Songna Privacy Policy
This Privacy Policy explains how Songna (“Songna,” “we,” “our,” or “us”) collects, uses, shares, stores, and protects personal data when you use the Songna mobile app, related websites where this Privacy Policy is linked, and related services (collectively, the “Service”).
Songna is a cycle-awareness and wellbeing service. It is not a medical device, does not replace medical care, and is not intended for contraception, fertility treatment, or family-planning decisions.
1. Scope
This Privacy Policy applies to personal data we process in connection with Songna, including when you:
- create or use a Songna account;
- log cycle, symptom, lifestyle, or related information;
- use reminders, premium features, forecasts, analytics, or weekly summaries;
- contact us for support; or
- interact with Songna through a supported sign-in or purchase platform.
2. Who controls your data
Songna is the controller of the personal data described in this Privacy Policy, unless this Privacy Policy says otherwise.
You can contact us at:
3. The data we collect
We collect the data you provide directly, the data generated through your use of Songna, and limited technical data from your device and service providers.
3.1 Account and sign-in data
This may include:
- email address;
- username or display name;
- encrypted or tokenized sign-in/session information;
- social sign-in provider details if you use Apple or Google sign-in, such as provider user IDs and account email;
- your subscription tier and entitlement status; and
- support or account-related messages you send us.
3.2 Profile and onboarding data
This may include:
- date of birth;
- age derived from date of birth;
- smoking baseline; and
- profile settings relevant to Songna’s forecasts and features.
3.3 Health, cycle, symptom, and lifestyle data
Because Songna is a cycle-awareness service, you may choose to provide health-related or wellbeing-related information, including:
- last period start date;
- usual cycle length and usual bleed length;
- daily bleeding information;
- symptoms and symptom severity;
- mood, stress, sleep, exercise, diet, caffeine, alcohol, smoking, and medication entries; and
- any other health or wellness information you choose to enter into the app.
3.4 Optional health-integration data
If you choose to connect supported device health sources, we may receive and store selected metrics such as:
- steps;
- sleep duration;
- resting heart rate; and
- active minutes.
These integrations are optional. If you do not grant access, Songna will continue to work with the information you enter manually.
3.5 Derived and generated data
We generate additional information from the data you provide, such as:
- cycle timing estimates;
- phase windows and forecasts;
- confidence levels and forecast status labels;
- reminders and suggested calendar events;
- analytics cards, summaries, and weekly stories;
- premium entitlement and exposure state; and
- first-run guidance and product state needed to operate the app.
3.6 Subscription and transaction data
If you purchase premium features, we may receive limited subscription and transaction data such as:
- plan type;
- renewal and expiration dates;
- trial status;
- purchase identifiers, entitlement state, and store receipt metadata; and
- refund or cancellation state.
We do not receive your full payment-card number from Apple or Google in connection with in-app purchases handled by their stores.
3.7 Device, technical, and usage data
We and our service providers may collect technical data needed to operate the Service, such as:
- device platform and operating system;
- app version;
- push notification token if you enable notifications;
- time zone and notification preferences;
- IP address and routine server logs;
- authentication timestamps; and
- diagnostic or security data needed to keep the Service reliable and secure.
4. How we use your data
We use personal data to:
- create and manage your account;
- provide Songna’s cycle, calendar, forecast, analytics, reminder, and premium features;
- authenticate you and keep sessions secure;
- process purchases, renewals, cancellations, and restore requests;
- generate forecasts, summaries, and other service outputs you ask us to provide;
- send reminders and product messages you choose to receive;
- respond to support requests and feedback;
- maintain, debug, secure, and improve the Service;
- detect abuse, enforce our Terms, and prevent fraud; and
- comply with legal obligations.
We may also use aggregated or de-identified information to understand product performance and improve Songna. We do not try to re-identify properly de-identified data.
5. Sensitive and health-related data
Some of the data you choose to enter into Songna, including cycle, symptom, medication, and health-integration data, may be considered sensitive or special-category health data under applicable law.
We process that data only for limited purposes tied to Songna, including:
- providing the features you requested;
- generating your cycle and wellbeing outputs;
- supporting you when you contact us about those features;
- keeping the Service safe and reliable; and
- complying with legal requirements.
We do not sell your health data. We do not share your health data with third-party advertisers.
6. Legal bases for processing
If you are in the EEA, UK, or Switzerland, our legal bases may include:
- Contract: to create and maintain your account, deliver the features you requested, manage subscriptions, and provide customer support.
- Consent: for push-notification permissions, optional health integrations, and where required for the processing of health-related information you choose to provide.
- Legitimate interests: to secure the Service, prevent abuse, troubleshoot issues, improve reliability, and operate Songna responsibly, provided those interests are not overridden by your rights.
- Legal obligations: where we must retain or disclose information to comply with applicable law, lawful requests, tax obligations, or enforcement requirements.
Where our processing of health-related data relies on consent, you can withdraw that consent by stopping the relevant use, deleting the relevant entries, disconnecting the optional integration, deleting your account, or contacting us. Some features may no longer function if you do so.
7. How we share data
We share data only where needed to operate Songna, complete a request you made, comply with the law, or protect rights and safety.
Categories of recipients may include:
- Authentication and database providers, such as Supabase, to manage sign-in, account state, and app data storage.
- Hosting and backend infrastructure providers that help us run the Songna service.
- Subscription and payment infrastructure providers, including RevenueCat and the Apple App Store or Google Play, to process and validate in-app subscriptions.
- Push-notification and platform providers, including Apple and Google, when you enable reminders or other device notifications.
- Identity providers, such as Apple or Google, if you choose their sign-in options.
- Professional advisers or authorities where disclosure is reasonably necessary for legal compliance, claims, security incidents, fraud prevention, or protection of rights and safety.
- A successor or acquirer if Songna is involved in a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality measures.
We do not sell personal data in the ordinary meaning of that term, and we do not share your health data for third-party advertising.
8. International transfers
Songna and its service providers may process data in countries other than the one where you live. Where required by law, we use appropriate safeguards for international transfers, such as contractual protections or other recognized transfer mechanisms.
9. Data retention
We keep personal data for as long as necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain records, resolve disputes, and comply with legal obligations.
In general:
- account, profile, and app data are retained while your account is active;
- if you delete your account, we will delete or anonymize the associated app data within a reasonable period, subject to legal, security, backup, fraud-prevention, or technical retention needs;
- support records may be retained for a reasonable period to resolve prior issues, train support, or meet legal requirements; and
- subscription, tax, and transaction records may be retained for as long as applicable law requires.
10. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- export your data;
- delete your account and associated data;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- complain to a supervisory authority if you believe your rights have been violated.
In the app, you can currently:
- export your data from Settings;
- request deletion of your account from Settings;
- turn reminders on or off; and
- control certain optional integrations and permissions through your device settings.
To exercise privacy rights, contact privacy@songna.app.
11. Children and age restrictions
Songna is intended for people aged 15 and older. We do not knowingly permit children under 15 to use the Service.
If you are 15 to 17 years old, Songna may still process health-related information you choose to enter. Because of that:
- we encourage you to read this Privacy Policy carefully;
- we recommend reviewing Songna with a parent, guardian, or trusted adult; and
- we may apply extra checks, limit access, or take other steps where required by law or necessary to protect younger users.
If we learn that a user under 15 has created an account or submitted personal data to Songna, we may suspend the account and delete the related data.
If you are a parent or guardian and believe someone under 15 has used Songna, contact privacy@songna.app.
12. Security
We use technical and organizational safeguards designed to protect personal data, including measures such as:
- encryption in transit;
- access controls;
- secure storage of authentication state on supported devices;
- row-level or account-level access controls where supported;
- environment-based configuration and operational protections; and
- internal measures to reduce unauthorized access, loss, misuse, or disclosure.
No system is completely secure, and we cannot guarantee absolute security.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, such as through the app, by email, or by updating the effective date above.
14. Contact us
For privacy questions, rights requests, or concerns, contact: