Für dich. Für deinen Körper.

Privacy Policy

Last updated: September 4, 2026

1. Data Controller

The controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is:

Jörg Holdschick
Bredenbeekweg 31
31848 Bad Münder
Germany
Email: info@femdays.eu

In short: femdays.eu is currently an editorial content platform without user accounts. We deliberately follow a data-minimal approach: no ad trackers, no analytics cookies, no external loading of Google Fonts. In parallel, we are developing the FemDays app for cycle and fertility tracking – its planned, end-to-end encrypted data processing is already described transparently in Section 7.

2. Overview of Processing

When you visit femdays.eu in your browser, we generally only process the data that is technically necessary to display the site reliably and securely (server log files). Further data is only collected if you actively contact us.

3. Hosting

This website is hosted and technically maintained by:

Holdschick Media Hameln
Owner: Jörg Holdschick
Bredenbeekweg 31
31848 Bad Münder
Germany
Phone: +49-5042-527987
Fax: +49-5042-527991
Email: Holdschick@hm-hm.com
Website: www.hm-hm.com
VAT ID under § 27a German VAT Act: DE250232570

Since Holdschick Media Hameln and the controller named above (Jörg Holdschick) are the same natural person, hosting is carried out in-house without engaging an external data processor. The server infrastructure is located within the European Union.

Every time our website is accessed, information is automatically recorded in so-called server log files, which your browser transmits automatically:

This data cannot be attributed to a specific person by us and is not combined with other data sources. Collection is based on Art. 6(1)(f) GDPR (legitimate interest in the technically error-free and secure operation of the website) and is automatically deleted or anonymized shortly afterward.

4. Cookies

During a normal, anonymous visit to femdays.eu, we set no cookies. Should you log in to the WordPress backend as an editorial team member in the future, WordPress sets technically necessary session cookies (Art. 6(1)(f) GDPR). These relate exclusively to internal editorial access, not to public use of the site.

Should we wish to use cookies for statistics or convenience purposes on the website in the future, we will ask for your consent in advance via a consent banner and update this policy accordingly.

5. Embedded Fonts

This website uses the web fonts „Fredoka“ and „Nunito“ for a consistent appearance. These are installed locally on our own server (not at Google). Visiting this site therefore results in no connection to Google’s servers.

6. Contacting Us by Email

If you contact us by email (e.g. to info@femdays.eu), we store the information from your email (email address, name if provided, and the content communicated) in order to process your request. The legal basis is Art. 6(1)(b) GDPR, insofar as your inquiry serves to initiate or fulfil a contract, otherwise Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR for voluntary feedback. We delete this data once your inquiry has been fully processed and no statutory retention obligations apply.

Please note: Please avoid sending us sensitive health information via regular email, as unencrypted email transmission cannot be fully protected against access by third parties.

7. The FemDays App: Planned Processing of Health Data

The FemDays app will complement femdays.eu with cycle and fertility tracking functionality. The following applies to the processing of your health data in the app:

7.1 What Data the App Will Process

With the FemDays app, you will be able to log your cycle, period, symptoms, mood, basal body temperature, cervical mucus, ovulation test results, and optionally information on trying to conceive/contraception. These are special categories of personal data (health data) within the meaning of Art. 9 GDPR.

7.2 End-to-End Encryption – the Server Never Sees Your Content

All health content is stored exclusively end-to-end encrypted (AES-256-GCM). This means your entries are encrypted on your device before they reach the server. Our server (the WordPress backend at femdays.eu) only holds an encrypted data package – we cannot view the content and do not pass it on to third parties in plain text. Only the date of an entry remains unencrypted so the app can sort and synchronize entries chronologically; all derived evaluations (e.g. cycle prediction, fertile window) are calculated exclusively on your device and are not transmitted to the server.

7.3 Key Management and Recovery

The key used to decrypt your data remains on your devices:

When first setting up the app, you will be shown a one-time recovery code (a recovery passphrase) that lets you regain access to your encrypted data if you change or lose a device. Important: keep this code safe – if it is lost and all your devices are simultaneously unavailable, your data is irretrievably lost. This is the deliberate, technically necessary consequence of true end-to-end encryption, under which we as the provider hold no master key either.

In addition to the standard confirmation („I have saved the code“), you can optionally choose to have the recovery code emailed to you for convenience. Important to know: unlike the app itself, this email delivery is not end-to-end encrypted; the code leaves our directly controlled environment and ends up in your email inbox. We do not store the code permanently but merely forward it once for sending. This option is a deliberate convenience-versus-security trade-off and purely a voluntary extra alongside the more secure standard confirmation.

7.4 Account, Login, and Minimum Age

Using the app will require a user account (email address and password), optionally supplemented by „Sign in with Apple“ or Google sign-in. An account is necessary so your encrypted data package can be synced across devices and linked to an existing subscription. The legal basis for creating the account is Art. 6(1)(b) GDPR (performance of a contract); for processing the actual health content it is Art. 9(2)(a) GDPR (your explicit consent, given separately during onboarding and revocable at any time with effect for the future).

When setting up the app, you will be asked for your date of birth. This date of birth is stored exclusively locally on your device and is never transmitted to our server – it only serves as a technical mode switch:

Sharing your data with another person (see Section 7.5) is, in local mode (under 16), only possible with a verified adult (18+) recipient.

7.5 Sharing with Trusted People (Partner/Family Sharing)

You can optionally share individual categories of your data with trusted people of your choice (e.g. partner, mother, daughter – simultaneously and independently, multiple connections possible). For each individual connection, you freely choose which categories are visible: whether your period is currently active, the fertile window, predicted dates, symptoms, mood, trying-to-conceive status, or notes (for notes, we specifically point out their often very personal content).

Technically, this is deliberately not solved by sharing your full encryption key. Instead, each trusted person needs their own, free FemDays account; pairing takes place via invitation (QR code/link) with its own asymmetric encryption channel per connection. With every change, the app creates a filtered, encrypted package solely for the categories released for that connection – the server never sees plain text, even for shared data.

You can revoke each sharing connection individually and completely at any time; the person concerned then immediately loses access to future synchronizations. Important technical limitation: copies already received and stored on the other person’s device before revocation are not retroactively deleted by this – this is a fundamental property of any sharing feature, and you are informed about it transparently in the app when setting up a sharing connection.

7.6 Connection to Apple Health and Health Connect

Optionally, and disabled by default, you can connect the app to Apple Health (iOS) or Health Connect (Android). If this connection is enabled, the app reads existing health data from the respective platform interface and additionally writes new FemDays entries back to it. This connection runs entirely locally on your device – the data is not routed through our server. However, it therefore additionally ends up in Apple’s or Google’s own separate storage, which is subject to each provider’s own privacy policy. You can disable this connection at any time in the app settings or your device’s platform settings.

7.7 Subscription and Payment Processing

The app is planned as a freemium model with a free trial period (2 months or 60 days, depending on platform) followed by a paid subscription, available in several tiers (including basic functions as well as an advanced tier with personalized fertility-window calculation; optionally a family tier for shared use by several people). Purchases are made via Apple In-App Purchase, Google Play Billing, or a web payment provider. In that case, Apple or Google process the data required for payment processing (e.g. purchase confirmation) under their own privacy policies; we are only informed of a subscription status, not of payment details such as card data.

7.8 No Authority Access to Plain-Text Data

Since we technically only store your health data in encrypted form and have no access to the plain text ourselves, we cannot hand over decrypted content even in the event of a request from authorities – we technically only hold unreadable, encrypted data packages.

8. Security of Data Transmission (SSL/TLS Encryption)

For security reasons, this website uses SSL/TLS encryption for the transmission of content. You can recognize an encrypted connection by the fact that the browser’s address bar switches from „http://“ to „https://“ and by the lock icon in your browser bar.

9. Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your personal data:

Please note the technical particularity from Section 7.8 for deletion and access requests regarding app data: content that exists exclusively in end-to-end encrypted form cannot be handed over to you in plain text or reviewed by us in terms of content – however, we can carry out a deletion request for the encrypted data set at any time.

To exercise your rights, please contact us informally at info@femdays.eu.

10. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen (Data Protection Authority of Lower Saxony, Germany)
Prinzenstraße 5
30159 Hannover
Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: www.lfd.niedersachsen.de

11. Changes to This Privacy Policy

We update this privacy policy whenever the legal situation or our range of services changes. The version published on this page at any given time applies.