Privacy
Last updated: 16 July 2026
The short version
Linism is built around one rule: your data stays on your device — on iPhone, Apple Watch, Android, or Wear OS. The app does not send your health information, voice recordings, location history, or notes to us or to anyone else. We do not run analytics, ad networks, or crash reporting. The only network requests the app makes are those you trigger yourself or explicitly opt in to (for example, an App Store / Google Play subscription, the optional Garmin integration, or the optional Place Insights lookup via OpenStreetMap). This website does not set cookies and does not track you.
Data collected by Linism is not linked to your identity (Non-Linked Data) and is not used to track you across third-party apps and websites.
1. Who is responsible
The controller for processing of personal data within the meaning of Art. 4 (7) GDPR is:
Benjamin Tokgöz
Mengeder Str. 716
44359 Dortmund, Germany
Email: hello@linism.app
Phone: +49 1567 8336978
A data protection officer is not required (Art. 37 GDPR), as Linism is operated by a single individual without large-scale processing of special categories of data outside the user's own device.
2. This website (linism.app)
Hosting. linism.app is delivered through Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare automatically processes your IP address, the URL you requested, the time of the request, your user agent, and the HTTP response status. This is necessary to deliver the page to you and to protect the site against abuse (Art. 6 (1) (f) GDPR, legitimate interest in a functioning and secure website). Cloudflare keeps these access logs for a short retention period defined in its own policy (cloudflare.com/privacypolicy). A data processing agreement under Art. 28 GDPR is in place.
International transfers. Cloudflare may process data outside the EEA. Cloudflare is certified under the EU-US Data Privacy Framework, and we additionally rely on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR).
Cookies, tracking, fonts. This site sets no cookies, embeds no third-party fonts, loads no external scripts, and runs no analytics. Its Content Security Policy permits only first-party resources.
Contact by email. If you write to hello@linism.app, your message and email address are processed to answer your request (Art. 6 (1) (b) or (f) GDPR). Messages are kept only as long as needed to handle your enquiry and any follow-up.
3. The Linism iOS & Apple Watch app
Linism is designed so that your personal data stays on your iPhone and Apple Watch. We (the controller) have no servers receiving your health data, voice samples, location, mood entries, or routines. The sections below describe what the app reads on your device, how it stores it, and the rare situations in which something leaves your device.
3.1 Data the app processes
The app may read or store the following categories of data, only after you grant the relevant iOS permission:
- Health data via Apple HealthKit (special category of data under Art. 9 GDPR): heart rate, heart rate variability (HRV/SDNN), sleep analysis, blood oxygen saturation, respiratory rate, wrist temperature, and environmental audio exposure. The app requests read access through Apple's HealthKit consent screen. You decide which categories to grant.
- Microphone for ambient noise level. When the noise detection feature is active, the device microphone is sampled to compute an instantaneous decibel level (dB SPL). The short audio buffer is processed in memory or written to a temporary file that is deleted immediately after the level is computed. We never retain the audio content; only the computed noise level is stored.
- Location (optional, with a separate background opt-in). If you enable the "stress location" feature, the app uses your device's location to tag detected stress moments to a place on your own map. By default this happens only while the app is in use ("While Using the App"). If you opt in to background capture (so the breadcrumb keeps working while the phone is in your pocket), the app additionally requests iOS's "Always" location permission. Stress-location records are stored only on your device and automatically deleted after 30 days. Your location history never leaves your device; if you turn on the optional Place Insights lookup, a rounded coordinate per stress spot is sent to OpenStreetMap (see 3.3).
- Data you enter yourself. Profile (name, address, autism level, difficulty tags, optional emergency contact, optional phone number), mood self-reports, pain and symptom logs, custom routines, routine execution records (timestamps and step completions), social-battery levels, sleep-feedback ratings, time-blindness destinations and travel records, day reflections (free-text notes you optionally write about a day), calendar appointments you plan (title, category, optional place and notes, and the preparation, travel and quiet-time spans), and optional photos you upload (profile picture or card backgrounds).
- App-derived data. Stress scores computed from the signals above, paired with timestamps.
- Local notifications. The app schedules local notifications through iOS (for example, a soft nudge when stress rises, or an appointment reminder you chose). These never leave your device and do not use Apple Push Notification servers.
Calendar appointments specifically: appointments you plan in the app are stored only on this device and encrypted at rest like every other record. Their reminders are scheduled and delivered locally by the operating system. Past appointments are deleted together with the calendar window described in 3.5; future appointments stay until they have passed. Appointments leave the device only inside an export you trigger yourself, and are removed by "Delete all data".
Importing appointments: you can bring appointments in from an .ics file or, read-only, from calendars on this device. Linism only reads; it never changes your calendars and contacts no server to do this. Imports are limited to the calendar window plus the next 60 days, are stored and encrypted like your own appointments, and never add reminders on their own. If you turn on the optional update on opening the app, appointments cancelled in your calendar are removed here too, while your own additions like preparation time are kept. Imported appointments can be removed per source at any time and are covered by "Delete all data".
HealthKit specifically: we do not use or disclose HealthKit data to third parties for advertising, marketing, or other use-based data mining purposes. HealthKit data is read on your device for the sole purpose of computing the local features you have enabled.
What the app does not access: contacts, calendar, photos library (beyond a picture you explicitly choose for your profile), camera, advertising identifier, or your address book.
3.2 Where the data is stored
All of the above is stored on your iPhone (and synced to your Apple Watch through the secure on-device WatchConnectivity channel, in an App Group container shared between the phone, watch, and widget extensions). Concretely:
- Records are encrypted at rest with AES-256-GCM (CryptoKit) using authenticated encryption with associated data (AEAD). The master key is a 256-bit symmetric key.
-
The master key is generated on first launch and stored in the iOS Keychain with accessibility
flag
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly. It cannot leave the device, is not synced to iCloud, and is unavailable while the device is locked before first unlock after boot. -
Files in the app's Documents directory (for example, your profile picture) are protected with iOS's
.completeFileProtectionattribute, so they are unreadable while the device is locked. - No data is written to iCloud, CloudKit, or any other cloud backup that we control.
The technical and organisational measures described here are intended to meet the security requirements of Art. 32 GDPR for processing of health data.
3.3 Data that may leave your device
The app has no ambient telemetry. The only situations in which network traffic occurs are the ones you initiate:
- Optional Garmin integration. If you have a paired Garmin watch and the Garmin Connect Mobile companion app installed and signed in, Linism uses the on-device Garmin Connect IQ SDK to exchange messages with the watch through that companion app. The companion app may pull or push your Garmin wellness data (heart rate, HRV, stress, sleep, blood oxygen, temperature) between Garmin's servers and your devices. Linism never sees Garmin credentials and never holds a token; everything flows through Garmin's own app. Garmin's privacy policy applies (garmin.com/privacy/connect). You can disconnect at any time in the app settings.
- App Store subscriptions. If you purchase a subscription, the transaction is handled directly by Apple via StoreKit, subject to Apple's privacy policy (apple.com/legal/privacy). We receive only an anonymous subscription status from Apple, not your name, email, or payment details.
-
Place Insights (optional Pro feature). If you turn this on, the app sends a deliberately
coarse, rounded coordinate (no precise location, no identifier) to the public OpenStreetMap Overpass API
(
overpass-api.de) to look up what kinds of places are near you (for example "park" or "supermarket"). The result is used to compute one local insight on your device and is then discarded. The lookup is opt-in and gated behind the Pro tier. Overpass is a community-run service; its terms apply (wiki.openstreetmap.org/wiki/Overpass_API). - Stress-map display. The stress map itself is rendered with Apple Maps (MapKit); map data is loaded by iOS directly from Apple, under Apple's privacy policy (apple.com/legal/privacy).
- Manual export. You can export your data as a file via the iOS share sheet. Where that file goes (AirDrop, Mail, iCloud Drive, another app) is entirely your choice. The exported file is plaintext; treat it with the same care as any other personal document.
What we do not run: no analytics (no Firebase, Mixpanel, Amplitude, PostHog), no crash reporting (no Sentry, Crashlytics, Bugsnag), no advertising SDKs, no fingerprinting. The app does not contact a Linism server, because no such server exists.
3.4 Legal basis for processing
- Art. 9 (2) (a) GDPR (explicit consent for special-category data): for HealthKit access. You grant this through Apple's system consent screen and can revoke it at any time in iOS Settings > Privacy & Security > Health.
- Art. 6 (1) (a) GDPR (consent): for microphone, location (both foreground and the opt-in background capture), notifications, the optional Garmin integration, and the optional Place Insights lookup.
- Art. 6 (1) (b) GDPR (contract performance): for processing strictly necessary to provide the features you enable, including local processing of data you enter into the app.
3.5 Retention and deletion
Because data stays on your device, you remain in direct control of its lifetime. You can delete individual entries, reset categories from the app's settings, or delete the app entirely. Deleting the app removes the encrypted on-device storage and the Keychain master key, rendering any residual ciphertext mathematically unrecoverable (cryptographic erasure).
Automatic retention: on top of that, time-stamped history is deleted from your device on a rolling schedule. Health readings and daily records (for example heart rate, HRV and sleep readings, noise levels, mood and social-battery entries, pain and symptom logs, and day reflections) are deleted after 60 days. Stress readings, including the heart rate, HRV and sound levels attached to them, and stress-location records are deleted after 30 days; resolved place insights after 60 days. Calendar appointments follow the same calendar window: past appointments are deleted with it, while future appointments stay until they have passed and age out. Routines and their execution records, time-blindness destinations and travel records, and learned summaries (for example your personal baselines) are kept until you delete them, because they carry streaks and long-term self-knowledge rather than raw measurements. Data exports therefore cover at most the last 60 days, plus any future appointments you have planned.
4. The Linism Android phone and Wear OS app
Linism is designed so that your personal data stays on your Android phone and on a paired Wear OS watch. We (the controller) have no servers receiving your health data, voice samples, location, mood entries, or routines. The sections below describe what the app reads on your device, how it stores it, and the situations in which something may leave your device.
4.1 Data the app processes
The app may read or store the following categories of data, only after you grant the relevant Android permission:
- Health data via Android Health Connect (special category of data under Art. 9 GDPR): heart rate, heart rate variability (HRV), sleep, resting heart rate, blood oxygen saturation, respiratory rate, and steps. With your separate permission the app may also read history older than 30 days (for example to seed your personal baseline). The app requests read access through Android's Health Connect permission flow. You decide which categories to grant.
- Microphone for ambient noise level. When the noise detection feature is active, the device microphone is sampled to compute an instantaneous decibel level (dB SPL). The short audio buffer is processed in memory only and immediately discarded; the audio content is never written to disk and never retained. Only the computed dB value is stored. Microphone monitoring is foreground-only — it stops automatically as soon as the app is backgrounded.
- Location (optional). If you enable the "stress location" feature, the app uses your device's location to tag detected stress moments to a place on your own map. The app only asks for the "While using the app" location permission and never requests Android's "Allow all the time" (background) permission. So that the breadcrumb keeps working while the phone is in your pocket, the app runs a foreground service with a persistent notification while location is being captured; capture stops as soon as you turn the feature off. Stress-location records are stored only on your device and automatically deleted after 30 days. Your location history never leaves your device; if you turn on the optional Place Insights lookup, a rounded coordinate per stress spot is sent to OpenStreetMap (see 4.3).
- Data you enter yourself. Profile (name, address, autism level, difficulty tags, optional emergency contact, optional phone number), mood self-reports, pain and symptom logs, custom routines, routine execution records (timestamps and step completions), social-battery levels, sleep-feedback ratings, time-blindness destinations and travel records, day reflections (free-text notes you optionally write about a day), calendar appointments you plan (title, category, optional place and notes, and the preparation, travel and quiet-time spans), and optional photos you upload (for the profile picture or as card backgrounds).
- App-derived data. Stress scores computed locally from the signals above, paired with timestamps.
- Local notifications. The app schedules local Android notifications (for example, a soft nudge when stress rises, a routine reminder, or an appointment reminder you chose). These are delivered by the Android system; no push servers and no Linism servers are involved. Appointment reminders are readable on the lock screen by design (a glance at the moment of transition is the point); if you have told Android to hide sensitive notification content, they show a neutral "Calendar reminder" instead.
Calendar appointments specifically: appointments you plan in the app are stored only on this device and encrypted at rest like every other record. Their reminders are scheduled and delivered locally by the operating system. Past appointments are deleted together with the calendar window described in 4.5; future appointments stay until they have passed. Appointments leave the device only inside an export you trigger yourself, and are removed by "Delete all data".
Importing appointments: you can bring appointments in from an .ics file or, read-only, from calendars on this device. Linism only reads; it never changes your calendars and contacts no server to do this. Imports are limited to the calendar window plus the next 60 days, are stored and encrypted like your own appointments, and never add reminders on their own. If you turn on the optional update on opening the app, appointments cancelled in your calendar are removed here too, while your own additions like preparation time are kept. Imported appointments can be removed per source at any time and are covered by "Delete all data".
Specifically about Health Connect: we do not use or disclose Health Connect data for advertising, marketing, or other use-based data mining. Health Connect data is read on your device only to compute the local features you have enabled.
What the app does not access: contacts (beyond a single emergency contact you explicitly type or pick), calendar, camera (beyond photos you explicitly choose), advertising identifier, SMS, or your call log.
4.2 Where the data is stored
All of the above is stored in the app's private storage on your Android phone (and, where relevant, mirrored to your paired Wear OS watch via the on-device Google Play Services Wearable Data Layer — a peer-to-peer transport between your two devices). Concretely:
- Personal records are encrypted at rest with AES-256-GCM using authenticated encryption with associated data (AEAD). The master key is a 256-bit symmetric key. Each record is bound to its storage slot as additional authenticated data, so swapping or copying ciphertext between records is detected and rejected.
- The master key is generated on first launch and stored in the Android Keystore (hardware-backed where the device supports it). It cannot leave the device, is not synced to Google Drive or any other cloud, and is unavailable to other apps and to ADB.
- The app's private files directory (where the encrypted blobs and any user-uploaded photos live) is additionally protected by Android File-Based Encryption (FBE), which is unlocked by the device credential after first boot.
-
Android Auto Backup is explicitly disabled for Linism (
android:allowBackup="false",android:fullBackupContent="false"), so no app data is uploaded to Google Drive via the system backup mechanism.
The technical and organisational measures described here are intended to meet the security requirements of Art. 32 GDPR for processing of health data.
4.3 Data that may leave your device
The app has no ambient telemetry. The only situations in which network traffic occurs are the ones you initiate or opt in to:
- Google Play subscriptions. If you purchase a subscription on Android, the transaction is handled directly by Google Play Billing, subject to Google's privacy policy (policies.google.com/privacy). We receive only an anonymous purchase token from Google Play, which the app uses to verify your entitlement on-device. We do not receive your name, email, or payment details.
- Optional Garmin integration. If you have a paired Garmin watch and the Garmin Connect Mobile companion app installed and signed in, Linism uses the on-device Garmin Connect IQ SDK to exchange messages with the watch through that companion app. The companion app may pull or push your Garmin wellness data (heart rate, HRV, stress, sleep, blood oxygen, temperature) between Garmin's servers and your devices. Linism never sees Garmin credentials and never holds a token; everything flows through Garmin's own app. Garmin's privacy policy applies (garmin.com/privacy/connect). You can disconnect at any time in the app settings.
-
Place Insights (optional Pro feature). If you turn this on, the app sends a deliberately
coarse, rounded coordinate (no precise location, no identifier) to the public OpenStreetMap Overpass API
(
overpass-api.de) to look up what kinds of places are near you (for example "park" or "supermarket"). The result is used to compute one local insight on your device and is then discarded. The lookup is opt-in and gated behind the Pro tier. Overpass is a community-run service; its terms apply (wiki.openstreetmap.org/wiki/Overpass_API). -
Stress-map tiles. When you open the stress map, the app downloads map tiles from the
public OpenStreetMap tile servers (
tile.openstreetmap.org). Each tile request reveals the map area you are currently looking at, as is inherent to any map tile system; the tiles are cached on your device. No identifier or other personal data is attached. The OpenStreetMap Foundation's privacy notice applies (osmfoundation.org/wiki/Privacy_Policy). - Manual export. You can export your data as a file via the Android share sheet. Where that file goes (Drive, Gmail, another app) is entirely your choice. The exported file is plaintext; treat it with the same care as any other personal document.
What we do not run: no analytics (no Firebase Analytics, Mixpanel, Amplitude, PostHog), no crash reporting (no Sentry, Crashlytics, Bugsnag), no advertising SDKs, no fingerprinting. The app does not contact a Linism server, because no such server exists.
4.4 Legal basis for processing
- Art. 9 (2) (a) GDPR (explicit consent for special-category data): for Android Health Connect access. You grant this through the Health Connect permission flow and can revoke it at any time in the Health Connect app or in Android Settings > Apps > Health Connect.
- Art. 6 (1) (a) GDPR (consent): for microphone, location (both foreground and the opt-in background-while-pocketed capture), notifications on Android 13+, the optional Garmin integration, and the optional Place Insights lookup.
- Art. 6 (1) (b) GDPR (contract performance): for processing strictly necessary to provide the features you enable, including local processing of data you enter into the app and Google Play subscription handling.
4.5 Retention and deletion
Because data stays on your device, you remain in direct control of its lifetime. You can delete individual entries, reset categories from the app's settings, or use "Delete All Local Data" to wipe everything and destroy the Android Keystore master key — rendering any residual ciphertext mathematically unrecoverable (cryptographic erasure). Uninstalling the app has the same effect on the encrypted store; Android also clears the app's private files directory.
Automatic retention: on top of that, time-stamped history is deleted from your device on a rolling schedule. Health readings and daily records (for example heart rate, HRV and sleep readings, noise levels, mood and social-battery entries, pain and symptom logs, and day reflections) are deleted after 60 days. Stress readings, including the heart rate, HRV and sound levels attached to them, and stress-location records are deleted after 30 days; resolved place insights after 60 days. Calendar appointments follow the same calendar window: past appointments are deleted with it, while future appointments stay until they have passed and age out. Routines and their execution records, time-blindness destinations and travel records, and learned summaries (for example your personal baselines) are kept until you delete them, because they carry streaks and long-term self-knowledge rather than raw measurements. Data exports therefore cover at most the last 60 days, plus any future appointments you have planned.
5. Your rights under GDPR
You have the following rights regarding personal data we process:
- Right of access (Art. 15 GDPR). Because your app data is on your device, you can already view it inside the app and export it via the share sheet. For any data we hold (for example, your support email correspondence), write to hello@linism.app.
- Right to rectification (Art. 16 GDPR). Edit your entries directly in the app.
- Right to erasure (Art. 17 GDPR). Delete entries in the app, or uninstall the app to wipe all locally stored data and the encryption key.
- Right to restriction (Art. 18 GDPR) and right to object (Art. 21 GDPR). Revoke HealthKit, microphone, location, or notification permissions in iOS Settings, or revoke Health Connect, microphone, location, and notification permissions in Android Settings (Health Connect permissions are managed in the Health Connect app or under Android Settings > Apps > Health Connect).
- Right to data portability (Art. 20 GDPR). Use the in-app export to obtain your data in a machine-readable format.
- Right to withdraw consent (Art. 7 (3) GDPR). Withdraw any of the permissions above at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint (Art. 77 GDPR) with a supervisory authority. The competent authority for Linism is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2 to 4, 40213 Düsseldorf, Germany, ldi.nrw.de.
6. Automated decision-making and profiling
The app computes a local stress score from your health signals (HealthKit on iOS, Android Health Connect on Android — and optionally Garmin) and the ambient noise level, and uses it to decide when to nudge you with a soft notification. This computation runs only on your device, has no legal or similarly significant effect on you in the sense of Art. 22 GDPR, and never leaves your device.
7. Children
Linism is intended to support autistic users of all ages, which may include children. The app does not require account creation and does not collect data online, so we do not knowingly receive personal data from minors. If a minor uses the app on their own device, the data they enter stays on that device. We recommend that parents or guardians supervise app installation, HealthKit / Health Connect consent, and any sharing of exported data.
8. Changes to this policy
We may update this policy when the app or its data practices change. The current version is always available at this URL and dated at the top.
9. Contact
Questions about this policy or about your data: hello@linism.app.
Back to home