Privacy Policy
Last updated: 6 September 2026
Plain-Language Summary
We built Bleed so you can track your cycle without anyone watching. You don't need an account, an email, or a name. We don't know who you are. Your cycle data, symptoms, notes, and predictions stay on your phone. We don't run analytics, we don't sell anything to advertisers, and we don't have ads. The app works offline. The only things that ever leave your phone are: an in-app message check, if you choose to switch messages on, any feedback you choose to send us, and your support contribution if you choose to make one. Even then, no name, email, or health data is involved. Messages are off unless you turn them on, and every message is the same for everyone who receives it.
1. Introduction
This Privacy Policy (“Policy”) describes how PERIOD DEALER LTD, registered at 123 Promenade, Second Floor, Cheltenham, England, GL50 1NW, company number 16173056 (“we,” “us,” or “our”) handles information in connection with the Bleed mobile application (“App”). We are the data controller for the limited information described in this Policy.
By installing and using the App, you acknowledge that you have read and understood this Policy.
The App is an offline-first, privacy-focused period tracking tool. You do not need to create an account, provide an email address, or share any personal information to use any feature of the App. Health data entered into the App is stored exclusively on your device and is not transmitted to or accessible by us.
Which version this Policy covers. This Policy applies to Bleed on both iPhone and Android. Almost everything below is identical on either platform. Where the two genuinely differ, because Apple and Google provide different app stores, payment systems, and health platforms, the paragraph is marked iOS only or Android only. Anything not marked applies to both.
2. No Account, No Identifiers
The App does not require registration. We do not collect or store:
- Your name
- Your email address
- Your phone number
- Your physical or postal address
- Any government-issued identifier
- Any social media handle
- Any account credentials of any kind
There is no log-in screen and no sign-up flow. The App is fully usable from the moment it is installed.
3. What Stays on Your Device
All of the following information is stored locally on your device only. It is never transmitted to our servers:
- Period log (start dates, end dates, flow)
- Symptoms, moods, and notes
- Intimacy log
- Personal cycle journal entries
- Predictions for upcoming periods and the fertile window (calculated on-device)
- Historical cycle analytics
- Any data you import from Apple Health (iOS only, see Section 4)
- Any JSON backup file you export from the App
- Any doctor's report or summary you export from the App
- Biometric or passcode lock state, which is handled by your device's operating system
We have no ability to view, retrieve, or restore any of this information.
4. Apple Health (iOS only)
This section applies to Bleed on iPhone. On Android, the App does not integrate with Health Connect or any other operating-system health platform, and does not read health data from anywhere outside the App. There is no import step on Android, and nothing in this section applies.
During first-time setup, the App offers you a choice: import your existing cycle data from Apple Health, or start fresh with a clean slate. This is entirely optional, and you can decline.
If you choose to import:
- The import is a one-time read performed on your device. The App does not continuously pull data from Apple Health in the background.
- The App reads your cycle data from Apple Health on your device only.
- The imported data is copied into your local on-device records.
- The data is never transmitted from your device to our servers, and we cannot see it.
- Apple Health itself is governed by Apple's privacy controls. We do not interact with Apple Health beyond the one-time on-device read you authorise.
If you choose to start fresh, the App does not read anything from Apple Health.
You can review and manage Apple Health permissions at any time from iOS Settings → Privacy & Security → Health → Bleed.
5. Information That Leaves Your Device
The App is offline-first, but a small number of network interactions exist. None of them involve your name, email, phone number, identity, or health data. The complete list is:
a) In-app messaging (optional, off unless you turn it on). When you first set up the App you choose whether to receive in-app messages. If you decline, the App does not contact our server for messages at all. If you accept, the App checks our server periodically, and at most every 48 hours, to see whether a message is waiting.
From time to time we publish a message for all users who have messages switched on to read in the App: occasional notes from the founder, product updates, or research updates.
Every message is the same for everyone who has messages switched on. Messages are not personalised, targeted, or selected on the basis of anything about you or anything you have logged. We could not personalise them if we wanted to: we hold no profile, no identifiers, and no access to the data on your device. The check itself reveals only that a Bleed app instance asked whether a message was waiting.
You can switch messages off at any time in Settings. The App then stops checking, and nothing else about the App changes.
b) Optional message responses. Some in-app messages may invite a response (a like, a dislike, a rating, or a short text reply). Replying is entirely optional. If you reply, only the content of your response is stored. We do not capture, attach, or infer who sent it.
c) Optional feedback form. If you choose to send us feedback through the in-app feedback form, the text you submit is sent to our server. We do not capture your name, email, or any device identifier. Only the content of the message is stored, and only because you chose to send it.
d) Optional support processing. If you choose to support the App with an optional in-app contribution, the payment is handled by the store you installed the App from, Apple on iOS or Google Play on Android, and processed via RevenueCat (see Section 6). We do not receive or store your name, email, payment card, or billing details. No cycle, period, or health data is involved in the support flow.
We do not collect, transmit, or store any other information from your device.
6. Support (Optional Contributions)
The App is free to use. There are no paid tiers, no subscriptions, and no features hidden behind any paywall, and that is never changing.
If you wish to support the App, you can choose to make an optional one-time contribution from within the App. Supporting Bleed is purely voluntary. It does not unlock features, remove anything, or change how the App behaves in any way.
Support payments are handled by:
a) Apple In-App Purchase (iOS only). Apple processes the payment under its own privacy and payment terms.
b) Google Play Billing (Android only). Google processes the payment under its own privacy and payment terms.
c) RevenueCat (both platforms). We use RevenueCat to facilitate the in-app purchase. RevenueCat is the data controller for the limited technical data it processes (such as a RevenueCat-generated app user ID, purchase events, and basic diagnostics) for the purpose of completing the transaction.
We do not see, store, or process your payment card, billing address, name, or email. You can review the relevant privacy practices and terms here:
Refunds are handled by whichever store processed the payment, not by us. On iOS, request one through Apple at Report a Problem on Apple. On Android, request one through Google Play at Google Play refunds. If the store directs you back to us, or you have a question about a support contribution, contact us (see Section 18).
7. Information We Do Not Collect
We do not collect, store, or process any of the following:
- Health, cycle, or reproductive data
- Apple Health data (iOS). On Android, the App does not integrate with Health Connect or any comparable health platform, so there is no equivalent data to collect
- Location or geolocation data
- Device identifiers (the IDFA on iOS, the Android Advertising ID on Android, MAC address, IMEI, or any other hardware or resettable identifier)
- Usage analytics, crash analytics, or behavioural analytics SDKs
- Browsing behaviour or cookies
- Contact lists, photos, or other device content
- Any data through third-party advertising networks or data brokers
- Push notification tokens, whether Apple Push Notification service (APNs) on iOS or Firebase Cloud Messaging (FCM) on Android. The App does not use push notifications on either platform
- Names, emails, phone numbers, or any other personal identifiers
- Profiles, segments, or any automated decision-making about you (Article 22 UK GDPR). We hold nothing to profile you with, and no message is selected by any automated assessment of you
8. Health Data and Special Category Data
Cycle data, period tracking data, symptoms, intimacy logs, and any related health information you enter into the App is classified as special category data (health data) under Article 9 of the UK GDPR.
This data is stored locally on your device only. It is never transmitted to our servers or to any third party. We have no ability to view, access, or retrieve it.
The legal basis for processing this data on your device is your explicit consent (Article 9(2)(a) UK GDPR), which you provide by choosing to enter health information into the App. You may withdraw this consent at any time by deleting your data through the App or uninstalling the App.
9. Data Backup and Recovery
Because your health data is stored solely on your device, we have no ability to recover it in the event of device loss, damage, theft, or factory reset. You are solely responsible for maintaining backups.
The App provides a data export function in Settings. This feature lets you download your data as a JSON file, which you may store wherever you choose. You may upload this file back into the App at any time to restore your data. Once you export the file it is yours to place where you like, and wherever you put it is governed by that service's policies, not by ours.
Whether your device includes App data in its own automatic backups differs by platform. See Section 11(e).
10. Legal Basis for Processing
Under UK GDPR Article 6, our legal bases for the limited processing described above are:
a) In-app messaging. Consent (Article 6(1)(a)). You choose whether to receive in-app messages during setup, and the App contacts our server for messages only if you have switched them on. Your choice is stored on your device. You can withdraw it at any time in Settings, with immediate effect, and withdrawing is as easy as giving it. Declining or withdrawing costs you no functionality. Every feature of the App remains available.
b) Message responses and feedback submissions. Legitimate interest (Article 6(1)(f)). Where you choose to reply to a message or send us feedback, we process the content you submit in order to improve the App. The submission is anonymous and contains no identifiers we can attribute to you.
c) Optional support contributions. Contractual necessity (Article 6(1)(b)) for completing the transaction you initiated, and legitimate interest (Article 6(1)(f)) for retaining basic transaction records. We do not receive or store payment or identity details ourselves.
d) Health data on your device. Explicit consent (Article 9(2)(a)). You choose to enter health data into the App. The data is processed locally and never reaches our servers.
11. Third-Party Services
a) Apple (iOS only).Apple's privacy policy applies to data Apple processes on its own platforms, including the App Store, Apple In-App Purchase, and Apple Health: Apple Privacy Policy
b) Google (Android only).Google's privacy policy applies to data Google processes on its own platforms, including the Google Play Store and Google Play Billing: Google Privacy Policy
c) RevenueCat (both platforms). RevenueCat processes transaction data for support contributions under its own privacy policy: RevenueCat Privacy Policy
d) No analytics, advertising, or tracking SDKs. On both platforms, the App contains no analytics SDKs, no advertising SDKs, no marketing automation, no third-party tracking, and no data brokers.
e) Device-level backups. This works differently on each platform.
Android.The App switches off Android's automatic backup service. Your cycle data is never included in a device backup to your Google account or anywhere else. The export function in Settings is the only way data leaves your device.
iOS.If your iPhone automatically backs up to iCloud or to a computer, App data may be included in that backup. Those backups are held by Apple, or by you locally, and are governed by Apple's privacy policy rather than this one. You can review what is included, and switch Bleed off, in iOS Settings under your Apple Account, then iCloud.
12. International Data Transfers
The data described in Section 5 (the in-app messaging poll, optional message responses, and optional feedback content) is stored on servers located in the United Kingdom.
Apple, Google, and RevenueCat may process transaction data in countries outside the United Kingdom, including the United States. Each maintains appropriate safeguards for international transfers (Standard Contractual Clauses or equivalent) under its own privacy policy.
13. Data Retention
a) In-app message poll requests. Aggregated only, and not retained in any form that could be linked to a specific user or device.
b) Optional message responses and feedback content. Retained while operationally useful for product decisions, then deleted on a rolling basis. Because these submissions are anonymous, we cannot retrieve, attribute, or selectively delete an individual submission on request.
c) Support transaction records. Held by Apple or Google, depending on the store you used, and by RevenueCat, under their own retention practices and applicable tax obligations. We do not receive or store the transaction details ourselves.
d) Health data on your device. Under your control. You may delete it at any time through the App or by uninstalling.
14. Your Rights
Under UK GDPR you have rights in relation to personal data we hold about you. Because the App does not collect or store any data that identifies you, we hold no records that we can link back to you specifically. As a result:
- We cannot produce a record of “your” data, because we do not know which submissions came from you.
- We cannot selectively delete a single feedback or response, for the same reason.
- You can fully exercise control over your health data by deleting it in-app or uninstalling the App.
If you have a general privacy question or wish to raise a concern, contact us at info@mybleed.io. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Make a complaint to the ICO
- Phone: 0303 123 1113
15. Children's Privacy
The App is not intended for use by individuals under the age of 18. Because we do not collect identifying information, we cannot verify age. If you are under 18, do not use the App.
16. Security
Health data stored on your device is protected by your device's own security measures. We recommend enabling a device passcode and biometric lock.
The minimal data sent in the interactions described in Section 5 is transmitted over encrypted connections. No method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
17. Changes to This Policy
We may update this Policy from time to time. The current version is always available in the App and on our website, and the “Last updated” date at the top of this Policy indicates when it was most recently revised.
Where we make material changes we will also publish an in-app message before the changes take effect. You will see that message only if you have in-app messages switched on, so if you have them switched off, please check the “Last updated” date from time to time.
Continued use of the App after changes take effect constitutes acceptance of the revised Policy.
18. Contact
If you have questions about this Policy or any privacy-related concerns, please contact us at:
PERIOD DEALER LTD
123 Promenade, Second Floor, Cheltenham, England, GL50 1NW
info@mybleed.io
Or through the support information provided in the App.