Legal
Privacy Policy
Rendered from herprivacy/docs/legal/privacy-policy.md — the reviewed source document.
Privacy Policy — herPrivacy
Last updated: [DATE] Applies to: herPrivacy for Android and iOS, version 1.0 and later.
The short version
Your cycle data stays on your phone. We cannot read it. We do not sell it, share it, or use it for advertising — and we have built the app so that we could not, even if we wanted to.
You do not need an account to use herPrivacy. If you choose to turn on backup, we store a copy that is already encrypted before it leaves your phone, using a passphrase we never receive.
The rest of this policy explains that precisely, because on this subject you deserve detail rather than reassurance.
1. Who we are
herPrivacy is operated by herPrivacy by Karao Digital, 3/1 A, 6th Cross, 1st Main, Mahadevpura, Outer Ring Road, Mahadevpura, Bengaluru - 560048, India.
For any question about this policy or your data: karao.digital@gmail.com
Grievance Officer
As required by the Digital Personal Data Protection Act, 2023:
Moumita Chowdhury Chatterjee Email: cmoumita88.mc@gmail.com
Any complaint about how your data is handled can go directly to the Grievance Officer, who will respond within [N] days. You do not have to raise it with anyone else first.
2. What stays on your phone
Everything you log. Specifically:
- Period start and end dates, flow intensity
- Symptoms, and any private notes you write
- Optional sexual activity records (off by default; recorded only as none/protected/unprotected)
- Your age range, PCOS status and cycle-regularity answers from onboarding
- Predictions, detected patterns, and the explanations shown to you
- PDF reports and any CSV or JSON exports you generate
This is stored in an encrypted database on your device (SQLCipher). The encryption key is generated on your phone and held in the platform's secure keystore — the iOS Keychain or the Android Keystore. It is never transmitted.
We never receive any of it. Not in aggregate, not anonymised, not for research.
3. What leaves your phone, and only if you ask
Two things. Both optional. Neither enabled by default.
3.1 Your email address — only if you enable backup
Backup needs a way to give your data back to you on a new phone, and that requires an identity. Signing in uses a one-time code sent to your email, handled by Clerk (clerk.com), our authentication provider.
- Clerk holds your email address. We do not store it. Our own records contain only an opaque identifier that Clerk gives us.
- We never send you marketing email. The only email you receive is your sign-in code.
- You are asked to sign in at exactly one point in the app: turning on backup. Declining costs you nothing else.
3.2 An encrypted backup — only if you turn it on
When you enable backup, herPrivacy asks you to choose a recovery passphrase, then:
- Derives an encryption key from that passphrase on your phone (PBKDF2-SHA256, 600,000 iterations).
- Encrypts a snapshot of your data with AES-256-GCM, on your phone.
- Uploads only the resulting ciphertext to our storage (Cloudflare R2, [REGION]).
Your passphrase never leaves your device, and we never receive it. This has a consequence we want stated plainly rather than buried: if you forget your passphrase, your backup cannot be recovered — not by you, and not by us. There is no reset, because a reset we could perform would mean we could read your data.
Alongside the ciphertext we store: a random backup identifier, your opaque account identifier, the size in bytes, a checksum of the encrypted file, and the time it was created. No filename, no date range, no counts, nothing describing what is inside.
We keep the three most recent backups and delete older ones automatically.
3.3 Nothing else
herPrivacy sends no analytics, no telemetry, no crash reports and no advertising identifiers. There is no third-party tracking of any kind, and no advertising SDK in the app.
4. What we never do
- We do not sell your data. There is no circumstance in which we would.
- We do not share it with advertisers, data brokers, insurers or employers.
- We do not use it to train machine-learning models. The prediction model shipped with the app was trained entirely on synthetic data before release, and does not learn from you or send anything anywhere.
- We do not build profiles for advertising.
- We do not track you across other apps or websites.
5. Who else is involved
| Provider | What they do | What they can see |
|---|---|---|
| Clerk | Sign-in by emailed one-time code | Your email address. No health data of any kind. |
| Cloudflare | Storage and API hosting | Encrypted bytes they cannot decrypt, plus the metadata in §3.2. |
Both are contractually bound to process data only on our instructions. Neither has ever been given, and neither can obtain, anything readable about your cycle.
6. Your rights
Under the DPDP Act 2023 you may access, correct, or delete your data, and withdraw consent.
Because your data is on your phone, most of this you do directly and immediately:
- Access and export — Settings → Data → Export (JSON or CSV, generated on your device).
- Correct — edit or delete any entry, at any time.
- Delete everything local — Settings → Data → Review deletion. Requires typing DELETE, and cannot be undone.
- Delete your backups — Settings → Backup. This removes them from our servers.
- Withdraw consent — turn backup off, or delete the app. Uninstalling removes all local data.
For anything you cannot do in the app, write to the grievance officer in §1. We respond within [N] days.
7. If you are under 18
herPrivacy is not intended for anyone under 12.
If you tell us you are between 12 and 17, the app runs in a restricted mode: everything stays on your phone and cloud backup is not offered, so nothing is transmitted at all.
8. Security
- Local data: SQLCipher (AES-256), key in the platform keystore.
- Backups: AES-256-GCM, encrypted on your device before upload.
- Key derivation: PBKDF2-SHA256, 600,000 iterations, per-backup random salt.
- In transit: TLS.
- Optional app lock with PIN or biometrics; screenshot blocking on sensitive screens.
- Our servers log no request bodies, no email addresses and no health data.
No system is perfect, and we will not claim otherwise. What we can say is that the design limits the damage: a complete compromise of our servers would expose encrypted files nobody can open and a list of opaque identifiers.
9. Where your data is processed
Backups are stored in [REGION]. Authentication is handled by Clerk in [CLERK REGION].
10. How long we keep things
- On your phone: until you delete it, or delete the app.
- Backups: until you delete them. The three most recent are kept; older ones are pruned automatically.
- Account record: until you ask us to delete it.
11. Changes to this policy
If we change it materially, we will tell you in the app before the change takes effect. The "last updated" date at the top always reflects the current version.
12. Medical disclaimer
herPrivacy is not a medical device and does not diagnose, treat or prevent any condition. Its predictions are estimates from your own history and can be wrong. It is not a contraceptive and must not be relied on to prevent pregnancy.
Explanations shown in the app are written and reviewed by qualified clinicians as general information. They are not personal medical advice. If something concerns you, speak to a doctor.
Full terms are in the Terms of Service.