Privacy Policy

Flory

Our Basic Position

Your health data does not leave this device.
The free version includes ads, and the ad SDK reads advertising identifiers and your IP address. But the ad SDK cannot see a single byte of your periods, symptoms, mood or weight — that data simply has no upload path.
The paid version has no ads.

This is not a promise; it is structure. The developer isn't refusing to sell your data — the developer is unable to.

1. Information the Developer Does NOT Collect

• Records of periods, symptoms, mood, weight, pain or conception (all stay on your device)
• Name, email address, phone number (there is no account registration)
• Location
• Data read from Apple Health / Health Connect

2. Information the Developer (and Partners) Do Collect

Google AdMob (free version only)
Collected: advertising identifiers (IDFA / AAID), IP address, device information, ad impressions and taps
Purpose: serving and measuring ads
Health data: none (technically impossible)

Google Firebase Analytics
Collected: app usage (screens viewed, feature usage counts), device information
Purpose: understanding issues and improving the app
Health data: never includes the contents of your records

Apple / Google (app stores)
Collected: purchase records
Purpose: restoring purchases, handling refunds
Health data: none

Cloudflare (only when using AI phrasing — planned feature)
Collected: one line of statistics (Terms, Section 5)
Purpose: rewording text
Health data: no identifiers, no raw records

Cloudflare (only when using data transfer)
Collected: ciphertext encrypted on your device
Purpose: temporary relay (deleted within 24 hours)
Health data: cannot be decrypted

Cloudflare (when fetching in-app news)
Collected: IP address, device information (access logs)
Purpose: delivering the in-app news list
Health data: none (news is download-only — nothing is sent from your device)

3. Advertising

The free version shows ads via Google AdMob. On iOS, the App Tracking Transparency (ATT) dialog is shown, and if you decline, no tracking occurs.
To opt out of personalized ads: on iOS, go to Settings > Privacy & Security > Tracking; on Android, Settings > Google > Ads.
Health data is never used for advertising. As explained, it is structurally impossible — and using Apple Health / Health Connect data for ads is also expressly forbidden by each platform's rules.
Once you buy Flory Plus, the ad SDK does not run and none of the above is collected.

4. Protection on the Device

Data living on your device means the device itself is the only line of defense. Therefore:
• An app lock (Face ID / fingerprint / passcode) is provided free of charge.
• The app's icon and name are kept neutral, so its purpose isn't obvious at a glance.
Uninstalling deletes your health data from the device. No copy exists on the developer's servers (it was never sent).

5. Children's Information

This app has no account registration and collects no personally identifying information. The free version does include ads, however, so parents and guardians may wish to consider Flory Plus.

6. Data Retention

The developer operates no server that stores your health data. The amount of your data the developer retains is zero. Retention periods, item by item:

Health data (period, symptom, mood, weight, pain and conception records): stored only on your device and retained until you delete it. Neither the developer nor any third party retains it, because no path exists by which it could be transmitted. Uninstalling the app deletes it at the same moment.
Account information: not retained — there is no account registration at all.
Transfer ciphertext (only if you move data to a new device): held on the relay server (Cloudflare) for at most 24 hours, or until the receiving device picks it up, whichever comes first, and then deleted automatically. The developer cannot decrypt it.
AI readings (planned; only when you use the feature): a single line of statistical conclusion containing no identifier is sent, and nothing is retained once the response has been generated.
Advertising identifier and IP address (Google AdMob, free version only): retained by Google under Google’s own policies; the developer retains none of it. You can reset or delete your advertising ID at any time in your device settings.
App usage (Google Firebase Analytics): retained by Google, with event-level data deleted automatically after at most 14 months. The developer can see only aggregated reports that identify no individual.
Access logs (when the app fetches announcements, and when you browse this site; Cloudflare): retained for at most 30 days for troubleshooting and abuse prevention, then deleted.
Purchase records: retained by Apple and Google under their own policies.

Except where retention is required by law, no data is retained beyond the periods above. See “7. Deleting and Exporting Your Data” below for how to delete it.

7. Deleting and Exporting Your Data

Deletion: uninstall the app — that is all it takes. No request to the developer is needed (the developer holds nothing). You can also delete all data from the app's Settings.
Export: from Settings, you can export an encrypted file (.flory). Free, and provided permanently.

8. Contact and Changes to This Policy

For inquiries, please use the support page on this site. Important changes to this policy will be announced in the app and on this site.


Enacted December 12, 2024
Revised July 17, 2026
Revised August 25, 2026 (data retention stated explicitly)
Privacy Policy | Flory