Skip to content
herPrivacy
Language English
  • English
  • हिन्दी
  • বাংলা
  • অসমীয়া
  • தமிழ்
  • తెలుగు
  • മലയാളം
  • ಕನ್ನಡ

Legal

Privacy Policy

Rendered from herprivacy/docs/legal/privacy-policy.md — the reviewed source document.

On this page

  • The short version
  • 1. Who we are
  • 2. What stays on your phone
  • 3. What leaves your phone
  • 4. What we never do
  • 5. Who else is involved
  • 6. Your rights
  • 7. If you are under 18
  • 8. Security
  • 9. Where your data is processed
  • 10. How long we keep things
  • 11. Changes to this policy
  • 12. Medical disclaimer

Privacy Policy — herPrivacy

Last updated: 8 August 2026 Applies to: herPrivacy for Android and iOS, version 1.0 and later.


The short version

Your cycle data stays on your phone. We cannot read it. We do not sell it, share it, or use it for advertising — and we have built the app so that we could not, even if we wanted to.

You do not need an account to use herPrivacy. If you choose to turn on backup, we store a copy that is already encrypted before it leaves your phone, using a passphrase we never receive.

The rest of this policy explains that precisely, because on this subject you deserve detail rather than reassurance.


1. Who we are

herPrivacy is operated by herPrivacy by Karao Digital, 3/1 A, 6th Cross, 1st Main, Mahadevpura, Outer Ring Road, Mahadevpura, Bengaluru - 560048, India.

For any question about this policy or your data: karao.digital@gmail.com

Grievance Officer

As required by the Digital Personal Data Protection Act, 2023:

Moumita Chowdhury Chatterjee Email: cmoumita88.mc@gmail.com

Any complaint about how your data is handled can go directly to the Grievance Officer, who will acknowledge it within 7 days and resolve it within 30 days. You do not have to raise it with anyone else first.


2. What stays on your phone

Everything you log. Specifically:

  • Period start and end dates, flow intensity
  • Symptoms, and any private notes you write
  • Optional sexual activity records (off by default; recorded only as none/protected/unprotected)
  • Your age range, PCOS status and cycle-regularity answers from onboarding
  • Predictions, detected patterns, and the explanations shown to you
  • PDF reports and any CSV or JSON exports you generate

This is stored in an encrypted database on your device (SQLCipher). The encryption key is generated on your phone and held in the platform's secure keystore — the iOS Keychain or the Android Keystore. It is never transmitted.

We never receive any of it. Not in aggregate, not anonymised, not for research.


3. What leaves your phone

Four things. Three are optional and off until you turn them on. The other is a once-a-day check for a software update, described in §3.3 — we have put it in this section rather than leaving it unmentioned, because it is the only thing here that happens without you asking.

3.1 Your email address — only if you enable backup

Backup needs a way to give your data back to you on a new phone, and that requires an identity. Signing in uses a one-time code sent to your email, handled by Clerk (clerk.com), our authentication provider.

  • Clerk holds your email address. We do not store it. Our own records contain only an opaque identifier that Clerk gives us.
  • We never send you marketing email. The only email you receive is your sign-in code.
  • You are asked to sign in at exactly one point in the app: turning on backup. Declining costs you nothing else.

3.2 An encrypted backup — only if you turn it on

When you enable backup, herPrivacy asks you to choose a recovery passphrase, then:

  1. Derives an encryption key from that passphrase on your phone (PBKDF2-SHA256, 600,000 iterations).
  2. Encrypts a snapshot of your data with AES-256-GCM, on your phone.
  3. Uploads only the resulting ciphertext to our storage (Cloudflare R2, Asia-Pacific region).

Your passphrase never leaves your device, and we never receive it. This has a consequence we want stated plainly rather than buried: if you forget your passphrase, your backup cannot be recovered — not by you, and not by us. There is no reset, because a reset we could perform would mean we could read your data.

Alongside the ciphertext we store: a random backup identifier, your opaque account identifier, the size in bytes, a checksum of the encrypted file, and the time it was created. No filename, no date range, no counts, nothing describing what is inside.

We keep the three most recent backups and delete older ones automatically.

3.3 A check for software updates — at most once a day

herPrivacy can repair itself between app-store releases. That matters most for the things you would never see: a flaw in the encryption, or a change to a security certificate that would otherwise stop the app working. To do that, the app asks our update provider whether a newer version exists.

How often: at most once every 24 hours, and never while you are waiting on a screen. Most apps make this request every time they are opened; we deliberately do not, because you may open a period tracker several times a day and we did not want that pattern leaving your phone.

What is sent:

  • A random installation identifier, created on your phone the first time the app runs. It is not your email, not your account, and not linked to either — if you enable backup, the two are held by different companies and we do not connect them.
  • Which platform you are on (Android or iOS), the app version, and which release track the app was installed from.
  • Your IP address, which is unavoidable in any internet request.

What is not sent: anything about you. No cycle data, no symptoms, no dates, no settings, no identifiers that mean anything outside this one purpose.

Can you turn it off? Not from inside the app, and we want to be straight about why rather than pretend it is an oversight. This is the only route a security fix has to an installation that has never signed in — which is most of them, by design. An update channel that people can switch off is one that fails for exactly the users who most need it. If you would rather not have it at all, turning off the app's network access in your phone's settings stops it, along with backup.

3.4 A crash report — only if you switch it on

Under Settings → Privacy → Optional data there is a switch called "Send crash reports". It is off. If you turn it on, then when the app crashes it records what went wrong and sends it the next time you open the app.

What is sent:

  • The kind of error (for example TypeError) and one line saying which part of the app's code it happened in.
  • Which screen you were on — the screen's name only, never anything the screen was showing.
  • The app version, your platform, and your OS version.

What is not sent — and this is enforced by how it is built, not by a promise. There is no field for an error message anywhere in this system. Error messages are written by whatever broke, and they routinely quote the data they were working on, which in this app would be your entries. So instead of collecting the message and trying to clean it, the app never collects it: it picks a short label from a fixed list we wrote in advance, and nothing from the error itself is attached. The same rule removes the details from screen names — the app reports that you were on the cycle screen, never which date you were looking at.

There is no identifier of any kind. We can see that a crash happened, not who it happened to, and not whether two crashes came from the same phone.

The reports go to our own servers, not to a crash-reporting company. That was the point of building it ourselves: the alternatives all collect error messages and a device identifier by default, which for a period tracker is the wrong default in both directions.

Turning the switch off deletes anything still waiting to be sent.

3.5 Nothing else

Beyond §3.1–3.4, herPrivacy sends no analytics, no telemetry and no advertising identifiers. There is no third-party tracking of any kind, and no advertising SDK in the app.


4. What we never do

  • We do not sell your data. There is no circumstance in which we would.
  • We do not share it with advertisers, data brokers, insurers or employers.
  • We do not use it to train machine-learning models. The prediction model shipped with the app was trained entirely on synthetic data before release, and does not learn from you or send anything anywhere.
  • We do not build profiles for advertising.
  • We do not track you across other apps or websites.

5. Who else is involved

ProviderWhat they doWhat they can see
ClerkSign-in by emailed one-time codeYour email address. No health data of any kind.
CloudflareStorage and API hostingEncrypted bytes they cannot decrypt, plus the metadata in §3.2.
ExpoDelivering software updatesOnly what §3.3 lists: a random installation identifier, your platform and app version, and your IP address. No health data, and no way to link it to your email.

Both are contractually bound to process data only on our instructions. Neither has ever been given, and neither can obtain, anything readable about your cycle.


6. Your rights

Under the DPDP Act 2023 you may access, correct, or delete your data, and withdraw consent.

Because your data is on your phone, most of this you do directly and immediately:

  • Access and export — Settings → Data → Export (JSON or CSV, generated on your device).
  • Correct — edit or delete any entry, at any time.
  • Delete everything local — Settings → Data → Review deletion. Requires typing DELETE, and cannot be undone.
  • Delete your backups — Settings → Backup. This removes them from our servers.
  • Withdraw consent — turn backup off, or delete the app. Uninstalling removes all local data.

For anything you cannot do in the app, write to the grievance officer in §1. We acknowledge within 7 days and respond within 30 days.


7. If you are under 18

herPrivacy is not intended for anyone under 12.

If you tell us you are between 12 and 17, the app runs in a restricted mode: everything stays on your phone and cloud backup is not offered, so nothing is transmitted at all.


8. Security

  • Local data: SQLCipher (AES-256), key in the platform keystore.
  • Backups: AES-256-GCM, encrypted on your device before upload.
  • Key derivation: PBKDF2-SHA256, 600,000 iterations, per-backup random salt.
  • In transit: TLS.
  • Optional app lock with PIN or biometrics; screenshot blocking on sensitive screens.
  • Our servers log no request bodies, no email addresses and no health data.

No system is perfect, and we will not claim otherwise. What we can say is that the design limits the damage: a complete compromise of our servers would expose encrypted files nobody can open and a list of opaque identifiers.


9. Where your data is processed

Backups are stored on Cloudflare R2 in the Asia-Pacific region.

Sign-in is handled by Clerk. We are confirming in writing which region processes it, and will name that region here as soon as we have their answer. We would rather leave this sentence visibly incomplete than state a location we have not verified — the only thing Clerk holds is your email address, and none of your cycle data is ever sent to them.

The update check in §3.3 is answered by Expo's globally distributed network, so it is served from whichever location is nearest to you. Nothing about you is stored there — the request carries only the installation identifier, platform and app version listed in §3.3.


10. How long we keep things

  • On your phone: until you delete it, or delete the app. Nothing on this list expires.
  • Backups, while you are using the app: until you delete them. The three most recent are kept; older ones are pruned automatically.
  • Backups, if you stop using the app: if you do not open the app for 24 months, your backups are marked for deletion and removed 30 days after that. Your local data on the phone is untouched — this only affects the encrypted copies held on our storage.
  • Account record: until you ask us to delete it.

Why 24 months and not less. This app tracks a cycle, and someone who is pregnant, post-partum, on contraception that suppresses menstruation, or simply taking a break is still using the app in every sense that matters. A shorter window would delete the histories of people who fully intend to come back.

We do not currently email you before this happens, and we would rather say so than imply a warning you will not receive. By construction this only affects accounts that have not opened the app in two years, so an in-app notice cannot reach them either. If you want to keep a copy regardless, Settings → Data exports your full history to a file you hold yourself, and that file never expires.

What resets the clock: anything that reaches our servers while you are signed in — backing up, restoring, or opening the Backup screen. Using herPrivacy offline does not, because we genuinely cannot see it. If you use the app happily for years without ever turning backup on, there is nothing of yours on our servers for this to apply to.


11. Changes to this policy

If we change it materially, we will tell you in the app before the change takes effect. The "last updated" date at the top always reflects the current version.


12. Medical disclaimer

herPrivacy is not a medical device and does not diagnose, treat or prevent any condition. Its predictions are estimates from your own history and can be wrong. It is not a contraceptive and must not be relied on to prevent pregnancy.

Explanations shown in the app are written and reviewed by qualified clinicians as general information. They are not personal medical advice. If something concerns you, speak to a doctor.

Full terms are in the Terms of Service.

herPrivacy

Period and PCOS tracking that stays on your phone.

Pages

  • Home
  • Privacy Policy
  • Terms of Service
  • Support

Contact

karao.digital@gmail.com

Support, privacy and security.

Grievance Officer

Moumita Chowdhury Chatterjee

cmoumita88.mc@gmail.com

Required under India's DPDP Act, 2023. Any complaint about how your data is handled can go straight here — you do not have to raise it with support first.

herPrivacy is operated by Karao Digital .

3/1 A, 6th Cross, 1st Main, Mahadevpura, Outer Ring Road, Mahadevpura, Bengaluru - 560048, India.

Not a medical device. herPrivacy does not diagnose, treat or prevent any condition, and it is not a contraceptive. If something worries you, speak to a doctor.

© 2026 herPrivacy by Karao Digital