Privacy Policy
Draft last updated August 12, 2026
Pre-launch draft: not legally reviewed and not in effect.
Status of this draft
This pre-launch draft describes the application's current technical behaviour. It is not a complete privacy notice. The operating entity and address, legal bases, the condition for processing health data, international-transfer safeguards, final retention periods and supervisory-authority information must be completed and reviewed against the GDPR Article 13 transparency requirements before public launch. Questions can be sent to privacy@whichear.app.
What we store
- Account data. Email address, a normalized copy used for matching, an Argon2id password hash, verification and password-change dates, account creation/update dates, and the last successful login date. Whichear does not store the password itself.
- Sessions. A hash of the random session token, creation and last-seen timestamps, expiry and revocation timestamps. The unhashed token stays in an HTTP-only session cookie in the browser.
- Account tokens. Hashes of email-verification and password-reset tokens, their purpose, creation, expiry and consumption timestamps. The email provider receives the one-time link needed to deliver the message.
- Security and rate-limit records. Login result and reason, timestamps, account reference when available, and deterministic hashes derived from the submitted email address and client IP address. These hashes reduce direct exposure but are still treated as personal data.
- Optional symptom diary. If the diary is enabled and you explicitly turn it on, Whichear stores the consent-record version and time plus the episode facts you enter: time, body position, side, duration, selected accompanying symptoms and free-text notes. These entries are sensitive health data.
- Optional aggregate product counters. Product analytics is disabled by
default. If it is separately approved and enabled, Whichear stores only the
UTC date, one of two allowlisted events (
home_vieworregistration_completed) and an aggregate count. The counter has no IP address, user agent, cookie, session/account identifier, URL, referrer, locale, questionnaire interaction or diary activity attached to it.
Whichear does not use third-party analytics, advertising or cross-site tracking.
Why we store it
Account and session data provide passwordless authentication, first-login account creation and account management. Security records protect the service from abuse. Optional diary data provides the factual history the user asks Whichear to keep and export. If separately enabled, aggregate counters measure only visits to the home page and completed registrations so the operator can assess whether the basic public service works.
The legal basis for each purpose, and the separate Article 9 condition required where GDPR applies to health data, have not yet been approved. The diary must remain disabled in affected markets until that review is complete.
How long we keep it
- Sessions expire 30 days after they are created.
- Email-verification links expire after 24 hours; password-reset links expire after one hour. Expired or consumed token records cannot be used again.
- Account and optional diary records remain in the live database until the user deletes the diary or account.
- Security-event and expired-record deletion periods still require approval before launch; the application must not claim a period that is not enforced.
- Each successful analytics-counter write and an independent daily retention task delete aggregate rows older than the rolling 400-day window, including while analytics is disabled. Analytics must remain disabled until this period and its legal basis have been approved for the launch market.
- Local database backups are retained for 14 days. If encrypted off-server backups are configured, the current schedule keeps 14 daily and eight weekly recovery points.
Deleting an account removes its account, sessions, tokens, linked security events, diary consent and episodes from the live database. Existing backup copies age out under the backup retention schedule; they are not edited in place. Deletion cannot be undone through the application.
Who else sees your data
- Resend, when production email is enabled, receives the destination email address and verification or reset message needed for delivery.
- Our hosting provider runs the servers and database.
Processor identities, locations, contracts and any international-transfer safeguards must be confirmed in the reviewed notice before launch. Whichear does not sell personal data.
Cookies
Whichear sets an HTTP-only session cookie after sign-in and, when the language switcher is used, a cookie remembering that choice. It currently sets no analytics or advertising cookies. The optional aggregate counter request explicitly omits browser credentials and the referrer and also honours Do Not Track and Global Privacy Control signals.
Your rights
The account screen provides a JSON export and account deletion when the account lifecycle feature is enabled. Depending on applicable law, additional rights may include access, correction, erasure, restriction, objection, portability, withdrawal of consent and a complaint to a supervisory authority. The reviewed notice must identify which rights and authority apply. Requests can be sent to privacy@whichear.app.
Changes
When this draft changes, its version and date will be updated. A reviewed, effective notice and an appropriate change-notification process are required before launch.