periEd
Back
Your data

Privacy Policy.

Last updated May 2, 2026 · Effective May 2, 2026

This Privacy Policy explains what personal information periEd (“periEd,” “we,” “us”) collects, why we collect it, how we use and share it, and the rights you have over it. We treat your health information with the care it deserves. We do not sell it, ever.

periEd is operated by [LEGAL ENTITY NAME], a [STATE] [LLC/CORPORATION] based in the United States. By using the Service, you agree to this Privacy Policy and our Terms of Service.

The 30-second version. We collect what you voluntarily tell us (profile, symptoms, periods, meds, labs, notes, conversations) plus your sign-in email and basic technical data. We use it solely to provide periEd to you. We never sell it. We never share it with advertisers, employers, insurers, or data brokers. We use a small number of service providers (listed below) to run the app. You can export everything we have on you at any time, and you can delete your account and all data permanently with one click.

1. Who this applies to

This Privacy Policy applies to anyone who uses the Service, whether you are in the United States or elsewhere. If you are in the European Economic Area, the United Kingdom, or Switzerland, additional rights apply to you under the GDPR — see Section 11.

The Service is intended for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe a minor has used the Service, contact us at [[email protected]] and we will delete the account.

2. What we collect

We collect only what we need to provide the Service. Categories of information:

2.1 Account & contact information

  • Email address — used to send your one-time sign-in link and transactional emails (account changes, billing receipts).
  • Display name — if you choose to enter one.

2.2 Health and lifestyle information (sensitive)

The information below is “consumer health data” under the Washington My Health My Data Act (MHMDA), “medical information” under California's CMIA, and “special category data” under the GDPR where applicable. We treat all of it as sensitive.

  • Profile and history — date of birth, menopause stage, height and weight, ethnicity, smoking and alcohol use, surgical history, family medical history, health-related goals, allergies, practitioner status.
  • Reproductive and cycle data — period start dates, flow intensity, cycle regularity, and related notes.
  • Symptoms and daily logs — symptom entries, severity, mood, sleep, free-text notes, and any other information you log.
  • Medications — medications you take (including HRT details), dose, route, schedule, and notes.
  • Lab results — values, units, reference ranges, lab name, and free-text notes you record.
  • Conditions — medical conditions you tell us you have or have had.
  • AI conversation history — the questions you ask Peri (our AI) and the responses generated for you.

2.3 Payment information

If you subscribe to Pro, our payment processor Stripe, Inc. collects your name, billing address, and payment details directly. We do not see or store your full card number. We receive limited information back from Stripe to associate your subscription with your account: a Stripe customer ID, subscription status, plan, and renewal date.

2.4 Technical and usage information

  • Authentication and session metadata — timestamps, session tokens, the email-link verification token (which is single-use and short-lived).
  • Server logs — IP address, browser/user agent, request paths, and timestamps. We retain these for a limited period for security and abuse prevention.
  • Cookies and similar technologies — we use a small number of strictly necessary cookies to keep you signed in and to remember preferences. We do not use third-party advertising cookies.

2.5 What we do not collect

  • We do not collect precise location data. We do not use location-based marketing or geofencing of any kind.
  • We do not collect data from third parties about you (data brokers, social-media graphs, etc.).
  • We do not require, request, or store any government identifier.

3. How we use your information

We use the information we collect only for these purposes:

  • Provide and personalize the Service — store your data so it is there when you come back; surface patterns, education, and recommendations based on your profile and recent activity; generate AI responses tailored to your context.
  • Authenticate and secure your account — issue magic links, prevent unauthorized access, detect abuse.
  • Process payments — provision and renew your subscription, send receipts, handle failed payments.
  • Communicate with you — transactional messages (sign-in links, billing notifications, account changes, policy updates) and, only if you opt in, occasional product updates.
  • Comply with law and protect rights — meet legal obligations and respond to lawful requests; defend or assert rights as needed.

We do not use your data to train AI models. Our AI subprocessors are contractually prohibited from training on it either.

We do not use your data for advertising, profiling for marketing purposes, or selling to third parties.

4. Legal bases for processing (GDPR)

If you are in the EEA, the UK, or Switzerland, our legal bases for processing are:

  • Performance of a contract — to deliver the Service you requested.
  • Explicit consent — specifically for processing health data (special category data under GDPR Article 9(2)(a)).
  • Legitimate interests — security, abuse prevention, and improving the Service in non-personal ways (aggregated, never individual-level).
  • Legal obligation — tax, accounting, legal requests.

You can withdraw your consent at any time by deleting your account.

5. Who we share information with

We do not sell your personal information. We do not share it with advertisers, data brokers, employers, insurers, or family members. We use a small number of vetted service providers (“subprocessors”) to run the Service, each contractually bound to use your data only as we direct:

  • Railway Corporation — cloud hosting and managed PostgreSQL database (United States). Stores your account and Content.
  • Anthropic, PBC — AI provider (United States). Receives the prompts and contextual data needed to generate AI responses for you. Anthropic is contractually prohibited from training on your data.
  • Resend, Inc. — transactional email (United States). Receives your email address and the contents of transactional messages we send to you.
  • Stripe, Inc. — payment processing (United States). Receives the payment information you provide to subscribe; we never see your full card number.

We may also disclose information:

  • To comply with law — when required by a valid subpoena, court order, or other legal process. We will challenge requests we believe are overbroad or improper, and will notify you where legally permissible.
  • To protect rights and safety — when we reasonably believe disclosure is necessary to prevent imminent harm or to protect our or another person's rights.
  • In a business transition — if we are acquired or merge with another company, your data may transfer to the successor, subject to the same protections in this Policy. We will notify you before any such transfer.

6. Security

We use technical and organizational safeguards to protect your data:

  • Encryption in transit — all connections to the Service use HTTPS/TLS.
  • Encryption at rest — our database is encrypted at rest by our cloud provider.
  • Access controls — production data is accessible only by a small number of authorized operators on a need-to-know basis.
  • Backups — encrypted, retained on a limited schedule, and used only for recovery.
  • Vendor due diligence — we sign data processing agreements with our subprocessors.

No security is perfect. We cannot guarantee absolute security, but we will tell you promptly if we ever experience a breach affecting your data, in accordance with applicable laws (including the FTC Health Breach Notification Rule and state breach laws).

7. Data retention

We keep your account and Content for as long as you have an active account. When you delete your account, we permanently delete your data within 30 days, except where we are legally required to retain it (for example, payment records for tax purposes, which we retain for the legally required period and then delete).

Server logs are retained for up to 90 days. Backups are retained for up to 30 days and rotate out of existence on that schedule.

8. Your rights and how to exercise them

You have the rights below. To exercise any of them, use the self-serve tools in Settings → Your data or email us at [[email protected]]. We will respond within 45 days (extendable by 45 more if needed).

  • Access & portability. Download a complete copy of your data as JSON anytime via Settings → Your data → Export your data.
  • Correction. Edit your profile and tracking data anytime in Settings.
  • Deletion. Permanently delete your account and data anytime via Settings → Your data → Delete your account.
  • Withdraw consent. You can withdraw your consent to processing at any time by deleting your account.
  • Opt out of profiling and sale. We do not sell your data and we do not engage in profiling that produces legal or similarly significant effects. There is no need to opt out because these activities do not happen.
  • Non-discrimination. We will not discriminate against you for exercising any of your rights.

You may also have the right to lodge a complaint with your local data protection authority (in the EEA/UK), or with your state attorney general (in the US).

9. State-specific notices (United States)

9.1 Washington (My Health My Data Act)

For Washington consumers (and others whose health data is processed within Washington): your “consumer health data” under MHMDA includes everything in Section 2.2 above. We collect this data only with your consent (given when you create an account and provide it). We do not sell consumer health data, and we do not collect or share precise geolocation information. You can confirm collection, withdraw consent, and delete your data using the tools described in Section 8. If you believe we have not honored your rights, you may also email [[email protected]] or contact the Washington State Attorney General.

9.2 California (CCPA/CPRA, CMIA)

For California residents: in the past 12 months, we have collected the categories of information described in Section 2 for the purposes described in Section 3, and disclosed it only to the subprocessors described in Section 5. We have not sold or shared your personal information for cross-context behavioral advertising.

You have the right to know what we collect, request deletion, correct inaccurate information, and limit the use of sensitive personal information. We treat health data as sensitive and process it only as described above. Use the tools in Section 8 or email [[email protected]]. You may designate an authorized agent to make a request on your behalf; we may require verification.

9.3 Other states (Connecticut, Colorado, Texas, Virginia, Oregon, etc.)

You have rights similar to those above (access, correction, deletion, opt-out of sale and certain processing). Use the tools in Section 8 or email [[email protected]]. You may appeal a denied request by replying to our response.

10. International transfers

We host the Service in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. Where required, we use lawful transfer mechanisms (such as Standard Contractual Clauses for EEA/UK transfers).

11. Additional rights for EEA, UK, and Switzerland users

In addition to the rights in Section 8, you have the right under the GDPR/UK GDPR to: object to processing based on legitimate interests; restrict processing in certain cases; lodge a complaint with your supervisory authority; and not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (we do not engage in such decision-making).

12. AI-specific notice

When you interact with the Ask Peri or article-generation features, we send relevant context from your profile and recent activity to our AI subprocessor (Anthropic) so the response can be personalized. Anthropic is contractually prohibited from training on your data and from retaining it beyond what is required for safety and abuse prevention. You can avoid sending health context to the AI by not using these features.

13. Cookies

We use a minimal set of strictly necessary cookies: an authentication cookie that keeps you signed in, and a session cookie that holds CSRF protection. We do not use advertising cookies, third-party tracking, or fingerprinting. If we ever add analytics, we will use a privacy-respecting tool that does not link to advertising networks, and we will update this Policy before doing so.

14. Changes to this Policy

We may update this Privacy Policy from time to time. If we make a material change, we will notify you by email or through an in-app notice at least 14 days before it takes effect (or as required by law). Your continued use after the effective date constitutes acceptance.

15. Contact

For privacy questions or to exercise your rights, contact us at [[email protected]]. For everything else, [[email protected]]. Postal mail: [POSTAL ADDRESS].

Last updated May 2, 2026. Effective May 2, 2026.


Terms of ServicePrivacy PolicyMedical DisclaimerHome