Last updated: September 28, 2026
Privacy policy
This privacy policy applies to the Rena app and to this website. It explains what data is processed, for what purpose, and what rights you have.
1. Controller
The controller responsible for data processing is Amin Jaoui, 6020 Innsbruck, Austria. Email: jaouiamin@gmail.com.
2. Core principle: local first
Rena stores all entries, including blood pressure readings, medications, drink and meal logs, symptoms, documents, appointments, tasks and notes, in a database on your device. As long as you don't create an account or connect third-party services, this data never leaves your device.
The app contains no advertising, no analytics or tracking tools, and does not share data for advertising or marketing purposes.
3. Health data
Much of the data in Rena is health data within the meaning of Art. 9 GDPR. Where we process it on our servers (only when sync is enabled), we do so solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give when enabling sync and can withdraw at any time by turning sync off or deleting your account.
4. Account and sync (optional)
If you create an account, we process your email address, a password (stored only as a hash) and the profile details you provide during onboarding (first name, sex, date of birth). With sync enabled, your entries and attachments are transferred encrypted (TLS) and stored with our processor Supabase Inc. Access rules restrict the data to your account.
The purpose is to make your data available on multiple devices and to restore it. The legal bases are Art. 6(1)(b) GDPR (contract) and, for health data, Art. 9(2)(a) GDPR (consent). Where data is processed outside the EU, this is based on the EU Standard Contractual Clauses.
You can delete your account in the app at any time. This permanently removes your account and all synced data and attachments from the server.
5. Google Calendar and Google Tasks (optional)
If you connect Rena to your Google account, the app receives OAuth access to your calendar events (calendar.events scope) and tasks (tasks scope). Events and tasks are exchanged directly between your device and Google. We do not receive this data on our own servers.
Rena's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The data is used only for syncing, is not shared with third parties and is not used for advertising. You can disconnect at any time in the app settings or at myaccount.google.com.
6. Apple Health (optional, iOS only)
With your permission, Rena reads steps, active energy and heart rate from Apple Health to display them on your Today screen. Rena does not write any data to Apple Health. This data stays on your device, is not synced, is not shared with third parties and is not used for advertising. You can revoke access at any time in the Health app.
7. Other app features
- Calendar subscriptions (ICS): Rena fetches the calendar address you enter directly from its provider. Your IP address is visible to that provider.
- Reminders are scheduled as local notifications on your device. There is no push server.
- App lock uses your operating system's Face ID, Touch ID or passcode. Rena never receives biometric data.
- Camera and photos are only used when you scan a document or attach an image.
- PDF reports and backups are created on your device. You decide whether and with whom to share them.
8. This website
This website is hosted by Vercel Inc. When you visit it, technically necessary data such as IP address, time, requested page and browser information is processed in server logs (Art. 6(1)(f) GDPR, legitimate interest in secure operation).
We use Vercel Web Analytics and Speed Insights to measure usage. They work without cookies and only collect aggregated, non-personal data. This website does not set any cookies.
9. Contact form and email
If you contact us via the form or by email, we process your name, email address and message to answer your request (Art. 6(1)(b) and (f) GDPR). Form messages are delivered via a webhook to an internal channel at Discord Inc. (USA). Requests are deleted once resolved, at the latest after twelve months.
10. Retention
Local data remains on your device until you delete it or remove the app. We store server-side data for as long as your account exists. After account deletion it is erased unless statutory retention obligations apply.
11. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time with effect for the future. Contact us at jaouiamin@gmail.com.
You may also lodge a complaint with the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at).
12. Changes
We update this privacy policy when the app or legal requirements change. The version published here applies.