Privacy policy
- Effective from
- 8 August 2026
- Last updated
- 8 August 2026
- Version
- 1.0
In short
- Your cycle data and your deen data live in a database in Frankfurt, in the European Union.
- We do not call this end-to-end encryption, because it isn't: your data sits readable in our database. What limits access is procedure and logging, not mathematics.
- There is no ad, attribution or analytics SDK in the app, and this website sets no cookies that would require consent.
- We train no models on your data and our suppliers are contractually barred from doing so.
- Delete your account and your live data is gone within 30 days, your backups within another 14.
- Questions or a request? Email privacy@mensishealth.com. We respond within 30 days.
Mensis processes data about your menstrual cycle and, if you switch on the deen module, about your religious practice. Those are two of the most sensitive categories of data the General Data Protection Regulation (GDPR) recognises. This policy describes exactly what we do with them.
We've tried to keep this readable without becoming imprecise. Where we use a legal term, we explain it. If something is still unclear, email us — that isn't a courtesy line, we genuinely answer it ourselves.
1. Who is responsible for your data
The controller within the meaning of Article 4(7) GDPR is Mensis Health B.V. (Chamber of Commerce 98765432, VAT NL867890123B01), Spoorlaan 21, 5038 CB Tilburg, the Netherlands.
- Privacy questions and requests
- privacy@mensishealth.com
- Questions about the app
- support@mensishealth.com
We have not appointed a data protection officer. That isn't required for an organisation of our size; privacy requests reach the team that builds the app directly.
2. What data we process
Account data
You sign in with Sign in with Apple or with Google. We receive an identifier from that service and, depending on your choice, an email address or a relayed alias. We deliberately offer no email-and-password sign-in: without email addresses we don't need an email processor in the chain.
Health data (Article 9 GDPR)
- The start and end dates of your period and the intensity of your flow
- The symptoms you log: mood, energy, pain and cramps, sleep, skin, libido, discharge, headache and appetite
- Free notes you write yourself
- Your contraception method and chosen mode (tracking your cycle, trying to conceive, using contraception)
- Your average cycle and period length, derived from your logs
Data on religious belief (Article 9 GDPR)
Only if you switch on the deen module: your configured fiqh thresholds, your hayd and istihada status, your ghusl records, your missed and made-up fasting days and the Ramadan dates you confirmed. Leave the module off and we process nothing from this category at all.
Technical and operational data
- Error reports when the app crashes, without the contents of your logs
- Your settings: theme, notification preferences, language, discreet mode
- The contents of your emails to our support addresses
3. What we use it for, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Creating your account and syncing your device with the cloud | Account data | Article 6(1)(b) — performance of the contract |
| Showing your cycle, calculating predictions and filling your calendar | Health data | Article 9(2)(a) — explicit consent, asked before the first question about your data |
| Hayd status, ghusl reminder and qadaa counter | Data on religious belief | Article 9(2)(a) — separate explicit consent |
| Sending the notifications you switched on yourself | Settings, derived prediction data | Article 6(1)(b), combined with the consent above |
| Fixing crashes and keeping the app secure | Error reports | Article 6(1)(f) — legitimate interest (a working, secure app) |
| Answering your support question | The contents of your email | Article 6(1)(b) and (f) |
| The AI assistant (available later, off by default) | Cycle phase, day number, average lengths, symptom summary | Article 6(1)(a) and Article 9(2)(a) — separate consent, separately withdrawable |
4. Two special categories, consent twice
Article 9 GDPR prohibits processing data on health and on religious belief in principle. That prohibition lifts, among other grounds, when you give explicit consent. Mensis touches both categories, and we keep them apart.
- We ask for consent for health data in step 2 of onboarding, before the first question about your cycle. Not pre-ticked.
- We ask for consent for the deen module separately, in step 7. Withhold it and the module doesn't exist in your app, and we process nothing about your faith.
- Consent for the AI assistant is a third, separate consent that you can withdraw without giving up the rest of the app.
You withdraw each consent through Settings → Privacy. Withdrawing must be as easy as giving (Article 7(3) GDPR), and here it is: it's the same switch. Withdraw consent for health data and the app can no longer perform its core function, so we offer to delete your account — with an export first, if you want one.
5. Where your data sits and how it's secured
Your data sits in a PostgreSQL database at Supabase in the Frankfurt region (eu-central-1), Germany. Your device keeps a local copy so the app works offline; that copy is protected by the standard iOS or Android app sandbox and, if you enable it, by biometric locking.
What the security is
- Transport over TLS 1.2 or higher
- Encryption at rest with AES-256
- Row-level security in the database: a user can only reach their own rows
- Separation of identity and content: who you are sits in a different table from what you log
- Two-factor authentication on all administrative accounts
- A penetration test before launch and a documented breach response plan
6. Who can reach your data — our break-glass procedure
In day-to-day work nobody touches user data. The key that can bypass row-level security (the service role) does not live in our normal working environment and is not used for development, support or analysis.
If access to individual data becomes unavoidable — during an outage that can't be resolved otherwise, or for a legal request we must comply with — the following procedure applies:
- 1.The reason is recorded in writing beforehand: what the problem is, why access to this data is necessary, and which less intrusive route was considered.
- 2.Two people must approve. The person requesting access cannot approve themselves.
- 3.The access is written to an append-only log that the person granted access cannot alter or delete.
- 4.The access is limited in scope and in time: only the rows needed, and no longer than needed.
- 5.Counts and categories from this log appear in our annual transparency report.
We publish this procedure because a promise without a verifiable mechanism is worth nothing. To be clear: this is an organisational measure. It works as long as we hold to it and as long as the log stays intact. If you find that insufficient, that's a fair objection — we won't pretend otherwise.
7. Who processes data for us
We work with as few suppliers as possible. We have a data processing agreement with each of them. The full list, with role, data location and transfer basis per party, sits on a separate page that we update whenever something changes.
That page also states explicitly which kinds of supplier we do not use: no ad networks, no attribution or analytics SDKs, no data brokers and no social media SDKs.
8. Transfers outside the EU, and what the CLOUD Act has to do with it
Your data sits physically in Frankfurt. Several of our suppliers are, however, legal entities established in the United States. Where that can lead to a transfer or to access from outside the EU, we use the European Commission's standard contractual clauses (module 2) and, where the party is certified for it, the EU-US Data Privacy Framework.
9. How long we keep data
We state retention in days. "As long as necessary" is not a retention period, it's an evasion.
| Data | Retention |
|---|---|
| Cycle, symptom and deen data | As long as your account exists. You decide that moment. |
| Everything after you delete your account | Live data deleted within 30 days; backups overwritten within another 14. |
| Conversations with the AI assistant | As long as your account exists, or until you delete the thread yourself. |
| Error reports | 90 days. |
| Emails to support | 2 years after the last contact. |
| Purchase administration | 7 years, because Dutch tax law requires it. |
10. Your rights, and how to exercise them
The GDPR gives you a number of rights. Where possible we've built them into the app itself — then you don't have to wait for us.
- Access (Article 15)
- Everything we hold about you is visible in the app. If you want a complete file, use the export function or email us.
- Rectification (Article 16)
- You edit your logs and your profile directly in the app.
- Erasure (Article 17)
- Settings → Account → Delete. This works without us being involved.
- Restriction (Article 18)
- Email privacy@mensishealth.com with what you want restricted and why.
- Portability (Article 20)
- Settings → Data → Export gives you a JSON file in a machine-readable format. A PDF for human use is available too.
- Objection (Article 21)
- Email privacy@mensishealth.com. We honour objections to processing based on legitimate interest unless there are compelling grounds that outweigh them.
- Withdrawing consent (Article 7(3))
- Settings → Privacy. Per category: health, deen, AI assistant.
If you make a request by email we respond within 30 days. In the rare case that we can't meet that deadline, we'll tell you within it why and how much longer we need. A request is free; only for manifestly unfounded or excessively repeated requests may we charge a fee or refuse.
11. Automated decision-making and profiling
Mensis makes no decisions with legal effects or similarly significant effects based solely on automated processing, as referred to in Article 22 GDPR.
The app does calculate predictions from your own history. That's a calculation, not a decision about you: nothing is granted or refused, and the result is always shown with a margin of uncertainty. The AI assistant provides information and makes no diagnosis.
12. The AI assistant
The AI assistant is not available yet. When it is, the following applies, and we're writing it down now so you know where you stand.
- The assistant is off by default and asks for its own consent, separate from your other consents.
- The model runs on Amazon Bedrock with a European inference profile. The model provider's direct API has no EU region; this route does.
- Included in the context: your cycle phase, your day number, your average cycle and period length, a summary of your symptoms over recent days and your chosen mode.
- Never in the context: your email address, your user id, your name, your raw logs and your free notes.
- Never in the context: your deen data. Categorically, without exception. A test in our pipeline fails if a deen field ever ends up in the context builder.
- The assistant answers no fiqh questions.
- No training happens on your messages. That's contractually fixed with the model provider, not assumed.
13. Age
Mensis is intended for users aged 16 and over. That's the age at which you can consent to the processing of your personal data on your own in the Netherlands (Article 5 of the Dutch GDPR Implementation Act).
Onboarding asks for your year of birth in the first step. If you're younger, the flow stops with an explanation and we process nothing further. If we later discover an account belongs to someone younger, we delete it and the associated data.
14. This website
This website is a static site. There is no tracking on it, no analytics script runs, and no cookies are set that would require consent.
- Our hosting provider processes technical logs, including your IP address, to deliver the site and protect it against abuse. Legal basis: legitimate interest (Article 6(1)(f)).
- If you request a quote through Mensis for Business, we process what you enter in that form: company name, contact person, business email address, number of employees and any note you add. Legal basis: performance of, or steps towards, a contract (Article 6(1)(b)). These are business contact details, not health data.
- When an HR administrator signs in to the portal, we process the business email address and a login code that expires after use. The portal shows counts only — never data about individual employees.
- Fonts are served from our own server. No request goes to Google Fonts or any other external domain.
15. Data breaches
We have a plan for when something goes wrong anyway. In the event of a personal data breach we report it to the Dutch Data Protection Authority within 72 hours (Article 33 GDPR), unless the breach is unlikely to result in a risk.
If the breach is likely to result in a high risk to your rights and freedoms, we inform you without undue delay and in plain language (Article 34 GDPR): what happened, which data was involved, what we're doing and what you can do. Given the sensitivity of cycle and deen data, we lean towards reporting when in doubt.
16. Transparency report
Once a year we publish a report stating how many requests from governments or law enforcement we received, from which countries, how many we complied with, and how often the break-glass procedure from section 6 was used.
We publish that report even when the answer to every question is zero. That's precisely when it becomes a baseline that means something later.
17. Changes to this policy
We update this policy when the app or our suppliers change. The date at the top shows when that last happened, and we keep older versions.
If a change restricts your rights or materially alters what we do with your data, we announce it at least 30 days in advance through a notice in the app. Where a change requires fresh consent, we ask for it again — carrying on quietly is not consent.
18. Filing a complaint
If you disagree with how we handle your data, tell us first at privacy@mensishealth.com. We'd rather resolve it ourselves.
If we can't reach a resolution, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl. If you live in another EU member state, you can also go to the supervisory authority there.