PerseyaPerseya
StagesFeaturesPrivacyPlus
Download
StagesFeaturesPrivacyPlusDownload
← Back to Perseya
Privacy & Integrity

Privacy Policy

Last updated: 15 June 2026

Perseya is a women’s health, fertility, pregnancy, and baby-tracking app. Because it handles some of the most sensitive information that exists about a person, we built it around one principle: the health information you record stays on your device.

The short version

  • Your health data never leaves your device through us. Periods, symptoms, temperatures, ovulation tests, sexual activity, medications, hormone therapy, lab results, pregnancy details (including pregnancy-loss history), and baby tracking are stored locally on your iPhone and are never uploaded to, or stored on, any Perseya server. We cannot see them.
  • The only personal data that leaves your device is your account login. Your email (and Google account details, if you use Sign in with Google) are handled by Google Firebase Authentication so you can sign in securely.
  • Our analytics are anonymous. We measure which screens and features are used. These events are never linked to your identity and never contain your health data.
  • Subscriptions are processed by Apple. We never see or store your payment-card details.
  • We do not sell your data, show you ads, or build advertising profiles about you.
  • You are in control. You can export your data and permanently delete your account and all on-device data from within the app at any time.

Contents

  1. 1. Who we are (Data Controller)
  2. 2. Scope of this policy
  3. 3. On-device storage of health data
  4. 4. What data we process, and why
  5. 5. What we do not collect
  6. 6. Third-party services
  7. 7. International data transfers
  8. 8. How long we keep your data
  9. 9. Your rights
  10. 10. How we protect your data
  11. 11. Data you export or share
  12. 12. Children’s privacy
  13. 13. Predictions & automated decisions
  14. 14. Changes to this policy
  15. 15. Contact us

1. Who we are (Data Controller)

The data controller responsible for your personal data is:

[PUBLISHER NAME]
[PUBLISHER LEGAL FORM, e.g. sole trader / EOOD / Ltd]
[REGISTERED ADDRESS], [COUNTRY]
Email: privacy@perseya.app

If we have appointed a Data Protection Officer or an EU representative, their contact details are: [DPO / REPRESENTATIVE CONTACT — if applicable, otherwise remove]. For any privacy question or to exercise your rights, contact us at privacy@perseya.app.

2. Scope of this policy

This policy applies to the Perseya iOS application and the limited cloud services it relies on (described in Section 6). It does not apply to third-party services you separately choose to use (for example, your Google account or your Apple account), which are governed by their own privacy policies.

3. Our core principle: on-device storage of health data

Perseya is offline-first. The information you record is stored in a local database (Apple SwiftData) inside the app’s private, sandboxed storage on your device.

  • We do not operate a health-data backend. There is no cloud database, no server-side copy, and no automatic synchronisation of your logs to us or any third party.
  • We therefore do not have access to your cycle, fertility, pregnancy, or baby data. We cannot read it, share it, sell it, or hand it over, because we never receive it.
  • Your data may be included in your own device backups (such as Apple iCloud Backup or an encrypted computer backup) if you enable them. Those backups are controlled by you under your Apple account and Apple’s terms — not by us.

This design is deliberate. Reproductive- and pregnancy-related information can be especially sensitive, and the strongest protection we can offer is to never collect it in the first place.

4. What data we process, why, and our legal basis

We process the following categories of data. “On device only” means the data is stored locally and is not transmitted to us.

4.1 Account and identity data — handled by Firebase Authentication

  • What: email address; password (stored only as a secure hash by Firebase, never visible to us); if you use Sign in with Google, the basic Google account information Google provides (such as email and name); your display name; your account identifier (Firebase UID).
  • Why: to create and secure your account, authenticate you, enable password reset/change, and associate your on-device data with your account.
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR); and our legitimate interest in account security (Art. 6(1)(f)).

4.2 Profile data — on device only

  • What: email, display name, and year of birth (we store the year only, not a full date of birth), plus your in-app preferences and settings (theme, language, units, tracking toggles, notification and security/app-lock preferences).
  • Why: to personalise the app and operate the features you enable.
  • Legal basis: performance of a contract (Art. 6(1)(b)).

4.3 Health and wellbeing data you log — on device only (special category data)

Depending on which features you use, this includes:

  • Cycle and fertility: periods and menstrual flow, symptoms, daily notes, basal body temperature (BBT), ovulation-test (OPK) results, sexual activity, medications and medication plans, hormone therapy, and lab/test results.
  • Pregnancy: pregnancy status and dates, prenatal check-ups, kick-counter sessions, contraction timing, and pregnancy history and outcomes (which may include pregnancy loss).
  • Baby: baby profile details, feeding, sleeping, diapering, potty, pumping, growth measurements, and activity logs.

This is special category data concerning health and sex life under Art. 9 GDPR.

  • Why: to provide the app’s core tracking, calendar, projection, and reporting features for your own personal use.
  • How: processed and stored locally on your device. We do not receive or have access to this data.
  • Legal basis: any processing is carried out on your device under your control, based on your explicit consent (Art. 9(2)(a) GDPR), which you give when you choose to record this information, together with performance of a contract (Art. 6(1)(b)). You can withdraw consent at any time by deleting the data or the app.

4.4 Usage and analytics data — Firebase Analytics (anonymous)

  • What: anonymous, aggregated events describing how the app is used — for example which screens are viewed and which buttons are tapped. To deliver these analytics, Google also processes standard technical identifiers such as a randomly generated app-instance ID, device model, operating-system and app version, language, and coarse, country-level location derived from your IP address.
  • What it never includes: we deliberately do not attach your account identifier (Firebase UID) to analytics events, and we never include the contents of your health, cycle, pregnancy, or baby logs. Event names describe that a feature was used, not what you recorded.
  • Why: to understand which features are useful, find problems, and improve the app.
  • Legal basis: your consent (Art. 6(1)(a)) where required by applicable law, and/or our legitimate interest (Art. 6(1)(f)) in improving and securing the app.

4.5 Performance and diagnostics data — Firebase Performance Monitoring

  • What: technical performance measurements such as app start-up and screen-rendering times, with related device and network metadata.
  • Why: to monitor and improve the app’s stability, speed, and reliability.
  • Legal basis: our legitimate interest (Art. 6(1)(f)); and/or consent (Art. 6(1)(a)) where required.

4.6 Security and anti-abuse data — Firebase App Check

  • What: a device-attestation token generated using Apple’s DeviceCheck/App Attest to confirm that requests come from a genuine, untampered copy of the app.
  • Why: to protect our backend services from abuse and fraud.
  • Legal basis: our legitimate interest (Art. 6(1)(f)) in security and fraud prevention.

4.7 Purchase and subscription data — Apple App Store / StoreKit

  • What: your subscription status and transaction identifiers for Perseya Premium. Payments are processed by Apple; we never receive or store your payment-card or billing details.
  • Why: to provide, restore, and validate your Premium subscription.
  • Legal basis: performance of a contract (Art. 6(1)(b)).

4.8 Notifications data — on device only

  • What: reminders you schedule (for example, medication reminders) and in-app notifications.
  • Why: to deliver reminders and alerts you have asked for.
  • How: notifications are scheduled and delivered locally on your device. Perseya does not use push servers and does not send remote/push notifications.
  • Legal basis: consent (Art. 6(1)(a)) via the iOS notifications permission, and/or performance of a contract (Art. 6(1)(b)).

4.9 Consent records — on device only

  • What: a record that you accepted these Terms and this Privacy Policy, with a timestamp.
  • Why: to demonstrate that consent and acceptance were obtained.
  • Legal basis: compliance with a legal obligation (Art. 6(1)(c)) and our legitimate interest (Art. 6(1)(f)) in keeping proof of consent.

5. What we do not collect

To be explicit, Perseya does not:

  • collect your precise location (the app does not use GPS or location services);
  • access your Apple Health / HealthKit data;
  • access your camera, photo library, microphone, or contacts;
  • collect biometric identifiers (any Face ID / Touch ID “app lock” is handled entirely by iOS on your device and never shared with us);
  • show third-party advertising or build advertising/marketing profiles about you;
  • sell or rent your personal data to anyone; or
  • combine your anonymous analytics with your account identity.

6. Third-party services (sub-processors and independent providers)

We rely on a small number of carefully chosen providers. Each processes data only as described above.

ProviderServiceData involvedPrivacy information
Google (Google Ireland Ltd / Google LLC)Firebase AuthenticationAccount email, password hash, Google sign-in details, Firebase UIDfirebase.google.com/support/privacy
GoogleFirebase AnalyticsAnonymous usage events, app-instance ID, device/technical datafirebase.google.com/support/privacy
GoogleFirebase Performance MonitoringPerformance metrics, device/network metadatafirebase.google.com/support/privacy
GoogleFirebase App CheckDevice-attestation tokenfirebase.google.com/support/privacy
GoogleGoogle Sign-InGoogle account authentication detailspolicies.google.com/privacy
Apple (Apple Inc. / Apple Distribution International)App Store & StoreKit (subscriptions)Subscription/transaction statusapple.com/legal/privacy

These providers act as our processors where they process data on our behalf, and/or as independent controllers for their own purposes as described in their policies. We do not control, and are not responsible for, the independent practices of Apple or Google.

7. International data transfers

Perseya is operated from [COUNTRY] within the European Economic Area (EEA). The cloud providers above (Google and Apple) may process certain data outside the EEA, including in the United States. Where this happens, the transfer is protected by appropriate safeguards under GDPR, such as the European Commission’s Standard Contractual Clauses and/or the providers’ certification under the EU–U.S. Data Privacy Framework. You can review the relevant safeguards in the providers’ privacy documentation linked in Section 6, or request a copy by contacting privacy@perseya.app.

8. How long we keep your data (retention)

  • On-device data (health, baby, profile, notifications, consent records): retained on your device until you delete it, delete your account, or remove the app. We do not hold a copy, so we cannot retain it after you delete it.
  • Account data (Firebase Authentication): retained for as long as your account exists. When you delete your account in the app, the associated Firebase account is deleted and your on-device data for that account is permanently purged.
  • Analytics data: retained by Google for the retention period configured for our Firebase/Google Analytics project (by default, user-level data is retained for a limited period such as 2–14 months and then automatically deleted; aggregated, non-identifying reports may be kept longer).
  • Performance data: retained by Google for the period applicable to Firebase Performance Monitoring.

9. Your rights

Under the GDPR (and equivalent national law), you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data (“right to be forgotten”);
  • Restrict or object to our processing;
  • Data portability — receive your data in a structured, commonly used, machine-readable format;
  • Withdraw consent at any time, without affecting processing carried out before withdrawal; and
  • Lodge a complaint with a supervisory authority.

How to exercise your rights — most are built into the app:

  • Access & portability: use Settings → Export Data to export the information stored on your device.
  • Rectification: edit your profile and entries directly in the app.
  • Erasure: use Settings → Delete Account to permanently delete your account and purge all associated on-device data; or delete individual entries; or uninstall the app.
  • For anything else, email privacy@perseya.app. We will respond within the time limits required by law (generally one month).

Because most of your data lives only on your device and we cannot access it, the fastest and most complete way to exercise the access, portability, and erasure rights over that data is to use the in-app tools above.

You also have the right to complain to your local data-protection authority. Our lead supervisory authority is [SUPERVISORY AUTHORITY — e.g. the data-protection authority of [COUNTRY]]. You may also contact the authority in your own country of residence.

10. How we protect your data

  • Your logs are stored in the app’s private, sandboxed storage, isolated by iOS from other apps.
  • You can enable an optional app lock (device passcode / Face ID / Touch ID), handled entirely by iOS, to require authentication before the app opens.
  • Data exchanged with our cloud providers (authentication, analytics, performance) is encrypted in transit using industry-standard TLS.
  • Authentication is handled by Google Firebase, which applies its own robust security controls; passwords are never stored by us in readable form.
  • We use Firebase App Check to reduce abuse of our backend services.

No method of electronic storage or transmission is ever completely secure, but we work to protect your data using appropriate technical and organisational measures and the on-device-first design described above.

11. Data you choose to export or share

Some features let you export your data or share a summary (for example, sharing baby information). When you choose to export or share, the data goes wherever you direct it (such as another app, a recipient, or a file). Once it leaves the app at your instruction, it is outside our control and this policy no longer governs it. Please share sensitive information thoughtfully.

12. Children’s privacy

Perseya is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, please contact privacy@perseya.app and we will take appropriate steps.

If you use the baby-tracking features, any information you record about an infant or child is information you, as the parent or guardian, choose to record. It is stored locally on your device under your control; we do not receive or access it, and you are responsible for that information.

13. Automated decision-making and predictions

Perseya may calculate predictions and projections (for example, estimated cycle phases, fertile windows, or due dates). These calculations are performed on your device, are estimates for your information only, and are not used by us to make any decision producing legal or similarly significant effects about you. They are not a medical diagnosis and not a method of contraception (see the Terms & Conditions). We do not carry out profiling of you.

14. Changes to this policy

We may update this policy from time to time, for example to reflect changes to the app or the law. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app. Your continued use of the app after an update means you accept the revised policy.

15. Contact us

Questions, requests, or complaints about privacy:

[PUBLISHER NAME]
[REGISTERED ADDRESS], [COUNTRY]
Email: privacy@perseya.app

If you are not satisfied with our response, you have the right to lodge a complaint with your data-protection supervisory authority.

PerseyaPerseya
Contact & SupportPrivacy PolicyTerms of Service
© 2026 Perseya. All rights reserved.A tracking tool — not a diagnostic device.