 4.2, the results of our analyses of that session, under your ID from the session and never with your name.
- Our service providers (processors), who store or send data for us under a data processing agreement:
- Server and database hosting (api.selfscience.tech): Google Cloud (Google Cloud EMEA Limited, Ireland), on servers in the Netherlands.
- File storage: Google Cloud Storage (Google Cloud EMEA Limited, Ireland), in the EU.
- Sending one-time codes by email: Simply.com (Denmark).
- Sending one-time codes by text message: Twilio (USA).
- Authorities, if the law requires it.
Outside the EU: when you sign in with your phone number, Twilio receives your phone number and the one-time code in the USA. That transfer is covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses. All other data is stored in the EU.
7. How long we keep data
| Data | How long |
|---|---|
| Session recordings and values from a kept session you contributed (Yes in section 4.2) | 7 years after the session, then deleted |
| Session recordings and values from a kept session you did not contribute (No) | While the session is linked to your account; 3 days after the session if you joined without an account and did not add it. Then deleted |
| The links between your account and your sessions | Until you delete your account |
| A session on your phone that you joined without an account: its IDs and its copy of the recording | 3 days after the session, unless you add it to an account |
| Consent records | 7 years after the session |
| Account data | Until you delete your account |
| Account deletion requests | 7 years |
| Server logs | 30 days |
| Other data on your phone | Until you uninstall the app (signing out removes your sign-in details) |
About withdrawal and erasure: when you withdraw, we record an erasure request. Within 30 days, our system erases your rows in the session database and the files that were already uploaded to cloud storage (deleted files stay recoverable by us for 7 days, then are gone). Summary results about the whole group that were calculated during the session may remain after your own data is erased.
8. Your rights
Under the GDPR you have the right to:
- see the data we hold about you (access)
- have wrong data corrected
- have your data deleted
- restrict or object to how we use it
- get your data in a portable format
- withdraw your consent at any time. This does not affect what was done before you withdrew.
To use any of these rights, write to data-protection@selfscience.tech. A session that is not linked to an account is stored only under random IDs, so we need your help to find your data in it: tell us the date, time and place, or the 4-digit session code, and your ID in that session (such as i57) if you remember it. Without these we may not be able to tell which data is yours. We answer within one month.
How to withdraw from a session: during the session, open the "…" menu and choose "Withdraw from this session". This stops your data, deletes the recording on your phone, and requests erasure of your data from that session. It cannot be undone. After the session has ended, write to data-protection@selfscience.tech instead.
How to withdraw your consent to the uses in section 4.2: write to data-protection@selfscience.tech with the date, time and place of the session, or its 4-digit session code. We then stop using that session's data for them, and leave it out of any results we give your practitioner from then on. Results they already received are not recalled.
How to hide: tap "Hide me" during a session. You leave the room screen. Hiding does not stop the recording on your phone. To stop and request deletion, withdraw instead.
How to delete your account: in the app, open Profile and tap "Delete account", or write to data-protection@selfscience.tech. In the app, your account is deleted immediately: it can no longer sign in and its personal details are erased. The links between your account and your sessions are deleted within 30 days, and we confirm by email. The session data itself stays under its random IDs (section 4.1); if you want a session's data deleted too, write to data-protection@selfscience.tech with its date, time and place, or its 4-digit session code.
You also have the right to complain to the Danish Data Protection Agency (Datatilsynet), www.datatilsynet.dk, or to the authority in the EU country where you live.
9. Security
- The app talks to our server only over encrypted connections (HTTPS). The production app refuses to start with an unencrypted server address.
- Session data is stored with random IDs, not names.
- The live stream between your phone and the facilitator's tablet uses the room's Wi-Fi. The app does not add its own encryption to it; it is protected only as far as the Wi-Fi network is (for example, by a Wi-Fi password).
10. Children
The app is for adults aged 18 and over. Do not use it if you are under 18. If you think a child has given us data, write to data-protection@selfscience.tech and we will delete it.
11. Not a medical device
Live Biofeedback is not a medical device. It does not diagnose, treat, prevent or monitor any disease or condition. Do not use it to make health decisions.
12. Changes to this policy
If we change this policy, we will update the date at the top and the text in the app. If a change affects how we use data you have already given us, we will tell you in the app or by email before it takes effect.
13. Contact
Self Science Institute ApS, Eremitageparken 213, 2D, 2800 Kongens Lyngby, Denmark
Privacy: data-protection@selfscience.tech
Support: helloworld@selfscience.tech