Privacy Policy
This Privacy Policy applies to the website hazeless.de and the Hazeless app (collectively referred to as "Services").
1. Controller (Responsible Party)
Jannik Brose
Brose Media
Kasernengasse 32
88416 Ochsenhausen
Germany
Email: support@hazeless.de
2. Overview of Data Processing
Hazeless is a cannabis harm reduction app designed to support more mindful cannabis use. Protecting your personal data is our highest priority. The app is built on a local-first principle. Your data is only transmitted to our servers or selected service providers where required for account, purchases or features you activate, such as Cloud Sync, Chatpot or push notifications.
We use no advertising, retargeting, or cross-app tracking services, set no advertising cookies, and do not share your data with third parties for marketing purposes. Limited in-app usage analytics only takes place after your voluntary consent. Technical errors may be collected in a data-minimising way to maintain app stability and security.
3. Legal Bases for Processing
Your data is processed on the following legal bases under the GDPR:
- Art. 6(1)(a) GDPR (Consent) – Cloud Sync, Chatpot, marketing emails, push notifications, and optional usage analytics
- Art. 6(1)(b) GDPR (Contract performance) – Providing app features, account management, subscriptions
- Art. 6(1)(f) GDPR (Legitimate interest) – Server log files on website visits, fraud prevention, error diagnosis, and technical stability
- Art. 9(2)(a) GDPR (Consent for special categories) – Health-related data (consumption behaviour, mood, sleep, cravings) is only stored on our servers or processed for Chatpot with your explicit consent
4. Data Processing on the Website
4.1 Hosting
The website is hosted by ALL-INKL.COM – Neue Medien Münnich (owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany). When you visit the website, server log files are automatically recorded:
- IP address (anonymised)
- Date and time of access
- Page accessed and referrer URL
- Browser type and operating system
This data is not merged with other data sources and is deleted after a maximum of 7 days. Legal basis: Art. 6(1)(f) GDPR.
4.2 Fonts
The website uses exclusively self-hosted fonts (Inter). No external font services (such as Google Fonts) are used. No data is transferred to third parties.
4.3 Cookies
The website uses only technically necessary functions (localStorage) to store your cookie consent decision. No tracking cookies or third-party cookies are set.
4.4 Links to App Stores
The website contains links to the Apple App Store. Clicking these links redirects you to Apple's platform, which has its own privacy policy.
5. Data Processing in the App – Local Storage
The following data is generally stored locally on your device. It leaves your device only if you activate optional features such as Cloud Sync or Chatpot, or where required for account, purchases and notifications you allow.
5.1 Profile Data (Onboarding)
- Date of birth and gender
- Personal goal (pause, reduce, quit, track)
- Consumption methods (e.g. joints, vapes, edibles)
- Consumption frequency and quantity (times per week, grams per session)
- THC potency (optional)
- Weekly spending and currency
- Time of first daily consumption
- Main concerns about quitting (e.g. cravings, social pressure)
- Personal motivation
- Baseline values for sleep quality, mood and stress
Purpose: Personalising the app experience and calculating individual KPIs.
5.2 Daily Tracking Data
- Daily check-ins: consumed yes/no, quantity, method
- Mood, sleep quality, craving level (scales)
- Withdrawal symptoms (selection from predefined categories)
- Craving SOS interventions, intensity values and completion status
- Money spent
- Free-text notes (optional)
Purpose: Progress tracking, statistics and pattern analysis.
5.3 Cognitive Test Data
- Reaction times (milliseconds)
- Memory test results
- Stroop test accuracy and interference scores
- Test timestamps
Purpose: Cognitive progress measurement and self-reflection.
5.4 Pause and Streak Data
- Start and end dates of consumption pauses
- Pause status (active, completed, abandoned)
- Calculated statistics (days, savings)
5.5 Gamification Data
- Experience points (XP) and levels
- Completed tasks and milestones
- XP event history (last 40 entries)
Purpose: Motivation and engagement.
5.6 App Settings
- Language, notification preferences, haptic settings
- Reminder times and intensity
- Consent status (Cloud Sync, Chatpot, marketing)
6. Cloud Sync (Optional Data Transfer)
If you enable Cloud Sync, the data described in Section 5 will additionally be stored on our servers. This is entirely optional and requires your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR).
6.1 Service Provider
We use Supabase for cloud storage (Supabase Inc., 970 Toa Payoh North, #07-04, Singapore 318992). The database servers are located in the European Union. Supabase processes data on our behalf under a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.
6.2 Data Transferred
When Cloud Sync is enabled, the following data is synchronised:
- Profile data and onboarding information
- Daily tracking data and check-ins
- Cognitive test results
- Pause data
- Consent logs
6.3 Encryption
All data is encrypted in transit via TLS/HTTPS. Data stored on servers uses server-side encryption.
6.4 Withdrawal of Consent
You can disable Cloud Sync at any time in the app settings. Upon deactivation, all your data is automatically deleted from our servers. Your local data on the device remains unaffected. Legal basis: Art. 7(3) GDPR.
6a. Chatpot (Optional AI Processing)
Chatpot and AI-assisted Craving SOS suggestions are optional premium features. They are only used after you have given separate AI consent in the app. This consent is separate from Cloud Sync and can be withdrawn at any time in the privacy settings.
6a.1 How it works
The app sends your Chatpot message to our Supabase Edge Function. There, consent is checked server-side, a daily limit is applied and the request is forwarded to OpenRouter as an AI routing and model provider. The API key is kept server-side only and is not stored in the app.
6a.2 Data transmitted
Only reduced context signals are transmitted for Chatpot:
- your current Chatpot message and recent messages in the Chatpot conversation
- broad goal and progress signals such as goal, streak days, level and XP
- aggregated 14-day values such as check-in count, average mood, craving and sleep values
- broad states such as active pause, today's tracking status or number of completed pauses
- limited trigger IDs and aggregated Craving SOS relief values
We do not send private notes, exact daily raw logs, minute-level timestamps or payment data to the AI provider.
6a.3 Purpose, legal basis and third-country transfer
The purpose is to provide personalised, supportive Chatpot responses and short Craving SOS plans. The legal basis is your consent under Art. 6(1)(a) GDPR and, where health-related information is involved, Art. 9(2)(a) GDPR. OpenRouter is based in the United States; transfer is based on appropriate safeguards, in particular Standard Contractual Clauses under Art. 46 GDPR.
AI responses do not replace medical, therapeutic or legal advice.
7. Account and Authentication
7.1 Account Creation (Required)
An account is required to use Hazeless. The app cannot be used without registration. During registration and use, we process:
- Email address
- User ID (automatically generated)
- Name (optional)
- Registration timestamp
Purpose: Account management, cross-device synchronisation, data recovery when switching devices. Legal basis: Art. 6(1)(b) GDPR.
7.2 Authentication Methods
Authentication is handled via Supabase Auth. Session tokens are stored securely on your device (Expo Secure Store). We do not store passwords in plain text.
Hazeless also supports Sign in with Apple and Sign in with Google. When using these methods, only authentication tokens (and optionally email address and name, as provided by Apple/Google) are transmitted. No additional personal data from Apple or Google is accessed.
8. In-App Purchases and Subscriptions
We use RevenueCat (RevenueCat Inc., 633 Tarava St Ste 101, San Francisco, CA 94116, USA) for managing premium subscriptions.
8.1 Data Processed
- Anonymised user ID
- Subscription status (active/inactive)
- Purchase history and transaction data
- Entitlements (unlocked premium features)
Purpose: Subscription management, providing premium features, purchase restoration. Legal basis: Art. 6(1)(b) GDPR.
8.2 Payment Processing
If you purchase a subscription on iOS, payment processing is handled by the Apple App Store. We have no access to your payment data (credit card numbers, bank details, etc.).
8.3 Data Transfer to the USA
RevenueCat is based in the USA. Data transfer is made on the basis of the EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46(2)(c) GDPR).
9. Push Notifications
Hazeless uses local notifications for reminders scheduled directly on your device. If you enable notifications and allow them in your system settings, an Expo push token may also be stored in Supabase so that we can send server-side notices, for example for unlocked Pro campaigns or important app information.
We store user ID, push token, platform, app version, enabled status and registration or update timestamps. We use Expo Push Notification Services for delivery. You can disable notifications at any time in the app settings or in your device's system settings; in that case we mark the token as disabled.
9a. Email Delivery (Resend)
For sending transactional emails (e.g. confirmations, password resets), we use Resend (Resend Inc., 2261 Market Street #4913, San Francisco, CA 94114, USA).
The following data is transmitted to Resend:
- Recipient's email address
- Content of the respective email (e.g. confirmation link)
Resend processes this data exclusively for the purpose of email delivery on our behalf. Data transfer to the USA is based on Standard Contractual Clauses (Art. 46(2)(c) GDPR). Legal basis: Art. 6(1)(b) GDPR.
10. Device Permissions
Hazeless requests only the following permissions:
| Permission | Purpose |
|---|---|
| Notifications | Reminders for daily tracking |
| Internet access | Cloud Sync (optional), authentication, subscription management, Chatpot and push token registration |
Hazeless does not access your camera, location, contacts, calendar, microphone, photos or other sensitive device data.
11. Usage Analytics and Error Diagnostics
11.1 Optional usage analytics with PostHog
If you expressly consent in the app, we use PostHog (PostHog Inc., USA) for pseudonymous product analytics. Processing takes place in the EU Cloud in Germany selected by us. Without consent, the PostHog client is not activated and no usage events are sent to PostHog.
Only the following are transmitted:
- events relating to onboarding, the paywall, checkout, and initial app use
- limited event parameters such as step, product, package, source, or error codes
- platform, app version, and a pseudonymous technical identifier
Consumption information, health data, private notes, chat content, and other free text are technically excluded from transmission. PostHog may also process technical connection data such as the IP address when establishing a connection. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time under “Settings → Privacy & Consents” with effect for the future. Withdrawal resets the local analytics identity. To request deletion of events already stored, contact support@hazeless.de.
11.2 Error diagnostics with Sentry
We use Sentry (Functional Software, Inc. d/b/a Sentry, USA) in its Germany region to detect and resolve technical errors. When an error occurs, the error type, stack trace, affected app area, app version, and device and operating-system information may be transmitted. Default personal information transmission is disabled in the SDK; session replay and advertising profiles are not used. Consumption, health, chat, and free-text data must not be sent to Sentry. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is maintaining the security, stability, and reliability of the app. You may object on grounds relating to your particular situation.
Neither PostHog nor Sentry is loaded on the Hazeless website itself. Google Analytics, Firebase Analytics, Meta Pixel, advertising networks, and retargeting services are not used.
12. Overview of Third-Party Services
| Service | Purpose | Server location | Legal basis |
|---|---|---|---|
| Supabase | Auth, Cloud Sync, Edge Functions, push token and promo management | EU | Art. 6(1) a/b |
| RevenueCat | Subscription management | USA (DPF) | Art. 6(1) b |
| PostHog | Optional pseudonymous in-app usage analytics | Germany (EU Cloud; US provider, DPF/SCC) | Art. 6(1) a |
| Sentry | Error diagnostics and app stability | Germany region (US provider, DPF/SCC) | Art. 6(1) f |
| OpenRouter | Chatpot and AI SOS responses | USA (SCC) | Art. 6(1) a, Art. 9(2) a |
| Expo Push Notification Services | Push notifications | USA / international | Art. 6(1) a |
| Apple App Store | Distribution, payment | USA (DPF) | Art. 6(1) b |
| All-Inkl | Website hosting | Germany | Art. 6(1) f |
| Resend | Email delivery | USA (SCC) | Art. 6(1) b |
| Apple Sign-In | Authentication | USA (DPF) | Art. 6(1) b |
| Google Sign-In | Authentication | USA (DPF) | Art. 6(1) b |
13. Special Categories of Personal Data
Hazeless processes health-related data within the meaning of Art. 9 GDPR, including information about consumption behaviour, mood, sleep quality, craving level and withdrawal symptoms.
This data is processed and stored locally on your device by default. Transfer to our servers or the AI provider only occurs with your explicit consent (Cloud Sync or Chatpot activation). Legal basis: Art. 9(2)(a) GDPR.
Hazeless does not access Apple Health (HealthKit) or comparable fitness and health services and does not read or write data from or to these services.
14. Data Retention
| Data | Retention period |
|---|---|
| Local app data | Until app is uninstalled or manually deleted |
| Cloud Sync data | Until consent is withdrawn or account deleted |
| Account data | Until account deleted |
| Purchase data (RevenueCat) | As required by law (up to 10 years) |
| Chatpot requests and ai_usage counters | For technical delivery, rate limits and abuse prevention; consent and usage until withdrawal or account deletion |
| Push tokens | Until notifications are disabled or account is deleted |
| Server log files (website) | Maximum 7 days |
| Consent logs | 3 years (evidence under GDPR) |
15. Data Deletion and Account Deletion
15.1 Account Deletion
You can delete your account at any time directly in the app under Settings → Delete Account. Upon deletion, all data stored on our servers is irrevocably deleted:
- Profile and onboarding data
- All tracking data and check-ins
- Pause data
- Account information and authentication data
Deletion is protected by double confirmation and executed immediately.
15.2 Disabling Cloud Sync
When you disable Cloud Sync, all data stored on our servers is automatically deleted. Your local data on the device is retained.
15.3 Deleting Local Data
Local data is reset when you sign out of the app. Alternatively, you can uninstall the app to remove all local data.
16. Data Security
- All data transmission via encrypted connections (TLS/HTTPS) only
- Authentication tokens stored securely in the device keychain (Expo Secure Store)
- AI API keys stored only as server-side secrets in Supabase Edge Functions
- Server-side encryption of cloud data
- Row-Level Security (RLS) in the database — each user can only access their own data
- No passwords stored in plain text
17. Use by Minors
Hazeless is intended exclusively for persons who are at least 18 years old. Age confirmation is obtained during onboarding. We do not knowingly collect data from minors. If we discover that data has been collected from a minor, we will delete it immediately.
18. Contact by Email
When you contact us by email (support@hazeless.de), your information including the contact details you provide will be stored for the purpose of processing the enquiry and for any follow-up questions. We will not share this data without your consent. Legal basis: Art. 6(1)(b) GDPR.
19. Your Rights (Art. 15–21 GDPR)
You have the following rights regarding your personal data at any time:
- Access (Art. 15 GDPR) – What data we have stored about you
- Rectification (Art. 16 GDPR) – Correction of inaccurate data
- Erasure (Art. 17 GDPR) – Deletion of your data ("right to be forgotten")
- Restriction (Art. 18 GDPR) – Restriction of processing
- Data portability (Art. 20 GDPR) – Receiving your data in a machine-readable format
- Objection (Art. 21 GDPR) – Objecting to processing
- Withdrawal of consent (Art. 7(3) GDPR) – At any time with effect for the future
To exercise your rights, contact us at: support@hazeless.de
You can also delete your cloud data and account directly in the app (Settings → Delete Account).
20. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
An overview of all authorities can be found at:
www.bfdi.bund.de
21. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy as necessary to reflect changes in law or in the Services. The current version is always available on this page and in the app. We will notify you of material changes within the app.
Last updated: July 16, 2026