Girl Harmony

Privacy Policy

Effective May 1, 2026 · Last updated May 1, 2026
The short version. We built Girl Harmony as a privacy-first cycle tracker because the alternatives weren't. Your cycle data is encrypted in transit and at rest, never sold, never shared with advertisers, and you can wipe everything we have on you in one tap from the app. We collect the minimum we need to run the service. This page is the long, lawyer-readable version of that promise.

1. Who runs Girl Harmony

Girl Harmony is operated by Girl Chocolate LLC (the "Company", "we", "us"). This Privacy Policy applies to the Girl Harmony mobile apps (iOS, Android), the Girl Harmony web app at app.girlharmony.com, and the API at api.girlharmony.com.

2. What we collect, and why

2.1 Account information (required to use the app)

2.2 Cycle and health data (the core of the service)

You enter this; we store it on our servers so it syncs between your devices.

2.3 Voice journal data (only if you record)

2.4 Bestie chat data

2.5 Device + technical data

2.6 Subscription + billing data

3. Where your data lives

Data typeWhere it's stored
Cycle logs, profile, settings, chat history, supplementsCloudflare D1 (SQLite) — US, ENAM region
Voice journal audio + saved PDFsCloudflare R2 (object storage) — US, ENAM region
Authentication state (sessions, JWTs)Clerk Inc. — US, encrypted at rest
Email deliveryResend (US-based)
Subscription status (status only — not card data)RevenueCat (US-based)
Card data + payment processingStripe (US-based, PCI-DSS Level 1)
Crash + error reportsSentry (US-based, optional)

All data is encrypted in transit (TLS 1.2+) and at rest (each provider's encryption-at-rest defaults).

4. Who sees your data

By default, no one but you.

The only situations in which a person other than you would see your data:

We never: sell your data, share it with advertisers, allow it to be used for ad targeting, or pass it to insurers or employers.

5. Bestie + AI

Bestie is powered by Anthropic's Claude API. When you send a message to Bestie:

6. Your rights and controls

6.1 Access + export

You can see everything we store on you from inside the app. To request a JSON export of your full dataset, email support@girlchocolate.co and we will email you a secure download link within 30 days.

6.2 Delete

Open the app → You → Settings → Erase everything. This:

If you'd rather we delete your account by email, write to support@girlchocolate.co. We process deletions within 30 days.

6.3 Correct

You can edit any logged data directly in the app. For account-level corrections (e.g. email change), email support@girlchocolate.co.

6.4 Object / restrict

If you're in the EEA, UK, California, Virginia, Colorado, Connecticut, or any other state or country with data privacy rights, you have the legal right to object to processing or restrict it. Email us and we'll honor your request.

7. Children

Girl Harmony is intended for users 13 and older. We do not knowingly collect data from anyone under 13. If you are between 13 and 17, please use Girl Harmony with the awareness and permission of a parent or legal guardian. The app's Teen Mode setting limits some features (purchases, partner sharing) for younger users.

8. International transfers

Girl Harmony servers are located in the United States. If you use Girl Harmony from outside the US, your data will be transferred to and stored on US-based infrastructure. We use the Standard Contractual Clauses (SCCs) with our US sub-processors to maintain GDPR-equivalent protections.

9. Security

No security system is perfect. If you become aware of a vulnerability, please email support@girlchocolate.co with the subject line SECURITY.

10. Sub-processors

We rely on the following sub-processors. Their privacy policies are linked.

Sub-processorPurposeRegion
Cloudflare, Inc.Application hosting, database, file storage, CDNUS (ENAM)
Clerk Inc.User authenticationUS
Anthropic PBCBestie AI chat backendUS
Stripe, Inc.Payment processingUS
RevenueCat, Inc.Subscription state aggregationUS
Resend, Inc.Transactional email deliveryUS
Functional Software, Inc. (Sentry)Crash + error reportingUS
Apple Inc.iOS App Store distribution + Sign in with AppleUS
Google LLCAndroid Play Store distribution + push notificationsUS

11. Cookies + similar technologies

Girl Harmony uses the browser's localStorage and IndexedDB to cache your data on-device for offline use. We use a single first-party authentication cookie set by Clerk to keep you signed in. We do not use third-party tracking cookies. We do not embed advertising pixels. We do not run Google Analytics.

12. Changes to this policy

We will update this policy when our practices change. The "Last updated" date at the top reflects the most recent change. For material changes, we'll send an in-app notification and an email at least 30 days before the change takes effect.

13. Contact

Email: support@girlchocolate.co
Mailing: Girl Chocolate LLC, [add address before launch], United States

14. State + region-specific notices

California (CCPA / CPRA)

California residents have the right to know what personal information we collect, to access it, to delete it, and to not be discriminated against for exercising these rights. We do not sell your personal information. We do not share it for cross-context behavioral advertising. To exercise your rights, email support@girlchocolate.co.

EEA + UK (GDPR)

The lawful basis for our processing of your personal data is your consent (Article 6(1)(a)) and the performance of our contract with you (Article 6(1)(b)). You have the right to access, rectify, erase, restrict processing of, port, and object to processing of your data, and the right to lodge a complaint with a supervisory authority. Health data (your cycle, symptoms, etc.) is processed under Article 9(2)(a) — your explicit consent. You can withdraw consent at any time by deleting your account.

Other states

Residents of Colorado, Connecticut, Virginia, Utah, and any other state with comprehensive privacy law have the same access, deletion, correction, and opt-out rights described above. Email us to exercise them.