Legal

Privacy Policy

How Appify sp. z o.o. collects, uses, discloses and protects information in connection with the Ovify mobile application.

Last updated: 2026-07-29

This Privacy Policy describes how Appify sp. z o.o. ("we", "us", "our") collects, uses, discloses and protects information in connection with the Ovify mobile application (the "App"). By installing or using the App you acknowledge that you have read and understood this Policy.

This Policy is intended to comply with the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive consumer-privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Jersey, New Hampshire, Nebraska, Minnesota, Tennessee and Indiana.

1. Who we are

Appify sp. z o.o. is a limited liability company organized under the laws of the Republic of Poland. We are the data controller under the GDPR and the "business" under the CCPA/CPRA for the personal data described in this Policy.

Because Appify sp. z o.o. is established in the European Union, we are not required to appoint a representative in the Union under Article 27 GDPR.

2. Scope

This Policy covers the App, the ovify.app website, and any related services we provide directly. It does not cover third-party services that you access through the App, which are governed by their own privacy policies (see Section 7).

3. The information we collect

The App is designed as a local-first product. We intentionally minimize the personal data we collect and process.

3.1 Information you provide that stays on your device

The categories below are stored exclusively on your device in a local Hive database, protected by iOS's built-in device encryption (data is encrypted at rest while your device is locked) and the App's sandbox. They are never transmitted to us, and we have no technical ability to read them — we operate no server that stores user data.

3.2 Information that necessarily leaves your device when you use certain features

Some features cannot function locally. These are summarized here and detailed in Section 7.

3.3 Information collected automatically

The App does not contain third-party analytics SDKs, advertising SDKs, or behavioral-tracking tools. The App does not collect the Apple Identifier for Advertisers (IDFA), or any comparable identifier. The App does not share your data with advertising networks.

The App does not send crash reports to us. (Apple may collect crash diagnostics under your device's "Share With App Developers" analytics setting, governed by Apple's privacy policy; we do not integrate any crash-reporting SDK of our own.)

3.4 Special-category / sensitive personal information

Under GDPR Article 9, data concerning health, sex life and sexual orientation is "special category" personal data. Under the CPRA, precise health data is "sensitive personal information" (SPI). We treat all cycle, symptom, STM, contraception, medication, chat and Apple Health data as special-category / sensitive data and apply heightened protections: it is stored locally, never sold, never used for profiling, and only transmitted off your device when you actively use a feature that requires it.

3.5 The Ovify website

Sections 3.1 to 3.4 concern the App. This subsection concerns ovify.app, the website you are reading now, which is a set of static pages hosted on Cloudflare's global network. The site runs no analytics, contains no advertising or behavioral-tracking scripts, and loads no third-party resources — the fonts are served from our own domain, so reading these pages does not disclose your visit to Google or anyone else.

The site sets no cookies. It writes two short values to your browser's local storage, in each case only as the direct result of an action you take:

Neither value is transmitted to us, neither is readable by any other website, and neither is used to identify, profile or track you. Because each is written only in response to a deliberate choice you made, and serves only to give effect to that choice, both fall within the exemption for storage that is strictly necessary to provide a service you have requested; we therefore do not present a cookie-consent banner. You can erase both at any time through your browser's site-data controls, and the site will continue to work exactly as before.

As with any website, your browser necessarily discloses standard request information — including your IP address, user agent and the address of the page requested — to our hosting provider, Cloudflare, Inc., in order for the page to be delivered to you. Cloudflare processes this on our behalf for connectivity, caching and security purposes (see Section 7). We do not receive visitor-level logs from Cloudflare, and none of this information is used for tracking or profiling.

4. How we use your information

We use personal data only for the following purposes.

PurposeCategories usedLegal basis under GDPR
Provide cycle, symptom, STM and contraception trackingCycle, symptom, STM, contraception, medication dataArt. 6(1)(b) performance of a contract; Art. 9(2)(a) explicit consent for health data
Generate local notifications and remindersSettings, schedulesArt. 6(1)(b) performance of a contract
Provide the Ovify AI assistant when usedMessages and limited context you choose to shareArt. 6(1)(a) consent; Art. 9(2)(a) explicit consent for health data
Generate insights, charts and daily guidanceCycle, symptom, STM data — processed entirely on your deviceArt. 6(1)(b) performance of a contract; Art. 9(2)(a) explicit consent
Process subscriptions and free trialsPurchase receipts, anonymized identifiersArt. 6(1)(b) performance of a contract
Maintain App security (PIN / biometric lock)Authentication stateArt. 6(1)(f) legitimate interests
Export and backup your data at your requestFull cycle / symptom / settings exportArt. 6(1)(b) performance of a contract
Comply with legal obligationsAs required by lawArt. 6(1)(c) legal obligation

We do not use your personal data for advertising, for cross-context behavioral advertising, for automated decision-making with legal or similarly significant effects, or for training artificial-intelligence models.

5. Sharing and disclosure

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising within the meaning of the CCPA/CPRA. In the past 12 months, we have not sold or shared any category of personal data.

We disclose personal data only:

5.1 Government and law-enforcement requests for reproductive-health data

Because of the App's local-first architecture, we do not possess your cycle, symptom, fertility, contraception, chat or any other health data, and therefore cannot produce it in response to a subpoena, court order, warrant or other legal demand — from any government, in any country. There is no server-side copy for anyone to request. Data that exists only on your device is subject to your device's protections and to legal process directed at you or at Apple (for device backups you have enabled), not at us.

The only records about you that we or our processors hold are the subscription/transaction records described in Section 3.2 (held by Apple and RevenueCat). If we ever receive a legal demand, we will: (a) verify its legal validity; (b) narrow or challenge requests that are overbroad or unlawful where we have standing; (c) notify you before responding unless legally prohibited; and (d) never voluntarily disclose any data for the purpose of investigating or prosecuting a person for seeking, obtaining, providing or facilitating reproductive health care.

6. Storage, security and retention

6.1 Storage

Cycle, symptom, STM, contraception, medication, settings, chat and engagement data is stored locally on your device in a Hive database. On iOS the App is sandboxed and the database is subject to the device's full-disk encryption while the device is locked.

6.2 Security

We apply commercially reasonable technical and organizational safeguards:

No method of transmission or storage is completely secure. You remain responsible for the physical security of your device and for any backups you create.

Breach notification. Because we hold no user health data, a breach of our systems cannot expose it. If, despite this architecture, identifiable data within our control (for example, support correspondence or subscription records accessible to us) is ever acquired without authorization, we will notify affected users and the appropriate authorities as required by applicable law — including, where applicable, the FTC Health Breach Notification Rule (16 CFR Part 318), state breach-notification statutes, and GDPR Articles 33–34.

6.3 Retention

7. Processors and third-party services

ServicePurposeProviderLink
Apple App Store + In-App PurchaseApp distribution and payment processingApple Inc. (USA / Ireland)apple.com/legal/privacy
RevenueCatSubscription state and entitlement verification (receives: anonymous app user ID, transaction/subscription state, device type and OS version, IP address; never health data)RevenueCat, Inc. (USA)revenuecat.com/privacy
Apple Foundation Models (on-device)Ovify AI assistant — processed by the on-device language model via Apple's LanguageModelSession APIApple Inc.apple.com/legal/privacy
Apple HealthKitRead / optional write of health metrics on deviceApple Inc.apple.com/legal/privacy
Device calendar (if enabled)Write predicted period / ovulation eventsYour installed calendar providers—
Website hosting (ovify.app)Delivery, caching and security of the static website; receives standard request data (IP address, user agent, requested URL) as a technical necessity of serving the pageCloudflare, Inc. (USA)cloudflare.com/privacypolicy

8. International transfers

The processors listed in Section 7 are based in the United States. For transfers of personal data from the European Economic Area to those processors we rely on the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where the recipient is self-certified, and on the Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914) with supplementary technical and organizational measures otherwise. You may request a copy of the relevant transfer-mechanism documentation through the contact details in Section 12.

9. Your rights

9.1 Rights available to everyone, directly in the App

Because the App is local-first, the quickest way to exercise most rights is through the App itself:

9.2 Additional rights — European Economic Area and Switzerland (GDPR)

You have the right to:

If you are resident in Poland, the competent supervisory authority is the Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office, "UODO"), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl. You may also lodge a complaint with the supervisory authority of the EU/EEA Member State of your habitual residence or place of work. If you are resident in Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch.

9.3 Additional rights — California (CCPA/CPRA)

Californian residents have the right to:

9.4 Additional rights — other U.S. states

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware (DPDPA), Iowa (ICDPA), New Jersey (NJDPA), New Hampshire (NHPA), Nebraska (NDPA), Minnesota (MCDPA), Tennessee (TIPA) and Indiana (ICDPA) — among others — have similar rights, including the right to appeal a denial of a privacy request. You may exercise them by using the in-app controls or by contacting us.

9.5 Consumer health data — Washington, Nevada and Connecticut

This subsection serves as our Consumer Health Data Privacy Policy for the purposes of the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 (NRS 603A.500 et seq.) and the health-data provisions of the Connecticut Data Privacy Act.

9.6 How to exercise rights that require our involvement

For any right that cannot be exercised through the App, write to support@ovify.app with the subject line "Privacy request". We will respond:

We may request information reasonably necessary to verify your identity and the scope of your request. We will not discriminate against you for exercising any right.

10. Children's privacy

The App is not directed at children under 16 in the European Economic Area and Switzerland, or under 13 in the United States (COPPA). We do not knowingly collect personal information from a child. If you believe a child has provided personal information to the App, please contact us and we will delete the data.

If you are between 13 and 17 in the United States, or between 16 and 17 in the EEA / Switzerland, you may use the App only with the consent of a parent or legal guardian.

11. Changes to this Policy

We may update this Policy to reflect changes in the App or in applicable law. The "Last updated" date at the top of this Policy indicates the most recent version. Material changes will be brought to your attention in the App before they take effect. Continued use of the App after the effective date of a new Policy constitutes acceptance of the revised Policy, to the extent permitted by law.

12. Contact

To contact us about this Policy, exercise a right, or ask a question:

Appify sp. z o.o.
ul. Marcina Kasprzaka 31/119
01-234 Warsaw, Poland
KRS: 0001238642 — NIP: 5273217273 — Share capital: PLN 5,000
support@ovify.app