Privacy Policy

Last updated: 22 August 2026

Emese Care ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect when you use the Emese Care app, why we collect it, how long we keep it, and what rights you have.

We designed Emese Care with privacy as a first principle, not as a legal afterthought. Your health data is sensitive, and we treat it that way.

1. Who we are

Emese Care is a digital behaviour-change platform that helps people leave behind destructive habits. We operate programs including Nekotin (nicotine), as well as programs for social media, alcohol, gambling, medications, and other habits.

Data Controller:
Nekotin Kft.
2072 Zsambek, Nyarfas utca 38., Hungary
Company registration number: 13-09-235037 (Pest County Court of Registration)
Tax number: 32600025-1-13
privacy@emese.care

For anything about your data or this Privacy Policy, write to privacy@emese.care. This address reaches the person responsible for data protection at Nekotin Kft. and is the fastest route for a rights request. General questions can also go to hello@emese.care.

We have not appointed a Data Protection Officer. At our current scale we are not required to, and we reassess that whenever our processing grows.

2. The data we collect

2.1 Account and identity data

When you register, we collect:

Why: To create your account and deliver the service to you.

2.2 Health and behaviour data

To personalise your program, we collect:

Why: This data is the core engine of the app. Without it, we cannot personalise your experience or detect when you might need extra support.

This is special category data under GDPR Article 9. We only process it with your explicit consent, which you give during registration.

2.3 Things you write in the app, privately

Why: To deliver these features to you. Your letters are yours, we cannot read them.

One safety exception applies to free text. Before we store what you type in a feedback or check-in box, an automated check looks for words that signal a crisis, such as an intention to harm yourself. If it matches, the app shows you crisis resources and raises your safety level so we stop showing you experimental content. The text itself is then encrypted. This check runs on our own servers, no human reads your text because of it, and it is never sent to an analytics provider. Legal basis: your vital interests and ours in keeping you safe (Art. 6(1)(d) and Art. 9(2)(c)).

2.4 Things you post where other people can see them

Parts of the app are shared with other users. If you use them, we process:

Please read this before you post. Anything you post in the community is visible to every other user of the app, and posting in a programme about a habit says something about your health. Once you have posted it, that is your choice and not something we can undo for you elsewhere. You can delete your own posts at any time, and deleting your account removes them.

Automated moderation before publication. Every post, reply, shared coping strategy and photo is checked automatically before anyone else can see it. The check uses Google's Gemini API, which means the text or image is sent to Google and analysed there. Google acts as our processor for this, does not use the content to train its models, and returns only a decision to us. If the check refuses your content, it is not published and you are told. A refusal is a moderation decision, not a decision with legal effects about you, and you can ask a human to look at it again (see section 6).

Why: To run a community that is safe for people in recovery, and because the app stores are right to require it. Legal basis: contract performance for showing your content to the people you posted it to (Art. 6(1)(b)) and your explicit consent for the health-related content of what you write (Art. 9(2)(a)), which you give when you accept the health-data consent at registration. Moderation itself rests on our legitimate interest in a safe service and on our obligations as a hosting provider (Art. 6(1)(f) and Art. 6(1)(c)).

2.5 Usage data

Every significant action you take in the app creates a usage event (e.g. completing a lesson, tapping the panic button, checking in daily). We record:

Why: To improve the app and measure what works. We keep raw events for 90 days and then delete them.

2.6 Analytics data

If you consent to analytics, we record usage events such as screen views, lesson interactions, and session information. These events are sent to Google Analytics 4 so we can understand how people use the app at an aggregate level.

How it works technically: Unlike most apps, we do not embed a Google Analytics SDK inside the mobile app. Events travel first from your device to our own backend (hosted in the EU), and only then are they forwarded to Google Analytics via a server-to-server protocol. Your consent is re-checked on our backend before anything is forwarded. If the check fails, the event is dropped.

What we send: A pseudonymous internal user ID (not your email, not your name) plus bounded event metadata. The metadata fields are: screen name, lesson ID, content type, content ID, event type and timing, your current behavioural state (for example pre_quit, acute_withdrawal, stabilizing, maintenance, an inference our system makes about where you are in your change journey), and any A/B experiment assignments you were seeing when the event occurred. We never send your name, email, phone number, or anything you type into the app.

What we send about you as a user:alongside individual events we send a few standing properties of your account, so that aggregate reports can be broken down. These are: your behavioural state, your programme, your language, your country, your currency, your organisation's identifier if you joined through one, and the week you registered. Four numbers are sent as bands, never as exact values: how many days it has been since your quit date, how much XP you have collected, how many check-ins you have completed, and how many triggers you have identified. The bands are deliberately coarse (for example "31-90 days"), but we should say plainly that the days since your quit date and the number of check-ins are still a health inference about you. That is exactly why all of this goes only with your consent, under a pseudonymous identifier, and why you can stop it at any time.

What we never send: Crisis signals, safety escalations, and panic events are explicitly blocked from Google Analytics. These are routed only to a separate internal operations channel under stricter access controls, because GDPR treats them under a different legal basis (vital interests, Art. 6(1)(d)).

Why: To understand how people use the app at an aggregate level and improve the product.
You can withdraw this consent at any time in the app settings. Withdrawing stops all future analytics collection immediately, including on our backend.

2.7 Technical data

2.8 Data from public forms on emese.care and commons.emese.care

When you submit any form on our public websites (signing up, applying for early access, sending us feedback, applying as an employer or research contributor), we record some context about the submission alongside the details you typed. This helps us understand how people find us, fix bugs that only show up on certain devices, and follow up with you properly.

What we record automatically:

What we do with it:Everything in this bundle is used internally to (a) understand which marketing channels work, (b) fix rendering bugs, (c) help our team prioritise real leads over spam, and (d) display the context inside our internal task-tracking tool when a new submission needs follow-up (see section 4). We don't sell it, we don't share it with advertisers, and we don't use it to build a profile or make automated decisions about you.

Legal basis: Most of these fields rely on legitimate interest (Art. 6(1)(f)), running a business needs basic visibility into how its forms get used. The long-lived visitor_id is the exception: it relies on your explicit consent (Art. 6(1)(a)) via the cookie banner and is never set without it. The consent state at the moment you submitted is itself recorded on the form, so we can prove on a per-submission basis which legal basis applied.

Spam protection. Our public forms are protected by Google reCAPTCHA. When a form loads, reCAPTCHA receives your IP address and information about how you interact with the page, and Google uses it to decide whether you are a person or a bot. This happens on the form page whether or not you submit anything. It is covered by Google's own privacy policy and terms. Legal basis: our legitimate interest in not being flooded with fake submissions (Art. 6(1)(f)). We use it only where a form exists, never on ordinary content pages.

Website measurement. Our public websites are hosted by Vercel, which also provides the two measurement tools we use alongside Google Analytics: Vercel Web Analytics (page views and referrers) and Vercel Speed Insights (how fast pages load for real visitors). Both are switched off until you accept analytics in the cookie banner, both receive the page address with any credential removed from it, and neither is used to build a profile of you. Full detail, including every identifier stored on your device, is in our Cookie Policy.

Retention: This metadata lives on the same record as the rest of your form submission. The tracking and device fields are stripped from public-form records after 30 days, leaving only the submission itself and the consent record. When the record is deleted (either with your account, or on request), everything goes with it.

Statistics copy. We also keep a copy of this technical metadata in a separate statistics dataset, together with which form you used and its result, for example a feedback rating or the industry you chose. It holds no name, no email address and no message text. Before it is stored, the identifiers that could tie it to you are re-hashed and the times are rounded to the full hour, so it no longer carries anything that links it to your submission. We keep it indefinitely, on the basis of our legitimate interest in understanding how people find us (Art. 6(1)(f)), and you can object as described in section 6. Most of its rows cannot be tied to you, because their key is derived from a passing identifier in your browser, so a deletion request cannot single those out. One case is an exception, and we will name it: if you submitted the employer calculator, the key of this copy is derived from your email address, so we can find it. That row is deleted along with your deletion request.

2.9 Employer cost calculator

The cost calculator on our employers page is anonymous and stores nothing until you submit the form. If you do submit it, we collect your name, work email and company name, the figures you entered, and the name and work email of up to five colleagues if you choose to add them. We use this to email you the report from balu@emese.care and to follow up about Emese Care, and we record whether that email was opened and its links clicked. Your details are stored in our CRM (ClickUp) and the report is held in Google Cloud, shared only through private, expiring links.

If somebody added you as a colleague, you receive the report in the same email as the person who asked us to send it, and that email says who they were. We keep your name and work address so we know who at that organisation has seen the report. You did not tick our consent box, the person who invited you did, so if you would rather not be on our list, reply to that email or write to privacy@emese.care and we will delete you.

Legal basis: our legitimate interest in offering our service to employers (Art. 6(1)(f)), together with the consent checkbox on the form. No health data is involved. If we send you a personalised version of the report, we also store your name and work email against that link, and delete them 60 days after the link was created, or after you last extended it.

A one-week preview of the app. If you submitted the calculator without adding colleagues, an invite code comes with your report. That is the only condition: we do not look at which address it came from. The code can be redeemed for 30 days, and when you redeem it a real Emese Care account is created in your name, carrying the branding of a demonstration organisation. The preview runs for seven days from the moment you finish registering, after which the app locks. The lock happens inside the app itself, so on an older installation that has not been updated it may keep working.

Two things about this matter, and neither is obvious. First, it is a real health account, so everything you write into it falls under sections 2.2 and 2.3, with the same protection. Second, because we know you as a business prospect, we note the fact of each step on your record in our CRM: that you redeemed the code, that the account was created, that you sent feedback, and that the week has ended. Two details travel with them, and we will name both: your first name as you gave it at registration, and your feedback's star rating as a number. Never the writing:not what you put in the app, not the wording of your feedback, not how far you have got in the programme. After the seventh day we email you to say the preview has ended. If you would rather not hear from us again, reply to it with "unsubscribe", or write to privacy@emese.care.

What happens on day eight: your account is locked, not deleted, so that everything is still there if we later work together. If you would rather it did not remain, write to privacy@emese.care and we will delete it. The lock screen also carries buttons to export your data and to delete your account. Legal basis: providing the preview is a pre-contractual step taken at your request (Art. 6(1)(b)); health data is covered by your explicit consent under section 2.2; the note on the record is our legitimate interest (Art. 6(1)(f)).

The marketing checkbox. The form carries a separate, unticked box asking whether you would like to hear about how Emese Care is developing. This is consent (Art. 6(1)(a)), entirely optional, and it changes nothing described above: you receive the report and the code whether or not you tick it. We record whether you ticked it and when. Your most recent answer always wins, so leaving it unticked later withdraws it. You can unsubscribe at any time: reply to any of our emails with "unsubscribe", or write to privacy@emese.care.

2.10 Business contact records (business-to-business outreach)

If you work at a company we think Emese Care could help, we may hold a record about you before you have ever contacted us: your name, job title, employer, LinkedIn profile and work email, our own notes, any LinkedIn messages between us, and meetings you book with us. We take this from your public LinkedIn profile, and we use Google's Gemini service to estimate public facts about your employer, such as its size.

If we send you a personalised report link, we also record which message you were sent, when the link was last opened, how long the report page was open and across how many separate visits, which version of the page you were shown, and which sections of it you scrolled far enough to read. The reading measurement itself stores nothing on your device; the section and page-depth measurements are ordinary website analytics and run only if you accept analytics cookies. We do not record where inside a section you scrolled, or the position of anything you clicked. None of it scores or ranks you: it marks the record as engaged, and one person reads it to decide what to write next. All of it is held in our CRM (ClickUp) alongside the rest of your record.

How many devices opened it. You can forward the personalised report to your colleagues, and we would like you to. So we count how many different devices opened that one link, and note the number on your record. There are two reasons, and the second one is for you: the first is to see whether the report is travelling inside the company; the second is that the form on the page pre-fills your name and work email only on the first device, so whoever you forward it to does not see your details.

We do this on our server and store nothing on your device. From what your browser sends to every website (your IP address and your browser identifier) we make a one-way, keyed fingerprint that includes the link itself. So the same browser opening two different reports produces two values that cannot be connected: it is not an advertising identifier and cannot become one. It does not identify you; it knows only whether this is the same device, within this one link. It is deleted with the rest of the link, 60 days after the link was created, or after you last extended it.

Legal basis: our legitimate interest in business-to-business outreach (Art. 6(1)(f)). No health data about you is involved. Retention: until you object; a personalised link and everything held against it is deleted 60 days after it was created.

You can object at any time, with no reason given, at privacy@emese.care, and we will stop approaching you. There are two things you can choose between, and the choice is yours:

If you do not say which you would prefer, we close the record and tell you we have done so. Your other rights in section 6 apply in full.

2.11 If you joined through your employer, university or insurer

Some people reach Emese Care through an organisation that pays for it, using an invite code. If that is you, this section is the important one, so it is deliberately blunt.

What your organisation sees about you by name:

Those three facts are the whole list. Not because we picked them out of something larger, but because nothing else reaches an organisation's screen at all.

What it sees as a group, anonymously:

One number is an exception, and we would rather name it than leave it out. On the billing page the organisation sees how many of its members were active in the month, with no minimum applied, because that is what their invoice is calculated from: they pay per active person. In a very small organisation that number can say something on its own. That is why it exists and it is the only reason: there is no service without an invoice, and it still produces no list of names.

What your organisation can never see:

Who is responsible for what.Nekotin Kft. is the controller for your health and app data and decides how it is used. Your organisation is a separate controller for the contact details it holds about you and for its decision to invite you. We will refuse any request from an organisation for data about one of its members as an individual. That refusal is not a courtesy we extend, it is how the product is built: the figures are aggregated before they ever reach the organisation's screen.

If you would rather your employer did not know. Accepting an invite code marks that code as used, so from then on the organisation knows the person behind the invited address joined. Registering with a personal email address does not change that: the code is still theirs. If you would rather they did not know, do not use the code they gave you. Write to hello@emese.careand we will work out how you can take part without going through your employer's invitation.

2.12 If you request access on emese.care

The access form has one field to fill in, your email address. Alongside it we record your answers to the two checkboxes, the language you chose, the result of the spam check, and the form metadata described in section 2.8. (Older versions of the app also carry a second form that asks for your name and a short reason; if you applied through that one we store those too, and you can have them deleted on the same terms.)

What happens next depends on the domain of your address, and there are four paths. A personal address puts you on the contributor waiting list, and we answer within 24 hours. If your employer is already a partner, you either get a code immediately or we tell you to ask your administrator. If you apply from a company address we do not yet know, we send a thank-you email and your address is also recorded as a business lead.

What we tell you in that last case: if at least three people from your company have asked for access, the email says how many. We never give a name. If exactly one colleague besides you has asked, we say so in words rather than as a figure; if you are the first, we mention nothing at all.

The two checkboxes. One required box accepts the terms and confirms you have read this notice; a second, unticked by default, asks whether you would like to hear about how Emese Care is developing. The second is optional, consent (Art. 6(1)(a)), and has no effect on whether you get in. We store both answers with the date, your most recent answer always wins, and you can withdraw at any time by replying to any of our emails with "unsubscribe", or at privacy@emese.care.

Retention, and your rights without an account. The record of your application stays until the process closes, and the consent entry stays so that we can prove what you ticked. The technical metadata from the form is stripped after 30 days, as described in section 2.8. You do not need an account to be deleted or to receive your data: write to privacy@emese.care and we will find your application and every row belonging to it from your address.

2.13 If you ask your workplace

At emese.care/en/ask-your-workplace you can write a letter to your workplace asking them to make Emese Care available. The page asks you to finish one sentence: "I would be glad if Emese Care were available in our organization, because…"

We keep that sentence, and here is how. It is the most direct answer to a question we cannot otherwise ask: why does somebody who does not have Emese Care want it. We store the sentence on its own: no email address beside it, no device data, no visitor identifier, and the time rounded to the full hour. Before storing it we remove email addresses and phone numbers from the text. We keep it for one year and then it is deleted. Honestly: this is pseudonymisation, not perfect anonymity, because a very distinctive sentence and the time it arrived could in principle be compared against other traces. That is exactly why we attach no identifier to it. Legal basis: our legitimate interest in understanding what workplaces need (Art. 6(1)(f)).

Two ways to send the letter, and you choose between them. One opens your own mail program: the letter itself never touches our servers, and we do not learn who you sent it to or whether you sent it at all. We do know that you pressed that button, and your sentence above is saved then too, on its own, as described. The other option is for us to send it for you. The letter then goes out from hello@emese.care, you are copied in, and replies reach both you and us.

If you ask us to send it, this is what we store.Your name, your address, the recipient's name and work address, the subject line, and the form metadata described in section 2.8, for 60 days, so that we can answer what went out in our name and to whom. The letter text sits with them, encrypted. The recipient is additionally added to the business contact records described in section 2.10, and a note goes onto our CRM saying that you asked for the letter, with your name and address. The letter text itself is never copied there. If you are the named recipient, we did not get your details from you but from your colleague (Art. 14): the letter says who asked us, and you can ask to be deleted at privacy@emese.care on the same terms as anybody else.

3. How we use your data

PurposeLegal basis
Delivering and personalising your behaviour-change programContract performance (Art. 6(1)(b))
Inferring your behavioural state and adapting contentContract performance (Art. 6(1)(b))
Safety escalation, detecting high-distress signals and showing crisis resourcesLegitimate interest / vital interests (Art. 6(1)(f) + Art. 9(2)(c))
Personalising content through A/B experimentsExplicit consent (Art. 6(1)(a) + Art. 9(2)(a))
Sending you transactional emails (onboarding, milestones)Contract performance (Art. 6(1)(b))
Showing your community posts to other usersContract performance (Art. 6(1)(b)) + explicit consent (Art. 9(2)(a))
Moderating user content before and after publicationLegitimate interest in a safe community (Art. 6(1)(f)) + legal obligation as a hosting service (Art. 6(1)(c))
Diagnosing crashes and errorsLegitimate interest in a working app (Art. 6(1)(f))
Analytics and product improvementExplicit consent (Art. 6(1)(a))
Business-to-business outreach and the employer calculatorLegitimate interest (Art. 6(1)(f)), assessed in a balancing test you can request
Sending product news to people who asked for itConsent (Art. 6(1)(a))
A one-week preview of the app for people who complete the employer calculatorA pre-contractual step at your request (Art. 6(1)(b)) + explicit consent for health data (Art. 9(2)(a))
Understanding why people want Emese Care at their workplaceLegitimate interest (Art. 6(1)(f))
Keeping a do-not-contact list of people who asked us to stopLegitimate interest (Art. 6(1)(f))
Billing an organisation that pays for seatsContract with that organisation (Art. 6(1)(b)) + legal obligation to keep accounts (Art. 6(1)(c))
Legal compliance and audit recordsLegal obligation (Art. 6(1)(c))

We do not use your data to make fully automated decisions that have legal or similarly significant effects on you.

4. How we share your data

We do not sell your data. We do not share your health data with advertisers. We share data only with the third-party service providers listed below, who process it strictly to deliver the service on our behalf.

ProviderWhat they receivePurposeRegionTransfer mechanism
Google Cloud (Firestore, Cloud Run)All user and health dataHosting and databaseEU (Belgium)Data processed in EU only
Firebase Authentication (Google)Your email address, your password in hashed form, and the identifier Firebase issues for your accountSigning you in and keeping your session validGlobal (Google LLC)EU Standard Contractual Clauses + EU-US Data Privacy Framework
Google (Gemini API)Community posts, replies, shared coping strategies and attached photos, checked before publication. Also company names and public LinkedIn profile addresses for business research (section 2.10). Never your health profile, letters, check-ins or private feedbackAutomated moderation of user content, and business researchUS (Google LLC)EU Standard Contractual Clauses + EU-US Data Privacy Framework
Google Cloud StoragePhotos you attach to community posts, and generated employer report PDFs. Shared only through private links that expireFile storageEU (Belgium)Data processed in EU only
Google Workspace (Gmail)Recipient name and work email on employer report and outreach emails sent from balu@emese.care. For the "send it for me" option in section 2.13, also the named recipient's name, work address and the letter text itself, from hello@emese.care. No app user health dataSending business email, and forwarding the workplace letter you wroteEUEU Standard Contractual Clauses + EU-US Data Privacy Framework
Google CalendarDate, time, title and attendee addresses of meetings booked with us, read automatically. Business contacts only (section 2.10)Recording that a meeting happenedEUEU Standard Contractual Clauses + EU-US Data Privacy Framework
Google reCAPTCHAYour IP address and page interaction data, on pages that carry a formBlocking automated form abuseUS (Google LLC)EU Standard Contractual Clauses + EU-US Data Privacy Framework
VercelWebsite requests, and (only with analytics consent) page views, referrers and page load timings for emese.care and commons.emese.care. No mobile app dataHosting and measurement of the public websitesUS (Vercel Inc.), served from EU edge locationsEU Standard Contractual Clauses
StripeBilling contact and payment details of organisations that pay for Emese Care. Never any data about app users. Card details go directly to Stripe and never reach our serversSubscription billing for partner organisationsEU (Stripe Payments Europe Ltd)EU Standard Contractual Clauses where processing reaches the US
Apple, Google and Microsoft (sign-in providers)If you choose to sign in with one of them, they confirm your identity to us and receive the fact that you signed in to Emese Care. They are told nothing about your programmeOptional social sign-inUSEU Standard Contractual Clauses + EU-US Data Privacy Framework
Google Analytics 4 (via Measurement Protocol, server-to-server from our backend, no SDK on your device)Pseudonymous user ID + bounded event metadata (consent required; crisis events never sent)Product analyticsUS (Google LLC)EU Standard Contractual Clauses + EU-US Data Privacy Framework
BrevoYour email address, your nickname and your language. It carries the transactional emails, the access-process emails (section 2.12) and the news emails sent on your consent. Each send also passes your pseudonymous user id and the content id of the email. This matters, so we spell it out: inside Brevo we keep a separate list per programme, so which list you are on reveals which programme you are working on. That is a health inference, which is why this provider is in the EU and why nothing else about your programme is sent thereTransactional and process emails, and the news email sent on your consentEUData processed in EU only
ClickUpThree separate things. (a) Public-form submissions (employer leads, early-access requests from a company address, commons contributor applications) with the form metadata bundle described in section 2.8. (b) Feedback you send us: your rating, your message, and your reply email if you asked for a reply. If you send it from inside the app, it also carries your pseudonymous user ID and the identifiers of your last few completed lessons, so we can make sense of the report. (c) Business contact records as described in section 2.10, including how many different devices opened your personalised report. (d) If you took the one-week preview after the employer calculator (section 2.9), the fact of each step on your record: that you redeemed the code, that the account was created, that you sent feedback, that the week ended. Never the content of any of them. Never sent: your health profile, your behavioural state, your letters, your check-ins, or anything you post in the community. Note that a feedback message is free text you write yourself, so please do not put anything about your health in it if you would rather it stayed in the EU.Internal task-tracking, so our team can follow up on submissionsUS (ClickUp, Inc.)EU Standard Contractual Clauses

Every provider in this table processes data on our instructions under a Data Processing Agreement, and none of them may use your data for their own purposes. No provider receives your health data in plain, identifiable form beyond what is strictly necessary for the job listed beside their name.

We also share nothing with advertisers, data brokers or insurers, and we never sell your data. There is no advertising anywhere in Emese Care.

We may disclose data if required by law, court order, or to protect the safety of our users or the public.

5. How long we keep your data

Data typeRetention period
Your account and health profileUntil you delete your account
Future self lettersUntil you delete them or delete your account
Community posts, replies and photosUntil you delete them or delete your account
Moderation records (what was refused, what was reported or blocked)12 months, so repeat behaviour can be recognised
Raw usage events90 days
Crash reports90 days
Tracking and device fields on public-form submissions30 days, then stripped from the record
Statistics copy of public-form metadata (section 2.8)Kept indefinitely, with the identifiers that link it to you removed
Marketing attribution on your account (how you found us)90 days, then anonymised
Analytics data (Google Analytics)Up to 24 months (aggregated)
Audit and compliance records7 years (legal obligation)
Deletion records (proof of erasure)7 years (legal obligation)
Personalised employer report links (name, work email, report figures and reading time held against the link)60 days after last use, then deleted automatically
Business contact records (section 2.10)Until you object, or we stop pursuing the relationship. No fixed expiry
A closed business record for somebody who asked us to stop (section 2.10)Until you withdraw it. This is our do-not-contact list, and it stays for exactly that reason
Marketing consent entry (whether you ticked it and when)Until you withdraw it; the fact and time of the withdrawal are kept after that, because we have to be able to prove it too
Access application and its consent entry (section 2.12)Until the process closes; the consent entry stays longer so that it can be proven
Preview account after the employer calculator (section 2.9)Locked after the seventh day, not deleted. Deleted on request at any time
The "I would be glad, because…" sentence from the workplace page (section 2.13)1 year, then deleted automatically
Workplace letters we sent for you (section 2.13)60 days, then deleted automatically

When you delete your account, your personal data is permanently deleted within 30 days. Two things deliberately survive it, and neither is personal data any more, because neither can be traced back to you: the deletion audit record, which is hashed and proves only that an erasure happened, and anonymised, aggregated statistics. We keep those: they are built from many people's data, no line in them points at you, and they are how we know whether the programme works at all. The GDPR does not treat them as personal data, so they fall outside your right to erasure.

Backups. Our database keeps 7 days of point-in-time history and 14 days of daily backups. A deleted account can therefore persist in a backup for up to 14 days, after which it is gone from there too. We hold no backup longer than the 30 days we promise for erasure, which is the reason the backup window is set where it is.

6. Your rights

Under GDPR, you have the following rights:

RightWhat it meansHow to exercise it
AccessSee all the data we hold about youTap "Export my data" in app settings
PortabilityDownload your data in a machine-readable format (JSON)Tap "Export my data" in app settings
ErasureDelete your account and all your data permanently. The one exception is the part of the statistics copy in section 2.8 that we cannot search for you, because it carries no identifier of yours. Any row of it we can find, we deleteTap "Delete my account" in app settings
RectificationCorrect inaccurate dataEdit your profile in app settings
Withdraw consentStop analytics tracking at any timeTap "Manage consent" in app settings
ObjectObject to a specific processing activity, including anything we do on the basis of legitimate interestEmail us at privacy@emese.care
RestrictAsk us to pause processing while a complaint is resolvedEmail us at privacy@emese.care
Human review of a moderation decisionAsk a person to look again at content that automated moderation refused, or at a restriction on your accountEmail us at privacy@emese.care, and see the Terms, section 7

Exercising any of these rights is free, and using them never affects the programme you are on. If you withdraw the health-data consent in section 2.2 we can no longer run the programme, because that data is what the programme is made of, so withdrawing it ends the service. Withdrawing analytics or marketing consent changes nothing about your programme.

We will respond to all requests within 30 days. If a request is complex, we may extend this by a further 60 days and will notify you.

You also have the right to lodge a complaint with your national data protection authority. In Hungary, this is the Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) at naih.hu. For EU users in other countries, contact your local supervisory authority.

7. Security

We take security seriously because we know your data is sensitive.

8. International data transfers

Our database and our servers are in Belgium (EU). Your health profile, your letters, your check-ins and your community content are stored there and are not moved anywhere else for storage.

Four things do leave the EU, and this is the complete list:

Each of these transfers relies on the recipient's EU Standard Contractual Clauses, and for Google additionally on its participation in the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to any one of them at privacy@emese.care.

9. Children's privacy

Emese Care is not intended for anyone under the age of 18. Registration asks your age before anything else and blocks the account outright if you are under 18. We check what you tell us, we cannot check it against a document, so if we become aware by any other route that a person under 18 has an account we delete it and all its data immediately. If you believe a minor has registered, contact us at privacy@emese.care.

10. Medical disclaimer

Emese Care is not a medical service.

The content, tools, and features in Emese Care are for informational and peer support purposes only. Emese Care is not intended to diagnose, treat, cure, or prevent any disease or condition. It is not a substitute for professional medical treatment, therapy, or counselling.

If you are experiencing a medical emergency, call 112 (EU) or your local emergency number immediately.

If you are in crisis:

Always seek the advice of qualified healthcare providers with any questions about a medical condition or treatment.

11. Changes to this policy

We may update this Privacy Policy when our practices change or when the law requires it. When we make significant changes, we will notify you in the app and update the "Last updated" date at the top of this document. We will always ask for your consent again if we start processing your data in a new way that requires it.

Previous versions of this policy are available via the "What changed?" panel at the top of this page.

12. Contact us

For anything about your data, your rights, or this Privacy Policy:

privacy@emese.care

For anything else, including support and complaints: hello@emese.care. Our postal address and company details are in the Imprint.

We aim to respond within 5 working days. For formal data subject rights requests, the legal deadline is 30 days.