Privacy Policy
Last updated: 25 August 2026
Controller
The controller is Bettag Systems UG (haftungsbeschränkt). Address and representation details are available in the legal notice. Privacy requests can be sent to healthnut@bett.ag.
What Healthnut processes
We process your email address and account identifiers; passwordless sign-in and refresh tokens; submitted public source URLs, locale and random request IDs; Healthcheck references, likes and quota events; subscription and billing status; support messages; and necessary security and server log data such as IP address, time, user agent and request result.
Please do not submit private medical records, symptoms, measurements or other personal health data. Healthnut is designed for public claims and sources, not a personal health profile.
Purposes and legal bases
We process account, source, like and subscription data to provide the requested service and contract (Article 6(1)(b) GDPR). Billing records are also processed to meet legal obligations (Article 6(1)(c)). Security, abuse prevention, service reliability and limited product improvement rely on our legitimate interests (Article 6(1)(f)). Optional communications or analytics that require consent are used only after consent and can be revoked (Article 6(1)(a)).
Intelligence data boundary
Healthnut has no direct access to the Intelligence database. It calls token-protected HTTP APIs. Intelligence receives only the submitted public URL, locale and a random request ID — never your Healthnut user ID, email address, subscription state or personal health data. Healthnut stores minimal analysis references and account state; authoritative public evidence and dossiers remain in Intelligence.
Deleting your Healthnut account removes your personal account links, Healthchecks, likes and tokens. Public, de-personalized evidence can remain in Intelligence because it is not tied to your Healthnut identity.
Service providers and recipients
We use infrastructure providers required to host and secure Healthnut. Postmark delivers passwordless sign-in and transactional email. Mollie processes Premium payments and acts under its own privacy obligations for payment data. Intelligence supplies public evidence through the boundary described above. Data is disclosed only where required to provide the service, comply with law or protect the service.
Where a provider processes data outside the European Economic Area, we use an applicable adequacy decision or appropriate safeguards such as EU standard contractual clauses where required.
Cookies and device storage
The website uses technically necessary session and security cookies. The iOS app stores access and refresh tokens in the Keychain and queued public URLs in its App Group container. We do not build advertising or cross-app profiles.
Retention
Account-linked Healthnut data is retained while the account exists and deleted when you use account deletion, subject to short technical backups and mandatory legal retention. Expired or revoked authentication tokens and stale quota reservations are removed according to their configured lifetimes. Billing and tax records are retained for statutory periods. Security logs are kept only as long as reasonably necessary for security and operations.
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability and objection, and may withdraw consent for the future. You may also complain to a competent data-protection authority. We may need to verify your identity before fulfilling a request.
Contact: healthnut@bett.ag