Legal

Privacy Policy

We wrote this to actually be read — not to bury things in legal language.

Last updated: August 2026
✦ The short version (plain English)

1. Who we are

CycleVault ("we," "us," "our") is an independent web application providing period and cycle tracking tools. Our service operates under the privacy principles described in this policy.

We are subject to the General Data Protection Regulation (GDPR) as an entity operating within the European Union.

For privacy-related enquiries: privacy@cyclevault.app

2. Your health data — the most important section

CycleVault is architecturally designed so that your cycle data never reaches our servers. We are technically incapable of accessing it.

All period tracking information you enter — cycle dates, symptom logs, mood entries, notes, and any other health information — is stored exclusively in your browser's local storage on your own device.

This data is:

Because this data exists only on your device, it is subject to your own device's security (screen lock, device encryption, etc.). We strongly recommend keeping your device secured.

If you clear your browser data or uninstall your browser, your cycle data will be permanently deleted. We cannot recover it for you because we have never held it.

3. What we do not collect, and what the hosting platform may collect

CycleVault itself does not use analytics software, tracking pixels, session recording tools, heatmap tools, or behavioural tracking services. We do not collect:

CycleVault is hosted on Lovable's platform. The hosting layer injects Tinybird web analytics scripts at the platform level to collect basic page-view data: the URL you visit, your browser's User Agent, your approximate country/location, your referrer, and a session identifier. This is outside CycleVault's control and is not linked to your cycle data. On certain pages (for example, immediately after checkout), the URL may temporarily include a one-time transaction identifier, which would also be included in that analytics data.

4. Cookies and browser storage

CycleVault uses browser local storage to save your cycle data on your device. This is distinct from cookies: local storage data does not leave your browser and is not transmitted with web requests.

We may use a small number of essential session cookies for the following purposes only:

We do not set advertising cookies, analytics cookies, or any third-party tracking cookies.

You can delete all browser storage and cookies for CycleVault at any time through your browser's settings. This will remove your local cycle data permanently.

5. Payments — Stripe

If you purchase a paid plan or feature, payments are processed by Stripe, Inc. When you make a payment, you interact directly with Stripe's secure payment interface.

For payment processing, Stripe may collect:

We receive confirmation of successful payments and your email address for the purpose of managing your subscription. We do not receive or store your full payment card details.

If you purchase a Pro subscription, a license key is generated and stored in our database linked to your Stripe subscription ID. This allows you to restore access on a new device. No personal health data is involved.

Abuse protection on license lookups. When your license key is retrieved after checkout, we briefly record a salted, one-way hash of your network address — never the address itself — purely to rate-limit automated attempts to guess or scrape license keys. These hashes cannot be reversed or linked to you, are used for no other purpose, and are deleted automatically after 10 minutes. This is not analytics or tracking, and it never touches your cycle data.

Stripe's privacy practices are governed by their own privacy policy, available at stripe.com/privacy.

6. Blog and public content

Our blog is hosted as part of CycleVault. Blog posts are public content and carry no personalisation or user tracking. We do not use comment systems, social sharing widgets, or embedded third-party content that would introduce tracking on blog pages.

If you contact us via a form or email linked from our blog, the information you provide will be used solely to respond to your enquiry and will not be retained longer than necessary.

7. Your rights under GDPR

As a person in the European Union or European Economic Area, you have the following rights regarding any personal data we hold:

Because your cycle data is stored only on your device and is never transmitted to us, most of these rights are exercised directly by you through your browser settings. For any personal data we do hold (email address associated with a paid account), contact us at privacy@cyclevault.app and we will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority.

8. Data security

Because we do not store your health data on our servers, the primary security of your cycle information is determined by your own device security. We recommend:

For any account data we do hold (email for paid plans), we apply industry-standard security practices including encryption in transit (HTTPS) and at rest.

9. Children's privacy

CycleVault is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, please contact us and we will delete it promptly.

10. Platform Infrastructure

CycleVault is hosted on Lovable's platform. Lovable's hosting layer injects Tinybird web analytics scripts at the platform level to collect basic page-view data (URL, User Agent, approximate country/location, referrer, and a session identifier). These scripts are outside CycleVault's control, do not access or transmit your cycle data, and are not linked to your health information. On certain pages (for example, immediately after checkout), the URL may temporarily include a one-time transaction identifier, which would also be included in that analytics data. We are actively working with Lovable to minimise or disable these scripts. Your health data remains on your device only and is unaffected.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If changes are material, we will make a reasonable effort to notify users with an active paid account by email.

Your continued use of CycleVault after changes are posted constitutes your acceptance of the updated policy.

12. Contact us

We aim to respond to all privacy-related enquiries within 5 business days and to all GDPR rights requests within 30 calendar days.

Why we built CycleVault

Health Disclaimer