Legal

Privacy Policy

Effective: May 24, 2026 · Last updated: May 24, 2026

This Privacy Policy describes how Dana ("Dana", "we", "us", or "our") collects, uses, discloses, stores, and protects information when you use the Dana mobile application and related services (the "Service"). It is designed to satisfy the App Store Review Guidelines (5.1 Privacy), the Google Play Data Safety and User Data policies, and applicable laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / CPRA (CCPA), Brazil's LGPD, Canada's PIPEDA, and similar regulations.

1. Who we are (Data Controller)

The data controller responsible for your personal data is the publisher of the Dana app. You can reach our privacy team at privacy@dana-app.com for any privacy-related question, request, or complaint. EU/UK users have the right to lodge a complaint with their local Data Protection Authority.

2. Summary (at a glance)

  • Dana is a personal health and wellness tracker — not a medical device and not a substitute for professional medical advice.
  • We collect only what is necessary to make the app work for you.
  • We do not sell your personal information and we do not share health data for advertising.
  • Your reproductive, cycle, fertility and pregnancy data is treated as sensitive and protected with additional safeguards.
  • You can export or delete your data at any time from the app or via our data request page.

3. Information we collect

3.1 Information you provide

  • Account information: name or nickname, email address, hashed password, profile photo (optional), date of birth, country, language.
  • Health & reproductive data you choose to log: period start/end dates, cycle length, flow intensity, fertility window inputs, ovulation tests, basal body temperature, contraception method, sexual activity, pregnancy status and milestones, symptoms, moods, weight, sleep, water, medications and reminders, personal notes.
  • Support communications: messages and attachments you send through the contact form or by email.

3.2 Information collected automatically

  • Device & technical data: device model, operating system and version, app version, language, time zone, anonymous device identifiers.
  • Diagnostic & usage data: crash reports, performance metrics, feature usage in aggregate. Used only to keep the app stable and improve quality.
  • Approximate location (optional): derived from IP for localization. We do not collect precise GPS location.

3.3 Information we do not collect

  • We do not collect contacts, photos, microphone, camera, or precise location unless you explicitly enable a feature that requires them.
  • We do not collect government IDs, biometric identifiers, or payment card numbers (payments, if introduced, are processed by Apple or Google).

4. How we use information (purposes and legal bases)

PurposeLegal basis (GDPR)
Provide and operate the Service (cycle predictions, reminders, logs)Performance of a contract
Process sensitive health data you enterYour explicit consent (Art. 9(2)(a))
Authenticate accounts, prevent abuse and secure the ServiceLegitimate interests & legal obligation
Send transactional emails, push notifications and reminders you configuredPerformance of a contract / consent
Diagnostics, crash reporting, quality improvementLegitimate interests
Respond to support and legal requestsLegal obligation / legitimate interests

5. Sensitive personal information (health data)

Cycle, fertility, pregnancy, sexual activity, and related notes are treated as sensitive personal information. We:

  • Process this data only with your explicit consent and only for the features you use.
  • Never use it for advertising or marketing profiling.
  • Never sell or rent it.
  • Restrict internal access on a strict need-to-know basis.
  • Retain it only while your account is active or as required by law.

6. How we share information

We share information only in the limited cases below, under contractual safeguards:

  • Service providers (processors) that host, secure, and operate Dana — cloud hosting and database, authentication, email delivery, push notifications, crash analytics. They are contractually bound to use your data only on our instructions.
  • Legal & safety: when required by law, court order, or to protect the rights, safety or property of users or the public.
  • Business transfers: in connection with a merger, acquisition or asset sale, with continued protection under this policy and prior notice where required.
  • With your consent: any other sharing only after you opt in.

We do not sell or "share" personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.

7. International data transfers

Dana may process data in countries other than your own, including the United States and the European Union. Where data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Data retention

We keep personal data only as long as needed for the purposes set out in this policy:

  • Account and health data: until you delete your account or request deletion.
  • Diagnostic and crash data: typically up to 90 days.
  • Support communications: up to 24 months.
  • Backups: securely overwritten on a rolling basis (up to 35 days after deletion).
  • Records we are legally required to keep: for the period required by applicable law.

9. Security

We use industry-standard safeguards including encryption in transit (TLS), encryption at rest, hashed passwords, least-privilege access, monitoring, and regular reviews. The app also offers an optional app lock (PIN/biometric) for an extra on-device privacy layer. No method of transmission or storage is 100% secure; we encourage you to use a strong, unique password.

10. Your rights

Depending on where you live, you have rights including: access, rectification, erasure ("right to be forgotten"), restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.

California residents (CCPA/CPRA) additionally have the right to know, delete, correct, limit the use of sensitive personal information, and to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.

To exercise any right, use our data request page or email privacy@dana-app.com. We will respond within the timeframe required by applicable law (generally 30 days). We may need to verify your identity before fulfilling a request.

11. Children's privacy

Dana is not directed to children under 13 (or under 16 in the EEA, or the higher age set by your local law). We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us at privacy@dana-app.com and we will promptly delete it.

12. Third-party services

Dana relies on a limited set of trusted providers acting as processors on our behalf, which may include:

  • Cloud hosting, database and authentication (e.g. Supabase / cloud providers).
  • Push notification delivery (Apple Push Notification service, Firebase Cloud Messaging).
  • Crash and performance analytics (privacy-respecting providers, aggregated only).
  • Email delivery for transactional and support messages.

Each provider operates under its own privacy and security commitments and processes data only as needed to deliver its service to Dana.

13. Tracking and advertising

Dana does not use third-party advertising SDKs, does not perform cross-app tracking, and does not implement the AppTrackingTransparency tracking prompt because we do not track you across apps and websites owned by other companies.

14. Notifications, reminders and permissions

Dana requests only the permissions needed for the features you choose to use:

  • Notifications: to deliver reminders you set (e.g. medication, period prediction).
  • Biometrics / Face ID / Touch ID: to unlock the optional app lock.
  • Health data integrations (optional): only when you explicitly connect them.

You can revoke any permission at any time in your device settings.

15. Account deletion

You can permanently delete your Dana account and personal data at any time:

Deletion removes your profile and logged data from production systems. Encrypted backups are overwritten on a rolling basis (within 35 days).

16. Automated decision-making

Dana does not make decisions that produce legal or similarly significant effects about you using solely automated means.

17. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced in the app and the "Last updated" date above will be revised. Where required by law, we will request your renewed consent.

18. Contact us

For privacy questions, requests, or complaints, contact us at privacy@dana-app.com or via our contact form. EU users may also contact our EU representative on request.


Dana is a personal-tracking and educational tool. It is not a medical device and does not provide medical advice, diagnosis, treatment or contraception guidance. Always consult a qualified healthcare professional for medical concerns.