Privacy notice
What we collect, why, and the choices you have.
Draft for legal review · effective at launch
What we collect
Account details (name, email, time zone, country), your diary answers, optional menopause context (every item offers “prefer not to say”), session bookings and notes, consent records, and payment status from our payment provider. We never store full card numbers.
Why
To run your program (service delivery), to send the reminders and calendar invites you have asked for, and to keep records the law requires. Analytics never include health, free-text or photo data.
Research
Research use of your diary is a separate, optional consent that is off by default and only offered once an ethics committee has approved the study. Research records are pseudonymised and exclude names, emails, free text and original photos. You can withdraw at any time.
Your rights
You can export your data at any time from your account, and request deletion. Deletion is completed within 30 days, except payment records we must keep for tax law and any adverse-event records we must keep for safety reporting. GDPR applies to EU residents and the California rules to California residents; the same controls serve both.
Security
Passwords are hashed with Argon2id, sessions use secure HTTP-only cookies, all traffic is encrypted, and every founder or guide access to sensitive records is logged.