Privacy Policy for the App "Ally"
Version: 04.05.2026
Scope: Mobile App "Ally" (iOS/Android)
1. Controller
Aumio GmbH
Mühlenstraße 8a
14167 Berlin
Germany
This privacy policy is also available online at:
https://www.ally.aumio.com/datenschutzerklarung-app
2. Data Protection Officer
External Data Protection Officer (DPO): Graham Reilly (Workstreet)
E-Mail: graham.reilly@workstreet.com
Internal Data Protection Coordinator: Steffen Scherf (Aumio GmbH)
E-Mail: datenschutz@aumio.de
3. General Information on Data Processing
We process personal data to provide the app "Ally". "Ally" is an AI-powered wellbeing coach app for preventive support of wellbeing and health.
Ally does not provide medical diagnosis or treatment and is not a medical device within the meaning of the EU Medical Device Regulation (MDR).
Users may enter content in free-text fields. We do not specifically request health data and recommend not entering sensitive medical information. However, users may voluntarily share information that qualifies as health data within the meaning of Art. 9 GDPR.
Processing is based on the following legal bases, depending on the function:
- Art. 6(1)(b) GDPR (performance of a contract)
- Art. 6(1)(a) GDPR (consent)
- Art. 6(1)(f) GDPR (legitimate interest)
- Art. 9(2)(a) GDPR (explicit consent)
4. Consent
The consent screen is located in the onboarding. Services (analytics/tracking/third-party SDKs) are only started after consent has been given.
The processing of chat content is the core function of the app and is carried out for the provision of the service (performance of contract). Consent is obtained separately for optional processing (e.g. training/improvement).
Consent can be withdrawn at any time with effect for the future.
5. Target Audience / Age Restriction
"Ally" is aimed at adults. The app is intended for persons aged 18 and over. During onboarding, there is an age query (soft gate). If "< 18" is selected, a notice is displayed ("Ally is for ages 18+") and the user is returned to the previous page.
6. What Data We Process
6.1 Account and Profile Data
- Email address
- Name/display name (if applicable)
- Age (>18)
- Language
- Coaching preferences
Purposes: Providing user account, onboarding/personalization, app functionality.
Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(a) GDPR for optional personalizations.
6.2 Chat and Content Data (Free Text)
The following is processed:
- Chat messages
- AI responses
- Conversation objects
- Summaries ("Memories"), topics, recommendations
All information entered in the app (text or voice) is processed to provide the service. This may include sensitive data including health-related information if users choose to share such information in the chat.
We do not specifically collect health data through mandatory fields; the processing of such content occurs contextually through the free input of users. Users are responsible for what information they share.
Note: "Ally" is not a medical device and does not provide medical diagnosis or treatment. We recommend not sharing sensitive medical records or detailed health data. Responses are generated automatically by AI and are not individually reviewed by human professionals. AI-generated content may be incomplete or inaccurate and is not suitable as a sole basis for decisions.
Storage: Chat content is stored to ensure conversation continuity, personalization and technical provision of the app function.
Purposes: Providing chat functionality, context across conversations, personalization, quality improvement.
Legal basis: Art. 6(1)(b) GDPR; where health data is concerned, additionally Art. 9(2)(a) GDPR (explicit consent).
6.3 Health Data
During use, depending on inputs in the chat, information may be processed that allows conclusions about physical or mental health.
Purposes: Providing app functionality (coaching/AI chat) and appropriate interaction in the usage context.
Legal basis: Where health data is concerned, Art. 9(2)(a) GDPR (explicit consent) in conjunction with Art. 6(1)(b) GDPR.
Note: This section serves transparency, as users may share content in free text that qualifies as health data. We do not collect such data through mandatory fields.
6.4 Device and Technical Data
We process technical data for provision, stability and security:
- OS / app version
- Push token
- Device information
Purposes: Operation, security, error analysis, push delivery.
Legal basis: Art. 6(1)(b) GDPR and/or Art. 6(1)(f) GDPR.
6.5 Usage and Analytics Data
Depending on integration, we process events related to usage and stability of the app, e.g.:
- App events
- Sessions
- Feature usage (analytics)
- Crash reports
- Performance metrics
Purposes: Product improvement, stability, bug fixing, usage evaluation.
Legal basis: Art. 6(1)(a) GDPR (consent), where tracking/analytics is used.
Note: Analytics/tracking services are only started after consent.
6.6 Payment Data
Subscriptions and payments are handled through App Store / Play Store.
Additionally, the following providers are used for subscription management/validation:
- RevenueCat (USA)
- Purchasely (EU)
Purposes: Subscription management, activation of premium features, receipt validation.
Legal basis: Art. 6(1)(b) GDPR; legal retention obligations may apply.
6.7 Support (Freshdesk)
For support requests, we process:
- Name
- Ticket content
Purpose: Processing support requests and bug reports.
Legal basis: Art. 6(1)(b) GDPR (contract/support) or Art. 6(1)(f) GDPR.
Support channel: Users can reach support via our Freshdesk service page:
https://heyally.freshdesk.com/de/support/home
7. How AI Is Used
7.1 Server-Side AI Processing
To generate responses, chat content is transmitted to our AI service providers OpenAI (USA) for text and speech processing and ElevenLabs (EU/USA) for speech processing. The transmitted content is processed exclusively for generating the respective AI response, stored only temporarily and not used for training AI models.
Chat inputs and necessary context are transmitted. We only transmit the content required for the respective response (data minimization). PII redaction is performed by default before transmission.
OpenAI does not use this data for training its own models.
7.2 Voice Features
When using voice features, audio/speech data may be processed (STT/TTS). Processing is exclusively temporary for the provision of the respective function.
7.3 Training / Improvement of AI Systems
Principle: Without prior consent, no content from user chats is used for training purposes.
Voluntary consent: With explicit, voluntary consent, selected data may be used to improve AI systems. Consent can be withdrawn at any time in the app (opt-out). Withdrawal takes effect for the future.
Data minimization: Where possible, training data is anonymized or pseudonymized.
Retention: Chat and conversation data is generally stored as long as the user account exists. After deletion of the user account, the associated data is deleted.
7.4 Safety and Crisis Detection
To support user safety, Ally may automatically detect content indicating acute crisis situations to display appropriate support resources.
This serves exclusively for user safety. No medical evaluation, risk scoring, automated profiling or profiling for advertising/marketing purposes takes place.
8. Recipients / Data Processors
We use service providers as data processors. Relevant recipients:
- Google/Firebase (EU region: europe-west3): Auth, Firestore, Remote Config, Analytics, Crashlytics, Performance, FCM
- Render (Frankfurt): Backend hosting (FastAPI)
- OpenAI (USA): AI chat and STT/TTS; processing exclusively for generating responses, temporary, under contractual data protection guarantees.
- ElevenLabs (EU/USA): Speech processing (TTS); exclusively temporary processing.
- LangSmith (EU): Tracing/observability incl. input/output (typically redacted)
- Mixpanel (EU): Analytics
- CleverTap (EU): Analytics, Push, App Inbox, Email
- Freshdesk (EU): Support
- RevenueCat (USA): Subscription/IAP management
- Purchasely (EU): Subscription/IAP management
Advertising/Ads: No advertising or ads SDKs are used.
9. Third Country Transfers
For transfers to third countries, appropriate safeguards pursuant to Art. 46 GDPR are used, in particular EU Standard Contractual Clauses (SCC).
Where providers are certified under the EU-US Data Privacy Framework, the transfer is based on this framework.
10. Storage & Retention Periods
Account data as well as chat and conversation data is generally stored as long as the user account exists to enable conversation continuity, personalization and provision of the app function. After deletion of the user account, the associated data is deleted, unless legal retention obligations apply.
11. Push Notifications
Technology: Firebase Cloud Messaging (FCM) and APNs; additionally CleverTap Push/App Inbox.
Content: Title, text, optionally image/sound.
Opt-in/Opt-out: Via operating system settings and app settings.
12. Rights of Data Subjects
Data subjects have – where applicable – the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR) with effect for the future
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Withdrawal of consent: Consent can be withdrawn at any time with effect for the future. Where the explicit consent to the processing of health data (Art. 9 GDPR) is concerned and this processing is required for the provision of the core function (AI chat), the app cannot be used further without consent.
Requests can be directed to datenschutz@aumio.de.
12a. Automated Decisions
No automated decision-making with legal or similarly significant effect within the meaning of Art. 22 GDPR takes place.
13. Deletion & Data Export
Account deletion: Currently there is no self-service account deletion in the app. Users can request deletion of their account and associated data via support by creating a ticket at: https://heyally.freshdesk.com/de/support/home
Processing period: We process deletion and access requests typically within 30 days.
Identity verification: To prevent misuse, it may be necessary to appropriately verify identity/account association before implementing deletion (e.g. confirmation via registered email address).
Data export / access: A data export or access request can also be made via support. Data is typically provided in a common electronic format (e.g. CSV or JSON). External payment data from app stores is not provided.
14. Security Measures
We implement technical and organizational measures to protect data, including:
- TLS encryption
- Encryption at rest
- Access restrictions
- PII redaction before AI forwarding
- Logging without request/response bodies
15. AI Transparency under the EU AI Act
Ally is an AI-powered application. Users interact with an AI system, not a human person. Content is generated automatically and may be incorrect. Ally is not intended for emergencies and does not replace professional advice or treatment.
16. Changes
The current version is always available in the app and online.
