Last updated: September 24, 2026
This policy covers two things: the website bedfit.app and the Bedfit app. They are very different in how much data they involve, so they are described separately. The first part is about the website, the second part, starting at "The Bedfit app", is about the app.
The website is deliberately lean: it tells you about Bedfit, offers a waitlist so we can let you know when the app launches, and lets you request personal coaching. Nothing else happens there right now: no ads, no accounts, no ad trackers, and no analytics cookies; for traffic measurement we use the cookieless Pirsch (more on that below).
The app is the actual product, and it does involve real data: an account, your conversations with the AI coach, what the coach remembers about you, and your training. Bedfit is about sexual health, so a lot of this is health data in the sense of Art. 9 GDPR. We treat it accordingly, and we would rather write down plainly what happens than leave you guessing.
The controller responsible for data processing on this website and in the Bedfit app is:
Burkhart Digital LLC, 30 N Gould St #21068, Sheridan, WY 82801, USA
Represented by: Thomas Burkhart
Email: [email protected]
Only six processing activities currently take place on this website:
There are no ad trackers, no analytics or marketing cookies, no sharing of your data for advertising purposes, and no newsletter beyond the waitlist notification.
This website is hosted by Hetzner Online GmbH on servers in the European Union. As our processor, Hetzner handles the data required to operate the website on our behalf.
When you visit the website, access data is automatically processed in server logs: IP address, user agent (browser and device type), time of access, and the requested URL. We use this data for a short period to keep the site running, find errors, and fend off attacks. The legal basis is our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR).
One detail that matters to us: email addresses never appear in our logs in plain text, only as a cryptographic digest (HMAC). Even someone with access to the logs could not reconstruct your address from it.
All access to this website passes through the network of Cloudflare, Inc. (USA). Cloudflare serves as a content delivery network and protective layer: it delivers the website quickly and fends off attacks (such as overload and bot attacks). In doing so, Cloudflare necessarily processes your IP address and other connection data. The legal basis is our legitimate interest in the fast and secure delivery of the website (Art. 6(1)(f) GDPR). The transfer to the USA is based on the EU standard contractual clauses and Cloudflare's certification under the EU-US Data Privacy Framework.
If you join the waitlist, we process your email address, your language choice, and the page or campaign that brought you to us (referrer page/UTM parameters).
We use a double opt-in procedure: after you sign up, we send you an email with a confirmation link. Your sign-up only becomes effective once you click that link — until then we send you nothing further. This ensures that nobody can enter your address without your knowledge.
To be able to prove your sign-up, we store the time of your sign-up, of the confirmation email being sent, and of your confirmation, as well as the IP address and user agent of the confirmation click.
The legal basis is your consent (Art. 6(1)(a) GDPR); we store the proof data to meet our obligation to demonstrate consent (Art. 7(1) GDPR).
The purpose of the waitlist is a one-time notification when the app launches, plus a few updates directly related to it. No other advertising, no general newsletter. Every email contains an unsubscribe link; you can withdraw your consent at any time with effect for the future. Unconfirmed entries and unsubscribed addresses are not used any further.
One honest word: Bedfit is about sexual health. We are aware that merely signing up for this waitlist is a more sensitive matter than on most other websites — even though we collect no health data here, only your email address. We treat it accordingly: discreetly, without sharing it with third parties for advertising purposes and, as described above, without plain text in our logs.
Via the form on the page about Till, you can request personal coaching. We process the details from the form: first name, last name, email address, and phone number. There is deliberately no message field — everything substantive is discussed directly with Till afterwards, not through the form. Please note: the coaching itself takes place in German.
Your request is delivered by email directly to Till — he will contact you personally — and is also stored in our database so we can handle it reliably. The legal basis is the performance of pre-contractual measures taken at your request (Art. 6(1)(b) GDPR); with the checkbox in the form you confirm that we may use your details for this purpose.
To prevent abuse and spam, we additionally store the IP address and browser identifier (user agent) at the time of your request (Art. 6(1)(f) GDPR); both are deleted together with the request.
We treat your request discreetly and keep it only as long as needed for handling it and setting up the coaching; after that we delete it.
To send confirmation and notification emails and to deliver coaching requests, we use the service Resend (Resend, Inc., USA) as our processor. Resend processes your email address, the respective email contents, and the technical data of the email delivery on our behalf and on the basis of a data processing agreement. The transfer to the USA is based on the EU standard contractual clauses.
To detect and fix technical errors on our server quickly, we use the service Sentry (Functional Software, Inc., USA) as our processor. When an error occurs, an error report with technical error data (such as the error message, the affected part of the program, and the time) is transmitted to Sentry; processing takes place via Sentry's EU region (ingest.de.sentry.io). We have configured Sentry so that error reports contain no request contents and no email addresses. The legal basis is our legitimate interest in the stable and error-free operation of the website (Art. 6(1)(f) GDPR).
To understand how this website is used (for example, which pages are viewed how often), we use Pirsch Analytics, operated by Emvi Software GmbH (Germany), as our processor. The data is processed exclusively on servers in Germany.
Pirsch works without cookies and does not access your device's storage — so no consent under § 25 TDDDG (the German act on data protection in digital services) is required, and you will not see a banner for this either. Your IP address is not stored: together with your user agent, the date, and a daily changing random value, it only feeds into a short-lived, anonymous identifier from which it cannot be reconstructed and which changes after 24 hours at the latest. Recognizing you over longer periods, across devices, or across other websites is therefore not possible.
The legal basis is our legitimate interest in measuring the use of our website without invasively tracking you (Art. 6(1)(f) GDPR).
This website sets exactly one cookie: it stores your language choice so the site appears in your language on your next visit. This cookie is technically required to provide the service you requested (§ 25(2) no. 2 TDDDG); no consent is needed for it, which is why you see no cookie banner here. We do not use analytics, tracking, or marketing cookies; our traffic measurement (Pirsch, see above) also works without cookies.
Everything above describes the website. From here on, this policy describes the Bedfit app for iOS and Android.
The app talks to our own server at api.bedfit.app. That server runs on the same machine as the website, at Hetzner Online GmbH in the European Union, and requests to it pass through Cloudflare, Inc. (USA) in the same way website requests do. So the access data described under "Hosting and access data" and "Content delivery network" applies to app requests too: IP address, user agent, time of access and the requested address end up in server and proxy access logs, are used to keep the service running, find errors and fend off attacks, and are kept only briefly.
Below we go through everything the app does with your data, feature by feature.
The app needs an account. You can create one in three ways:
Whichever way you sign up, a profile record is created alongside it. It holds a user name, a full name, your email address and, if the sign-in service supplied one, a profile picture. It is deleted together with your account.
Inside Bedfit you are identified by a random internal id, not by your email address. That id is what is attached to your data on our server. On your device, the login token is stored in the operating system's secure storage (Keychain on iOS, Keystore on Android).
On first launch, the app gets a random, anonymous id from our server. Until you sign up, we store only usage events, the install attribution and a purchase, if you buy before signing up, under it. Your answers to the opening questions stay on your device until then. When you sign up, the id becomes part of your account. If you do not create an account within 30 days, we delete it; usage, attribution and purchase data then remain only without any link to you.
Sign-in attempts, successes and failures are recorded in our server logs for security and troubleshooting. Failed sign-ins in the app are also reported to our error reporting service (see below).
Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR) and, for the security logging, our legitimate interest in a secure service (Art. 6(1)(f) GDPR).
Before the first conversation, the app asks you a few questions so the course and the coach can be useful to you. We store the answers with your account: which track you are training (premature ejaculation or erections), your age or age bracket, what you have already tried, your own assessment of where you are starting from, how confident you feel, how long this has been going on, whether you have had therapy before, a first name you choose for yourself, and your language.
These answers say something about your sexual health. They are health data in the sense of Art. 9 GDPR, and we process them on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by answering and starting to use the app, together with Art. 6(1)(b) GDPR for providing the service. You can withdraw that consent at any time by deleting your account.
Two of these answers, how long this has been going on and whether you have had therapy, are also written into the coach's memory (see below), so the coach does not have to ask you again.
The coach is an AI. It is not Till and not a therapist, and there is no message channel from the coach to Till or to anyone on our team.
To produce an answer, our server sends a request to an AI provider. At the moment that is Google (Google, USA), model Gemini, through Google's Gemini API. If Gemini declines a message, Anthropic (Anthropic PBC, USA) answers that one message with its Claude model through Anthropic's API. We can also switch to Anthropic entirely.
What we send with each request:
What we do not send: your email address and your account id are not part of the request, and we attach no user identifier to it. The provider cannot tell from us which account a conversation belongs to.
What does go out is the first name you chose for yourself, because it is part of what the coach knows about you, and any first name of a partner the coach has noted. If you would rather not have that, a nickname works just as well: you can change the name you use at any time in the settings.
How long the provider keeps it, checked on 20 September 2026: Anthropic deletes API inputs and outputs within 30 days of receiving them, except for content its automated safety systems flag, which it may keep for up to two years. Google states for the paid tier of the Gemini API that it logs prompts and responses for a limited period, without naming a duration, and uses them only to detect abuse and to meet legal obligations. Neither provider uses this data to train or improve its models, and both act as our processors under a data processing agreement. We are asking Anthropic for an arrangement with no retention at all; if we get it, this paragraph changes and says so.
If you dictate a message instead of typing it, the speech recognition is done by your device's operating system (Apple or Google). Their terms apply to that; we receive only the resulting text.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and your explicit consent to processing health data (Art. 9(2)(a) GDPR), which you give on the notice shown before the first conversation.
There is no message table on our server. Your chat thread is held by the app on your device, and the server does not keep a copy of it as a matter of course. What the server does store per conversation is metadata: when it started, how many messages, how many tokens it cost, which model and which prompt version were used, and a short AI-written summary for continuity into the next conversation.
There are two exceptions where actual conversation text is stored:
A full transcript can be written alongside that metadata, which means your exchanges with the coach in readable form, capped at the most recent ones. This is off by default: normally we do not store what you and the coach say to each other. It is controlled by two switches, and we want to be straight about both:
So while neither switch is set for you, nothing of your conversations is stored in readable form. If one is, the transcript is stored with your account and is deleted when you delete your account.
Anonymized training samples. We are building a corpus of real coach conversations so that a future model can carry Till's way of talking. Before anything is written, each captured exchange is put through an automated anonymization pass that replaces names, places, employers and institutions with neutral placeholders and blurs details such as an exact age or profession. That pass is itself a request to Anthropic (a smaller model, Claude Haiku), even when Gemini answered, so the exchange goes out a second time before anything is stored. If the pass fails, nothing is written. The stored row carries no account id, no conversation id and no link to any table that identifies you, and it is dated to the day rather than the second. This capture is off by default and is switched on deliberately. One case is captured regardless of that switch: if the AI provider's content filter refuses an exchange, that exchange is captured (through the same anonymization) because otherwise it would be lost.
Legal basis for the transcript: our legitimate interest in finding and fixing problems with the coach (Art. 6(1)(f) GDPR). Legal basis for the training samples: our legitimate interest in improving the coach (Art. 6(1)(f) GDPR), on data from which the identifying details have been removed.
So that you do not have to start over every time, the coach stores individual facts about you: things you told it about your health, your goals, your progress, your patterns, your history and your current state, and it may store the first name of a partner if you mention one. Each fact is a short sentence, stored with your account, a category and a date. There is no fixed expiry; older and less important facts are deactivated once there are too many.
You can see this memory in the app and delete it: a single fact, or all of it at once. Deleting all of it really deletes the records, and it also clears the conversation summaries so the coach cannot infer from them what it just forgot. Your training progress is not affected by that. One limit worth knowing: if a transcript of your conversations was stored (see above), your original messages stay in that transcript until you delete your account.
Notes you save from a conversation (the coach's answer plus your question) are stored with your account on our server so they survive a reinstall. You can delete all of them in the settings.
Three things in a conversation can reach our team:
Legal basis: our legitimate interest in a coach that actually answers people's questions and in fixing problems you report (Art. 6(1)(f) GDPR); sending a conversation for review happens on your request.
If you rate a coach message with a thumb or report it, we store the rating, the reason, your comment and a short excerpt of the conversation around that message. This is stored under a random id generated on your device, not under your account: we can read the feedback, but not who sent it. This feedback is off until you turn it on.
The general feedback button in the app uses the feedback service Wiredash. It transmits your account id and your language, together with the device and app information the service collects by itself and, if you take one, the screenshot you send.
Legal basis: your consent (Art. 6(1)(a) GDPR) for the message feedback you switch on, and our legitimate interest in improving the app for feedback you actively send (Art. 6(1)(f) GDPR).
The training module runs on your device. After a session, a record is synced to our server so your history survives a reinstall and the coach can refer to it: when the session started, the level and track, whether you completed it, which phase it ended in and how far into that phase, why it ended, how many pauses there were, how much guidance audio you had set (off, only at the transitions, or full) and whether music was on, how the stimulus was configured (placement and intensity) and, if you tapped it, the mood chip afterwards. Which videos of the course you have watched is stored as well.
What is deliberately not stored: which specific recording you listened to. That would be data about your sex life, and the fields that used to hold it were removed.
If you record in the app that you had sex, how it went and how it compared to before, we store that entry on our server too, with everything you enter in it, including the free-text field. That is so the log survives a reinstall and is not lost, and so the coach can read a summary of it when you talk. You can delete individual entries or the whole log at any time in the settings. When you delete your account, the entry is separated from your account and the free text in it is removed; the rest of it (when, whether alone or with a partner, how it felt) is kept with no link to you.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and your explicit consent for health data (Art. 9(2)(a) GDPR).
Videos and audio are streamed from Cloudflare R2, a storage service of Cloudflare, Inc. (USA). Our server checks your access and then hands your app a short-lived link. That link is signed by us, not by you: it contains no account id, no device id and nothing else that identifies you, and two people watching the same lesson get the same kind of link. Cloudflare sees the IP address and the browser or app identification of the requesting device, the time, and the internal name of the file. Those file names are deliberately short technical identifiers, so the title of a lesson does not appear in addresses or logs.
If you import your own audio file for the training, that file stays on your device. The app copies it into its own folder and never uploads it, and its name is never sent to us.
Purchases are handled entirely by the App Store or Google Play. We never see your payment data.
To find out whether you have bought access, we use RevenueCat (RevenueCat, Inc., USA) as a processor. From the first launch, the app tells RevenueCat your internal Bedfit id, which before you sign up is the anonymous id (see "Your account"), so your purchase follows your account across devices. We set no name, no email address and no other personal attributes on it.
Our server stores, per account: the status of your access, which product it is, when it expires, whether it came from Apple or Google, the transaction id from the store and the id of the RevenueCat record. No receipts and no payment data are stored.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
To see where people get stuck, the app sends usage events to our own server. There is no third-party analytics provider in the app and no Pirsch: these events land in our own database. Each event carries the name of the event, a timestamp, the app version, the platform, your internal id (the anonymous one before you sign up, see "Your account") and, added on our side, the IP address of the request and the country derived from it.
When the app is first launched, it also tries to work out which advertisement an install came from. On Android it reads the referrer the Play Store supplies. On iOS, where there is no such referrer, it sends the device model, the operating system version, the language setting and the time zone so an install can be matched against a click with some probability.
Legal basis: our legitimate interest in understanding and improving the use of our app (Art. 6(1)(f) GDPR).
When the app runs into an error, an error report is sent to Sentry (Functional Software, Inc., USA), processed through Sentry's EU region (ingest.de.sentry.io), as described above for the website. The app's error reports can contain your IP address and information about your account, so that we can tell which account an error affected. Error reports are sent for technical faults, not for the content of your conversations.
Legal basis: our legitimate interest in an app that works (Art. 6(1)(f) GDPR).
Besides writing to us, the app gives you four things you can do yourself, in the settings:
Deleting your account removes, from our server: your conversations including any stored transcript and summaries, the conversations you sent in for review, the coach's memory about you, your notes, your settings and onboarding answers, your daily usage totals and your current rate-limit counter, and your login records with Google, Apple or your email address, along with the account itself and your profile record. On your device, all local data is wiped at the same time. This happens automatically once you confirm the deletion in the app; you do not have to write to us for it.
What remains after that: a keyed, irreversible hash of your email address, with the date, so we can tell that an address belonged to a deleted account if it is used to register again. Your email address itself is not kept. Some records are kept, but with no link to you: your course progress, your training session history, your event log (with the free text in it also removed), the usage events, the log of when you ran into a usage limit, and the install-attribution record. In those we replace your account's identifier with a random label that points to nothing, and we shorten the timestamps to the minute. In the escalations described above (knowledge gaps and product feedback) we also replace your own wording, so only the topic is left. Your purchase records are kept for bookkeeping, because we are legally required to, but with the link to your account removed entirely. On top of that we write a single anonymous row for our statistics: how many lessons were watched, how old the account was, which course and which month, with no identifier of any kind. None of it points back to you. The anonymized training samples cannot be deleted on request, because there is deliberately nothing in them that would let us find your rows.
Some of the processing described above involves transfers to the USA: to Cloudflare (EU standard contractual clauses and EU-US Data Privacy Framework), to Resend (EU standard contractual clauses), and to Sentry (certified under the EU-US Data Privacy Framework, additionally EU standard contractual clauses; the error reports themselves run through Sentry's EU region). In addition, the controller itself is based in the USA, so waitlist data is also processed there. The hosting of the website itself takes place on servers in the EU, and traffic measurement with Pirsch runs entirely on servers in Germany — no data leaves the EU there.
For the app, further transfers to the USA take place: to the AI providers that produce the coach's answers (Google and Anthropic), to RevenueCat for your purchase status, and to Cloudflare for delivering videos and audio. Our own server and its database, and with them your account, your conversations' metadata, the coach's memory and your training history, are located in the European Union.
We store data only as long as needed for the respective purpose: server logs are kept only briefly for operational and security purposes. Waitlist data is stored until the purpose is fulfilled or you unsubscribe; unconfirmed entries and unsubscribed addresses are not used any further. Coaching requests are stored until they are dealt with or as long as needed to set up the coaching, and deleted afterwards. Proof of consent is kept as long as we must be able to demonstrate it.
Data in the app is stored for as long as your account exists, and is deleted when you delete your account, with the exceptions named under "Deleting your data in the app". An anonymous id for which no account was ever created is deleted after 30 days (see "Your account"). Your chat thread itself is not kept by us at all; it lives in the app on your device. The coach's memory can be deleted at any time without deleting the account.
As a data subject, you have the following rights under the GDPR:
Just contact us at [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in Germany, the authority of your federal state.
For the app, you can exercise some of these rights yourself, right away: the settings let you delete the coach's memory, your notes, your event log and your entire account (see "Deleting your data in the app").
As the website and the app evolve, we will update this privacy policy. The current version published here applies; you can find its date at the top.