Privacy
Privacy Policy
Last Updated: September 27, 2026
PinkyBloom, a product of Veronata, Inc. (“we,” “our,” or “us”), is built on a simple principle: your health data belongs to you. This Privacy Policy explains what data the app handles, where it goes, and how long it is kept. We never sell your data, show you ads, or share it with data brokers.
1. Data Collected & Stored on Your Device
PinkyBloom stores your health data on your iPhone, in encrypted on-device storage. This includes:
- Menstrual cycle dates and predictions
- Symptoms you log (cramps, headaches, bloating, etc.)
- Mood and energy entries
- Journal entries and notes
- AI conversation history with Pinky
- The notes Pinky keeps about you (“What Pinky remembers”)
Copies of this data leave your iPhone only as this policy describes: in your own iCloud account if you turn on iCloud Sync, and in your iPhone’s own backups (Section 6), and in your own iCloud Drive if you turn on chat backup; in what Pinky receives when you use Pinky (Section 5); and in what you share with your partner (Section 4).
Dictation (speaking instead of typing) uses Apple’s speech recognition on your iPhone; the audio is not stored or sent. What you dictate to Pinky is then sent as text, like anything you type to Pinky. Voice calls with Pinky are different: your voice is streamed to our voice service. Both are described in Section 5.
2. Data We Do NOT Collect
PinkyBloom does not collect, transmit, or have access to:
- Your name, email address or phone number — the app does not ask for them, except for an optional email address when you contact support (see “Support requests and feedback”), and Pinky receives whatever you choose to tell it, as described in Section 5. The app does send random identifiers that we do not link to your identity — an install identifier, a wallet identifier and, if you are paired, a pairing identifier (Sections 3 and 5) — and, when you use Pinky, the photos you give it and, in a voice call, your voice (Section 5)
- Account credentials — there are no accounts or logins
- Location data or GPS coordinates for our own use — if you send your partner a place, or share your live location with him, those coordinates are end-to-end encrypted on your phone first. We relay them; we cannot read them. See Section 4. If you allow the app to use your location, Pinky receives your approximate location to answer (Section 5).
- Browsing history or web activity
- Advertising identifiers (IDFA) or tracking pixels
- Contacts, your photo library, or other device data (a photo, video or file you choose to send your partner is end-to-end encrypted first — see Section 4; a photo you choose to give Pinky is described in Section 5)
3. Anonymous Analytics (On by Default — Opt Out Anytime)
To understand which features are useful and to find problems, PinkyBloom collects anonymous usage analytics. This is on by default, and you can turn it off at any time in Settings → Anonymous Analytics. The app works identically whether it is on or off, and the iPhone and Android versions collect exactly the same analytics. What we collect:
- Interaction events — e.g. app opens, sessions and their duration, screens viewed, onboarding steps, and which features you used (such as “logged a day” or “opened the forecast” — never what you logged)
- Feature health — whether an AI answer appeared and roughly how long it took; whether notifications are allowed and arrive; the steps of pairing with a partner; and for partner calls, their type (audio or video), how they connected, how long they lasted, and how they ended
- Error codes — a short category code when something fails (for example, a notification that could not be registered or a message that could not be sent), and on iPhone the same kind of code when the app crashes or freezes: which kind of failure it was, and for a freeze roughly how long it lasted. Never an error message, content, a stack trace, or a file path. We use no third-party crash-reporting service: the crash and freeze reports come from Apple’s own diagnostics, which iOS shares with us only if you allow it in your iPhone’s settings, and we keep one category code from each and delete the rest.
- An anonymous install ID — a random identifier generated in the iOS Keychain, used only to group events from the same install. It is not tied to your Apple ID, name, email, or phone number, and it is never stored together with your partner-pairing ID.
- Technical and regional context — app version, iOS version, device model, the app’s language, and the region set on your device (a country code — never GPS, and never worked out from your IP address)
- Pairing status — whether the app is paired with a partner and roughly how long ago, in ranges such as “4–7 days” — never who your partner is
We never include your health or cycle data, symptoms, journal content, messages, AI conversations, or any personally identifiable information in analytics — by design the analytics system has no access to health data. Events are processed by our own backend (hosted on Convex), which does not store IP addresses with them. They are not linked to your identity, and are never sold, shared with third parties, or used for advertising or cross-app tracking. When you turn analytics off, no further events are collected or sent.
4. End-to-End Encrypted Partner Sharing
PinkyBloom offers optional partner sharing through PinkyBond, our companion app. This connection uses end-to-end encryption that the developer cannot decrypt:
- Key exchange: Curve25519 ECDH — key pairs are generated on each device and exchanged in person by scanning a QR code, or remotely with a one-time pairing code that expires after 24 hours. Only public keys pass through our server, and it cannot derive your shared key from them
- Data encryption: AES-256-GCM — all shared data is encrypted before leaving your device
- Blind relay architecture: Our server acts as a mailbox, passing sealed encrypted blobs it cannot read or decrypt, and holding each one only until your partner’s phone has received it
- Photos, voice notes, videos and files you send in the partner chat (up to 2 GB each) are encrypted on your phone with a fresh key for every file, which only your two phones have. The encrypted file is stored with Cloudflare R2, our storage provider, until your partner’s phone has downloaded it — after 30 days at most. Where either app has not yet been updated for large files, files go the older way instead: up to 25 MB, encrypted with your pairing key, stored with Convex, and kept for 30 days even after they have been opened
- Calls are end-to-end encrypted between the two phones and never recorded. Our server keeps a call log — see Section 8
Your app’s automatic updates to your partner are limited to the following (anything else reaches your partner only if you send it yourself, as a message, photo, voice note, video or file in the partner chat):
- Your life stage, and your cycle phase and cycle day when your life stage tracks a cycle
- Mood and energy, and your forecast for the coming days, unless you choose the Basic sharing level
- When your rough days tend to cluster, only if you turn on sharing the pattern
- In pregnancy, once you have told him: your week of pregnancy and the day and kind of your next appointment, and at the Full level your due date
- After a birth: weeks since the birth and your recovery stage, and at the Full level the baby’s name and whether you are breastfeeding (yes or no)
- In perimenopause and menopause, at the Full level: the names of up to three symptoms you logged today
- At the Full level: your custom status message and a weekly summary of your chat (message and appreciation counts, not the messages)
- Whether you have allowed his Coach to use what you share (see below)
The following is never shared:
- Symptom details, and any symptoms other than those above
- Journal entries
- AI conversations
- Medical records or HealthKit data
- What you say to Pinky by voice
His Coach. PinkyBond includes an AI Coach that uses the same hosted AI service as Pinky (Section 5). If you turn on “Let his Coach use what I share” (off by default), his app includes what you share with him — your life stage, cycle phase, the mood and energy you share, your forecast for the coming days and when your rough days tend to cluster — in readable form in his requests to the Coach, which go to an outside AI service (our AI model provider, Section 5). It is processed as described in Section 5 and is not stored by us. Your fertile window is never used. With the switch off, none of your data is sent to the Coach.
5. Pinky, the AI Companion
Pinky’s answers are generated by a hosted AI service, not on your phone. Nothing described in this section is sent until you turn Pinky on and confirm that you are 18 or older. When you use Pinky, the app sends our server:
- What you type or dictate to Pinky, with the recent turns of that conversation
- In a voice call with Pinky, your voice, streamed live (see “Voice calls” below)
- Context about you: your life stage (cycle, pregnancy, postpartum, perimenopause or menopause), your cycle day and usual cycle length or your week of pregnancy, and your forecast for the next 14 days (cycle phase, predicted period and fertile days)
- The notes Pinky keeps about you (“What Pinky remembers”), which are stored on your phone and sent with each request. To update them, the app sends the conversation once more after a chat or a call
- Your shared tasks, if you use them, so Pinky can read and change them for you
- Your approximate location, if you have allowed the app to use your location, and the events in a stretch of your calendar, only when you allow it for a request that needs it (for example, finding a free evening)
- Photos you choose to give Pinky: a photo of a meal or a nutrition label for the food log, or screenshots of another period tracker’s calendar to import your history
- Technical data: a random install identifier (used to apply usage limits), the app’s language, your region, your phone’s local date and time, the wallet identifier described below, and, if you are paired, a random pairing identifier used only to count how often couples use Pinky
Pinky does not receive your Apple Health data, the symptoms and notes you have logged, your partner chat, or your age (only your confirmation that you are 18 or older).
Processing and retention. Requests pass through our server (hosted on Convex) to our AI model provider, Groq, Inc., with Zero Data Retention enabled on our account: it processes each request to produce the answer and does not keep it. Our server does not store or log what you send or what Pinky answers, and does not keep your photos or screenshots. It keeps counts with no content, such as the number of requests per day. Your conversation history with Pinky and Pinky’s notes about you are stored on your phone; your conversation history is also copied to iCloud if you turn on iCloud Sync, and to your iPhone backup if you use one (see Section 6).
Voice calls. A voice call with Pinky streams your audio in real time through our voice service, LiveKit, Inc., which hosts the call. Your speech is transcribed by Deepgram, Inc. (through LiveKit), the reply is written by Groq, and it is spoken by X.AI Corp. (xAI) text-to-speech. These services process the call only to transcribe your speech, write the reply and speak it; the speech service turns the reply text into audio, and we do not use any of it for training. Calls are not recorded, and we do not store the audio or a transcript. The context described above (such as your life stage and Pinky’s notes about you) is passed to the call when it starts. The location, calendar events and tasks the app sends for a call are held with the call and deleted shortly after it ends, within about two hours.
Lookups. When you ask Pinky to search the web, find a place, check the weather or play music, our server sends the search, and your approximate location where the lookup needs it, to the service that answers it: Exa Labs, Inc. (web search), Google (Places), the Norwegian Meteorological Institute (weather) or StarSinger (music). A barcode you scan for the food log is looked up in Open Food Facts by our server, not by your phone. These lookups do not include your identifiers.
Voice minutes and purchases. The app creates a random wallet identifier, kept in your iPhone’s Keychain, and attaches it to App Store purchases of voice minutes. Under that identifier our server keeps your purchases (product, dates, renewal state and the App Store transaction identifier), your minute balance, and a record of each voice call: when it started, how long it lasted, the minutes used and which lookups it used — never the audio or what was said. We do not link the wallet identifier to your name, email or Apple Account. Payment is handled by Apple; we never receive your payment details.
6. iCloud Sync and iPhone Backups
iCloud Sync. PinkyBloom offers optional iCloud Sync using Apple’s CloudKit Private Database:
- It is off by default and is turned on with the iCloud Sync switch in the app’s settings
- When it is on, the app keeps a copy of the health records you log, your conversation history with Pinky, and the medical records and emergency contacts in your Vault in your personal iCloud account. Pinky’s notes about you, the food log, your encryption keys and your pairing data are not synced
- Apple encrypts this data in transit and at rest. PinkyBloomdevelopers have no access to your CloudKit Private Database
- Turning the switch off stops syncing. You can delete the synced copy at any time from your iCloud settings
iPhone backups. Separately from iCloud Sync, if your iPhone is backed up to iCloud or to a computer, iOS includes the app’s data in that backup, as it does for other apps. The app excludes the food log, Pinky’s notes about you, and the photos, videos, voice notes and files from your partner chat. Your backups are controlled in your iPhone’s settings, and we have no access to them.
Chat Backup
Backing up your partner chat is optional and off until you turn it on. When you do, the backup is written to your own iCloud Drive, in the app’s own container — not to us. It is encrypted on your iPhone before it is written, with a key kept in your iCloud Keychain (or, if iCloud Keychain is off, derived from a passphrase you choose), so that a new iPhone signed in to your iCloud account can restore it. We never receive the backup or the key. You can delete the backup from inside the app or from your iCloud settings.
Support Requests and Feedback
If you contact us from the app’s support form, we receive what you write, any screenshots you attach, the email address you give (optional), your anonymous install identifier, and the app version, iOS version and device model. If you answer “Not really” when the app asks whether you are enjoying it and tell us what we could do better, we receive what you write with the same identifier and technical details. Both are stored by our backend (hosted on Convex) and sent to our team by email through an email delivery service, so that we can answer and improve the app. They are used for nothing else, and are kept for about 90 days, then deleted.
7. Apple Health (HealthKit)
With your explicit permission, PinkyBloom reads from and writes to Apple Health:
- Reads and writes: menstrual flow (period days and flow level)
- Reads: symptoms logged in Apple Health that match PinkyBloom’s symptoms, including perimenopause and menopause symptoms (such as hot flashes, sleep changes, headache, fatigue, bloating and breast pain)
- Reads, only if you connect wearable data: resting heart rate, heart-rate variability, active energy, exercise time, body weight and sleep
What the app reads from Apple Health is used on your iPhone, for your Today screen, insights and the doctor-visit summary you create, and is not sent to Pinky. Symptoms it reads are added to your log and are then treated like symptoms you log yourself (Section 4). HealthKit access requires your permission and can be revoked at any time in iOS Settings. PinkyBloom does not read or write any other HealthKit data types.
8. Data Retention
- Local health data: Stored on your device indefinitely. Permanently deleted when you uninstall the app.
- iCloud Sync and iPhone backups: Retained in your personal iCloud account, or in your backup, until you delete them. Controlled entirely by you.
- Encrypted partner data: Messages, snapshots, photos, voice notes, videos and files relayed between you and your partner are deleted from our servers as soon as your partner’s phone has received them, and after 30 days at most if it stays offline. (A file sent to a partner whose app has not yet been updated for large files goes the older way — up to 25 MB — and is kept for 30 days even after it is opened.) We cannot read this data at any point.
- Delivery records: After a message is delivered or expires, a small record with no content — which message it was, and whether and when it was delivered — is kept for 30 days so the sender’s app can show that a message was not delivered.
- Call log: For partner calls, which of your two phones called, when, voice or video, whether the call was answered, missed or declined, and how long it lasted — never any audio or video. This is not end-to-end encrypted: the server reads it to tell a phone that was off about the calls it missed. Kept for 90 days for call history and missed-call notices, deleted when you unpair, and never combined with analytics.
- Notification token: The push-notification address Apple issues to the app. We delete it the moment Apple tells us it is dead, and otherwise after 270 days without being refreshed — the point at which the address has expired anyway. It used to be 30 days, which meant a partner could not reach you after a quiet month.
- Anonymous analytics: Individual events are deleted after 180 days. Daily summaries per anonymous install (for example, which features were used that day) are kept to measure long-term trends. Analytics contain no name, email address or phone number.
- Pinky (hosted AI): Requests and answers are not stored on our servers (Section 5). Voice-call records and purchases are kept under your wallet identifier to account for your minutes and for our financial records.
- Support requests and feedback: kept for about 90 days, then deleted (see “Support requests and feedback”).
- Couple activity counts: for each paired couple, daily counts with no content — how many messages, media, calls and call minutes, and AI chats and voice calls there were that day, and which of the two apps was active — kept under the random pairing identifier to understand how couples use the apps. They are kept after you unpair, together with a record of when the pairing was first seen and which kind of app build each side used. They contain no health data and no message content.
9. Data Export
You can export your health data at any time from the Settings screen within the app. Export formats include:
- JSON — Machine-readable, suitable for data portability
- CSV — Spreadsheet-compatible format
- PDF — Formatted report suitable for sharing with your healthcare provider
10. Data Deletion
Deleting the PinkyBloom app from your iPhone permanently removes the health data stored on it, but not a copy kept by iCloud Sync or in your iPhone’s backups (Section 6). There is no account to delete. If you are paired, Remove Partner or Delete All Data in the app also deletes what our servers hold for the pairing — undelivered messages and files, delivery records and the call log. It does not delete the content-free couple activity counts described in Section 8. Deleting only the app leaves those to expire on the schedule in Section 8 (the call log after 90 days). Apart from the call log, delivery records and couple activity counts, the voice-call and purchase records kept under your wallet identifier (Section 5), and any support request you send, what our servers hold is either encrypted so that we cannot read it, or anonymous and not linked to you.
If you have turned on iCloud Sync, you can delete the synced copy separately from Settings → [Your Name] → iCloud → Manage Storage on your iPhone.
11. Children’s Privacy
PinkyBloom is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. Pinky is available only to people who confirm they are 18 or older. If you believe a child has provided data through the app, please contact us and we will take appropriate steps.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. We encourage you to review this policy periodically.
13. Contact Us
If you have questions or concerns about this Privacy Policy or your data, please reach out through our contact form.
Veronata, Inc.
2261 Market Street STE 22406
San Francisco, CA 94114
