Privacy Policy
Embrace Pregnancy — The 2-in-1 of Pregnancy An app by Embrace Life Technologies S.P.A. Società Benefit
As of: July 2026
1. Data Controller
Embrace Life Technologies S.P.A. Società Benefit Bozner Str. 5B, 39044 Neumarkt (BZ), Italy
Email: [email protected] Website: https://embrace-pregnancy.app
2. Overview: Our Data Protection Principles
The protection of your personal data is of utmost importance to us. The Embrace Pregnancy app is designed so that as little personal data as possible leaves your device. Nearly all data you enter in the app — your name, your due date, diary entries, and photos — is stored exclusively on your device and encrypted with the industry-standard AES-256. It does not leave your device. Your chat history is also stored locally; however, as soon as you actively use the AI companion Verena, the chat content — on the basis of your consent — is transmitted to our servers and processed there (see Section 4).
Only when you actively use the AI companion feature or the read-aloud feature is data transmitted for that specific purpose. Details can be found in the sections below.
3. Locally Stored Data (remains on your device)
The following data is stored exclusively on your device and is never automatically transmitted to our servers or third parties:
| Data Category | Specific Content |
|---|---|
| User Profile | Your first name, estimated due date, selected language, display setting (light/dark mode) |
| Diary | Your personal text entries for the journal prompts in the app |
| Bookmarks | Chapters and sections of the companion book you have saved |
| Baby Family Tree | Names of family members, baby names, gender (optional), ultrasound photo (optional), pregnancy test photo (optional) |
Note on chat history: Your chat messages are — like the categories above — stored locally and encrypted on your device. Unlike those categories, however, the chat content is transmitted to our servers when you actively use the AI companion Verena — on the basis of your explicit consent — and stored there for quality and safety analysis for up to 90 days. Details are set out in Sections 4.1 and 4.3.
Encryption
All of the above data — as well as your locally stored chat history — is encrypted locally with AES-256-GCM before being stored on your device. Each device generates a unique encryption key. Photo data is also stored in encrypted form. This locally stored data is not sent to our servers; chat content is transmitted only when you actively use the AI companion, as described in Section 4.
Legal basis:
- Strictly operational data (display setting, selected language): Art. 6(1)(b) GDPR — necessary to provide the app functionality you have requested.
- Health-related data (estimated due date / pregnancy week, diary entries, baby family tree content, chat history): Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR — your explicit consent to the processing of special-category health data, given through the in-app AI consent dialog for the chat feature and through your voluntary use of the corresponding local features. You can withdraw this consent at any time in the settings.
Retention period: Local data remains on your device until you delete it via the app settings, revoke AI chat consent (which clears the chat history), or uninstall the app. No automatic expiry applies.
Data Export (voluntary, user-controlled)
You can export your data at any time as a JSON file to your device. This export file is unencrypted — you are responsible for its safe storage. There is no automatic cloud sync and no cross-device synchronisation.
4. Data Transmitted When Actively Using Certain Features
4.1 AI Companion (Verena)
When you use the AI companion Verena, the following data is transmitted to our servers and from there to our AI service provider:
| Data Point | Description |
|---|---|
| Your message text | The text you enter in the chat function |
| Conversation history | The previous messages of the current chat session (maximum the last 20 messages / 8,000 characters) |
| Pregnancy week | An anonymous number (e.g., “22”), calculated based on the locally stored due date. The due date itself is not transmitted |
No directly identifying data is transmitted — neither your name, nor your due date, nor a device ID or email address. If you have consented to the AI companion, a randomly generated, pseudonymous identifier is additionally sent to group a conversation for the quality and safety analysis — not linked to your name, your email address, or a device ID, and can be reset via “Reset data” in the app. Section 4.3 provides further details.
Data flow:
App on your device -> Embrace Life Technologies server (Bolzano, IT) -> Anthropic (AI provider)
Storage: For the mere forwarding to the AI provider, your messages are processed only for the duration of the request. Beyond that, your conversation — on the basis of your consent to the AI companion — is stored in our self-hosted observability system for quality and safety analysis; you can find details on this in Section 4.3. For processing by Anthropic, their own privacy policy applies (see Section 6).
The chat history on your device is retained until you manually delete it. You can delete it at any time using the reset button in the app.
Legal basis: Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR — your explicit consent to the processing of special-category health data, given through the in-app AI consent dialog. The chat feature is disabled until consent is granted. You can withdraw this consent at any time in the settings, which also clears your local chat history.
4.2 Read-Aloud Feature (Text-to-Speech)
When you activate the read-aloud feature, the corresponding book text section (max. 5,000 characters) is transmitted for speech synthesis. This consists exclusively of companion book content — no personal data.
Data flow:
App -> Embrace Life Technologies server (Bolzano, IT) -> OpenAI (TTS service)
The generated audio file is streamed back to your device. Pre-generated audio files of the app’s static content (weekly companion-book texts) may additionally be cached in Cloudflare R2 object storage to reduce latency and synthesis cost. The cache key is a content hash derived from the static text, model, and voice identifier; it contains no user identifier. Only the app’s own static content is cached — never user-generated chat content, diary entries, photos, or other personal data.
Technical logging: For ongoing technical monitoring of the read-aloud feature, the transmitted book text section and technical metrics (model used, response times) may be recorded in our self-hosted observability system (see Section 4.3). This consists exclusively of static, non-personal companion book text — no personal data.
Legal basis: Art. 6(1)(b) GDPR (provision of the requested feature)
4.3 Quality and Safety Analysis of the AI Companion
To continuously monitor and improve the quality and safety of the AI companion Verena, we record — exclusively with your consent to the AI companion — your conversations in our own observability system.
| Data Point | Description |
|---|---|
| Conversation content | The messages you send and the responses generated by Verena in reply |
| Technical metrics | The AI model used, response times, and the number of processed text units (tokens) |
| Pseudonymous identifiers | A randomly generated, device-local install identifier and a session identifier that group the messages of a single conversation |
We operate this observability system (Langfuse) ourselves on our own infrastructure — the cluster in Bolzano, Italy described in Section 6. The conversation content is therefore not transferred to third parties and does not leave the EU.
No directly identifying data is recorded — no name, no due date, no email address, and no device ID. The pseudonymous install identifier is reset as soon as you choose “Reset data” in the app; on its own, it allows no conclusions to be drawn about your identity.
Purpose: exclusively to secure and improve the quality and safety of the AI companion — for example, detecting faulty or unsafe responses and enabling a more responsible handling of distressing topics. The data is not used for advertising, for profiling, or for cross-device recognition.
Legal basis: Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR — your explicit consent to the processing of special-category personal data (health data), given through the in-app AI companion consent dialog. Without this consent, neither the AI companion nor this analysis takes place. You can withdraw your consent at any time in the settings; the AI companion is then disabled and no further conversations are recorded.
Retention period: Recorded conversations are automatically deleted after at most 90 days.
4.4 Anonymous Usage Statistics (Ad-Campaign Attribution)
With your explicit consent, we collect pseudonymized installation and usage data via Google Firebase Analytics to measure the conversion rate of our paid advertisements in the Apple App Store and the Google Play Store. The sole purpose is to optimize our advertising budget between Apple Search Ads and Google Ads.
This statistic is available only in the iOS and Android app. No such collection takes place in the web/PWA version of the app.
Note on the term “anonymous”: We use “anonymous” in the sense customary for end users (you are not personally identifiable to us). Technically, this is a pseudonymized processing within the meaning of Art. 4(5) GDPR: Google receives a random identifier per app installation (Firebase installation ID), but no directly identifying personal data.
| Data Point | Description |
|---|---|
first_open | The first opening of the app after installation (standard Firebase Analytics event) |
session_start | The start of a usage session (standard Firebase Analytics event) |
schema_migration_failed | A technical error event with the affected database version (a number) — serves exclusively for error diagnosis and contains no personal data |
| Firebase installation ID | A random technical identifier per app installation; allows no direct link to a person |
No directly identifying data is transmitted — no name, no email address, no due date, and no pregnancy week. No advertising ID is used (on Android the AD_ID permission is removed, and on iOS the app is built without the advertising identifier IDFA), and no “App Tracking Permission” dialog (App Tracking Transparency, ATT) is shown, as we do not track you across apps or websites. IP addresses are automatically truncated by Google Analytics 4 before any storage.
What we do not do: no profiling for personalized advertising or content, no retargeting, no cross-device recognition, and no sharing with advertising networks outside of Google.
Data flow:
App on your device -> Google Firebase Analytics (Google) -> property linked to Google Ads
Legal basis: Art. 6(1)(a) GDPR — your explicit consent.
Default setting: Disabled. Collection begins only after you have explicitly agreed to it at the first app launch. You can withdraw your consent at any time under “More” in the app; no further events are sent thereafter. Via “Reset data”, the device-local app identifier is regenerated.
Recipient / processor: Google (Firebase / Google Analytics 4), linked to Google Ads — see Section 6.
Retention period: The event data stored in Google Analytics 4 is automatically deleted after Google’s default retention period of 14 months.
5. Technical Safeguards
| Measure | Description |
|---|---|
| Access control | The proxy server is protected against abuse by an API key |
| Rate limiting | Maximum 5 chat requests and 5 read-aloud requests per minute per IP address |
| Security headers | Industry-standard HTTP security headers (HSTS, CSP, XSS protection) |
| Self-hosted quality analysis | AI chat conversations (only with your consent) and the read-aloud static book text sections are stored solely in our own self-hosted system for quality and safety analysis (see Sections 4.2 and 4.3), not with third parties |
| No cookies | The app does not set any tracking or analytics cookies |
| Analytics only with consent | By default, no analytics services are active. Only with your explicit consent do we collect anonymized installation and usage data via Google Firebase Analytics (see Section 4.4) |
| No account required | No registration or login is required to use the app |
6. Third-Party Providers
The backend infrastructure runs on a self-managed Proxmox cluster located in an EU colocation facility (Bolzano, Italy). Hardware is owned and operated by Embrace Life Technologies S.P.A. Società Benefit. No third-party cloud provider is involved in the internal processing chain — the only external sub-processors are those listed below. Google (Firebase Analytics) is used exclusively for the consent-based usage statistics described in Section 4.4.
6.1 Anthropic (AI Companion)
For the AI companion feature, we work with Anthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA.
Anthropic processes your chat content to generate AI responses. For the transfer to the USA, we rely on the Standard Contractual Clauses offered by Anthropic pursuant to Art. 46(2)(c) GDPR.
More information: Anthropic Privacy Policy
6.2 OpenAI (Read-Aloud Feature)
For the read-aloud feature, we use the text-to-speech service of OpenAI, LLC, 3180 18th Street, San Francisco, CA 94110, USA.
OpenAI processes exclusively the read-aloud book text sections (no personal user data). For the transfer to the USA, Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are used.
As a technical fallback, the read-aloud feature may alternatively use the Cloud Text-to-Speech service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. OpenAI is the currently active provider in production; Google is retained as a configurable alternative to ensure service availability. In both cases, only static companion-book text sections are transmitted — no personal user data. For the transfer to the USA, Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply.
More information: OpenAI Privacy Policy · Google Cloud Privacy Notice
6.3 Cloudflare (Network Infrastructure and Static-Content Cache)
Our proxy server is accessible via a Cloudflare Tunnel. In this process, Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, processes connection metadata (in particular IP addresses) to secure network access.
We additionally use Cloudflare R2 object storage to cache pre-generated read-aloud audio of the app’s own static content (weekly companion-book texts). Cache objects are keyed by a content hash and contain no user identifier. Cloudflare R2 does not receive any user-generated content — no chat messages, diary entries, photos, or other personal data. For the transfer to the USA, Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply.
Cloudflare does not have access to the content of your messages.
More information: Cloudflare Privacy Policy
6.4 Google (Firebase Analytics)
For the anonymous usage statistics for ad-campaign attribution (see Section 4.4), we use — only with your consent — Google Firebase Analytics by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (or Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Google processes the pseudonymous installation and usage data described in Section 4.4. A transfer to the USA cannot be excluded; for this, the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply. No directly identifying data and no advertising ID are transmitted.
More information: Google Privacy Policy · Firebase Privacy and Security
7. Your Rights (Data Subject Rights Under GDPR)
You have the following rights at any time:
- Access (Art. 15 GDPR): You can request information about the data stored about you.
- Rectification (Art. 16 GDPR): You can have incorrect data corrected.
- Erasure (Art. 17 GDPR): You can request the deletion of your data. Since your data is stored exclusively on your device, you can delete it at any time directly in the app (Settings -> Reset data).
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): Using the app’s export function, you can download your data as a structured, machine-readable file.
- Objection (Art. 21 GDPR)
- Automated decision-making (Art. 22 GDPR): You have the right not to be subject to a decision based solely on automated processing. The Verena AI chatbot provides informational responses only and does not make automated decisions that produce legal effects or similarly significantly affect you.
- Complaint to the competent data protection supervisory authority: Garante per la protezione dei dati personali (Italy)
For enquiries, please contact: [email protected]
8. Data of Minors
The app is intended for adult users. We do not knowingly collect data from individuals under the age of 18.
9. Changes to This Privacy Policy
We reserve the right to amend this privacy policy as needed. The current version is always available on our website. The date of the last update is indicated at the beginning of this document.
10. Contact
For data protection enquiries, please contact:
Embrace Life Technologies S.P.A. Società Benefit Email: [email protected] Bozner Str. 5B, 39044 Neumarkt (BZ), Italy
This privacy policy was prepared based on a technical analysis of the app’s source code (as of July 2026). Responsible: Embrace Life Technologies S.P.A. Società Benefit.