CycleTrack Privacy Policy
Last updated: August 18, 2026 | App: CycleTrack (Google Play)
- Data retention: Local data stays on your phone until you delete it. Optional cloud backup is kept until you delete it. We do not store readable health data on our servers.
- Data deletion: In the app go to Settings → Delete everything. No account is required for deletion.
CycleTrack ("we", "our", or "the app") is a privacy-first period and ovulation tracking application developed by Hammad Ali. This Privacy Policy explains what information the app handles, how long we keep it, how you can delete it, and the choices you have.
1. Summary
- No account is required to use the app.
- Your cycle logs are stored locally in an encrypted database on your device.
- Cloud backup is optional and encrypted on your device before upload.
- We do not sell your personal data.
- You can delete all data in the app at any time (see Section 8).
2. Information you provide
You may optionally log:
- Menstrual flow, symptoms, mood, intimacy, libido
- Basal body temperature (BBT), weight, cervical mucus, pill intake, notes
- App lock PIN (stored as a one-way hash on device only — we cannot read your PIN)
- Pregnancy mode settings (if enabled)
This data is used only to show your calendar, predictions, analytics, insights, and local reminders inside the app.
3. Local storage
CycleTrack stores your data in an encrypted SQLite database (SQLCipher) on your device. We do not transmit this data unless you explicitly enable cloud backup and sign in with Google.
4. Optional cloud backup
If you choose Backup & restore and sign in with Google, the app encrypts your data on your device using AES-256-GCM, then uploads an opaque ciphertext blob to our Supabase backend. The server cannot read your plaintext cycle data. Your Google account is used only to identify your backup.
5. Third-party services
- Google Sign-In — only if you enable cloud backup.
- Supabase — stores encrypted backup blobs when you use cloud backup.
- Google Fonts — app typography may load from Google servers.
The app works fully offline without sign-in or cloud backup.
6. Notifications
If you allow notifications, the app schedules reminders locally on your device (period, fertile window, ovulation, late period, pill reminders). We do not send push notifications from a server.
7. Data retention
We do not retain readable personal health data on our servers. Retention depends on how you use CycleTrack:
- Local data (default mode) — Stored only on your device until you delete it using Settings → Delete everything, or until you uninstall the app. We do not automatically delete local data after a fixed number of days.
- Optional cloud backup — If you enable backup and sign in with Google, one encrypted backup file is stored on our Supabase server until you delete it using the in-app steps in Section 8. We do not use backups for ads or analytics.
- Data we do not collect or retain — We do not maintain separate server copies of your plaintext cycle entries, symptoms, notes, or health measurements. Google Sign-In data is handled by Google; see Google Privacy Policy.
If you use CycleTrack offline only and never enable cloud backup, we do not store or retain your personal data on our systems.
8. How to delete your data
You can delete your data at any time. You do not need to email us for standard in-app deletion.
8.1 Delete all data (local + cloud) — recommended
- Open the CycleTrack app.
- Tap Settings in the bottom navigation bar.
- Scroll down and tap Delete everything.
- Confirm when prompted.
This permanently deletes your local encrypted database, app lock PIN/biometrics settings, scheduled notifications, and your encrypted cloud backup (if signed in).
8.2 Delete cloud backup only
- Open Settings → Backup & restore.
- Sign in with Google (if not already signed in).
- Use Delete everything in Settings to remove the cloud backup, or sign out and contact us (Section 8.4) to request server-side deletion.
8.3 Delete local data only
- Tap Settings → Delete everything, or
- Uninstall CycleTrack from your Android device.
8.4 Data deletion requests by email or GitHub
If you cannot open the app (for example, lost phone with cloud backup enabled), you may request deletion of your cloud backup by contacting us:
- GitHub: Open a new issue with title Data deletion request and include the Google account email used for backup.
- Email: hammadali.official13@gmail.com — subject line: CycleTrack Data Deletion Request.
We will verify account ownership and delete the encrypted cloud backup within 30 days. Data stored only on a lost device cannot be deleted remotely unless cloud backup was enabled.
9. Data export
Export your logs anytime: Settings → Export CSV. The file is saved on your device only and is not uploaded to our servers.
10. Children
CycleTrack is not directed at children under 13. We do not knowingly collect personal information from children.
11. Medical disclaimer
CycleTrack shows statistical estimates based on your logs. It is not medical advice, diagnosis, or contraception counseling. Consult a healthcare professional for medical decisions.
12. Security
We use encryption for local storage and cloud backups. No method is 100% secure; use app lock and keep your device protected.
13. Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top will change when we do. Continued use of the app after updates means you accept the revised policy.
14. Contact
Developer: Hammad Ali
Email: hammadali.official13@gmail.com
GitHub: SoftwareEngineer-Hadi/CycleTrack