1. Introduction
Welcome to CycleCue ("we," "our," or "us"). We are committed to protecting your privacy and handling your personal information with care and respect. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web service (collectively, the "Service").
CycleCue operates under South African law and complies with the Protection of Personal Information Act (POPIA). Where our users are located in other jurisdictions, we also respect applicable local privacy laws.
Privacy First Promise
We believe your health data is deeply personal. We will never sell, rent, or share your personal health information with third parties for commercial purposes without your explicit consent.
By using CycleCue, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Health and Cycle Information
To provide you with personalized period tracking and health insights, we collect:
- Menstrual Cycle Data: Period start and end dates, flow intensity, cycle length
- Symptoms: Physical and emotional symptoms you choose to track
- Mood Data: Mood tracking information you voluntarily provide
- Health Notes: Personal notes and observations you add to your cycles
- Self-care & Lifestyle: Sleep quality, energy level, stress, and self-care entries you log
2.2 Account Information
- Email address (for account creation and communication)
- Profile information (name, date of birth, cycle defaults)
- App preferences and settings
2.3 Technical Information
- Device information (device type, operating system, app version)
- Usage analytics (which features you use, how often)
- Crash reports and performance data (to improve app stability)
- IP address and general location (for security and app optimization)
2.4 Information You Choose Not to Provide
You can use CycleCue without providing certain information. However, limiting data may affect the accuracy of predictions and personalized features.
3. How We Use Your Information
3.1 Core Service Functions
- Cycle Tracking: Record and display your menstrual cycle information
- Predictions: Generate period and fertility predictions using your cycle history
- Insights: Provide personalized health insights and pattern analysis
- Reminders: Send notifications for upcoming periods, ovulation, and health check-ups
3.2 Service Improvement
- Analyze aggregated, anonymized data to improve prediction accuracy
- Enhance user experience based on usage patterns
- Develop new features that benefit our user community
3.3 Communication
- Send important service updates and security notifications
- Provide customer support and respond to your inquiries
- Share educational content about reproductive health (with your consent)
3.4 Legal and Security
- Comply with applicable laws and legal requirements
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service
4. Information Sharing and Disclosure
Important: We Do NOT Sell Your Data
CycleCue will never sell, rent, or lease your personal health information to third parties for commercial purposes.
4.1 Service Providers
We may share information with trusted third-party service providers who assist us in operating our Service:
- Cloud Storage: Secure hosting of your encrypted data
- Analytics: Anonymized usage analytics to improve our service
- Customer Support: Platforms that help us provide you with support
- Security: Services that help protect against fraud and abuse
All service providers are contractually required to protect your information and use it only for specified purposes.
4.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal process (subpoenas, court orders)
- Government investigations
- Protection of rights, property, or safety of CycleCue, our users, or others
- Emergency situations involving immediate physical harm
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice and ensure the same privacy protections apply.
4.4 With Your Consent
We may share information with your explicit consent, such as when you choose to share data with healthcare providers or researchers.
5. Data Security
End-to-End Encryption
Your sensitive health data is encrypted using industry-standard AES-256 encryption both in transit and at rest.
Secure Infrastructure
We use enterprise-grade cloud infrastructure with multiple layers of security, including firewalls and intrusion detection.
Access Controls
Strict access controls ensure only authorized personnel can access systems, and all access is logged and monitored.
Ongoing Reviews
We regularly review our security practices and infrastructure to identify and address potential vulnerabilities.
5.1 Data Minimization
We collect and store only the information necessary to provide our services effectively. We regularly review and purge unnecessary data.
5.2 Incident Response
In the unlikely event of a data breach, we have incident response procedures in place and will notify affected users and the relevant authorities as soon as reasonably possible after discovery, in accordance with applicable law including South Africa's POPIA.
6. Data Retention
6.1 Active Accounts
We retain your data as long as your account remains active and for a reasonable period thereafter to provide our services.
6.2 Account Deletion
When you delete your account:
- Personal health data is permanently deleted within 30 days
- Some anonymized, aggregated data may be retained for research and service improvement
- Legal and safety information may be retained as required by law
6.3 Inactive Accounts
Accounts inactive for more than 3 years will be marked for deletion, with 90 days notice provided to your registered email.
7. Your Privacy Rights
Access
Request a copy of all personal data we have about you
Correction
Update or correct inaccurate personal information
Deletion
Request deletion of your personal data and account
Portability
Export your data in a machine-readable format
Restriction
Limit how we process your personal information
Objection
Object to certain types of processing
7.1 Exercising Your Rights
To exercise any of these rights, you can:
- Use the privacy controls in your account settings
- Export your data directly from the app
- Contact us at privacy@cyclecue.co.za
7.2 Response Time
We will respond to your requests within 30 days and provide updates if additional time is needed.
8. Children's Privacy
Age Requirement
CycleCue is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we discover we have collected information from a child under 13, we will delete it promptly.
8.1 Teen Users (13-17)
For users aged 13-17, we recommend parental guidance when using health tracking apps. We encourage teen users to discuss their use of CycleCue with a trusted adult.
9. International Data Transfers
CycleCue operates globally, and your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
9.1 Safeguards
When we transfer your information internationally, we ensure adequate protection through:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions by relevant data protection authorities
- Your explicit consent for specific transfers
9.2 Data Localization
Where legally required, we store data locally within specific jurisdictions to comply with local data residency requirements.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
10.1 Notification of Changes
- Minor Changes: Posted on our website with updated "Last Modified" date
- Material Changes: Email notification to registered users 30 days in advance
- Significant Changes: In-app notification requiring acknowledgment
10.2 Continued Use
Your continued use of CycleCue after privacy policy changes indicates acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Response Time
We aim to respond to all privacy-related enquiries within 24 hours. For urgent matters, please mark your email as "URGENT - Privacy Concern".