Sola - Privacy Policy
Last Updated: 13 August 2026
Effective Date: 13 August 2026
Our Commitment to Your Privacy
Sola is a period, ovulation and pregnancy tracker. What you log about your body is the most sensitive category of data there is, and the app is built so that it never reaches us. This Privacy Policy explains what data Sola handles, what leaves your phone, and the choices you have.
The short version: Everything you log is stored on your phone. There is no account, no login, and no server of ours for your cycle data to sync to, so no copy of it exists for anyone to take. iCloud backup is optional, off until you turn it on, and goes to your own private iCloud account. We do measure how the app is used, through Firebase Analytics, and that measurement is built to be health-free: no symptom, no flow, no date, no cycle length, no due date, ever. We don’t sell data, we don’t run ads, and nothing here is used to track you across other apps or websites.
1. Information We Collect
1.1 What You Log
| Data Type | Description | Where Stored |
|---|---|---|
| Cycle data | Period start and end, flow, cycle history, predictions derived from it | Your phone, and your iCloud (if backup is on) |
| Day logs | Symptoms, mood, discharge, intercourse, temperature, test results | Your phone, and your iCloud (if backup is on) |
| Notes | Any free text you write | Your phone, and your iCloud (if backup is on) |
| Preferences | What you’re tracking, cycle setup, reminders, app settings | Your phone, and your iCloud (if backup is on) |
We do not receive, store, or have any way to read any of it. It is never uploaded to a server of ours, because we do not operate one. Logging, predicting, trends, the doctor summary, and export all run entirely on your phone. The app works fully offline.
1.2 Usage Analytics
Sola uses Firebase Analytics, a Google service, to understand how the app is used: whether people finish onboarding, whether they log anything on the day they install, which features are reached, and where flows are abandoned. This tells us what to fix and what to build next. It does not identify you.
The app links FirebaseAnalyticsCore specifically, not the default Firebase Analytics product. The default pulls in Apple’s advertising framework; the one we ship does not exist to. There is no IDFA, no ad personalisation, and therefore no App Tracking Transparency prompt.
What is collected:
- A closed set of product events, fixed in the code: onboarding steps reached, that a day was logged, that a chip was toggled, that the day sheet was opened and how, that a purchase or restore started or finished, that an export or a delete-all completed, and which screens were viewed. Event names and every parameter value come from a fixed list — a build failure stops any free text from reaching Google by accident.
- Four coarse properties describing the install: what you’re tracking (cycle, trying to conceive, or pregnancy), a logging-streak bucket, a history bucket (
none,1-2 cycles,3-5,6+), and subscription state (trial,paid,lapsed). - A device-generated analytics identifier, created and managed by Firebase, used only to tell one installation’s activity apart from another’s inside our own dashboards. It dies with the install.
On the one that deserves naming: what you’re tracking is reproductive intent, and it is coarser than anything else in this section but not nothing. It is sent because the three modes behave like three different products and the onboarding numbers are unreadable without it. It is a three-value bucket, never a diagnosis, never dated, attached to an install rather than a person, with no user ID and no advertising identifier to join it to. We state it here rather than leave you to infer it.
What is never sent, in any event, parameter, or property:
- Any symptom, mood, discharge or intercourse value. We record that a chip moved, never which one — the category name is as identifying as the chip.
- Any flow tier.
- Any date. No period start, no predicted window, no due date, no cycle boundary.
- Any number derived from your body. Cycle length, period length, pregnancy week, days late, temperature, weight.
- Any free text. Note bodies, note lengths, search queries, custom symptom names.
- Any identifier. No user ID, no email, no device name, no IDFA. The app has none of these and analytics will not become the reason it acquires one.
- Screenshots, files, or export contents.
There is also no event on a late day and none on a pregnancy loss. Those screens record that they appeared and nothing else. Instrumenting a moment someone is worried, in order to optimise it, is not something we are willing to do.
Because none of this links your activity to other companies’ apps or websites, it does not meet Apple’s definition of tracking.
1.3 Purchases
Sola is a paid app with a free trial, handled by Apple’s App Store, with subscription and entitlement bookkeeping through RevenueCat. RevenueCat receives an anonymous identifier it generates itself, together with your purchase and entitlement status. It does not receive your name, email, or payment details, and it receives nothing about your cycle. Apple handles the payment and never passes those details to us.
1.4 Information We Do NOT Collect
- Personal identification (name, email address, phone number)
- Account credentials, because there are no accounts
- Your cycle data, day logs, or notes
- Apple Health data. Sola does not read from or write to HealthKit
- Location data
- Contacts or address book
- Photos
- Browsing history
- Advertising identifiers
2. How We Use Your Information
2.1 To Provide the Service
- Storing your logs: written to your phone, and copied to your own iCloud account if you turned backup on
- Predicting from your own history: calculated on your device, from your data, never from a population average held elsewhere
- Unlocking the app: verifying your purchase and restoring it on your other devices
2.2 To Improve the App
- Usage analytics: understanding which features are reached and where flows break down, within the health-free limits in §1.2
- Crash reporting: Apple’s standard crash and performance reports, delivered through App Store Connect
2.3 Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), our legal bases are:
- Contractual Necessity: processing needed to provide the app and your purchase
- Legitimate Interests: understanding and improving how the app is used, and keeping it secure
Your cycle data is special category data under Article 9. We do not process it at all — it stays on your device — so no Article 9 condition is engaged on our side.
3. How Your Data Is Stored
3.1 Local-First Architecture
Sola is local-first:
- Everything you log is stored on your phone, saved as you tap. There is no save button because there is nothing to submit
- The app works fully offline. No feature requires a network connection to log, predict, or export
- We operate no server that holds your content, so there is nothing of yours for us to lose, sell, or be compelled to hand over
3.2 iCloud Backup (Optional)
iCloud backup is off until you turn it on, in Settings → iCloud backup. With it on:
- Your history is copied into your private iCloud account, controlled by Apple. We cannot access it
- It survives a lost phone and comes back when you restore or sign in on a new one
- The first backup copies years of history at once and can take a few minutes
Turning the switch off stops further backups but does not remove what is already in iCloud. Remove that yourself in iOS Settings → [your name] → iCloud. Using Delete all data inside Sola does remove the iCloud copy along with everything on the phone.
Apple’s privacy practices apply to anything in iCloud. See Apple’s Privacy Policy.
3.3 Analytics Data
Firebase Analytics data is processed by Google under its own Firebase data processing terms, and retained according to Google’s retention settings for our project. We do not sell it and do not use it for anything beyond understanding and improving the app.
4. Third-Party Services
4.1 Apple iCloud
- Purpose: backing up your history, only if you turn it on
- Data shared: your logs, stored in YOUR iCloud account
- Privacy Policy: apple.com/privacy
4.2 Google Firebase Analytics
- Purpose: measuring feature reach and where flows are abandoned
- Data shared: the closed event set and four coarse properties described in §1.2, plus a device-generated analytics identifier. No IDFA, no health values, no dates, no free text, no personal identifiers
- Privacy Policy: policies.google.com/privacy
4.3 RevenueCat
- Purpose: managing the trial, the subscription, and restores
- Data shared: an anonymous identifier, purchase and entitlement status
- Privacy Policy: revenuecat.com/privacy
4.4 Apple App Store
- Purpose: app distribution, payment, standard analytics and crash reports
- Data shared: standard App Store analytics (downloads, crashes, usage statistics)
- Privacy Policy: apple.com/privacy
There are no other third-party SDKs in the app that collect data.
5. Data Retention
5.1 Your Logs
They remain on your phone, and in your iCloud account if backup is on, until you delete them. We do not control or have visibility into that retention, and we cannot delete your data for you — there is nothing on our side to delete.
5.2 Analytics
Analytics events are retained by Google under our Firebase project’s retention configuration. They contain no personal identifiers and no health values.
5.3 Purchases
RevenueCat and Apple retain purchase records as required for billing, restores, and legal purposes.
6. Your Rights and Choices
6.1 Take Your Data With You, Free
Settings → Export everything makes one plain CSV file on your phone and opens the share sheet. Nothing is uploaded. It is available on every tier, it keeps working if your subscription lapses, and it always will.
6.2 Delete Your Data
- In-app: Settings → Delete all data erases every log, every cycle, and your settings from this phone and from your iCloud backup. There is no server copy, so there is nothing left to recover. The screen offers to export a copy first
- iCloud: manage or remove Sola’s stored data in iOS Settings → [your name] → iCloud
- Uninstall: deleting the app removes all local data
6.3 Notifications
Every reminder is optional and off until you turn it on, in Settings → Reminders. Reminder text is deliberately vague — “Something’s due in a couple of days” — so a glance at your lock screen tells no one anything about you.
6.4 Subscriptions
Manage or cancel in your Apple Account settings. If your subscription lapses, Sola turns read-only rather than locking: your data stays readable and export keeps working.
6.5 Rights for EEA Residents (GDPR)
If you are in the European Economic Area, you have the right to access, rectification, erasure, portability, objection, restriction of processing, and to withdraw consent where processing is based on consent.
Because your logs never reach us, most of these you can exercise directly and immediately in the app. Export everything covers portability, and Delete all data covers erasure. For anything concerning analytics or purchase records, contact us at master@drnkn.dev.
6.6 Rights for California Residents (CCPA)
If you are a California resident, you have the right to know what personal information is collected and how it is used, to delete it, and to not be discriminated against for exercising those rights.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
To exercise these rights, contact us at master@drnkn.dev.
7. Data Security
7.1 Security Measures
- Encryption in transit: all network traffic (analytics, purchase verification, iCloud) uses HTTPS/TLS
- Minimal transmission: the app sends no cycle data anywhere, so there is very little to protect in the first place
- No content servers: we operate no service that stores what you log
- Discreet by default: notifications never name what they are about
7.2 Device Security
Your local data is only as safe as your phone:
- Use a strong device passcode
- Enable Face ID or Touch ID
- Keep iOS updated
- Enable two-factor authentication on your Apple Account
7.3 Limitations
No system is completely secure. We cannot guarantee absolute security of data transmitted over the internet.
8. Children’s Privacy
Sola is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13. Since there are no accounts and no personal identifiers, the risk is minimal, but if you are a parent or guardian with a concern, please contact us.
9. International Data Transfers
Analytics and purchase data may be processed by servers in the United States or other countries where Google, RevenueCat, and Apple operate. For transfers from the EEA, UK, or Switzerland we rely on standard contractual clauses, adequacy decisions where applicable, and our providers’ own compliance programmes.
Your cycle data is not transferred anywhere. iCloud data is handled by Apple according to your account settings and their policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last Updated” date, and may notify you in the app. Continued use after changes take effect constitutes acceptance.
11. Contact Us
Questions, concerns, or requests about this policy or our data practices:
Email: master@drnkn.dev
We aim to respond within 30 days.
12. Summary of Data Practices
| Category | What Is Collected | Why | Stored Where |
|---|---|---|---|
| Cycle data and day logs | Everything you log | Core app functionality | Your phone, your iCloud (optional) |
| Notes | Free text you write | Core app functionality | Your phone, your iCloud (optional) |
| Preferences | Mode, cycle setup, reminders | Personalisation | Your phone, your iCloud (optional) |
| Product events | Closed, health-free event set | Product improvement | Firebase Analytics |
| Install properties | Mode, streak bucket, history bucket, entitlement | Reading the funnels | Firebase Analytics |
| Analytics identifier | Device-generated, Firebase-managed | Telling installs apart in our dashboards | Firebase Analytics |
| Purchase status | Anonymous ID, entitlement state | Trial, subscription, restores | RevenueCat, Apple |
13. App Store Privacy Labels
In accordance with Apple’s App Store requirements:
Data Not Linked to You
- Identifiers: a device-generated analytics identifier
- Usage Data: product interaction events
- Diagnostics: crash and performance data
Data Not Collected
- Contact Info
- Health & Fitness. Your cycle data stays on your phone and in your own iCloud, and we never receive it
- Financial Info
- Location
- Contacts
- User Content
- Browsing History
- Search History
Data Used to Track You
- None. No IDFA is collected, no ad personalisation is enabled, and no data is linked across other companies’ apps or websites.
What you log is yours, and it stays on your phone. If you have any questions, please don’t hesitate to reach out.