App-specific policy

PCOS Lab

PCOS Lab is a private cycle, symptom, meal, experiment and lab-result tracker for people with PCOS. By default it collects nothing: no account is created for you, nothing you log is uploaded, and no analytics or crash reporting runs. An account, cloud backup, usage analytics and crash reports are four separate switches, each off until you turn it on yourself. PCOS Lab does not diagnose or treat anything, makes no predictions about your cycle, and does not interpret lab values.

Policy URL/apps/pcos-lab/
Packagecom.pcoslab.app
Last updated2026-09-18

Privacy Policy

Scope

This privacy policy applies to PCOS Lab, including the Android package com.pcoslab.app. It explains how Herazur accesses, collects, uses, shares, retains, and deletes user data for this app.

If you also use another app from the same developer, please review the app-specific page for that product because data practices can differ.

Privacy Policy

Information we collect

Health records stored on your device

Everything you enter is written to the app’s private storage on your phone: cycle and bleeding days, symptom entries, meals and what they were made of, weight if you choose to record it, notes you type, experiments (what you tried, the dose, the dates, why you stopped), lab results you type in, and your settings such as which symptoms you track, reminder time, units, theme and language. This is health information, and in most places it is treated as a special category of personal data; on your device it is protected by your phone’s app sandbox and by whatever device encryption you have enabled. With every switch left off, this is the whole of it: we have no copy and no way to obtain one.

Account information, only if you create an account

If you choose to sign up, we store the email address you register with — or the address and display name your Google account provides — together with an account identifier, through Firebase Authentication acting as our processor. That is all an account is for. It unlocks no feature, it is not required to use the app, and creating one uploads none of your health records. Legal basis (GDPR / KVKK): performance of the service you asked for, Art. 6(1)(b) GDPR.

Cloud backup of your records, only if you turn it on

With backup switched on, a copy of the days you logged (symptoms, flow, weight, notes and meals), your experiments, your lab results and your tracked-symptom list is kept in your account in Google Cloud Firestore, in the eur3 multi-region (Belgium and the Netherlands); the data does not leave the European Union at rest. Your reminder time, theme and language are not sent. Only your own signed-in account can read it: the Firestore security rules admit a request only when the authenticated user id matches the owner of the record, and there is no administrative path, no shared collection and no query that spans users. Switching backup off deletes the cloud copy and stops anything further being sent, leaving what is on your phone exactly as it is. Legal basis: your explicit consent to the processing of health data, Art. 9(2)(a) GDPR.

Usage analytics, only if you turn it on

A switch of its own, off by default. Usage analytics records which screens and features are opened, and how often — for example that a day was logged, or that an export was taken — through Firebase Analytics acting as our processor. It cannot carry anything you logged: the app can send only a fixed list of event names and, at most, a count of your own records, with no free-text field and no way to pass a value, so a symptom, weight, note, date or lab value cannot reach analytics even by mistake. Legal basis: your consent, Art. 6(1)(a) GDPR, withdrawable at any time.

Crash reports, only if you turn them on

A second, separate switch, also off by default; turning analytics on does not turn this on. If the app crashes, Firebase Crashlytics sends the technical stack trace and your device model and operating system version, so the fault can be found and fixed. Nothing you typed is attached, and no account identifier is attached. Switching either sharing switch off stops collection at the SDK level — not merely our own calls — and deletes anything captured that has not yet been sent. Legal basis: your consent, Art. 6(1)(a) GDPR, withdrawable at any time.

Subscription status, only if you subscribe to Pro

Pro is an optional paid tier. It needs no account in this app and changes nothing about what is stored or uploaded. Until you open the Pro screen, nothing about payments runs at all: the purchase library is not started and no payments company is contacted; if you already subscribe it starts at launch instead, to check whether the subscription is still active. The payment is handled entirely by Apple or Google, and the app never sees your card number, your billing address or your name. RevenueCat sits between the app and the store and answers one question — whether this installation’s subscription is active — receiving a random identifier it generates for the installation, the store’s own purchase receipt, and the device and country information the store attaches to it. It is never told your email address, your account in this app, or anything you have logged. Attribution and advertising-identifier collection are switched off in that library, and no advertising identifier is read.

Exports and shares you start yourself

Data leaves your phone in no other way than when you deliberately send it: an export as CSV or JSON, a PDF summary for an appointment, or a shared progress card, which renders an image containing only aggregate numbers and shows it to you before anything is shared. Each is built on the device and handed to your phone’s share sheet; where it goes next is your choice, and that destination’s own privacy policy then applies — your email provider, cloud drive or messaging app. We are not a party to it and cannot see it.

Reminder and notification preferences

This includes whether you opt in to reminders and the schedules or settings required to deliver those reminders.

Privacy Policy

How we use information

Store records locally on your device

Some apps are designed to keep your records on-device so core functionality works without maintaining a remote user database.

Give you an account, and a backup if you ask for one

An account exists so that a cloud copy can belong to someone. Cloud backup exists so your records survive a lost or replaced phone and follow you to another device. Both are optional, both are off until you switch them on, and each can be switched back off in the same place you turned it on.

Deliver reminders and notifications

We use reminder settings to schedule the notifications you ask the app to send.

Improve product quality and performance

We use analytics and diagnostics to understand reliability, troubleshoot issues, and improve app experience.

Manage premium subscriptions

We use billing and entitlement data to sell, restore, validate, and manage premium access.

Respond to support and deletion requests

We use contact and account details to verify requests, answer support questions, and process privacy-related actions.

Meet legal, tax, security, and fraud-prevention obligations

We may process limited data when necessary to comply with law, enforce agreements, prevent abuse, or protect users and the service.

Privacy Policy

Sharing and service providers

We may share data only with service providers or infrastructure needed to deliver the features you request, process payments, maintain security, or comply with law. We do not sell personal and sensitive user data.

Firebase Authentication

account sign-in and account security

Google Sign-In

optional account login provider

Google Cloud Firestore (eur3 multi-region, EU)

holding the backup copy of your records inside your own account, only while cloud backup is switched on; https://firebase.google.com/support/privacy

Firebase Analytics

product analytics and engagement measurement

Firebase Crashlytics (Google)

crash stack traces plus device model and OS version, only while crash reporting is switched on; https://firebase.google.com/support/privacy

RevenueCat, Inc. (United States)

telling the app whether a Pro subscription is active, from a random installation identifier and the store receipt; it receives no account and no health data; https://www.revenuecat.com/privacy/

Google Play Billing / app store billing infrastructure

purchase processing, restore flows, and subscription validation

On-device storage

storing settings, records, and other content locally on your device

Local notification services

scheduling reminders you configure inside the app

Privacy Policy

Permissions and sensitive access

Notifications

If you turn on the daily check-in reminder, the app asks your phone to schedule local notifications. These are alarms your device sets for itself: no push server is involved and no notification content leaves the device. The app requests no camera, microphone, contacts, photos, files or location access.

Privacy Policy

Data retention and deletion

On your device, your records stay until you delete them or delete the app. In your account, the backup copy mirrors what is on your phone and lasts until you turn backup off, delete the records, or delete the account — there is no separate retention period. Analytics and crash reports are kept by Google under Firebase’s own retention settings, and are deleted when you switch the relevant setting off. Subscription status is kept by RevenueCat and by the store for as long as the subscription and their own records require, and contains no health data. With all switches off, and without Pro, no sub-processor receives anything at all.

If you want to delete your account or associated data, use the dedicated account deletion page linked below. Open the PCOS Lab account deletion page.

Privacy Policy

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is perfectly secure.

Privacy Policy

Children's privacy

PCOS Lab is not directed at children under 13, and accounts are not intended for them. The app has no public profiles, no messaging and no user-to-user sharing of any kind. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.

Privacy Policy

Changes to this policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date on this site and, where appropriate, provide additional notice inside the app.

Privacy Policy

Contact

Developer: Herazur

Privacy contact: furkangokaytolucc@gmail.com

Support contact: furkangokaytolucc@gmail.com

Address: Contact by email for mailing address, Turkiye

We aim to respond to verified privacy requests within 30 days.