CycleTrack Privacy Policy

Last updated: August 18, 2026  |  App: CycleTrack (Google Play)

Quick answers for users:

CycleTrack ("we", "our", or "the app") is a privacy-first period and ovulation tracking application developed by Hammad Ali. This Privacy Policy explains what information the app handles, how long we keep it, how you can delete it, and the choices you have.

1. Summary

2. Information you provide

You may optionally log:

This data is used only to show your calendar, predictions, analytics, insights, and local reminders inside the app.

3. Local storage

CycleTrack stores your data in an encrypted SQLite database (SQLCipher) on your device. We do not transmit this data unless you explicitly enable cloud backup and sign in with Google.

4. Optional cloud backup

If you choose Backup & restore and sign in with Google, the app encrypts your data on your device using AES-256-GCM, then uploads an opaque ciphertext blob to our Supabase backend. The server cannot read your plaintext cycle data. Your Google account is used only to identify your backup.

5. Third-party services

The app works fully offline without sign-in or cloud backup.

6. Notifications

If you allow notifications, the app schedules reminders locally on your device (period, fertile window, ovulation, late period, pill reminders). We do not send push notifications from a server.

7. Data retention

We do not retain readable personal health data on our servers. Retention depends on how you use CycleTrack:

If you use CycleTrack offline only and never enable cloud backup, we do not store or retain your personal data on our systems.

8. How to delete your data

You can delete your data at any time. You do not need to email us for standard in-app deletion.

8.1 Delete all data (local + cloud) — recommended

  1. Open the CycleTrack app.
  2. Tap Settings in the bottom navigation bar.
  3. Scroll down and tap Delete everything.
  4. Confirm when prompted.

This permanently deletes your local encrypted database, app lock PIN/biometrics settings, scheduled notifications, and your encrypted cloud backup (if signed in).

8.2 Delete cloud backup only

  1. Open Settings → Backup & restore.
  2. Sign in with Google (if not already signed in).
  3. Use Delete everything in Settings to remove the cloud backup, or sign out and contact us (Section 8.4) to request server-side deletion.

8.3 Delete local data only

8.4 Data deletion requests by email or GitHub

If you cannot open the app (for example, lost phone with cloud backup enabled), you may request deletion of your cloud backup by contacting us:

We will verify account ownership and delete the encrypted cloud backup within 30 days. Data stored only on a lost device cannot be deleted remotely unless cloud backup was enabled.

9. Data export

Export your logs anytime: Settings → Export CSV. The file is saved on your device only and is not uploaded to our servers.

10. Children

CycleTrack is not directed at children under 13. We do not knowingly collect personal information from children.

11. Medical disclaimer

CycleTrack shows statistical estimates based on your logs. It is not medical advice, diagnosis, or contraception counseling. Consult a healthcare professional for medical decisions.

12. Security

We use encryption for local storage and cloud backups. No method is 100% secure; use app lock and keep your device protected.

13. Changes to this policy

We may update this Privacy Policy. The "Last updated" date at the top will change when we do. Continued use of the app after updates means you accept the revised policy.

14. Contact

Developer: Hammad Ali
Email: hammadali.official13@gmail.com
GitHub: SoftwareEngineer-Hadi/CycleTrack