Last updated 5 October 2026
OddHuman is made by Peter Lunderbye, Sweden, who is the data controller for the personal data described here. Questions, requests and complaints go to privacy@oddhuman.io.
The first time OddHuman opens, it creates a private account for you without asking for anything. It is identified only by a random ID. What you enter is backed up to it, so nothing is lost if you lose your phone. If the phone is offline, the app works as normal and the account is created the next time it is online.
If you add an email address, or sign in with Apple or Google, you can sign in on another phone and get everything back. For your account we store:
Why: to provide the app's backup and sync (GDPR Article 6(1)(b), performance of a contract). Security records are kept on the basis of our legitimate interest in protecting accounts (Article 6(1)(f)).
We email you only when you ask for it: a code to confirm the address you add and a code to reset your password. We send no newsletters or marketing.
To deliver fixes without a new App Store version, the app checks with Expo, our update service, when it starts. That request contains technical information such as the app version, the platform and your IP address. It contains nothing you have entered in the app.
We use a small number of service providers. Each only processes data on our instructions, under a data processing agreement.
| Provider | What for | Where |
|---|---|---|
| Supabase | Accounts, sign-in and the database for backup and sync | EU (Paris, France) |
| Resend | Sending the confirmation and password reset emails | EU (Ireland) |
| Expo (650 Industries) | Delivering app updates | United States |
| Apple | Distributing the app (App Store and TestFlight), and Sign in with Apple if you choose it | Under Apple's own privacy policy |
| Sign in with Google, if you choose it | Under Google's own privacy policy |
Where a provider or its subcontractors process data outside the EU and EEA, the transfer is protected by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
Your account data is kept until you delete your account. After deletion it is removed from the live database straight away, and from backups within 7 days. When you sign out, your data is removed from that phone; it remains in your account.
If you sign in to an existing account on a phone where you had already started, what you entered there is added to that account.
Under the GDPR you can ask for a copy of your data (including in a machine-readable format), have it corrected or deleted, restrict or object to its processing, and withdraw any consent you have given. Write to privacy@oddhuman.io and we will answer within one month.
You can delete your account at any time inside the app: Settings → Your account → Delete account. If you never added an email, the link is called Delete my data. It deletes everything at once, from our servers and from your phone. You can also write to us.
If you believe we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or the authority where you live.
Data is encrypted in transit. In the database, every row is tied to its account and can only be read by that account. Your sign-in session is kept in your phone's secure keychain.
OddHuman is not intended for children under 13, and we do not knowingly collect data from them.
When OddHuman changes what it does with data, we update this page and the date at the top. For significant changes, we will also tell you in the app before they take effect.