Skip to content
Self Science Institute

Live Biofeedback app

Live Biofeedback: privacy policy

Last updated: 21 September 2026

This policy explains what the Live Biofeedback app does with your data. It covers the app on iPhone and Android. We have tried to write it in plain language.

If anything is unclear, write to us at data-protection@selfscience.tech.

1. Who we are

The app is made and run by Self Science Institute ApS, a company registered in Denmark (CVR 43627287), Eremitageparken 213, 2D, 2800 Kongens Lyngby, Denmark.

We are the data controller for the personal data described here.

Privacy contact: data-protection@selfscience.tech

2. The short version

  • You can join a session without an account. The app then does not know your name, email or phone number.
  • During a session, your heart sensor's data goes from your phone to the facilitator's tablet in the room over the room's Wi-Fi. The room screen shows your heart rate under a made-up name, not your real name.
  • We ask for your consent before anything is recorded. Research use is a separate, optional choice. It is off unless you turn it on.
  • If the facilitator keeps the session, the recording is stored on our server and in our cloud storage in the EU.
  • You can hide yourself from the room screen, or withdraw from a session, at any time during the session.
  • An account is optional. If you create one, we store the details you enter. You can delete your account in the app or by email.
  • The app has no ads and no tracking. We do not sell your data.
  • The app is not a medical device.

3. What the app does

Live Biofeedback lets you take part in a live group biofeedback session led by a facilitator. You wear a Polar heart-rate sensor (a Polar H10 chest strap or a Polar Verity Sense armband). Your phone connects to the sensor over Bluetooth, calculates your heart rate and heart-rate variability, and sends them to the facilitator's tablet in the room. The room screen shows the group's signals together.

There is also a demo mode ("Try a demo"). It uses a made-up heart signal on your phone. Nothing from the demo is recorded or sent.

4. What data we process, and why

Each part below says what the data is, where it goes, why we use it and on what legal basis.

4.1 Session data (when you join a live session)

What we process:

  • Data from your heart sensor: heart rate, the time between heartbeats (beat-to-beat intervals), and the sensor's own quality and skin-contact signals, with timestamps from your phone's clock.
  • Values your phone calculates from that: heart rate, heart-rate variability (RMSSD and SDNN), a signal-quality score, and whether you are hidden from the room screen.
  • "Mark a moment" events: when you tap it, a time marker is sent to the facilitator's tablet.
  • Random identifiers: a session ID, and a participant ID that your phone creates for you in each session. The room screen shows a made-up name, not your name.
  • The kind of sensor (for example, chest strap or armband).

During the session, the calculated values, the beat-to-beat intervals and your markers go from your phone to the facilitator's tablet over the room's Wi-Fi. This live stream stays on the room's local network.

At the end of the session, the facilitator decides to keep or discard it. If it is kept, your phone uploads its recording of your sensor data to our server, and the facilitator's tablet uploads the calculated values. Both are stored with the random IDs, not with your name. If it is discarded, your phone deletes its recording and uploads nothing. If no decision reaches your phone, it keeps the recording and does not upload it.

On your phone, a compressed copy of a kept recording stays in the app's private storage until you uninstall the app.

Why: to run the live session, show it in the room, and keep a record of the session.

Legal basis: your explicit consent, given on the "Before you join" screen. Heart data is health data, so this is explicit consent under GDPR Articles 6(1)(a) and 9(2)(a).

4.2 Research use (optional)

On the "Before you join" screen you can turn on "Also use my data for research". It is off by default. Your session works the same either way.

If you turn it on, we may keep your session data and use it for research and to improve our methods and products.

Legal basis: your explicit consent (GDPR Articles 6(1)(a) and 9(2)(a)). You can withdraw it at any time by writing to us.

4.3 Consent records

For each session we keep one record for taking part and one for research use. Each says yes or no, the time you decided, the random session and participant IDs, and which version of the consent text you saw.

Why: we must be able to show that you gave consent, and when. If you withdraw, the records are not deleted; they are marked as withdrawn, with the time.

Legal basis: our legal obligation to be able to demonstrate consent (GDPR Articles 6(1)(c) and 7(1)).

4.4 Your account (optional)

You never need an account to join a session. If you create an account, we store what you enter:

  • email address
  • phone number (optional)
  • date of birth
  • sex
  • height and weight
  • the password you choose

You sign in with your email address and password, or with a one-time code that we send by email or text message.

Your phone stores your sign-in session, your user ID and your email address in the app's storage, so you stay signed in. Signing out removes them from the phone.

Why: to give you an account and, when that feature is available, a personal report of your sessions.

Legal basis: performance of a contract with you (GDPR Article 6(1)(b)). Height and weight may be health data; for those, your explicit consent (Article 9(2)(a)).

4.5 Linking a session to your account (optional)

If you are signed in when you join, the "Before you join" screen shows "Send my report to my account". If you leave it on, the app asks our server to link that session's random participant ID to you.

The server does not store your user ID next to your session data. It stores a pseudonym: a code calculated from your user ID with a secret key that only the server has. With it we can find your sessions for your report. Without the key, nobody can tell whose sessions they are.

The report service is still being set up. Until it is live, your phone keeps the link request and sends it later.

If you turn the option off, you join anonymously and nothing links that session to your account.

Legal basis: performance of a contract (your request for a report).

4.6 Withdrawal and erasure requests

If you withdraw from a session, the app stops sending your data, deletes the recordings on your phone for that session, and sends an erasure request to our server. The request contains the random session and participant IDs and the time. See section 7 for what is erased and when.

4.7 Account deletion requests

If you delete your account in the app, the app sends a request with your user ID and email address. Our server then immediately blocks the account and erases its personal details. We keep the request itself as a record that the deletion was done. See section 8.

4.8 Technical data

Like any server, ours receives your phone's IP address and the time of each request, and keeps them in its logs for a limited time (see section 7).

Legal basis: our legitimate interest in running a secure service (GDPR Article 6(1)(f)).

The app contains no analytics, advertising or tracking tools.

5. Data that stays on your phone

Some things the app uses never leave your phone:

  • Camera: used only to scan QR codes (the session code and your sensor's sticker). Camera images are not stored or sent.
  • Your sensor's ID: used to connect to your sensor. It is not sent to us.
  • Wi-Fi name and location permission (optional): phones only show an app the Wi-Fi network's name if the app has location permission. In Profile, under "Check the session Wi-Fi", you can turn this check on; it is off by default. The app then compares the Wi-Fi name with the session's network on your phone. It does not read your GPS position, and it does not store or send the Wi-Fi name or your location.
  • Joining the room's Wi-Fi: the session QR code can contain the room's Wi-Fi name and password. Your phone shows its own prompt, and you decide. The app does not keep the password.
  • "My sessions": a list of sessions you attended on this phone (date, duration, and whether the session was completed, discarded or withdrawn).
  • Settings, for example whether you have seen the introduction.

6. Who receives your data

We do not sell your data. We do not share it with advertisers.

  • People in the room: the room screen shows everyone's heart signals with made-up names. In a small group, others may be able to guess which signal is yours. You can hide yourself at any time.
  • The facilitator's tablet: receives your live values and markers, and uploads them if the session is kept.
  • Google Cloud (Google Cloud EMEA Limited, Ireland): hosts our server, database and file storage in the Netherlands (EU).
  • Google Workspace (Google Ireland Limited): sends one-time codes by email.
  • Twilio: sends one-time codes by text message, if you sign in with your phone number.
  • Authorities, if the law requires it.

These providers process data for us under a data processing agreement. Twilio and Google may process data outside the EU/EEA, for example in the United States. Those transfers are covered by the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses.

7. How long we keep data

DataHow long
Session recordings and values (no research consent)12 months after the session
Session data with research consentUntil the research project ends, at most 10 years
Consent records5 years after the session
Account dataUntil you delete your account
Account deletion requests3 years
Server logs90 days
BackupsDeleted data can remain in backups for up to 30 days
Data on your phoneUntil you uninstall the app (signing out removes your sign-in details)

About withdrawal and erasure: when you withdraw, we record an erasure request. Within 30 days our system erases your rows in the session database and the files already uploaded to cloud storage. Deleted files stay recoverable by us for 7 days, then are gone. Summary results about the whole group that were calculated during the session may remain after your own data is erased.

8. Your rights

Under the GDPR you have the right to:

  • see the data we hold about you (access)
  • have wrong data corrected
  • have your data deleted
  • restrict or object to how we use it
  • get your data in a portable format
  • withdraw your consent at any time. This does not affect what was done before you withdrew.

To use any of these rights, write to data-protection@selfscience.tech. A session you joined without an account is stored only under random IDs, so we may need your help to find it: tell us the date, time and place, or the 4-digit session code. We answer within one month.

How to withdraw from a session: during the session, open the "…" menu and choose "Withdraw from this session". This stops your data, deletes the recording on your phone, and requests erasure of your data from that session. It cannot be undone. After the session has ended, write to data-protection@selfscience.tech instead.

How to hide: tap "Hide me" during a session. Your tile leaves the room screen. Hiding does not stop the recording on your phone. To stop and request deletion, withdraw instead.

How to delete your account: in the app, open Profile and tap "Delete account", or follow the steps at https://www.selfscience.tech/en/live-biofeedback/delete-account/. Your account is blocked and its personal details are erased immediately. Anything else linked to it is deleted within 30 days.

You also have the right to complain to the Danish Data Protection Agency (Datatilsynet), www.datatilsynet.dk, or to the authority in the EU country where you live.

9. Security

  • The app talks to our server only over encrypted connections (HTTPS).
  • Session data is stored with random IDs, not names.
  • The live stream between your phone and the facilitator's tablet uses the room's Wi-Fi. The app does not add its own encryption to it; it is protected as far as the Wi-Fi network is (for example, by a Wi-Fi password).

10. Children

The app is for adults aged 18 and over. Do not use it if you are under 18. If you think a child has given us data, write to data-protection@selfscience.tech and we will delete it.

11. Not a medical device

Live Biofeedback is not a medical device. It does not diagnose, treat, prevent or monitor any disease or condition. Do not use it to make health decisions.

12. Changes to this policy

If we change this policy, we will update the date at the top and publish the new version at this address. If a change affects how we use data you have already given us, we will tell you in the app or by email before it takes effect.

13. Contact

Self Science Institute ApS, Eremitageparken 213, 2D, 2800 Kongens Lyngby, Denmark.

Privacy: data-protection@selfscience.tech

Support: helloworld@selfscience.tech