My Cycle Safe AI
Privacy Policy
Effective Date: May 5, 2026 · Last Updated: May 5, 2026
My Cycle Safe AI ("My Cycle Safe", "we", "us", or "our") provides an AI-powered menstrual cycle tracking service through the website at mycyclesafe.ai and any related applications, calculators, and tools (together, the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the rights and choices you have over your information.
We treat menstrual, reproductive, and other health information as among the most sensitive categories of personal data. This Policy is written to be plain enough to actually read. If anything is unclear, please contact us using the details at the end of this document.
Please read this Privacy Policy carefully. By creating an account, using the Safe Days Calculator, submitting the "Your Doctor" form, or otherwise using the Service, you acknowledge that you have read and understood this Policy. Where required by law, we will ask for your explicit consent before processing your sensitive health data.
1. Who We Are and How to Contact Us
My Cycle Safe AI is operated by mycyclesafe.ai, incorporated under the laws of India, with its principal place of business at Coimbatore, Tamil Nadu, India ("the Company").
For all privacy-related questions, requests, or complaints you can reach us at:
- Privacy contact email: [email protected]
- General support: [email protected]
- Postal address: Coimbatore, Tamil Nadu, India
If we are required by law to designate a Data Protection Officer or an EU/UK Representative, their details will be listed here once appointed.
2. Scope of This Policy
This Policy applies to:
- Our marketing website and product pages, including the Safe Days Calculator and the "Your Doctor" intake form.
- Accounts you create through the Service, including data you sync across devices.
- Communications you have with us by email or through the Service.
This Policy does not apply to third-party websites or services we link to. Their handling of your data is governed by their own privacy policies, and we encourage you to read them before sharing information.
3. Information We Collect
We collect three categories of information: (a) information you provide to us, (b) information collected automatically when you use the Service, and (c) information from third parties.
3.1 Information You Provide
Account information. When you create an account we collect your email address and password. You may optionally provide a display name, date of birth, and country.
Cycle and health information. To deliver the core Service, we process information about your menstrual cycle, including the start date of your last period, typical shortest and longest cycle lengths, and any cycle, mood, or symptom entries you choose to log. You decide what to log. You can use the Safe Days Calculator without an account, in which case the inputs are processed only to generate the on-screen result and are not stored against an identified user profile.
"Your Doctor" intake information. If you submit the "Your Doctor" form, we collect a free-text description of your symptom or health concern, the medical specialty you select, and your email address. This information is used to facilitate a referral or follow-up communication, as described in Section 4.
Communications. When you contact us by email or other support channels, we keep a record of the message, your contact details, and our reply.
3.2 Information Collected Automatically
Device and technical data. When you visit the Service we automatically receive technical information including IP address, browser type and version, operating system, device identifiers, referring URL, language preference, and approximate (city- or region-level) location derived from IP. We do not collect precise GPS location.
Usage data. We log how you interact with the Service: pages visited, features used, calculator inputs and results at an aggregate level, timestamps, error reports, and crash data. This is used to keep the Service stable, diagnose problems, and improve features.
Cookies and similar technologies. We and our analytics providers use cookies, local storage, pixels, and similar technologies. Details, including how to opt out, are in Section 9. We deploy Google Tag Manager and the analytics tools loaded through it; specific tools in use at any time are listed in our Cookie Notice at mycyclesafe.ai/cookies.
3.3 Information From Third Parties
If you log in using a third-party identity provider (for example, Apple or Google), we receive basic profile information from that provider, limited to what you authorize them to share with us (typically email address and a unique identifier). We do not receive your password.
We do not buy lists of personal information from data brokers, and we do not enrich your account data with information purchased from third parties.
3.4 Sensitive and Special-Category Data
Menstrual cycle data, fertility data, symptom logs, and the symptom description in the "Your Doctor" form are "special category" data under the EU and UK General Data Protection Regulation (GDPR), "sensitive personal information" under the California Consumer Privacy Act (CCPA/CPRA) as amended, and "consumer health data" under the Washington My Health My Data Act and similar US state laws.
We process this category of data only with your explicit consent and only for the purposes described in this Policy. You can withdraw that consent at any time by deleting your account or by contacting us; withdrawal does not affect the lawfulness of processing already carried out.
3.5 Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us at [email protected] and we will delete it. Where local law sets a higher age of digital consent, that higher age applies in that jurisdiction.
4. How We Use Your Information
We use your information for the following purposes:
Provide the Service. Create and authenticate your account, save your cycle data, calculate predicted period and ovulation dates, generate insights, and let you sync data across your devices.
Run the AI prediction model. Cycle data you log is used as input to our prediction algorithms so the Service can produce personalized period, ovulation, and fertility-window estimates. Section 5 explains how the AI features work and what they are not.
Operate the "Your Doctor" form. Match the symptom and specialty you provide with one of our partner clinicians or partner clinics, send you a verification code by email, and pass on the information you submitted so the partner can follow up with you. We will tell you, before you submit, who the partner is going to be in your case. We do not share your cycle log with the doctor unless you separately authorize that.
Communicate with you. Send service-related messages such as account verification, password resets, security alerts, and changes to legal terms. With your consent, we may also send product updates and educational content; you can unsubscribe at any time.
Improve and develop the Service. Diagnose bugs, monitor performance, build aggregate analytics, train and evaluate machine-learning models in line with Section 5, and design new features. Where used for AI training, data is de-identified before use unless you have given a separate, specific consent.
Keep the Service safe. Detect and prevent fraud, abuse, account compromise, and other harmful activity, and to enforce our Terms of Service.
Comply with the law. Meet legal, regulatory, tax, and accounting obligations and respond to lawful requests from public authorities, in line with Section 8.
4.1 Legal Bases for Processing (EU/UK)
If you are in the EU, the EEA, the UK, or Switzerland, the legal bases on which we process your personal data are:
- Performance of a contract — to deliver the features you have asked for, such as account login, cycle tracking, and calculator results.
- Explicit consent — for processing of your sensitive health data, for marketing communications, and for non-essential cookies. You can withdraw this consent at any time.
- Legitimate interests — to keep the Service secure, prevent fraud, and improve features, where our interests are not overridden by your rights and freedoms.
- Legal obligation — when we are required by law to retain or disclose certain information.
5. How We Use AI and What It Is Not
The Service uses machine-learning models trained on cycle and symptom data to estimate things like the likely start of your next period, your fertile window, and which phase of the cycle you are in.
A few important points about these AI features:
- The AI produces estimates, not certainties. Cycle length varies for many reasons — stress, illness, travel, breastfeeding, hormonal contraception, perimenopause, and others — and the model cannot account for every factor.
- No automated decisions with legal or similarly significant effects. We do not use AI to make decisions about you that produce legal effects (for example, denying you a service or determining a price). The AI generates information; you decide what to do with it.
- Training data. We may use de-identified, aggregated cycle data to improve our models. "De-identified" means we strip direct identifiers (such as email and account ID) and any free-text fields, and we do not attempt to re-identify the data. Where we want to use data that is not fully de-identified for training, we will ask for separate, specific consent.
- No use for third-party advertising or profiling. We do not use your cycle data, symptom logs, or AI-generated predictions to target advertising to you or to share profiles about you with advertisers.
6. How We Share Your Information
We share personal information only as described below. We do not sell your personal information for money, and we do not share your cycle data, symptom data, or "Your Doctor" submissions with advertisers or data brokers.
6.1 Service Providers
We use carefully selected third-party companies to host our infrastructure, send transactional emails, provide customer support, run analytics, and process payments if and when paid features are launched. These providers act as our "processors" or "service providers" — they may only use your information on our instructions and for the purposes we have set, and they are bound by written contracts that include confidentiality and security commitments.
Categories of providers we currently use include:
- Cloud hosting and storage
- Authentication and identity verification (including email verification codes)
- Transactional email delivery
- Product analytics and crash reporting
- Customer support tooling
A current list of named sub-processors is maintained at mycyclesafe.ai/subprocessors and is updated when it changes.
6.2 Partner Clinicians (the "Your Doctor" Feature)
When you submit the "Your Doctor" form, the symptom description, specialty, and email address you provide are sent to the partner clinic or clinician we match to your request, so they can contact you. Once that information is in the hands of the partner, the partner is an independent controller of your information and uses it under its own privacy practices and the medical-confidentiality rules of its jurisdiction. We will identify the partner before submission so you can review their privacy notice.
6.3 Legal, Compliance, and Safety
We may disclose information if we believe in good faith that disclosure is required:
- To comply with a court order, subpoena, or other binding legal process;
- To respond to a lawful request from a public authority;
- To establish, exercise, or defend legal claims;
- To protect the safety, rights, or property of any person, including detecting and preventing fraud, abuse, or attacks on the Service.
Our commitments around law-enforcement requests. We will not voluntarily provide your cycle, fertility, pregnancy, pregnancy-loss, or symptom data to law enforcement or other government agencies. Where we receive a legal demand, we will, unless prohibited by law, attempt to notify you so you have an opportunity to challenge it, and we will narrow disclosure to what is strictly required by the order. We publish a transparency report describing the volume and nature of legal requests we receive.
6.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you (for example, by email and through a prominent notice on the Service) before your information is transferred and becomes subject to a different privacy policy, and you will have the right to delete your account before the transfer takes effect.
6.5 With Your Direction
We will share information at your request — for example, if you choose to export your data and email it to your own clinician or partner.
7. International Transfers of Data
We are a global service. Personal data may be processed in countries other than the one in which you live, including India and the United States. The data-protection laws of these countries may differ from those of your country.
When we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognised as providing an adequate level of protection, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK Addendum where relevant;
- Supplementary technical and organisational measures such as encryption in transit and at rest;
- Vendor due diligence and ongoing monitoring of sub-processors.
You can request a copy of the safeguards in place by emailing [email protected].
8. How Long We Keep Information
We keep personal data only as long as we need it for the purpose we collected it, or as long as we are legally required to keep it. Specifically:
- Account and cycle data: kept while your account is active. If you stop using the Service, we will retain your account for 24 months and then notify you before deletion. You can delete your account and your cycle history at any time from your settings.
- "Your Doctor" submissions: retained by us for 12 months for support and audit purposes; the partner clinician retains the data under its own retention rules.
- Anonymous Safe Days Calculator inputs (without an account): not stored against you; aggregate logs are kept for up to 12 months for security and abuse prevention.
- Support communications: retained for 12 months from the date of the last interaction.
- Legal/compliance records: retained as long as required by applicable law (for example, tax records).
- De-identified data: may be retained indefinitely, because it cannot be linked back to you.
9. Cookies, Analytics, and Tracking
We use cookies and similar technologies for three main purposes:
- Strictly necessary — to make the Service work (login sessions, security tokens, load balancing). These cannot be turned off.
- Analytics — to understand how the Service is used in aggregate. Where required by law, we ask for your consent before deploying these.
- Preferences — to remember your settings (for example, language).
We do not use third-party advertising cookies or pixels on the Service.
You can manage your cookie preferences from the cookie banner shown on first visit and from the "Cookie Settings" link in the website footer. Your browser also lets you block or delete cookies; doing so may break parts of the Service.
We honour Global Privacy Control (GPC) signals where they are recognised as a valid opt-out under applicable law.
10. How We Protect Your Information
We use a combination of technical and organisational safeguards designed to protect your information against loss, misuse, and unauthorised access:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of cycle and symptom data at rest using industry-standard algorithms;
- Role-based access controls so that only employees and contractors who need access for a specific task can see your data;
- Logging and monitoring of access to production systems;
- Regular security testing, including third-party penetration testing;
- Bug-bounty and responsible-disclosure channels for external researchers.
No system is perfectly secure. If we ever experience a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authorities and, where required, you, in line with applicable law.
A note on our marketing claims. Our marketing pages describe the Service as "privacy-first" and reference end-to-end encryption and on-device processing. To be precise: cycle inputs in the Safe Days Calculator are computed locally in your browser and are not sent to our servers when you use the calculator without an account. When you create an account and sync data, your cycle data is encrypted in transit and at rest, but it is processed on our servers — it is not end-to-end encrypted in the strict cryptographic sense (where only your device holds the keys). We are working to make this distinction clearer on our marketing pages.
11. Your Privacy Rights
Depending on where you live, you may have the following rights over your personal data. We will honour these rights without charge and within the time limits set by applicable law (typically 30 days, extendable by another 60 days for complex requests).
11.1 Rights Available to All Users
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct information that is inaccurate or incomplete.
- Deletion — ask us to delete your account and the personal data associated with it.
- Export / Portability — receive your cycle data in a machine-readable format (JSON or CSV).
- Object / Restrict — object to certain processing or ask us to restrict it.
- Withdraw consent — for any processing that is based on your consent, including AI-training participation and marketing.
You can exercise most of these rights directly from your account settings. For anything that cannot be done from settings, email [email protected]. We may need to verify your identity before acting on a request to keep your data safe.
11.2 EU/UK Users
If you are in the EU, the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu (EU/EEA), ico.org.uk (UK), and edoeb.admin.ch (Switzerland). We would, of course, prefer that you contact us first so we can try to resolve the issue.
11.3 California Residents (CCPA/CPRA)
If you are a California resident you have the right to: know what personal information we collect and how we use it; request access, deletion, and correction; opt out of "sales" and "sharing" of personal information; and limit the use of "sensitive personal information". We do not sell your personal information for money, and we do not share it for cross-context behavioural advertising.
To exercise these rights, email [email protected] or use the "Do Not Sell or Share My Personal Information" link in the website footer. You can also designate an authorized agent to make a request on your behalf, subject to verification. We will not discriminate against you for exercising any of these rights.
11.4 Other US States
If you live in a US state with a comprehensive consumer privacy law (including but not limited to Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia), you have rights similar to those above. The Washington My Health My Data Act and similar laws in Nevada and Connecticut give you additional rights specifically over consumer-health data, including the right to withdraw consent for collection or sharing of that data and the right to have it deleted.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes — for example, new categories of data, new sharing recipients, or new uses for AI — we will:
- Post the updated Policy with a new "Last Updated" date;
- Notify you by email or in-product notice at least 14 days before changes take effect;
- Where the change requires it under law, ask for your renewed consent before applying it to your data.
Continued use of the Service after the effective date of an updated Policy means you accept the changes, except for changes that legally require fresh consent.
13. Jurisdiction-Specific Notes
13.1 No HIPAA Coverage
My Cycle Safe AI is not a "covered entity" or "business associate" under the United States Health Insurance Portability and Accountability Act (HIPAA), and the data we collect is generally not "Protected Health Information" as HIPAA defines it. The data we collect is, however, sensitive consumer-health data and is protected under this Policy and under state consumer-health and privacy laws (including the Washington My Health My Data Act, the California Confidentiality of Medical Information Act as amended for fertility-tracking apps, and similar laws). The "Your Doctor" feature involves a separate clinician partner who may be a HIPAA-covered entity; their handling of your data is governed by their own Notice of Privacy Practices.
13.2 India
Where we offer the Service to users in India, processing of your personal data is also subject to the Digital Personal Data Protection Act, 2023 (DPDPA). You may contact our designated Grievance Officer at [email protected] to raise any concerns, and you have the right to nominate another person to exercise your rights in the event of your death or incapacity.
13.3 Brazil
Where the Brazilian Lei Geral de Proteção de Dados (LGPD) applies, you have rights of confirmation, access, correction, anonymisation or deletion, portability, information about sharing, and withdrawal of consent. You can contact our DPO at [email protected].
14. Contact Us
If you have any questions, requests, or complaints about this Privacy Policy or how we handle your information, please contact us:
- Privacy: [email protected]
- Support: [email protected]
- Postal: mycyclesafe.ai, Coimbatore, Tamil Nadu, India
We aim to respond to all privacy enquiries within 30 days.