HerCare Official Heart Mark
HerCare
Back to Overview
← Return to HerCare Home
PRIVACY-FIRST ZERO-KNOWLEDGE ARCHITECTURE

HerCare Privacy Policy

Last Revised: September 2026 • Application ID: com.hercare.app • Legal Version: 2.1

Table of Contents

  • 1. Privacy Commitment & Zero Selling
  • 2. Data We Collect
  • 3. Legal Bases & GDPR Art. 9 Consent
  • 4. How Your Data is Used
  • 5. Cryptographic Security & Storage
  • 6. Subpoena & Law Enforcement Protocol
  • 7. Partner Connect & Mutual Encryption
  • 8. Clinical Advisory Assistant Safety
  • 9. Third-Party Service Providers
  • 10. Cookies & Local Storage Notice
  • 11. US Consumer Health Rights (MHMDA)
  • 12. Age Eligibility & Minor Policy
  • 13. Data Retention & 1-Click Deletion
  • 14. Your Rights & DPO Contact

1. Our Privacy Commitment & Zero Data Selling Policy

HerCare Technologies Inc. (“HerCare”, “we”, “our”, or “us”) operates the HerCare mobile application (Package ID: com.hercare.app) and official web properties (https://thehercare.in). We believe reproductive and hormonal cycle information represents an intimate, deeply sensitive category of personal human data that requires the highest standard of technical and ethical protection.

The HerCare Zero-Monetization Covenant: We will never sell, lease, rent, broker, or monetize your menstrual cycles, sexual health notes, symptom logs, or reproductive data to advertising networks, data brokers, insurance providers, employers, or third-party marketing entities. HerCare contains zero third-party advertising trackers, zero programmatic ad SDKs, and zero behavioral tracking beacons.

2. Data We Collect & Minimalist Collection Model

We adhere to strict data minimization principles under GDPR and international privacy standards, collecting only what is functionally essential to deliver accurate cycle estimations and wellness tools:

  • Account Credentials: Email address, cryptographically hashed authentication tokens, and user display alias (managed via Supabase Auth).
  • Reproductive & Cycle Telemetry: Period start and conclusion dates, bleeding flow intensity (spotting, light, moderate, heavy), and baseline historical cycle duration.
  • Daily Wellness & Symptom Logs: User-logged physical indicators (cramps, breast tenderness, headaches, bloating), mood status tags, water hydration counters (glasses logged), and pedometer step activity.
  • Specialized Mode Selections: Optional personal configurations indicating Trying to Conceive (TTC) mode or Bleed-Free / Polycystic Ovary Syndrome (PCOS) lifestyle support.
  • Client-Encrypted Journal Notes: Private journal reflections encrypted on your device prior to cloud backup.
  • Subscription Entitlements: Anonymous transaction receipts and subscription status tokens processed through Google Play Billing and RevenueCat.

3. Legal Bases for Processing & GDPR Article 9 Explicit Consent

For individuals residing in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, we process personal information under the following legal frameworks of the General Data Protection Regulation (GDPR / UK GDPR):

  • Special Category Reproductive Health Data (GDPR Article 9(2)(a)): We process cycle dates, flow intensities, and physical symptoms exclusively on the basis of your explicit, affirmative consent provided during app onboarding. You may revoke this consent at any time by deleting your account or clearing your logs.
  • Contractual Performance (GDPR Article 6(1)(b)): To calculate your cycle phases, maintain your account, and deliver requested subscription services.
  • Legitimate Interests (GDPR Article 6(1)(f)): To maintain application security, debug runtime errors, and enforce our cryptographic Row-Level Security policies.

4. How Your Data Is Used

HerCare uses collected information strictly for user-facing self-monitoring and health educational purposes:

  • To calculate statistical menstrual, follicular, ovulatory, and luteal phase timelines and project upcoming cycle dates.
  • To display multi-month correlation patterns between hydration, sleep, exercise, and hormonal symptoms.
  • To provide evidence-based, non-diagnostic lifestyle, nutritional, and seed-cycling guidance tailored to biological phases.
  • To verify Google Play and App Store Premium subscription entitlements and sync multi-device accounts securely.

5. Cryptographic Security & Zero-Knowledge Storage

HerCare implements a defense-in-depth architectural security model:

  • PostgreSQL Row-Level Security (RLS): Our database tier enforces strict PostgreSQL RLS policies. Every database operation is cryptographically restricted to the authenticated user’s private UUID. No user can ever query or modify data belonging to another account.
  • Client-Side Journal Encryption (AES-256-GCM): Freeform personal notes and diary reflections are encrypted directly on your device before transmission. HerCare database administrators cannot read your cleartext notes.
  • Encryption in Transit & At Rest: All web and mobile communications enforce TLS 1.3 encryption in transit with HTTP Strict Transport Security (HSTS), and all databases utilize AES-256 block-level encryption at rest.

6. Subpoena & Law Enforcement Protocol (Post-Dobbs Protections)

Following landmark legal shifts in reproductive healthcare privacy, HerCare enforces a rigorous standard concerning civil discovery and governmental inquiries:

Mathematical Zero-Knowledge Privacy: Because sensitive journal entries and Partner Connect channels are encrypted client-side where only the user holds the local private keys, HerCare cannot technically decrypt or produce cleartext reproductive journal entries to civil litigants or governmental agencies. HerCare challenges any overly broad or extraterritorial data requests seeking reproductive health records.

7. Partner Connect & End-to-End Mutual Encryption

HerCare offers an optional Partner Connect feature allowing users to mutually share hydration status, daily step counts, resting sleep hours, and cycle empathy reminders with a trusted loved one or spouse.

  • All partner data channels are secured using zero-knowledge end-to-end encryption (Curve25519 key exchange + AES-256-GCM).
  • Pairing keys reside solely on the two linked devices and are never saved in cleartext on HerCare servers.
  • Intimate daily symptom descriptions and journal notes are strictly quarantined and never shared over the partner channel.
  • You retain total authority to disconnect a paired partner instantly with 1 tap in app settings.

8. Clinical Advisory Assistant & Health Intelligence Privacy Safety

When utilizing HerCare's conversational Health & Cycle Advisory Assistant:

  • Zero-PII Sanitization Cluster: User queries pass through an automated server-side filter that strips names, emails, and device identifiers before clinical literature retrieval.
  • No Model Training on User Data: Conversations are quarantined in volatile memory and are never sold, transferred, or used to train public machine learning systems or commercial foundation models.

9. Essential Third-Party Infrastructure Providers

We work exclusively with vetted infrastructure providers bound by rigorous Data Processing Agreements (DPAs):

  • Supabase Inc.: SOC2 Type II compliant PostgreSQL cloud infrastructure, encrypted user authentication, and data synchronization.
  • Google Play Billing / RevenueCat Inc.: Transaction receipt validation and mobile subscription entitlement management.
  • Apple Inc. (App Store): iOS in-app purchases and receipt validation (upon iOS release).

We do not integrate any third-party behavioral analytics, crash reporters that capture health payload data, or ad networks.

10. Cookies & Local Storage Transparency

HerCare maintains a strictly functional approach to web storage under the EU ePrivacy Directive:

  • We do NOT use advertising cookies, third-party tracking pixels, or cross-site fingerprinting cookies.
  • We utilize browser localStorage solely for functional UI state preferences (such as remembering your dark mode choice, 3D interactive simulator orientation, and session status).
  • Because no tracking or advertising cookies are deployed, HerCare does not require invasive third-party cookie consent banners.

11. US Consumer Health Data Rights (Washington MHMDA & CCPA/CPRA)

Under the Washington My Health My Data Act (MHMDA), the California Consumer Privacy Act (CCPA/CPRA), and related US state health privacy statutes:

  • You have the right to confirm whether HerCare processes your consumer reproductive health data.
  • You have the right to access, download, and review your health data records.
  • You have the right to withdraw consent and mandate the immediate, permanent deletion of your reproductive health data.
  • No Sale / No Geofencing: HerCare does not sell consumer health data and strictly prohibits the geofencing of reproductive healthcare facilities.

12. Age Eligibility & Children's Privacy (COPPA & GDPR-K)

HerCare is strictly engineered for users who have reached the age of majority or minimum digital consent age:

  • United States: Users must be at least 13 years of age (in full compliance with the Children's Online Privacy Protection Act - COPPA).
  • European Union & UK: Users must be at least 16 years of age (or the relevant member state age threshold under GDPR-K).
  • We do not knowingly solicit or collect reproductive or cycle data from individuals under these threshold ages. If we discover that a child under the qualifying age has registered an account, we will immediately delete the account and purge all associated records.

13. Data Retention & 1-Click Permanent Deletion Guarantee

You retain absolute sovereignty over your digital health records:

  • In-App Immediate Deletion: Navigate to Settings > Privacy & Security > Delete My Account. Execution triggers an immediate atomic purge.
  • Web Deletion Portal: In full compliance with Google Play Developer Policies, users can submit an account and data wipe request via our online Account Deletion Portal without needing to install or open the app.
  • Upon deletion confirmation, cascading database triggers eradicate user rows, period logs, symptom entries, and cryptographic hashes permanently across all live clusters.

14. Your Global Privacy Rights & Data Protection Officer Contact

Regardless of your global location, you possess the right to access, rectify, export, restrict, or erase your personal data at any time without fees or discrimination.

For all privacy inquiries, Data Subject Access Requests (DSAR), or compliance communications, please contact our designated Data Protection Officer:

Data Protection Office — HerCare Technologies Inc.
Email: hello@thehercare.in
Legal Response Window: Within 30 calendar days (or sooner as required by applicable law)
Subject Line: Privacy Rights Request — HerCare App
thehercare.in • © 2026 HerCare Technologies Inc. All rights reserved.
Home About HerCare Features Privacy Policy Terms of Service Health Disclaimer Data Deletion Contact