Privacy Policy
Last updated: October 10, 2026
1. Controller
Stefan Renzler, Donaueschingenstraße 28/45-46, 1200 Vienna, Austria — stubensport@gmail.com — is the controller within the meaning of the General Data Protection Regulation (GDPR) for processing personal data as part of Ovulyx.
2. What data we process and why
Cycle and health data are a "special category of personal data" under Art. 9 GDPR. We process it exclusively with your explicit consent — at account creation, you confirm this via its own, separately worded checkbox (distinct from accepting the Terms), specifically referring to processing cycle and health data under Art. 9 GDPR, without which an account cannot technically be created. Revocable at any time by deleting your account.
| Type of data | Purpose | Legal basis |
|---|---|---|
| Email address, password (hashed) | Account creation, login, password reset | Art. 6(1)(b) GDPR (contract) |
| Display name (optional, can be set in settings) | Shown to your connected partner (e.g. "New reaction from …") | Art. 6(1)(b) GDPR (contract) |
| Period data (incl. optional period end, flow intensity), diary entries (mood, energy, symptoms, basal temperature, notes) | Core function: cycle tracking & forecasting | Art. 9(2)(a) GDPR (explicit consent) |
| Period data from an optional Apple Health import (export.xml, menstrual entries only) | Convenient data import during initial setup, at your own request | Art. 9(2)(a) GDPR (explicit consent, you actively choose the file) |
| Sharing settings, shared summary & reactions between you and your partner (e.g. "Thanks for letting me know") | Partner-sharing feature, if enabled | Art. 9(2)(a) GDPR (consent) |
| Your device's push-notification endpoint & encryption keys (if enabled) | Reminders (period approaching, diary entry) and partner reactions as notifications | Art. 6(1)(a) GDPR (consent when enabled) |
| Payment data (card details never touch our own systems) | Subscription billing after the trial period ends | Art. 6(1)(b) GDPR (contract) |
| Subscription status and purchase ID for purchases via the App Store or Google Play (purchase history, via RevenueCat) | Unlocking and managing your subscription | Art. 6(1)(b) GDPR (contract) |
| IP address (briefly, to prevent abuse) | Rate limiting against brute-force attacks | Art. 6(1)(f) GDPR (legitimate interest) |
3. Advertising (non-personalized only) & no sale of data
Ovulyx shows ads via Google AdMob (mobile app) and Google AdSense (web app) — deliberately non-personalized only, with no behavioral or interest-based targeting, precisely because Ovulyx processes special categories of personal data (health data). This may involve device/browser-level identifiers (e.g. an advertising ID, your IP address and the approximate location derived from it), information about your interaction with ads (e.g. impressions and clicks) and crash and diagnostic data from the ad SDK being sent to Google — strictly to serve ads, measure their delivery and prevent fraud, not to track you across apps or websites. No cycle, health, or other diary data is ever shared with ad networks. No Google Analytics, no Meta Pixel, or similar. We do not sell or rent out personal data. No cookies are set for analytics purposes — technically necessary session data (login token) is stored locally on your device, not as a tracking cookie.
4. Who else has access to data (processors)
To operate Ovulyx, we use the following service providers, who process data solely on our behalf:
| Provider | Purpose | Location of processing |
|---|---|---|
| Cloudflare, Inc. | App hosting, database (Cloudflare D1), server-side logic (Workers) | Western Europe region (WEUR) |
| Stripe Payments Europe, Ltd. | Payment processing for subscriptions | EU / USA (Stripe is certified under EU Standard Contractual Clauses) |
| Resend | Sending transactional emails (e.g. password reset) | USA (Standard Contractual Clauses) |
| Your browser's push delivery service (e.g. Google FCM for Chrome, Mozilla Push Service for Firefox) | Delivering push notifications — the content is end-to-end encrypted (RFC 8291); the service only sees that some message should be delivered to your device, not its content | depends on the respective provider, outside our control, only relevant if you enable notifications |
| Expo (650 Industries, Inc.) | Delivering push notifications to the mobile app (internally relays to the same platform push services listed above) — only relevant if you enable notifications | USA |
| RevenueCat, Inc. | Reconciling and managing App Store/Play Store subscription purchases (subscription status, purchase identifier) — only relevant for subscriptions bought directly through the App Store/Play Store | USA |
| Google Ireland Limited (Google AdMob) | Ad serving in the mobile app, non-personalized only (see section 3) | EU/USA, under Google's Standard Contractual Clauses |
| Google Ireland Limited (Google AdSense) | Ad serving in the web app, non-personalized only (see section 3) | EU/USA, under Google's Standard Contractual Clauses |
5. Partner sharing
If you enable partner sharing, you decide — and can revoke at any time — what information a person you've invited can see: period calendar, symptoms (except any you've hidden), your "what helps"/"what to avoid" notes (only individually shared entries), and — your choice — either your day-by-day mood/energy or only the phase average. Free-text notes and your basal temperature are never shared with the connected person. Connected partners can additionally send you a short, fixed reaction (e.g. "Thanks for letting me know") — these reactions are stored for as long as the respective connection exists, or until either account is deleted.
A connected partner can additionally keep their own cycle-independent list "What's good for me" ("what helps"/"what to avoid" entries, grouped by situation). An entry is only passed on to you if the partner explicitly shares it; everything else stays private. When you open that list or the matching row under their daily mood, the partner is shown only the time you last looked ("saw it today 14:05") — not which entries you read. This indicator cannot be turned off and is reset when the connection is removed or re-established.
6. Retention period
Your data is stored for as long as your account exists. If you delete your account through the app, all associated data (cycle data, diary entries, sharing settings, partner connections) is irrevocably deleted. An active Stripe subscription is automatically cancelled when the account is deleted; a subscription purchased through Google Play must be cancelled by you in Google Play. Invoices and payment records are retained as required by statutory retention obligations. Details: Delete account.
7. Your rights
- Access & data portability — you can download your complete data set as a JSON file at any time under "Settings → Account → Export data".
- Deletion — possible at any time yourself under "Settings → Account → Permanently delete account", with no waiting period, or by email (see Delete account).
- Rectification — every entry can be changed directly in the app.
- Objection/withdrawal of consent — at any time, by disabling individual features (e.g. partner sharing) or deleting your account.
- Complaint to a supervisory authority — in Austria, the Datenschutzbehörde (dsb.gv.at), or the authority responsible for your place of residence.
8. Changes to this policy
We update this policy whenever processing changes (e.g. new features, new service providers). The current version is always available at this address.