Privacy Policy
Period or Not — iOS and Android
The short version. Period or Not has no accounts, no user database and no servers of its own. Everything you log — period dates, symptoms, diary notes, settings — is stored only on your phone. It is never uploaded, never sold, never shared, and never analysed by anyone. There is no advertising SDK and no behavioural analytics in the app.
Who is responsible
Period or Not is an independent app made and published by Antonija Pek ("we", "us"). For anything in this policy, contact hi@apek.me.
What the app stores on your device
All of the following is written to your phone's private app storage, which only Period or Not can read:
- Period and bleeding dates you log
- Symptoms, moods and diary entries you add
- Cycle settings and preferences (cycle length, reminder settings, theme, notification choices)
- A local record that you have made an in-app purchase, so paid features stay unlocked
- The date of your last backup, so the app can remind you
We cannot see any of it. There is no server on the other end to see it with.
What we collect about you
Nothing. We do not collect, receive, store or process your personal data. We do not have accounts, sign-ups, email lists tied to the app, advertising identifiers, crash-reporting SDKs, or product analytics. We do not build a profile of you, and we do not sell or share data with data brokers, advertisers or anyone else — we have nothing to sell.
Permissions the app asks for
- Calendar (optional). If you turn on calendar sync, the app writes your period events to a calendar on your device. That calendar is controlled by you and by your device's own calendar provider (for example Apple Calendar or Google Calendar). If that calendar syncs to a cloud account you have set up, your events go wherever that account goes — that part is governed by Apple's or Google's privacy policy, not ours. Leave calendar sync off if you do not want that.
- Notifications (optional). Reminders are scheduled locally on your device. No push server is involved and no notification content leaves your phone.
You can revoke either permission at any time in your device settings.
Third parties
The app is local-first, but three things sit outside it and are worth being explicit about:
- Apple App Store / Google Play. Purchases and restores are handled entirely by Apple or Google. They tell the app whether a purchase is valid; the app stores that answer locally. We never see your name, payment details or address. Their handling of your data is covered by Apple's and Google's own privacy policies.
- App updates (Expo / EAS Update). The app checks for app updates when it starts. That request reaches the update service run by Expo and necessarily reveals your IP address plus basic technical details such as app version, platform and OS version. It never includes any of your cycle, symptom or diary data.
- Support email. If you email hi@apek.me, we obviously see the message and your email address. We keep support mail only as long as it takes to help you and to keep a record of the issue, and we never add it to a marketing list.
There are no ad networks, trackers or attribution SDKs in the app.
Backups and exports
You can export your data to a file at any time. That export is a plain, unencrypted JSON file containing your full history, and it is protected only by your device's own encryption and by wherever you choose to put it. Once you share it — to iCloud, Google Drive, email, a messaging app — it is outside the app and outside our control, and the privacy policy of that service applies. Treat an export as sensitive health data, because that is exactly what it is. Import works the same way, in reverse: the file is read on your device only.
Deleting your data
The app has a reset option that wipes your logged data from the device. Deleting the app removes everything too. Because we never had a copy, there is nothing for us to delete on our side and no deletion request you need to send us. If you enabled calendar sync, remove the events from your calendar app separately — those live in your calendar, not in ours.
Security
Your data sits in the app's private storage area, protected by the operating system's sandbox and by device-level encryption (which is active whenever you have a passcode, Face ID or fingerprint unlock set up). No data is transmitted, so there is no transport to intercept and no database of ours to breach. Keeping a screen lock on your phone is the single most useful thing you can do to protect it.
Health data and legal requests
Menstrual data is sensitive. We designed the app so that we hold none of it: if we are ever served a subpoena, a court order or a government request for a user's cycle history, we have nothing to hand over, because it never existed on any system we control.
Children
The app is not directed at children under 13 (or under the minimum age in your country), and we do not knowingly collect data from them. Since the app collects no data at all, there is nothing for us to hold or remove.
Your rights (GDPR, CCPA and similar)
Rights of access, correction, deletion, portability and objection apply to data a company holds about you. We hold none — your data stays on your device, under your control, and the in-app export and reset give you portability and erasure directly. For the small amount of data involved in support email, Antonija Pek is the controller, the legal basis is legitimate interest in answering you, and you can ask us to delete that correspondence at any time. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we never have.
Changes to this policy
If the app ever changes in a way that affects this policy, we update this page and change the date at the top. If a change is significant — for example if any data ever started leaving your device — we would say so in the app before it took effect.
Contact
Antonija Pek — hi@apek.me
See also the Terms of Service.