Privacy Policy
Your records stay
on your device.
Summary
- Your period records, symptoms, moods and notes are sensitive health data. By default they are stored and processed only on your device.
- No account is required. Core recording, estimates, calendar, insights, export and delete all work offline.
- No ads, no analytics, no tracking SDKs, and no sale or sharing of your health data with third parties.
- Cloud sync is optional, off by default, and uploads only an encrypted snapshot to a server that cannot read its content.
- You can export everything and delete everything at any time, in the app.
1. Who we are and what this policy covers
Mori (月序) is a privacy-first, offline-first period tracking and cycle estimation app for iOS and Android, developed and operated by an individual developer, Jie Cao (the "developer"). Mori is currently published for users outside mainland China; this policy does not describe a mainland-China-specific offering.
Developer (legal) name: Jie Cao
Contact: privacy@moricycle.com.
This policy covers the Mori app on all platforms where it is published, and this website. It explains what information the app handles, where it is stored, why it is needed, how long it is kept, and how you can export or delete it. Purchase and refund terms are published separately in the Purchase & Refund Policy.
2. What information we handle
The table below is the complete inventory of personal data the app can handle. "Leaves device" means the data is transmitted off your device; everything else stays local by default.
| Data | Purpose | Where it lives | Leaves device? | Retention |
|---|---|---|---|---|
| Period dates, cycle clusters derived from them; symptoms, moods, notes, custom tags (all user-entered) | Recording, cycle estimates, calendar, insights | App's local database (device only) | No (only inside an encrypted sync snapshot if you enable sync) | Until you delete it or reset the app |
| Predictions, statistics, insights derived from your records | On-device computation for display | Device only | No — never uploaded, not even with sync | Until you delete the underlying records |
| Reminder settings; language, theme, cycle preferences | App functionality | Device only | Only a small subset inside the sync snapshot | Until you change or delete them |
| Anonymous on-device identity (randomly generated) | Separates local data namespaces; not a login, not an account | System secure storage (device only) | No — never uploaded | Until you erase on-device data |
| Export files (JSON / CSV / readable summary) | Export — generated only when you ask | Wherever you choose to save or share them | Only if you share them; then outside our control | Under your control |
| Email address (sync account, optional) | Sign-in, verification, security notices, password reset | Sync server (Thailand) | Yes — only if you create a sync account | Until you delete the account |
| Encrypted sync snapshot (optional) | Cross-device backup/restore of your records | Sync server (Thailand) as ciphertext | Yes — only if you enable sync | Until you delete the snapshot or the account |
| Payment fields: email, order number, license key | Processing your one-time purchase (handled by the payment provider) | Payment provider and sync server | Yes — only if you purchase | See §7 and the Purchase & Refund Policy |
| Update-check metadata (platform, app/runtime version) | Checking for app updates over the network | Update service (Expo) — no health data involved | Yes — automatic, minimal technical data only | Handled by the update service |
All estimates shown in the app are computed from your own history. They are estimates, not medical facts.
3. Permissions
| Permission | When requested | Used for | If refused |
|---|---|---|---|
| Notifications | Only when you enable a period or ovulation reminder — never at first launch | Local reminders. Notification text never contains period or ovulation details | Reminders are unavailable; everything else works |
Mori requests no location, contacts, photos, microphone, calendar or health-platform permissions.
4. Storage, processing and what leaves your device
Without sync: all health data lives in the app's local database; the anonymous identity lives in system secure storage. The only network traffic the app generates is checking for software updates (technical metadata only, never health data). Core features need no network.
System backups: on-device data may be included in your OS backup (e.g. iCloud or Google backup). We cannot control how long your OS retains backups, and deleting data in the app does not delete existing OS backups.
What we do not do: no advertising or ad SDKs; no analytics, tracking or telemetry SDKs; no health data in logs, crash reports or diagnostics; no sale, rent or sharing of your health data with third parties.
5. Optional cloud sync
Sync is off by default and requires that you actively create a verified-email sync account. By enabling sync you explicitly consent to the processing described in this section; turning sync off withdraws that consent for future uploads (previously uploaded snapshots stay until you delete them).
When enabled, only the following leaves your device, as a client-encrypted snapshot:
- your verified email address (sign-in, verification, security notices, password reset);
- your period records, symptoms, moods, custom tags and a small set of settings, encrypted on your device with an account-specific key before upload.
Predictions, statistics, insights, export files, notification schedules and your anonymous identity are never uploaded. The sync server stores only ciphertext and does not parse, search or display your health data. However, the account-recovery flow can unwrap the encryption key, so this service is not end-to-end encrypted and not "zero-knowledge". We never describe it otherwise.
Three deletions are independent: delete on-device data, delete the cloud snapshot, delete the account. None of them performs the others automatically.
6. Payments
If you purchase the one-time cloud-sync unlock, checkout is processed by a third-party payment provider (Creem). Only the minimal fields needed for the transaction — email, order number and license key — are handled; your health data is never part of the transaction. Refunds, license-key rules and chargeback handling are published in the Purchase & Refund Policy.
7. Third-party services
| Service | Role | Data involved | Where |
|---|---|---|---|
| Sync server (self-hosted) | Stores sync accounts and encrypted snapshots | Email, credentials (hashed), ciphertext | Thailand |
| Creem | Payment checkout | Email, order number, license key | Operated by Creem — see their privacy policy |
| Resend | Sends verification and password-reset emails | Email address only; emails never contain health data | Operated by Resend |
| Cloudflare | DNS / CDN / TLS for our domains | Standard network metadata (e.g. IP) as processed by Cloudflare | Global network |
| Expo (EAS Update) | App update delivery | Update-check metadata (platform, versions) | Operated by Expo |
| Apple App Store / Google Play | App distribution | Your relationship with the store (account, downloads) | Per the store's own terms |
We do not embed advertising, analytics or tracking SDKs. Health data is shared with none of the services above.
8. International transfers
Mori is published for users outside mainland China. Depending on where you are, using sync, email verification or purchases transfers the limited data described above to Thailand (sync server) and to the third-party services in §7 in their operating regions. Those services process data under their own privacy policies.
9. Retention and deletion
| Data | Retention | How to delete |
|---|---|---|
| On-device records, settings, derived data | Until you delete them | Per-record delete, or Settings → Data & Privacy → Erase All On-Device Data & Reset |
| Anonymous on-device identity | Until erased with on-device data | Same erase action as above (irreversible) |
| Email address and account | Until account deletion | Settings → delete account (removes account, sessions, wrapped key, snapshots, reset tokens) |
| Encrypted snapshots | Until deleted | Settings → delete cloud snapshot (keeps the account) |
| Verification / reset one-time codes | 10 minutes, single use | Expire automatically |
| Server logs | Short operational window; never contain health data or message content | Rotate out automatically |
| Server backups | Encrypted backups rotate within ~30 days of online deletion | Automatic — we cannot promise instant disappearance from backups |
10. How we protect your data
- Health data is confined to the app's sandboxed local storage.
- Snapshots are encrypted on your device before upload and transmitted over TLS.
- Passwords are stored as strong salted hashes; session and reset tokens only as hashes; each account gets its own randomly generated data-encryption key.
- Server logs and error responses never contain health content, exact health dates or record data.
- There is no admin interface that can view, search or export your health plaintext.
If a security incident affects your personal data, we will notify you and take reasonable remediation steps without undue delay.
11. Your rights and how to exercise them
Where data-protection law applies to you (for example the GDPR if you are in the EEA or UK), you have the right to access, correct, delete, restrict and port your personal data, to object to certain processing, and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority.
Most rights can be exercised directly in the app: export (access & portability) and deletion of on-device data, cloud snapshots and account. For anything else, contact us at privacy@moricycle.com — we aim to respond within 30 days. We may need to verify your identity before acting on a request; if we refuse a request, we will explain why.
12. Children
Mori is not directed at children under 13 (or a higher minimum age where local law requires). If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We publish the current version on this page with its version number, effective date and last-updated date. Material changes will be announced in the app or on the website before they take effect; the version available in the app always matches this page.
14. Contact
Questions about this policy or your data: privacy@moricycle.com. Purchase and refund matters: see the Purchase & Refund Policy.