Privacy Policy
Last updated: April 22, 2026
This Privacy Policy explains how Sana ("we", "us") collects, uses, and protects information when you use our cycle-tracking service via Telegram and the website sanacycle.com(the "Service").
Short version: we do not sell your data, we do not run ads, and we use the minimum data needed to run the Service. You can export or delete everything at any time.
1. Who we are
Sana is operated as a personal project. For any privacy-related questions, contact us at privacy@sanacycle.com.
2. Data we collect
Data you provide directly
- Cycle data (period dates, symptoms, moods, notes) you enter in the app.
- Telegram user ID and first name (provided by Telegram when you open the Mini App).
- Email address, if you subscribe to launch updates on our website.
- Partner-mode connections you explicitly create.
Data collected automatically
- Basic analytics (page views, approximate country) via Google Analytics 4 with IP anonymization.
- Server logs (request time, status, user agent) retained up to 30 days for security and debugging.
3. How we use your data
- To provide the Service: predictions, reminders, partner sharing.
- To improve the Service (aggregated, non-identifying metrics only).
- To send launch updates, if you subscribed (double opt-in, unsubscribe anytime).
- To comply with legal obligations where required.
We do not sell, rent, or trade your personal data. We do not use your cycle data for advertising. We do notshare data with data brokers or "research partners".
4. Legal basis (GDPR)
If you are in the European Economic Area, UK, or Switzerland, we process your data on these bases:
- Consent — for email marketing and optional analytics.
- Contract — to provide the Service you signed up for.
- Legitimate interest — for security, fraud prevention, and basic service analytics.
5. Data storage and security
Your data is stored on servers located in the European Union. Data in transit is encrypted via HTTPS. Sensitive fields are encrypted at rest. Access to production systems is limited and logged.
6. Third parties
- Telegram— the platform Sana runs on. Governed by Telegram's own privacy policy.
- Brevo — email service provider (for launch-updates list, EU-based, GDPR-compliant).
- Google Analytics 4 — website analytics with IP anonymization enabled.
- Vercel — hosting provider for the website.
7. Your rights
You have the right to:
- Access your data (one-tap export in the app).
- Rectify any inaccurate data.
- Erase your data (one-tap delete in the app).
- Object to or restrict processing.
- Withdraw consent for emails via the unsubscribe link in every email.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@sanacycle.com. We respond within 30 days.
8. Data retention
We keep your data as long as your account is active. If you delete your account, all personal data is removed within 30 days, except where law requires longer retention.
9. Children
Sana is intended for users aged 13 and older. If you believe a child under 13 has provided us with data, please contact us and we will delete it.
10. Changes to this policy
We'll post changes on this page and update the "Last updated" date above. Material changes will also be announced in the app or via email if you've subscribed.
11. Contact
Email: privacy@sanacycle.com