Skip to content
TAKT

Legal

Privacy Policy

Version: · Applies to the app “Takt – Zyklus & Periode” and to the website taktcycle.com

For users in Ireland, this English version is the legally authoritative one. For Germany and Austria, the German version (Datenschutzerklärung) is authoritative — there this English text is a translation to read along, and where the two versions differ, the German text governs. For users in the United States there is a separate document, and there English is the authoritative version: Consumer Health Data Privacy Policy.

The essentials in five lines

  • There is no account and no registration.
  • The app does not know who you are.
  • The encryption is performed by the operating system with a key that does not leave the device and to which we have no access.
  • No server, no backend, no cloud of ours.
  • No disclosure to third parties — neither sold nor traded nor “shared in anonymised form”.

You do not have to take our word for it. Put your device into aeroplane mode. Takt carries on unchanged — entering, calculating, analysing, the doctor's report, all of it. Only buying and restoring the subscription need a connection, because they run through the App Store or Google Play. Whatever works fully without a network needs no server — and Takt sends nothing.

The full text below is the authoritative one; these five lines are a selection from it and do not replace it.

1. Who is responsible for this privacy policy

TRAJA Projects
Owner: Bao Anh Tran
Sulzbacher Straße 48
90489 Nürnberg
Germany

E-mail: traja.projects@gmail.com

We have not appointed a data protection officer. The conditions of Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) are not met: we do not employ at least 20 people on automated processing of personal data, and our core activity consists neither of large-scale monitoring nor of large-scale processing of special categories of data — because we do not process our users’ health data at all (see section 2).

2. The app: why your cycle data does not exist as far as we are concerned

This is the heart of this policy, and it calls for a justification rather than an assertion.

2.1 What Takt stores on your device

Takt stores exactly the information that you enter yourself or import from a source you have released. A daily entry can contain:

Data Takt stores on your device
ItemValues
Basal body temperature35.0–40.0 °C
Bleedingnone · spotting · light · medium · heavy
Cervical mucusdry · creamy · watery · stretchy
Cervixthree-step (optional, off by default)
Resting pulse40–160 bpm (optional, off by default)
Intercoursea single yes for the day (optional, off by default)
Symptomsmultiple choice from 15 predefined symptoms
Daily levelmild · medium · severe — only for the two symptoms hot flushes and night sweats, and voluntary there too
Notefree text that you determine yourself

The daily level is the only item that is not available for every symptom: hot flushes and night sweats often accompany women for years, and a bare yes says nothing after a few months. Anyone who does not set the level has still recorded the symptom completely — it is an addition to the yes, not a second mandatory field. Takt forms no score from it and applies no threshold; it stays the value you entered.

Additionally, once and voluntarily: your year of birth — the year only, not a full date. Takt needs it for a single purpose: the clinical normal range for cycle variation is age-dependent, and without your age the cycle report applies the laxer threshold. If you do not provide it, Takt shows the axis without an assessment — the report becomes less precise, not wrong. The question does not meet you at first launch but only where the doctor’s report is put together, that is, where the value actually makes a difference; leaving it unanswered is a full answer. You can add or remove the year of birth at any time in the cycle settings.

In addition there are your settings (which signs you want to record, your cycle defaults, your notifications, the language of the interface, whether the app lock is active) and the results calculated from them.

2.1a Your life path — events you set yourself

Alongside your cycles you can record what was happening in your life: pill or ring · IUD · pregnancy · breastfeeding · illness · medication · surgery · therapy · diet or weight · sport · relationship · job · moved · stress · good time · holiday — or something else in your own words. Each event has a day or a period, how sure you are of the date, an optional note and your own reading of it ("rather good" or "rather hard"). For a pregnancy you can record how it ended — with a birth, or earlier.

Takt does not distinguish between a miscarriage and a termination, and it stores no such distinction anywhere. The events feed into no calculation: the cycle engine does not read them, and Takt never names a reason. What the life path shows is your own cycles before and since — middle value, range and count, nothing more.

2.1b Your doctor section — what you take to the appointment

Appointments with date, time and the name of the practice you type in, your reason in one sentence, your topics for the conversation, a note about the visit and items you pay for yourself (service and amount). Plus a note for your doctor, if you want to pass it on in the doctor's report.

Only two things from here go into the doctor's report: your note and the events you choose for it yourself — under Takt's own term, with the date only if you want it. Appointments, practice name, your visit note and the cost items stay in the app.

Free text stays free text. In the note, the topics, the reason and the visit note you write whatever you like — including diagnoses, medications or treatments. Takt does not analyse these fields, does not link them to anything and does not evaluate them.

No field is mandatory. Every field left empty stays empty — Takt fills nothing in and estimates nothing into place. You can hide optional signs permanently. What you do not enter does not exist.

Takt deliberately does not ask for: your name, your e-mail address, your full date of birth, your location, your contacts, your telephone number, your device ID or an advertising identifier. There is no account and no registration. The app does not know who you are.

2.2 Where this data is stored

All entries are held in a single encrypted data block in your operating system’s key store — the iOS Keychain on iPhones, the Android Keystore on Android devices. The encryption is performed by the operating system with a key that does not leave the device and to which we have no access.

Outside this block there is exactly one thing — and only if you create it yourself: whatever a Takt widget has to draw on your home screen. A widget cannot look inside the encrypted block; what it displays has to sit readable next to it. How much that is, you decide twice — when you place it (ring only, or ring with text) and at any time in the app’s More section, under the app group, at the widget entry (More → App → Widget). On the quietest setting what sits there is a ring without a date, exactly as every fresh installation shows it. None of it is transmitted anywhere, and deleting all data removes it too. If you place no widget, this store does not come into existence.

Takt removes itself from device backups. Without this step an operating system would include the data block in the backup of your Apple or Google account — not to us, but nonetheless to a second location. Takt counteracts this in four ways at once:

So that this state cannot be lost unnoticed, an automated test checks it on every change to the program: if one of the four routes falls away, the test fails before a new version comes into being.

What this means for you, together with its downside: your entries are on this device. A device backup therefore also does not carry them to a new device — when you switch, you take your history with you via the backup file that Takt creates for you (see section 4). That file lies where you put it and is subject to your decision.

Two protective mechanisms are built in:

2.3 What Takt does not do

We list this individually, because the absence of these things is the product:

2.4 The legal classification: who is the controller — and what follows from that?

This question is the actual point, and we answer it openly, because the answer explains why this policy is so short where your health data is concerned.

Our classification: we are a controller within the meaning of the GDPR — and precisely for that reason we can show you how little that means at Takt.

We could make it easier for ourselves. There would be the argument that a maker of purely on-device software is not a controller at all, because it never sees the data. We do not run that argument, for one simple reason: it does not stand up to scrutiny.

The test asks about decision-making power, not about access. Under Art. 4(7) GDPR, the controller is whoever determines the purposes and means of the processing. That is exactly what we do: we determine which fields exist, how the calculation works, what is stored for how long and what happens on deletion. You decide whether you enter something — not for what purpose or how it is processed. The fact that the data never leaves your device changes nothing about this: the State Commissioner for Data Protection of Baden-Württemberg expressly answers the question whether a controller must have access to the data with no — what matters is "a determining influence on the purpose and the (essential) means", "even if they never actually have, or will have, access to the data".

Why we do not play this down. A controllership that is argued away is worthless in a dispute — and it would sit at odds with what we otherwise claim. We would rather accept it and show what it actually has to work with:

Controller obligations and what they amount to at Takt
Controller’s obligationWhat it looks like at Takt
Disclose recipientsThere are none. No server, no processor, no analytics tool.
Third-country transferDoes not take place — the data does not leave your device.
Provide access to dataYou already have it in full: in the app and as an export.
ErasureYou do it yourself and immediately. We could not, even if we wanted to.
Report a data breachA break-in at our end cannot reach your cycle data. None is held there.
Keep a record of processing activitiesWe do. It is unusually short — that is precisely the point.

What follows from this is not a weakness but the proof: most of a controller’s obligations run into the void with us, because there is nothing for them to act upon. Not because we have evaded them, but because the app is built this way. A provider with a server would have to explain to you at this point whom it has engaged and how long it stores things. We have to explain to you that the question has no subject matter here.

What applies to you is a separate question. That you record your own data for yourself is a purely personal activity (Art. 2(2)(c) GDPR) — you do not thereby become a controller yourself. That protects you and says nothing about how we are to be classified. Two different questions that are often conflated.

And frankly: no court has yet decided a case about an app where nobody but the user ever has access. We have chosen the more cautious position, not the one more comfortable for us.

Why this policy exists at all, then. For three reasons. First, the classification above applies only to the app: for our website, for support by e-mail and for purchase through the stores things look different, and we describe those cases in full below. Second, both stores require every health app to have a publicly accessible privacy policy, regardless of architecture. And third — the actual reason — you should be able to check what we claim instead of having to believe it. A privacy policy that nobody understands protects nobody.

2.5 Your consent at first launch — what it is and what it is not

When setting Takt up we expressly ask you to consent to the recording of health data in the app. We are honest about what this consent achieves:

This consent is our legal basis. Cycle data is health data and therefore a special category of personal data (Art. 9(1) GDPR); processing it is prohibited in principle unless one of the exceptions applies. We rely on your explicit consent under Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. That is not a safety net and not a precaution, but the operative ground — consistent with our classification in section 2.4.

At the same time it achieves two things: it documents your conscious decision, and it satisfies what both stores require of apps that record health data.

Consent is voluntary and is not hidden in the small print: it is a separate step during setup, in plain language, with its own act of agreement. You can withdraw it at any time in the app, in the More section under the legal group — labelled “Manage consent”. Withdrawal takes effect for the future; the lawfulness of the recording that took place up to that point remains unaffected. Your already stored entries remain unchanged on your device after a withdrawal until you delete them yourself or remove the app — we cannot touch them.

3. Apple Health and Health Connect: Takt works separately from them

Takt stays completely separate from Apple Health and Health Connect. No system permission, no permission dialog, no ongoing access, no import. The app reads nothing there, and it never writes anything there.

A legal basis is moot here, because there is no processing. Where nothing is collected, there is nothing left to consent to.

§ 25 TDDDG does not apply here, and the reason has become simpler: the provision concerns an app’s access to your device. Takt accesses no health store. Nor does it apply to Takt’s own storage of your entries: that is the core service itself and therefore “strictly necessary” (§ 25(2) no. 2 TDDDG).

4. Export, backup, doctor’s report: the only way out — and you are the one who takes it

Takt can release your data for you:

These files are generated entirely on your device. Nothing is sent to us — not even the doctor’s report.

As soon as you share the file, however, it leaves your device. Takt hands it over to your operating system’s share function for that purpose. What happens after that is determined by you alone through your choice of destination: sending by e-mail goes via your e-mail provider, storing in a cloud then sits with that cloud provider, sending by messenger with that messenger. Those destinations’ privacy terms apply, not ours — we are not involved and learn nothing about it.

Our advice, and we mean it: a cycle export is a health document. Treat it like a doctor’s letter. For the way to your doctor, the PDF on your own device or a printout is the safest form; an unencrypted e-mail is not.

5. Notifications, widgets, alerts

6. Purchase and subscription through the stores

Takt has no payment system of its own and no account. The purchase of the subscription runs exclusively through the Apple App Store or Google Play.

What we are not concealing here: Apple and Google know that you have downloaded and bought Takt — that is the one data trail an app without a server also produces, and we cannot take it away from you. It says nothing about your cycle, because no store reaches that far. But it exists, it lies outside our influence, and for a user with a high need for protection it is the remaining gap. We would rather name it than pretend it does not exist.

7. The website taktcycle.com

The classification in section 2.4 does not apply to the website — here we are the controller. It nevertheless stays manageable.

7.1 What arises when you open the page

Opening the website produces a few technically necessary details — some your browser sends along, the rest arise as the page is delivered:

page accessed · date and time of access · volume of data transferred · message about successful retrieval · browser type and version · operating system · referring page (referrer) · your IP address

Without your IP address, no server would know where to send the answer. That is not a decision of ours, it is how the internet works.

No access log is created from this. On the zone our host delivers this site from, logging is switched off. So no file is kept that records your visit with IP address, time and page accessed — we receive no such file, we store none, and we evaluate none. Whether the switch is still off is read again automatically every time the site is updated.

7.2 Hosting

The website is hosted by BunnyWay, informacijske storitve d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia. The host processes the data named above on our behalf; a data processing agreement under Art. 28 GDPR is in place. The servers are located in the EU/EEA. No transfer to third countries outside the EU/EEA takes place.

7.3 What the website does not do

7.4 The feedback form on /en/contact

There is a form on /en/contact for telling us what you notice about the app. It has no field for your name, none for your e-mail address and none for anything out of your cycle — not because we delete those details later, but because we never ask for them in the first place.

What you send. You pick three answers from fixed lists: what you noticed, where in the app it happened, and what it was about. You may add a message — optional, at most 2,000 characters. The form also contains a field that is invisible to people and catches automated submissions; its contents are only checked and are never stored.

What is stored out of that. The three answers you picked, your message if you wrote one, and the day you sent it. We write nothing more into the entry: no time of day, no running number. Instead of a number, each entry is given a random name.

The storage underneath does record a time, though, and we can read it. Here we separate two things that are easily conflated: the entry, and the storage it sits in. The entry carries no time of day — the storage does. Of its own accord it notes, for every file, when that file was created, accurate to the millisecond. Alongside the time, that also leaves the order in which a day’s feedback came in; the random name on its own does not prevent it. And this record is available to us: we read it with the same access key we use to fetch the feedback itself. Presenting it as a purely technical matter of our provider’s would therefore not be honest.

Why we do not simply switch it off. The storage has no setting for that. Overwriting a file afterwards would not remove the record but replace it with a different point in time; bundling entries into one file per day would merely move the same thing up a level. What does limit it effectively is deletion: the record goes when the entry goes, and we delete an entry once it has been evaluated (see Storage period below). Until then it holds that we can see when you sent this form — and with it, roughly, when you were occupied with the app. That is precisely the link we wanted to avoid; at the storage layer we did not manage it, and we would rather write that down than leave it unsaid.

What is never read. Your IP address, your browser identification and the referring page are not even read out when you submit — they are simply not available to the receiving end. The distinction matters to us: “we do not store it” is a promise about how we handle a detail, whereas “we do not collect it” means the detail does not exist on our side at all. The only thing checked on submission is whether it came from our own site, and that value is our own domain name; it says nothing about you.

Where the feedback is kept. In separate storage of its own in Germany, apart from the rest of the website. That storage cannot be retrieved over the network — there is no address at which anyone could call the entries up; we retrieve them with the access key. It is operated by the same processor as the hosting in 7.2 and under the same Art. 28 GDPR data processing agreement.

The upper limit counts entries, not people. We accept at most 500 pieces of feedback per day. What is counted is how many entries already lie there that day — not how often somebody has pressed send. There is expressly no counter per sender and none per IP address.

Taken on its own, a stored entry cannot be attributed to anybody — three picked values and a date say nothing about you. The optional message can undo that, because you can write whatever you like into it, and we store it exactly as you wrote it. Please do not: give us no name, no address and nothing out of your cycle. Describe what you noticed, not yourself.

We cannot answer you. There is no account and no address an answer could go to — that is not carelessness but the consequence of our not knowing who you are. If you need an answer, write us an e-mail instead (section 8).

The transmission itself is not anonymous. As with opening any page, submitting the form carries your IP address to our host — without it the request would arrive nowhere. What arises in the process, and why no access log comes of it, is described in 7.1.

7a. Takt on social networks

Takt has profiles on Instagram, TikTok, YouTube, X, Reddit, and Pinterest, all under taktcycle. The app and this website do not embed any of these networks. You reach a profile only if you open the platform yourself.

What we process there. We read and reply to what you write to us publicly: comments under our posts and mentions of our profile, together with your public profile name. The basis is our legitimate interest in talking to the people who reach out to us publicly (Art. 6(1)(f) GDPR). If you write something about your health in a public comment, you have made it public yourself (Art. 9(2)(e) GDPR). We may hide or delete comments that reveal more about you or others than belongs in that place. For anything that concerns you personally, the best way to reach us is by e-mail (section 8). On Instagram, our inbox for direct messages is closed.

What we see there. On Instagram we run a personal account with no analytics feature. If you vote in one of our story polls, Instagram shows us your profile name and your answer. We only count how the poll turns out overall. Other platforms show us aggregated numbers, for example how often a post was viewed. We cannot identify individual people from that.

What the platform does on its own is its own decision. When a profile is opened, the platform collects its own data, for example about your device, your usage behaviour, and for advertising. We have no influence over that. The platforms also process data in the United States and other countries outside the EU. How, is set out in their privacy policies: Instagram · TikTok · YouTube · X · Reddit · Pinterest

You can assert your rights (section 9) against us. For what the platform itself processes, you are best off turning to it directly.

8. Contact and support

If you write us an e-mail, we process your e-mail address and everything you tell us. Here we are the controller.

Important, and please take it seriously: do not send us health data unless it is unavoidable. We do not need it for a support enquiry. Describe the problem, not your cycle. If you should want to send us an export for troubleshooting after all, we will ask expressly beforehand and delete the file immediately after the matter is settled.

9. Your rights

Under the GDPR you have the following rights:

Your rights under the GDPR and the corresponding articles
RightArticle
Access to the data stored about youArt. 15
Rectification of inaccurate dataArt. 16
ErasureArt. 17
Restriction of processingArt. 18
Data portabilityArt. 20
Objection to processing based on legitimate interestsArt. 21
Withdrawal of consent given, with effect for the futureArt. 7(3)

For these, contact the address in section 1.

The honest note that goes with this: as regards your cycle data, these rights run against us into the void — not because we refuse them, but because we do not have the data. Information from us about your entries would be empty information. You exercise these rights in Takt itself, directly and without an application to anyone:

And the warning that belongs with it: because there is no cloud, the data block on your device is the only copy of your history. If you delete the app, it is gone — irretrievably for us too, because we never had a copy. Make a backup first if your data means something to you.

Right to lodge a complaint: you can lodge a complaint with a data protection supervisory authority at any time, Art. 77 GDPR — in particular in the member state of your residence, your place of work or the alleged infringement. The authority competent for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Postfach 1349, 91504 Ansbach, Germany.

10. Disclosure, third countries, automated decisions

11. Age

Takt is aimed at people aged 13 and over. You can voluntarily provide your year of birth so that the cycle report applies the age-appropriate normal range. Like everything else, this information stays on your device — we do not receive it and cannot check it. Age verification therefore does not take place and is technically impossible as well. We recommend that younger users discuss using the app with a parent or guardian — not out of legal caution, but because the subject deserves it.

12. Changes to this policy

We adapt this policy when the app or the legal position changes. The version published on this page is the authoritative one; the date at the top shows its status. If something material changes about the way your data is handled, we will point it out in the app — not quietly on a subpage.


For completeness: Takt is not a medical device and does not replace medical advice. What Takt is and what it is not is set out in the Terms of Use, section 2.