Privacy policy
Version 3, 6 October 2026. This policy applies to Algia, at algia.be, app.algia.be and api.algia.be. It replaces version 2 of the same date: it adds the free trial of Plus. Version 2 added passkeys and signing in with Google or Facebook, and named the place in the application where you exercise your rights yourself.
In short
- Algia keeps what you record about your pain. That is health data. We process it only with your explicit consent.
- Your diary stays in the European Union, with our hosting partner in Belgium. Diary text and medication details are encrypted.
- We do not sell your data, we do not use it for advertising, and no measurement script from another company runs inside the application.
- No email we send contains health data. A reminder on your screen names nothing.
- If you choose to sign in with Google or Facebook, that company learns that you use Algia. Nothing from your diary goes to them.
- You can export everything at any time, free, and erase your account. Erasure is final after 30 days.
- Questions or requests: support@algia.be.
1. Who is responsible
The controller of your data is Huskii VOF, a Belgian partnership, Sint-Barbarastraat 100, 3590 Diepenbeek, Belgium, company number 0689.570.723, VAT BE 0689.570.723. Algia is a product of Huskii VOF, not a separate company.
Contact for everything in this policy: support@algia.be. Huskii VOF has not appointed a data protection officer. The same address reaches the person responsible for your data.
2. What we process, and why
2.1 Your account
Your email address, your password if you set one (stored only as a hash we cannot read back), your second factor, the passkeys you add, your date of birth, your language, your time zone and the appearance you chose (automatic, light or dark). The date of birth shows that the age check happened: Algia is open from 16. Your email address is stored encrypted.
A passkey is kept on your device, or in your password manager if it keeps passkeys. We store only its public key, an identifier, a counter, the name you gave it and when it was added and last used. None of that is secret. Your fingerprint or face is checked by your device and never leaves it: no biometric data reaches us. Your device or password manager stores your email address with the passkey, so you can tell your passkeys apart; that copy is under your control, not ours.
Legal basis: the contract between you and Huskii VOF (Article 6(1)(b) GDPR).
2.2 Your diary and your medication
Where it hurts, how much, how your day went, what you write about it, and, if you record them, your medication and reminder times and your answers to reminders. This is health data under Article 9 GDPR.
Legal basis: your explicit consent (Article 9(2)(a) GDPR), which you give separately when you create your account and can withdraw at any time. Without it Algia cannot keep a diary for you.
We use this data only to show it back to you: in your diary, in charts, in a summary for a consultation and in the full export. Algia does not interpret it, and no text in Algia is chosen or worded from it.
Diary text, notes, earlier versions of an entry, and the name, dose and note of a medication are encrypted with a key kept apart from the application. Pain scores, regions, dates and the answers to the optional questions are not encrypted, so that charts can be drawn from them. They are protected by access control instead.
Algia does not let you add files yet. If that changes, this policy changes first.
2.3 Plus
If you take Plus, we keep your subscription status, the plan and the period, and the identifier Stripe gives your account as a customer. Stripe handles the payment on its own pages; we never see your card details.
Legal basis: the contract (Article 6(1)(b) GDPR). Invoices are kept because Belgian accounting and tax law requires it (Article 6(1)(c) GDPR).
Free trial of Plus. When you start a free trial, we keep a keyed hash of the fingerprint Stripe gives your payment method (a code for the card or bank account, not its number), so that the same payment method cannot start a second free trial. The hash is stored without your account, cannot be turned back into the fingerprint, and is deleted two years after it was last used for a trial. Legal basis: our legitimate interest in preventing abuse of the free trial (Article 6(1)(f) GDPR); you can object under Article 21. Two days before a free trial ends we email you its end date, the price and how to cancel, as part of the contract.
2.4 Security
Sign-in attempts, sessions with their IP address and browser, devices you chose to trust, recovery requests, the passkeys and linked accounts you added or removed, and an audit log of security events such as a password change, an export or an erasure. The audit log contains no diary content.
Legal basis: our legitimate interest in keeping your account and everyone else's safe, and in being able to show that we handled your data lawfully (Article 6(1)(f) GDPR).
2.5 Consent records
Which consent you gave, against which version of the text, when, and from which IP address. The GDPR requires us to be able to show that consent was given (Article 7(1)).
2.6 Email
We send the messages that using your account requires: confirming your address, resetting a password, security notices, a notice that an export was made, and a confirmation of your subscription. Legal basis: the contract and our legitimate interest in security.
Newsletters and offers are sent only if you ticked that box, which is off by default. Legal basis: your consent (Article 6(1)(a) GDPR).
2.7 Reminders
If you turn reminders on, your browser gives us a push address for that device. We store it encrypted. Legal basis: the contract, because you asked for the reminder.
2.8 Anonymised figures
If you agree, which is off by default, your data counts towards totals and averages across all users. Nothing published from it can identify you. Legal basis: your consent. Separately, we count how many entries were recorded each day across everyone, without linking the count to anyone.
2.9 The API
If you ask for API access and we grant it, we keep the purpose you gave (encrypted) and your tokens, stored only as a hash. Whatever you connect to your token receives your health data. That is your choice, and we cannot control or retrieve what that service does with it.
2.10 The public website
Our public pages set no cookie of their own. With your consent through the cookie banner, Google Analytics measures visits and Google Ads measures campaigns. The cookie policy has the details.
2.11 Signing in with Google or Facebook
Only if you choose it. When you sign in, register or link your account with Google or Facebook, your browser goes to their page and comes back to Algia with a code. With that code we receive from them your account identifier there, the email address of that account and, from Google, whether Google has confirmed that address. We ask for nothing else: not your name, your photo, your contacts or your friends.
We keep the identifier (as a keyed hash, and encrypted) and the address they gave (encrypted), to recognise you next time and to show you under Security which account is linked. We keep no access to your Google or Facebook account: the code is used once and forgotten. Signing in with them never replaces your second factor. If you register this way and Google has not confirmed the address, or you use Facebook, we send the usual mail to confirm it.
Google or Facebook learn that you use Algia, and when you sign in with them. They process that under their own privacy policy, as the companies responsible for it. Nothing from your diary, your medication or your health is ever sent to them. You can unlink the account under Security at any time, and it is removed with your account.
Legal basis: the contract (Article 6(1)(b) GDPR), because you asked for this way of signing in.
2.12 Support
If you write to support@algia.be, we keep the conversation to answer you. Please leave health details out of a support message. We do not need them to help you.
3. Who receives your data
We work with these processors. Each one has an agreement with Huskii VOF and receives only what is listed.
| Processor | What for | What it receives |
|---|---|---|
| Combell (Belgium) | Hosting, database and backups | Everything stored in Algia, with diary text and medication details encrypted |
| Amazon Web Services, Simple Email Service, EU region | Sending transactional email | Your email address and the message, which never contains health data |
| Mailchimp | Newsletters and offers, only with your consent | Your email address and your language, nothing else |
| Stripe | Payment for Plus | Your email address and your account identifier, plus what you enter on Stripe's own pages |
| Google (Analytics, Tag Manager, Ads) | Measuring visits and campaigns on the public website only, with your consent | Your visit to public pages, never anything from the application |
| Cookiebot | Recording your cookie choice on the public website | Your choice, its date and an identifier for it |
| Cloudflare | Domain name service, and delivery of the public website | Visits to public pages. The application addresses do not pass through Cloudflare |
| Browser push services (Google, Mozilla, Apple, depending on your browser) | Delivering a reminder you turned on | An encrypted message with a fixed text that names nothing, such as "Algia: Time for your reminder." |
Google (Google Ireland Limited) and Meta (Meta Platforms Ireland Limited, for Facebook) are not our processors when you sign in with them. Only if you choose it, they receive your request to sign in to Algia from your browser and send us what section 2.11 lists. They are responsible for what they do with it, under their own privacy policy.
We also use Anthropic's Claude to draft texts for the library and the blog. Those texts are written from a topic. No personal data is sent to Anthropic.
We give your data to nobody else, unless a law or a court order obliges us to. We never give it to an insurer, an employer or an advertiser.
4. Outside the European Union
Your diary is stored in Belgium, and transactional email is sent from an Amazon region in the EU.
Some processors are companies from the United States, or part of a group with companies there: Amazon Web Services, Mailchimp, Stripe, Google and Cloudflare, and, if you sign in with them, Google and Meta. They may process the data listed above outside the European Economic Area. Where that happens, the transfer relies on a safeguard the GDPR allows, such as an adequacy decision of the European Commission or the standard contractual clauses, as set out in our agreement with each of them. A push message may also pass through servers outside the EEA; its content is encrypted and names nothing.
5. How long we keep it
| What | How long |
|---|---|
| Your account and your diary | As long as your account exists. On Free, entries older than 30 days are hidden, never deleted, and always in your export |
| The previous version of an entry you changed or deleted | 90 days |
| A full export ready for download | 7 days |
| A trusted device | 30 days from when you trusted it |
| The audit log | 24 months |
| Consent records | As long as we may need to show that consent was given, without any health data |
| Invoices | As long as Belgian accounting and tax law requires |
| Your address at Mailchimp | Until you unsubscribe or erase your account |
| A passkey | Until you remove it under Security or erase your account |
| A linked Google or Facebook account | Until you unlink it under Security or erase your account |
| Backups | 90 days, then replaced |
6. Erasing your account
You can erase your account under Security, Your data, or ask us at support@algia.be. We first send a confirmation to your email address. For 30 days you can still change your mind; after that, everything is erased.
What is erased: your account, your sign-in methods (passkeys and linked Google or Facebook accounts included), your sessions, your diary, your medication and reminders, every export, your push addresses, your address at Mailchimp, and any queued task that refers to you.
What survives, and why. Two things, and this is a legal position rather than a technical convenience:
- The consent records, pseudonymised. The GDPR requires being able to demonstrate that consent was given. What is kept is the purpose, the text version, the timestamps and nothing else. The account identifier remains as an identifier that now points at no one, and the IP address is cleared.
- The audit log, pseudonymised the same way. It records that an account existed, when it was erased and on whose authority. Deleting it would remove the only evidence that the erasure itself was performed correctly.
Neither retains a name, an address, a diary line or an attachment.
Backups. Erasure applies to live systems immediately. Backups are snapshots on a 90-day rotation, so a copy of your data can exist in them until it rotates out. If we ever restore a backup, we re-apply every pending erasure before the system comes back up, so a restore cannot bring back someone who asked to be forgotten.
If a dispute or an authority's request requires us to keep evidence, we may pause the final purge. We then tell you that your request is recorded and paused, and why.
7. Your rights
- Access and export. You can download everything we hold about you, at any time and free, as a file you can open elsewhere. For your safety this asks for your password and your second factor again. It stays possible after you withdraw your consent.
- Rectification. You can correct your entries yourself. For anything else, write to us.
- Erasure. See section 6.
- Restriction. You can pause the use of your data yourself, under Security, Your data, or ask us to, while a question is settled. You can then still sign in and read your diary, but nothing new is recorded.
- Objection. You can object to processing based on our legitimate interest.
- Withdrawing consent. Under Security, Your data, at any time, without giving a reason. Withdrawing your consent for health data stops the processing and closes the diary; the export and erasure stay open to you. Withdrawing does not make earlier processing unlawful.
- Complaint. You can complain to the Belgian Data Protection Authority, gegevensbeschermingsautoriteit.be or autoriteprotectiondonnees.be, or to the authority where you live. We would like to hear from you first, at support@algia.be.
We answer a request within one month. If we need to check that a request comes from you, we ask.
8. No automated decisions
Algia makes no decision about you by automated means and builds no profile of you. Library texts are chosen by topic, never by what is in your diary.
9. How we protect your data
A second factor is required for every account, also when you sign in with Google or Facebook. A passkey counts as both, because it is bound to Algia's address and cannot be used on a look-alike site. Exporting, erasing and changing your email address ask again for your password (or, without one, your Google or Facebook sign-in) and your second factor, or a passkey. Adding a passkey or linking an account asks for them too, and we tell you by email when it happens. Diary text and medication details are encrypted. The application loads no script from another company. Every security event is recorded in a log that shows if it was changed afterwards. Diary text and medication details stay encrypted inside backups, and restoring a backup is tested every month.
If a breach puts your data at risk, we tell you and the Data Protection Authority as the GDPR requires.
10. Changes to this policy
A new version gets a new number and date. If a change affects what we do with your data, we tell you in the application or by email before it applies. Where a change concerns something you consented to, we ask you again.