Camera & Health Data Notice
Explicit consent under Article 9 GDPR · version 0.9, 27 August 2026
Camera and health-related indicators
| Controller | MORU-TECH Ltd., UIC 208895389 |
|---|---|
| Product | Moru: web application/PWA and desktop widget |
| Version and date | 0.9 / 27 August 2026 |
| Status | Public text for the web application and desktop widget — working draft |
Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.
1. Short screen before first use
Text for the web application/PWA
| Camera and health-related indicatorsMoru uses the camera to support the exercises and calculate indicative fatigue and eye-care indicators. Video is processed temporarily only on your device. Frames, photographs and facial/iris landmarks are not recorded or sent. Derived numerical indicators and session data are sent to our server, such as blink rate, head position, tracking quality, calibration data and your self-assessments. These may reveal information about your health. Moru does not diagnose and the results are only indicative wellness information. You may refuse or withdraw consent at any time in the Privacy Center. |
|---|
| Element | Text |
|---|---|
| Primary button | “I agree — turn on the camera” |
| Decline | “Not now” |
| Link | “Learn more in the Privacy Policy” |
| Age | “I confirm that I am at least 16 years old.” — separate, non-preselected declaration at registration. |
Text for the desktop widget
| Periodic camera checksTo perform periodic checks, Moru will activate the camera for short measurement windows. Frames and facial landmarks remain only in the device RAM and are deleted after the calculation. Only numerical indicators such as blink rate, PERCLOS, screen distance, head position, confidence and technical flags are sent to the server. These are used to calculate an indicative fatigue score. These data may constitute health data and are processed only with your explicit consent. You may withdraw consent in Settings; the camera will then stop, the local buffer will be cleared and the server will no longer accept new measurements. |
|---|
| Element | Text |
|---|---|
| Primary button | “I agree — enable checks” |
| Decline | “Not now” |
| Link | “Privacy Policy” |
2. Explicit consent statement
| Full consent statementI hereby explicitly consent to MORU-TECH Ltd. processing the described derived indicators, self-assessments and fatigue assessments, which may constitute data concerning my health, for the purposes of providing the exercises, tracking results and displaying personalised wellness recommendations. I understand that raw video frames, photographs and facial/iris landmarks are not recorded or sent to the server; that the service is not a medical diagnosis; and that I may withdraw my consent at any time without affecting the lawfulness of processing carried out before withdrawal. |
|---|
Consent is given through a clear affirmative action. Pre-ticked boxes, silence or default continuation are not used.
3. What the consent covers
| Data group | Examples | Does it leave the device? |
|---|---|---|
| Raw video and facial mesh | Video frames, face/iris landmarks, temporary image buffers | No. Local only in RAM; not recorded. |
| Web training indicators | blink rate, accuracy, stability, head control, tracking quality, session_trace, calibration data | Yes, as derived numerical/structured data. |
| Desktop indicators | blink rate, PERCLOS, screen_distance_cm, head_pitch/yaw, confidence, gating flags | Yes, through an allow-list. |
| Self-assessments and results | fatigue/eye-strain labels, numerical score, textual wellness recommendation | Yes, stored in the profile. |
4. What is not included in this consent
Product analytics and diagnostic events — requested separately.
Google Ads, Meta Pixel and marketing communications — requested separately.
Use of data to train or improve a general machine-learning model — not currently carried out and would require a new purpose, a new DPIA and separate explicit consent.
Disclosure of individual results to employers, schools, insurers or other organisations — not carried out under the current B2C model.
Medical diagnosis, treatment or clinical decision-making — not carried out.
5. Withdrawal of consent
The user opens “Profile” → “Privacy Center” → “Camera and health measurements”.
Selects “Withdraw consent” and confirms the decision.
The application stops the active camera and does not start new measurements.
The local offline queue/buffer is cleared.
The server records the withdrawal with date and version and rejects future payloads with HTTP 403 or an equivalent control.
The user chooses whether to keep previously collected history until the retention period expires or request immediate deletion. By default, the interface also offers a clear “Delete my health history” button.
| Technical task: the web application currently has no separate health-consent and withdrawal control. Before launch, it must be aligned with the desktop mechanism. |
|---|
6. Record for demonstrating consent
| Field | Minimum content |
|---|---|
| user_id | UUID/sub from the verified JWT |
| consent_kind | health_measurements / camera_processing |
| status | granted / withdrawn |
| policy_version | Version of the notice and policy |
| timestamp | UTC date and time |
| surface | web / desktop / mobile, if added |
| locale | Language of the displayed text |
| evidence | Identifier of the UI action and technical version; IP is retained only if necessary and proportionate. |
7. Renewed consent
New consent is requested before a material change, including new health-related indicators, use of a general machine-learning model, training on user data, a new recipient, a new purpose or another change that materially affects the risks. A purely editorial change with no new purpose does not necessarily require renewed consent, but the version is updated.
8. UX and technical acceptance criteria
- No endpoint for health-related measurements accepts data without active consent.
- Symptoms and onboarding goals are not stored locally or on the server before consent.
- The system camera permission is requested only after the information screen and a positive user choice.
- The refusal option is visible, requires the same number of actions and uses no misleading design.
- Withdrawal requires no more actions than giving consent.
- The camera and local buffer stop/are cleared immediately after withdrawal.
- Analytics and marketing consents are separate and are not a condition for the core service.
- Automated tests demonstrate that health payloads do not reach PostHog, GA4, Google Ads or Meta.
Sources and legal basis
Regulation (EU) 2016/679, in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.
European Data Protection Board Guidelines 05/2020 on consent.