Privacy Policy | JawBuddy

Last updated: August 25, 2026

1. Introduction

JawBuddy GmbH operates jawbuddy.com and the JawBuddy mobile application. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR, EU 2016/679).

Data Controller:
JawBuddy GmbH
Spinnereistraße 7 / Halle 14, Aufgang A, 04179 Leipzig, Germany
Email: privacy@jawbuddy.com
Phone: +49 160 92303560

Data Protection Officer:
Chino.io
Email: jawbuddy-dpo@chino.io

2. Scope of This Policy

This policy covers the website jawbuddy.com, the JawBuddy Mobile Application (iOS app for jaw health exercises), and the prevention course 'Progressive Muscle Relaxation for Stress Reduction and Promoting the Ability to Relax' offered in the app under Sec. 20 SGB V (see section 4a).

3. Website Data Collection

Automatic Data Collection

When you visit our website, we automatically collect IP addresses, access timestamps, browser/OS information, and referrer URLs for ensuring website functionality, security, and administration. This data is retained for 7 days under legitimate interests (Art. 6 para. 1 lit. f GDPR).

Email Contact

Inquiries sent via email are stored to process your requests under contract fulfillment (Art. 6 para. 1 lit. b GDPR).

4. JawBuddy Mobile Application Data

Account Data

Required: email address and password. Optional: name, age verification, and language preference. This data is used for authentication and personalization. You can delete your account at any time via Profile → Privacy & Sharing → Delete Account.

Health and Jaw Movement Data

The app collects jaw opening distance, lateral deviation, exercise completion, and progress metrics. The app does NOT collect face images, complete face meshes, biometric identification data, or unrelated facial expressions.

Important: JawBuddy (EU/EEA): Class I medical device under Regulation (EU) 2017/745 for jaw-health self-management. JawBuddy (other regions): lifestyle product, not a medical device. Prevention course 'Progressive Muscle Relaxation': standalone primary prevention offering under Sec. 20 SGB V, not medical, therapeutic or psychotherapeutic treatment; certification by the Zentrale Prüfstelle Prävention has been applied for. None of these offerings replaces medical advice, diagnosis, emergency care or treatment.

TrueDepth Camera Usage

All face data processing occurs locally on your device via Apple's ARKit. Face data is NEVER saved or transmitted — only calculated measurements (e.g., jaw opening in millimeters) are stored. The camera functions solely as a measurement tool, similar to how a ruler measures distance.

Legal basis: Art. 6 para. 1 lit. b GDPR + Art. 9 para. 2 lit. a GDPR (explicit consent for health data).

Technical Diagnostics and Connection Data

To improve app reliability and troubleshoot user issues, we collect limited technical diagnostics such as connection type (for example WiFi or cellular), connection quality, cellular generation, loading status, error context, app version, and session identifiers. We do not collect WiFi network names, precise location, carrier name, IP address for analytics profiling, or data used to identify a device by fingerprinting.

4a. Data in the Prevention Course (Sec. 20 SGB V)

If you book and use the prevention course “Progressive Muscle Relaxation for Stress Reduction and Promoting the Ability to Relax”, we additionally process the following data:

  • Registration and booking data: first name, last name, email address, selected health insurer, Apple in-app purchase confirmation. Purpose: contract performance, invoicing, delivery of the certificate of participation. Legal basis: Art. 6 (1)(b) GDPR.
  • Confirmation that no contraindications apply: before booking, you actively confirm that none of the displayed contraindications apply. We store this confirmation with a server-side timestamp and user ID. No details about medical conditions are collected; if a contraindication is selected, no account is created and no data is stored. Legal basis: Art. 9 (2)(a) GDPR (explicit consent), Art. 6 (1)(b) GDPR.
  • Course data: module progress (completed phases and modules, quiz pass status — individual quiz answers are not stored permanently) and your self-rated tension values before and after each exercise (scale 0–10) for your progress chart. Purpose: course delivery, proof of completion for the certificate, in-app feedback. Legal basis: Art. 6 (1)(b) GDPR; for tension values Art. 9 (2)(a) GDPR (explicit consent given at account creation).
  • Certificate of participation and invoice: after completion of all eight modules, both are created automatically and sent by email to the address provided at booking. Legal basis: Art. 6 (1)(b) GDPR.
  • Voluntary end-of-course evaluation: your answers are stored anonymously via a separate endpoint and are not linked to your account ID, email address, IP address or user agent. They cannot be traced back to you.

Storage and deletion: course data is processed on servers within the EU (Frankfurt region), transmitted via TLS 1.3 and stored AES-256 encrypted. After course completion you retain access to the course content for six months. If you delete your account, personal course data is permanently removed within 30 days. You may withdraw your consent to the processing of health data at any time with effect for the future; participation in the course is then no longer possible.

5. Advertising Measurement & Tracking

With your explicit consent, the app uses Meta (Facebook) SDK and TikTok Business SDK to measure campaign effectiveness. Only device advertising identifiers (IDFA), install confirmations, registration events, and subscription purchase details (amount/currency) are shared — never health data, measurements, names, emails, or behavioral data.

These SDKs activate only when you grant advertising consent, confirm you are 16+, and grant App Tracking Transparency permission. Consent is revocable anytime via Profile → Privacy & Sharing.

6. Third-Party Services & Data Sharing

Advertising Measurement (consent required): Meta Platforms, Inc. (Facebook SDK), ByteDance Ltd. (TikTok Business SDK)

Analytics (consent required): Firebase Analytics (Google LLC), Amplitude, Inc.

Essential Services (always active): Firebase Crashlytics (Google LLC), Firebase Cloud Messaging (Google LLC), RevenueCat, Inc., Google Cloud Platform (Frankfurt, Germany, EU)

We do not share health measurements, face tracking data or treatment progress with advertising or analytics parties, and we do not sell them. They are processed exclusively by contracted processors within the meaning of Art. 28 GDPR, to the extent required for service delivery, data security, notifications, purchase/subscription handling, or exports you request. The processors we use and their purposes are listed in this section.

7. Data Storage and Security

Storage Locations: On-device (app preferences, cached exercise data) and Backend (Frankfurt, Germany — Google Cloud europe-west3).

Security: TLS 1.3 encryption in transit, AES-256 at rest, access control, per-user data isolation, secure token-based authentication, and regular security audits.

Retention: Account data persists during account tenure. Deletion results in permanent removal within 30 days. Log files are auto-deleted after 30 days.

8. Medical Disclaimer

JawBuddy (EU/EEA): Class I medical device under Regulation (EU) 2017/745 for jaw-health self-management. JawBuddy (other regions): lifestyle product, not a medical device. Prevention course 'Progressive Muscle Relaxation': standalone primary prevention offering under Sec. 20 SGB V, not medical, therapeutic or psychotherapeutic treatment; certification by the Zentrale Prüfstelle Prävention has been applied for. None of these offerings replaces medical advice, diagnosis, emergency care or treatment.

9. Your Rights Under GDPR

  • Right to Access (Art. 15): Request your data via Profile → Privacy & Sharing → Request All Your Data
  • Right to Erasure (Art. 17): Delete your data via Profile → Privacy & Sharing → Delete Account
  • Right to Rectification (Art. 16)
  • Right to Restriction of Processing (Art. 18)
  • Right to Data Portability (Art. 20)
  • Right to Object (Art. 21)
  • Right to lodge a complaint: you have the right to complain to a data protection supervisory authority, in particular the Saxon Data Protection and Transparency Commissioner, Maternistraße 17, 01067 Dresden, Germany, www.datenschutz.sachsen.de, or any other competent supervisory authority.

10. Changes to This Privacy Policy

The current version with the date shown under 'Last updated' above applies. We will inform you of material changes by email or in-app notification. Continued use of the service implies acceptance.

11. Contact Us

Email: privacy@jawbuddy.com
Subject: Data Protection Inquiry
Response Time: Within 5 business days