This policy explains what personal data TYTTRA collects, why we collect it, who we share it with, how long we keep it and the rights you have under the EU General Data Protection Regulation and Portuguese law.
1. Who we are
TYTTRA Holdings (“TYTTRA”, “we”, “us”) is the controller of your personal data.
Registered office: Rua da Prata 80, Lisboa, Portugal. Privacy contact: support@tyttra.app.
This policy applies to the TYTTRA app, our website and the subscription service through which we compose and ship your supplement protocol.
2. What we collect
Account details. Name, email address, password (stored hashed, never readable by us), language and time zone.
Your quiz answers. Your answers to the TYTTRA assessment, including age band, sex, lifestyle, sleep, energy, stress, diet, symptoms, validated questionnaire scores, current medication and supplement use, pregnancy or breastfeeding status and other safety screening answers. Many of these answers are health data.
Your protocol and progress. The protocol we compute for you, the reasons behind each ingredient, doses you mark as taken, daily check-ins, reassessments, milestones and your BioScore.
Wearable signals (optional). Only if you connect a device (Whoop, Oura, Garmin, Apple Health or Health Connect), we read overnight heart rate variability, sleep depth and latency, resting heart rate, VO₂ max, skin temperature and recovery or readiness score. We do not read your location or GPS data, individual workouts or body weight.
Subscription and payment information. Your plan, billing cadence, invoices, promotion codes and payment status. Card details are entered directly into our payment provider, Stripe. TYTTRA never sees or stores your full card number.
Delivery information. Shipping name, address, phone number (if given to the carrier) and delivery preferences. Your address is used only for shipping and invoicing.
Communications. Messages you send to support and your notification and email preferences.
Device and usage data. App version, device type, operating system, crash reports and in-app events. Usage events never contain your raw quiz answers or raw health values.
Consent records. A log of each consent you give or withdraw, with the date and policy version, so we can prove we respect your choices.
3. Why we use it and our legal basis
- We use account details to create and run your account, based on performance of a contract (Art. 6(1)(b)).
- We use quiz answers, progress and wearable signals to compute your protocol and BioScore, based on your explicit consent to process health data (Art. 9(2)(a)) and performance of a contract (Art. 6(1)(b)).
- We use quiz answers, medication and safety answers for safety screening, such as flagging interactions or pausing a protocol, based on your explicit consent (Art. 9(2)(a)).
- We use subscription and payment information to take payments and manage your subscription, based on performance of a contract (Art. 6(1)(b)).
- We use name, billing address, tax number and invoice data to issue and keep invoices, based on a legal obligation (Art. 6(1)(c)).
- We use account details, communications and relevant order data for customer support, based on performance of a contract (Art. 6(1)(b)).
- We use device and usage data and audit logs for security, fraud prevention and keeping the service working, based on legitimate interests (Art. 6(1)(f)).
- We use usage events without raw health data for product analytics, with your consent where required (Art. 6(1)(a)).
- We use de-identified, aggregated data for anonymous cohort analytics to improve protocols, based on your consent (Art. 9(2)(a)).
- Marketing emails use your email address only with your consent (Art. 6(1)(a)) and are off by default.
Health data consent is required to use TYTTRA because we cannot compose a protocol without it. You can withdraw it at any time in Privacy & data. Withdrawing consent ends our ability to provide the service, so your subscription will be cancelled at the end of the current period.
We do not sell your data. We do not use your health data for advertising, and we do not share it with advertisers.
4. How your protocol is decided
TYTTRA is a supplement service, not a medical service.
Your protocol is generated automatically by the TYTTRA engine, a set of documented rules that combine your quiz answers, safety screening and, if connected, wearable signals. Our rules and dose ranges are reviewed by qualified professionals.
Your protocol does not have legal effects on you. Even so, you can always ask us to explain why an ingredient was included or excluded, express your point of view or request that a person reviews your protocol. Write to support@tyttra.app.
5. Wearable connections
Connecting a wearable is optional and read only. We never write data to your device or provider account.
For Apple Health and Health Connect, data is read on your device with the permissions you grant in your phone settings.
For Whoop, Oura and Garmin, you authorise TYTTRA through the provider’s own sign in. The access credentials that allow us to read your data are stored securely and encrypted, and are never shared with third parties.
You can disconnect a wearable at any time in the app. When you do, we revoke our access with the provider and stop collecting new data. The provider’s own privacy policy governs the data it holds about you.
6. Who we share it with
We share personal data only with service providers that help us run TYTTRA, under written data processing agreements, and only as far as needed for their task. These include providers for hosting and database services, payments (Stripe), email delivery, shipping, app notifications, product analytics and error reporting.
Analytics and error reporting providers never receive your raw health data.
An up to date list of our service providers is available on request at support@tyttra.app.
We may also disclose data when required by law, to a court or public authority, or to protect our rights. If TYTTRA is involved in a merger or acquisition, your data may transfer to the new owner, who must continue to respect this policy.
7. Where your data is stored
Your data is hosted in the European Union (Frankfurt, Germany). Where a provider may access or process data outside the European Economic Area, for example in the United States, we rely on an adequacy decision such as the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses, together with additional safeguards where needed.
8. How long we keep it
Account, protocol, progress and wearable data is kept while your account is active.
After you cancel your subscription without deleting your account, your data is kept for 60 days so you can reactivate. After that, your health and wearable data is deleted or irreversibly anonymised.
After you request deletion, access is removed immediately and your data is permanently erased within 30 days.
Quiz answers started without creating an account are kept for 30 days, then deleted. Invoices and billing records are kept for 10 years as required by Portuguese tax law, stored separately from your health data.
Consent and deletion records are kept in pseudonymised form as proof of compliance. Support messages are kept for 2 years after the conversation ends. Backups are overwritten on a rolling cycle of up to 35 days.
9. Your rights
You have the right to access your data and get a copy of it; correct inaccurate or incomplete data; delete your data; export your data in a portable format; restrict or object to certain processing, including processing based on our legitimate interests; withdraw consent at any time without affecting processing that happened before; and not be subject to decisions based solely on automated processing that significantly affect you, including the right to ask for human review.
You can access, export, correct or delete your data at any time from Privacy & data in the app, or by writing to support@tyttra.app. We reply within one month. We may ask you to confirm your identity first.
You also have the right to lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt, or with the authority in the EU country where you live or work.
10. How we protect it
We encrypt data in transit and at rest, restrict access to the few team members who need it, keep an audit trail of sensitive actions, use role-based access controls in our database and never copy real customer data into development or test environments.
Card payments are handled by Stripe, a PCI DSS certified provider. No system is perfectly secure, but if a breach affects your data we will notify you and the CNPD as the law requires.
11. Notifications and marketing
App notifications, such as dose reminders and check-ins, can be changed or turned off in the app or in your phone settings. Marketing emails are off by default and are only sent if you opt in. Every marketing email includes an unsubscribe link.
12. Cookies and similar technologies
Our app and website use technologies that are strictly necessary for them to work, such as keeping you signed in. We use analytics or similar technologies only with your consent where the law requires it, including Apple’s App Tracking Transparency permission on iOS.
You can change your choices at any time in the app settings, in your browser or in your phone settings.
13. Age
TYTTRA is only for adults aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
14. Changes to this policy
We may update this policy when our service or the law changes. We will show the date and version at the top. If a change is significant, or requires new consent, we will tell you in the app or by email before it takes effect.
Questions about your data or this policy? Contact support@tyttra.app.
TYTTRA Holdings · Rua da Prata 80, Lisboa · Portugal.