Privacy Policy of the mhplus mind+move App
Last updated: July 2026
This is an English translation provided for convenience. The legally binding version is the German one, available at Datenschutzerklärung (Deutsch).
1. Controller
mhplus Betriebskrankenkasse
Franckstrasse 8
71636 Ludwigsburg, Germany
Phone: +49 71 41 / 97 90 - 0
Website: www.mhplus-krankenkasse.de
As a public-law corporation, mhplus BKK is subject to the provisions of the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the rules on social data protection in the German Social Code (SGB I and SGB X).
2. Data Protection Officer
Data Protection Officer of mhplus BKK
Franckstrasse 8
71636 Ludwigsburg, Germany
Contact: www.mhplus-krankenkasse.de/kontakt
3. General Information on Data Processing
mhplus BKK takes the protection of personal data very seriously. We want you to know when we store which data and how we use it.
We have implemented technical and organizational measures to ensure that the data protection rules are observed both by us and by external service providers.
4. Legal Bases for Data Processing
| Processing | Legal basis |
|---|---|
| App use (registration, login) | Art. 6(1)(a) and (b) GDPR (consent and performance of a contract) |
| Health data (steps, meditation) | Art. 9(2)(a) GDPR (explicit consent) |
| Push notifications | Art. 6(1)(a) GDPR (consent) |
| Tracker integration (Google, Fitbit, Garmin, Polar) | Art. 6(1)(a) and Art. 9(2)(a) GDPR |
| Error analysis | Art. 6(1)(f) GDPR (legitimate interest) |
| Operation of the bonus programme (Fitcash) | Section 65a SGB V, data processing under Section 284 SGB V |
5. Categories of Personal Data
5.1 Master data
The following data is collected during registration and use of the app:
- Insurance number
- Date of birth
- Email address (used as username)
- Name (first and last name)
- Password (stored only as a non-readable hash)
5.2 Health data (special category under Art. 9 GDPR)
When using the app functions, the following health data is processed:
Mind mode (mental health):
- Meditation exercises (duration, date)
- Mindfulness sessions
- Answered impulse questions
- Challenge participation and progress
Move mode (physical activity):
- Step data (count, date, source)
- Movement activity
- Challenge participation and progress
This data is processed only with your explicit consent.
5.3 Device information
- Operating system version (iOS/Android)
- Device model
- App version and build number
5.4 Usage data
- App usage behavior (mind/move mode)
- Bonus points and redemptions
- Synchronization timestamps
6. Data Sources
| Source | Data | Consent |
|---|---|---|
| Direct input | Registration data, profile information | At registration |
| Apple HealthKit (iOS) | Step data, mindfulness minutes | iOS system dialog |
| Health Connect (Android) | Step data | Android system dialog |
| Google (Google Health API) | Activity and fitness data | OAuth authorization |
| Fitbit | Activity data | OAuth authorization |
| Garmin | Activity data | OAuth authorization |
| Polar Flow | Activity data | OAuth authorization |
| Automatic | Device information, timestamps | App use |
7. Push Notifications
When the app starts, and after you consent to receiving push messages, a Firebase Cloud Messaging registration token is created. This token uniquely identifies the app on your device so that push messages can be sent to your device.
This only happens with your consent (Art. 6(1)(a) GDPR).
Withdrawal: You can withdraw your consent at any time by disabling push notifications in your device system settings or by uninstalling and reinstalling the app. The token is automatically deleted after 35 days of inactivity.
8. Recipients of the Data
8.1 Internal recipients (mhplus)
- Health promotion department
- IT department (technical administration)
8.2 Processors
| Recipient | Purpose | Location | Processing agreement |
|---|---|---|---|
| DeviD GbR | App development and operation | Germany | Yes |
| plusserver GmbH | Server hosting | Germany | Yes |
| Firebase (Google) | Push notifications | USA/EU | Yes (Google DPA) |
8.3 Categories of authorized parties
Under Section 35 SGB I (social secrecy), the following authorized parties may be granted access to your data:
- Social insurance institutions
- IT service providers (under a processing agreement pursuant to Art. 28 GDPR in conjunction with Section 80 SGB X)
- Authorities on a statutory basis
9. Tracker Integrations
9.1 Google (Google Health API)
You can connect the mind+move app to your Google account in order to use your activity and fitness data (in particular step data) for the movement challenges.
Provider: Google LLC, USA
Data accessed: Activity and fitness data, read-only (scope: googlehealth.activity_and_fitness.readonly)
Legal basis: Your explicit consent (OAuth authorization, Art. 6(1)(a) and Art. 9(2)(a) GDPR)
Processing on your device only: The activity and fitness data retrieved from Google is processed exclusively locally on your device. Only the step values derived from it within the app are used for the challenge function. The data obtained from Google is not transmitted to servers of mhplus or to third parties, is not used for advertising purposes and is not sold.
The app's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Connecting your Google account and US transfer: Connecting requires a Google account. The provider is Google LLC in the USA. The activity and fitness data stored in your Google account is processed by Google under its own responsibility in accordance with the Google Privacy Policy, including in the USA. When you connect the app with your Google account, this data held at Google is accessed. The mind+move app does not transfer this data to mhplus servers or to third parties, it processes only the step values derived from it locally on your device.
Withdrawal: You can disconnect the connection at any time in the app under Settings, or revoke access in your Google account at myaccount.google.com/permissions.
Google privacy policy: https://policies.google.com/privacy
9.2 Fitbit
When connected to Fitbit, activity data is retrieved from Fitbit.
Provider: Google LLC (Fitbit), USA
Data transfer: USA (EU-U.S. Data Privacy Framework)
Legal basis: Your explicit consent (OAuth authorization)
Privacy policy: www.fitbit.com/legal/privacy-policy
9.3 Garmin
When connected to Garmin, activity data is retrieved from Garmin.
Provider: Garmin International Inc., USA
Data transfer: USA (standard contractual clauses)
Legal basis: Your explicit consent (OAuth authorization)
Privacy policy: www.garmin.com/de-DE/privacy/connect
9.4 Polar Flow
When connected to Polar, activity data is retrieved from Polar.
Provider: Polar Electro Oy, Finland (EU)
Data transfer: Within the EU
Legal basis: Your explicit consent (OAuth authorization)
Privacy policy: www.polar.com/de/rechtliche-hinweise/datenschutz
Withdrawal: You can disconnect the respective connection at any time in the app under Settings.
10. Apple HealthKit (iOS) and Health Connect (Android)
10.1 Apple HealthKit (iOS)
When using the HealthKit integration, step data and mindfulness minutes are read from the iOS Health app.
Important: This data is processed locally on your device. No transfer to Apple takes place.
Legal basis: Your consent (iOS system dialog)
Withdrawal: You can revoke access at any time in the iOS settings under "Privacy & Security" > "Health".
10.2 Health Connect (Android)
When using the Health Connect integration, step data is read from Health Connect on your Android device.
Important: This data is processed locally on your device. No transfer to Google or third parties takes place.
Legal basis: Your consent (Android system dialog)
Withdrawal: You can revoke access at any time in the Health Connect settings of your Android device.
11. Error Analysis and Logging
11.1 Error tracking
Service: GlitchTip (self-hosted)
Location: Germany
Data collected:
- Anonymized user ID (SHA-256 hash of the insurance number)
- Error messages and stack traces
- App version, device model, operating system version
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in error correction)
Retention period: 90 days
11.2 Support logging
For support requests you can send logs to our support team. These contain the app version, device information and error descriptions.
12. Data Transfer to Third Countries
When using certain functions, data is transferred to the USA:
| Service | Country | Safeguard |
|---|---|---|
| Firebase (push) | USA | EU-U.S. Data Privacy Framework |
| Google Health API | USA | EU-U.S. Data Privacy Framework |
| Fitbit | USA | EU-U.S. Data Privacy Framework |
| Garmin | USA | Standard contractual clauses (SCCs) |
The transfer only takes place with your explicit consent.
13. Retention Period and Deletion
| Data | Retention period | Basis |
|---|---|---|
| User account | Until deletion on request | Art. 17 GDPR |
| Health data | Until deletion on request | Art. 17 GDPR |
| Push token | 35 days after inactivity | Firebase policy |
| Error logs | 90 days | Technical necessity |
| Bonus points | After redemption/expiry | Program rules |
Deletion takes place in consideration of the retention periods pursuant to Section 110a SGB IV, Section 84 SGB X, Section 107 SGB XI and Section 304 SGB V.
14. App Access Permissions
| Permission | Purpose | Required |
|---|---|---|
| HealthKit (iOS) | Retrieval of step data and mindfulness minutes | Optional |
| Health Connect (Android) | Retrieval of step data | Optional |
| Google account (OAuth) | Retrieval of activity and fitness data | Optional |
| Push notifications | Reminders and challenge notifications | Optional |
| Network | Synchronization with the server | Yes |
| Biometric login (Face ID / Touch ID / fingerprint) | Secure login | Optional |
15. Your Rights
| Right | Article | Description |
|---|---|---|
| Access | Art. 15 GDPR in conjunction with Section 83 SGB X | You can request information about the data stored about you |
| Rectification | Art. 16 GDPR in conjunction with Section 84 SGB X | You can request the correction of inaccurate data |
| Erasure | Art. 17 GDPR in conjunction with Section 84 SGB X | You can request the deletion of your data |
| Restriction | Art. 18 GDPR in conjunction with Section 84 SGB X | You can request the restriction of processing |
| Objection | Art. 21 GDPR in conjunction with Section 84 SGB X | You can object to the processing |
| Data portability | Art. 20 GDPR | You can receive your data in a common format |
| Withdrawal | Art. 7(3) GDPR | You can withdraw consent you have given at any time |
Contact for exercising your rights:
mhplus BKK
Data Protection Officer
Franckstrasse 8
71636 Ludwigsburg, Germany
16. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
Competent supervisory authority:
The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Straße 153
53117 Bonn, Germany
Phone: +49 228 99 77 990
Website: www.bfdi.bund.de
17. Minors
Persons under 18 years of age should not submit any personal data to us without the consent of their parents or legal guardians.
18. Links to Other Websites
The app contains links to other websites. We have no influence over whether their operators comply with data protection provisions.
19. Security Measures
We use technical and organizational security measures to protect your data:
- Encrypted data transmission (TLS/HTTPS)
- Secure authentication (OAuth 2.0 with PKCE)
- Password hashing
- Separate environments (development/test/production)
- Regular security reviews
20. Further Information
You can find further information on data protection at mhplus BKK at www.mhplus-krankenkasse.de/datenschutz.
Legal notice: mhplus-app.de/impressum
21. Currency of This Privacy Policy
This privacy policy is currently valid and dated July 2026. As the app is further developed or due to changed legal requirements, it may become necessary to amend this privacy policy.