Hertracker Privacy Policy

Last updated Feb 5, 2025

1. What data we collect and why

We collect different types of data to ensure our app functions effectively and provides personalized experiences for users. All data is securely stored on Google Cloud Storage servers, configured to comply with applicable data protection regulations, including the General Data Protection Regulation (GDPR)

Account Creation Data: To create and manage your account, we require basic personal details like your first name, last name, email address, and date of birth. This data helps verify your identity and provide customized services, including age-related features if applicable. Your first, last name and email address are provided by the provider of the sign in (Apple or Google). Therefore, some of this information is already stored in the cloud but not necessarily by Hertracker.

Data stored locally: Firstname, date of birth.

Data stored in the cloud(encrypted): Email address

Health and Tracking Data: As part of the service, we enable users to record and monitor health information. You can choose to log data such as menstrual cycles and other personal details. This information is only processed if you actively provide it, either by manual entry or by backing up your data in the application. When you do decide to create a backup.

Data stored locally: All period tracking related data if no backup is made.

Data stored in the cloud (encrypted): All period tracking related data if a backup is made.

Device and Usage Information: To improve the performance and usability of our app and website, we collect technical information about your device, such as its make, model, operating system, and unique identifier. We also track system events like crashes and errors to identify problems and enhance stability. In addition, we gather data like your IP address, which helps us ensure services are delivered to the correct region and comply with local laws. However, we do not collect or track your precise location.

Habit Tracking Data: In addition to menstrual cycle-related data, our app allows you to track personal habits. This information is stored locally on your device and is not uploaded to our servers unless explicitly backed up by you. Habit tracking data may include goals, daily routines, reminders, and completion statuses, which help personalize your experience and keep you organized. Since this data remains stored locally, it remains private and is fully under your control. You can choose to delete this data at any time directly from the app settings of your device.

In the case you choose to create a backup by using the create backup button in the app, your data is securely stored on Google Cloud Storage, encrypted in rest and in transit. To further ensure the protection of your privacy we advice against adding identifiable data into the habits. Do not store any personally identifiable information in the open input fields such as the name and description field when creating a habit.

Noone, not even Hertracker or Google can access your encrypted backup data without your set password. It is your responsibility to remember your password, write it down in a safe place. Hertracker cannot help you recover your backup.

2. How we use your data

Data processing is a key part of delivering the services offered by our app. Whenever you interact with our platform, certain personal and non-personal data is collected, stored, and analyzed using both internal and third-party systems.

Below, we outline the reasons we process your data, along with the types of data used for each purpose:

2.1 Providing Core Features and Services

To provide our services, we process the following:

  • Health Data: This includes any health information you manually track or import through integrations in the Hertracker app. We process this data to deliver personalized insights and features related to health tracking, including cycle data and other sensitive information you choose to log.
  • Habit Data: When you use Hertracker to track habits, this information is processed to help you monitor your goals, patterns, and progress. This data contributes to providing tailored recommendations and reminders.
  • Device Data, Event Data, Usage Data, IP Address: We collect and process this information when you use the Hertracker app or visit our website. This helps us understand how you interact with our services and improve the technical performance and user experience of the app.
  • Account Data: When you create your Hertracker account, we process your account information to enable sign-ins and to communicate with you about essential service updates. This can include notifications related to your account, app updates, or personalized insights based on the data you’ve tracked. These communications may be sent via in-app messages, reminders, notifications, or emails.

Please review the following sections to learn more about the third-party services and integrations we use to deliver our core services effectively.

2.2 Providing Core Features and Services

We process habit, and period data to personalize your experience, but this data is stored locally on your device by default. If you enable backups, the data is securely stored in the cloud. All habit and period related recommendations made by the app are generated by processing your data directly on your device, ensuring your privacy and full control over your information.

We use Google services to enabled authentication in our app for both Google Sign-In and Apple Sign-In

  • For Google Sign-In, we collect your full name, email address, unique Google ID, and sign-in timestamp. Google may also collect your IP address as part of the authentication process for security purposes.
  • For Apple Sign-In on iOS devices, we collect your name (only if you choose to share it during sign-in), email address (or a private relay email if selected), unique Apple ID for the app, and sign-in timestamp. Google and Apple may also log your IP address for fraud prevention and account protection.

The data collected during sign-in is stored within Google servers and is accessible to us to manage the app for user authentication and account management. We use this information solely to provide secure access to your personalized experience and to manage your account. Firebase adheres to strict security protocols to protect your data, and both Google and Apple handle sign-in data according to their respective privacy policies.

2.3 Improving Hertracker With Analytics

All your health and/or habit data is stored locally on your device (unless backed up). The application does not track, process, or analyze your health and/or habit data for analytics purposes, even when you make a backup.

Data backups, if created by the user, are securely stored using Firebase and Google Cloud Storage. All backups are encrypted, and no data is processed or analyzed by Hertracker for any other purpose.

2.4 Improving Hertracker Technically

To enhance the Hertracker app experience and ensure reliable functionality, we utilize certain third-party services. These services may collect and process specific data as outlined below:

Third-Party Services:

  • RevenueCat: We use RevenueCat to manage in-app purchases and subscriptions. RevenueCat may collect information such as device identifiers, purchase history, and IP addresses to facilitate these transactions and improve service reliability. For more details, please refer to RevenueCat’s Privacy Policy.
  • Google Cloud Storage: Hertracker stores data using Google Cloud Storage. Google may collect data related to your device, usage patterns, and IP addresses to maintain and optimize their cloud services. For more information, please review Google Cloud’s Privacy Policy.
  • Firebase Authentication: Hertracker stores user data in Google servers using Firebase Authentication. For more information, please review Google Cloud’s Privacy Policy.
  • Firebase Crashlytics: Hertracker uses Firebase Crashlytics to track crashes and other problems while you use the app. Here aswell, Google may collect data related to your device, usage patterns, and IP addresses to maintain and optimize their cloud services. For more information, please review Google Cloud’s Privacy Policy

Future Features:

We are committed to maintaining user privacy and will continue to evaluate and disclose any additional data collection practices as our app evolves. Should we introduce new features that involve data processing, we will update this privacy policy accordingly and provide users with clear options to manage their data preferences.

2.5 Improving Features Through User Feedback

To gather valuable feedback from our Hertracker community, we may use surveys and conduct interviews to better understand health topics, app performance, and the usefulness of various features. Any information you provide through these surveys will be processed in accordance with this Privacy Policy.

Third-Party Providers:
Feedback can be submitted directly through the app via a dedicated feedback button. Tapping the button opens a pre-filled email template in the user’s default email app, allowing them to share their feedback by sending an email to support@hertracker.com.

Legal Basis:
The collection and processing of personal data for surveys are based on your explicit consent, as required by Art 6 Sec.1 lit a) GDPR. If health data is part of the process, it will be governed by Art 9 Sec.2 lit a) GDPR.

All personal data collected through surveys and interviews will be deleted as soon as it is no longer required for the purpose for which it was gathered.

2.6 Cookies on Hertracker.com

To monitor the performance of our services and enhance the user experience on our website, we use cookies on hertracker.com. For more details on how we use cookies and the legal basis for this, please refer to our Cookie Policy.

Cookies are small text files designed to improve your experience on the website. They are typically used to remember your preferences, store information like shopping cart contents, provide tracking data to third-party services such as analytics tools, or identify your device for targeted advertising purposes, such as retargeting.

We also employ third-party analytics and tracking services to help us measure website performance. When data is transferred outside of the European Economic Area (EEA), we implement the necessary safeguards in line with the General Data Protection Regulation (GDPR). Rest assured, any health data tracked in the Hertracker app is never shared with or sold to advertisers.

For more details, please review our full Cookie Policy.

2.7 Data Retention on Hertracker App

We are committed to protecting your privacy and ensuring the security of your personal data. This section outlines our data retention practices, ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

 

Purpose of Data Retention

 

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Our data retention practices are guided by the following principles:

  • Service Provision: To provide, maintain, and enhance our app’s functionality and your personalized experience.
  • Legal Obligations: To comply with legal requirements, resolve disputes, and enforce our agreements.
  • User Rights: To uphold your rights regarding data access, correction, and deletion.

Types of Data and Retention Periods

 

  1. User Authentication Data
  • Data Collected: Email address, unique user IDs (from Google or Apple Sign-In), sign-in timestamps, and IP addresses.
  • Retention Period:
  • Active Accounts: Retained for as long as your account remains active.
  • Deleted Accounts: Immediately deleted upon your request for account deletion, ensuring that your personal data is removed from our systems without delay.
  1. Habit and Period Data
  • Data Collected: Information related to your habits and periods.
  • Retention Period:
  • Local Storage: Stored on your device indefinitely unless you choose to delete it.
  • Cloud Backups: Retained encrypted for as long as you enable backup features. If backups are enabled and you choose to delete your account, all backups are deleted immediately alongside your account data.
  1. Inactive Accounts
  • Definition: Accounts that have not been accessed or used for an extended period (e.g., 24 months).
  • Retention Policy:
  • If your account remains inactive for 22 months, you will receive an email notification informing you of your account’s inactivity.
  • If there is no response or activity within 2 months after this notification, your account and all associated data will be deleted permanently.

Data Deletion and User Rights

 

Under GDPR, you have the right to request the deletion of your personal data. Here’s how you can exercise these rights:

 

  1. Deleting Your Account
  • Immediate Deletion: Use the “Delete My Account” option within the app settings to remove your authentication data and associated personal information instantly.
  • Email Request: Alternatively, contact our support team with your deletion request for immediate action.
  1. Data Erasure Process

Upon receiving a valid deletion request, we will:

  1. Verify Your Identity: Ensure the request is legitimate to protect your data.
  2. Delete Data: Remove your personal data from Firebase Authentication and immediately delete all associated cloud backups.
  3. Confirm Deletion: Notify you once your data has been successfully deleted.
  1. Data Minimization

We adhere to the principle of data minimization by:

  • Collecting Only Necessary Data: Gathering only the information essential for providing and improving our services.
  • Regularly Reviewing Data Practices: Periodically assessing our data collection and retention policies to eliminate unnecessary data storage.
  1. Data Security During Retention

To protect your data during its retention period, we implement robust security measures, including:

  • Encryption: Encrypting data both in transit (using HTTPS/TLS) and at rest.
  • Access Controls: Restricting access to personal data to authorized personnel only.
  • Regular Security Audits: Conducting periodic security assessments to identify and address vulnerabilities.
  1. International Data Transfers

Your personal data may be transferred to and stored on servers located outside the European Economic Area (EEA), including the United States. These transfers are governed by Standard Contractual Clauses (SCCs) to ensure that your data is protected in accordance with GDPR standards.

 

  1. Changes to Data Retention Policies

We may update our data retention policies to reflect changes in legal requirements or our business practices. Any significant changes will be communicated to you through:

  • In-App Notifications: Alerts within the app about policy updates.
  • Email Notifications: Direct emails informing you of important changes.
  • Privacy Policy Updates: Revised sections accessible via the app.

 

3. Third-Party Services and Integrations

We use third-party providers to assist in delivering our core services.

Google Cloud Storage:
Our app uses Google Cloud Storage as our hosting provider to securely store data. All data stored with Google Cloud Storage is encrypted to ensure security. Google Cloud complies with industry-leading safety and security standards, including certifications such as ISO 27001, SOC 1/2/3, and GDPR compliance, ensuring the highest level of data protection.

Google Cloud Storage helps us manage and store your account information, app usage data, and any other data necessary to provide our services.

It is not possible to opt out of Google Cloud Storage, as it is an essential tool required to deliver our services to you.

 

Firebase Authentication:

We use Firebase Authentication to manage user authentication and account creation within our app. Firebase Authentication securely handles user login credentials, such as email addresses and passwords, to provide seamless access to our services. Firebase ensures that all data is encrypted and complies with industry-leading security standards, including GDPR and ISO 27001 certifications. Firebase may process certain user data necessary for authentication and account management, but this data is handled securely and in line with privacy regulations.

It is not possible to opt out of Firebase, as it is an essential tool required to deliver our services to you.

RevenueCat:

We use RevenueCat to manage subscriptions and in-app purchases within our app. RevenueCat processes subscription data to ensure smooth functionality, such as tracking subscription status, handling renewals, and managing payments. RevenueCat does not have access to personal user data beyond what is necessary to manage subscriptions, and all data is handled in compliance with industry standards and privacy regulations.

It is not possible to opt out of RevenueCat, as it is an essential tool required to deliver our services to you.

Firebase Crashlytics:

We use Firebase Crashlytics to monitor app performance and track crashes in order to improve the reliability and user experience of our app. Firebase Crashlytics collects anonymized diagnostic data to identify and resolve issues such as app crashes and performance bottlenecks. This data is securely processed and handled in compliance with privacy regulations, including GDPR and ISO 27001 standards.

It is not possible to opt out of Firebase Crashlytics, as it is an essential tool required to deliver our services to you.

3.1 Payment Processors

If you choose to subscribe to our app, your subscription will be managed through either the Apple App Store or the Google Play Store, depending on your device. In this case, Apple or Google will handle the payment process and become the controller of your payment data. We remain the controller for all data related to your use of the app. Neither Apple nor Google will have access to any of your tracked data or other app-related usage data. You can find more information about how Apple or Google handles your payment data in their respective Privacy Policies.

3.2 Analytics and Website Optimization Tools

We utilize several plugins to ensure our website’s performance and optimize user experience while maintaining compliance with data privacy regulations such as GDPR and CCPA. These tools help us track, analyze, and manage user data responsibly:

  1. Burst Statistics – Privacy-Friendly Analytics for WordPress:
    Burst Statistics is a privacy-focused analytics tool that we use to gather insights on user behavior and website performance. Unlike traditional analytics platforms, Burst anonymizes all user data, ensuring compliance with GDPR. It tracks important metrics such as page views, user flow, and interactions without storing personally identifiable information (PII). This allows us to improve the website based on aggregate data while respecting the privacy of our users. No personal data is collected or processed without user consent, and all data is stored locally on our servers within the European Union.
    • Data Processed: Anonymized usage data (page views, session duration, user flow)
    • Compliance: Fully GDPR-compliant, no PII stored
    • User Consent: Required for any cookie tracking
  2. Complianz – GDPR/CCPA Cookie Consent:
    Complianz is an essential tool that helps us comply with GDPR, CCPA, and other data privacy regulations. It ensures that users are informed about the cookies being used on our website and can provide or withdraw their consent at any time. Complianz offers a detailed overview of the types of cookies in use (necessary, marketing, analytics, etc.), and users are given the option to opt-in or out based on their preferences.

This plugin plays a crucial role in allowing us to only track data after the user has explicitly consented. Additionally, it automatically blocks third-party cookies until proper consent is given. This ensures that all data collection on the website is transparent and fully compliant with international privacy standards.

    • Data Processed: User consent records (regarding cookies), cookie preferences
    • Compliance: GDPR, CCPA, ePrivacy Directive (EU Cookie Law)
    • User Consent: Explicit consent required for non-essential cookies

By integrating these tools, we ensure that the data collected from users is handled responsibly, with full transparency, and in compliance with relevant privacy laws. Additionally, users have full control over their data preferences, and no personal data is processed without explicit consent. These plugins help us strike a balance between delivering optimized website performance and respecting user privacy.

4. Marketing and Advertising

General Data Usage

To analyze the effectiveness of our advertising and improve our services, we process specific types of usage data, such as when you install the app or subscribe. This includes information like device identifiers (e.g., IDFA on iOS or GAID on Android) and IP addresses. This data helps us understand whether you’ve already downloaded the app and/or subscribed. By processing this data, we can refine our advertising efforts, such as which platforms are most effective in reaching new users.

Third-Party Provider

We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes data such as device identifiers and IP addresses to track subscription events, manage entitlements across devices, and determine user location for regional compliance. This data is processed securely and in accordance with privacy regulations.

Legal Basis

The processing of your usage data is necessary to provide our services and improve their effectiveness, as outlined under Art. 6 Sec. 1 lit b) GDPR (performance of a contract) and Art. 6 Sec. 1 lit f) GDPR (legitimate interest). This allows us to manage subscriptions, analyze aggregated trends, and optimize advertising strategies to grow our user base and provide a better experience.

 

This version clarifies that data processing is necessary for service delivery and business optimization (legitimate interest) and does not suggest an opt-out option. Let me know if you need further refinements!

  1. Your Privacy Rights

As a user and EU citizen, you have specific rights regarding your personal data, as outlined under the General Data Protection Regulation (GDPR). These rights ensure transparency and control over how your data is processed and stored. Below is a summary of your key rights:

  • Right to Access: You have the right to request access to the personal data we hold about you, as well as information about how we process it.
  • Right to Rectification: If any of your personal data is incorrect or incomplete, you have the right to ask us to correct or update it.
  • Right to Erasure (“Right to be Forgotten”): Under certain circumstances, you can request that we delete your personal data, for example, if it is no longer necessary for the purposes for which it was collected, or if you withdraw your consent.
  • Right to Restrict Processing: You may request that we limit the processing of your data, particularly if you contest the accuracy of the data or object to its processing.
  • Right to Data Portability: You can ask to receive your personal data in a structured, commonly used, and machine-readable format, and you can request that we transfer your data to another controller.
  • Right to Object: You have the right to object to the processing of your personal data in certain circumstances, particularly if the data is being processed for direct marketing purposes.

If at any point you feel that our data processing practices do not comply with applicable data protection laws or violate your privacy rights, you can contact us directly at support@hertracker.com. We take all concerns seriously and will investigate your query thoroughly.

As the owning company of Hertracker, Truffleleaf CV, is a Dutch entity, you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), the supervisory authority in the Netherlands responsible for monitoring the application of data protection laws.

For more information about your rights, or if you have any concerns about how we handle your data, feel free to contact us, and we will assist you with any inquiries or actions you’d like to take regarding your personal information.

5. Our Recommendations for Data Safety

Protecting your personal data starts with securing your devices and accounts. While we take extensive measures to safeguard your data within our app, it’s important that you also take steps to ensure your data remains private and secure. Here are some key recommendations to help you maintain data safety:

  1. Protect Your Hertracker Account
  • Secure Sign-In Options: Hertracker exclusively uses Google Sign-In on Android and Apple Sign-In on iOS to authenticate your account. These trusted sign-in methods are designed with advanced security features, such as strong encryption and built-in multi-factor authentication (2FA).
  • Protect Your Google and Apple Accounts: To keep your Hertracker account secure, ensure your Google or Apple ID is protected with a strong, unique password. Enabling Two-Factor Authentication (2FA) on your Google or Apple account adds an extra layer of security.
  • Update Your Security Settings: Regularly review and update the security settings of your Google and Apple accounts to ensure they remain secure.

By relying solely on Google and Apple sign-in services, we ensure your account benefits from their industry-leading security infrastructure.

  1. Protect Your Devices

Hertracker is designed as an offline-first application, and all habit and period tracking data can be stored locally on your device by default. If you choose not to enable optional backups, your data will remain offline-only, meaning it is stored solely on your physical device and not on external servers.

Because the data is stored locally, Truffleleaf CV is not liable for any data loss resulting from the loss, damage, or malfunction of your device. This includes, but is not limited to, circumstances such as accidental deletion, device theft, hardware failure, or software corruption.

  • Enable Device Security Features: Activate security options like a passcode, fingerprint (TouchID), or facial recognition (FaceID) on your device. This helps prevent unauthorized access to your Hertracker data.
  • Lock Your Screen: Set your device to automatically lock after a short period of inactivity to minimize the chances of someone accessing it without your permission.
  • Remote Data Erasure: In case your device is lost or stolen, it’s a good idea to set up a feature that allows you to erase all data remotely.
    • For iOS: Activate “Find My iPhone” and enable “Erase This Device” (instructions can be found in your device’s settings).
    • For Android: Set up Find My Device and use the online interface to lock or wipe your device if necessary.
  1. Regularly Review Data Sharing Settings If you’ve chosen to share data with others, it’s important to periodically review whether it still makes sense for you to share that information. Be cautious about who you allow access to your data and ensure you’re comfortable with the current permissions.
  2. Use Secure Networks Avoid using public Wi-Fi networks when accessing sensitive apps like Hertracker. If you must use a public network, consider using a Virtual Private Network (VPN) to encrypt your connection.
  3. Keep Your Apps and Devices Updated Make sure your device’s operating system and the Hertracker app are always up to date. Security updates often contain fixes for vulnerabilities that could be exploited by malicious actors.
  4. Security And Data Protection

When you create an account with Hertracker, your personal profile data is stored securely and separately from your health data and app settings, adding an extra layer of protection for your sensitive information.

  • Account Data: Hertracker uses Firebase Authentication to manage and store your account information. We exclusively use Google Sign-In on Android and Apple Sign-In on iOS, meaning we do not process or store any passwords. Firebase Authentication securely handles your login credentials using industry-standard security measures.
  • Optional Backup Data: If you choose to back up your data, it is securely stored in Google Cloud Storage. This ensures that your app settings and health data are protected using encryption both at rest and in transit.
  • Data Security: Firebase and Google Cloud Storage protect all data transmissions between your device and our servers using advanced security protocols, including encryption in transit (TLS) and encryption at rest. These measures ensure that your data cannot be accessed or intercepted by unauthorized parties.

All data is processed and stored on secure servers l, in compliance with EU data protection laws. For any subscriptions made through the app, payment details are securely managed by either the Apple App Store or Google Play Store, depending on your platform. Hertracker does not store or process any payment information.

Safeguarding your data privacy is a top priority for us. We implement a variety of security measures to protect your personal information from misuse, loss, or unauthorized alteration. In line with industry best practices, we ensure that your data is securely transferred and stored. While it is impossible to completely eliminate the risk of misuse, loss, or alteration, we are committed to taking all reasonable steps to minimize such risks and protect your data as much as possible.

6. Communications and Newsletters

To provide newsletter and email services, we process certain contact data of individuals who have opted in to receive such communications.

If you’ve subscribed to our newsletter without creating an account in the Hertracker app, we process the information you provided during registration on our website. This typically includes your name and email address, which we need to send you the newsletters you’ve subscribed to.

Legal Basis:

  • The legal basis for sending newsletters is your consent, as per Art 6 Sec.1 lit a) GDPR.
  • The legal basis for sending promotional emails is based on both your consent (Art 6 Sec.1 lit a) and our legitimate interest (Art 6 Sec.1 lit f) GDPR).

You can unsubscribe from newsletters and promotional emails at any time by clicking the “unsubscribe” link at the bottom of the emails.

7. Minors on Hertracker

Hertracker does not knowingly collect or process personal data from individuals under the age of 16. When creating an account, you must confirm that you are at least 16 years old or have received consent from your parent or legal guardian to use the Hertracker app.

If you are based in the EU, you may only use our services if you are above the age required to provide explicit consent for data processing under the laws of your country , or if you have obtained parental or legal guardian consent.

If you are a parent and discover that your child is using Hertracker without your permission, or if you have any concerns regarding data privacy, please contact us at support@hertracker.com.

For users in the United States, individuals under the age of 13 are not permitted to use the Hertracker app. In compliance with the Children’s Online Privacy Protection Act (COPPA), if Hertracker becomes aware that data has been collected from users under 13 years old, we will not disclose this information and reserve the right to delete the account and any associated personal, health, or sensitive data from our servers.

8. Privacy Policy Updates

Truffleleaf CV reserves the right to update or amend this Privacy Policy periodically to reflect changes in legal requirements, our data collection and usage practices, updates to Hertracker’s services, or advances in technology.

Please check this page regularly for any updates and refer to the “last updated” date at the top to see if any revisions have been made since your last visit. If we make significant changes to this Privacy Policy that could affect your consent, we will notify you accordingly.

As a reminder, since the Hertracker app has not yet launched, some of the policies mentioned may be subject to further changes prior to the official release of the app.

9. Responsibility for Hertracker’s Data Processing

Hertracker is developed by Truffleleaf CV, based in the Netherlands, and our approach to data processing adheres to the stringent requirements set by both Dutch and European Union regulations. Truffleleaf CV is located at Schoenmakerij 1H, Zevenbergen, Netherlands.

If you have any questions regarding how we handle your data, please feel free to reach out to us at support@hertracker.com. Further contact information can be found on our website.

10. Governing Language of this Privacy Policy

We aim to make the app accessible to users around the world in multiple languages. We try to ensure this Privacy Policy and other communications are accurately translated into various languages.

However, please note that legal content may vary slightly in translation. In case of any discrepancies, the English version of this Privacy Policy will be considered the authoritative version. The most current version of this Privacy Policy is always available in English on our website.