Girl Harmony is operated by Girl Chocolate LLC (the "Company", "we", "us"). This Privacy Policy applies to the Girl Harmony mobile apps (iOS, Android), the Girl Harmony web app at app.girlharmony.com, and the API at api.girlharmony.com.
You enter this; we store it on our servers so it syncs between your devices.
| Data type | Where it's stored |
|---|---|
| Cycle logs, profile, settings, chat history, supplements | Cloudflare D1 (SQLite) — US, ENAM region |
| Voice journal audio + saved PDFs | Cloudflare R2 (object storage) — US, ENAM region |
| Authentication state (sessions, JWTs) | Clerk Inc. — US, encrypted at rest |
| Email delivery | Resend (US-based) |
| Subscription status (status only — not card data) | RevenueCat (US-based) |
| Card data + payment processing | Stripe (US-based, PCI-DSS Level 1) |
| Crash + error reports | Sentry (US-based, optional) |
All data is encrypted in transit (TLS 1.2+) and at rest (each provider's encryption-at-rest defaults).
By default, no one but you.
The only situations in which a person other than you would see your data:
We never: sell your data, share it with advertisers, allow it to be used for ad targeting, or pass it to insurers or employers.
Bestie is powered by Anthropic's Claude API. When you send a message to Bestie:
You can see everything we store on you from inside the app. To request a JSON export of your full dataset, email support@girlchocolate.co and we will email you a secure download link within 30 days.
Open the app → You → Settings → Erase everything. This:
If you'd rather we delete your account by email, write to support@girlchocolate.co. We process deletions within 30 days.
You can edit any logged data directly in the app. For account-level corrections (e.g. email change), email support@girlchocolate.co.
If you're in the EEA, UK, California, Virginia, Colorado, Connecticut, or any other state or country with data privacy rights, you have the legal right to object to processing or restrict it. Email us and we'll honor your request.
Girl Harmony is intended for users 13 and older. We do not knowingly collect data from anyone under 13. If you are between 13 and 17, please use Girl Harmony with the awareness and permission of a parent or legal guardian. The app's Teen Mode setting limits some features (purchases, partner sharing) for younger users.
Girl Harmony servers are located in the United States. If you use Girl Harmony from outside the US, your data will be transferred to and stored on US-based infrastructure. We use the Standard Contractual Clauses (SCCs) with our US sub-processors to maintain GDPR-equivalent protections.
No security system is perfect. If you become aware of a vulnerability, please email support@girlchocolate.co with the subject line SECURITY.
We rely on the following sub-processors. Their privacy policies are linked.
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, CDN | US (ENAM) |
| Clerk Inc. | User authentication | US |
| Anthropic PBC | Bestie AI chat backend | US |
| Stripe, Inc. | Payment processing | US |
| RevenueCat, Inc. | Subscription state aggregation | US |
| Resend, Inc. | Transactional email delivery | US |
| Functional Software, Inc. (Sentry) | Crash + error reporting | US |
| Apple Inc. | iOS App Store distribution + Sign in with Apple | US |
| Google LLC | Android Play Store distribution + push notifications | US |
Girl Harmony uses the browser's localStorage and IndexedDB to cache your data on-device for offline use. We use a single first-party authentication cookie set by Clerk to keep you signed in. We do not use third-party tracking cookies. We do not embed advertising pixels. We do not run Google Analytics.
We will update this policy when our practices change. The "Last updated" date at the top reflects the most recent change. For material changes, we'll send an in-app notification and an email at least 30 days before the change takes effect.
Email: support@girlchocolate.co
Mailing: Girl Chocolate LLC, [add address before launch], United States
California residents have the right to know what personal information we collect, to access it, to delete it, and to not be discriminated against for exercising these rights. We do not sell your personal information. We do not share it for cross-context behavioral advertising. To exercise your rights, email support@girlchocolate.co.
The lawful basis for our processing of your personal data is your consent (Article 6(1)(a)) and the performance of our contract with you (Article 6(1)(b)). You have the right to access, rectify, erase, restrict processing of, port, and object to processing of your data, and the right to lodge a complaint with a supervisory authority. Health data (your cycle, symptoms, etc.) is processed under Article 9(2)(a) — your explicit consent. You can withdraw consent at any time by deleting your account.
Residents of Colorado, Connecticut, Virginia, Utah, and any other state with comprehensive privacy law have the same access, deletion, correction, and opt-out rights described above. Email us to exercise them.