Skip to content

The YIP privacy promise

Period apps have a trust problem. Ours is built so we couldn't break your trust even if we wanted to: your cycle data stays on your phone, full stop.


How it works (the two planes)

YIP runs as two separate worlds that never touch. The health plane — your cycle, symptoms, and wear data — lives in an encrypted database on your device and is never sent to our servers. The commerce plane — your orders, membership, and credits — lives in our cloud and contains zero health data. There is no shared identifier between the two. We can't join them, and neither can anyone who asks us to.

Health plane — on your phone

  • Cycle history, symptoms, and wear sessions
  • Predictions computed on-device
  • Encrypted local database
  • Never sent to a server

Commerce plane — in our cloud

  • Orders and shipping
  • Membership and credits
  • Referral codes
  • Zero health data

Every vendor we use

No ad networks. No data brokers. No third-party analytics on health screens. This is the complete list:


If law enforcement asks

We can only hand over what we have — and we don't have your cycle data. For commerce records, we require valid legal process, we notify you unless legally barred from doing so, and we publish every request in our transparency report.


Transparency report

Published twice a year: every government and law-enforcement request we receive and how we responded. First report due after launch.


Security researchers

Found something? We want to know. Read our security.txt