Last updated 19 August 2026
This is a standalone policy about consumer health data, published separately from our general Privacy Policy as required by Washington State's My Health My Data Act and Nevada's SB 370. If you're in Washington or Nevada, this policy is for you — though everything in it is true for everyone who uses SapphicTides.
| Category | What it is | Can we read it? |
|---|---|---|
| Menstrual and reproductive data | Period start and end dates, cycle length, flow-related symptoms, and predicted phases derived from your own history | No — encrypted on your device |
| Bodily functions and symptoms | Cramps, headaches, energy, sleep, cravings and anything else you choose to log | No — encrypted on your device |
| Mental and emotional state | Moods, needs, weekly relationship check-ins, notes and journal entries | No — encrypted on your device |
| The fact that you use this app | Your email address, and that it belongs to a SapphicTides account | Yes — this is the only health-adjacent thing we can actually see |
Only from you, typed into the app. We do not buy health data, receive it from data brokers, infer it from your behaviour, or collect it from any other app, device or service. SapphicTides does not connect to Apple Health or Google Fit and cannot read from them.
To show it back to you, to calculate your cycle estimates on your own device, and — if you've paired with someone — to sync it to their device so they can see it. That is the complete list of purposes.
We do not use it for advertising, profiling, research, product analytics, model training, or any purpose other than running the app for you.
Nobody. There is no third party that receives your consumer health data in readable form, because it does not exist in readable form outside your own devices.
Two parties handle the encrypted form of it:
| Who | What they hold | What they can read |
|---|---|---|
| Supabase (database hosting, Toronto, Canada) | Your email address, and your entries as encrypted blobs | Your email address only |
| Apple Push Notification service / Firebase Cloud Messaging | A device token and a one-word event type such as "checkin" | That something happened — never what |
We have never sold consumer health data and we do not. Selling it would require your signed authorization under Washington law; we have no mechanism to obtain one because we have no intention of asking.
Pairing is sharing, and it's the one disclosure that actually happens. When you invite someone and they accept, entries you write from then on become readable on their device. Entries written before you paired stay private unless you explicitly choose to share them, and notes you have locked stay private regardless. You choose this, deliberately, twice — once when you send the invite and once when you decide what to do with your earlier entries.
Until you delete it. Deleting an entry removes it from both devices. Deleting your account removes your account immediately; if you were the last person in a shared space, every entry in that space is deleted with it. There is no grace period and no archived copy.
Under Washington's My Health My Data Act, Nevada SB 370, and equivalent laws elsewhere, you have the right to:
We'll respond within 45 days, and usually far sooner. There's no charge.
Nobody can access your consumer health data, because it isn't readable. Access to the systems that store the encrypted form is limited to the people who operate the service — currently one person, the founder — protected by multi-factor authentication.
Privacy Officer
privacy@sapphictides.com
SapphicTides · Canada