1. Summary
In short: your cycle, period, symptom and profile data is stored only on your device and is never uploaded to our servers. Our cloud (Google Firebase) knows only your account identity and relays end-to-end encrypted partner stickers that we cannot read, deleting each one as soon as your partner's phone receives it. Invite codes and private encryption keys stay on your devices; only public keys pass briefly through our cloud when you pair. We show no ads, use no analytics or tracking SDKs, and never sell your data.
This Privacy Policy explains how the ourRegla mobile app ("ourRegla", "the app") and this website handle personal data. It applies to all users worldwide and includes specific information for the European Economic Area and the United Kingdom (GDPR) and for Türkiye (Law No. 6698 on the Protection of Personal Data, "KVKK").
2. Who we are
The data controller (veri sorumlusu) is Ayhan Şentürk, an individual developer based in Türkiye ("we", "us"). You can reach us at privacy@ourregla.com.
3. Data stored only on your device
The following data is created by you and kept in a local database (Hive) inside the app on your phone. It is never uploaded to our servers and we have no access to it:
- Cycle history, period start/end dates, cycle and period length settings;
- Symptoms, mood, energy and other daily logs;
- Fertility window and ovulation predictions, which are calculated on the device;
- Profile details (e.g. name or nickname, age group) including daughter profiles managed by a parent;
- Partner connection state, invite code, your partner's public key, sticker inbox/outbox and your private encryption key;
- App settings such as language, reminders and your Premium entitlement status.
Because this data stays on the device, it is removed when you delete your account in the app or uninstall the app. We cannot restore it for you. Your phone's operating system may include app data in device backups that you control (for example, device-to-device transfer); such backups are governed by your settings with Apple or Google, not by us.
4. Data processed in our cloud
We use Google Firebase (project ourregla-c6c55) for a small number of strictly necessary functions:
| Data | Purpose | Where |
|---|---|---|
| Account identity: email address, user ID, the display name you enter at sign-up, sign-in timestamps and password (stored by Firebase as a secure hash, never visible to us) | Create your account, sign you in, keep your account secure | Firebase Authentication |
| Pairing invites: your user ID, your public encryption key, an authentication code (HMAC), creation and expiry time; once your partner accepts, also their user ID, public key, authentication code and acceptance time. The document is named by a one-way hash of the invite code; the code itself is never uploaded | Exchange public keys so your two phones can pair securely | Cloud Firestore (partner_invites) |
| Encrypted relay packages: the ciphertext of a sticker (or of a “disconnected” notice) plus sender and recipient user IDs, a pairing ID derived from the invite, message type, timestamp and a delivered flag | Deliver stickers you send to your partner's device | Cloud Firestore (partner_relay) |
| Technical connection data (e.g. IP address, device/OS type, timestamps) | Processed automatically by Google to provide the service, security and abuse prevention | Firebase infrastructure |
| Push notification token, if registered: the token, platform (Android/iOS) and last update time | Wake your device to receive a partner package | Cloud Firestore (users/{your ID}/fcmTokens), Firebase Cloud Messaging |
No cycle, period, symptom, fertility or profile health data is written to Firebase in readable form. The app does not store any fields in your users/{your ID} document itself; your profile and settings stay on your device. Invite codes and private encryption keys are not stored in Cloud Firestore; public keys are stored there only temporarily, in a pairing invite (see above).
5. Partner sharing and end-to-end encryption
Partner mode is optional and free. When you invite a partner, the app creates an invite code and an X25519 key pair on your phone; you pass the invite code to your partner yourself (for example, by message). To pair the two phones, the app stores a short-lived pairing invite in Cloud Firestore with your user ID and public key, named by a one-way hash of the code. Your partner's app finds it with the code, checks it with a secret derived from the code (so nobody without the code can swap in a different key) and adds their user ID and public key. Your phone verifies that answer the same way and then deletes the invite. Invites expire after 24 hours. The invite code and your private key never leave your devices. What you send to your partner — currently stickers — is encrypted on your device with AES-GCM before it leaves your phone. Your sharing purpose (trying to conceive, avoiding pregnancy or neutral) only changes the tone of stickers and reminders on your devices.
- The encrypted package is placed in a relay (Cloud Firestore) only so your partner's device can collect it. The relay contains ciphertext only; we do not have the keys and cannot read it.
- As soon as your partner's phone receives and opens a package, it deletes it from the relay (if deletion fails, it marks it as delivered instead). Any packages still waiting are deleted when you or your partner disconnect (Partner mode → Disconnect partner) or delete the account. When you disconnect, your partner's phone is sent an encrypted notice so it unpairs too.
- Your partner sees an observer view of what you decided to share. Partner mode is not a full chat. You can stop sharing or disconnect at any time.
- Once your partner's device has decrypted information, it is stored on their device. Please share only with people you trust.
6. Notifications
Reminders (such as upcoming periods or fertile days) are scheduled as local notifications on your device; their content is not sent to us. To deliver partner packages, the app may use a push notification token from Google (Firebase Cloud Messaging) or Apple. Such tokens identify the app installation, not your health data, and are deleted when you delete your account. You can turn notifications off in your device settings.
7. Payments
Premium subscriptions ($4.99/month or $29.99/year, with a 7-day free trial on the yearly plan; local prices may vary) are sold and billed by Google Play or the Apple App Store. They process your payment details under their own privacy policies. We never receive your card details. The app receives a purchase confirmation from the store to unlock Premium on your device.
8. Support emails
If you email us, we process your email address and the content of your message to answer you and handle your request (for example, account deletion or data rights requests). Please do not send us health details that are not necessary for your request.
9. What we don't do
- No advertising and no advertising identifiers.
- No analytics, attribution or crash-tracking SDKs from third parties in the app.
- No selling, renting or sharing of your personal data for marketing.
- No profiling or automated decision-making with legal or similar effects.
- This website sets no cookies and uses no trackers; fonts are self-hosted. Our hosting provider (Firebase Hosting) processes standard server logs such as IP addresses to deliver the site securely.
10. Service providers and international transfers
We use Google LLC / Google Ireland Limited (Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging, Firebase Hosting) as a data processor, and Google and Apple as independent app stores for distribution and billing. Google may process data on servers outside your country, including in the United States and the EU. Where required, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses and Google's data processing terms, and, for transfers from Türkiye, in accordance with Article 9 of KVKK. We may also disclose data if required by law or to protect rights and safety.
11. Retention
- On-device data: until you delete it, delete your account in the app, or uninstall the app.
- Account identity: until you delete your account.
- Invite codes, pairing details and private keys: only on your devices, until you disconnect your partner, delete your account or uninstall the app.
- Pairing invites: until pairing completes (the inviting phone then deletes the invite). Invites expire after 24 hours; an unused invite is deleted by the inviting phone the next time the app runs after expiry, or when you disconnect or delete your account.
- Encrypted relay packages: until your partner's phone receives them — it deletes them straight away. Packages not yet received are deleted when the sender or the recipient disconnects or deletes their account (they remain ciphertext we cannot read).
- Push notification tokens: until you delete your account.
- Support emails: as long as needed to handle your request and to meet legal obligations, and then deleted.
- Purchase records: kept by Google Play or the App Store under their policies and applicable tax laws.
12. Security
We use encryption in transit (TLS), end-to-end encryption for partner sharing, Firebase security rules that restrict access to relay documents and pairing invites, and a data-minimising design. Your private key never leaves your device. No system is perfectly secure; please protect your phone with a screen lock.
13. Children and daughter profiles
ourRegla accounts are intended for adults. A parent or legal guardian may create a daughter profile on their own device to help a child learn about her cycle. Daughter profiles are managed by the parent, are stored only on the device, show calm, age-appropriate content only, and have partner features and flirty sticker packs disabled. We do not knowingly collect personal data from children through accounts. If you believe a child has created an account, contact us and we will delete it. Flirty sticker packs are intended for adults aged 18+.
14. Your choices and rights
- Delete your account in the app (Settings → Account → Delete account) or by email. See Account & data deletion.
- Stop partner sharing at any time with Partner mode → Disconnect partner.
- Access, correct or export your account data by contacting us. Your on-device data is already in your hands.
We will respond to requests within the time limits set by applicable law (generally within 30 days). We may need to verify that the request comes from the account holder.
15. Information for users in the EEA and UK (GDPR)
Legal bases. We process account identity, pairing invites (user IDs and public keys), encrypted relay packages (with their sender, recipient and pairing IDs) and push tokens because they are necessary to provide the service you request (Art. 6(1)(b) GDPR); technical data for security and abuse prevention on the basis of our legitimate interests (Art. 6(1)(f)); support correspondence on the basis of contract or legitimate interest; and data required to meet legal obligations under Art. 6(1)(c).
Health data. Health data (Art. 9 GDPR) is processed only on your device, under your control. Information you choose to share with a partner is end-to-end encrypted at your explicit request; we cannot access its content.
Your rights. You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interests, and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local data protection supervisory authority.
16. Information for users in Türkiye (KVKK disclosure)
This section serves as our disclosure notice (aydınlatma metni) under Article 10 of KVKK.
- Data controller: Ayhan Şentürk, Türkiye — privacy@ourregla.com.
- Data processed and purposes: identity/contact data (email, display name), account security data and transaction security data (technical connection data) to create and secure your account; technical identifiers (user ID, pairing ID, public encryption keys, push token) and end-to-end encrypted relay packages to deliver the stickers you send to your partner; customer transaction data (support requests) to answer you.
- Legal grounds (Art. 5): necessity for the establishment and performance of a contract (Art. 5(2)(c)), compliance with legal obligations (Art. 5(2)(ç)), and our legitimate interests provided they do not harm your fundamental rights (Art. 5(2)(f)).
- Special categories (Art. 6): health data is not transferred to or processed on our servers; it remains on your device. Content you share with your partner is end-to-end encrypted at your instruction and cannot be accessed by us.
- Method of collection: electronically, through the app and email.
- Transfers: to our service provider Google (servers may be located abroad) for hosting and authentication, in accordance with Article 9 of KVKK, including standard contractual clauses where required; and to authorities where legally required.
- Your rights (Art. 11): to learn whether your personal data is processed and request information; learn the purpose and whether it is used accordingly; know the third parties to whom it is transferred in Türkiye or abroad; request correction of incomplete or inaccurate data; request deletion or destruction under Article 7; request notification of such operations to third parties; object to results arising against you exclusively through automated analysis; and claim compensation for damages arising from unlawful processing.
- How to apply: send your request in writing or by email to privacy@ourregla.com in line with the Communiqué on the Procedures and Principles of Application to the Data Controller. We will respond free of charge within 30 days at the latest. You may also complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
17. Medical disclaimer
ourRegla is not a medical device. Predictions are estimates and are not contraception or medical advice. See our Terms of Use.
18. Changes to this policy
We may update this policy, for example when we add features. We will update the date above and, for significant changes, inform you in the app before they take effect.
19. Contact
Privacy questions or requests: privacy@ourregla.com
General support: support@ourregla.com
Controller: Ayhan Şentürk, Türkiye
This policy is available in English and Turkish. In case of discrepancy for users in Türkiye, the Turkish version prevails.