The short version
This summary is here for convenience and is not a substitute for the full policy below, but nothing in the full policy contradicts it.
- We never sell your data. Not to advertisers, data brokers, insurers, employers or anyone else. There is no advertising business here to fund.
- We treat your symptoms as health data. That means special category data under UK GDPR, which we process only with your explicit consent and protect accordingly.
- No third-party trackers in the app. No advertising SDKs, no social pixels, no cross-app tracking identifiers, no device fingerprinting.
- You can delete everything. From inside the app, permanently, without emailing anyone or explaining yourself.
- We only ever email you about the thing you asked for. If you joined the launch list, that means one email at launch.
1. Who we are
Fempower Health Ltd (“Fempower”, “we”, “us”) is the data controller for the personal data described in this policy. We are based in the United Kingdom and this policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy covers both the Fempower mobile application and the website at fempower.ai. Where something applies to only one of them, we say so.
For any privacy matter, contact privacy@fempower.ai.
2. What we collect
Information you give us in the app
- Account details — your email address and a password (stored only as a salted hash, never in readable form), plus the name you'd like to be called.
- Profile details — your birth year, whether your cycles are regular, irregular, absent or managed with HRT, the first day of your last period, your typical cycle length, and the symptoms you told us matter most. All of this is optional beyond what is needed to make the app work.
- Health logs — the symptoms you record, their severity and timing, your daily check-ins (mood, energy, sleep quality), period start and end dates, and any free text notes you add.
- Assistant messages — what you write to the assistant and the replies it gives you.
- Suggestion outcomes — which suggestions you accepted, dismissed, or tried, and what you reported afterwards.
Information collected automatically
- Technical data — app version, device model, operating system version and approximate region, used for diagnostics and to fix crashes.
- Notification tokens — if you allow notifications, the push token your device gives us, so we can send you the reminders you asked for.
Information collected on this website
- Launch list signups — if you enter your email address to be told when Fempower launches, we store that address, the page you signed up from, and the date.
- Aggregate analytics — anonymous, cookieless page-view counts. See our Cookie Policy.
What we deliberately do not collect
- Your precise location, contacts, photo library, microphone or camera.
- Payment card details — the App Store handles any payments, and we never see the card.
- Advertising identifiers (IDFA / AAID) or any cross-app tracking data.
3. Why we use your data, and our lawful basis
- To provide the app — explaining symptoms, generating your daily insight, scheduling follow-ups and producing your insights. Lawful basis: performance of a contract with you, and for health data, your explicit consent (see section 4).
- To send notifications you asked for — check-ins, evening prompts and follow-ups. Lawful basis: consent, withdrawable at any time in the app or in your device settings.
- To keep the service secure and working — diagnosing crashes, preventing abuse, maintaining backups. Lawful basis: legitimate interests in running a secure, reliable service.
- To improve the app in aggregate — understanding which explanations and suggestions help, using aggregated and de-identified data only. Lawful basis: legitimate interests, and consent where the underlying data is health data.
- To tell you when we launch — a single email to the address you gave us on this website. Lawful basis: consent.
- To comply with the law — responding to lawful requests and keeping records we are required to keep. Lawful basis: legal obligation.
We do not use your data for automated decision-making that produces legal or similarly significant effects. The suggestions the app makes are information, not decisions taken about you.
4. Health data
Symptoms, cycle information, mood and sleep are special category data under Article 9 of the UK GDPR. We process it on the basis of your explicit consent, which you give when you create an account and confirm you understand what the app records.
You can withdraw that consent at any time by deleting your account, which erases the underlying data. Withdrawing consent does not affect processing that already took place lawfully before withdrawal.
We do not disclose your health data to insurers, employers, advertisers, data brokers, or any third party for their own purposes. We would resist any request to do so.
5. The AI assistant
When you send a message to the assistant, that message and a limited amount of relevant context — your recent symptom logs, your cycle phase, your first name — are sent over an encrypted connection to our language model provider to generate a reply.
- Data sent to the model provider is not used to train their models, under the terms of our commercial agreement with them.
- The assistant is constrained to Fempower's own clinical knowledge base. It selects and explains from that base; it cannot invent a symptom, hormone or suggestion outside it.
- If you prefer not to use the assistant, the rest of the app — logging, explanations, GP scripts, insights — works without it, using a rule-based engine over the same knowledge base.
6. Who we share your data with
We share personal data only with service providers who process it on our instructions under a written contract, and only as much as they need:
- Cloud hosting and database — to run the service and store your data.
- Language model provider — to generate assistant replies and daily insights, as described in section 5.
- Push notification delivery — to deliver the reminders you asked for.
- Email delivery — to send account emails and the single launch email.
We may also disclose data where we are legally required to, or where necessary to establish, exercise or defend legal claims. If Fempower is ever acquired, your data may transfer as part of that business — you would be told in advance and this policy would continue to apply until you were given the chance to object or delete your account.
We never sell personal data, and we never share it for advertising.
7. International transfers
Your account and health data are stored in the UK or the European Economic Area. Some of our service providers process data outside the UK/EEA. Where they do, the transfer is covered by UK adequacy regulations or by the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, together with additional technical measures such as encryption in transit and at rest.
8. How long we keep it
- Account and health data — for as long as your account is open. The whole point of the app is the long view of your own history, so we do not silently prune it.
- After you delete your account — erased from live systems immediately and purged from encrypted backups within 30 days.
- Inactive accounts — if you do not use the app for 24 months, we email you and delete the account if you do not respond within 30 days.
- Launch list emails — deleted once the launch email has been sent, or immediately on request.
- Diagnostic logs — 90 days.
9. Security
- All traffic is encrypted in transit using TLS 1.2 or above.
- Data is encrypted at rest by our hosting and database providers.
- Passwords are stored only as salted hashes and are never recoverable by us.
- Access to production systems is restricted to the minimum number of people, protected by multi-factor authentication, and logged.
- We keep an append-only activity log so we can investigate anything that looks wrong.
No system is perfectly secure. If a breach affects your rights and freedoms we will notify the Information Commissioner's Office within 72 hours and tell you without undue delay.
10. Your rights
Under UK GDPR you have the right to:
- Access a copy of the personal data we hold about you.
- Rectify anything inaccurate — most of it you can edit directly in the app.
- Erase your data. Delete your account in the app and it is gone.
- Restrict or object to processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, without giving a reason.
Email privacy@fempower.ai to exercise any of these. We respond within one month and never charge a fee for a reasonable request.
11. Children
Fempower is intended for adults and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
12. Cookies and this website
This website sets no advertising or tracking cookies. Full detail is in our Cookie Policy.
13. Changes to this policy
If we make a material change we will tell you in the app and by email before it takes effect, and update the date at the top of this page. Continuing to use Fempower after a change takes effect means you accept the updated policy; if you don't, you can delete your account.
14. Contact and complaints
Email privacy@fempower.ai, or write to Fempower Health Ltd, United Kingdom.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We'd appreciate the chance to put it right first.