Privacy Policy
Last updated August 31, 2026
Fleura tracks cycles, trying to conceive, pregnancy, contraception and perimenopause. Because that is health data, this policy is written to be specific rather than reassuring — what is collected, where it lives, and what your choices actually do.
The short version
- What you log stays on your device, encrypted, unless you turn on cloud backup.
- Cloud backup is end-to-end encrypted with a key derived from your password on your own device — our servers only ever see ciphertext.
- We never sell health data. Not to advertisers, not to anyone.
- Fleura is free. The uses below sit behind one switch, “Enable personalisation”, which you can turn off at any time.
- You can export or delete everything, at any time, from Settings.
What Fleura stores, and where
Cycle, symptom, and health-check entries are saved on your device the moment you log them, encrypted at rest. Once you're signed in, Fleura works fully offline day to day — nothing about logging an entry or viewing your history requires a network connection.
Your name and date of birth are optional, and if you give them they are part of that same encrypted blob — not fields on your account. We hold them the way we hold everything else you write: as ciphertext we cannot open. Fleura asks for the date of birth because cycle length shifts with age and screening guidance is age-dependent, and for the name only so the app can greet you.
Creating an account is required to use Fleura, and stores the email address and password you provide. Your password is never stored, and it is never even sent to us as you type it: the app derives two separate values from it on your device, sends one of them to sign you in, and keeps the other — the one that unwraps your data — on your device alone. Supabase, our authentication provider, stores only a salted hash of the value it receives, and that value cannot be turned back into the other one.
Two other things sit on that account record, both in plain text because neither is health data: the language you use Fleura in, and — if you arrived through somebody else's invite link — the invite code you arrived with. The code identifies the person who invited you, not you, and it is the only thing they ever learn: that someone joined, never who, and nothing about what you track.
Signing in turns on cloud backup. It uploads an encrypted copy of your entries so your history reaches your other devices, and the key that opens it is the half of the derivation that never leaves your devices. We can hold that copy; we cannot read it. You can turn backup off at any time in Settings, which deletes the server copy.
Apple Health and Health Connect
Fleura can connect to Apple Health (on iPhone) or Health Connect (on Android), and each direction is its own switch: reading your existing period history into Fleura, and writing what you log in Fleura back out. Both start off, and connecting is never required — the switches live in Settings, and onboarding offers the import once.
Fleura reads and writes menstruation records only. What it imports becomes part of the same encrypted store as everything you log by hand — encrypted on your device, included in the end-to-end encrypted backup only if backup is on, and covered by every promise in this policy. Health data obtained through Apple Health or Health Connect is never used for advertising, never shared with third parties, and never sold; when Fleura writes to those stores it touches only records it created itself, and turning a direction off stops it immediately.
The companies that help us run Fleura
Three, and no others. Each is bound by a contract to process data only on our instructions, none may use it for their own purposes, and none is an advertising or analytics company.
- Supabase — the database and sign-in. Holds your email address, the salted hash described above, and the encrypted copy of your entries if backup is on. The encryption means the entries are ciphertext to them exactly as they are to us.
- Vercel — hosting. Serves the app and, like any web host, sees the IP address and browser your requests arrive from. It never receives your entries.
- Resend — email delivery. Receives your email address and the text of the sign-in, password-reset and support-reply messages we send you. Nothing about your cycle is ever in one.
Apple and Google also deliver notifications to your device if you turn reminders on, and they see that a message was sent, never what it is for — see Reminders below.
Personalisation, and what it covers
Fleura has no subscription and nothing to buy. In the app, the uses below sit behind a single switch called Enable personalisation, on by default. Turning it off withdraws all of them at once and turns off what Fleura derives from your history — your predictions, your insights, and what it suggests you check. Everything you have logged stays on your device, readable, exportable and deletable, either way.
- Usage analytics. Anonymous counts of which screens are opened, to decide what to build next — with the platform the app runs on and the country your device's language setting names. Country comes from that setting alone, never from your IP address or location, and nothing finer than a country is ever recorded. Never your logged entries.
- Error reports. Separately from analytics, and not covered by the switch above: when the app itself breaks, it sends us the technical error — the error message, a code trace, which platform, and the browser version. Nothing else: no account, no device identifier, and not the page you were on. This is how we find and fix crashes, it cannot describe you, and it lands in our own database (run by Supabase, listed above) — no crash-reporting company is involved.
- Partner sharing. Lets you create a revocable link that shows a partner or a doctor your predictions only — never your logged symptoms or history. Nothing is shared until you create a link.
- Cloud backup. Keeps the encrypted copy described above, so your history reaches your other devices.
- Reminder delivery. Lets us hold a push address for your device and send the content-free daily wake-up described under Reminders.
- Contextual advertising and affiliate links. Described below. Neither can see anything you log.
Storing your entries on your own device is not in that list, because it is not a use of your data that could be declined — it is what the app is.
Two things you have to switch on yourself
The uses above are covered by the agreement you make when you start using Fleura. Two are not, because they serve us rather than you, and it would not be honest to make the app conditional on them. Both start off. Both live under Settings → Optional, and the app behaves identically whether or not you ever touch them.
- Ad relevance. Lets sponsored content reflect the mode you've selected (such as trying to conceive) instead of only the page you're on. Only that self-declared mode is ever used, never anything you log, and it is never sent to the advertiser — only whether it matched. Left off, sponsored content is chosen by the page alone, and no health-derived information reaches the advertising layer at all.
- Product news. Occasional notifications about what has changed, and a nudge if you stop opening the app. These never mention your cycle or anything you have logged. Your reminders are a different setting and are unaffected by this one.
Sponsored content and affiliate links
Fleura shows contextual advertising and affiliate links, and both can be turned off in Settings. Both are chosen by the page you're on, never by anything you log: the code that selects what to show has no access to your entries at all, by construction, not just by policy. Affiliate links do not tell the merchant which page sent you.
How we measure ad campaigns
If you installed Fleura from an ad, we confirm that install happened and, once, that you created an account — so we can tell which campaigns are worth running, not so anyone can be tracked. We may work with more than one ad platform over time; whichever ones we use, all of them are held to the same rule: they may learn those two facts, and nothing else, ever — not your email, not anything you log, not your device's advertising identifier, and nothing that could reveal you use a period-tracking app beyond the fact that you have an account. On iPhone this runs entirely through Apple's own attribution system, which never gives us or any advertiser your identity in the first place. On Android we send only those two facts ourselves, from our own server, never from your device directly.
What we never do
- We do not sell health data, to anyone, under any circumstances.
- We do not use your logged entries to target advertising unless you opt in, and even then, only your self-declared mode is used — never the entries themselves.
- We do not share your data with data brokers.
Reminders
Reminders are worked out and delivered on your device. What a reminder says, whether you have one at all, and when it is due are decided on the phone and sent nowhere — a schedule sitting on someone else's machine would disclose that a reminder exists at a particular time even if its contents were hidden. In the phone apps, upcoming reminders are handed to the operating system so they arrive without Fleura being open; that queue lives on the phone too.
The phone apps also receive a daily push from us, and it is worth being exact about what that is. It carries no content. It arrives at the same hour every day — an hour picked at random when the app was installed, unrelated to anything you track — and every device gets one whether or not it has anything due. It means only “wake up and check”; your phone then does the deciding. Apple and Google carry it, as they carry every notification on a phone, and what they can observe is that a message arrived at a fixed hour, which is the same thing they can observe about everybody. We use them directly rather than through a notifications company, so there is no additional party in the path.
Turning off Reminder delivery in Settings deletes the address we hold for your device. Separately, Product news — occasional messages about new features — is off unless you turn it on, and those messages never mention your cycle, your pregnancy or anything you have logged, because a lock screen is read by whoever is holding the phone.
Support messages
If you write to us from Settings → Support & feedback, that message is the one thing in Fleura a person at our end can read. It is stored as ordinary text alongside your email address, because a message nobody can open is not support. Every other thing you put into this app — your entries, your dates, your symptoms — is encrypted on your device first, and this is the single exception.
We say so on the form itself, above the box, rather than only here: please describe what the app did rather than what your body did. If you do mention something about your health in order to explain a problem, we treat it as we treat everything else — we do not sell it, share it, or use it for advertising — but it is worth knowing before you write it rather than afterwards. You can delete any message you have sent from the same screen, and deleting your account deletes them with it.
We reply by email, to the address on your account. There is no inbox inside the app, and we do not use your message to identify you anywhere else in Fleura.
Your choices
From Settings, you can export your data, delete your account and everything associated with it, and turn personalisation off. Deleting your account removes your server-side data; anything stored only on your device is removed when you uninstall the app or clear its storage.
How long we keep things
The encrypted backup exists for as long as backup is on: turning backup off deletes the server copy, and deleting your account deletes everything server-side — the backup, your email address, and your support messages — at once. Support messages can also be deleted individually, from the screen you sent them on. Usage analytics carry a random device identifier rather than your account, so they describe a device we cannot name; we keep them only to see which parts of Fleura are used. Nothing is retained “for business purposes” after you ask for it to be gone.
Your privacy rights
Wherever you live, the same mechanics apply, and most of them are switches rather than request forms: you can read everything Fleura holds about you (it is on your device), correct it (edit any entry), export it (Settings → a readable file), delete it (Settings → Delete everything, or fleura.cc/delete-account), and withdraw consent for any optional use by turning its switch off. We will never treat you differently for exercising any of these rights.
If you live in California: we do not sell personal information. On Android, if you installed Fleura from an ad, we do share a narrow signal with the ad platforms we use — that the install happened and, once, that you created an account — which is what the California Consumer Privacy Act calls sharing for cross-context behavioural advertising. Nothing else is ever included: not your email, not anything you log, not your cycle, not a device advertising id. On iPhone this never happens at all — Apple's own attribution system handles it without Fleura sharing anything. You can opt out of the Android sharing at any time — Settings → Privacy → Optional → “Confirm ads led to your install” — which is the Do Not Sell or Share My Personal Information control the CCPA requires, available to everyone regardless of where they live. We also honor the Global Privacy Control signal as the same opt-out, automatically. The rights the CCPA gives you — to know, to correct, to delete, and to not be discriminated against — are the switches above. To exercise any of them another way, or through an authorised agent, email us and we will verify the request against your account.
If you live in Washington or another state with a consumer health data law: this page is also our consumer health data privacy policy. The consumer health data Fleura handles is what you give it — cycle, symptom, pregnancy, and health-check entries, plus period records you import from Apple Health or Health Connect — and what it derives from that on your device: predictions and insights. It is collected for one purpose, making the app work for you, and it is not sold, not shared with third parties, and not used for advertising. You can withdraw consent or delete it with the switches above. If you email us to exercise a right and are unhappy with our answer, reply and say so — the same address handles appeals, a different set of eyes reads them, and we answer within the time your state's law sets. If the appeal still fails you, you may contact your state Attorney General.
If you are in the European Economic Area or the United Kingdom: our legal bases are the contract with you (storing and syncing what you log is the app), and consent for everything optional, which the switches withdraw as easily as they gave it. You additionally have the right to lodge a complaint with your data-protection authority.
Where data is processed
Our service providers may process the little they hold — the account record, the ciphertext, delivery logs — in the United States and other countries. The encryption described in this policy travels with the data: your entries are ciphertext wherever they are stored, in every jurisdiction, because the key never leaves your devices.
Security
Entries are encrypted on your device before anything is written to disk. Cloud backups are end-to-end encrypted — encrypted before they leave your device, with a key we never receive. Traffic to our servers is encrypted in transit.
Children
Fleura is not directed at, and should not be used by, anyone under 16.
Changes to this policy
If this policy changes in a way that affects how your data is handled, we'll update the date at the top of this page and, where the change is material, ask for your consent again rather than assuming it carries over.
Contact
Fleura is operated by Akrane sp. z o.o., a company registered in Poland (NIP 5273212577, REGON 544387756), with its registered office at Aleja Jana Pawła II 27, 00-867 Warsaw, Poland — the data controller for the personal data this policy describes. Questions about this policy, or about exercising any of the rights above: .