Back to Emmenia

    Privacy Policy

    Last updated:

    This Privacy Policy explains how Emmenia ("Emmenia", "we", "us", "our") collects, uses, shares, stores and protects personal data when you use the Emmenia application, website and related services (the "Service"). Emmenia is a menstrual-health, pain-management and wellness tracking product. Because the Service is designed to record information about your body, most of what you enter is special-category health data and we treat it with a correspondingly high standard of care.

    This policy is maintained by the operator of Emmenia and is written to describe the app's actual data practices. Please read it together with our Terms of Service.

    1. Summary of key points

    • You control your health data. It is stored in your authenticated account and protected by row-level access rules so that, by default, only you can read your own records.
    • We do not sell your personal data, we do not share it with advertisers, and we do not use your health data for advertising or profiling for marketing purposes.
    • AI features are off until you switch them on. When enabled, only the data needed for the requested feature is sent to our AI processor.
    • You can export everything you have entered at any time, and you can permanently delete your account and health records from Settings.
    • Community and messaging features are visible to other people by design — only post what you are comfortable sharing.

    2. Who is responsible for your data

    The operator of the Emmenia service is the data controller for the personal data described in this policy. For any privacy question, request or complaint, contact us at privacy@emmenia.com. Where required by law, the operator will identify its registered legal entity, postal address and (if appointed) its data protection officer or EU/UK representative in response to a written request to that address.

    3. Data we collect

    3.1 Data you give us directly

    • Account data: email address, password credentials handled by our authentication provider, sign-in timestamps and session tokens.
    • Profile data: display name, first/last name, avatar, language, time zone and any optional profile details you add.
    • Cycle and reproductive-health data: period start and end dates, cycle length, flow intensity, ovulation and fertile-window entries, corrections you make to predicted dates, and cycle settings.
    • Symptom and wellbeing data: pain levels and locations, cramps, fatigue, mood, sleep, stress, energy, free-text notes, and any tags you apply to a calendar day.
    • Medication, remedy and care data: medication and supplement names, doses, times taken, duration, schedules, remedies and routines tried, and the relief or effectiveness ratings you record.
    • Nutrition and activity data: meals, hydration, supplements, exercise sessions and related logs.
    • Wellness-session data: breathing exercises, sound-therapy sessions, content you view, bookmark, complete or rate in the pain-relief and educational libraries.
    • Community and communication data: posts, comments, likes, group memberships, anonymous usernames, support requests, direct and support-room messages, and connections with other users or providers.
    • Care-team data: information you choose to share with a healthcare provider or partner through sharing features, provider consultations, appointments and care plans.
    • Support correspondence: messages you send to us and the contents of any bug or safety report.

    3.2 Data collected automatically or from your device

    • Technical data: IP address, browser and device type, operating system, and app version — used to operate the Service, apply rate limits and detect abuse.
    • Usage data: feature usage events, session duration, error and diagnostic logs used to keep the Service working.
    • Local storage on your device: preferences (theme, navigation layout, reminder settings, quiet hours, time zone), notification history and an offline cache of care logs held in your browser's storage/IndexedDB so the app works without a connection. This data stays on your device until it syncs or you clear it.
    • Push notification data: if you enable background reminders, we store the push endpoint your browser issues plus the associated encryption keys and user agent, solely to deliver your reminders.

    3.3 Data from third parties

    • Wearables and health devices: if you connect one, we receive the metrics you authorise (for example heart rate, heart-rate variability, sleep, steps or stress scores).
    • Authentication providers: if you sign in with a third-party identity provider, we receive your email address and basic profile fields from it.

    3.4 Data we do not want

    Please do not upload government identifiers, payment card numbers or third parties' medical records into free-text fields. We do not need them, and we will delete such data if we become aware of it.

    4. How and why we use your data

    PurposeData usedLegal basis (GDPR)
    Create and secure your account, authenticate youAccount, technicalContract; legitimate interests (security)
    Provide tracking, calendar, cycle forecasts, symptom trends and dashboardsCycle, symptom, care, profileContract; explicit consent for health data
    Generate insights and correlations (for example remedy effectiveness, fertile-window comparisons, phase analytics)Symptom, care, cycleExplicit consent
    Deliver reminders and notifications you configureReminder settings, push subscription, schedulesContract; consent for push
    Optional AI features (coach, predictions, voice, text-to-speech)Only the inputs needed for the requestExplicit consent (withdrawable)
    Community, messaging and peer-support featuresPosts, messages, anonymous usernameContract; consent
    Sharing with a provider or partner you chooseThe specific records you shareExplicit consent
    Safety, crisis detection and abuse prevention in community spacesMessage content, usage, technicalLegitimate interests; vital interests where life is at risk
    Maintain, debug, secure and improve the ServiceTechnical, usage, error logsLegitimate interests
    Respond to support requests and legal obligationsCorrespondence, accountContract; legal obligation

    Where we rely on consent, you may withdraw it at any time — by turning the relevant feature off, leaving a community space, revoking a share, or deleting the data. Withdrawal does not affect processing that already took place.

    5. Automated decision-making and AI

    Emmenia produces forecasts (such as your predicted next period, fertile window and ovulation day), pattern analyses and optional AI-generated coaching text. These are statistical or generative outputs, not medical determinations, and they produce no legal or similarly significant effect on you. They can be wrong, and you can override or correct any predicted date. AI features are disabled until you consent, and disabling them stops further AI processing of your data. We do not use your health data to train third-party foundation models.

    6. Sub-processors and recipients

    • Supabase — database, authentication, file storage and serverless functions that host the Service.
    • AI providers (OpenAI and the Lovable AI Gateway) — used only when you enable AI features, to process the specific inputs required for the response you requested.
    • Web push services — the push service operated by your browser vendor (for example Google, Mozilla or Apple) receives the encrypted notification payload needed to deliver a reminder to your device.
    • Hosting and delivery infrastructure — used to serve the application to your browser.

    We may also disclose data to professional advisers, or to authorities where we are legally required to do so, and to a successor entity in the event of a merger, acquisition or asset sale (in which case we will notify you and this policy will continue to apply until replaced). We do not sell personal data and we do not share it for cross-context behavioural advertising.

    7. International transfers

    Our providers may process data in countries outside your own, including the United States. Where data leaves the EEA, UK or Switzerland, transfers are made under appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) together with technical and organisational measures. You may request further information about these safeguards at privacy@emmenia.com.

    8. Security

    • Row-level security policies restrict every health table to the authenticated owner of the record.
    • Data is encrypted in transit with TLS and encrypted at rest by our hosting provider.
    • Sensitive message content in support and provider channels is additionally encrypted before storage.
    • Server-side rate limiting, input validation and role checks guard our APIs and functions.
    • Administrative access is limited to what is necessary to operate and support the Service.

    No method of transmission or storage is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and notify affected users without undue delay.

    9. Retention

    • Account and health records: kept while your account is active.
    • Account deletion: your profile and health records are deleted from the live database when you delete your account; residual copies in encrypted backups are overwritten on our provider's normal backup rotation (generally within 30 days).
    • Community posts and messages: deleting your account removes your posts, comments and messages; copies other users have saved or screenshotted are outside our control.
    • Push subscriptions: removed when you disable notifications, when the endpoint expires, or on account deletion.
    • Security and audit logs: retained for a limited period for fraud prevention and legal compliance, then deleted or aggregated.
    • Local device data: cleared when you sign out, clear site data, or uninstall the app.

    10. Your rights

    Depending on where you live, you may have the following rights:

    • Access and portability — export your data as JSON or CSV at any time from the Data Export screen.
    • Rectification — edit or correct any entry, including predicted dates, directly in the app.
    • Erasure — delete individual records, or your whole account, from Settings.
    • Restriction and objection — ask us to pause processing, or object to processing based on legitimate interests.
    • Withdraw consent — disable AI, notifications, wearable sync, sharing or community features at any time.
    • Non-discrimination — we will not degrade the Service because you exercised a privacy right.
    • Complain — you may lodge a complaint with your local data protection authority; we would appreciate the chance to resolve it first.

    We respond to verified requests within 30 days (extendable where the law allows). We may need to verify your identity via your registered email address before acting.

    You can submit a request using the form below — it is recorded in our compliance workflow and sent to our privacy team — or email privacy@emmenia.com.

    Privacy rights request
    30-day response

    Ask us to access, correct, export, restrict or delete your personal data. Requests are recorded and sent to privacy@emmenia.com.

    0/4000

    We use the details above only to verify and fulfil your request, and keep a record of it to show compliance. We respond within 30 days (extendable where the law allows).

    11. Reproductive-health data and legal requests

    We recognise that menstrual and reproductive-health data can be sensitive in ways that go beyond ordinary privacy concerns. We minimise what we store, keep it accessible only to you by default, and do not sell or monetise it. If we receive a legal demand for user data, we will require valid legal process, review the request for scope and validity, object where we have grounds, and — where we are legally permitted — notify the affected user before disclosing anything. If this concerns you, you can delete individual entries or your entire account at any time.

    12. Cookies and similar technologies

    Emmenia uses only the storage strictly necessary to run: authentication tokens, your preference settings and an offline cache. We do not use advertising cookies, third-party trackers, or cross-site analytics pixels. You can clear this storage through your browser at any time, though doing so signs you out and removes unsynced offline entries.

    Anything beyond strictly necessary storage is grouped into consent categories (preferences, analytics and marketing) and stays switched off until you allow it. On your first visit a consent banner asks for your choice, and no optional or third-party script loads before you decide. You can review or withdraw your choices at any time in Settings → Cookies & storage; withdrawal takes effect immediately for future page loads.

    13. Children

    The Service is not directed at children under 13 (or under 16 where local law sets a higher age for consent to information-society services). If you are below that age, you may use Emmenia only with the involvement and consent of a parent or guardian where required. If we learn that we have collected data from a child without a required consent, we will delete it promptly.

    14. Region-specific disclosures

    EEA / UK

    Health data is processed under Article 9(2)(a) GDPR (explicit consent) unless another exception applies. You have the rights listed in section 10 and may complain to your supervisory authority.

    California

    We collect the categories described in section 3, for the purposes in section 4, from the sources in section 3. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information beyond the purposes permitted by section 7027(m) of the CCPA regulations. You may exercise access, deletion, correction and non-discrimination rights as described above.

    United States — health privacy

    Emmenia is a consumer wellness product. Unless you are using it through a covered healthcare provider, we are not a HIPAA covered entity or business associate, and the data you enter is protected by this policy and applicable consumer health privacy laws (such as the Washington My Health My Data Act) rather than by HIPAA.

    15. Changes to this policy

    We may update this policy as the Service evolves. The "last updated" date above always reflects the current version. For material changes affecting how we use health data, we will give notice in the app and, where the law requires it, ask for fresh consent before the change takes effect.

    16. Contact

    Privacy questions, rights requests or complaints: privacy@emmenia.com. Security vulnerability reports: security@emmenia.com. General support: support@emmenia.com.

    This policy describes the application's actual data practices in plain language. It is not legal advice; the operator should have it reviewed by qualified counsel for its jurisdiction and confirm its registered entity details before commercial launch.