Privacy Policy
Last updated: October 8, 2026
Please note: This app is for informational purposes only and does not provide medical advice or contraception.
1. Who we are and Policy Applicability
The controller of your personal data is Tarfion Ltd, company registered at Griva Digeni 59, Kaimakliotis Building, 5th Floor, 6043 Larnaca, Cyprus
Contact: [email protected]
This Policy explains how we collect, use, and protect your data when you use Ondiva (the "App"). It should be read together with our Terms of Use. By using the App, you confirm you have read this Policy.
Cycle, symptom, and related health information you log is sensitive data under GDPR Article 9 and under US state laws (including CCPA/CPRA "sensitive personal information" and state reproductive/health-data statutes such as Washington's My Health My Data Act). We process it only with your explicit, separate consent - see Section 2 below.
2. What we collect, purposes and legal basis
| What data | What for | Legal basis |
|---|---|---|
| Cycle dates and symptoms you log — the data you put in app | Calculating your cycle forecast, showing insights, tips, statistics and charts | Consent |
| Your answers on onboarding - year of birth, goal (track / conceive / perimenopause), cycle length, symptoms you usually have | For you to understand your expectations from using App core features; To deliver insights for you. Please note: Insights are generated locally; your data is not transmitted to our servers or any other external services. | Consent; Performance of Terms of Use |
| Install ID for Anonymous Mode — a random identifier generated on your device Note: Install ID is not linked to your personality | Operating the App, syncing your data to that install | Performance of Terms of Use |
| Account data — email and contact data | Creating an account | Performance of Terms of Use |
| Device and basic usage data — device type, OS version, app version, crash reports. | Keeping the App stable, fixing bugs | Legitimate interest |
| Push token | Sending the reminders and notifications you turn on | Consent (notification permission) |
| Support correspondence | Responding to your requests | Performance of Terms of Use / Legitimate interest |
Anonymous Mode. We don't ask for your name, email, or other identifiers; your data is bound only to your device. This mode is available to everyone and let you use the App when neither we nor any third party can identify you. Please note: 1) data in Anonymous Mode cannot be recovered if you lose or reset your device, see Section 5; 2) when using Anonymous Mode, our customer support may not be able to assist with specific or technical questions. However, we will do our best to help where possible.
Cycle forecasts, ovulation window, and flow trends are calculated on your device. From the dates and symptoms you log, the App predicts your ovulation window and cycle trends locally on your device.
3. Who we share data with
We do not sell your personal data. We share it only with service providers, including SDKs, who process it on our behalf under the respective contract and following privacy commitments, and only as needed:
- Hosting and infrastructure — Google Cloud (Cloud Run, Cloud SQL), Cloudflare (DNS, TLS, CDN)
- Analytics and crash reporting — Sentry, Google Cloud logs and metrics, BigQuery
- Authentication — Firebase Authentication
We may also share data with:
- Law enforcement and authorities: when required by law, legal process, or to protect user safety.
- Affiliates and corporate entities: for internal operations, auditing, and in the context of mergers, acquisitions, or corporate restructuring. In such cases, the acquiring entity will be bound by the terms of this Policy.
Using Anonymous Mode limits what we have to disclose in the first place, since we hold no name, email, or other identifier to connect to your data.
4. How long we keep data
| Data | Term |
|---|---|
| Cycle, symptom, and account/install data | While you use the App; deleted when you delete an entry, use Delete all data, or delete your account |
| Crash reports and diagnostics | Up to 14 months |
| Support correspondence | Up to 3 years |
We may retain certain types of Account data, technical logs and support correspondence data beyond the periods above where we still need it for lawful purposes: to establish, exercise or defend legal claims; to handle a complaint, dispute, audit or investigation; and to comply with a legal, regulatory, or accounting obligation; or to prevent, detect and address fraud, abuse, or security incident.
We may also keep aggregated (the data that does not contain personal identifiers) for internal analytics and statistics, as well as to evaluate our products.
5. Your rights and choices
If you're using Anonymous Mode, read this first: your data is tied only to this install. Deleting the App, resetting your device, or clearing app data deletes it permanently — we have no email or account to restore it from.
5.1 Deleting your data
- Delete all data (Settings) removes everything you logged, your settings and your consent record from your device. This cannot be undone.
- Delete account (Settings, when you are signed in) deletes your account. It does not delete the data on your device; use Delete all data for that.
- You can also ask us to delete your account by email: write to [email protected] and we will process your request.
Please note: Deleting your account does not automatically cancel a subscription. If you subscribed through Apple or Google, cancel it in your App Store or Google Play account settings. If you subscribed on our website, cancel it in your account settings on the website or by writing to support.
5.2 Withdrawing consent
Your consent is required for us to use your health data for core App features. You can withdraw this consent at any time in the App under Settings → Privacy → Withdraw health-data consent, or by contacting us. The App then stops using your logs and reminders stop. You choose whether your data stays on your device, unused, or is deleted. Withdrawing does not affect processing that happened before, and you can agree again at any time.
5.3 California and US state privacy rights
Cycle and symptom data is "sensitive personal information" under the CCPA/CPRA and, in some states, explicitly protected reproductive or health information. You may have the right to know what we collect, request deletion, correct inaccurate data, and limit the use of sensitive personal information. We do not sell or share this data for cross-context behavioral advertising. Contact us using Section 1's details to exercise these rights; we'll need to verify your identity first.
5.4 EU, UK & Canada privacy rights
If you are in the European Economic Area, you have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of your personal data |
| Restriction | Request we temporarily stop processing your data |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest |
| Complaint | Lodge a complaint with a supervisory authority |
| Withdraw Consent | Withdraw consent at any time |
UK Citizens Rights Under UK GDPR Addendum
This section provides details about individuals residing in the United Kingdom and details additional rights they have under the United Kingdom Data Protection Act 2018 (DPA) and the EU General Data Protection Regulation (GDPR) which is retained EU law after Brexit. Therefore, this section applies only to UK residents.
Your Rights and Choices in the UK
As a UK resident, You have the rights in relation to Your Personal Data under this Privacy Notice, including:
Right to be informed: You have the right to be provided with clear, transparent, and easily understandable information about how we use your personal data and your rights. This is why we’re providing you with the information in this Addendum.
Right of access: You have the right to obtain access to your personal data (if we’re processing it) and certain other information (similar to that provided in this Privacy Notice). This is so you’re aware and can check that we’re using your personal data in accordance with data protection law.
Right to rectification: You are entitled to have your personal data corrected if it’s inaccurate or incomplete.
Right to erasure: This is also known as ‘the right to be forgotten’ and, in simple terms, enables you to request the deletion or removal of your personal data where there’s no compelling reason for us to keep using it. This is not a general right to erasure; there are exceptions.
Right to restrict processing: You have the right to ‘block’ or suppress further use of your personal data in certain circumstances. When processing is restricted, we can still store your personal data, but may not use it further.
Right to data portability: You have the right to obtain and reuse your personal data in a structured, commonly used, and machine-readable format in certain circumstances. In addition, where certain conditions apply, you have the right to have such information transferred directly to a third party.
Right to object to processing: You have the right to object to us processing your personal data for our legitimate interests or for direct marketing purposes (including in each case any related profiling).
Right to withdraw consent: If we have obtained your consent to process your personal data for certain activities (for example, for optional features that rely on your consent), or consent to market to you, you may withdraw your consent at any time.
Rights related to automated decision-making and profiling: You have the right not to be subject to a decision when it’s based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for entering into, or the performance of, a contract between you and us.
To exercise any of these rights at any time, please contact our Customer Support.
5.5 Push Notifications
Turn off push notifications anytime in your device settings.
6. Security
We implement appropriate technical, organizational, and administrative measures to protect your personal and health-related data from accidental loss, unauthorized access, misuse, alteration, disclosure, or destruction. Given the sensitive nature of the information processed through our Services, our security protocols are built to address high data protection standards and include:
- Vulnerability & Threat Management: We periodically conduct system scans and security evaluations to identify and mitigate potential vulnerabilities.
- Access Control & Internal Policies: Access to system backend environments is strictly restricted to authorized personnel on a need-to-know basis. Our team members are bound by strict confidentiality obligations and privacy protocols.
- Data Integrity: We maintain technical controls designed to ensure the accuracy, resilience, and unauthorized modification of processed data.
Device Security
Because our App operates in Anonymous Mode, access to your cycle history depends directly on your device. We strongly recommend securing your smartphone with a passcode, PIN, Face ID, or fingerprint recognition to prevent unauthorized physical access to your App data.
While we take rigorous measures to safeguard your information, no method of transmission over the Internet or electronic storage system can be guaranteed as completely breach-proof. Therefore, we cannot warrant absolute security against all potential cyber threats or unauthorized interception during data transmission.
7. International Data Transfers
When we transmit your personal data beyond the EU/EEA, we rely on Standard Contractual Clauses approved by the European Commission, or, where a recipient is certified under it, the EU-US Data Privacy Framework, together with contractual confidentiality obligations.
All and any transfer of the personal data is done only for the purposes specified in this Policy and the Terms of Use.
8. Age and eligibility
Ondiva is intended for users aged 13 and over. We do not knowingly collect data from children under 13. Where the applicable digital consent age in your country is higher than 13 (as permitted under GDPR), use by someone below that age requires a parent or guardian's consent.
9. Changes to this Policy
We'll notify you of material changes by posting notice in the App. Continued use after a change takes effect means you accept the updated Policy, which supersedes all previous versions.