Privacy Policy

Last Updated: August 28, 2026

1. Data Controller

Limbico is provided by CLICK GENERATION S.R.L. S.B., Piazza IV Novembre 4, 20124 Milan, Italy, VAT number IT12373690960 ("Click Generation", "Limbico", "we", "us", or "our"). Click Generation is the controller of the personal data described in this Privacy Policy.

Privacy contact: privacy@genoma-group.com

2. Scope

This Privacy Policy explains how we process personal data when you use the Limbico iOS application, website, and related services. Limbico is a general wellness service and is not a medical device or healthcare service.

3. Personal Data We Process

Depending on the features you use, we may process the following data.

Account and identity data: name, email address, Firebase user identifier, authentication provider, profile image, language, age confirmation, and records of legal-document acceptance.

Optional contact data: telephone number used to connect the optional WhatsApp service.

Health and fitness data: activity, steps, energy expenditure, workouts, sleep, heart rate, heart-rate variability, resting heart rate, respiratory rate, recovery, strain, stress, temperature, oxygen-related metrics, and similar measurements made available by Apple Health or a wearable provider.

Wellbeing data: Mind Scores, component scores, questionnaire responses and results, self-reported mood or stress, goals, profession, interests, notes, and observations.

Conversation and memory data: messages sent in the app or through the optional WhatsApp channel, AI responses, conversation summaries, and memories created to preserve relevant context.

Calendar data: for calendars you select, event title, start and end time, all-day status, event location, notes, and calendar name.

Location data: geographic coordinates, accuracy, altitude, timestamp, and a reverse-geocoded place name when location access is enabled.

Social data: friend code, connections, display name, and the score or trend information you choose to share through Limbico's social features.

Subscription and transaction data: subscription state, expiry, offer code, and the App Store original transaction identifier. Apple processes payment details; Limbico does not receive your full payment-card data.

Technical, notification, and usage data: app instance and device information, operating system, Firebase Cloud Messaging token, screen and feature events, timestamps, diagnostic logs, and error information. Usage events may include feature names, questionnaire type or result, wellness score values, stress category, wearable type, and interaction timing. Full conversation content is not sent to Firebase Analytics.

Support and feedback data: messages, ratings, and information included in support, privacy, or feedback requests.

We receive data directly from you, from your device and permissions, from Apple, Google, connected wearable providers through Spike, and from the App Store where applicable.

4. Why We Process Data and Legal Bases

We process personal data for the following purposes.

Provide the account and requested service: authentication, cloud synchronization, conversations, scores, subscriptions, notifications, support, and security. The legal basis is performance of our contract or steps requested before entering into it.

Process health and fitness data: calculate Mind Scores, provide personalized wellbeing information, and support features you choose to use. We process these special-category data only after your explicit consent.

Use optional calendar and location context: personalize insights and identify contextual patterns after you grant the relevant device permission and, where required, consent.

Provide optional integrations: connect wearable providers or WhatsApp at your request and with the permissions required by those services.

Operate and improve the service: use minimized, non-content analytics, diagnose failures, prevent abuse, and protect the service. The legal basis is our legitimate interest in operating a secure and reliable service, balanced against your rights.

Meet legal obligations and establish or defend legal claims where required by law.

You may refuse or withdraw optional consent without losing access to features that do not require the relevant data. Withdrawal does not affect processing that was lawful before withdrawal.

5. Health Data Consent and Device Permissions

Before connecting Apple Health or another wearable provider, Limbico presents a specific health-data disclosure. By actively choosing a provider, confirming the health-data consent where shown, and completing the device or provider authorization flow, you expressly request and consent to the related processing.

You can withdraw consent by disconnecting all wearable providers in the app. This stops future collection through Limbico and requests deletion of synced Spike data. You may also change Apple Health, calendar, location, and notification permissions in iOS settings. Limbico does not use health data for advertising or sell it to data brokers.

6. AI Processing

Limbico uses Microsoft Azure OpenAI Service for conversations, wellbeing insights, safety classification, summaries, and embeddings. The Azure OpenAI resource currently used by Limbico is deployed in Sweden Central. Prompt and response data sent through Azure OpenAI is not used to train the underlying foundation models.

AI output may be inaccurate and must not be treated as medical advice. Limbico does not use solely automated processing to make decisions that produce legal or similarly significant effects about you.

7. Service Providers and Recipients

We use the following categories of providers where necessary.

Google Firebase and Google Cloud: authentication, Firestore storage, Cloud Functions, push messaging, minimized analytics, operational logging, backup, and recovery.

Microsoft Azure OpenAI Service: AI generation, embeddings, and safety processing.

Spike: connection to Apple Health and supported wearable providers and retrieval of authorized health and fitness data.

Mem0: optional conversational memory and context management.

Apple and Google: sign-in, device permissions, Apple Health, App Store subscriptions, and platform services.

Twilio and WhatsApp/Meta: the optional WhatsApp messaging channel.

Providers process data only for the relevant service functions and under their applicable terms, privacy documentation, and data-processing arrangements. We may also disclose data where required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards.

We do not sell personal data.

8. International Data Transfers

Firestore and the deletion-recovery register currently use Google Cloud resources located in the United States. Azure OpenAI processing used by Limbico is currently deployed in Sweden Central. Other providers may process data in countries outside the European Economic Area.

Where personal data is transferred outside the EEA, we apply the transfer mechanism required for the relevant recipient and destination, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required. You may request information about the applicable safeguards at privacy@genoma-group.com.

9. Data Retention

We retain personal data only for as long as necessary for the purposes above.

Active account data: while the account is active and the relevant feature is used, unless a shorter period applies or deletion is requested.

Operational Google Cloud logs: generally 30 days; mandatory Google Cloud audit logs are retained for 400 days.

Azure operational logs: 90 days. Full Azure OpenAI request and response logging is disabled.

Completed account-deletion records: a limited pseudonymous operational result is retained for up to 30 days.

Deletion-recovery markers: a one-way SHA-256 value derived from the Firebase user identifier, request/completion times, expiry time, and purpose is retained separately from Firestore for up to 90 days after completed deletion. It contains no original user identifier, name, email, health data, or conversation content.

Point-in-time recovery: Firestore historical versions are retained for up to 7 days.

Scheduled backups: daily backups are retained for 14 days and weekly backups for 84 days.

Provider copies: data sent to Spike, Mem0, Twilio, Apple, Google, or other providers may remain in provider-controlled backup or legal-retention systems until the applicable provider retention cycle expires.

Legal claims and obligations: limited information may be retained longer where necessary to comply with law or establish, exercise, or defend claims.

Truly anonymized aggregate data may be retained because it is no longer personal data.

10. Account Deletion

You can request account deletion from the app. When the request is accepted, Limbico immediately disables the Firebase account, creates a tracked deletion job, records the deletion-recovery marker, revokes known Spike integrations, requests deletion from Mem0, deletes user data from Firestore, and deletes the Firebase Authentication account. Temporary provider failures are retried automatically and the pseudonymous outcome is recorded.

Data removed from the live service may remain in encrypted, access-controlled point-in-time recovery or backup copies until the retention periods above expire. Restored databases must be reconciled against active deletion-recovery markers before they can be used, so covered deleted accounts are removed again.

Deleting the Limbico account does not automatically cancel an App Store subscription. Subscriptions must be managed through the Apple Account.

11. Security

We use encryption in transit, encryption at rest provided by our cloud platforms, access controls, secret management, restricted operational logs, deletion protection, backups, and recovery procedures. No security measure can guarantee absolute protection.

12. Your Rights

Subject to applicable law, you may request access to and a copy of your personal data, correction of inaccurate data, deletion of data, restriction of processing, portability of data you provided, objection to processing based on legitimate interests, withdrawal of consent at any time, and information about international-transfer safeguards.

To exercise a right, contact privacy@genoma-group.com or use the available in-app controls. We may need to verify your identity. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the competent authority where you live or work.

13. Adults Only

Limbico is reserved for adults aged 18 or older. We do not knowingly allow minors to create accounts or use the service. If we learn that a minor has provided personal data, we will disable the account and take steps to delete the data.

14. Third-Party Services

Third-party devices, platforms, and services have their own privacy notices and controls. Their independent processing is governed by those notices. Review the privacy information provided by Apple, Google, your wearable provider, Spike, WhatsApp/Meta, and any other service you connect.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes to the service, law, security, or our providers. We will provide notice of material changes through the app, website, or email where required. Where a change requires renewed consent, Limbico will request it before continuing the affected processing.

16. Contact

CLICK GENERATION S.R.L. S.B.

Piazza IV Novembre 4

20124 Milan, Italy

VAT number: IT12373690960

Email: privacy@genoma-group.com

Website: https://limbico.genoma-group.com