Health app: EU hosting or a US provider
Updated: 2026-09
Health data falls under the special categories of personal data in the GDPR and carries heightened protection. Server location is less about technical quality than about which legal framework applies, how enforceable your rights are, and who can demand access under what conditions.
For a notes app, few people care where the servers are. For an app accompanying an ongoing course of medication, that changes: this data says something about a condition or a treatment and therefore falls under Article 9 GDPR.
The comparison below is not about provider quality but about the conditions they operate under — and the questions worth asking regardless of location.
| Criterion | Innopulse | Alternative |
|---|---|---|
| Applicable legal framework | Hosted in the EU, GDPR directly applicable, supervisory authority in the same legal space. | Often relies on an adequacy instrument or standard contractual clauses. Their standing has repeatedly been the subject of litigation. |
| Exercising access and deletion rights | Data subject rights against a controller in the same legal space, generally straightforward. | Legally provided for in most cases too. Enforcing them across legal spaces tends to take longer in practice. |
| How the product is funded | Ad-free, no onward sale of user data. | Varies. With free offerings it is worth understanding what funds the product. |
| Feature range and reach | Focused on GLP-1 support in the DACH region and the EU. | Large international providers often offer more integrations, languages and wearable connections. |
When an alternative is the better choice
If you use a specific device or wearable that only connects to one platform, that practical advantage may outweigh server location. What matters is making the trade-off deliberately.
If you use the app outside the DACH region and need functions tuned to local clinicians, pharmacies or insurers, a provider with a presence in your market is often more workable.
If you would rather keep data on the device only, an app without cloud sync is the most consistent answer — at the cost of losing it when you change devices.
FAQ
Is data in the EU automatically safer?
Not automatically. Location determines the applicable legal framework, not the technical safeguards. Encryption, access control and data minimisation have to be assessed separately.
What should I check before installing?
Where the data sits, how the provider is funded, what is collected at all, whether an export exists, and how to delete the account completely. Any usable privacy policy answers those five.
Does this apply to users in Switzerland?
Switzerland applies its revised data protection act, which also treats health data as particularly sensitive. For providers with an EU nexus the GDPR is relevant on top of that.
Penday
Penday hosts in the EU and carries no advertising. For data about an ongoing course of treatment we regard that as the foundation, not as a selling point that could be dropped.
The application collects only what the support function needs. Less data collected is the most effective privacy measure there is, regardless of where the server sits.
