Privacy

Last updated: 16 July 2026

The short version

Linism is built around one rule: your data stays on your device — on iPhone, Apple Watch, Android, or Wear OS. The app does not send your health information, voice recordings, location history, or notes to us or to anyone else. We do not run analytics, ad networks, or crash reporting. The only network requests the app makes are those you trigger yourself or explicitly opt in to (for example, an App Store / Google Play subscription, the optional Garmin integration, or the optional Place Insights lookup via OpenStreetMap). This website does not set cookies and does not track you.

Data collected by Linism is not linked to your identity (Non-Linked Data) and is not used to track you across third-party apps and websites.

1. Who is responsible

The controller for processing of personal data within the meaning of Art. 4 (7) GDPR is:

Benjamin Tokgöz
Mengeder Str. 716
44359 Dortmund, Germany
Email: hello@linism.app
Phone: +49 1567 8336978

A data protection officer is not required (Art. 37 GDPR), as Linism is operated by a single individual without large-scale processing of special categories of data outside the user's own device.

2. This website (linism.app)

Hosting. linism.app is delivered through Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare automatically processes your IP address, the URL you requested, the time of the request, your user agent, and the HTTP response status. This is necessary to deliver the page to you and to protect the site against abuse (Art. 6 (1) (f) GDPR, legitimate interest in a functioning and secure website). Cloudflare keeps these access logs for a short retention period defined in its own policy (cloudflare.com/privacypolicy). A data processing agreement under Art. 28 GDPR is in place.

International transfers. Cloudflare may process data outside the EEA. Cloudflare is certified under the EU-US Data Privacy Framework, and we additionally rely on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR).

Cookies, tracking, fonts. This site sets no cookies, embeds no third-party fonts, loads no external scripts, and runs no analytics. Its Content Security Policy permits only first-party resources.

Contact by email. If you write to hello@linism.app, your message and email address are processed to answer your request (Art. 6 (1) (b) or (f) GDPR). Messages are kept only as long as needed to handle your enquiry and any follow-up.

3. The Linism iOS & Apple Watch app

Linism is designed so that your personal data stays on your iPhone and Apple Watch. We (the controller) have no servers receiving your health data, voice samples, location, mood entries, or routines. The sections below describe what the app reads on your device, how it stores it, and the rare situations in which something leaves your device.

3.1 Data the app processes

The app may read or store the following categories of data, only after you grant the relevant iOS permission:

Calendar appointments specifically: appointments you plan in the app are stored only on this device and encrypted at rest like every other record. Their reminders are scheduled and delivered locally by the operating system. Past appointments are deleted together with the calendar window described in 3.5; future appointments stay until they have passed. Appointments leave the device only inside an export you trigger yourself, and are removed by "Delete all data".

Importing appointments: you can bring appointments in from an .ics file or, read-only, from calendars on this device. Linism only reads; it never changes your calendars and contacts no server to do this. Imports are limited to the calendar window plus the next 60 days, are stored and encrypted like your own appointments, and never add reminders on their own. If you turn on the optional update on opening the app, appointments cancelled in your calendar are removed here too, while your own additions like preparation time are kept. Imported appointments can be removed per source at any time and are covered by "Delete all data".

HealthKit specifically: we do not use or disclose HealthKit data to third parties for advertising, marketing, or other use-based data mining purposes. HealthKit data is read on your device for the sole purpose of computing the local features you have enabled.

What the app does not access: contacts, calendar, photos library (beyond a picture you explicitly choose for your profile), camera, advertising identifier, or your address book.

3.2 Where the data is stored

All of the above is stored on your iPhone (and synced to your Apple Watch through the secure on-device WatchConnectivity channel, in an App Group container shared between the phone, watch, and widget extensions). Concretely:

The technical and organisational measures described here are intended to meet the security requirements of Art. 32 GDPR for processing of health data.

3.3 Data that may leave your device

The app has no ambient telemetry. The only situations in which network traffic occurs are the ones you initiate:

What we do not run: no analytics (no Firebase, Mixpanel, Amplitude, PostHog), no crash reporting (no Sentry, Crashlytics, Bugsnag), no advertising SDKs, no fingerprinting. The app does not contact a Linism server, because no such server exists.

3.4 Legal basis for processing

3.5 Retention and deletion

Because data stays on your device, you remain in direct control of its lifetime. You can delete individual entries, reset categories from the app's settings, or delete the app entirely. Deleting the app removes the encrypted on-device storage and the Keychain master key, rendering any residual ciphertext mathematically unrecoverable (cryptographic erasure).

Automatic retention: on top of that, time-stamped history is deleted from your device on a rolling schedule. Health readings and daily records (for example heart rate, HRV and sleep readings, noise levels, mood and social-battery entries, pain and symptom logs, and day reflections) are deleted after 60 days. Stress readings, including the heart rate, HRV and sound levels attached to them, and stress-location records are deleted after 30 days; resolved place insights after 60 days. Calendar appointments follow the same calendar window: past appointments are deleted with it, while future appointments stay until they have passed and age out. Routines and their execution records, time-blindness destinations and travel records, and learned summaries (for example your personal baselines) are kept until you delete them, because they carry streaks and long-term self-knowledge rather than raw measurements. Data exports therefore cover at most the last 60 days, plus any future appointments you have planned.

4. The Linism Android phone and Wear OS app

Linism is designed so that your personal data stays on your Android phone and on a paired Wear OS watch. We (the controller) have no servers receiving your health data, voice samples, location, mood entries, or routines. The sections below describe what the app reads on your device, how it stores it, and the situations in which something may leave your device.

4.1 Data the app processes

The app may read or store the following categories of data, only after you grant the relevant Android permission:

Calendar appointments specifically: appointments you plan in the app are stored only on this device and encrypted at rest like every other record. Their reminders are scheduled and delivered locally by the operating system. Past appointments are deleted together with the calendar window described in 4.5; future appointments stay until they have passed. Appointments leave the device only inside an export you trigger yourself, and are removed by "Delete all data".

Importing appointments: you can bring appointments in from an .ics file or, read-only, from calendars on this device. Linism only reads; it never changes your calendars and contacts no server to do this. Imports are limited to the calendar window plus the next 60 days, are stored and encrypted like your own appointments, and never add reminders on their own. If you turn on the optional update on opening the app, appointments cancelled in your calendar are removed here too, while your own additions like preparation time are kept. Imported appointments can be removed per source at any time and are covered by "Delete all data".

Specifically about Health Connect: we do not use or disclose Health Connect data for advertising, marketing, or other use-based data mining. Health Connect data is read on your device only to compute the local features you have enabled.

What the app does not access: contacts (beyond a single emergency contact you explicitly type or pick), calendar, camera (beyond photos you explicitly choose), advertising identifier, SMS, or your call log.

4.2 Where the data is stored

All of the above is stored in the app's private storage on your Android phone (and, where relevant, mirrored to your paired Wear OS watch via the on-device Google Play Services Wearable Data Layer — a peer-to-peer transport between your two devices). Concretely:

The technical and organisational measures described here are intended to meet the security requirements of Art. 32 GDPR for processing of health data.

4.3 Data that may leave your device

The app has no ambient telemetry. The only situations in which network traffic occurs are the ones you initiate or opt in to:

What we do not run: no analytics (no Firebase Analytics, Mixpanel, Amplitude, PostHog), no crash reporting (no Sentry, Crashlytics, Bugsnag), no advertising SDKs, no fingerprinting. The app does not contact a Linism server, because no such server exists.

4.4 Legal basis for processing

4.5 Retention and deletion

Because data stays on your device, you remain in direct control of its lifetime. You can delete individual entries, reset categories from the app's settings, or use "Delete All Local Data" to wipe everything and destroy the Android Keystore master key — rendering any residual ciphertext mathematically unrecoverable (cryptographic erasure). Uninstalling the app has the same effect on the encrypted store; Android also clears the app's private files directory.

Automatic retention: on top of that, time-stamped history is deleted from your device on a rolling schedule. Health readings and daily records (for example heart rate, HRV and sleep readings, noise levels, mood and social-battery entries, pain and symptom logs, and day reflections) are deleted after 60 days. Stress readings, including the heart rate, HRV and sound levels attached to them, and stress-location records are deleted after 30 days; resolved place insights after 60 days. Calendar appointments follow the same calendar window: past appointments are deleted with it, while future appointments stay until they have passed and age out. Routines and their execution records, time-blindness destinations and travel records, and learned summaries (for example your personal baselines) are kept until you delete them, because they carry streaks and long-term self-knowledge rather than raw measurements. Data exports therefore cover at most the last 60 days, plus any future appointments you have planned.

5. Your rights under GDPR

You have the following rights regarding personal data we process:

6. Automated decision-making and profiling

The app computes a local stress score from your health signals (HealthKit on iOS, Android Health Connect on Android — and optionally Garmin) and the ambient noise level, and uses it to decide when to nudge you with a soft notification. This computation runs only on your device, has no legal or similarly significant effect on you in the sense of Art. 22 GDPR, and never leaves your device.

7. Children

Linism is intended to support autistic users of all ages, which may include children. The app does not require account creation and does not collect data online, so we do not knowingly receive personal data from minors. If a minor uses the app on their own device, the data they enter stays on that device. We recommend that parents or guardians supervise app installation, HealthKit / Health Connect consent, and any sharing of exported data.

8. Changes to this policy

We may update this policy when the app or its data practices change. The current version is always available at this URL and dated at the top.

9. Contact

Questions about this policy or about your data: hello@linism.app.

Back to home