Privacy Policy - Thryve Quick Health Check

Android and iOS Mobile Application

Effective Date: June 8, 2026 | Version 3.0

1. Identity and Contact Details of the Controller

The controller responsible for the processing of your personal data in connection with the Thryve Quick Health Check application is:

mHealth Pioneers GmbH
Schleiermacherstr. 25
10961 Berlin, Germany
Email: developer@thryve.de
Website: https://www.thryve.health/

For privacy-related inquiries, you may also contact our Data Protection Officer Hannes Schenk at: privacy@thryve.de

2. Scope and Purpose of This Privacy Policy

This Privacy Policy describes how mHealth Pioneers GmbH collects, uses, stores, and otherwise processes personal data when you use the Thryve Quick Health Check mobile application ("the App") on iOS and Android devices. It applies to all users within the European Economic Area (EEA) and to all other individuals whose data is processed under the General Data Protection Regulation (EU) 2016/679 ("GDPR").

The App is a wellness and lifestyle companion providing daily awareness insights across four areas: activity, sleep, mindfulness, and heart-rhythm patterns. It is not a medical device and does not provide medical advice, diagnosis, or treatment.

3. Overview of Data Architecture and Processing Flows

The App processes personal data through three distinct technical pathways. Understanding these flows is central to understanding how your data is handled:

  • Raw device data pathway: Health and fitness data from your wearables and connected health apps is transmitted directly from your device to the Thryve platform via the Thryve SDK. This includes activity, sleep, heart rate, and other sensor data.
  • Score calculation pathway: Your questionnaire responses are sent from your device to a calculation service hosted on Amazon Web Services (AWS) within the European Union. This service retrieves your daily health data from the Thryve platform using your pseudonymous token (not your name or any direct identifier), performs the score calculation, and returns the results directly to your device. No data is retained or stored on AWS infrastructure at any point; processing is transient, typically completing within a few seconds.
  • Video scan pathway: The on-device scan processes video frames locally on your device. Derived biometric metrics (such as heart rate and blood pressure indicators) are uploaded to the Thryve platform. Non-health scan event metadata may be shared with Shen.AI for licensing, usage accounting, analytics, and technical support purposes (see Section 7).

All three pathways use your pseudonymous Thryve token as the sole data identifier. Your name is never transmitted off your device.

4. Categories of Personal Data Processed

4.1 Profile Data You Voluntarily Provide

You may optionally provide the following personal information:

  • Your name: stored locally on your device only and never transmitted to any server or third party.
  • Sociodemographic data (height, weight, gender): uploaded to the Thryve platform via the Thryve SDK using your pseudonymous token, to contextualise and improve the accuracy of your wellness insights.

4.2 Health and Fitness Data from Wearables and Health Apps

With your explicit consent, the App reads health and fitness data from your device's health platform (e.g., Apple Health, Google Fit, Samsung Health) or connected wearables, including:

  • Step count and physical activity metrics
  • Sleep duration and quality data
  • Heart rate measurements
  • Mindfulness or meditation session records

This data is uploaded directly to the Thryve platform via the Thryve SDK. It is also retrieved transiently by the AWS score calculation service when you submit questionnaire responses, solely for the purpose of computing your wellness scores.

4.3 Questionnaire Responses

The App may present you with a short questionnaire covering a mix of lifestyle and health-relevant topics, which may include questions about sleep habits, physical activity, stress levels, energy, and mood. Because some of these responses may relate to your physical or mental health, they are treated as special category data under Article 9 GDPR and processed only on the basis of your explicit consent.

Your questionnaire responses are transmitted from your device to the AWS score calculation service. They are used in combination with your Thryve platform health data to calculate your wellness scores. They are not stored on AWS and are not retained after the calculation is complete.

4.4 Video Scan Metrics (Shen.AI On-Device Processing)

The App includes an optional, on-device wellness scan powered by technology provided by Shen.AI (see Section 7 for details on this third-party provider). During a scan session:

Short video frames are captured and analysed entirely on your device. No video data is ever transmitted off your device. The frames are processed only in memory during the scan and are not stored on your device or anywhere else.

Derived biometric metrics resulting from the scan (such as estimated heart rate, heart rate variability, and blood pressure indicators) are computed on-device and subsequently uploaded to the Thryve platform as part of your wellness data.

Non-health scan event metadata (i.e., the fact that a scan session occurred, without any health or wellness values) is shared with Shen.AI for analytical, technical support and accounting purposes. These include: hardware and hardware components type, data and analytics about your use of the Shen.AI SDK; your device type and the operating system that you use; broad geographic location (e.g. country or city-level location) based on your IP address; qualitative and quantitative metrics of the Shen.AI SDK's performance on your device. The abovementioned data collected automatically are necessary for Shen.AI to operate the Shen.AI SDK.

4.5 Pseudonymous Thryve Token

Upon first use, the App automatically generates and registers a pseudonymous Thryve token with the Thryve server. This token is a randomly generated 64-character string with no relationship to your identity. It is computationally infeasible to derive your identity from the token alone. All data uploaded to the Thryve platform and all data retrieved by the AWS calculation service is associated with this token only.

Notwithstanding its strong pseudonymisation properties, the token remains personal data within the meaning of Art. 4(1) GDPR, as it can in principle be linked back to you through the App. All GDPR protections accordingly apply in full.

4.6 Aggregated and Anonymised Statistical Data

Thryve may derive fully anonymised, aggregate statistical insights from the collective, de-identified data of all App users (for example, cohort-level activity trends across time periods). Such statistics do not identify any individual and are not personal data within the meaning of the GDPR. They may be used for marketing, research, and public communications purposes (see Section 14).

4.7 Technical and Support Data

If you contact us for support, we may process your email address, name (if provided), device type, operating system version, App version, and a description of your issue.

5. Legal Bases for Processing

We process personal data only where a valid legal basis under Art. 6 GDPR exists, and Art. 9(2) GDPR where health data is involved:

  • Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR): The upload of health and fitness data to the Thryve platform, the transmission of questionnaire responses (including health-relevant responses) to the AWS calculation service, the upload of biometric scan metrics, and the upload of sociodemographic data are all carried out on the basis of your explicit, freely given, informed consent. You may withdraw consent at any time (see Section 11).
  • Legitimate interests (Art. 6(1)(f) GDPR): The generation and use of your pseudonymous Thryve token, and the processing of limited technical data necessary for the secure and correct operation of the App and its backend services, are based on our legitimate interest in providing a functional, secure service. These interests do not override your fundamental rights and freedoms, in part because of the strong pseudonymisation measures applied.
  • Legitimate interests — anonymised statistics (Art. 6(1)(f) GDPR): The derivation and use of fully anonymised aggregate statistics for marketing and communication does not involve personal data. To the extent any processing of personal data occurs in the aggregation pipeline prior to anonymisation, our legitimate interest in understanding usage trends provides the legal basis, subject to appropriate safeguards.
  • Legal obligation (Art. 6(1)(c) GDPR): We may process personal data to comply with applicable laws, regulations, or enforceable legal orders.

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.

6. Special Category (Health) Data

The following data processed by the App constitutes special category data under Art. 9 GDPR: health and fitness data from wearables and health platforms; biometric metrics derived from the video scan (heart rate, heart rate variability, blood pressure indicators); questionnaire responses that relate to physical or mental health (including stress levels, energy, and mood); and sociodemographic data (height, weight) where used in combination with health data.

We process all such data exclusively on the basis of your explicit prior consent (Art. 9(2)(a) GDPR), and solely for the purpose of providing you with personalised wellness insights. We do not use special category data for advertising targeting, profiling for purposes unrelated to your wellness, or sale to third parties.

7. Third-Party Data Processors and Service Providers

7.1 Thryve Platform (mHealth Pioneers GmbH)

The Thryve platform, operated by mHealth Pioneers GmbH (the same legal entity as the controller), serves as the central data store for your health, biometric, and sociodemographic data. Data is received directly from the Thryve SDK on your device. The Thryve platform also exposes an API used by the AWS score calculation service to retrieve your daily data (identified by your pseudonymous token) for the purpose of score computation. The Thryve platform runs exclusively on Open Telekom Cloud infrastructure within the European Union (see Section 7.3).

7.2 Amazon Web Services - Score Calculation Service (EU Region)

A score calculation service is operated on Amazon Web Services (AWS) infrastructure located within the European Union. This service is invoked when you submit your questionnaire responses and operates as follows:

  • It receives your questionnaire responses and your pseudonymous Thryve token from your device.
  • It retrieves your daily health data from the Thryve platform API using the pseudonymous token. Account-level API credentials are used to authenticate the request; however, the query is scoped to your individual token, and the service only ever processes the data of one token per invocation.
  • It calculates your wellness scores by combining questionnaire responses with the retrieved health data.
  • It returns the calculated scores directly to your device.
  • No data is written to any AWS storage service. All data handled by the calculation service is held transiently in memory for the duration of the computation (typically a few seconds) and is not persisted after the response is returned.

AWS acts as a data processor on our behalf pursuant to a Data Processing Agreement compliant with Art. 28 GDPR and AWS's standard EU data processing addendum. Because all processing occurs within an AWS EU region, no international transfer under Chapter V GDPR occurs.

7.3 Open Telekom Cloud - Thryve Platform Infrastructure

The Thryve server infrastructure is hosted exclusively on Open Telekom Cloud, operated by T-Systems International GmbH, a wholly-owned subsidiary of Deutsche Telekom AG (Germany). All data is stored and processed on servers physically located within the European Union. Open Telekom Cloud acts as a data processor pursuant to a Data Processing Agreement compliant with Art. 28 GDPR.

7.4 Shen.AI - Video Scan Technology

The on-device scan functionality is powered by technology licensed from Shen.AI. Shen.AI processes all video data exclusively on your device and does not receive any video, facial images, health, or biometric data. In connection with the licensed SDK, Shen.AI collects standard non-health technical and usage data, namely: the occurrence of a scan session; hardware and device type; the operating system you use; broad (country or city-level) geographic location derived from your IP address; and qualitative and quantitative performance metrics of the SDK on your device. This data is used for licensing, usage accounting, analytics, and technical support only, and no health, biometric, or wellness values are included. A data processing or licensing agreement with Shen.AI governs the permissible scope of this exchange.

7.5 No Other Third-Party Sharing

Other than the processors described above, we do not share your personal data with any third party. We do not sell, license, or otherwise disclose personal data to advertisers, data brokers, or unrelated commercial partners.

We may disclose personal data to public authorities or law enforcement agencies where required by applicable law or in response to a legally binding request. Where legally permissible, we will notify you of such a request.

8. International Data Transfers

All personal data processed in connection with the App is handled exclusively within the European Union:

  • Thryve platform data is stored and processed on Open Telekom Cloud servers within the EU.
  • Score calculation processing occurs on AWS infrastructure in an EU region. No data is transferred to AWS data centres outside the EU.
  • No personal data is transferred to any third country in connection with the App's core functionality.

Should any future service engagement require a transfer of personal data outside the EEA, we will ensure that appropriate safeguards are in place under Chapter V GDPR (e.g., Standard Contractual Clauses or an adequacy decision) and will update this Privacy Policy before such transfers begin.

9. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law. By default, all your data is removed 48hrs after creation.

  • Video scan frames (the face data): Not retained. They are processed only in memory during the scan and discarded immediately, and are never written to disk or transmitted off the device.
  • Name: Stored locally on your device only.
  • Health, biometric, and sociodemographic data on the Thryve platform: Retained for as long as your token remains active. To request deletion, contact developer@thryve.de.
  • Questionnaire responses: Not retained. Transmitted transiently to the AWS calculation service and discarded after scores are returned.
  • Wellness scores: Returned to and stored on your device. Also retained on the Thryve platform associated with your token for historical insight purposes.
  • Pseudonymous Thryve token: Retained for the duration of your use of the App and for a reasonable operational period thereafter.
  • Scan event metadata shared with Shen.AI: Retained by Shen.AI in accordance with their own data retention policies, limited to licensing purposes.
  • Support correspondence: Retained for as long as necessary to resolve your inquiry, typically no longer than 24 months.

10. Data Security

We implement appropriate technical and organisational measures under Art. 32 GDPR to protect personal data. These include:

  • On-device processing of all video frames, with only derived metrics transmitted;
  • Pseudonymisation of all server-side data via a randomly generated 64-character token, ensuring no direct link between stored data and your identity;
  • Transient-only processing of questionnaire responses and health data on AWS, with no persistence to any storage layer;
  • Encryption of all data in transit between your device, the Thryve platform, and the AWS calculation service;
  • Exclusive use of EU-based cloud infrastructure for all data storage and processing;
  • Scoped API access in the AWS calculation service, restricted to one token per invocation;
  • Access controls and role-based authorisation limiting data access to authorised personnel only;
  • Regular review of security practices and data protection impact assessments where required.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required by Art. 34 GDPR, inform affected individuals without undue delay.

11. Your Rights Under the GDPR

Subject to applicable law, you have the following rights:

  • Right of access (Art. 15 GDPR): Request confirmation of whether we process your data and obtain a copy, including details of how it is used.
  • Right to rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17 GDPR): Request deletion of your data where no overriding legal basis exists. Note that questionnaire responses are not retained after processing and cannot be retrieved or deleted after the fact.
  • Right to restriction of processing (Art. 18 GDPR): Request that processing be restricted in certain circumstances.
  • Right to data portability (Art. 20 GDPR): Where processing is consent-based and automated, request a machine-readable copy of your data.
  • Right to object (Art. 21 GDPR): Object to processing based on legitimate interests; we will cease unless we can demonstrate compelling grounds.
  • Right to withdraw consent (Art. 7(3) GDPR): Withdraw consent at any time via your device's permission settings or by contacting us. Withdrawal does not affect prior processing.
  • Right not to be subject to solely automated decision-making (Art. 22 GDPR): We do not make decisions with legal or significant effects based solely on automated processing.

To exercise any of these rights, contact us at: developer@thryve.de. We will respond within one month, with a possible two-month extension for complex or numerous requests (with prior notice).

You have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for mHealth Pioneers GmbH is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstr. 219, 10969 Berlin, Germany
Website: https://www.datenschutz-berlin.de/

You may also lodge a complaint with the supervisory authority in your EU Member State of habitual residence or place of work.

12. Children's Privacy

The App is intended for a general audience. However, the wellness, biometric, and health data processing features are intended for users capable of providing informed, meaningful consent. We do not knowingly process the personal data of children under 16 years of age without verified parental or guardian consent, as required by Art. 8 GDPR and applicable national laws.

If you believe a child has provided personal data without appropriate consent, please contact us immediately at developer@thryve.de and we will promptly delete such data.

13. Cookies, Tracking, and Analytics

The App does not use cookies. The App does not currently employ any third-party advertising SDKs or behavioural tracking technologies. Should this change, we will update this Privacy Policy and seek your prior consent where required.

14. Anonymised Statistics and Marketing Use

Thryve may derive fully anonymised, aggregate statistical insights from the collective, de-identified usage of the App. Examples include population-level wellness trends such as relative activity levels observed across user cohorts during specific time periods. These statistics do not identify any individual user and are produced through aggregation processes designed to prevent re-identification.

Such statistics may be used for marketing communications, public wellness reports, research publications, and similar purposes. Because properly anonymised data falls outside the scope of the GDPR (Recital 26), no consent is required for this use. We are nonetheless committed to transparency about this practice and will not characterise data as anonymised unless it meets recognised standards, such as those described in the Article 29 Working Party Opinion 05/2014 on anonymisation techniques.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technologies, service providers, or legal requirements. Where changes are material, we will notify you via an in-App notification or other appropriate means before they take effect.

The current version is always available within the App and at https://www.thryve.health/legal/privacy-policy. The effective date at the top of this document indicates when the most recent version was adopted.

16. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:

Email: developer@thryve.de
Postal address: mHealth Pioneers GmbH, Schleiermacherstr. 25, 10961 Berlin, Germany

We are committed to resolving all privacy-related concerns promptly and in accordance with applicable law.

This Privacy Policy was prepared in accordance with Regulation (EU) 2016/679 (GDPR). © 2026 mHealth Pioneers GmbH. All rights reserved.