Legal

Privacy Policy

We wrote this to actually be read — not to bury things in legal language.

Last updated: June 2026
✦ The short version (plain English)

1. Who we are

CycleVault ("we," "us," "our") is an independent web application providing period and cycle tracking tools. Our service operates under the privacy principles described in this policy.

We are subject to the General Data Protection Regulation (GDPR) as an entity operating within the European Union.

For privacy-related enquiries: privacy@cyclevault.app

2. Your health data — the most important section

CycleVault is architecturally designed so that your cycle data never reaches our servers. We are technically incapable of accessing it.

All period tracking information you enter — cycle dates, symptom logs, mood entries, notes, and any other health information — is stored exclusively in your browser's local storage on your own device.

This data is:

Because this data exists only on your device, it is subject to your own device's security (screen lock, device encryption, etc.). We strongly recommend keeping your device secured.

If you clear your browser data or uninstall your browser, your cycle data will be permanently deleted. We cannot recover it for you because we have never held it.

3. What we do not collect

We do not use analytics software, tracking pixels, session recording tools, heatmap tools, or any third-party behavioural tracking services. This means we do not collect:

4. Cookies and browser storage

CycleVault uses browser local storage to save your cycle data on your device. This is distinct from cookies: local storage data does not leave your browser and is not transmitted with web requests.

We may use a small number of essential session cookies for the following purposes only:

We do not set advertising cookies, analytics cookies, or any third-party tracking cookies.

You can delete all browser storage and cookies for CycleVault at any time through your browser's settings. This will remove your local cycle data permanently.

5. Payments — Stripe

If you purchase a paid plan or feature, payments are processed by Stripe, Inc. When you make a payment, you interact directly with Stripe's secure payment interface.

For payment processing, Stripe may collect:

We receive confirmation of successful payments and your email address for the purpose of managing your subscription. We do not receive or store your full payment card details.

If you purchase a Pro subscription, a license key is generated and stored in our database linked to your Stripe subscription ID. This allows you to restore access on a new device. No personal health data is involved.

Stripe's privacy practices are governed by their own privacy policy, available at stripe.com/privacy.

6. Blog and public content

Our blog is hosted as part of CycleVault. Blog posts are public content and carry no personalisation or user tracking. We do not use comment systems, social sharing widgets, or embedded third-party content that would introduce tracking on blog pages.

If you contact us via a form or email linked from our blog, the information you provide will be used solely to respond to your enquiry and will not be retained longer than necessary.

7. Your rights under GDPR

As a person in the European Union or European Economic Area, you have the following rights regarding any personal data we hold:

Because your cycle data is stored only on your device and is never transmitted to us, most of these rights are exercised directly by you through your browser settings. For any personal data we do hold (email address associated with a paid account), contact us at privacy@cyclevault.app and we will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority.

8. Data security

Because we do not store your health data on our servers, the primary security of your cycle information is determined by your own device security. We recommend:

For any account data we do hold (email for paid plans), we apply industry-standard security practices including encryption in transit (HTTPS) and at rest.

9. Children's privacy

CycleVault is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, please contact us and we will delete it promptly.

10. Platform Infrastructure

CycleVault is hosted on Lovable's platform. Lovable's hosting layer may inject session and error monitoring scripts at the platform level. These scripts are outside CycleVault's control and do not access or transmit your cycle data. We are actively working with Lovable to disable these scripts. Your health data remains on your device only and is unaffected.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will make a reasonable effort to notify users with an active paid account by email.

Your continued use of CycleVault after changes are posted constitutes your acceptance of the updated policy.

12. Contact us

We aim to respond to all privacy-related enquiries within 5 business days and to all GDPR rights requests within 30 calendar days.

Why we built CycleVault

Health Disclaimer