Last updated 19 August 2026
SapphicTides holds some of the most sensitive information a person can write down: menstrual cycles, moods, needs, and the state of a relationship. This policy explains exactly what happens to it. It's written to be read, not skimmed past.
SapphicTides is built and operated from Canada by its founder. A Canadian company is currently being incorporated to operate it; this page will be updated with the company's registered name and address once that completes.
Privacy Officer
privacy@sapphictides.com
We answer privacy requests ourselves, usually within a few days.
Stored in readable form so you can sign in and recover access. Used for sign-in, password resets, and rarely a service message about the app itself. We do not send marketing to this address.
Cycle dates, check-ins, moods, needs, symptoms, notes, weekly check-ins, nudges, goals and settings are stored as encrypted blobs. Each is encrypted with AES-256-GCM using a key derived (HKDF-SHA256) from a 256-bit recovery key generated on your device and never transmitted to us. Even the name of each stored row is an HMAC, so the database cannot reveal which dates you've written about.
The consequence is deliberate and unavoidable: if you lose your recovery key, we cannot recover your data. Nobody can. That's the trade that makes every promise above true.
Our hosting provider keeps standard server logs — IP address, timestamp, which endpoint was called — for security and abuse prevention, retained 30 days. They are not linked to the content of any entry, because we cannot read the content of any entry.
No advertising identifiers. No location. No contacts. No photos. No device fingerprinting. No behavioural analytics. No crash-reporting SDK. The app requests no permission other than notifications, and only if you turn them on. It does not connect to Apple Health or Google Fit.
If you signed up on our website to hear about the launch, that email address lives in a separate system from the app's account database. It is not linked to a SapphicTides account, to anything you write, or to whether you use the app at all. You consented to it explicitly with an unticked box, and every email has a one-click unsubscribe. We keep a record of when and how you consented, as Canada's anti-spam law requires. We do not upload that list to advertising platforms.
Your email authenticates you. Your encrypted entries are stored so they sync between your device and your partner's. That's the whole list.
We don't use your data to train models, build profiles, or generate insights for anyone but you and the person you paired with.
If you turn notifications on, your device registers a push token with us. When your partner writes something, we send a notification saying only what kind of thing happened — "they checked in", "they replied" — never the content. The content isn't on our servers in readable form, so it couldn't be included even if we wanted it to be.
| Who | What they get | Why |
|---|---|---|
| Supabase (database & auth hosting, Toronto) | Your email address and your encrypted entries | To store and sync your data |
| Apple Push Notification service / Firebase Cloud Messaging | A push token and a one-word event type | To deliver notifications you asked for |
| Apple / Google | Purchase records | To sell you the app |
Nobody else. We have never received a government request for user data. If we do, we'll disclose what the law requires us to — and the answer will be an email address and a body of ciphertext we cannot open.
Menstrual and reproductive information is special-category data, and it's the reason this app is built the way it is. There's a separate Consumer Health Data Privacy Policy with the detail required by Washington and Nevada law.
SapphicTides is not a medical device. Predictions are estimates from your own logged history. It is not contraception and must not be used as such.
This covers your rights under Canada's PIPEDA and Quebec's Law 25, under UK and EU GDPR Articles 15–20, and under the CCPA as amended. We don't sell or share personal information as those laws define it, so there's nothing to opt out of.
Email privacy@sapphictides.com and we'll do any of it for you. Allow up to 30 days; it's usually the same week. If you're unhappy with our response you can complain to the Office of the Privacy Commissioner of Canada, or your local data protection authority.
We keep a record of every security incident, and we'll notify you and the relevant regulator where the law requires it — within 60 days under the FTC's Health Breach Notification Rule, and as soon as feasible under PIPEDA and Quebec's Law 25.
SapphicTides isn't intended for anyone under 13, and we don't knowingly collect information from children. If you believe a child has created an account, email us and we'll remove it.
Data is stored in Toronto, Canada. If you use the app from elsewhere, your encrypted entries are transferred there. Because they're encrypted before they leave your device, a transfer moves ciphertext, not readable personal data.
If this policy changes in a way that affects what we collect or who sees it, the app will tell you before the change takes effect. The date at the top always reflects the current version.
Privacy Officer
privacy@sapphictides.com
SapphicTides · Canada