Privacy Policy
Cycavera (formerly FloWise) is operated by SEVEN SAAS LIMITED, a company registered in England and Wales, number 16470398. Contact address: 178 Littlehampton Road, Worthing, BN13 1QY, United Kingdom. Registered office: 31a Brighton Road, Worthing, England, BN11 3EF. Email: support@sevensaaslimited.com.
We use your account details to provide Cycavera and your health information with your explicit consent to provide tracking and personal estimates. We do not sell your health data or use it for targeted advertising. You can withdraw health consent, download available records and request deletion from the app’s Privacy settings or by contacting us.
1. Scope and who is responsible
SEVEN SAAS LIMITED is the controller of personal information described here. This notice covers diagnosticdigitals.com, app.diagnosticdigitals.com and the Cycavera service. It does not cover another app merely because the same company operates it. Cycavera is intended for adults aged 18 or over. If you believe an under-18 has provided information, contact us so we can investigate and arrange appropriate deletion.
2. Information we collect
- Account and profile: your name, email, authentication information, user identifier, account preferences, age confirmation and acceptance records. If you choose to complete your health profile, this may include date of birth, gender, height, blood type and allergies.
- Health information: entries you make about periods, cycle and fertility, pregnancy, symptoms, medications, weight, temperature, sleep and related notes, where the relevant feature supports saving them. Estimates and patterns derived from entries may also be health information. Educational illustrations are general examples, not measured facts about you. Tracking summaries use your saved records.
- Billing: subscription status, plan, payment/customer identifiers, trial and billing dates and transaction information. Stripe handles payment-card details; we do not receive your full card number or security code in the app.
- Support and privacy requests: messages, optional reasons for deletion, consent choices, timestamps and records of how we respond. Please avoid sending unnecessary health details by email.
- Technical information: IP address, browser/device information, request timestamps, authentication and error logs, and information needed to provide and protect the service.
We receive information from you, your use of the service, and our authentication, hosting and payment providers. We do not obtain health records from your doctor or an external advertising data broker.
3. Purposes and lawful bases
- Creating and operating your account, providing the service and administering subscriptions: performance of our contract with you, or steps you request before entering it, under UK GDPR Article 6(1)(b).
- Storing and using health entries for personal tracking and estimates: consent under Article 6(1)(a) and explicit consent for health information under Article 9(2)(a). The separate health-consent control explains this purpose. Agreeing to the Terms is not health consent.
- Security, preventing abuse, troubleshooting and answering non-health support enquiries: our legitimate interests under Article 6(1)(f) in providing a safe, functioning service, balanced against your rights. We do not use this basis to bypass explicit consent for routine health tracking.
- Accounting and legal obligations: Article 6(1)(c). Establishing, exercising or defending legal claims may involve Article 6(1)(f) and, where necessary, Article 9(2)(f) for health information.
Account details are needed to provide an account; payment details are needed for a paid subscription. Health entries are optional, but tracking cannot function without permission to use the relevant information. Declining health consent does not prevent access to privacy requests or billing management.
4. Consent and your choices
You may grant or withdraw health consent in Privacy settings. Saving withdrawal pauses access to the app’s health-tracking screens. It does not undo processing that was lawful before withdrawal, automatically erase existing records, or cancel a subscription. Use the deletion and billing controls for those separate actions, or contact us. We stop consent-based use after withdrawal; existing records may remain pending deletion or where a legal obligation or claim requires limited retention.
We do not currently run a health-data research-sharing programme, targeted advertising, external AI processing of health records or optional analytics on this service. We do not sell personal information or share it for cross-context behavioural advertising. If a new optional purpose is introduced, we will provide the required notice and obtain consent where required before using your information for it.
5. Storage on your device and cookies
Period dates and vital records are saved to your account in our hosted database. The app uses browser storage for authentication sessions and some records, including symptom and medication entries. These local records are device/browser-specific and are not automatically a cloud backup. They remain until removed through available controls or by clearing site data. Clearing browser storage can permanently remove them; export first if you want to keep a copy. Signing out does not itself erase local health records. Use a trusted device, particularly when enabling medication notifications.
Local tracking entries are separated by signed-in account. Older versions used shared browser keys; the Privacy settings offer an explicit import for older entries only if they belong to you. Those legacy entries are not automatically assigned to another account.
A cookie remembers acknowledgement of the browser-storage notice for up to 365 days. Authentication and essential hosting/security technologies support the service. Acknowledging that notice is not consent to health processing or advertising. Our marketing site loads fonts from Google Fonts, which receives technical request information such as your IP address and browser details. We do not load advertising or optional analytics tags.
6. Who receives information
Access is limited to people and service providers who need information for the purposes described here. Our providers include Supabase for database and authentication services and Hostinger for delivery of account emails through our configured SMTP mailbox, Netlify for website/app hosting, and Stripe for payments, fraud prevention and subscription management. Google Fonts supplies marketing-site fonts. These providers may use their own subprocessors. Our checkout uses Stripe Managed Payments, with the merchant of record identified under Link/Onelink branding. Stripe/Link may act as an independent controller for payment, fraud, tax and regulatory activities; the privacy notice displayed at checkout also applies. Payment and subscription emails may come from Link/Onelink, while our authentication emails use the Cycavera sender name.
We may disclose necessary information to professional advisers, authorities when legally required, or parties involved in a business transfer subject to appropriate confidentiality and data-protection safeguards. A business transfer does not remove your statutory rights.
7. Hosting and international processing
Our primary Supabase database is hosted in London, United Kingdom (eu-west-2). This does not mean every copy, support activity, email or payment operation stays in the UK. Our providers may process information in other countries. Where a restricted transfer requires protection, we use an applicable adequacy decision or contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum to standard contractual clauses, as appropriate to the provider and transfer. Contact us for information about the relevant safeguards or a copy, with commercially confidential details removed where necessary.
8. How long we keep information
We keep account and health records while needed to provide the service you request, subject to your consent choices and deletion rights. We do not apply a published automatic inactivity-deletion schedule. Retention is determined by whether the account remains in use, the purpose of the records, pending requests or disputes, and applicable legal obligations. Information no longer needed for these purposes is eligible for removal, subject to the exceptions explained here.
Payment, tax and accounting records may need to be kept after account deletion for statutory record-keeping periods. We retain only necessary request/consent records to demonstrate how we handled your choices, and necessary security logs for investigating incidents or preventing abuse. Contact us for retention information specific to your request.
The configured daily Supabase database backups have a seven-day retention window. Deleted database records can remain in those restricted backups until rotation. They are not used for normal product operations; if a backup is restored, relevant deletion requests must be reapplied. Database backups do not include uploaded Storage objects. This backup window is not a promise that all data held by payment, email or other providers disappears within seven days. Device-local records must also be removed on the devices where they are stored.
9. Your rights and requests
Subject to the applicable law and its exceptions, you can request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. You can withdraw consent at any time. The app’s download provides available account/database records and this browser’s account-specific local records; contact us for a fuller access request or information not included in that export.
Submit a deletion request in Privacy settings or email us. An in-app request is queued for review; it is not confirmation that deletion has already happened. You may request health-record deletion while keeping your account, or full account deletion. We may verify your identity proportionately and retain information where the law permits or requires it. Requests are normally free. We respond without undue delay and normally within one month under UK data-protection law; if a lawful extension applies, we explain it within that period. Other applicable laws may set different time limits.
You can complain to the UK Information Commissioner’s Office or your local supervisory authority. You do not have to contact us first. We will not penalise you for exercising applicable privacy rights. Residents elsewhere retain mandatory local rights; contact us to make a request.
10. Security, estimates and changes
We use access controls, authenticated services and HTTPS to help protect information. No internet service or device is completely secure. Keep your password private and protect your device. Cycle estimates are informational; we do not use them to make decisions with legal or similarly significant effects about you.
We will update this notice when our practices change and provide a prominent notice of material changes. A new purpose that needs consent will require a separate choice. The date below identifies this version; it does not retroactively create consent.