Privacy Policy — Balanced
Last updated: April 12, 2026
1. Who we are
Balanced is a wellness app developed by Balansert Mestring AS (org. no. 933 854 760). We are the data controller for the personal data processed in the app.
Contact: balansert@doktorfive.no
2. What the app is – and is not
Balanced is a wellness app for relaxation, stress management and personal development. The app is not a medical device and does not diagnose, treat, cure or prevent any disease. Always contact a healthcare professional for medical advice.
The content in the app is developed by doctors and psychologists, but does not replace individual medical treatment or advice.
3. What personal data we collect
Account information
- Name
- Email address
- Login method (Google, email/password)
- User ID in Firebase Authentication
Subscription and payment data
- Subscription status
- Subscription type
- Purchase history via the app store (we do not see card numbers or bank details)
Usage data
- Which meditations and courses you have listened to
- Course progress
- Practice statistics (streak, mindful minutes, level)
- Your wellness preferences
- Downloaded files for offline use
Technical data
- Device type and operating system
- App version
- Error reports and crash data
Advertising and analytics data
- Advertising ID
- App events
- Anonymised usage statistics
We do NOT collect
Location, contacts, SMS, call history, health records, biometric data or sensitive health information.
4. Legal basis for processing
- Contract (Art. 6(1)(b)): to deliver the service you have requested, including account, content and subscription.
- Consent (Art. 6(1)(a) and Art. 9(2)(a)): for optional cookies, analytics, marketing and processing of any special categories of personal data. Consent may be withdrawn at any time.
- Legitimate interest (Art. 6(1)(f)): for security, fraud prevention, internal analytics and service improvement.
- Legal obligation (Art. 6(1)(c)): for bookkeeping under Norwegian accounting law.
5. Third parties and data processors
We use the following sub-processors. Each one is bound by a data processing agreement (DPA) with us:
- Firebase / Google Cloud (EU) – authentication and push notifications. See Firebase DPA.
- RevenueCat (USA with SCCs) – subscription management and payment processing. See RevenueCat Privacy Policy.
- Meta Platforms Ireland Ltd – ad measurement and campaign analytics. See Meta Privacy Policy.
- App store (Apple App Store / Google Play) – distribution and payment processing.
- Accounting system – bookkeeping and accounting in accordance with Norwegian law.
We never sell personal data to third parties.
6. Advertising ID and tracking
We use Meta/Facebook SDK for ad measurement and campaign optimisation. The advertising ID may be used to measure the effectiveness of advertising campaigns.
You can disable the advertising ID in your device settings:
- iOS: Settings → Privacy & Security → Tracking
- Android: Settings → Google → Ads
7. Storage and retention
- Account information: deleted within 30 days after account deletion.
- Usage data: deleted together with the account.
- Analytics data: anonymised after 26 months.
- Payment data: retained for 5 years in accordance with the Norwegian Bookkeeping Act.
- Downloaded files: deleted 14 days after the last server check.
8. Your rights (GDPR Articles 15–22)
You have the following rights:
- Access – find out what data we hold about you
- Rectification – correct inaccurate data
- Erasure – request deletion of your data
- Restriction – restrict the processing of your data
- Data portability – receive your data in a machine-readable format
- Objection – object to processing based on legitimate interest
- Withdraw consent – withdraw your consent at any time
Contact us at balansert@doktorfive.no to exercise your rights, or use the tools in your privacy settings. We will respond within 30 days.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe we are not complying with applicable privacy law.
9. Account deletion
You can delete your account in the app: Help → Delete account.
What is deleted
- Your authentication account is deleted immediately.
- Usage data is deleted within 30 days.
- Downloaded files are deleted when you uninstall the app.
What we retain
- Anonymised analytics data (cannot be linked back to you).
- Payment data is retained for 5 years in accordance with the Norwegian Bookkeeping Act.
For complete deletion of all data, send an email to balansert@doktorfive.no.
10. Children
Balanced is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you discover that a child has created an account, contact us at balansert@doktorfive.no and we will delete the account.
11. Security measures
We protect your personal data with the following measures:
- HTTPS/TLS encryption for all data in transit
- AES-256 encryption for data at rest
- Firebase Authentication for secure login
- Role-based access control (RBAC) for internal access
In the event of a security breach affecting your personal data, we will notify you and the Norwegian Data Protection Authority within 72 hours in accordance with GDPR Articles 33 and 34.
12. International transfers
Some of our data processors (such as RevenueCat) are located in the USA. For these transfers we use EU Standard Contractual Clauses (SCCs) to ensure adequate protection of your personal data.
Firebase/Google Cloud processes data in the EU region.
13. Automated decisions
We do not make any automated decisions that have legal effects on you or that significantly affect you. Recommendations in the app are based on your wellness preferences and do not constitute profiling within the meaning of the GDPR.
14. Changes to this policy
We may update this privacy policy from time to time. For material changes we will notify you via email or a prominent notice in the app before the changes take effect.