Back home

Legal · Last updated 1 October 2026

Privacy Policy

Innercode works with some of the most personal data there is: your blood results. This page explains, in plain language, what we collect, why, who helps us run the service, and how you stay in control.

The short version

  • We use your data only to give you your own interpretation. We never sell it, and never share it with insurers, employers or advertisers.
  • Your data is stored in the EU (Frankfurt, Germany).
  • To create an interpretation, your results are processed by an AI model from Google. Details are below.
  • You can export everything or delete your account at any time in Settings → Data & Privacy.
  • No tracking or advertising cookies.

Who is responsible

Innercode is a private, non-commercial project run by Camila Klein Rinaldi as part of her product management portfolio, currently in a small private beta. Being a personal project doesn't change how carefully we treat your data: under the GDPR, Camila Klein Rinaldi is the controller of your personal data and responsible for everything on this page.

Petersburger Str. 2710249 BerlinGermany

For anything about your data, email privacy@innercode.health. We aim to reply within a few days and always within one month.

What we collect and why

Your account. Your email address and name, and your password (stored only as a secure hash) or your Google sign-in. We need these to give you an account. Legal basis: performance of our agreement with you (Art. 6(1)(b) GDPR).

Your health profile. Date of birth, life stage, diet, activity level, family history, what brings you to Innercode, and the supplements you take. This is what makes your interpretation personal.

Your blood results. The lab reports you upload (PDF or photo), the marker values we read from them or that you enter yourself, and the interpretations we generate. Your uploaded file is stored, not just read and discarded, so you can come back to it.

Your health profile and blood results are health data, a special category under the GDPR. We process them only with your explicit consent (Art. 9(2)(a) GDPR), which you give before you enter any health details, and again if we change how we describe this processing. You can withdraw it at any time in Settings → Data & Privacy → Withdraw consent, which deletes your account and its data; this doesn't affect processing that already happened.

Beta access requests. If you ask for a beta code, we store your email address and any note you add, only to review your request and send you a code (Art. 6(1)(b) GDPR).

Security data. If you turn on two-factor authentication, we store what's needed to check your codes. Our hosting providers keep short-lived technical logs (such as IP addresses) to keep the service running and secure (Art. 6(1)(f) GDPR, our legitimate interest in a secure service).

How the AI interpretation works

To read your lab report and write your interpretation, we send your uploaded file, your marker values and the relevant parts of your health profile to an AI model: Google Gemini, accessed through Lovable's AI Gateway. We send only what the interpretation needs, and the result comes back to your account. We don't send your name or email address with your results.

Lab reports usually also show personal details, such as your name, date of birth or address. Because the AI reads the file as a whole, it sees these too, but it only extracts your marker values, the lab's name and the test date; nothing else is taken from the file or used for your interpretation. If you'd rather not share these details, cover or crop them out before uploading, or enter your values manually instead.

The AI can make mistakes. Innercode is an interpretation layer, not a diagnosis; see our Terms of use.

Who helps us run Innercode

We don't sell or rent your data. We work with a small number of service providers (processors) who handle data only on our instructions and only to run Innercode:

  • Supabase: database, sign-in and file storage. Your data is stored in Frankfurt, Germany.
  • Lovable (Sweden): hosts the Innercode website and app, and provides the AI Gateway.
  • Google: runs the Gemini AI models that read and interpret your results, and handles sign-in if you choose "Continue with Google".
  • Cloudflare: delivers our providers' traffic securely and quickly.

Some of these providers may process data outside the EU, for example in the United States. Where that happens, the transfer is protected by the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How long we keep your data

We keep your account and health data for as long as you have an account. When you delete your account in Settings, your profile, results, uploaded files and interpretations are deleted straight away. Copies can remain in encrypted backups for a short time until those backups are overwritten.

Beta access requests are deleted once they're no longer needed, and at any time on request.

Your GDPR rights

You have the right to:

  • Access your data and get a copy of it. Settings → Data & Privacy → Download my data gives you everything at once.
  • Correct data that's wrong. Most of it you can edit yourself in Settings.
  • Delete your data ("right to be forgotten"). Settings → Data & Privacy → Delete my account removes it all.
  • Restrict or object to certain processing.
  • Take your data elsewhere (data portability). The download is a machine-readable JSON file.
  • Withdraw your consent at any time, in Settings → Data & Privacy → Withdraw consent. Innercode can't work without your health data, so withdrawing deletes your account and its data.

For anything you can't do in Settings, email privacy@innercode.health. You can also complain to a data protection authority, for example the one where you live or the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

Cookies and browser storage

Innercode doesn't use tracking, analytics or advertising cookies, so there's nothing to accept or reject.

We use your browser's local storage only for things the service needs: keeping you signed in and remembering your light or dark appearance setting. These are strictly necessary, so they don't require consent.

Our network provider, Cloudflare, sets one security cookie (__cf_bm) to tell people from automated bots. It holds no information about who you are, expires after 30 minutes, and is also strictly necessary.

Our fonts are served from Innercode's own servers, so loading a page doesn't send your IP address to Google.

How we protect your data

  • All connections are encrypted (HTTPS/TLS), and data is encrypted at rest.
  • Database rules make sure each account can only ever read its own data.
  • You can add two-factor authentication in Settings.

Changes to this policy

If we change how we handle your data, we'll update this page and the date at the top. For important changes, we'll tell you in the app or by email before they take effect.