Compliance and Data Protection
Last updated July 2026
This page describes the technical and organizational safeguards LunaCycle uses to protect your reproductive health data, and how those practices align with recognized frameworks.
Encryption at rest
Health data stored on your device is encrypted using AES-GCM. Encryption keys are generated and managed locally, so your logged data remains unreadable without your device and credentials.
Anonymous Mode
You can use LunaCycle with no account. In Anonymous Mode, no personal data is transmitted to our servers and no profile is created.
Access control
An optional PIN lock adds an additional access barrier. Only you can unlock your app and view your data.
Data export & deletion
You can export or permanently erase all of your data at any time. Deletion removes your data from your device and, where applicable, from our sync infrastructure.
Data minimization & no sale
We collect only what is needed to provide the service, and we never sell your health data to third parties.
HIPAA alignment
LunaCycle follows security practices aligned with HIPAA's administrative, physical, and technical safeguards. We are not a HIPAA-covered entity, and this page does not constitute a formal HIPAA certification or Business Associate agreement. Where applicable, we execute Business Associate Agreements with subprocessors that handle protected health information.
GDPR readiness
Our data-subject controls — access, export, and erasure — are designed to align with GDPR principles. This is not a substitute for a formal legal compliance review.
Trial integrity
A device-level record (DeviceTrialRecord) stores only an opaque device identifier, a boolean indicating whether a free trial has been used, and a timestamp. This record exists solely to prevent duplicate free trials and stores no other information. It is not linked to your health data, account email, or any personal profile beyond this single purpose.