mH²

Draft — not yet legally reviewed.

Highlighted [items in brackets] must be completed by the platform operator before this page is relied on.

Privacy notice

Written for participants and researchers of studies run on mH² (mh2research.com and the mH² mobile app). Last updated: 24 September 2026.

1. Who is responsible for your data

Controller: Coding Here & There Mateusz Daniol, 31-334 Kraków, Poland, contact@mh2research.com.

Data protection contact: Mateusz Daniol, contact@mh2research.com. No data protection officer is appointed: the controller does not meet the criteria in Art. 37(1) GDPR.

For a specific study, the study's principal investigator (named in the study's consent document you accept in the app) is the controller of the research data collected in that study; the platform operator acts as a processor for hosting and transmission and never has access to the readable content of your health data (see section 4).

2. What we collect and why

DataPurposeLegal basis
Account data: e-mail address, name (optional), password (stored as a one-way hash), verification and login timestampsCreating and securing your account, sending verification and password-reset e-mailsContract (Art. 6(1)(b) GDPR)
Enrolment and consent records: which study you joined, the consent text version you accepted, the data types you agreed to, timestamps, IP address and device/browser type at the moment of consentProof of informed consent, withdrawal handling (Art. 7(1) GDPR)Legal obligation / legitimate interest of the controller in evidencing consent
Health and sensor data collected during a study (for example accelerometer windows from your phone, ECG and heart rate from a wearable, questionnaire answers, audio recordings if the study includes them), together with recording-quality metadata (sampling rate, gaps, device model)The scientific purpose described in the study's consent documentYour explicit consent (Art. 9(2)(a) GDPR), given per data type in the app; scientific research safeguards (Art. 89)
Technical data: app version, crash reports, error identifiers, request logs with pseudonymous identifiers, notification tokensKeeping the service working and secureLegitimate interest (Art. 6(1)(f))

We do not collect precise location unless a study explicitly includes it and you consent to it. We do not use your data for advertising or sell it.

3. How long we keep it

  • Account data: until you delete your account or [N] years after your last login.
  • Consent records: for the retention period the study's ethics approval requires ([typically 10 years] after the study ends), as evidence of consent.
  • Study data: for the period stated in the study's consent document; after withdrawal, your data is excluded from all research exports and analyses from the moment of withdrawal, and deleted [or anonymised] within [30 days] unless the study protocol requires retention of already-analysed data.
  • Technical logs: 21 days (application logs) and up to 7 days (server request logs); error reports: [90 days].
  • Security audit records: 6 years (GDPR Art. 5(2) accountability; general limitation period of the Polish Civil Code, art. 118). Records about a deleted account are masked whenever they are read.
  • Encrypted backups: up to 90 days, rolling; deletions are re-applied after any restore.

When you delete your account, your account data is deleted — at once on the web, and at the latest within one month for a request sent from the current mobile app or by e-mail — and you are signed out everywhere. We never refuse to delete an account. Study data you have already contributed is then either erased or, where the study's principal investigator determines that erasure would make the research impossible or seriously impair it and a platform administrator records that decision on their instruction, kept in pseudonymised form under Article 9(2)(j) and Article 17(3)(d) GDPR, with the safeguards of Article 89(1): the account no longer holds your name, e-mail address or any other contact detail, so the data can be re-identified only through access-restricted security records. Consent records and security audit records are kept as described above. Details and timelines: Delete your account.

4. How your data is protected

  • End-to-end encryption. Health and questionnaire data are encrypted on your device with keys generated on your device before they leave it. Only the study's researchers (and you) hold keys that can decrypt them; the platform operator and hosting provider cannot read them. Some categories are not encrypted end to end and are readable by the operator with the researchers' authorisation: recording-quality metadata, and annotation labels and notes that researchers write about signals.
  • Transport encryption (TLS) for all connections; encrypted backups; access logging and tamper-evident audit trails.
  • Your password protects your keys. If you forget it and have not set up a recovery phrase, neither we nor the researchers can restore access to data encrypted for you.

5. Where your data is stored and who processes it

Servers are located in the European Union (Hetzner Online GmbH, Helsinki, Finland). Service providers that process limited personal data on our behalf: Hetzner (hosting, Finland), Migadu (transactional e-mail — verification and password reset — Switzerland), Google Firebase (push notifications and test distribution for the mobile app, United States), Better Stack (public service-status page; no personal data), and GlitchTip (error reports, scrubbed of identifiers), which we host ourselves. Two of these sit outside the European Economic Area. Switzerland is not an EEA member, but the European Commission has adopted an adequacy decision for it, so the transfer to Migadu needs no further safeguard. The transfer to Google Firebase in the United States relies on the EU–US Data Privacy Framework. There are no other transfers to third countries.

6. Your rights

You can, at any time and free of charge: access the personal data we hold about you; correct it; withdraw from a study (in the app: Studies → the study → Withdraw) — this stops collection immediately and excludes your data from further research use; withdraw consent for individual data types; delete your account (in the app: Settings → Danger zone → Delete my account and data; on the web: Profile → Delete my account; or by e-mail to contact@mh2research.com, as described on the “Delete your account” page linked in section 3) and request erasure of your study data; receive a copy of your data in a machine-readable form; object to processing based on legitimate interest; and lodge a complaint with the supervisory authority ([Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa] or your local authority).

Withdrawing consent does not affect the lawfulness of processing before withdrawal. Research results already derived from anonymised data cannot be reversed.

7. Children

The platform is intended for adults (18+). Studies involving minors require specific ethics approval and parental consent handled by the study team.

8. Changes

We will announce material changes to this notice on this page and in the app; continued use after the effective date constitutes acceptance for account-level processing. Changes to what a study collects always require your renewed consent in the app.

Version 0.3 — 24 September 2026 — prepared as a draft from the platform's technical documentation (encryption model, consent versioning, data retention settings) and the regulatory pack in the mobile repository (GDPR_LAWFUL_BASIS, GDPR_ROPA). Requires legal review before publication.

See also the Terms of use and the Imprint.