Legal

Privacy Policy

Effective as of February 21, 2026 · Last updated: March 21, 2026

Plain-language summary: Estroclic collects only the data needed to run the app — your email, pill type, cycle dates, and daily pill logs. We will never sell your data and never share your health information with third parties for commercial purposes. Your contraceptive data is treated as sensitive health data with the highest level of protection under applicable law.

Table of Contents
  1. About Us & This Policy
  2. Data We Collect & Why
  3. Sensitive Health Data
  4. Legal Bases for Processing
  5. How We Use Your Data
  6. Data Sharing & Third-Party Processors
  7. Data We Do Not Collect or Sell
  8. Data Retention
  9. Your Privacy Rights (All Users)
  10. Additional Rights for EU / EEA / UK Users (GDPR)
  11. Additional Rights for California Users (CCPA)
  12. International Data Transfers
  13. Security Measures
  14. Children's Privacy
  15. Push Notifications
  16. Cookies & Web Tracking
  17. Changes to This Policy
  18. Contact & Data Requests

1. About Us & This Policy

Estroclic is a contraceptive pill tracking and reminder application operated by BeeDazl LLC, a Wyoming Limited Liability Company ("we," "us," or "our"). Our registered business address is in the State of Wyoming, United States.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the Estroclic mobile application, visit our website at estroclic.com, or sign up for our waitlist (collectively, the "Service"). It also explains your rights and how to exercise them.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

2. Data We Collect & Why

Data You Provide Directly

Data Collected Automatically

Data We Never Collect

We do not collect: fertility data, ovulation dates, pregnancy status, sexual activity details, precise GPS location, biometric data, financial data beyond what Google Play Billing processes for subscriptions, or any data not directly necessary for pill tracking and reminders.

3. Sensitive Health Data

Your pill type, cycle schedule, and pill-taking history constitute sensitive personal health data — classified as "special category" data under the EU General Data Protection Regulation (GDPR) and afforded the highest level of legal protection.

We process this data only with your explicit consent, obtained during onboarding when you enter your cycle details. You may withdraw this consent at any time by deleting your account. Withdrawal of consent will result in deletion of your health data and termination of your ability to use the core tracking features of the Service.

We never use your health data for advertising, profiling, insurance purposes, employer reporting, or any purpose other than operating the Estroclic Service for you personally.

4. Legal Bases for Processing

Where applicable law requires us to identify a legal basis for processing your personal data, we rely on the following:

5. How We Use Your Data

We use the data we collect exclusively for the following purposes:

We do not use your data for behavioural advertising, third-party marketing, data brokerage, or AI model training.

6. Data Sharing & Third-Party Processors

We do not sell your personal data to anyone, ever.

We share your data only with the following trusted service providers, who act as data processors on our behalf under strict contractual obligations. They may only use your data for the specific purpose we instruct them:

We may also disclose your data if required to do so by law, court order, or government authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of BeeDazl LLC, our users, or the public.

In the event of a merger, acquisition, or sale of all or part of our assets, your data may be transferred to the acquiring entity, subject to the same privacy protections described in this policy. We will notify you before your data becomes subject to a materially different privacy policy.

7. Data We Do Not Collect or Sell

We explicitly confirm: We do not sell your personal data. We do not rent your data. We do not share your health data with advertisers, data brokers, insurance companies, pharmaceutical companies, employers, or any third party for commercial purposes. We do not show you targeted advertisements. We do not build advertising profiles from your health data.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Our specific retention periods are:

9. Your Privacy Rights (All Users)

Regardless of your location, we extend the following rights to all Estroclic users:

AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
DeletionRequest deletion of your account and all associated personal data
PortabilityRequest your data in a machine-readable format (CSV/JSON)
Withdraw ConsentWithdraw consent for health data processing at any time
Opt OutUnsubscribe from waitlist or marketing emails at any time

To exercise any of these rights, email support@estroclic.com. We will respond within 30 days. Account deletion is also available directly in the app under Profile → Delete Account.

10. Additional Rights for EU / EEA / UK Users (GDPR & UK GDPR)

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following additional rights under the GDPR and UK GDPR:

Our legal basis for processing special category health data under GDPR Article 9 is your explicit consent (Article 9(2)(a)). You may withdraw this consent at any time without prejudice to the lawfulness of processing carried out before withdrawal.

For EU/EEA users, BeeDazl LLC acts as the data controller. Supabase Inc. acts as a data processor under a Data Processing Agreement compliant with GDPR requirements, including Standard Contractual Clauses for international data transfers.

11. Additional Rights for California Users (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To submit a CCPA rights request, email support@estroclic.com with the subject line "CCPA Rights Request." We will verify your identity and respond within 45 days.

12. International Data Transfers

BeeDazl LLC is headquartered in the United States. If you use the Service from outside the US, your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your country of residence.

For transfers from the EU/EEA/UK to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the appropriate safeguard for international data transfers. Our data processing agreements with Supabase and other US-based processors incorporate these SCCs.

13. Security Measures

We implement appropriate technical and organisational security measures to protect your personal data from unauthorised access, loss, destruction, or alteration, including:

Despite these measures, no system is 100% secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law (within 72 hours where GDPR applies).

14. Children's Privacy

Estroclic is not directed to individuals under the age of 18, and we do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at support@estroclic.com. We will promptly delete such information from our systems.

If we become aware that we have inadvertently collected personal data from a child under 13 (or under 16 in the EU/EEA), we will take immediate steps to delete it in compliance with the Children's Online Privacy Protection Act (COPPA) and applicable law.

15. Push Notifications

Estroclic sends push notifications to remind you to take your daily pill. To receive these notifications, you must grant notification permissions on your device. You can manage or revoke notification permissions at any time through your device's system settings (Settings → Notifications → Estroclic).

We use Expo's push notification infrastructure to deliver reminders. Your device push token is shared with Expo solely for this delivery purpose. Revoking notification permissions will not affect your account or data.

16. Cookies & Web Tracking

Our website (estroclic.com) may use essential cookies to operate correctly (e.g., remembering your waitlist form submission). We do not use tracking cookies, advertising cookies, or third-party analytics cookies that profile your behaviour across the web.

The Estroclic mobile application does not use cookies. It does use local device storage to maintain your login session.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

If you do not agree with a material update, you may delete your account before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

18. Contact & Data Requests

To exercise your rights, submit a data request, report a privacy concern, or ask any question about this Privacy Policy, please contact us:

We aim to respond to all data subject requests within 30 days. For complex requests, we may extend this period by a further 60 days, in which case we will notify you of the extension within the initial 30-day period.