What data we collect
PMDD Support stores the information you choose to enter, and what the app needs to work: - Your email address, display name and role (the person tracking, or their support partner) - Daily check-ins: each item you rate and its level, plus bleeding and period pain - The optional private question about thoughts of self-harm, if you turn it on - Journal notes, and whether each one is private or shared - Treatments you record, their schedule, and whether you marked each dose taken or skipped - Notes your support partner writes about how your day seemed, if you allow that - Quick signals and acknowledgements sent between linked partners - Couple points earned from using the app together - Notification preferences, your chosen reminder times, and push tokens for your devices - Your device's timezone, so reminders arrive on the right day - Clinician links you create, including when each was opened - Messages you send through the suggestion box We do not collect your address, phone number or payment details, and we do not use location tracking.
Who can see your data
Nothing is visible to anyone else until you link with a partner, and then only at the levels you set. From the Partner page you choose, separately: - Daily check-ins: everything you log, only whether a day felt calmer or harder, or nothing - Your cycle forecast: the window and expected period dates, the window alone, or nothing - Medication: what you take and whether you marked each dose, or nothing Journal notes are private unless you mark one as shared, and you can make a shared note private again at any time. The private question about self-harm is never shared with a partner at any level, and neither is anything you record about treatments beyond the medication setting above. New links start at the most private setting for check-ins and forecast. Medication starts shared, and can be switched off. Disconnecting in the Partner page stops all sharing immediately. We do not sell, rent or share your health data with advertisers, data brokers or analytics providers.
Sharing a record with a clinician
You can create a read-only link to your record to send to a doctor, for example before a phone appointment. You control it entirely: - It expires on a date you choose, and you can turn it off at any moment - You can add a PIN, which you send separately - You can see whether it has been opened, and when A clinician link contains the report only: your daily ratings, your cycles, and your treatments and doses. It does not contain your journal notes, the private question, or anything your partner has written, and none of that is sent to the person opening the link. Anyone holding an active link can open it without an account, so treat it like a key. Turning it off stops it working straight away.
How your data is stored
Data is held in a Supabase Postgres database with row-level security, which limits each account to its own data plus whatever has been shared with it. Those rules are enforced by the database, not only by the app. Connections are encrypted in transit, and Supabase encrypts stored data at rest. We can technically read your data in order to run the service; it is not encrypted in a way that hides it from us. Backups are managed by Supabase under their standard retention policy.
How we use your data
Only to run the app: - Show your history, trends, cycle forecast and report - Share what you have chosen to share with your linked partner - Show the report to anyone holding a clinician link you created - Send the notifications you have turned on, at the times you chose We do not use your data for advertising or profiling, and we do not train anything on it.
Getting a copy of your data
Settings > Your data > Download everything gives you a complete copy: every check-in, note, treatment, dose, plan and setting as a JSON file, plus your daily ratings as a spreadsheet. It is yours to keep and readable without this app. You do not need to ask us for it, and you do not need a reason.
Data retention and deletion
Your data is kept while your account is active. You can delete it permanently at any time from Settings > Your data > Delete account, and the app will tell you exactly what it is about to remove before you confirm. Deletion removes your check-ins, journal notes, private answers, treatments and doses, calm-day plan, signals, couple points, notification settings, devices, clinician links, relationship links and your login. Two things survive, because they are not solely yours: notes your partner wrote in their own account, and any copy a clinician saved or printed from a link before you turned it off. Deleting your account turns off every active link, but we cannot reach a copy already made.
Cookies and local storage
A sign-in cookie keeps you logged in. Your browser's local storage holds small preferences, such as your theme and whether you have seen the walkthrough. Opening a PIN-protected clinician link sets one cookie recording that the PIN was answered, which expires with the link. No tracking or advertising cookies are used. You can clear local preferences from Settings > Your data > Clear local data.
Third-party services
- Supabase: database and authentication (supabase.com/privacy) - Vercel: hosting and the daily cycle-alert job (vercel.com/legal/privacy-policy) - GitHub Actions: triggers the hourly reminder job. It receives no health data; it only asks our server to run - Web push services: notifications are delivered through your device's push service (Apple Push Notification service on iPhone, Firebase Cloud Messaging on Android and Chrome). The notification text passes through these services, so we keep it brief No analytics, advertising or tracking SDKs are used.
Not a medical service
PMDD Support helps you notice patterns, keep a record and communicate. It is not a medical device. It does not diagnose, does not treat, and is not monitored by anyone. The report it produces is a record of what you logged, for a clinician to interpret. It is not an emergency service. If you are in danger, call 000 in Australia or your local emergency number. Lifeline is 13 11 14.
Children
This app is intended for adults. We do not knowingly collect data from anyone under 18.
Changes to this policy
If we make material changes, we will update the date at the top of this page.
Contact
Questions about privacy, or anything here that does not match what you see in the app? Email info@ridethevibe.co.