This is the English version of the Dutch privacy policy. If the English and Dutch texts differ in any way, the Dutch version prevails.
1. Introduction
PMDD Tracker (a product name of FemTech Solutions B.V.) respects your privacy and is responsible for protecting your personal data. This privacy policy describes how we collect, use, store and protect your data when you use the PMDD Tracker app ("the App").
This policy has been drawn up in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, UAVG).
2. Controller
FemTech Solutions B.V. (product: PMDD Tracker)
Email: privacy@pmddtracker.nl
3. What data do we collect?
3.1 Account data
- Email address (for registration and signing in)
- Display name (optional)
- Authentication method (email/password, Apple Sign In or Google Sign In)
If you use Apple Sign In or Google Sign In, we receive your email address and possibly your name from that provider. We do not receive passwords, contacts or any other account data from Apple or Google. Authentication takes place through a secure token mechanism (OAuth 2.0 / OpenID Connect).
3.2 Health data
- Daily symptom scores (21 DRSP items, scale 1-6)
- Interference items (3 items, yes/no)
- Optional: custom symptoms (symptom names you define yourself and daily scores 1-6, max. 10)
- Cycle events (menstruation, spotting)
- Cycle data (start date, length, phase)
- Notes added to daily entries
3.3 Signalling plan
- Personal signals and actions for each cycle phase (follicular phase and luteal days)
- Letter to yourself
- Instructions for the people around you
3.4 Crisis contacts
- Names and telephone numbers of personal crisis contacts
- Relationship to you as the user
3.5 Medication data
- Medication names, dosage, frequency
- Records of doses taken
3.6 App settings
- Theme preference (light/dark/system)
- Notification settings
- Biometric lock (on/off, no biometric data itself)
3.7 Research data (optional)
If you choose to do so, you can make anonymous symptom data available for scientific research into PMDD. The following data is then shared, after it has been fully anonymised:
- Symptom scores (1-6) per relative cycle day (no exact dates)
- Interference items (yes/no)
- Cycle events (menstruation/spotting)
- Cycle lengths
The following data is never shared as part of research data:
- Your name, email address or account ID
- Notes and free text
- Exact dates (relative cycle days only)
- Medication names or dosages
- Crisis contacts
- The contents of your signalling plan
The anonymising happens on your own device, before any data is sent to the server. Once anonymised, the data can no longer be traced back to you as a person (in line with GDPR Recital 26).
3.8 Data we do NOT collect
- We do not collect location data
- We use no analytics or tracking SDKs
- We include no advertising SDKs
- We share no data with advertisers
- We build no user profiles for marketing
4. Legal basis for processing
We process your data on the basis of:
- Consent (Article 6(1)(a) GDPR): you actively give consent when you register
- Performance of the contract (Article 6(1)(b) GDPR): necessary to make the App work
- Special categories of personal data (Article 9(2)(a) GDPR): health data is processed on the basis of your explicit consent
- Donating research data (Article 9(2)(a) GDPR): sharing anonymised symptom data for scientific research takes place solely on the basis of your explicit, separate consent. That consent is entirely voluntary and can be withdrawn at any time via Settings → Contribute to research
5. Where is your data stored?
5.1 Local storage (primary)
The App works offline-first. All data is stored primarily on your own device in an encrypted local database. This data does not leave your device unless you switch on synchronisation.
5.2 Cloud synchronisation (optional)
If you switch on cloud synchronisation, your data is stored on Supabase (PostgreSQL database), hosted on Amazon Web Services in region eu-west-2 (London, United Kingdom).
What does storage in the United Kingdom mean? Since Brexit, the UK has been outside the European Union. However, the European Commission has established that the UK protects personal data just as well as the EU itself does. That decision — an adequacy decision under Article 45 GDPR — was renewed on 19 December 2025 and applies until 27 December 2031. Your data therefore enjoys the same level of protection as it would if it were stored inside the EU, and you keep the same rights. No additional consent from you is required for this storage.
Earlier versions of this policy stated that the data was stored in Frankfurt, Germany. That was incorrect: the database has been located in London since the project was created. We corrected this as soon as it was established. No data has been moved, and nothing has changed about who has access to your data.
The connection to the server is encrypted using TLS 1.3. In addition, the App applies field-level encryption to your symptom scores and notes on your own device (AES-256) before they are sent, so they are also stored encrypted at Supabase. Data is stored with Row Level Security (RLS), which means that no other user can reach your data or your key.
The key used for that encryption is tied to your account and is held within your account. This is necessary so that you can read your data on a second device. It also means that this is not end-to-end encryption: because we hold the key, we could technically access your data. We do not do so, and access is limited as described in section 6, but we say it explicitly because "end-to-end" promises something stronger than what we deliver.
6. Security
We take the following measures to protect your data:
- Encryption in transit: TLS 1.3 for all communication with servers
- Field-level encryption on your device: AES-256 for sensitive health data before it is synchronised. See section 5.2 for what this does and does not mean
- Encryption at rest: AES-256 for database storage at Supabase
- Access control: Row Level Security (RLS) — every user sees only their own data
- Optional biometric lock: Face ID / Touch ID / fingerprint
- No debug logging in production: sensitive data is not logged
- Secure authentication: JWT tokens with a short lifetime, OAuth 2.0 for social login (Apple/Google)
7. Retention period
- Active account: Your data is kept for as long as your account is active
- After account deletion: All personal data is permanently deleted within 30 days
- Audit trail: An anonymised log of the deletion is kept for GDPR compliance
8. Anonymous research data
8.1 Purpose
The App gives you the option to contribute anonymous symptom data to scientific research into PMDD. The aim is to help researchers understand PMDD better, which can lead to better care.
8.2 Your choice
Taking part is entirely voluntary and is off by default. You can give or withdraw your consent at any time via Settings → Contribute to research. Not taking part has no effect whatsoever on how the App works.
8.3 How the data is anonymised
Before any data is shared, it is anonymised on your own device. That means:
- Your account ID, name and email address are removed
- Exact dates are converted into relative cycle days (day 1, day 2, and so on)
- Notes, medication names, crisis contacts and the contents of your signalling plan are removed entirely
- Only numerical symptom scores (1-6), interference items and cycle events are shared
Once anonymised, the data no longer falls under the GDPR (Recital 26), because it can no longer be traced back to an identified or identifiable person.
8.4 Where research data is stored
Anonymised research data is held in a separate, shielded database schema within our Supabase infrastructure in London (United Kingdom). That schema cannot be reached through the regular API and is accessible only through secured server functions.
8.5 Withdrawing consent
You can withdraw your consent at any time via Settings → Contribute to research. No new data is shared after that. Data already donated is fully anonymous and cannot be traced or deleted, because no link to your account remains. We say this explicitly because it is a genuine limitation: withdrawal works forwards, not backwards.
8.6 Recording your consent
When you give consent, we record which version of the consent text applied. If the research policy changes substantially, we will ask for your consent again.
9. Your rights
Under the GDPR you have the following rights:
- Right of access (Article 15 GDPR): You can request which data we process about you
- Right to rectification (Article 16 GDPR): You can have incorrect data corrected
- Right to erasure (Article 17 GDPR): You can delete your account and all associated data via Settings → Delete account
- Right to data portability (Article 20 GDPR): You can export all of your data as a PDF report or in a structured format
- Right to restriction of processing (Article 18 GDPR): You can request that the processing of your data be restricted
- Right to withdraw consent: By deleting your account, or for research data via Settings → Contribute to research
- Right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (088-1805250)
10. Sharing with third parties
We do not share your data with third parties, with the exception of:
| Sub-processor | Service | Location | Purpose |
|---|---|---|---|
| Supabase Inc. | Database & authentication | United Kingdom (London), covered by the EU adequacy decision | Cloud synchronisation and account management |
| Resend (Plus Five Five, Inc.) | Email delivery | United States, with EU Standard Contractual Clauses | Newsletter and service emails |
| Apple Inc. | Sign in with Apple | US (with EU Standard Contractual Clauses) | Optional authentication via Apple ID |
| Google LLC | Google Sign-In | US (with EU Standard Contractual Clauses) | Optional authentication via a Google account |
A data processing agreement (DPA) has been concluded with Supabase Inc. and with Resend. Resend processes only your email address and delivery data; no health data goes to Resend. Because Resend processes data in the United States, for which no adequacy decision applies, that transfer rests on the Standard Contractual Clauses in their data processing agreement. If you use Apple Sign In or Google Sign-In, Apple and Google respectively act as an independent controller for the authentication on their own platform. We receive only a one-time authentication token and your email address. Apple and Google have no access to your health data in the App.
You can generate PDF reports yourself and share them with your healthcare provider: this happens solely on your own initiative.
11. Cookies and tracking
The App uses no cookies, tracking pixels or comparable technologies. No analytics are collected.
12. Children
The App is not intended for children under the age of 16. We do not knowingly collect data from children. If we discover that we have collected data from a child, we will delete it immediately.
13. Changes to this policy
We may update this privacy policy from time to time. In the event of substantial changes, we will inform you through the App.
14. Contact
For questions about this privacy policy, or to exercise your rights:
FemTech Solutions B.V. (product: PMDD Tracker)
Email: privacy@pmddtracker.nl
Website: https://pmddtracker.nl
FemTech Solutions B.V. (product: PMDD Tracker)
Last updated: 29 July 2026