Privacy policy
Weighbridge processes weight and body composition data. That is health data under Article 9 GDPR and carries the strongest protection the regulation offers. This page says plainly what is processed and why.
Controller
[NAME], [STRASSE], [PLZ ORT], Germany. Email: [E-MAIL]
What is processed
To provide the service:
- Your email address and a password hash (scrypt; the password itself is never stored)
- Your scale's readings: weight, body fat, muscle mass, bone mass, hydration, visceral fat, basal metabolic rate, metabolic age and BMI, each with a timestamp
- Access tokens for Withings and Garmin, encrypted with AES-256-GCM
- Settings, subscription status, and a record of which syncs ran
- A push subscription, if you turned notifications on
- Server logs including your IP address, for at most 30 days
- Rate-limiting counters keyed by an irreversible hash of your address or IP, kept for at most two days and readable only as a count
Your Garmin password
Garmin offers third parties no official way to be granted write access. Your Garmin credentials are therefore accepted once, at linking time, sent to Garmin solely to create a session, and then discarded. They are not stored and not logged. Only the resulting session token is kept, encrypted.
Withings does not have this problem: it uses OAuth, so no Withings password is ever transmitted.
Legal bases
Account data is processed under Article 6(1)(b) GDPR — performance of a contract.
Health data is processed on the basis of your explicit consent under Article 9(2)(a) GDPR. You give it by connecting your Withings account; without it the service cannot do the only thing it does. You may withdraw it at any time with effect for the future by disconnecting the provider or deleting your account.
Server logs are processed under Article 6(1)(f) GDPR — the legitimate interest of keeping the service secure and working.
Recipients and processors
Your data is not sold and not shared for advertising. The following are involved:
- Vercel Inc. (USA) — application hosting, under a data processing agreement and EU standard contractual clauses
- Neon Inc. (USA), database located in the EU (Frankfurt) — storage of all account and measurement data
- Paddle.com Market Ltd. (United Kingdom) — payment processing as merchant of record; receives your email address and payment details, and no health data
- Resend Inc. (USA) — transactional email; receives your address and the content of the message
- Functional Software, Inc. dba Sentry (USA) — error monitoring, under a data processing agreement and EU standard contractual clauses. It receives technical fault reports: the error, where in the code it happened, and the page it happened on. Request bodies from the sign-in, linking, checkout and callback routes are discarded before sending, as are all cookies and any field that looks like a credential. No measurement data is sent.
- Withings SA (France) and Garmin Ltd. (Switzerland/USA) — the services you connected yourself, between which the data moves
- Your browser's push service (Google, Apple or Mozilla) if you enabled notifications; payloads are end-to-end encrypted
Transfers outside the EU
Some of the above are established outside the EU. Transfers rely on the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. The measurement data itself is stored in a database in Frankfurt.
Retention
Measurements and account data are kept for as long as your account exists, and removed in full immediately when you delete it.
Billing records are the exception: German commercial and tax law requires them to be kept for ten years. They contain no health data.
Server logs are deleted after at most 30 days.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).
Two of them are built into the application: “Download my data” produces a complete JSON export, and “Delete my account” removes everything. For the rest, an email to [E-MAIL] is enough.
You also have the right to lodge a complaint with a supervisory authority, normally the one where you live.
What stays in Garmin
Measurements already written to Garmin live in your Garmin account and are governed by Garmin's privacy policy. Once the connection is removed or your Weighbridge account is deleted, there is no longer any way to reach them — they can then only be removed in Garmin Connect itself. If you want both gone, delete them there first.
No automated decision-making
There is no profiling and no automated decision-making within the meaning of Article 22 GDPR. The monthly report is a summary of your own numbers, not an assessment of them.
Last updated 24 August 2026. This is a courtesy translation; the German version is the binding one.