Privacy Policy
Last updated: March 15, 2026
Introduction
Welcome to CycleGlow. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store and protect your information when you use the CycleGlow mobile application.
CycleGlow is a menstrual cycle and wellness tracking application that helps you track your period, symptoms, mood and energy. The app offers daily affirmations, phase-specific meditations, cycle predictions and personal insights.
Data Controller
What Data We Collect
Account Information
- Email address
- Password (encrypted, never stored in plain text)
- Age/year of birth
- Account creation date
- Sign-in method: email/password, Sign in with Apple, or Sign in with Google
- Biometric preference (Face ID / Touch ID): stored only locally on your device
Health & Wellness Data
- Menstrual cycle information (period start/end date, cycle length, flow intensity)
- Daily symptoms (cramps, headaches, acne, bloating, etc.)
- Mood tracking (1–5 scale)
- Energy levels (1–5 scale)
- Personal notes and observations
- Cycle predictions (algorithmically calculated)
Usage Data
- App interaction data (screens visited, features used), collected via PostHog
- Device information (device type, operating system version)
- App version and language preference
- Error logs and crash reports, collected via Sentry (only a user number, no personal data)
- Notification history (stored locally on your device, maximum 45 items)
Widget Data (iOS)
If you use the CycleGlow widget on your iOS home screen or lock screen, the following data is shared with the iOS App Group (group.com.mp.cycleglow):
- Last period start date
- Cycle length and current cycle day
- Current cycle phase
- Expected start date of next period
This data is only shared locally on your device with the iOS widget extension. It is not sent to external servers.
Note: Payment data (credit card numbers) is processed securely by Apple (App Store) or Google (Play Store). We never see or store your payment card details.
How We Use Your Data
Essential App Functionality
- Providing cycle tracking and predictions
- Storing and displaying your health data
- Enabling daily logging features
- Authenticating your account and keeping it secure
- Offering phase-specific meditations
- Sending push notifications (only with your consent)
- Providing the iOS widget with up-to-date cycle data
AI-Generated Daily Affirmations
- Generating a daily personalized affirmation based on your cycle phase, mood and energy level
Note: To generate affirmations, your cycle day, phase, mood and energy level are processed via OpenAI's API. No personally identifiable information (such as your email or name) is ever sent.
Analytics & App Improvement
- Understanding how features are used to improve the app (via PostHog)
- Detecting and fixing errors and crashes (via Sentry)
Legal Basis for Processing (GDPR)
- Performance of Contract: Processing necessary to provide the CycleGlow service
- Consent: When you explicitly give consent
- Legitimate Interest: To improve our services and ensure security
- Legal Obligation: To comply with laws and regulations
Third-Party Services
Supabase (Database & Authentication)
Securely stores your account and health data. EU servers (GDPR-compliant). Processes: all account data and health data.
OpenAI (AI Affirmations)
Generates daily personalized affirmations. Processes: cycle day, cycle phase, mood and energy level. No personally identifiable information (no name, email or user number) is shared.
RevenueCat (Subscription Management)
Manages in-app subscriptions and purchase status. Processes: anonymous user ID and subscription status.
PostHog (Usage Analytics)
Collects anonymous analytics about app usage to improve the app. Processes: screen visits, feature usage and a pseudonymized user ID. No health data is shared.
Sentry (Error & Crash Reporting)
Detects technical errors and app crashes to ensure stability. Processes: error messages, technical stack traces and a pseudonymized user ID. No health data or personal information is shared.
Apple & Google (Authentication & Payment)
Sign in via Apple or Google (optional) and process payments via the App Store or Google Play. Payment card details are never seen or stored by CycleGlow.
Important: We carefully select services that comply with the GDPR. We only share the minimum data necessary.
Data Retention
While Your Account Is Active
As long as your account is active, we store the following data to give you personalized insights and recommendations:
- Your cycle history and predictions
- Daily mood, energy and symptom logs
- Personalized AI-generated tips
- Cycle insights and patterns
Deleting Your Account
If you want to delete your account, the following happens:
Request Submitted
You can delete your account via Profile settings. Your request is processed immediately.
Data Deletion
All your personal data will be permanently deleted from our servers within 30 days.
Deletion Completed
Your data is fully deleted. This action cannot be undone.
Note: Pseudonymized usage data (without health data) may be retained by our analytics providers (PostHog, Sentry) for up to 12 months after your account is deleted, in accordance with their own retention policies.
AI & Your Data
CycleGlow uses AI to generate daily affirmations. Here's how it works and how we protect your privacy.
How AI Affirmations Work
Input Data
We send your current cycle day, cycle phase, mood and energy level to OpenAI's API. Never your name, email or other personally identifiable information.
Generation via Edge Function
Processing takes place through a secure server environment (Supabase Edge Function). Your data never leaves CycleGlow directly to OpenAI.
Daily Affirmation
You receive a personalized affirmation that matches your cycle phase and how you're feeling at that moment.
Your Privacy Is Protected
Your data is encrypted and stored securely
We never sell your personal data to third parties
No name, email or personally identifiable information is sent to OpenAI
When you delete your data, AI-generated affirmations are deleted too
Important Note: AI-generated affirmations are intended only as wellness support and must not replace professional medical advice. Always consult a healthcare provider for medical concerns.
Your Rights (GDPR)
Right of Access
Request a copy of your data via Settings → Export Data
Right to Rectification
Edit your data directly in the app
Right to Erasure
Delete your account via Settings → Delete Account
Right to Data Portability
Export your data in JSON format
Contact: contact@cycleglow.nl
Data Security
- All data is transmitted encrypted (HTTPS/TLS)
- Passwords are hashed with bcrypt
- Database access is restricted and monitored
- Optional biometric authentication (Face ID, Touch ID)
Children's Privacy
CycleGlow is intended for users 9 years of age and older.
- We recommend parental guidance for users under 13
- Parents can request data deletion via contact@cycleglow.nl
Medical Disclaimer
CycleGlow is a wellness and tracking tool, not a medical device.
- No Diagnosis: We do not provide medical diagnoses
- No Medical Advice: All insights are general in nature
- Not Contraception: Not intended as a contraceptive method
Always consult a healthcare provider for medical advice.
Contact
We respond within 30 days as required by the GDPR.
Summary
What we collect: Email, cycle data, symptoms, mood, energy level and anonymized app usage data.
Why: To track your cycle, generate daily affirmations and improve the app.
With whom: Supabase (storage), OpenAI (affirmations), RevenueCat (subscriptions), PostHog (analytics), Sentry (crash reporting), Apple/Google (authentication & payment). We only share what's necessary.
Your control: You can view, edit, export (JSON) your data or delete your account entirely.
Security: HTTPS/TLS encryption, bcrypt password hashing, hardware-secured biometric storage.
Thank you for trusting CycleGlow on your wellness journey.