Privacy Policy
Last Updated: February 2026
Operator: Polivora | Contact: privacy@polivora.com
This Privacy Policy explains how Polivora ("we", "us", or "our") collects, uses, and protects personal data when you visit our website (polivora.com) or subscribe to our newsletter. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).
Table of Contents
1. Data Controller
The data controller responsible for the processing of your personal data is:
mobileapart GmbH
Vollmerhauser Str. 47
51645 Gummersbach, Germany
Email: privacy@polivora.com
2. What Data We Collect
2.1 When You Visit Our Website
When you access our website, our web server automatically records the following technical data temporarily in server logs:
- IP address (anonymized)
- Browser type and version
- Operating system
- Date and time of access
- Pages visited and referrer URL
This data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest) to ensure the technical operation and security of our website. Server logs are retained for a maximum of 7 days and then automatically deleted.
2.2 When You Subscribe to Our Newsletter
When you sign up for the Polivora newsletter, we collect:
- Your email address
- Date and time of subscription
- IP address at time of registration (for verification purposes)
- Your preferred language (optional), to deliver content in the language of your choice
- Your topic interests (optional), to personalize the newsletter content you receive
We use a double opt-in procedure: after entering your email address, you will receive a confirmation email and must click the link to activate your subscription. The legal basis for processing is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time by clicking the unsubscribe link in any newsletter.
2.3 When You Subscribe to a Paid Plan
If you choose to subscribe to a premium paid plan, we additionally collect payment and billing information necessary to process your subscription. Payment transactions are handled by our third-party payment processor (e.g., Stripe). We do not store your full payment card details. The legal basis for processing is the performance of a contract pursuant to Art. 6(1)(b) GDPR.
3. Newsletter Service: Brevo
We use Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) to send our newsletters. Brevo processes your email address and related data on our behalf as a data processor under a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR.
Brevo may collect technical data such as email open rates and click statistics using tracking pixels to help us measure the effectiveness of our newsletters. This processing is based on Art. 6(1)(f) GDPR (legitimate interest in analyzing newsletter performance).
You may opt out of email tracking at any time by disabling image loading in your email client, or by unsubscribing from the newsletter entirely.
For more information, see Brevo's Privacy Policy at: https://www.brevo.com/legal/privacypolicy/
4. Analytics: Plausible
We use Plausible Analytics (Plausible Insights OÜ, Vaksali 24-2, 50409 Tartu, Estonia) to understand how visitors use our website. Plausible is a privacy-first analytics tool that:
- Does not use cookies
- Does not collect personal data or persistent identifiers
- Does not track users across websites
- Processes only aggregated, anonymized statistics
Because Plausible does not process personal data, no cookie consent is required for its use. The legal basis for using aggregated website statistics is Art. 6(1)(f) GDPR (legitimate interest in improving our service).
For more information, see Plausible's data policy at: https://plausible.io/data-policy
5. Advertising and Sponsored Content
Our newsletter and website may contain advertising and sponsored content. We handle this in the following ways:
5.1 Sponsored Content in the Newsletter
We may include clearly labeled sponsored sections in our newsletter on behalf of third-party advertisers (e.g., health brands, supplement companies, wellness apps). Sponsored content is always identified with a label such as "Sponsored" or "Advertisement." When you click on a sponsored link, the advertiser may receive information that a click originated from our newsletter, but we do not share your personal data (including your email address) with advertisers unless you actively engage with their own sign-up forms or services.
The legal basis for including advertising in our newsletter is our legitimate interest in financing the service pursuant to Art. 6(1)(f) GDPR.
5.2 Affiliate Links
Our newsletter and website may contain affiliate links. If you click on an affiliate link and make a purchase, we may receive a commission from the affiliate partner at no additional cost to you. Affiliate links are disclosed with a label such as "Affiliate link" or "*" with a corresponding note. When you click an affiliate link, the affiliate partner may set cookies or collect technical data on their own platform. We recommend reviewing the privacy policies of those third-party platforms.
The legal basis for using affiliate links is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
5.3 No Sale of Personal Data
We do not sell, rent, or trade your personal data (including your email address) to third-party advertisers or data brokers. Advertiser relationships are limited to placement of content within our platform and do not involve the transfer of your personal information.
6. Content Sources
Polivora aggregates publicly available scientific studies and health research from sources including PubMed, medical journals, and health news websites. We do not collect personal data from these sources. All content displayed on our platform is based on publicly available research and is processed solely to provide health information summaries.
7. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data where no legal obligation requires us to retain it.
- Right to restriction of processing (Art. 18 GDPR): You may request that we limit how we use your data.
- Right to data portability (Art. 20 GDPR): You may request your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at: privacy@polivora.com
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes applicable data protection law. The competent supervisory authority in Germany is the data protection authority of the federal state in which we are located. You may also contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI): https://www.bfdi.bund.de
9. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required by applicable law:
- Newsletter subscriber data: retained until you unsubscribe or request deletion
- Server logs: deleted after 7 days
- Double opt-in confirmation records: retained for the duration of your subscription as legal proof of consent
- Billing and payment records: retained for 10 years in accordance with German commercial law (HGB)
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure. Our website is served via HTTPS. Access to subscriber data is restricted to authorized personnel only.
11. Third-Party Links
Our website and newsletters may contain links to third-party websites. This includes affiliate links, sponsored links, and links to original research sources. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies independently.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The date at the top of this document indicates when it was last revised. We encourage you to review this policy periodically.
13. Contact
For any questions or concerns regarding this Privacy Policy or the processing of your personal data, please contact us at:
privacy@polivora.com