1. Information We Collect
1.1 Information You Provide
- Account information: Email address, name, and password when you create an account.
- Health data: Menstrual cycle dates, symptoms, basal body temperature, mood, and other reproductive health information you choose to log.
- Profile information: Date of birth, cycle preferences, and notification settings.
- Communications: Messages you send to our support team or feedback you provide.
1.2 Information Collected Automatically
- Device information: Device type, operating system, app version, and unique device identifiers.
- Usage data: Features used, pages visited, and interaction patterns (anonymized).
- Cookies and similar technologies: See our Cookie Policy for details.
2. How We Use Your Information
We use your information to:
- Provide and improve cycle predictions, fertility insights, and personalized health information.
- Operate, maintain, and improve the Cyla app and website.
- Send you notifications, reminders, and updates you've opted into.
- Respond to your support requests and feedback.
- Conduct anonymized, aggregated research to improve our prediction algorithms.
- Comply with legal obligations.
3. Health Data Processing
Your health data receives the highest level of protection. Cyla processes health data exclusively to provide you with cycle predictions and health insights. We use on-device processing wherever possible, meaning much of your data never leaves your phone. When server-side processing is required, your data is encrypted in transit and at rest.
We never sell your health data. We never share your health data with advertisers. Period.
4. Data Sharing
We do not sell, rent, or trade your personal information. We may share limited data with:
- Service providers: Trusted third parties who help us operate our services (e.g., cloud hosting, analytics), bound by strict confidentiality agreements.
- Legal requirements: When required by law, legal process, or to protect the rights and safety of Cyla and our users.
- Anonymized research: Aggregated, de-identified data may be used for scientific research to advance menstrual health understanding. Individual users cannot be identified from this data.
5. Data Storage and Security
Your data is stored on secure servers with industry-standard encryption (AES-256 at rest, TLS 1.3 in transit). We implement strict access controls, regular security audits, and follow security best practices. Health data is stored separately from account data, adding an additional layer of protection.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide you services. You can request deletion of your account and all associated data at any time. Upon deletion, your data is permanently removed from our servers within 30 days, except where retention is required by law.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your data.
- Portability: Export your data in a machine-readable format.
- Restriction: Request limitation of processing.
- Objection: Object to certain types of processing.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
8. GDPR Compliance (European Users)
If you are located in the European Economic Area, we process your personal data under the following legal bases: your consent (for health data), contractual necessity (for account management), and legitimate interests (for service improvement). You have the right to lodge a complaint with your local data protection authority.
9. CCPA Compliance (California Users)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. As stated above, Cyla does not sell personal information. To exercise your rights, contact us at the address below.
10. Children's Privacy
Cyla is not directed to children under 13. We do not knowingly collect personal information from children under 13. Users between 13 and 18 may use Cyla with parental or guardian consent. If we learn we have collected data from a child under 13, we will promptly delete it.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, to protect your data during international transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. Continued use of Cyla after changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.