Privacy Policy
Scope
This privacy policy applies to PCOS Lab, including the Android package com.pcoslab.app. It explains how Herazur accesses, collects, uses, shares, retains, and deletes user data for this app.
If you also use another app from the same developer, please review the app-specific page for that product because data practices can differ.
Privacy Policy
Information we collect
Health records stored on your device
Everything you enter is written to the app’s private storage on your phone: cycle and bleeding days, symptom entries, meals and what they were made of, weight if you choose to record it, notes you type, experiments (what you tried, the dose, the dates, why you stopped), lab results you type in, and your settings such as which symptoms you track, reminder time, units, theme and language. This is health information, and in most places it is treated as a special category of personal data; on your device it is protected by your phone’s app sandbox and by whatever device encryption you have enabled. With every switch left off, this is the whole of it: we have no copy and no way to obtain one.
Account information, only if you create an account
If you choose to sign up, we store the email address you register with — or the address and display name your Google account provides — together with an account identifier, through Firebase Authentication acting as our processor. That is all an account is for. It unlocks no feature, it is not required to use the app, and creating one uploads none of your health records. Legal basis (GDPR / KVKK): performance of the service you asked for, Art. 6(1)(b) GDPR.
Cloud backup of your records, only if you turn it on
With backup switched on, a copy of the days you logged (symptoms, flow, weight, notes and meals), your experiments, your lab results and your tracked-symptom list is kept in your account in Google Cloud Firestore, in the eur3 multi-region (Belgium and the Netherlands); the data does not leave the European Union at rest. Your reminder time, theme and language are not sent. Only your own signed-in account can read it: the Firestore security rules admit a request only when the authenticated user id matches the owner of the record, and there is no administrative path, no shared collection and no query that spans users. Switching backup off deletes the cloud copy and stops anything further being sent, leaving what is on your phone exactly as it is. Legal basis: your explicit consent to the processing of health data, Art. 9(2)(a) GDPR.
Usage analytics, only if you turn it on
A switch of its own, off by default. Usage analytics records which screens and features are opened, and how often — for example that a day was logged, or that an export was taken — through Firebase Analytics acting as our processor. It cannot carry anything you logged: the app can send only a fixed list of event names and, at most, a count of your own records, with no free-text field and no way to pass a value, so a symptom, weight, note, date or lab value cannot reach analytics even by mistake. Legal basis: your consent, Art. 6(1)(a) GDPR, withdrawable at any time.
Crash reports, only if you turn them on
A second, separate switch, also off by default; turning analytics on does not turn this on. If the app crashes, Firebase Crashlytics sends the technical stack trace and your device model and operating system version, so the fault can be found and fixed. Nothing you typed is attached, and no account identifier is attached. Switching either sharing switch off stops collection at the SDK level — not merely our own calls — and deletes anything captured that has not yet been sent. Legal basis: your consent, Art. 6(1)(a) GDPR, withdrawable at any time.
Subscription status, only if you subscribe to Pro
Pro is an optional paid tier. It needs no account in this app and changes nothing about what is stored or uploaded. Until you open the Pro screen, nothing about payments runs at all: the purchase library is not started and no payments company is contacted; if you already subscribe it starts at launch instead, to check whether the subscription is still active. The payment is handled entirely by Apple or Google, and the app never sees your card number, your billing address or your name. RevenueCat sits between the app and the store and answers one question — whether this installation’s subscription is active — receiving a random identifier it generates for the installation, the store’s own purchase receipt, and the device and country information the store attaches to it. It is never told your email address, your account in this app, or anything you have logged. Attribution and advertising-identifier collection are switched off in that library, and no advertising identifier is read.
Exports and shares you start yourself
Data leaves your phone in no other way than when you deliberately send it: an export as CSV or JSON, a PDF summary for an appointment, or a shared progress card, which renders an image containing only aggregate numbers and shows it to you before anything is shared. Each is built on the device and handed to your phone’s share sheet; where it goes next is your choice, and that destination’s own privacy policy then applies — your email provider, cloud drive or messaging app. We are not a party to it and cannot see it.
Reminder and notification preferences
This includes whether you opt in to reminders and the schedules or settings required to deliver those reminders.
Privacy Policy
How we use information
Store records locally on your device
Some apps are designed to keep your records on-device so core functionality works without maintaining a remote user database.
Give you an account, and a backup if you ask for one
An account exists so that a cloud copy can belong to someone. Cloud backup exists so your records survive a lost or replaced phone and follow you to another device. Both are optional, both are off until you switch them on, and each can be switched back off in the same place you turned it on.
Deliver reminders and notifications
We use reminder settings to schedule the notifications you ask the app to send.
Improve product quality and performance
We use analytics and diagnostics to understand reliability, troubleshoot issues, and improve app experience.
Manage premium subscriptions
We use billing and entitlement data to sell, restore, validate, and manage premium access.
Respond to support and deletion requests
We use contact and account details to verify requests, answer support questions, and process privacy-related actions.
Meet legal, tax, security, and fraud-prevention obligations
We may process limited data when necessary to comply with law, enforce agreements, prevent abuse, or protect users and the service.
Privacy Policy
Permissions and sensitive access
Notifications
If you turn on the daily check-in reminder, the app asks your phone to schedule local notifications. These are alarms your device sets for itself: no push server is involved and no notification content leaves the device. The app requests no camera, microphone, contacts, photos, files or location access.
Privacy Policy
Data retention and deletion
On your device, your records stay until you delete them or delete the app. In your account, the backup copy mirrors what is on your phone and lasts until you turn backup off, delete the records, or delete the account — there is no separate retention period. Analytics and crash reports are kept by Google under Firebase’s own retention settings, and are deleted when you switch the relevant setting off. Subscription status is kept by RevenueCat and by the store for as long as the subscription and their own records require, and contains no health data. With all switches off, and without Pro, no sub-processor receives anything at all.
If you want to delete your account or associated data, use the dedicated account deletion page linked below. Open the PCOS Lab account deletion page.
Privacy Policy
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is perfectly secure.
Privacy Policy
Children's privacy
PCOS Lab is not directed at children under 13, and accounts are not intended for them. The app has no public profiles, no messaging and no user-to-user sharing of any kind. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.
Privacy Policy
Changes to this policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date on this site and, where appropriate, provide additional notice inside the app.
Privacy Policy
Contact
Developer: Herazur
Privacy contact: furkangokaytolucc@gmail.com
Support contact: furkangokaytolucc@gmail.com
Address: Contact by email for mailing address, Turkiye
We aim to respond to verified privacy requests within 30 days.