← Home

PRIVACY & SECURITY

Your data. Your course. Your decision.

If you keep track of your course, you write down things you often don't even tell people close to you: sleepless nights, forgotten pills, thoughts from difficult phases. Data like this is among the most sensitive there is.

That's why, at PHASE, data protection is not an add-on at the end of development but part of it from the start. Our benchmark is the requirements for DiGA (digital health applications that can be prescribed in Germany) — even though PHASE is still a prototype today.

Our data protection principles

You decide.

Your entries belong to you. Whether and what clinicians or family and friends can see is up to you — area by area, and you can withdraw it at any time.

Only what is needed.

PHASE only collects what is really needed for your course. No selling of data, no advertising. Research only anonymised and only with your consent.

Stored securely.

Your data is encrypted in transit and at rest. For approval, we are planning a server location in the EU.

Proven, not promised.

Data protection has to be provable. That's why we are building the required evidence step by step — up to an information security audit based on the requirements of the German Federal Office for Information Security (BSI) for digital health applications.

Where we stand today.

Trust doesn't come from big promises, but from steps you can follow. That's why we are open about what is already in place — and what is still to come.

TODAY

  • Prototype in daily use
  • Data stored in a cloud database
  • AI features purely descriptive, no diagnoses
  • Not yet approved as a medical device

ON THE WAY

  • Server location in the EU
  • Data processing agreements and data protection impact assessment
  • Information security according to BSI requirements for DiGA (TR-03161)
  • Approval as a medical device (MDR)