Privacy Policy โ PCOS Pal
Last Updated: 2026-08-07
Overview
PCOS Pal ("we", "our", "the app") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
Where your data lives. Your logs are saved on your device, and โ once you
create an account โ backed up to Firebase so you can reach them from another
phone. Only you can read them: our security rules allow each account to read
and write its own records and nothing else. Crash reports are sent from
release builds. You can erase everything, on the device and on the server,
from You โ your name โ Delete Account & Data.
>
Server location. Our database is hosted in Singapore
(
asia-southeast1). If you are in the EU or UK, your data is transferredoutside that area and processed there.
Data We Collect
Data You Provide
- Account information: Email address and password, handled by Firebase Authentication. Guests get an anonymous account with no email attached.
- PCOS profile: Quiz answers, PCOS type, dietary preferences, goals
- Health tracking data: Symptoms, period/cycle dates, weight entries, supplement logs, mood, water intake
- Meal data: Food scans, meal plan preferences, recipes saved
- Pictures: Your profile picture, stored in your own Firestore record. Progress photos never leave your phone โ they are not uploaded anywhere, and only the date, the weight and the file name sync, so a new device shows the entry without the picture.
- Notes you write in Circles: saved to your account and readable only by you. Nobody else can see them.
- App activity: which grocery items you have ticked off, and a seven-day summary of days you logged, used to work out your weekly score.
Data Collected Automatically
- Usage analytics: app opens, screens viewed, onboarding and quiz progress, paywall views, subscription events, lessons and workouts completed, streak milestones, and the PCOS score of a food you scan. These are not anonymised: they are attached to an analytics profile identified by a random ID, which also carries your plan type, streak length and whether you finished the quiz. No cycle, period, symptom, weight, mood or supplement data is ever sent.
This goes to two services, which receive the same events: Firebase Analytics (Google), active in every release build, and Mixpanel, only in builds configured with a Mixpanel token. Neither runs while the app is in development.
Firebase Analytics also records some things on its own that we do not choose event by event: session starts, your device model, OS version and app version, the country your connection appears to come from, and a random app-instance identifier. It does not receive your name, email or account ID, and it is not used for advertising โ the app does not include an advertising SDK and does not ask for your device's advertising identifier.
- Crash reports: Device type, OS version, app version and the stack trace of a crash, through Firebase Crashlytics. Enabled in release builds; disabled while the app is in development.
- Subscription status: Plan type and whether a subscription is active, handled by the App Store or Play Store. We do not receive your payment details.
We never send Apple Health data to analytics or any third party.
Data from Third Parties
- Apple HealthKit: Weight only, and only if you explicitly opt in. On iPhone and iPad; the Android build does not connect to Health Connect.
How We Use Your Data
| Purpose | Data Used |
|---|---|
| Personalize your experience | PCOS type, preferences, tracking data |
| Generate meal plans | PCOS type, dietary preferences, calorie target |
| Show insights and correlations | Symptom logs, cycle data, weight trends |
| Calculate PCOS Score | Nutrition, supplements, activity, logging, sleep |
| Improve the app | Anonymized usage analytics, crash reports |
| Manage subscriptions | Email, subscription status |
| Send notifications | Notification preferences (only if you opt in) |
What We Do NOT Do
- We do NOT sell your personal data to third parties
- We do NOT share your health data with advertisers
- We do NOT use your data for purposes other than those listed above
- We do NOT store your Apple Sign In credentials (handled by Apple)
- We do NOT track you across other apps or websites
Data Storage & Security
On your device: your logs live in the app's sandbox, protected by your device passcode and iOS/Android app isolation.
On our servers:
- Health data in Firebase Firestore, encrypted at rest, in
asia-southeast1 - Profile pictures in your Firestore record. Progress photos are never uploaded
- Transmitted over HTTPS
- Sign-in through Firebase Authentication (email and password)
- Access rules restrict every record to the account that owns it; there is no path that lets one account read another's data, and no public read access
Sub-processors: Google (Firebase โ authentication, database, crash reporting, and usage analytics), Apple and Google (subscription status, through their own in-app purchase systems), Mixpanel (pseudonymous usage analytics, only in builds configured for it). Apple Health data is never sent to any of them.
Retention: we keep your data for as long as your account exists. Deleting your account removes the server copy immediately and the device copy at the same time. Crash reports are retained by Firebase Crashlytics for 90 days. Firebase Analytics keeps its event data for the period set in the project's console; aggregate reports are retained indefinitely.
Apple HealthKit
- HealthKit data is only accessed if you explicitly grant permission
- We read one thing: your weight
- We never write to HealthKit without your explicit action
- HealthKit data is not shared with third parties or used for advertising
- You can revoke HealthKit access at any time in iOS Settings
Your Rights
Access
You can view all of your data inside the app.
Deletion
You โ your name โ Delete Account & Data permanently erases your profile, quiz results, cycle history, symptom and weight logs, pictures and streak โ from the device and from the database, and it deletes the account itself. Progress photos are erased with the device data, having never been uploaded anywhere. It cannot be undone.
Export
You โ Export My Data produces a complete JSON file plus CSV copies of your symptom and weight logs, and hands them to the share sheet so you can save or email them wherever you like.
GDPR (European Users)
You have the right to: access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.
CCPA (California Users)
You have the right to: know what data we collect, request deletion, and opt out of data sales (we do not sell data).
Community Content
Circles posts are moderated: a filter screens posts before they publish, every post can be reported, and any member can be blocked. Blocked members can be managed in You โ Blocked members. Community guidelines are shown in-app from the shield icon in any circle.
Anything you write in a circle is saved to your own account and is readable only by you. Nothing is shared with other members until community sync ships, and this policy will be updated before that happens.
Children's Privacy
PCOS Pal is intended for adults. Onboarding asks you to confirm you are 18 or older before any health data is collected, and users who indicate they are under 18 cannot proceed. We do not knowingly collect data from anyone under 18.
Medical Disclaimer
PCOS Pal is for educational and informational purposes only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical decisions.
Cycle and fertility estimates are not contraception. PCOS cycles are often irregular, which makes ovulation prediction unreliable. Do not rely on the fertile-window estimate to prevent or achieve pregnancy.
Supplement information is educational. The app names supplements but gives no amounts โ a dose is a prescription, and it is not ours to write. Several of the ones named (including berberine and inositol) interact with medications such as metformin and other blood-sugar lowering drugs. Talk to your doctor or pharmacist before starting anything.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via the app or email.
Contact Us
For privacy-related questions: support@ichime.dev