This Privacy Policy explains how GetMyMood Inc. ("GetMyMood", "we", "us"), the data controller, collects, uses, stores, and shares information when you use the GetMyMood: Period & Cycle Tracker mobile app and related pages (the "Services").
Language versions. The English and French Canadian versions of this Privacy Policy describe the same privacy practices and have the same effective date. A right or disclosure that applies only in a particular jurisdiction is identified in the text.
1) Information we collect
Information you provide
- Account information, such as email address, display name, and authentication identifiers.
- Cycle and symptom information you enter, including period dates, symptom selections, flow intensity, and optional notes.
- Optional profile and settings information, for example goals, age group, reminder preferences, and cycle settings.
- Partner Sharing information, if you use that feature, such as invite status, sharing preferences, relationship status, and the selected cycle information you choose to make visible to an invited partner.
- Feedback you choose to submit to us.
Information collected automatically
- Technical and device data such as platform, app version, and basic diagnostics.
- Billing-support metadata, such as the App Store or Google Play storefront country reported by RevenueCat, used for purchase troubleshooting and, as a country-level analytics property, to understand where the app is used.
- Crash and reliability information via crash reporting tools.
- Pseudonymous usage events and analytics properties processed through Firebase/Google Analytics and Amplitude, which may include information about screen views, feature usage, cycle and period length ranges, symptom logging activity, insight content interactions, age group buckets, goals, notification preferences, entitlement status, and reliability diagnostics. Health-related analytics are only collected with your separate, optional health analytics consent. Limited operational events — such as confirmations that data was deleted (including how many records), or opens of reminders and widgets — may indicate that you use tracking features and are collected without this consent.
- Approximate location for analytics. Firebase/Google Analytics derives approximate location (such as country, region, or city) from the IP address of analytics requests. The IP address is used transiently for this derivation and is not logged or stored by Google Analytics, and we see this location only in aggregated reports. We do not collect precise (GPS or location-services) location, the app requests no location permissions on any platform, and Amplitude is configured not to record IP addresses or derive location from them.
- When Firebase In-App Messaging is enabled, Firebase may generate and use a per-installation identifier and record in-app message impressions, clicks, and dismissals so we can deliver and measure informational or promotional messages shown while you are actively using the app.
Advertising and consent data
- On iOS and Android, we may show banner ads via Google AdMob.
- Ad requests are currently configured as non-personalized in the app.
- Where required, we use Google's User Messaging Platform (UMP) to collect and manage ad consent choices.
On-device storage
The app stores data locally on your device to support offline functionality, performance, and user preferences. On iOS and Android, locally stored health and session data is encrypted at rest using platform-level secure storage. If encrypted storage is unavailable on a device, the app may fall back to the operating system's standard sandboxed app storage so the app remains usable. If you add the optional home-screen widget, a small cycle summary (current phase, cycle day, and next predicted period) is stored in the app's sandboxed storage on your device so the widget can display it.
If you use Partner Sharing, selected information that has already loaded in the app may be stored locally on the invited partner's device to support app performance and limited offline viewing. When access is revoked, disconnected, or changed, the app updates or removes that locally stored Partner Sharing information after the partner's app reconnects and receives the change.
Cycle and symptom information may be considered sensitive health-related information under some laws.
Age assurance
Where required by applicable law or app-store policy, the app may receive age-assurance signals from the app store or operating system to determine whether you are eligible to use health-data features. On iOS this may use Apple's Declared Age Range, and on Android it may use Google Play Age Signals.
- These signals are limited to a coarse age range and, where applicable, a parent or guardian approval status. We do not receive or store your exact birth date or government-ID status, and we do not ask you to provide an exact birth date. On iOS, to honour parent or guardian consent withdrawals reported by Apple, the app sends an App Store transaction identifier scoped to your Apple Account and this app to our backend, which immediately converts it to a salted, hashed reference linked to your account and does not store or log the raw identifier.
- We store only the minimum derived state needed to enforce access to health-data features (for example, whether the current device is allowed, blocked, or awaiting parent or guardian approval). On your device, this state is stored using the platform-level secure storage described under On-device storage above. If Apple notifies us that a parent or guardian has withdrawn consent, we also record that withdrawal in our cloud database — a consent-status flag on your account and a salted, hashed transaction reference — so we can pause access to health-data features across your devices. These records never include an age range, birth date, or raw platform identifier.
- Age-assurance signals and any derived eligibility state are not used for advertising, analytics, or profiling, and are not sent to our analytics, crash-reporting, or advertising providers. They are used solely to determine eligibility for the Services.
These eligibility checks are separate from, and do not replace, the two health-related consents described below in Legal bases. If a required signal indicates you are under the minimum age, or a required parent or guardian approval is pending or declined, or a required signal is unavailable, access to health-data features may be limited or paused; any cycle or symptom information already stored on your device is not deleted by these checks.
2) How we use information
- Provide core functionality, including tracking, calculations, predictions, and account features.
- Sync your data across sessions and devices and maintain service reliability.
- Provide Partner Sharing features when you choose to use them, including creating invite codes, showing selected cycle information to the partner you invite, supporting revocation or disconnection, and maintaining safety and abuse-prevention controls.
- Provide reminders and notifications you enable.
- Where required by applicable law or app-store policy, determine eligibility for health-data features using coarse age-range and parent/guardian approval signals from the app store or operating system, as described in Age assurance above. This information is used only for eligibility and is never used for advertising, analytics, or profiling.
- Operate, secure, monitor, debug, and improve the Services, including through pseudonymous analytics and derived or bucketed usage signals.
- Display informational and promotional in-app messages while you are actively using the app and measure campaign performance.
- Show ads to users who are not in an ads-free entitlement state.
- Respond to support and feedback requests.
- Comply with legal obligations and enforce our Terms.
3) Legal bases (EEA/UK users)
- Contract (Art. 6(1)(b)): To provide the Services you request.
- Legitimate interests (Art. 6(1)(f)): Security, fraud prevention, reliability, and service improvement.
- Consent (Art. 6(1)(a), Art. 9(2)(a)): We collect two separate health-related consents at registration:
- Health data processing consent (required): Consent to process your health-related data, including period dates, symptoms, and cycle information, in order to provide the core tracking service. This consent is required to create an account. To withdraw this consent, delete your account in Settings > Account and Data > Delete Account.
- Health analytics consent (optional): Separate, optional consent to include pseudonymized, mostly bucketed health-related data in analytics (for example cycle-length ranges, plus a limited set of specific values such as the current cycle day, tied to a hashed telemetry identifier — never your raw entries or account identity). This consent is not required to use the app and can be freely withdrawn at any time in Settings > Account and Data without affecting core app functionality.
- Consent is also collected for ad consent choices where required.
- Legal obligation (Art. 6(1)(c)): Where we must retain or disclose information by law.
You may withdraw health analytics consent at any time without affecting core app functionality. To withdraw health data processing consent, delete your account. Withdrawal does not affect processing already performed lawfully before withdrawal.
4) How and where data is stored
We use Firebase and Google Cloud infrastructure, including Firebase Authentication and Cloud Firestore, to store and process account and app data. Data sent between the app and Firebase is encrypted in transit, and Cloud Firestore stores data using Google-managed encryption at rest. On iOS and Android, locally stored health and session data is encrypted on the device. Cycle and symptom fields are not additionally field-encrypted by the app before being sent to Firebase, so they remain available to our app systems when needed to provide syncing, account deletion, support, security, and legal compliance.
Data may be processed in countries other than your own, including the United States and other jurisdictions where our service providers operate. Where personal data of EEA, UK, or Swiss users is transferred to countries without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses in our service-provider agreements and, where applicable, our providers' certification under the EU-U.S. Data Privacy Framework (and its UK Extension). You can request a copy of the relevant safeguards at support@getmymood.com. For Quebec residents: your information may be communicated outside Quebec, including to the United States, for the purposes described in this policy.
5) Sharing and disclosures
We do not sell or rent your personal information. We do not share personal information for cross-context behavioral advertising.
People you choose to share with
If you use Partner Sharing, you direct us to make selected cycle-related information available to the partner you invite. While sharing is active, your partner can see your current cycle phase and cycle day. Depending on your settings, this may also include period estimates, shared calendar ranges, ovulation estimates if enabled, and your most recent symptom entry within a limited time window — including the individual symptoms in the categories you enable (for example mood, physical, or energy), flow intensity if enabled, and the date and time the entry was logged. We do not share your private notes, your full symptom history, your raw period-day records, your email address, or your invite code with your partner. Your partner's app receives an internal account identifier and technical metadata needed to operate the sharing connection; these are not displayed to your partner.
You can change what you share, stop sharing, revoke access, or disconnect a Partner Sharing relationship in the app. Revocation or disconnection stops future access through the app after the change is received, but we cannot control screenshots, memory, exports, information that was previously loaded for offline viewing, or information your partner may have saved or shared outside the app.
If you accept a Partner Sharing invite without creating a full tracking account, we may create a limited partner-only anonymous account using Firebase Anonymous Authentication. This account is used only to let you view the shared cycle information, manage your Partner Sharing access, and protect the relationship from unauthorized access. Partner-only anonymous accounts do not complete normal tracker onboarding and cannot log period or symptom data unless you later choose to create or link a tracking account and complete the required health-data consent flow.
Service providers
We use service providers and processors only as needed to operate the Services. We do not state that health-related data is processed only internally by GetMyMood, because some service providers process data on our behalf to deliver hosting, authentication, analytics, crash reporting, and ad-related functions.
These providers process data for us under contractual, confidentiality, and security obligations, including:
- Google and Firebase for authentication, database, analytics, crash reporting, remote configuration, in-app messaging, cloud functions, and infrastructure hosting.
- Amplitude for pseudonymous analytics and service-improvement measurement.
- Google AdMob and Google's User Messaging Platform (UMP) for non-personalized in-app ad delivery and consent management on supported mobile platforms.
- RevenueCat for managing subscriptions, in-app purchases, and entitlement tracking.
For analytics and service improvement, we may send pseudonymous usage data and derived or bucketed data points to Firebase/Google Analytics and Amplitude, such as screen views, feature usage, symptom logging activity, cycle-length ranges, period-length ranges, insight content interactions, age group buckets, goals, entitlement status, notification settings, app-store storefront country (country level), and reliability diagnostics. Health-related analytics data is only sent when you have provided separate, optional health analytics consent. Both analytics providers use pseudonymous telemetry identifiers; we do not send the raw Firebase user ID to analytics providers. Firebase/Google Analytics also derives approximate location (such as country, region, or city) from the IP address of analytics requests; the IP address is used transiently and is not logged or stored, and we use this coarse location only in aggregate. Amplitude is configured not to record IP addresses or derive location from them; we do, however, send the country-level app-store storefront country to both analytics providers as a user property. We do not use these disclosures for selling data or cross-context behavioral advertising.
For Firebase In-App Messaging, Firebase may use an automatically generated installation identifier to deliver messages and measure whether a message was displayed, tapped, or dismissed. Depending on the campaign, we may use limited in-app activity and feature-completion signals, including whether certain tracking actions have been completed, to decide whether to show relevant in-app messages. We do not use the contents of cycle or symptom entries for cross-context behavioral advertising, and we do not sell this information. Where these signals are derived from health-related activity (such as whether tracking actions were completed), they are used for in-app message eligibility only if you have provided the optional health analytics consent, and only to surface relevant app features and health-management information. We never use health-related data for advertising or third-party marketing.
We may also disclose information if required by law, legal process, or to protect rights, safety, and service integrity.
6) Data retention
- We retain account and app data while your account is active.
- Partner Sharing relationship records and selected shared information are retained while needed to provide Partner Sharing and to operate revocation, disconnection, deletion, security, and abuse-prevention controls.
- If you delete your account, we initiate deletion of your account record and associated user data from our primary systems.
- If you delete your account, we also initiate deletion of Partner Sharing relationships, invites, and selected shared information involving your account from our primary systems.
- Limited copies may persist temporarily in backups, logs, and disaster recovery systems before automatic overwrite or expiry.
- Aggregated or de-identified analytics may be retained longer where permitted by law and in accordance with applicable de-identification standards.
7) Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port certain personal information, and to withdraw consent where processing is based on consent. To request a copy of your data in a portable format, contact support@getmymood.com. We will respond within 30 days.
You may also:
- Delete your account in the app settings.
- Request an email confirmation link at /delete-account if you no longer have app access.
- Withdraw health analytics consent at any time in the app in Settings > Account and Data. Health-related analytics will stop immediately; core tracking continues normally.
- Withdraw health data processing consent by deleting your account in Settings > Account and Data > Delete Account.
- Manage ad consent choices where UMP is presented.
- Control notification permissions from device settings.
We do not currently respond to "Do Not Track" browser signals. Where required by law, we honor Global Privacy Control (GPC) signals as opt-out requests.
Canadian users may file a complaint with the Office of the Privacy Commissioner of Canada. Quebec residents may also file a complaint with the Commission d'accès à l'information du Québec. EEA and UK users may lodge a complaint with their local data protection authority.
Washington and Nevada residents: our Consumer Health Data Privacy Policy describes the additional disclosures and rights that apply to consumer health data under Washington's My Health My Data Act and Nevada's consumer health data law, including how to exercise those rights and how to appeal a decision.
To submit a privacy request, contact support@getmymood.com.
8) Children and young users
The Services are intended for users aged 14 and older. We encourage users between 14 and 17 to review this policy with a parent or guardian before using the app.
For all users, including those under 18, the following protections apply by default:
- Ads are non-personalized.
- Analytics data is collected only in bucketed or pseudonymized form. Health-related analytics are collected only with separate, explicit opt-in consent; other usage analytics (such as screen views and reliability diagnostics) are pseudonymous and are never used to build profiles of any user or to target advertising; the only user-level use is the in-app message eligibility described in the next bullet.
- We do not build individual behavioural profiles to target content, features, or recommendations. The only user-level targeting is deciding whether to show an informational in-app message based on limited feature-usage signals, as described in Section 5; the contents of your cycle and symptom entries are never used for this.
- No precise or device-based geolocation is collected, and the app requests no location permissions. Analytics may include coarse, IP-derived approximate location (such as country, region, or city) used only in aggregate; the IP address itself is not stored, and location is never used to profile or target any user.
Where required by applicable law or app-store policy, we use coarse age-range and parent/guardian approval signals from the app store or operating system to help confirm eligibility before health-data features become available, as described in Age assurance in Section 1. We rely on these platform mechanisms rather than collecting exact birth dates, and we do not use these signals for advertising, analytics, or profiling.
For more information about our approach to age-appropriate design, see our AADC Conformance page.
We do not knowingly collect personal information from children under 14. If you believe a child under 14 has provided personal information, contact us so we can take appropriate action.
9) Medical and automated decision notice
The app provides informational cycle tracking features and predictions. It is not intended to provide medical diagnosis or treatment, and we do not use your data for automated decision-making that produces legal or similarly significant effects.
10) Security
We apply reasonable technical and organizational safeguards, including platform-level secure storage (with encryption used wherever available) for locally stored health and session data on mobile devices, pseudonymized analytics identifiers, and authenticated server-side access controls. No system can be guaranteed 100% secure. You are responsible for maintaining the security of your device and account credentials.
If a breach of security involving your personal information creates a risk of harm to you, we will notify you and the applicable regulators without unreasonable delay and within the timelines required by applicable law, including the FTC Health Breach Notification Rule (US), PIPEDA (Canada), Quebec Law 25 (we maintain a register of confidentiality incidents and notify the Commission d'accès à l'information where required), and the GDPR/UK GDPR. Notices will describe what happened, the information involved, any third parties that acquired it, and steps you can take to protect yourself.
11) Third-party policies
Our providers have their own privacy practices. Relevant policies may include Google/Firebase, including Firebase In-App Messaging, AdMob, Amplitude, and RevenueCat policies. We encourage you to review those materials directly.
12) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post updates at /privacy and revise the "Last updated" date above. Material changes may also be communicated in-app or by other appropriate means.
13) Contact us
Email: support@getmymood.com
Privacy Officer (Personne responsable de la protection des renseignements personnels), GetMyMood Inc.: reachable at support@getmymood.com — please include "Privacy" in the subject line.
Mail:
GetMyMood Inc.
2 Bloor Street East, Suite 3500
Toronto, Ontario M4W 1A8
Canada