Security & Trust

BodySeasons processes data in compliance with the GDPR. This page explains where your data lives, when selected service providers receive data, and which safeguards BodySeasons actually implements.

Last updated: 24 July 2026

Data protection

GDPR-compliant data processing

Processing in BodySeasons is built around clear purposes, data minimisation, appropriate legal bases, and traceable data flows. This includes requested AI reports: they are created only at the user's request, personal text is disabled by default and requires separate consent, identifiers are reduced through multiple stages, and completed reports are encrypted server-side at rest.

You can find more details about data processing, recipients, and safeguards in our Privacy Policy.

Privacy Policy

Where your data lives

You decide which connected features to use. We distinguish clearly between what remains local and what is transferred for those features.

Local browser storage

Cycle, tracking, and settings data is first stored locally in your browser. Data is transferred only when you use a connected feature such as cloud sync, an AI report, optional weather data, or coach sharing; the relevant data flows are described below.

Cloud synchronization

For accounts and anonymous backup profiles, BodySeasons synchronizes a compressed copy with the self-managed backend. Transport is protected by HTTPS/TLS and access is derived from the authenticated session. The cloud-save copy is encrypted server-side at rest with AES-256-GCM; the record is cryptographically bound to the account, project, and user identifier, and the key mechanism supports rotation. This is not end-to-end encryption.

Export & deletion

You can export your cycle data as a machine-readable file and use the provided controls to delete local data, cloud data, and your account.

Technical and organizational safeguards

Safeguards are applied to each specific data flow and are not presented as a blanket security promise.

Encrypted transport

Connections between the app, website, and our services are transported over HTTPS/TLS.

AI reports with a clear boundary

Only when you request an AI report is the selected structured cycle data sent to OpenRouter. Date of birth, birth year, exact age, and structured account identifiers are not included in the model prompt as profile or account fields. Your own texts are off by default and are processed only as individually reviewed copies after separate consent for that report. Multi-stage filtering is a best-effort safeguard, not a guarantee of complete anonymity. The completed report is encrypted at rest with AES-256-GCM in the BodySeasons middleware.

Granular coach sharing

You choose categories, free-text notes, and the time period separately. The backend stores only the resulting coach projection and encrypts it at rest with AES-256-GCM. After consent is withdrawn, the projection is no longer available to the coach and is removed from active storage.

No advertising or tracking SDKs

BodySeasons integrates no advertising SDKs and no third-party analytics for cross-app or cross-site tracking. Personal data is not sold for advertising.

Selected service providers

Service providers receive only the data needed for the function you request:

Stripe

Web purchases open Stripe-hosted Checkout. You enter card details directly with Stripe; they do not pass through BodySeasons and BodySeasons neither receives nor stores them. We internally reviewed Stripe's current PCI DSS service-provider attestation; it applies to Stripe as the payment provider.

Open-Meteo

Location coordinates are sent to Open-Meteo only when you enable the optional location-based weather feature.

Cloudflare: Edge, Turnstile & R2

Public web requests routed through Cloudflare pass through Cloudflare's edge for TLS termination, delivery, and WAF filtering before reaching our self-managed origin systems. For web registration and the contact form, Turnstile is loaded on demand only there and the short-lived verification token is then validated server-side. Available tutorial videos are loaded only when the relevant help is opened, via videos.bodyseasons.com from Cloudflare R2; this first triggers only a video-metadata request.

OpenRouter

OpenRouter receives selected structured cycle data only when you request an AI report. Optionally approved text copies are sent separately after prefiltering in the BodySeasons middleware and without separately attached account identifiers or session data to an isolated sanitizer, checked locally in the middleware afterwards, and only then combined with structured data. BodySeasons requests Zero Data Retention and disabled data collection during provider selection. This routing request is not a provider guarantee; selected content is transferred for processing to OpenRouter and the documented model providers selected there.

Report a vulnerability responsibly

Please report a suspected security vulnerability confidentially to [email protected] and give us reasonable time to investigate and remediate before publication.

  • Acknowledgement within three business days.
  • Initial status update within ten business days.
  • Helpful details include the affected URL or feature, reproducible steps, and potential impact. Do not send real cycle, health, password, or payment data.

How we review and frame security

Internal security review of 12 July 2026

On 12 July 2026, code, configuration, and controls were reviewed internally against selected applicable requirements from OWASP ASVS 5.0.0, OWASP MASVS, and BSI TR-03161 version 3.0, parts 1 and 3. Five identified high-risk findings were remediated and retested; medium and process findings remain documented. The review was internal and does not replace an independent penetration test.

Internal accessibility review of 15 July 2026

Representative BodySeasons and BodySeasons Coach views were reviewed internally against selected WCAG 2.2 requirements and published BIK test steps. Automated checks were supplemented with source, keyboard, and reduced-motion reviews; identified deviations are remediated or tracked. The review was internal and does not replace a BIK BITV test.

Transparency about our review scope

We describe the documented review scope and update it when relevant changes are made. You can find additional details about data flows and safeguards in our Privacy Policy.