Gårdisto AB · Updated 8 September 2026
Privacy Policy
Only Hz and getonlyhz.com are provided by Gårdisto AB, Sweden. We are responsible for the processing described here. Contact support@gardisto.eu with questions or privacy requests.
Only Hz does not require an app account. It has no advertising, app-added behavioural analytics or cross-app tracking. We do not sell personal information.
Audio delivery and service security
When the app prepares or plays audio, our service processes the requested frequency, session length and programme where applicable. The audio service uses OpenAI Sites and Cloudflare infrastructure; this information website is hosted by Vercel. Providers may process an IP address, request time and path, device or browser information, security signals, approximate location derived from an IP address, and diagnostics such as response status or latency to deliver, secure and troubleshoot the service.
Our application uses the network address to create a process-local, pseudonymous rate-limit key. It does not store the raw address in that map; the counter is removed when its one-minute window ends. Provider-managed delivery and security logs are separate.
Google Play purchases and access checks
Google Play handles payment for the paid app and, in Android versions that offer it, an optional one-time full unlock. Google may provide Gårdisto AB with sales, tax and financial reports. We do not receive payment-card details.
For installation and audio-access verification, the app sends a Google Play Integrity proof and a random request reference. In versions offering the unlock, verifying or restoring it also sends a Google Play purchase token. We check the installation and current purchase status with Google, including pending, cancelled, consumed, refunded and acknowledgement states. Eligible purchases are acknowledged with Google before access is confirmed. These checks are for purchase fulfilment, restoration, fraud prevention and protected audio access, not advertising.
Google Play sends purchase, cancellation and refund-related notifications through Google Cloud Pub/Sub. These may contain purchase tokens, product identifiers, event details and technical message identifiers. We authenticate the notifications and check the current purchase status with Google.
The Android verification service processes those proofs, tokens and notification contents during requests. It does not maintain a customer-account or purchase-history database for these checks or deliberately log those payloads. For sessions requiring the optional full unlock, purchase status is checked again when new playback access is requested. Google and infrastructure providers may separately retain transaction, messaging, security and diagnostic records.
On your device
Volume and session preferences may be saved on the device and can be removed by clearing app data or uninstalling. Local screen-capture status may be used to block protected playback during recording; that status is not sent for advertising. Removing local app data does not delete Google purchase records or provider-managed logs.
Website cookies and external services
We do not add advertising or behavioural-analytics cookies. Hosting and security services may use strictly necessary cookies. External links, Google Play and any services you use alongside Only Hz have their own privacy practices.
Provider information: Google, OpenAI, Cloudflare and Vercel. These providers may process information outside your country, including outside the EEA; their notices describe relevant transfer safeguards.
Purposes, retention and sharing
We process information needed to provide requested playback, purchases, restoration and support, to protect the service from fraud and misuse, and to meet applicable legal and accounting obligations. These purposes rely, as applicable, on providing the service under our contract, legitimate security interests and legal obligations.
We retain support correspondence and any necessary business records for their support, dispute-resolution or legal purpose. We do not retain them for advertising. Technical-log retention depends on the purpose and provider controls. Our verification service does not set the retention of Google purchase records or hosting-provider logs, and we cannot promise their immediate deletion. Contact us for a review of records relating to you.
Information is shared with the service providers described above as needed for these purposes, and where required by law. It is not sold or shared for targeted advertising.
Health information
The app does not request or collect medical records or health measurements. Frequency themes are reflective and spiritual prompts, not a diagnosis or guaranteed health effect. Please do not send sensitive medical information in support messages.
Your rights and deletion requests
Email support@gardisto.eu to request access, correction or deletion, or to ask about restriction, objection or portability where applicable. Explain the request and the relevant approximate date. We may ask for the minimum information needed to locate and verify a record. Because there is no app account, some technical records may not be identifiable as yours.
We assess requests under applicable data-protection law. Some records may need to be retained for legal obligations or claims. You can also complain to the Swedish Authority for Privacy Protection, IMY, or your local supervisory authority. Changes to this notice will be published here with an updated date.