How we protect your data
See what data BodySeasons actually stores, where it is held, and when external services are involved. Explained clearly and separated by feature.
Technical status: 11 August 2026

„I stay watchful so you do not have to. What you record here stays yours.“
Riven
The essentials in one sentence
We store an account or an anonymous identifier so that your entries, settings, and BodySeasons features work on your device and, with your consent, in your encrypted personal cloud storage.
There is no hidden default matching of health data for advertising.
Health, cycle, and journal data is created only through your entries. Additional data is created only when you use or enable the relevant feature.
Your data journey at a glance
This overview separates what belongs to your account from data that is created only through your use.
Only when a feature needs it:
These services get to see something, and only what their task requires.
What is stored when you sign in
Every sign-in method receives its own stable BodySeasons user ID. It connects your account to your cloud storage, settings, and, when used, purchases or analyses.
Without emailStart anonymously
No email address, name, or password. User ID and anonymous recovery code Account status, free tier, and creation time Active session for using the app
Via GoogleSign in with Google
The one-time Google sign-in code is used for authentication. It is not a field in our user account. Stable Google identifier for account matching Email address and display name supplied by Google, when available Account status, tier, and timestamps
The classic waySign in with email
This data is needed for sign-in, email confirmation, and password reset. Email address and chosen display name Password stored only as an unreadable password hash Confirmation or reset data while it is needed Account status, tier, and timestamps
Via AppleSign in with Apple
The encrypted, single-use intermediate step for Apple sign-in on Android expires after no more than ten minutes. Stable Apple identifier for account matching Email address supplied by Apple, including a private relay address First and last name if Apple supplies them on first sign-in Account status, tier, and timestamps
Shared technical data
This is what exists on every sign-in path. We write down where it lives.
- Why
- User ID, account status, selected tier, and creation and update times. This opens the correct account and assigns access correctly.
- Why
- Expiry time and, in native apps, a securely stored rotating refresh code. This keeps you signed in and protects the session.
- Why
- The IP address and browser or app identifier of an active session support technical security, session checks, and abuse protection.
- Why
- The version and time of consent are stored so that the expressly required consent can be traced.
Your data in the app
We store this data only when you enter it in BodySeasons or choose a related setting. It is held in your personal cloud storage, separated by user and stored with server-side encryption.
- Why
- This supports the calendar, phases, relevant content, and personal analyses.
- What is stored
- Cycle start, phase lengths, completed cycles, goals, and reflections Selected cycle or contraception profile, life stage, and NFP setting Optionally date of birth or age group, zodiac sign, desire for children, breastfeeding, time since stopping hormonal contraception, number of births, stress level, and PCOS marker
- Why
- This supports your day view, statistics, comparisons, and features you choose.
- What is stored
- Bleeding, mood, feelings, physical wellbeing, and symptoms Temperature, cervical mucus, weight, and optional body measurements Sleep, energy, water, weather, nutrition, movement, and sport Sex tracking and free-text notes when you enter them
- Why
- This lets the app continue across devices as you configured it.
- What is stored
- Color theme, light or dark mode, tone, calendar design, language, and units Active tracking cards, order, and custom groups Notification and email reminder settings Onboarding, tour, in-app news, reading, and sorting preferences
Weather place: When you use a weather feature with a place, the app stores the place name, latitude, and longitude in your cloud storage. Coordinates are rounded to a 0.1 degree grid before being sent to MET Norway.
Additional data only when you use a feature
These areas do not apply to every user. They are created only when you deliberately use or enable the relevant feature.
ReportsPersonal analysis
What is stored: The encrypted analysis plus its ID, period, language, and creation time. Selected cycle and tracking data is processed during creation.
Why: So you can open the analysis again later. The analysis AI receives only a broad age group, not the exact date of birth.
ConversationsPersonal companions
What is stored: Messages between you and the selected companion, timestamps, conversation IDs, reminders, and short conversation summaries, each encrypted. Operational data without message content is also stored.
Why: So conversations with the selected companion can continue and reminders can be shown. Content is cleared after 30 days and no more than 50 conversations remain.
Web purchasePurchase through Stripe
What is stored: User ID, tier, purchase and time data, Stripe customer, checkout, payment, invoice, subscription and reference IDs, amount, currency, and refund or dispute status.
Why: So your tier, Lotus, refunds, and customer portal work. Card data is not stored on our servers.
VoluntaryVoluntary usage and success measurement
What is stored: Only after activation: Berlin calendar date, platform, number of app starts, and notification status. After a tagged campaign contact, also source, medium, campaign, optional content, provider, platform, and capture time.
Why: For product improvement and attribution of new registrations. The data is linked to your account, stored on self-managed systems for no more than 90 days, and can be withdrawn in settings.
FeedbackFeedback
What is stored: Subject, message, category, optional reply email address, and a shortened device or browser identifier.
Why: So we can handle bugs, requests, and questions.
TechnicalError log
What is stored: User ID, error class or code, time, and a technical message about cloud storage errors.
Why: So we can detect and fix synchronization errors.
Your notesFree text in analyses
What is stored: Only after express selection, a consent record with time, version, count, and cryptographic checksum. The note text itself is not included in this record.
Why: So confirmed notes may be included. Contact, address, account, and similarly identifying details are removed first.
LotusLotus and fair use of personal companions
What is stored: Lotus, redemption, used character units, weekly allowance, reservation status, technical input/output token counts and, where necessary, abuse protection. Logs contain no message content.
Why: So companion responses are charged fairly, are not charged twice, and costs and capacity can be monitored without content logging.
Store purchasePurchase through Apple App Store or Google Play
What is stored: For a store purchase: store, product ID, transaction or subscription reference, purchase status, and timestamps linked to your user ID.
Why: So a store purchase is assigned to your access and your Lotus. Payment data stays with the relevant store.
CoachCoach sharing
What is stored: Expressly selected tracking categories, time period, and permissions, encrypted for the coach relationship. Free text, names, contact, and location data are removed.
Why: So a connected coach sees only shared data. Nothing is transferred to a coach without permission.
ContactContact form
What is stored: Name, email address, subject, category, and message are forwarded to our contact mailbox. Cloudflare checks the Turnstile token with the IP address.
Why: So we can reply and protect the form from abuse.
What is additionally stored on your device
Selected data is held locally so sign-in and app operation work.
- Public account information such as user ID, email address, display name, tier, and consent status
- In the browser, sign-in secrets only for the current tab; in the native app, in protected device storage
- Local copies of cycle configuration, notifications, theme, language, tour, and news status
- For personal companions, local conversation display, drafts, unread prompts, and usage preference for no more than 30 days or 50 conversations
- A minimized first campaign attribution from a tagged web link, Google Play, or Apple Search Ads. Web data is stored locally only after consent; native store campaign data is retrieved only after the new explicit consent. The sanitized record may then be uploaded and linked to your account.
Signing out and deleting your account
When you sign out, the app removes its BodySeasons keys and sensitive temporary files from the device.
Clear boundaries
What does not happen in the standard profile. Not today, and not as a quiet option in the settings.
- No advertising ID or cross-device advertising profile
- No Google Ads, Meta Pixel, Facebook or Instagram advertising trackers, and no third-party analytics SDK
- No transfer of companion messages, companion prompts, or companion history to OpenRouter or another third-party model provider
- No automatic collection of cycle or health data outside your own entries
- No credit card or bank account data on our servers
- No complete AI prompts, analyses, or message content in our technical logs
- No personal details from the old mood field. This legacy field is not shared.
External processing when you use it
These services are not hidden permanent trackers in the app. They are contacted only for the relevant feature. Personal companions run separately through the private BodySeasons worker with a local llama.cpp model and local Lumi RAG on our own AI server.
How to read this overview
This page documents the storage and processing paths currently implemented in the code. It is deliberately written in everyday language and does not replace the Privacy Policy. Before publication, the content is checked against production configuration, provider retention periods, and the legal Privacy Policy.
Report a security vulnerability
If you have found a possible security vulnerability, use our confidential security contact or read the guidance in our security.txt. Do not send real health, password, or payment data.