The YIP privacy promise
Period apps have a trust problem. Ours is built so we couldn't break your trust even if we wanted to: your cycle data stays on your phone, full stop.
How it works (the two planes)
YIP runs as two separate worlds that never touch. The health plane — your cycle, symptoms, and wear data — lives in an encrypted database on your device and is never sent to our servers. The commerce plane — your orders, membership, and credits — lives in our cloud and contains zero health data. There is no shared identifier between the two. We can't join them, and neither can anyone who asks us to.
Health plane — on your phone
- Cycle history, symptoms, and wear sessions
- Predictions computed on-device
- Encrypted local database
- Never sent to a server
Commerce plane — in our cloud
- Orders and shipping
- Membership and credits
- Referral codes
- Zero health data
Every vendor we use
No ad networks. No data brokers. No third-party analytics on health screens. This is the complete list:
- Stripe — Payments and payouts
- PostHog — Commerce analytics only (allowlisted events; never health data, never quiz answers)
- Sentry — Crash reporting (scrubbed; no health data)
- Expo — App build and update infrastructure
If law enforcement asks
We can only hand over what we have — and we don't have your cycle data. For commerce records, we require valid legal process, we notify you unless legally barred from doing so, and we publish every request in our transparency report.
Transparency report
Published twice a year: every government and law-enforcement request we receive and how we responded. First report due after launch.
Security researchers
Found something? We want to know. Read our security.txt