OddHuman

Privacy policy

Last updated 5 October 2026

The short version

Who is responsible

OddHuman is made by Peter Lunderbye, Sweden, who is the data controller for the personal data described here. Questions, requests and complaints go to privacy@oddhuman.io.

Your account

The first time OddHuman opens, it creates a private account for you without asking for anything. It is identified only by a random ID. What you enter is backed up to it, so nothing is lost if you lose your phone. If the phone is offline, the app works as normal and the account is created the next time it is online.

If you add an email address, or sign in with Apple or Google, you can sign in on another phone and get everything back. For your account we store:

Why: to provide the app's backup and sync (GDPR Article 6(1)(b), performance of a contract). Security records are kept on the basis of our legitimate interest in protecting accounts (Article 6(1)(f)).

Emails we send

We email you only when you ask for it: a code to confirm the address you add and a code to reset your password. We send no newsletters or marketing.

What never leaves your phone

App updates

To deliver fixes without a new App Store version, the app checks with Expo, our update service, when it starts. That request contains technical information such as the app version, the platform and your IP address. It contains nothing you have entered in the app.

What we don't do

Who processes data for us

We use a small number of service providers. Each only processes data on our instructions, under a data processing agreement.

ProviderWhat forWhere
SupabaseAccounts, sign-in and the database for backup and syncEU (Paris, France)
ResendSending the confirmation and password reset emailsEU (Ireland)
Expo (650 Industries)Delivering app updatesUnited States
AppleDistributing the app (App Store and TestFlight), and Sign in with Apple if you choose itUnder Apple's own privacy policy
GoogleSign in with Google, if you choose itUnder Google's own privacy policy

Where a provider or its subcontractors process data outside the EU and EEA, the transfer is protected by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.

How long we keep it

Your account data is kept until you delete your account. After deletion it is removed from the live database straight away, and from backups within 7 days. When you sign out, your data is removed from that phone; it remains in your account.

If you sign in to an existing account on a phone where you had already started, what you entered there is added to that account.

Your rights

Under the GDPR you can ask for a copy of your data (including in a machine-readable format), have it corrected or deleted, restrict or object to its processing, and withdraw any consent you have given. Write to privacy@oddhuman.io and we will answer within one month.

You can delete your account at any time inside the app: Settings → Your account → Delete account. If you never added an email, the link is called Delete my data. It deletes everything at once, from our servers and from your phone. You can also write to us.

If you believe we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or the authority where you live.

Security

Data is encrypted in transit. In the database, every row is tied to its account and can only be read by that account. Your sign-in session is kept in your phone's secure keychain.

Children

OddHuman is not intended for children under 13, and we do not knowingly collect data from them.

Changes

When OddHuman changes what it does with data, we update this page and the date at the top. For significant changes, we will also tell you in the app before they take effect.