Matta Harmonia ("we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our period tracking mobile application.
Information We Collect
Health Data
- Menstrual cycle information (period dates, cycle length, symptoms)
- Personal health notes (mood, symptoms, medications)
- Fertility tracking data (ovulation predictions, basal body temperature)
- Pregnancy tracking (if applicable)
Authentication Data (App Lock Feature)
- PIN codes (stored locally with strong encryption)
- Biometric data (processed entirely by your device's secure hardware)
- Authentication preferences (stored locally only)
Technical Data
- Device information (device type, operating system version)
- App usage analytics (anonymized, opt-in only)
- Crash reports (anonymized technical data)
Advertising Data
- Ad interaction data (minimal, contextual only)
- No personal health data is ever used for advertising
How We Use Your Information
Primary Purposes
- Period tracking and predictions — core app functionality
- Health insights — personalized cycle analysis
- Data synchronization — secure cloud backup and sync
- App security — local authentication and data protection
Secondary Purposes
- App improvement — anonymized analytics to enhance user experience
- Customer support — responding to your inquiries
- Legal compliance — meeting regulatory requirements
Data Storage and Security
Local Storage
- Device-only storage for authentication data
- Encrypted storage using AES-256 encryption
- Zero network transmission of sensitive authentication data
Cloud Storage
- Firebase Firestore (Google Cloud Platform)
- Encryption for sensitive health data
- GDPR-compliant data centers
Security Measures
- Strong encryption (AES-256, SHA-256)
- App Lock protection (PIN and fingerprint authentication)
- Advanced rate limiting with anomaly detection
- Comprehensive security monitoring with real-time threat detection
- OWASP MASVS-aligned mobile security best practices
- Progressive lockout protection with intelligent cooldown periods
- Regular security audits and continuous monitoring
Data Sharing and Disclosure
We DO NOT share:
- Personal health data with third parties
- Authentication credentials (never transmitted)
- Identifiable user information with advertisers
We MAY share:
- Anonymized analytics (no personal identification)
- Technical data with service providers (Firebase, Google)
- Data when required by law (with proper legal process)
Your Rights and Controls
- View your data — complete data export available
- Modify your data — edit or delete information anytime
- Delete your account — complete data removal available
- Data portability — export your data in standard formats
- Disable analytics — opt out of data collection
- Manage App Lock — enable/disable authentication features
GDPR Rights (EU/UK Users)
- Right of access, rectification, erasure, data portability, and to object to processing.
Third-Party Services
- Firebase (Google) — data storage, authentication, analytics. Google's privacy policy applies.
- Google AdMob — advertising. Contextual ad data only; no health information. Google's advertising privacy policy applies.
- Local Authentication — App Lock processed entirely by device secure hardware; no transmission.
Data Retention
- Health data retained until you delete your account or specific data; backups retained up to 30 days after deletion.
- Authentication data stored locally only; deleted when you disable App Lock.
- Analytics anonymized; personal identifiers removed within 30 days.
Children's Privacy
- COPPA compliance — we do not knowingly collect data from children under 13.
- Users must be 13+ to use the app. Parents may request data deletion for minors.
International Data Transfers
- Data primarily stored in US/EU data centers, protected by standard contractual clauses and encryption.
Regional Privacy Laws
- California (CCPA/CPRA): access, deletion, and opt-out rights. We do not sell personal information.
- Brazil (LGPD) and Canada (PIPEDA): access, correction, deletion, and portability rights.
Data Processing Summary
| Data Type | Purpose | Legal Basis | Retention | Shared |
|---|---|---|---|---|
| Health Data | App functionality | Consent | Until deletion | No |
| Authentication | App security | Legitimate interest | Local only | No |
| Analytics | App improvement | Consent | Anonymized | No |
| Ad Data | Revenue | Consent | Contextual only | AdMob only |
Changes to This Policy
We'll notify you of material changes via in-app alerts and, where appropriate, email. Continued use of the app after changes constitutes acceptance.
Contact Us
- Privacy questions: privacy@mattaharmonia.com
- Data requests (GDPR): gdpr@mattaharmonia.com
- Security concerns: security@mattaharmonia.com
Summary: Your data, your control. We use strong encryption, local-only authentication,
and transparent data practices. Your health data is never shared with third parties or used for advertising.