Legal

Privacy Policy

Last updated: 21 August 2026

Plain-English summary. PeriFlow stores cycle dates, symptoms, fasts, meals, journal entries, and — if you choose to share it — your HRT (hormone replacement therapy) status. If you turn on sleep import, we read your sleep sessions from Apple Health or Health Connect on your device and keep only a simple 1–5 sleep quality rating — the raw sleep data never leaves your phone. We treat all of this as health data: encrypted in transit and at rest, hosted in the EU, never sold, never shared with advertisers. You can export or delete everything at any time from inside the app.

1. Who we are

PeriFlow ("we", "us", "our") is operated by the developer of the PeriFlow mobile app. This Privacy Policy explains how we handle personal information when you use the app or periflow.io. We are the data controller for the personal information described below.

2. What we collect

We collect account information (email, display name, auth metadata), health and wellness data (cycle dates, symptom logs, fasts, meals, journal entries, movement check-ins, relief exercise history, profile preferences, and optionally HRT status, HRT type, and HRT cycle details), subscription status, consent records, and technical data (event telemetry, crash reports, server logs). Most event telemetry is linked to your account. Before you create an account, we also record a small number of basic events — which onboarding step you reached, whether a screen or prompt was shown — so we can see where the setup process loses people and fix it. Those pre-account events are grouped only by a temporary identifier that exists while the app is open, is never saved to your device, and is never connected to you or to any account you later create. We cannot use them to identify you or to build a profile. Event telemetry records how you use the app — which screens you open, which features you use, whether a prompt was shown or dismissed — and never includes health information: no cycle dates, no symptom values, no journal text, no cycle phase, and no hormone therapy details. HRT data is only collected if you actively provide it during onboarding or in Settings — it is never inferred or required. If you turn on sleep import (Settings → Health Data), we read your sleep sessions from Apple Health (iOS) or Health Connect (Android) on your device and store only a derived sleep quality rating on a 1–5 scale — the same rating you could enter by hand. The underlying sleep records (durations, sleep stages, timestamps) are processed on your device only and are never stored by us or transmitted to our servers. If you request a free guide or sign up for updates on periflow.io, we collect your email address. We never collect contacts, photos, location, or third-party advertising identifiers. Full detail available on request at hello@periflow.io.

3. How we use it

To run the app, sync your data across devices, process your subscription, answer support requests, and improve the app using usage telemetry that contains no health information. If you signed up on our website, we also use your email address to send you the content you requested and occasional PeriFlow updates — every email includes a one-click way to unsubscribe, and we never use your health data for marketing. We do not sell your data, share it with advertisers, or use it to train machine-learning models.

We rely on explicit consent (Article 9(2)(a) GDPR) for special category health data, including cycle data, symptom logs, and HRT status; contract (Article 6(1)(b)) for account and subscription operations; legitimate interests (Article 6(1)(f)) for security and for usage telemetry, which contains no health data and is therefore ordinary personal data rather than special category data — this covers both account-linked telemetry and the temporary, unlinked events described in section 2, and you can object at any time by turning off Usage analytics in Settings; consent (Article 6(1)(a)) for email updates you request on our website, which you can withdraw at any time via the unsubscribe link in any email; and legal obligation (Article 6(1)(c)) where required.

Where and when we ask for it. We ask inside the app, in plain language, before we store anything. This is live on iPhone, iPad and Android: new accounts are asked during setup, and anyone who was already using PeriFlow is asked once, on a screen that has to be answered before the app carries on. You can delete your health data at any time from Settings → Danger Zone → Delete Account, or by emailing hello@periflow.io. Signing in is not treated as agreement — creating an account and consenting to health data are two separate decisions. We record the date you agreed and the version of this policy you agreed under, so we can show what you were actually asked; if we materially change what we collect, we ask again rather than assuming the old answer still stands. Saying no stops PeriFlow rather than leaving you with a reduced version of it.

Withdrawing it. Withdrawing is as easy as giving it (Article 7(3)): Settings → Health data consent. Because your health data is the only thing PeriFlow runs on, withdrawing deletes it — we do not keep a copy. Consent for HRT data is collected separately during onboarding and can be withdrawn at any time by changing your HRT status to "Not on HRT" in Settings. Consent for sleep import is collected separately when you enable it and can be withdrawn at any time by turning off sleep import in Settings → Health Data; ratings already saved stay in your log until you edit or delete them.

5. Who we share it with

Supabase — database and auth, EU region (Ireland). RevenueCat — subscription state only, no health data. Resend — email delivery (weekly summaries and website signups); receives your email address only, never health data. Vercel — website hosting; standard server logs. Apple and Google — app distribution and in-app purchases under their own policies. We may disclose data if required by law.

6. Apple Health and Health Connect (optional sleep import)

Sleep import is off by default and entirely optional. If you enable it, PeriFlow requests read-only access to your sleep data through Apple HealthKit (iOS) or Health Connect (Android) — you grant or refuse this through the operating system's own permission screen, and you can revoke it there at any time. PeriFlow only ever reads sleep sessions; we never write to Apple Health or Health Connect, and we never read any other health data type from them. Everything read is processed on your device and reduced to a single 1–5 sleep quality rating per night, which is stored alongside your other symptom logs. Import never overwrites a rating you entered yourself. Data obtained from Apple HealthKit or Health Connect is never used for advertising, marketing, or similar purposes, is never sold, and is never shared with third parties.

7. Where it lives, how long we keep it

Ireland (eu-west-1), Supabase infrastructure. Account deletion wipes all data within seconds. Backups purged within 30 days. Server logs retained up to 30 days. Website email signups are kept until you unsubscribe or ask us to delete them.

The pre-account events described in section 2 are kept for 90 days and then deleted automatically. Because they are not linked to any account, deleting your account does not affect them — there is nothing in them that identifies you.

8. How we protect it

TLS 1.2+ in transit · AES-256 at rest · Row-level security on every table · Magic-link and OAuth authentication — no passwords · No advertising SDKs. Breach notification within 72 hours of discovery.

9. Your rights

Access, correct, delete, restrict, port, and withdraw consent for your data. Delete your account in-app (Settings → Danger Zone → Delete Account) or email hello@periflow.io. To lodge a complaint: UK — ico.org.uk; EU — your member state's DPA.

10. Children

PeriFlow is for adults 18+. We do not knowingly collect data from minors. Contact us if you believe we have done so.

11. International transfers

Data stored on EU infrastructure. Non-EU processors (e.g. RevenueCat, Resend, Vercel) are covered by Standard Contractual Clauses.

12. California residents

We do not sell or share personal information under CCPA/CPRA. To exercise rights: hello@periflow.io.

13. Changes

Material changes posted here with updated date and in-app notification before effect.

14. Contact

hello@periflow.io