Privacy Policy
CycleQuest ("CycleQuest," "we," "our," or "us") respects your privacy. This Privacy Policy explains how we collect, use, store, sync, and share information when you use the CycleQuest mobile application and related services (the "Services"). Section 2 lists, line-by-line, what we store on your device, what we sync to our backend when you sign in, and what we never collect.
1. Scope
This Privacy Policy applies to information collected through the CycleQuest mobile app, related backend APIs, and any partner-linking features that connect CycleQuest to companion services such as CalmHer.
CycleQuest is local-first wherever possible. Some features — premium subscription and partner-linking with CalmHer — require a CycleQuest account, and using those features causes a defined set of data to be synced to our backend. The complete inventory is in Section 2 below.
2. Information We Collect
A. Information You Provide Directly
Depending on how you use CycleQuest, we may collect information you enter into the app, including:
- Cycle tracking information (period start date, cycle length, period length, ovulation day)
- Daily check-in entries (sleep hours, anxiety level, energy level, bloating level, cravings, caffeine, movement, optional free-text notes describing what you were experiencing or what helped)
- Past cycle history (start and end dates, cycle length, symptoms experienced, optional free-text notes, whether the entry is approximate)
- Custom symptom names and categories you choose to add
- Free-text journal entries
- Intimacy log entries
- Recipe favorites, custom recipe entries, ingredient swap preferences, grocery lists
- Profile and preference settings (display name, tone preference, anxiety threshold, reminder times, notification preferences)
- Onboarding responses
- Account registration information (email, name, password) if you create a CycleQuest account. An account is required to use premium subscription features or partner-linking with CalmHer; it is not required for the rest of the app.
- Information you choose to submit when using partner-linking features
B. Information Stored Only on Your Device
The following data is stored only on your device using the device's local storage. It is never sent to our servers under any circumstances:
- Free-text journal entries
- Intimacy log entries
- Custom recipe entries, recipe favorites, "made it" history, and ingredient swap preferences
- Grocery list contents and checked-off state
- Notification preferences
- Background and visual customization settings
- Cached cycle phase calculations
- Apple HealthKit and Android Health Connect readings (see Section 2(C) and the Health Data page)
If you use the app without creating an account, everything you enter stays on your device and never reaches our servers.
C. Apple HealthKit and Android Health Connect Data
If you grant CycleQuest permission to read from Apple HealthKit (iOS) or Android Health Connect, the app may read data such as sleep, heart rate variability, resting heart rate, basal body temperature, and active energy in order to provide personalized insights inside the app. CycleQuest does not currently write any data back to Health.
HealthKit and Health Connect data is processed entirely on your device. CycleQuest never transmits raw HealthKit or Health Connect data to our servers, to CalmHer, or to any third party. You may revoke this permission at any time from your device's settings (iOS: Settings → Privacy & Security → Health → CycleQuest; Android: Health Connect app). See the Health Data page for the full per-data-type list.
D. Information Synced to Our Backend (Account Holders Only)
If you create a CycleQuest account, the following information is synced from your device to our backend so that account features, premium subscription, and partner-linking can function. This is the complete list — we do not sync anything else:
Account and authentication
- Email address
- Display name
- Password, hashed with bcrypt (we never store or have access to your plaintext password)
- Active session tokens
Cycle profile
- Cycle length, period length, ovulation day
- Cycle start date
- Anxiety threshold, tone preference
- Reminder times (morning, lunch, night)
Daily check-ins (every check-in you log)
- Date and time slot (morning, lunch, night)
- Calculated cycle day and phase
- Sleep hours
- Anxiety, energy, and bloating levels
- Cravings, caffeine, and movement flags
- Risk level
- Optional free-text "notes" and "what helped" responses
- XP earned for the check-in
Past cycles
- Start and end dates
- Cycle length
- Symptoms list
- Optional free-text notes
- Whether the entry is approximate
- Source of the entry (manual, imported, etc.)
Custom symptoms — symptom names and categories you create.
Gamification
- XP, level, current streak, longest streak, total check-ins, last check-in date
- Badges earned and the date you earned them
Subscription and billing status
- Whether you have an active premium subscription
- The source of the subscription (Apple App Store, Google Play, Stripe, etc.)
- The plan you chose (monthly or yearly)
- Activation and expiration dates
We do not store credit card numbers, bank details, or full payment information. Payment processing is handled directly by the relevant payment provider (Apple, Google, or Stripe), and we receive only the resulting subscription status.
Partner linking (only if you use this feature)
- One-time invite codes you generate
- Access tokens used to maintain the partner connection
- Partner link status (pending, linked, revoked)
- Connection metadata (creation and expiration timestamps)
- Your granular consent settings (which fields you allow your partner to see)
If you do not create an account, none of the data above is sent to our backend and CycleQuest functions entirely on your device. Premium and partner-linking features are unavailable without an account.
E. Automatically Collected Technical Information
When you interact with our backend (account features, premium subscription, or partner-linking), we may automatically collect limited technical information needed to operate, secure, and improve the Services, such as:
- Device type and operating system
- App version
- Crash information and basic diagnostic logs
- API/request logs related to authentication, syncing, subscription, and partner connection status
We do not use third-party analytics, advertising, or tracking SDKs. CycleQuest does not include Google Analytics, Firebase Analytics, the Facebook SDK, Mixpanel, Amplitude, PostHog, Sentry, or any similar tools. We do not track you across other apps or websites.
3. How We Use Information
We use information we collect to:
- Provide cycle tracking, check-in, and wellness app functionality
- Save your settings, preferences, and app state
- Generate cycle phase, cycle-day, timing, predictions, pattern alerts, and related wellness insights — calculated on your device wherever possible, and on our backend for premium features that require server-side computation
- Support login, authentication, and account management for users who choose to create an account
- Operate and verify your premium subscription, including granting premium features for the duration of your active subscription period
- Enable partner-linking features and partner-facing summaries (see Section 4)
- Calculate streaks, XP, levels, and badges for the in-app gamification experience
- Troubleshoot bugs, maintain app security, and improve reliability
- Comply with legal obligations and enforce our terms
We do not use your information for advertising, profiling, or to build behavioral profiles of you, and we do not sell your information.
4. Partner Linking and Sharing with CalmHer
CycleQuest can connect to a companion app called CalmHer, which allows a partner you choose to receive supportive insights based on your cycle.
If you choose to connect CycleQuest with CalmHer:
- You generate a one-time invite code in CycleQuest and share it with your partner.
- Your partner enters that code in CalmHer to establish the link.
- Once linked, CalmHer can request a partner-facing summary of your cycle status from our backend.
- The summary CalmHer receives is limited to: cycle phase, cycle day, period-active status, next-period prediction, mood trend (stable / elevated / sensitive / variable), energy trend (high / medium / low), support mode, and an action card category.
- You control which of these summary fields are shared via in-app consent toggles. Any field you turn off is not included in the summary CalmHer receives.
- You can disconnect the partner link at any time from inside CycleQuest. Disconnection takes effect immediately and your partner will lose access.
- Raw daily check-ins, free-text notes, journal entries, intimacy log entries, custom symptoms, past cycle entries, and HealthKit / Health Connect data are never included in the summary sent to CalmHer.
Note that the underlying data described in Section 2(D) is stored on our backend so that summaries can be computed — but only the limited summary above is ever returned to CalmHer, and only when you have linked your accounts and only for the fields you have consented to share.
5. Local Storage and Backend Sync
CycleQuest uses a combination of local device storage and (for account holders) backend sync.
- The data described in Section 2(B) and Section 2(C) is stored only on your device and never sent to our servers.
- The data described in Section 2(D) is synced to our backend when you create an account and use the relevant feature.
- If local data has not yet been synced, some connected features may not reflect the most current data until sync occurs.
- Deleting the app from your device removes all locally stored data. Use the in-app "Delete Account" option to also remove backend account data if you have created an account.
6. Data Sharing
We do not sell your personal information. We do not share your information with advertisers or data brokers.
We share information only in the following limited circumstances:
- With companion or linked app functionality that you intentionally enable (such as CalmHer partner-linking, and only the consented summary fields described in Section 4)
- With infrastructure vendors that help us operate the backend — currently the cloud hosting and database providers we use to run the API and store account data — which process data only as needed to deliver the Service and are bound by contractual confidentiality obligations
- With payment processors (Apple, Google, Stripe) when you purchase or manage a premium subscription — these providers handle payment information directly and we receive only the resulting subscription status
- If required by law, subpoena, court order, or other legal process
- To protect rights, safety, security, or to prevent fraud or abuse
7. Data Retention
We retain information for as long as reasonably necessary to:
- Provide the Services
- Maintain account, subscription, and partner-link functionality
- Comply with legal obligations
- Resolve disputes and enforce agreements
You can delete your account at any time from inside the app. When you delete your account, we permanently delete: your account record, profile, all synced check-ins, past cycles, custom symptoms, gamification stats and badges, partner-link state and consent settings, and active session tokens. Data stored only on your device (journals, intimacy log, recipe favorites, grocery list, HealthKit / Health Connect data, etc.) is removed when you delete the app or clear app storage on your device.
Backups maintained by our infrastructure provider may retain deleted data for a short rolling window (typically up to 30 days) before being permanently expunged.
8. Your Choices and Rights
Depending on the functionality available to you, you may be able to:
- View, edit, or delete cycle, check-in, and profile entries in the app
- Export your data using the in-app export feature, which returns a JSON file containing your account, profile, check-ins, gamification stats, and badges
- Toggle which partner-shared summary fields are visible to your partner
- Disconnect a linked partner connection at any time
- Revoke HealthKit or Health Connect permissions from your device's settings
- Cancel your premium subscription through your Apple App Store, Google Play, or Stripe account
- Delete your account (which deletes all backend data described in Section 2(D))
- Stop using the Services and remove the app from your device
- Contact us with questions or requests at the email below
If you are located in the European Union, the United Kingdom, California, or another jurisdiction with data subject rights (such as access, correction, deletion, portability, or objection), you may exercise those rights by contacting us at the email below.
9. Data Security
We use reasonable administrative, technical, and organizational safeguards to protect information we process, including:
- Encryption in transit (HTTPS/TLS) for all communication between the app and our backend
- Bcrypt password hashing — we never store your plaintext password
- Encrypted-at-rest storage provided by our database vendor
- Session tokens that expire and can be revoked
However, no system is completely secure, and we cannot guarantee absolute security. Because much of your sensitive data lives on your device, we strongly recommend you also protect your device with a passcode, Face ID, or Touch ID.
10. Children's Privacy
CycleQuest is not intended for children under 17, and we do not knowingly collect personal information from children under 17 through the Services. If we learn that we have inadvertently collected personal information from a child under 17, we will delete that information.
11. Wellness / Medical Disclaimer
CycleQuest is a wellness and informational tool only. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Cycle predictions and insights are estimates based on the information you provide and should not be relied upon as a method of contraception or for diagnosing any medical condition. You should not rely on CycleQuest as a substitute for professional medical advice. Always consult a qualified health professional for medical concerns.
12. International Use
If you use the Services from outside the United States, you understand that your information may be processed in the United States or in other jurisdictions where our service providers operate, subject to applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we do, we will update the Effective Date above and post the revised version in the app and at this URL. Material changes will be communicated through an in-app notice when reasonable. Your continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.
14. Contact
If you have questions about this Privacy Policy or wish to exercise any of your rights described above, contact us at: