Privacy Policy
We wrote this to actually be read — not to bury things in legal language.
- Your cycle data is stored on your device only — never on our servers
- We do not collect, transmit, or sell your health information
- Our hosting platform may collect limited technical data to operate the site; we do not collect or access your health information ourselves
- Stripe processes payments — their privacy policy governs that data
- We receive no personally identifiable information about your cycle
- You can delete all your data at any time by clearing browser storage
1. Who we are
CycleVault ("we," "us," "our") is an independent web application providing period and cycle tracking tools. Our service operates under the privacy principles described in this policy.
We are subject to the General Data Protection Regulation (GDPR) as an entity operating within the European Union.
For privacy-related enquiries: privacy@cyclevault.app
2. Your health data — the most important section
CycleVault is architecturally designed so that your cycle data never reaches our servers. We are technically incapable of accessing it.
All period tracking information you enter — cycle dates, symptom logs, mood entries, notes, and any other health information — is stored exclusively in your browser's local storage on your own device.
This data is:
- Never transmitted over the internet to our servers or any third-party server
- Never seen, accessed, or processed by CycleVault as a company
- Never shared with, sold to, or disclosed to any third party
- Never used for advertising, profiling, or research purposes
Because this data exists only on your device, it is subject to your own device's security (screen lock, device encryption, etc.). We strongly recommend keeping your device secured.
If you clear your browser data or uninstall your browser, your cycle data will be permanently deleted. We cannot recover it for you because we have never held it.
3. What we do not collect, and what the hosting platform may collect
CycleVault itself does not use analytics software, tracking pixels, session recording tools, heatmap tools, or behavioural tracking services. We do not collect:
- Your cycle, symptom, mood, or health data
- Pages you visit within the app or features you use
- Device identifiers or browser fingerprints
- IP address logs tied to your usage
- Any personally identifiable health or behavioural data
CycleVault is hosted on Lovable's platform. The hosting layer injects Tinybird web analytics scripts at the platform level to collect basic page-view data: the URL you visit, your browser's User Agent, your approximate country/location, your referrer, and a session identifier. This is outside CycleVault's control and is not linked to your cycle data. On certain pages (for example, immediately after checkout), the URL may temporarily include a one-time transaction identifier, which would also be included in that analytics data.
4. Cookies and browser storage
CycleVault uses browser local storage to save your cycle data on your device. This is distinct from cookies: local storage data does not leave your browser and is not transmitted with web requests.
We may use a small number of essential session cookies for the following purposes only:
- Remembering your language or display preferences
- Maintaining a login session if you purchase a paid plan
We do not set advertising cookies, analytics cookies, or any third-party tracking cookies.
You can delete all browser storage and cookies for CycleVault at any time through your browser's settings. This will remove your local cycle data permanently.
5. Payments — Stripe
If you purchase a paid plan or feature, payments are processed by Stripe, Inc. When you make a payment, you interact directly with Stripe's secure payment interface.
For payment processing, Stripe may collect:
- Your name and email address
- Payment card details (stored by Stripe, not by us)
- Billing address
- Transaction metadata
We receive confirmation of successful payments and your email address for the purpose of managing your subscription. We do not receive or store your full payment card details.
If you purchase a Pro subscription, a license key is generated and stored in our database linked to your Stripe subscription ID. This allows you to restore access on a new device. No personal health data is involved.
Abuse protection on license lookups. When your license key is retrieved after checkout, we briefly record a salted, one-way hash of your network address — never the address itself — purely to rate-limit automated attempts to guess or scrape license keys. These hashes cannot be reversed or linked to you, are used for no other purpose, and are deleted automatically after 10 minutes. This is not analytics or tracking, and it never touches your cycle data.
Stripe's privacy practices are governed by their own privacy policy, available at stripe.com/privacy.
6. Blog and public content
Our blog is hosted as part of CycleVault. Blog posts are public content and carry no personalisation or user tracking. We do not use comment systems, social sharing widgets, or embedded third-party content that would introduce tracking on blog pages.
If you contact us via a form or email linked from our blog, the information you provide will be used solely to respond to your enquiry and will not be retained longer than necessary.
7. Your rights under GDPR
As a person in the European Union or European Economic Area, you have the following rights regarding any personal data we hold:
- Right of access — request a copy of personal data we hold about you
- Right to rectification — ask us to correct inaccurate personal data
- Right to erasure — request deletion of your personal data
- Right to portability — receive your data in a structured, machine-readable format
- Right to object — object to processing of your data in certain circumstances
- Right to restrict processing — ask us to pause processing of your data
Because your cycle data is stored only on your device and is never transmitted to us, most of these rights are exercised directly by you through your browser settings. For any personal data we do hold (email address associated with a paid account), contact us at privacy@cyclevault.app and we will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority.
8. Data security
Because we do not store your health data on our servers, the primary security of your cycle information is determined by your own device security. We recommend:
- Using a screen lock or password on your device
- Keeping your browser and operating system updated
- Using CycleVault on a personal device only
For any account data we do hold (email for paid plans), we apply industry-standard security practices including encryption in transit (HTTPS) and at rest.
9. Children's privacy
CycleVault is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, please contact us and we will delete it promptly.
10. Platform Infrastructure
CycleVault is hosted on Lovable's platform. Lovable's hosting layer injects Tinybird web analytics scripts at the platform level to collect basic page-view data (URL, User Agent, approximate country/location, referrer, and a session identifier). These scripts are outside CycleVault's control, do not access or transmit your cycle data, and are not linked to your health information. On certain pages (for example, immediately after checkout), the URL may temporarily include a one-time transaction identifier, which would also be included in that analytics data. We are actively working with Lovable to minimise or disable these scripts. Your health data remains on your device only and is unaffected.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will make a reasonable effort to notify users with an active paid account by email.
Your continued use of CycleVault after changes are posted constitutes your acceptance of the updated policy.
12. Contact us
We aim to respond to all privacy-related enquiries within 5 business days and to all GDPR rights requests within 30 calendar days.