S Seori Labs
PrivacyTermsSupport
Back to Seori Labs

Cycle Pair Privacy Policy

Cycle Pair Privacy Policy

This policy applies to “Cycle Pair” (package com.seorilabs.cyclepair, the “App”), provided by Seori Labs. The App helps two people share cycle and daily condition information to the extent the author allows. It is not a medical, diagnostic, contraceptive, or fertility-prediction tool. When the App’s actual data handling or store disclosures differ from our general policy, this product-specific policy controls.

Effective and last updated: August 9, 2026
Language
  • 한국어
  • English

Data the App Processes

Account identifiers: at sign-in we process an authentication account identifier and email address for authentication and pair linking. We do not combine them with advertising identifiers.

Sensitive health data: period start and end dates, symptoms, mood, condition, support preferences, and notes are entered by you. These original entries are stored as owner-private documents accessible only to their author and are enforced by Security Rules.

Partner projections: only the fields you switch on are written to a separate projection and delivered to exactly one linked partner. Everything is private by default, and original entries are never exposed to a partner.

Invitation codes: generated by the App for pair linking and stored as a hash. They are single-use, expire after 24 hours, and are deleted 7 days after expiry.

Notification tokens: if you allow notifications, we store only the device push token. Lock-screen text uses neutral wording and never contains health information.

Subscription entitlements: if you subscribe, we store only the server-validated receipt result and entitlement or refund status; clients cannot write it directly. We do not collect payment card or bank account details.

Diagnostics and usage data: we process non-sensitive activity events and crash and performance diagnostics to monitor reliability and flows. They exclude period dates, symptoms, cycle phase, and free text.

The App does not collect advertising identifiers or behavioural tracking, precise location, contacts, photos, microphone recordings, or any fertility, ovulation, or contraception determination.

Purposes and Basis of Processing

Sensitive health data is processed on the basis of your explicit consent to provide the App’s core journaling features. You may withdraw consent and stop recording and sharing at any time.

Partner sharing is processed only within the scope you switch on, to carry out the sharing you requested. Sharing consent can be withdrawn per field at any time.

Account identifiers and subscription data are processed to authenticate you, check and restore entitlements, validate purchases, apply refunds, prevent fraudulent transactions, and meet legal obligations.

Diagnostics and usage data are processed to monitor reliability and improve features.

Processors and International Transfers

Seori Labs does not sell personal data and does not share it for marketing or advertising.

Google Firebase and Google Cloud (Authentication, Firestore, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, Performance, App Check) process data as our processors for authentication, storage, server processing, notifications, and diagnostics. Google Play and the Apple App Store process subscription payments and receipt validation.

Cloud Functions run in the Seoul region (asia-northeast3) and the default Firestore database runs in the United States multi-region (nam5). Stored entries are therefore transferred to and processed in the United States. Global services such as Firebase Authentication follow Google’s data-location policy.

Data sent to servers is encrypted in transit with HTTPS/TLS.

Retention and Deletion

When you delete your account, the server recursively deletes your entries, the pair relationship and partner projections, invitation codes, notification tokens, subscription entitlement documents, and the authentication account. See the account deletion page for the full procedure.

Invitation codes are retained for 7 days after expiry and acknowledged cache tombstones for 30 days, then deleted automatically.

When a pair is unlinked, we retain an unlink record to prevent reuse of the released pair identifier and incorrect re-linking. It contains only the pair identifier, both members’ account identifiers, and the unlink time and actor; it contains no health entries. Deleting your account also deletes the unlink records for pairs your account belonged to.

Data remaining in backups is destroyed within 30 days of the deletion request.

Subscription transaction records are retained for the period required by applicable consumer-protection and e-commerce law, then deleted or de-identified.

If you cannot use the App, send access or deletion requests to cs@seorilabs.com. We may request the minimum information needed to verify your identity and prevent deletion of another person’s data.

How Partner Sharing Works

A pair is exactly two people who each explicitly accept the link. You can keep your own entries before linking.

A partner receives only the fields you switch on, as a projection. Original entries are never delivered.

Switching sharing off or unlinking the pair immediately revokes that partner’s server access. A newly linked pair does not inherit previous sharing consent and starts fully private.

Security Measures

Original sensitive entries and offline changes are never stored in plaintext on the device; they are protected by OS secure storage such as the Keychain.

For every request the server verifies authentication, the target identifier, and where required recent re-authentication, sharing settings, partner signatures, and single-use tickets.

App Check (Play Integrity / App Attest) is applied to prevent abuse by tampered clients.

The App does not provide end-to-end encryption. Data is protected by encryption in transit and at rest together with access control.

Children and Minimum Age

The App is offered to people aged 17 and over. It is not directed to users under 17, and we do not knowingly collect personal data from children.

Minors should use in-app subscriptions only with a guardian’s consent and the payment protections configured on the device and store account.

Changes and Contact

If data handling changes, we will update this page and the App’s store privacy disclosures together. We will announce material changes before they take effect.

Privacy and App support: cs@seorilabs.com

This product-specific policy is linked from the App privacy disclosures on Google Play and the Apple App Store.

cs@seorilabs.com