Back to Emmenia

    Trust & safety

    Your data is your body. We keep it that way.

    Privacy, security and evidence standards for the most sensitive data you'll ever track.

    Last updated:

    Six promises we keep

    Encrypted sensitive entries

    Period symptoms, notes and intimate health logs are encrypted at rest with AES-256-GCM. Routine account metadata is protected by Supabase Row-Level Security.

    Anonymous by default in community

    Community handles are deterministically pseudonymised per room so your posts cannot be linked back to your profile or across conversations.

    Private media, signed URLs only

    Wellness-media uploads live in a private bucket. They are never publicly listable and are only served through time-limited signed URLs.

    One-tap export and deletion

    Request a full GDPR data export or permanently delete your account and all health logs from Settings. No email gatekeeping.

    No ads, no data brokers

    We do not sell, rent or share identifiable health data with advertisers, insurers, employers or data brokers. Research insights are aggregated and de-identified.

    Clinician reports are yours to share

    PDF conversation packs are generated on demand and downloaded by you. We do not send them to any provider unless you choose to.

    Questions about privacy, evidence and reports

    Plain-language answers on how we handle your health information, grade remedies, and keep clinician reports under your control.

    We store only what you actively log: period dates, symptom scores (cramps, mood, flow, fatigue, sleep), care-plan check-ins, medication and remedy doses, optional wearable imports, and any notes you choose to add. We do not scrape contacts, location, or browsing behaviour.

    Sensitive entries are encrypted with AES-256-GCM before being stored. Database access is gated by Row-Level Security policies so each row is only readable by its owning account. All database traffic is encrypted in transit, and media uploads are served through signed URLs that expire quickly.

    By design, only you. Row-Level Security means the app only ever returns your own records to you, and staff do not browse individual health logs in normal operations. A very small number of administrators can reach the database for maintenance, security and incident response under strict, audited controls — routine work never relies on that access. If you use partner sharing, you explicitly choose what to share and with whom; the recipient gets a read-only view, not edit access.

    Community features assign a random, consistent pseudonym per room using a one-way derivation from your account. Other members cannot see your email, real name or profile photo, and the same account gets a different handle in each room to prevent cross-room linking.

    Clinician reports are PDF or conversation summaries generated from your own logs — cycle history, symptom trends, medication and remedy tracking, and any screening scores. They are created on demand, downloaded by you, and never transmitted to a provider unless you personally send them. Reports include educational context, not a diagnosis.

    Each Relief Lab protocol carries an A/B/C evidence grade based on published research for menstrual pain or closely related outcomes. 'A' means consistent support from randomised trials; 'B' means promising but mixed or smaller trials; 'C' means mechanistic rationale or traditional use with limited clinical data. We do not invent study IDs or overstate findings.

    My Evidence is your personal n-of-1 experiment. It compares symptom scores on days you used a remedy with days you did not, then ranks what appears to help you most. Rankings include confidence gates so thin data is never overstated as certainty. You can export the results into your clinician report.

    No. Emmenia is a wellness and education tool, not a medical device. Condition pathways (heavy bleeding, PMDD diary, endometriosis red flags) are conversation starters to bring to a clinician. They do not replace diagnosis or treatment advice.

    We keep your data for as long as your account exists so you can view long-term trends. If you delete your account, all personal health data and generated reports are permanently removed from our systems within 30 days, except where we are legally required to retain minimal records. The full category-by-category schedule lives in our cancellation and data retention policy.Read the cancellation & data retention policy

    Yes. Settings includes a one-tap data export that packages your logs into a machine-readable file. You can also submit a GDPR data-subject request through the Privacy Center; we respond within 30 days.

    We do not share identifiable data for research. Any research insights we develop are aggregated and de-identified. A future opt-in outcomes study is planned; when it launches it will require separate, explicit consent and will never enrol you automatically.

    Email security@emmenia.com with details. We investigate all reports and will coordinate disclosure responsibly. Please do not include personal health information in your report.

    For the full legal wording, data-controller details and terms of use, see these pages.