01Who we are
Miorah is a menstrual health and cycle tracking application developed and operated by DareDoc Technologies. When this policy refers to “Miorah,” “we,” “us,” or “our,” it means DareDoc Technologies.
Contact: daredoctech@gmail.com
02Scope of this policy
This Privacy Policy applies to the Miorah mobile application on the Apple App Store and Google Play Store — including all features, notifications, and related services — and to this website. It applies to all users of the app worldwide, with additional rights described separately for users in the European Economic Area (EEA), the United Kingdom, and California.
The iOS and Android apps share the same account and the same stored records, so everything described here applies identically on either platform.
03Information we collect
We collect information in the following categories.
3.1 Account and profile information
Miorah needs an account to hold what you log, but it does not ask you to create one. When you accept the privacy promise on first launch, the app creates an anonymous account for you — no email, no phone number, no password, no sign-up form. This step needs a working internet connection, and the app cannot continue without it.
That anonymous account is identified only by a random ID. Attaching an email address, a Google account or an Apple ID to it is entirely optional, and exists so your history survives a lost or replaced phone. Sign in with Apple lets you hide your real email address behind Apple's private relay, and Miorah works exactly the same either way.
| Data type | Purpose | Required? |
|---|---|---|
| Anonymous account ID | A random identifier that ties your logs to you. It is generated for the account, not derived from your device, and it carries no advertising identifier. The only things attached to it are what you enter in the app. | Automatic |
| Display name (chosen by you) | Personalise your in-app experience — it is what the app greets you by, and it is never shown to doctors. Setup asks for one, and any name you like will do; you can change it later in your profile. | Required at setup |
| Email address | Only if you choose to save your data to an account — used for authentication, password recovery, and restoring your history on a new device. | Optional |
| Google or Apple sign-in details | If you save your data with Google Sign-In, Firebase Authentication stores the provider identifier, email address, account name and profile photo URL that Google returns. With Sign in with Apple it stores the provider identifier and the email address — which is Apple's private relay address if you chose to hide yours, and we neither need nor try to unmask it — plus your name, only on the first sign-in and only if you share it. We use these to sign you in and restore your history, nothing else. | Optional |
3.2 Cycle and health data
| Data type | Purpose |
|---|---|
| Average cycle length | Generate period and ovulation predictions. |
| Average period length | Improve prediction accuracy. |
| Cycle start and end dates | Track and display your cycle history; power insights. |
| Daily logs — flow intensity, symptoms, cramp intensity, and the free-text note saved when you add a symptom that is not in the list | Enable the daily logging feature; generate symptom trend insights; power the gentle check-in prompts you see on the home screen. |
| Optional details about you — age, health conditions, your goal (for example trying to conceive or avoiding pregnancy), and birth control method | Sharpen predictions and tailor what the app shows you. The app only ever asks for these — every one can be skipped. Age and health conditions can be changed or cleared in your profile at any time; deleting your account removes all of them. |
3.3 Preferences and interaction data
| Data type | Purpose |
|---|---|
| Reminder preferences — which reminders are on and how many days ahead | Deliver the reminders you configure, on your device. |
| Doctor-contact interest flag | Record that you would like to hear when doctor consultations launch. The consultations section is not part of the current release, so this stays off unless and until you turn it on. |
| In-app notification history | Track which reminders and prompts have been shown or acknowledged. |
| Articles you have read | Avoid re-suggesting content you have already seen. |
3.4 Analytics and diagnostics
| Data type | Purpose |
|---|---|
| Usage analytics (Google Analytics for Firebase) | Understand how features are used so we can improve the app. Events record screen views and actions such as “a daily log was saved,” together with coarse values like your cycle length setting, a flow level, or how many symptoms were selected. They never carry your symptom names, your notes, your logged dates, your display name, or your email. |
| Crash and diagnostic logs (Firebase Crashlytics) | Identify and fix technical errors and maintain app stability. These record the error and where in the app it happened, not what you logged. |
| Feature configuration (Firebase Remote Config) | Let us turn features on or off without shipping a new release. The app fetches settings; it sends no personal data to do so. |
| Technical information sent alongside the above | Like any app that talks to a server, requests carry your IP address, and the Firebase SDKs add your device model, operating system and app version, language and region, and a resettable app-instance identifier they generate. Google derives an approximate country or region from the IP address for analytics; we neither request nor store a location for you. We do not collect your advertising identifier (IDFA) — Miorah never shows the App Tracking Transparency prompt and does not track you across other companies' apps or websites. |
Health data sensitivity notice
Cycle and symptom data is health information. We store it in your own private account, encrypted in transit and at rest, access it only to provide the features you asked for, and never use it to target advertising or sell it to third parties under any circumstances.
Not now, not later
- Your precise location, your contacts, your photos, your camera or your microphone — the app never asks for any of these permissions
- Your advertising identifier — there are no advertising or tracking SDKs in the app, and no cross-app tracking
- Health records from Apple Health, Google Fit, or any other health service
- Anything you log, used to train models, ours or anyone else's
04How we collect information
- Directly from you: when you log a cycle date, enter symptoms, set your preferences, or choose to add an email or sign-in provider to your account.
- Automatically: usage analytics, crash reports and the technical information listed in 3.4 are collected as you use the app. None of it is joined to your cycle logs, and we do not use it to work out who you are.
- From a sign-in provider: only if you choose to sign in with Google or Apple, and only the account details that provider returns for the sign-in.
What happens on your phone, and stays there
Predictions. Your next period, fertile window and ovulation estimate are calculated on your device from the cycles you have logged. There is no round trip to a prediction server, and no model is trained on your data.
Reminders. Every reminder is scheduled with the operating system on your device and fires locally. Miorah does not operate a push server for reminders and does not send your device a notification containing your health data.
05How we use your information
We use your information for the following purposes only:
- To provide and operate Miorah's core features — cycle prediction, symptom logging, reminders, and insights.
- To personalise your in-app experience using your display name and preferences.
- To keep your history available across devices and restore it when you sign in on a new phone.
- To deliver the reminders you have configured.
- To generate the cycle statistics and symptom trend insights displayed to you.
- To surface in-app prompts about your own cycle patterns — for example, asking whether recent variation feels normal to you — based solely on rules you can see and control. Miorah does not diagnose you and does not tell you what to do medically.
- To identify and fix crashes and technical issues.
- To understand aggregate feature usage patterns and improve the app. We read analytics in aggregate; they are never joined to your logs.
- To comply with legal obligations.
We do not use your health data to train AI or machine learning models, our own or anyone else's, and we do not sell, rent, or trade your personal data to any third party.
06Legal bases for processing (EEA & UK users)
Where the GDPR or UK GDPR applies, we process your data on the following legal bases:
- Contract performance: processing necessary to deliver the features you requested when you started using the app or created an account.
- Consent: processing of health and cycle data, which is a special category of data under the GDPR, based on your explicit consent given when you first use the logging features. You may withdraw consent at any time by deleting your data or your account.
- Legitimate interests: usage analytics and crash diagnostics, where our interest in keeping the app working and improving it does not override your privacy rights.
- Legal obligation: where required by applicable law.
08Data retention
We retain your personal data for as long as your account is active or as necessary to provide the services you use. Specifically:
- Account, profile and cycle data: retained until you delete it. Deleting your account from inside the app removes your profile, cycles, daily logs, notification history and read-article records immediately, then removes the account record itself. If it has been a while since you last signed in, our authentication provider requires one more sign-in before that last empty record can be removed — your data is already gone at that point, and the app tells you so.
- Backups: residual copies in encrypted backups are purged within 30 days of deletion.
- Usage analytics: event-level data is kept no longer than our Firebase retention setting allows, at most 14 months. Aggregate reports, which describe no one individually, may be kept indefinitely.
- Crash logs: retained by Crashlytics for up to 90 days, then deleted automatically.
- Anonymous accounts: if you never add an email or sign-in provider and you delete the app, the account cannot be signed into again and its data can no longer be reached from the app.
- Merged accounts: if you sign in to an account you already had, the logs from your anonymous session are copied into it so nothing is lost, and — from the release this policy accompanies — the anonymous copy is then deleted. If your accounts were merged on an earlier version, that copy may still exist, unreachable from the app: write to us and we will purge it.
09Data security
We implement industry-standard technical and organisational measures to protect your data, including:
- Encryption of all data in transit using TLS (Transport Layer Security).
- Encryption of sensitive health data at rest.
- Server-side security rules that scope every record to the account that created it, so no other user can read your data.
- Access controls limiting who within DareDoc Technologies can access personal data.
- Regular review of our security practices.
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable means to protect your data, we cannot guarantee absolute security. If a data breach occurs that is likely to affect your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.
10Children's privacy
Miorah is intended for users aged 13 and above. We do not knowingly collect personal information from children under 13, or under the applicable minimum age in your jurisdiction. If we become aware that we have collected data from a child below this age without verifiable parental consent, we will delete that information promptly. If you believe a child has provided us with personal data without consent, please contact us at daredoctech@gmail.com.
Users aged 13–17 should review this policy with a parent or guardian.
11Your rights and choices
Most of these you can exercise yourself, in the app, without waiting on a reply from us.
You also have the following rights regarding your personal data, exercisable by contacting us at daredoctech@gmail.com:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete data. |
| Erasure | Request deletion of your personal data and account. You can do this yourself in the app immediately; if you ask us, we will action it within 30 days. |
| Portability | Request your data in a structured, machine-readable format. |
| Restrict processing | Request that we limit how we process your data in certain circumstances. |
| Object | Object to processing based on legitimate interests. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing. |
11.1 Additional rights for EEA and UK users (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, all rights listed above apply to you in full under the General Data Protection Regulation (GDPR) or UK GDPR. You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
11.2 Additional rights for California residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to know: the categories and specific pieces of personal information we have collected about you.
- Right to delete: request deletion of your personal information, subject to certain exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm this.
- Right to non-discrimination: we will not discriminate against you for exercising any CCPA rights.
To exercise California rights, contact us at daredoctech@gmail.com. We will respond within 45 days.
12International data transfers
DareDoc Technologies operates globally, and your data is stored on Google Cloud infrastructure that may sit outside your country. If you are accessing Miorah from the EEA, the UK, or another jurisdiction with data transfer restrictions, be aware that your data may be transferred to and processed in countries that may not offer the same level of data protection as your home jurisdiction. Where such transfers occur, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses approved by the European Commission — to protect your data in accordance with this policy and applicable law.
13Third-party services and links
Miorah contains no third-party advertisements and no advertising SDKs. The app may include links or prompts to contact healthcare professionals or access external health resources. This policy does not apply to any third-party websites, services, or providers, and we encourage you to review the privacy policies of any you access.
This page itself. It sets no cookies, runs no scripts, carries no analytics, and loads nothing from another company's servers — the typefaces are served from this site rather than from a font CDN, so reading this policy tells no third party that you did.
Doctor consultations are not yet live. The consultations section is not part of the current release: no consultation has taken place, and no cycle history has ever been shared with a doctor. When consultations launch, your history will reach a doctor only when you choose to send it — per call, per doctor — and this policy will be updated before that happens.
14Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by:
- Posting the updated policy in the app and on this page with a revised “Last updated” date.
- Displaying an in-app notification or prompt for significant changes.
- Sending an email to users who have added one to their account, where required by law.
Your continued use of Miorah after the effective date of a revised policy constitutes your acceptance of the changes.
15Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us. A person reads every message.
We respond to all enquiries within 30 days. For EEA and UK users with unresolved complaints, you have the right to contact your local data protection authority.