Privacy policy
Moona collects no personal data. This page explains what that means in practice, and what the exceptions are.
What the app records
The period days, symptoms, energy, notes and settings you enter. This data is stored only in the app's own space on your phone. It is sent to no server, neither ours nor a third party's. There is no account, no identifier, no sync.
What we do not do
No advertising, no ad SDK, no sharing with commercial partners, no profile. We cannot look at your cycle data: we do not have it.
Usage measurement
To learn which screens are useful and which are ignored, the app sends anonymous events to the PostHog service, hosted in Europe: which screen was opened, which recipe or plant was read, that a backup or a summary was created, that a plan was purchased. These events are tied to an install identifier drawn at random on the phone, linked to no name, address or account. They never contain a period date, a symptom, a note or any typed text: the date of a journal day is stripped from the screen name before sending. No screen recording, no geolocation, and the IP address is not retained. PostHog's policy.
Crash reports
The only thing that leaves the phone without an action on your part: if the app crashes, a technical report is sent to the Sentry service, hosted in Europe, so we can fix it. It contains the place in the code where it broke, the app version, the phone model and the OS version. It contains no cycle data, no text you typed, no account or device identifier, and the IP address is not retained. Sentry's policy.
Purchases
Payment goes through the App Store or Google Play. We see neither your name nor your payment method. To recognise a purchased plan and restore it on a new phone, the app uses the RevenueCat service, which receives an anonymous identifier generated on the device, the store receipt, and the install identifier of the usage measurement so the purchase joins the same anonymous events. No cycle data is sent to it. RevenueCat's policy.
Sharing with a partner
The link you generate contains the date of your last period and the length of your cycles, inside the link itself, never on a server. What the link shows is your choice when you create it. A link that has been sent cannot be revoked: it expires on its own after the duration you chose.
Reminders and the widget
Notifications are scheduled locally on the phone. The widget reads content the app places in a shared space on the same phone. Nothing goes through a notification server.
Apple Health and Health Connect
If you enable syncing, only period data is read and written, with your explicit permission, in your phone's health record. It does not leave it.
Your rights
Viewing, exporting, correcting and erasing your data is done from the app, without asking us: Settings then My data. See Delete your data. Since we hold no data, we have nothing to disclose or erase on our side.
Age
The app collects no data, so it does not verify age. It is intended for people who menstruate.
Controller
whodevelop ltd, contact@moona.cc. This policy may change with the app; the date below is that of its last update.