Privacy Policy
We wrote this to actually be read — not to bury things in legal language.
- Your cycle data is stored on your device only — never on our servers
- We do not collect, transmit, or sell your health information
- We use no analytics tools, tracking pixels, or surveillance scripts
- Stripe processes payments — their privacy policy governs that data
- We receive no personally identifiable information about your cycle
- You can delete all your data at any time by clearing browser storage
1. Who we are
CycleVault ("we," "us," "our") is an independent web application providing period and cycle tracking tools. Our service operates under the privacy principles described in this policy.
We are subject to the General Data Protection Regulation (GDPR) as an entity operating within the European Union.
For privacy-related enquiries: privacy@cyclevault.app
2. Your health data — the most important section
CycleVault is architecturally designed so that your cycle data never reaches our servers. We are technically incapable of accessing it.
All period tracking information you enter — cycle dates, symptom logs, mood entries, notes, and any other health information — is stored exclusively in your browser's local storage on your own device.
This data is:
- Never transmitted over the internet to our servers or any third-party server
- Never seen, accessed, or processed by CycleVault as a company
- Never shared with, sold to, or disclosed to any third party
- Never used for advertising, profiling, or research purposes
Because this data exists only on your device, it is subject to your own device's security (screen lock, device encryption, etc.). We strongly recommend keeping your device secured.
If you clear your browser data or uninstall your browser, your cycle data will be permanently deleted. We cannot recover it for you because we have never held it.
3. What we do not collect
We do not use analytics software, tracking pixels, session recording tools, heatmap tools, or any third-party behavioural tracking services. This means we do not collect:
- Pages you visit within the app
- Features you use or how often you use them
- Device identifiers or browser fingerprints
- IP address logs tied to your usage
- Any personally identifiable health or behavioural data
4. Cookies and browser storage
CycleVault uses browser local storage to save your cycle data on your device. This is distinct from cookies: local storage data does not leave your browser and is not transmitted with web requests.
We may use a small number of essential session cookies for the following purposes only:
- Remembering your language or display preferences
- Maintaining a login session if you purchase a paid plan
We do not set advertising cookies, analytics cookies, or any third-party tracking cookies.
You can delete all browser storage and cookies for CycleVault at any time through your browser's settings. This will remove your local cycle data permanently.
5. Payments — Stripe
If you purchase a paid plan or feature, payments are processed by Stripe, Inc. When you make a payment, you interact directly with Stripe's secure payment interface.
For payment processing, Stripe may collect:
- Your name and email address
- Payment card details (stored by Stripe, not by us)
- Billing address
- Transaction metadata
We receive confirmation of successful payments and your email address for the purpose of managing your subscription. We do not receive or store your full payment card details.
If you purchase a Pro subscription, a license key is generated and stored in our database linked to your Stripe subscription ID. This allows you to restore access on a new device. No personal health data is involved.
Stripe's privacy practices are governed by their own privacy policy, available at stripe.com/privacy.
6. Blog and public content
Our blog is hosted as part of CycleVault. Blog posts are public content and carry no personalisation or user tracking. We do not use comment systems, social sharing widgets, or embedded third-party content that would introduce tracking on blog pages.
If you contact us via a form or email linked from our blog, the information you provide will be used solely to respond to your enquiry and will not be retained longer than necessary.
7. Your rights under GDPR
As a person in the European Union or European Economic Area, you have the following rights regarding any personal data we hold:
- Right of access — request a copy of personal data we hold about you
- Right to rectification — ask us to correct inaccurate personal data
- Right to erasure — request deletion of your personal data
- Right to portability — receive your data in a structured, machine-readable format
- Right to object — object to processing of your data in certain circumstances
- Right to restrict processing — ask us to pause processing of your data
Because your cycle data is stored only on your device and is never transmitted to us, most of these rights are exercised directly by you through your browser settings. For any personal data we do hold (email address associated with a paid account), contact us at privacy@cyclevault.app and we will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority.
8. Data security
Because we do not store your health data on our servers, the primary security of your cycle information is determined by your own device security. We recommend:
- Using a screen lock or password on your device
- Keeping your browser and operating system updated
- Using CycleVault on a personal device only
For any account data we do hold (email for paid plans), we apply industry-standard security practices including encryption in transit (HTTPS) and at rest.
9. Children's privacy
CycleVault is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, please contact us and we will delete it promptly.
10. Platform Infrastructure
CycleVault is hosted on Lovable's platform. Lovable's hosting layer may inject session and error monitoring scripts at the platform level. These scripts are outside CycleVault's control and do not access or transmit your cycle data. We are actively working with Lovable to disable these scripts. Your health data remains on your device only and is unaffected.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will make a reasonable effort to notify users with an active paid account by email.
Your continued use of CycleVault after changes are posted constitutes your acceptance of the updated policy.
12. Contact us
We aim to respond to all privacy-related enquiries within 5 business days and to all GDPR rights requests within 30 calendar days.