Behind the scenes
Trust & data practices
This page is maintained by MenstrualBae to answer common questions about how we handle your health data. It is app-owner editable content, not an independent verification.
Where your data lives
- Database & auth: Lovable Cloud (built on Supabase), EU region. Encrypted at rest, TLS in transit.
- App hosting: Cloudflare edge — request/response only, no health data stored at the edge.
- AI (Health GPS): Lovable AI Gateway routes prompts to model providers contractually prohibited from training on your inputs.
- Email: Lovable email infrastructure for sign-in links, password resets and account emails. No marketing email without opt-in.
DPIA — Data Protection Impact Assessment (summary)
We process special-category data under UK GDPR Article 9. A DPIA is required for that kind of processing. Here's the short version we keep on file:
- Nature of processing: users voluntarily log menstrual, fertility, pregnancy, postpartum, menopause and mental-health information to receive personalised insights, prepare for clinical appointments and access educational content.
- Lawful basis (Art 6): consent and (for paid features) contract performance.
- Special category basis (Art 9): explicit consent, given by the user's act of logging each entry.
- Necessity: we collect the minimum required for the feature; account creation needs only email + nickname.
- Risks identified: (1) unauthorised account access exposing health history, (2) re-identification of "anonymised" datasets, (3) lawful-but-coercive disclosure requests, (4) AI subprocessor mishandling.
- Mitigations: row-level security; HIBP-checked passwords (10+ chars); no third-party ad/analytics SDKs; minimum-necessary content sent to AI provider with no user identifiers; EU hosting; one-click delete; subpoena policy of user notification unless legally gagged; aggregated stats only published when group size makes re-identification implausible.
- Residual risk: low–medium; reviewed at least every 12 months and on any new data type, new subprocessor, or new AI feature.
Subprocessors
- Lovable Cloud (Supabase) — database, authentication, file storage. EU region.
- Cloudflare — app hosting and CDN.
- Lovable AI Gateway — routes Health GPS prompts; no model training on user inputs.
- Lovable email infrastructure — transactional email.
We will email registered users and update this page before adding any new subprocessor that processes personal data.
Retention
- Active account: kept while your account is open.
- After account deletion: wiped from live systems within 30 days, rolls out of encrypted backups within 90 days.
- Server logs: up to 30 days.
- Aggregated / de-identified statistics: may be retained indefinitely.
For business customers (DPA)
If you're considering MenstrualBae for a team, workplace, or NHS-adjacent context and need a Data Processing Agreement, a list of subprocessors, or completed security questionnaire, email hello@menstrualbae.app with "DPA request" in the subject line and we'll send our template within 5 working days.
Government and legal requests
- We disclose data only when legally compelled (e.g. a valid UK court order).
- We will tell affected users unless the order specifically prohibits us from doing so.
- We do not share data voluntarily with law enforcement, insurers, employers or advertisers.
Your rights & controls
- Account page — export your data, delete your account.
- Privacy policy — full GDPR statement.
- Security & disclosure — controls and how to report a vulnerability.
- Complain to the UK ICO: ico.org.uk.
