Privacy policy
CYNC PRIVACY POLICY
Last Updated: July 6, 2026
CYNC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the CYNC mobile application (the "App") and related services (collectively, the "Services").
By using CYNC, you agree to the collection and use of information in accordance with this Privacy Policy.
1. INFORMATION WE COLLECT
1.1 Information You Provide to Us
Health and Wellness Data:
- Menstrual cycle information (period start/end dates, cycle length, flow intensity)
- Symptom tracking (mood, energy levels, physical symptoms, pain levels)
- Daily check-in responses (how you're feeling, energy levels, sleep quality)
- Manual activity logs (workouts, exercise type, duration, intensity)
- Nutrition preferences and dietary information
- Mindfulness and meditation session data
- Personal wellness goals and preferences
Account Information:
- Email address (for account creation and communication)
- Username (optional display name)
- Password (encrypted and never stored in plain text)
- Account preferences and settings
Optional Information:
- Wearable device data (if you choose to connect Apple Health, Oura, Whoop, or similar devices)
- Profile information (age range, fitness level, wellness goals)
- Feedback, survey responses, and support communications
1.2 Information Collected Automatically
Device and Usage Information:
- Device type, operating system, and version
- App version and unique device identifiers
- App usage data (features used, session duration, interaction patterns)
- Crash logs and diagnostic information (to improve app stability)
- IP address (temporarily, for security purposes only)
Analytics Data:
- Feature usage patterns (which features you use and when)
- Performance metrics (load times, errors, crashes)
- Aggregated, anonymized usage statistics
1.3 Information We Do NOT Collect
We explicitly do not collect:
- Your real name (unless you choose to provide it)
- Physical address or precise location data
- Social security number or government-issued ID
- Financial information (payments processed by Apple App Store)
- Contact lists or phone numbers
- Photos or camera access (unless you explicitly grant for specific features)
- Microphone access
- Browsing history outside the App
2. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
2.1 To Provide and Improve the Services
- Generate personalized daily wellness plans (movement, nutrition, mindfulness)
- Predict menstrual cycle phases and provide cycle-based recommendations
- Track patterns and provide insights about your cycle
- Personalize workout recommendations based on your cycle phase
- Customize nutrition guidance based on your hormonal phase
- Deliver guided meditation and breathwork sessions
- Integrate wearable device data for enhanced personalization
- Improve app functionality and user experience
- Develop new features based on aggregated usage patterns
2.2 To Communicate with You
- Send account-related notifications (password resets, account changes)
- Provide customer support and respond to your inquiries
- Send educational content about cycle awareness and wellness (if you opt in)
- Notify you of app updates or new features
- Request feedback or participation in surveys (optional)
2.3 To Ensure Security and Prevent Fraud
- Authenticate your identity and secure your account
- Detect, investigate, and prevent fraudulent or malicious activity
- Monitor for security threats and protect against unauthorized access
- Comply with legal obligations and enforce our Terms of Service
2.4 For Analytics and Research
- Analyze aggregated, de-identified data to understand usage patterns
- Conduct research to improve cycle-aware wellness recommendations
- Generate anonymized statistics for internal business purposes
- Note: We never sell or share individually identifiable data for research
3. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
We may share information only in the following limited circumstances:
3.1 Service Providers
We share data only with the service providers needed to run CYNC, under contracts that limit their use of it:
- Cloud infrastructure (Amazon Web Services) — encrypted storage and processing of your account and health data.
- AI features (e.g. for CYNC Chat and insights) — receive only the minimum content needed to answer a request; they do not receive your identity or your full health record, and may not use your data to train their models.
- Analytics and crash reporting — receive only de-identified technical and usage data. They never receive your health data, lab results, or clinical records.
- Payments (Apple App Store) — processes your subscription and payment. We never receive or store your full payment details.
- Subscription management (RevenueCat) — helps us manage and validate your subscription status. It receives a pseudonymous account identifier and your purchase/renewal status only; it does not receive your health data, lab results, clinical records, or full payment details.
We do not sell, rent, or share your personal or health information with third parties for their own marketing, and we do not share your health data with advertising networks or data brokers.
3.2 Apple Health and Clinical Health Records
With your explicit permission, CYNC can read health information from Apple Health on your device:
- Health metrics (optional): activity, heart rate, sleep, and reproductive-health data you choose to share, used to personalize your daily plan and cycle insights.
- Clinical health records / lab results (optional): if your healthcare provider makes your lab results available in Apple Health, you can import them into CYNC. We read these records read-only — CYNC never writes to or modifies your clinical records. Imported lab results (for example hormone, thyroid, iron, and vitamin levels) are used solely to display and explain your biomarkers in the context of your cycle phase.
All data read from Apple Health — including clinical health records — flows one way, from your device into your private CYNC account. We never use Apple Health data (including clinical health records) for advertising or marketing, never share it with advertisers, data brokers, or any third party for their own purposes, and never sell it.
Our use and transfer of information received from Apple Health adhere to the Apple Health (HealthKit) requirements, including the restrictions against using HealthKit data for advertising or sharing it with third parties for advertising or data-mining purposes.
You can disconnect Apple Health at any time in the Health app, and you can delete imported lab results from within CYNC at any time.
3.3 Legal Requirements
We may disclose information if required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service or investigate potential violations
- Protect the rights, property, or safety of CYNC, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
Important: We will anonymize data wherever possible before sharing for legal purposes. We cannot connect cycle data to identity without additional identifiers.
3.4 Business Transfers
If CYNC is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different Privacy Policy.
3.5 With Your Consent
We may share information with third parties when you explicitly consent or direct us to do so.
4. DATA SECURITY
We take your data security seriously and implement industry-standard measures to protect your information:
4.1 Encryption
- In Transit: All data transmitted between your device and our servers uses TLS 1.2+ encryption
- At Rest: All data stored in our database is encrypted using AES-256 encryption
- HIPAA-Grade Security: We apply HIPAA-grade security practices to your health information
4.2 Access Controls
- Multi-factor authentication for all team members accessing systems
- Role-based access controls (team members access only what they need)
- Regular security audits and penetration testing
- Automatic session timeouts and secure password requirements
4.3 Anonymization
- Your cycle data is stored separately from identifiable information (email, username)
- We cannot connect a cycle record to a specific person without cross-referencing multiple databases
- Even in the event of a data breach, health data cannot be tied to individuals
4.4 Data Integrity
- Regular automated backups
- Disaster recovery procedures
- Monitoring for unusual activity or unauthorized access
Important Security Note: While we implement strong security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data using industry best practices.
4.5 Regulatory Compliance
We apply HIPAA-grade security practices to your health information, including AES-256 encryption in transit and at rest. CYNC is a direct-to-consumer wellness app and is not a HIPAA "covered entity," but we treat your health data with that standard of care. We handle your health information in accordance with applicable laws, including the FTC Health Breach Notification Rule and applicable U.S. state privacy and consumer-health-data laws.
5. DATA RETENTION
5.1 Active Accounts
We retain your data for as long as your account is active or as needed to provide Services.
5.2 Deleted Accounts
When you delete your account:
- All personally identifiable information is deleted within 30 days
- Health data (cycle information, symptoms, check-ins) is permanently deleted