Legal
Privacy Policy
Version: · Applies to the app “Takt – Zyklus & Periode” and to the website taktcycle.com
For users in Ireland, this English version is the legally authoritative one. For Germany and Austria, the German version (Datenschutzerklärung) is authoritative — there this English text is a translation to read along, and where the two versions differ, the German text governs. For users in the United States there is a separate document, and there English is the authoritative version: Consumer Health Data Privacy Policy.
The essentials in five lines
- There is no account and no registration.
- The app does not know who you are.
- The encryption is performed by the operating system with a key that does not leave the device and to which we have no access.
- No server, no backend, no cloud of ours.
- No disclosure to third parties — neither sold nor traded nor “shared in anonymised form”.
You do not have to take our word for it. Put your device into aeroplane mode. Takt carries on unchanged — entering, calculating, analysing, the doctor's report, all of it. Only buying and restoring the subscription need a connection, because they run through the App Store or Google Play. Whatever works fully without a network needs no server — and Takt sends nothing.
The full text below is the authoritative one; these five lines are a selection from it and do not replace it.
1. Who is responsible for this privacy policy
TRAJA Projects
Owner: Bao Anh Tran
Sulzbacher Straße 48
90489 Nürnberg
Germany
E-mail: traja.projects@gmail.com
We have not appointed a data protection officer. The conditions of Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) are not met: we do not employ at least 20 people on automated processing of personal data, and our core activity consists neither of large-scale monitoring nor of large-scale processing of special categories of data — because we do not process our users’ health data at all (see section 2).
2. The app: why your cycle data does not exist as far as we are concerned
This is the heart of this policy, and it calls for a justification rather than an assertion.
2.1 What Takt stores on your device
Takt stores exactly the information that you enter yourself or import from a source you have released. A daily entry can contain:
| Item | Values |
|---|---|
| Basal body temperature | 35.0–40.0 °C |
| Bleeding | none · spotting · light · medium · heavy |
| Cervical mucus | dry · creamy · watery · stretchy |
| Cervix | three-step (optional, off by default) |
| Resting pulse | 40–160 bpm (optional, off by default) |
| Intercourse | a single yes for the day (optional, off by default) |
| Symptoms | multiple choice from 15 predefined symptoms |
| Daily level | mild · medium · severe — only for the two symptoms hot flushes and night sweats, and voluntary there too |
| Note | free text that you determine yourself |
The daily level is the only item that is not available for every symptom: hot flushes and night sweats often accompany women for years, and a bare yes says nothing after a few months. Anyone who does not set the level has still recorded the symptom completely — it is an addition to the yes, not a second mandatory field. Takt forms no score from it and applies no threshold; it stays the value you entered.
Additionally, once and voluntarily: your year of birth — the year only, not a full date. Takt needs it for a single purpose: the clinical normal range for cycle variation is age-dependent, and without your age the cycle report applies the laxer threshold. If you do not provide it, Takt shows the axis without an assessment — the report becomes less precise, not wrong. The question does not meet you at first launch but only where the doctor’s report is put together, that is, where the value actually makes a difference; leaving it unanswered is a full answer. You can add or remove the year of birth at any time in the cycle settings.
In addition there are your settings (which signs you want to record, your cycle defaults, your notifications, the language of the interface, whether the app lock is active) and the results calculated from them.
2.1a Your life path — events you set yourself
Alongside your cycles you can record what was happening in your life: pill or ring · IUD · pregnancy · breastfeeding · illness · medication · surgery · therapy · diet or weight · sport · relationship · job · moved · stress · good time · holiday — or something else in your own words. Each event has a day or a period, how sure you are of the date, an optional note and your own reading of it ("rather good" or "rather hard"). For a pregnancy you can record how it ended — with a birth, or earlier.
Takt does not distinguish between a miscarriage and a termination, and it stores no such distinction anywhere. The events feed into no calculation: the cycle engine does not read them, and Takt never names a reason. What the life path shows is your own cycles before and since — middle value, range and count, nothing more.
2.1b Your doctor section — what you take to the appointment
Appointments with date, time and the name of the practice you type in, your reason in one sentence, your topics for the conversation, a note about the visit and items you pay for yourself (service and amount). Plus a note for your doctor, if you want to pass it on in the doctor's report.
Only two things from here go into the doctor's report: your note and the events you choose for it yourself — under Takt's own term, with the date only if you want it. Appointments, practice name, your visit note and the cost items stay in the app.
Free text stays free text. In the note, the topics, the reason and the visit note you write whatever you like — including diagnoses, medications or treatments. Takt does not analyse these fields, does not link them to anything and does not evaluate them.
No field is mandatory. Every field left empty stays empty — Takt fills nothing in and estimates nothing into place. You can hide optional signs permanently. What you do not enter does not exist.
Takt deliberately does not ask for: your name, your e-mail address, your full date of birth, your location, your contacts, your telephone number, your device ID or an advertising identifier. There is no account and no registration. The app does not know who you are.
2.2 Where this data is stored
All entries are held in a single encrypted data block in your operating system’s key store — the iOS Keychain on iPhones, the Android Keystore on Android devices. The encryption is performed by the operating system with a key that does not leave the device and to which we have no access.
Outside this block there is exactly one thing — and only if you create it yourself: whatever a Takt widget has to draw on your home screen. A widget cannot look inside the encrypted block; what it displays has to sit readable next to it. How much that is, you decide twice — when you place it (ring only, or ring with text) and at any time in the app’s More section, under the app group, at the widget entry (More → App → Widget). On the quietest setting what sits there is a ring without a date, exactly as every fresh installation shows it. None of it is transmitted anywhere, and deleting all data removes it too. If you place no widget, this store does not come into existence.
Takt removes itself from device backups. Without this step an operating system would include the data block in the backup of your Apple or Google account — not to us, but nonetheless to a second location. Takt counteracts this in four ways at once:
- iOS: the entry in the key store is tied to this one device; even from a backup it cannot be restored on any other device.
- iOS: in addition, Takt’s files are excluded from backup at file level.
- Android: the app is excluded from device backup.
- Android: a separate rules file additionally excludes the direct device-to-device transfer, which the first setting no longer covers on its own on newer systems.
So that this state cannot be lost unnoticed, an automated test checks it on every change to the program: if one of the four routes falls away, the test fails before a new version comes into being.
What this means for you, together with its downside: your entries are on this device. A device backup therefore also does not carry them to a new device — when you switch, you take your history with you via the backup file that Takt creates for you (see section 4). That file lies where you put it and is subject to your decision.
Two protective mechanisms are built in:
- Protection mode: if Takt cannot read the stored data block at launch, the app locks all writing and does not overwrite the existing data. Better no input than data loss.
- App lock (optional, off by default): Face ID, Touch ID, other biometrics or
your device code. The check is performed by the operating system; Takt learns only “successful”
or “not successful” and stores no biometric features itself. On Android,
FLAG_SECUREadditionally prevents a preview in the app switcher.
2.3 What Takt does not do
We list this individually, because the absence of these things is the product:
- No server, no backend, no cloud of ours. There is no place at our end to which data could flow.
- No account, no login, no synchronisation between devices.
- No analytics or statistics tools. No Google Analytics, no Firebase, no Matomo, no counting of our own.
- No crash or error reporting service. No Crashlytics, no Sentry. The Play Console still shows us how often the app crashes or stops responding, along with a technical error report — from devices whose users have agreed to share usage and diagnostics data with Google. What you have entered is not in there.
- No advertising, no advertising components, no advertising ID, no cross-app tracking.
- No third-party payment or subscription providers (no RevenueCat, no Adapty). Subscription management runs exclusively through the stores’ interfaces.
- No social networks, no embedded content, no fonts from third-party servers. The fonts used are shipped with the app.
- No disclosure to third parties — neither sold nor traded nor “shared in anonymised form”.
2.4 The legal classification: who is the controller — and what follows from that?
This question is the actual point, and we answer it openly, because the answer explains why this policy is so short where your health data is concerned.
Our classification: we are a controller within the meaning of the GDPR — and precisely for that reason we can show you how little that means at Takt.
We could make it easier for ourselves. There would be the argument that a maker of purely on-device software is not a controller at all, because it never sees the data. We do not run that argument, for one simple reason: it does not stand up to scrutiny.
The test asks about decision-making power, not about access. Under Art. 4(7) GDPR, the controller is whoever determines the purposes and means of the processing. That is exactly what we do: we determine which fields exist, how the calculation works, what is stored for how long and what happens on deletion. You decide whether you enter something — not for what purpose or how it is processed. The fact that the data never leaves your device changes nothing about this: the State Commissioner for Data Protection of Baden-Württemberg expressly answers the question whether a controller must have access to the data with no — what matters is "a determining influence on the purpose and the (essential) means", "even if they never actually have, or will have, access to the data".
Why we do not play this down. A controllership that is argued away is worthless in a dispute — and it would sit at odds with what we otherwise claim. We would rather accept it and show what it actually has to work with:
| Controller’s obligation | What it looks like at Takt |
|---|---|
| Disclose recipients | There are none. No server, no processor, no analytics tool. |
| Third-country transfer | Does not take place — the data does not leave your device. |
| Provide access to data | You already have it in full: in the app and as an export. |
| Erasure | You do it yourself and immediately. We could not, even if we wanted to. |
| Report a data breach | A break-in at our end cannot reach your cycle data. None is held there. |
| Keep a record of processing activities | We do. It is unusually short — that is precisely the point. |
What follows from this is not a weakness but the proof: most of a controller’s obligations run into the void with us, because there is nothing for them to act upon. Not because we have evaded them, but because the app is built this way. A provider with a server would have to explain to you at this point whom it has engaged and how long it stores things. We have to explain to you that the question has no subject matter here.
What applies to you is a separate question. That you record your own data for yourself is a purely personal activity (Art. 2(2)(c) GDPR) — you do not thereby become a controller yourself. That protects you and says nothing about how we are to be classified. Two different questions that are often conflated.
And frankly: no court has yet decided a case about an app where nobody but the user ever has access. We have chosen the more cautious position, not the one more comfortable for us.
Why this policy exists at all, then. For three reasons. First, the classification above applies only to the app: for our website, for support by e-mail and for purchase through the stores things look different, and we describe those cases in full below. Second, both stores require every health app to have a publicly accessible privacy policy, regardless of architecture. And third — the actual reason — you should be able to check what we claim instead of having to believe it. A privacy policy that nobody understands protects nobody.
2.5 Your consent at first launch — what it is and what it is not
When setting Takt up we expressly ask you to consent to the recording of health data in the app. We are honest about what this consent achieves:
This consent is our legal basis. Cycle data is health data and therefore a special category of personal data (Art. 9(1) GDPR); processing it is prohibited in principle unless one of the exceptions applies. We rely on your explicit consent under Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. That is not a safety net and not a precaution, but the operative ground — consistent with our classification in section 2.4.
At the same time it achieves two things: it documents your conscious decision, and it satisfies what both stores require of apps that record health data.
Consent is voluntary and is not hidden in the small print: it is a separate step during setup, in plain language, with its own act of agreement. You can withdraw it at any time in the app, in the More section under the legal group — labelled “Manage consent”. Withdrawal takes effect for the future; the lawfulness of the recording that took place up to that point remains unaffected. Your already stored entries remain unchanged on your device after a withdrawal until you delete them yourself or remove the app — we cannot touch them.
3. Apple Health and Health Connect: Takt works separately from them
Takt stays completely separate from Apple Health and Health Connect. No system permission, no permission dialog, no ongoing access, no import. The app reads nothing there, and it never writes anything there.
- The file route is closed too. Until 31 Aug 2026 Takt could read an export file from Apple Health; that option has been removed. What sits in Apple Health stays there.
- You enter temperature and resting pulse yourself. Both are signs of their own in Takt, with their own entry and their own display — they come from your hand, not from someone else’s store.
- Moving over from another cycle app remains and is a different thing: there you hand over a file that you provide yourself (in the app: More → Data → Get data). How Takt handles it is in section 2.
A legal basis is moot here, because there is no processing. Where nothing is collected, there is nothing left to consent to.
§ 25 TDDDG does not apply here, and the reason has become simpler: the provision concerns an app’s access to your device. Takt accesses no health store. Nor does it apply to Takt’s own storage of your entries: that is the core service itself and therefore “strictly necessary” (§ 25(2) no. 2 TDDDG).
4. Export, backup, doctor’s report: the only way out — and you are the one who takes it
Takt can release your data for you:
- Complete backup as a JSON file (lossless, for moving to a new device)
- Table as a CSV file
- Doctor’s report as a PDF (generated entirely on the device, without any outward connection)
These files are generated entirely on your device. Nothing is sent to us — not even the doctor’s report.
As soon as you share the file, however, it leaves your device. Takt hands it over to your operating system’s share function for that purpose. What happens after that is determined by you alone through your choice of destination: sending by e-mail goes via your e-mail provider, storing in a cloud then sits with that cloud provider, sending by messenger with that messenger. Those destinations’ privacy terms apply, not ours — we are not involved and learn nothing about it.
Our advice, and we mean it: a cycle export is a health document. Treat it like a doctor’s letter. For the way to your doctor, the PDF on your own device or a printout is the safest form; an unencrypted e-mail is not.
5. Notifications, widgets, alerts
- Notifications (measurement in the morning, expected period, start of your fertile days) are local alerts. They are scheduled and triggered on your device. There is no push service, no server and no push token — neither from Apple nor from Google nor from us. The texts are deliberately discreet, so that nothing appears on a lock screen that you would not want to see there.
- Home screen widgets (Android and iOS) draw from the store described in section 2.2 — not from the encrypted block, which they cannot look inside. In the “ring only” version they show no text at all. Here too: no transmission.
6. Purchase and subscription through the stores
Takt has no payment system of its own and no account. The purchase of the subscription runs exclusively through the Apple App Store or Google Play.
- Your payment data (card, billing address, purchase history) is processed exclusively by the respective store. We do not see it and do not receive it. Apple and Google are independently responsible for that processing; their privacy terms apply.
- From the stores we receive aggregated, non-personal billing and sales reports (for example: the number of purchases in a period, revenue per country). We cannot identify an individual user from them.
- The check whether your subscription is active happens on your device, using the purchase receipt managed by the operating system. There is no server-side check by us — deliberately not, because that would require an account, and an account is exactly what we do not want.
- Because the subscription is tied to the store account and not to an account with us, the restore-purchases action is your way back into the paid product, for example after changing devices.
What we are not concealing here: Apple and Google know that you have downloaded and bought Takt — that is the one data trail an app without a server also produces, and we cannot take it away from you. It says nothing about your cycle, because no store reaches that far. But it exists, it lies outside our influence, and for a user with a high need for protection it is the remaining gap. We would rather name it than pretend it does not exist.
7. The website taktcycle.com
The classification in section 2.4 does not apply to the website — here we are the controller. It nevertheless stays manageable.
7.1 What arises when you open the page
Opening the website produces a few technically necessary details — some your browser sends along, the rest arise as the page is delivered:
page accessed · date and time of access · volume of data transferred · message about successful retrieval · browser type and version · operating system · referring page (referrer) · your IP address
Without your IP address, no server would know where to send the answer. That is not a decision of ours, it is how the internet works.
No access log is created from this. On the zone our host delivers this site from, logging is switched off. So no file is kept that records your visit with IP address, time and page accessed — we receive no such file, we store none, and we evaluate none. Whether the switch is still off is read again automatically every time the site is updated.
- Purpose: delivering the page to your browser and operating it securely.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the technically faultless and secure operation of the website.
- Storage period: no log is created that could have a storage period. The details are processed for the duration of the request; no file is kept that records them beyond it. This data is not merged with other sources, and it is not evaluated for usage statistics.
7.2 Hosting
The website is hosted by BunnyWay, informacijske storitve d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. The host processes the data named above on our behalf; a data processing agreement under Art. 28 GDPR is in place. The servers are located in the EU/EEA. No transfer to third countries outside the EU/EEA takes place.
7.3 What the website does not do
- No cookies. The website sets no cookies and reads no information from your terminal equipment. That is also why there is no cookie banner here — not because we forgot one, but because without cookies and without tracking nothing requires consent under § 25 TDDDG.
- No analytics tools, no tracking, no counting pixels, no advertising.
- No fonts, scripts or maps from third-party servers. Everything this page loads is with our host or already on your device in any case. Not a single third party is contacted when the page is accessed; your IP address therefore goes to nobody else.
- No JavaScript. The pages are pure HTML and CSS.
- No embedded content from social networks, video platforms or map services.
- No newsletter, no registration, no user account.
7.4 The feedback form on /en/contact
There is a form on /en/contact for telling us what you notice about the app. It has no field for your name, none for your e-mail address and none for anything out of your cycle — not because we delete those details later, but because we never ask for them in the first place.
What you send. You pick three answers from fixed lists: what you noticed, where in the app it happened, and what it was about. You may add a message — optional, at most 2,000 characters. The form also contains a field that is invisible to people and catches automated submissions; its contents are only checked and are never stored.
What is stored out of that. The three answers you picked, your message if you wrote one, and the day you sent it. We write nothing more into the entry: no time of day, no running number. Instead of a number, each entry is given a random name.
The storage underneath does record a time, though, and we can read it. Here we separate two things that are easily conflated: the entry, and the storage it sits in. The entry carries no time of day — the storage does. Of its own accord it notes, for every file, when that file was created, accurate to the millisecond. Alongside the time, that also leaves the order in which a day’s feedback came in; the random name on its own does not prevent it. And this record is available to us: we read it with the same access key we use to fetch the feedback itself. Presenting it as a purely technical matter of our provider’s would therefore not be honest.
Why we do not simply switch it off. The storage has no setting for that. Overwriting a file afterwards would not remove the record but replace it with a different point in time; bundling entries into one file per day would merely move the same thing up a level. What does limit it effectively is deletion: the record goes when the entry goes, and we delete an entry once it has been evaluated (see Storage period below). Until then it holds that we can see when you sent this form — and with it, roughly, when you were occupied with the app. That is precisely the link we wanted to avoid; at the storage layer we did not manage it, and we would rather write that down than leave it unsaid.
What is never read. Your IP address, your browser identification and the referring page are not even read out when you submit — they are simply not available to the receiving end. The distinction matters to us: “we do not store it” is a promise about how we handle a detail, whereas “we do not collect it” means the detail does not exist on our side at all. The only thing checked on submission is whether it came from our own site, and that value is our own domain name; it says nothing about you.
Where the feedback is kept. In separate storage of its own in Germany, apart from the rest of the website. That storage cannot be retrieved over the network — there is no address at which anyone could call the entries up; we retrieve them with the access key. It is operated by the same processor as the hosting in 7.2 and under the same Art. 28 GDPR data processing agreement.
The upper limit counts entries, not people. We accept at most 500 pieces of feedback per day. What is counted is how many entries already lie there that day — not how often somebody has pressed send. There is expressly no counter per sender and none per IP address.
- Purpose: finding faults in the app, rewriting what is unclear, and weighing up what is missing.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is improving the app. Little stands against it: you decide for yourself whether to send anything, and the construction is laid out from the start so that as little as possible about you arises in the process.
- Storage period: we delete an entry once it has been evaluated.
Taken on its own, a stored entry cannot be attributed to anybody — three picked values and a date say nothing about you. The optional message can undo that, because you can write whatever you like into it, and we store it exactly as you wrote it. Please do not: give us no name, no address and nothing out of your cycle. Describe what you noticed, not yourself.
We cannot answer you. There is no account and no address an answer could go to — that is not carelessness but the consequence of our not knowing who you are. If you need an answer, write us an e-mail instead (section 8).
The transmission itself is not anonymous. As with opening any page, submitting the form carries your IP address to our host — without it the request would arrive nowhere. What arises in the process, and why no access log comes of it, is described in 7.1.
7a. Takt on social networks
Takt has profiles on Instagram, TikTok, YouTube, X, Reddit, and Pinterest, all
under taktcycle. The app and this website do not embed any of these networks. You
reach a profile only if you open the platform yourself.
What we process there. We read and reply to what you write to us publicly: comments under our posts and mentions of our profile, together with your public profile name. The basis is our legitimate interest in talking to the people who reach out to us publicly (Art. 6(1)(f) GDPR). If you write something about your health in a public comment, you have made it public yourself (Art. 9(2)(e) GDPR). We may hide or delete comments that reveal more about you or others than belongs in that place. For anything that concerns you personally, the best way to reach us is by e-mail (section 8). On Instagram, our inbox for direct messages is closed.
What we see there. On Instagram we run a personal account with no analytics feature. If you vote in one of our story polls, Instagram shows us your profile name and your answer. We only count how the poll turns out overall. Other platforms show us aggregated numbers, for example how often a post was viewed. We cannot identify individual people from that.
What the platform does on its own is its own decision. When a profile is opened, the platform collects its own data, for example about your device, your usage behaviour, and for advertising. We have no influence over that. The platforms also process data in the United States and other countries outside the EU. How, is set out in their privacy policies: Instagram · TikTok · YouTube · X · Reddit · Pinterest
You can assert your rights (section 9) against us. For what the platform itself processes, you are best off turning to it directly.
8. Contact and support
If you write us an e-mail, we process your e-mail address and everything you tell us. Here we are the controller.
- Purpose: answering your enquiry.
- Legal basis: Art. 6(1)(b) GDPR insofar as your enquiry concerns a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
- Storage period: we delete the correspondence as soon as it is no longer needed and no statutory retention obligations (in particular under commercial and tax law) stand in the way.
- E-mail provider: our mailbox is hosted by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use an ordinary, free Google account for it. That means: there is no data processing agreement under Art. 28 GDPR. For this mailbox Google is not our processor but a controller in its own right — what Google does with your message follows Google's own privacy policy and not our instructions. We are writing that down rather than claiming a contract that does not exist.
Important, and please take it seriously: do not send us health data unless it is unavoidable. We do not need it for a support enquiry. Describe the problem, not your cycle. If you should want to send us an export for troubleshooting after all, we will ask expressly beforehand and delete the file immediately after the matter is settled.
9. Your rights
Under the GDPR you have the following rights:
| Right | Article |
|---|---|
| Access to the data stored about you | Art. 15 |
| Rectification of inaccurate data | Art. 16 |
| Erasure | Art. 17 |
| Restriction of processing | Art. 18 |
| Data portability | Art. 20 |
| Objection to processing based on legitimate interests | Art. 21 |
| Withdrawal of consent given, with effect for the future | Art. 7(3) |
For these, contact the address in section 1.
The honest note that goes with this: as regards your cycle data, these rights run against us into the void — not because we refuse them, but because we do not have the data. Information from us about your entries would be empty information. You exercise these rights in Takt itself, directly and without an application to anyone:
- Access and data portability → in the app’s More section, under the data group, choose the backup entry — labelled “Back up your data”. The JSON export is complete and machine-readable; the CSV table opens in any spreadsheet. That is more than Art. 20 GDPR requires, and it takes seconds rather than a month.
- Rectification → change any entry at any time in the day editor.
- Erasure → delete individual entries in the app, or uninstall the app. With uninstallation the encrypted data block is finally gone.
And the warning that belongs with it: because there is no cloud, the data block on your device is the only copy of your history. If you delete the app, it is gone — irretrievably for us too, because we never had a copy. Make a backup first if your data means something to you.
Right to lodge a complaint: you can lodge a complaint with a data protection supervisory authority at any time, Art. 77 GDPR — in particular in the member state of your residence, your place of work or the alleged infringement. The authority competent for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Postfach 1349, 91504 Ansbach, Germany.
10. Disclosure, third countries, automated decisions
- Disclosure: we do not pass personal data on, do not sell it and do not trade it. There are exactly two places where anything arrives at all: our host — as a processor under Art. 28 GDPR and bound by instructions — and our e-mail provider, if you write to us. The e-mail provider is not a processor; what that means is in section 8.
- Third countries: For the website: No transfer to third countries outside the EU/EEA takes place. We cannot give that assurance for our mailbox — there Google is a controller in its own right, and where Google takes your message is not ours to decide (section 8). Your cycle data is never affected; it does not leave your device.
- Automated decisions in individual cases or profiling under Art. 22 GDPR do not take place. The calculations in Takt run on your device, are rule-based and documented transparently; they produce no legal effect concerning you.
11. Age
Takt is aimed at people aged 13 and over. You can voluntarily provide your year of birth so that the cycle report applies the age-appropriate normal range. Like everything else, this information stays on your device — we do not receive it and cannot check it. Age verification therefore does not take place and is technically impossible as well. We recommend that younger users discuss using the app with a parent or guardian — not out of legal caution, but because the subject deserves it.
12. Changes to this policy
We adapt this policy when the app or the legal position changes. The version published on this page is the authoritative one; the date at the top shows its status. If something material changes about the way your data is handled, we will point it out in the app — not quietly on a subpage.
For completeness: Takt is not a medical device and does not replace medical advice. What Takt is and what it is not is set out in the Terms of Use, section 2.