Privacy Policy
Last updated: August 2026
Effective date: August 2026
Who We Are
Period & Beyond™ is a product of Devcollar Private Limited, a company registered under the Companies Act 2013 in India.
- Registered name: Devcollar Private Limited
- Product: Period & Beyond™
- Contact: support@periodandbeyond.com
- Website: periodandbeyond.com
When this policy says "we", "us", or "our", it refers to Devcollar Private Limited acting as the Data Fiduciary (data controller) under India's Digital Personal Data Protection Act 2023 (DPDPA).
The Short Version
We built Period & Beyond on a single principle: your health data belongs primarily on your device.
- Your period tracking data, symptoms, moods, notes, and intimacy logs are stored locally on your device by default.
- We do not operate a cloud store of your health data: we cannot browse your period history on our servers.
- When you accept our Terms, Privacy Policy, and Medical Disclaimer during onboarding, we store a small compliance record (not your health data) on our servers so we can prove you agreed.
- If you use optional features such as in-app feedback or opt-in analytics, limited technical or message data may leave your device as described below.
- We do not sell your data. Ever.
- We do not show you ads.
If you want the full details, read on.
What Data We Collect and Why
1. Health and Wellness Data (Stored on Your Device)
This includes everything you log in the app:
- Period dates, flow levels, duration
- Symptoms and pain levels
- Mood and emotional state
- Private notes
- Intimacy logs (if you use this feature)
- Cycle predictions and insights generated from your data
- Cycle preferences used for predictions (typical cycle length, period length, last period date, trying-to-conceive preference)
Where it lives: On your device in a local SQLite database encrypted at rest with SQLCipher (AES). The database encryption key is stored in your device Keychain / Keystore. We cannot access this data on our servers. This includes your health and wellness logs and cycle preferences (for example typical cycle length, period length, last period date used for predictions, and trying-to-conceive preference). Ordinary app settings (such as language, notification toggles, and theme) may be stored separately on your device outside that encrypted database file.
Local encrypted backup: You may export a password-protected encrypted backup file (.pbk) from the app and restore it on a device you control. This is a local export/import feature — not cloud backup operated by us.
Legal basis under DPDPA: You give explicit consent during onboarding before any data is recorded.
2. Optional Profile Information (Stored on Your Device)
The app offers a profile section where you can voluntarily add personal details:
- Your name
- Your age (derived from date of birth where provided)
- Your email address
- An "About me" note
- An optional profile image (stored in the encrypted on-device database)
All of this is entirely optional. The app works fully without it. Profile fields stay on your device and are not used for advertising.
Legal basis under DPDPA: Voluntary consent; you choose whether to provide this information.
3. Legal Agreement Records (Stored on Our Servers)
When you accept our Terms & Conditions, Privacy Policy, and Medical Disclaimer during onboarding (or again if we ask you to re-accept an updated version), we store a compliance record that includes:
- Your app-generated user identifier (a pseudonymous ID created on your device)
- The version of the legal documents you accepted
- Which documents you accepted
- The date and time of acceptance
- Optional technical details: app version, platform (iOS/Android), and language
What this does NOT include: Period dates, flow, symptoms, moods, intimacy logs, private notes, your name, email, date of birth, or other health data.
Purpose: To maintain proof that you agreed to our terms, as required for operating the service under applicable Indian law (including DPDPA and the IT Act).
Where it lives: On servers operated by Devcollar Private Limited for periodandbeyond.com, hosted with our hosting provider (Hostinger) in India. Hostinger may store backups of this database in Singapore for disaster recovery. Those backups contain the same non-health compliance metadata only.
Retention: We retain legal agreement records for 7 years from acceptance, unless a longer period is required by law.
Legal basis under DPDPA: Necessary to record and evidence your agreement to process personal data for the specified purposes of providing the app.
4. Analytics and Performance Data (Anonymised; Opt-Out)
To understand whether the app is functioning correctly, to fix technical problems, and to improve product usability, we may collect anonymised, non-personal information such as:
- Device type and operating system version
- App version
- Crash reports and error logs (stack traces and related technical context)
- Product usage milestones (for example: onboarding progress, that a period / intimacy / day log was saved, that Insights was opened, and analytics opt-in or opt-out). These events do not include the content of logs (symptoms, moods, notes, dates, or intensity values)
What this does NOT include: Any health or intimacy content, your name, your email address, phone number, or your in-app account identifier.
Anonymous install identifier: We may store a random identifier on the device that is sent only with crash reports (and, when behaviour analytics is enabled, with usage milestones) so we can group technical events from the same installation. It is not linked to your name, contact details, or health data.
Tools used:
- Sentry (EU-hosted, Frankfurt /
ingest.de.sentry.io) for anonymised crash and error reporting. Session replay is disabled. You can turn crash reporting off in Settings → Privacy & Security. - PostHog (EU Cloud) for anonymous product milestones described above. Autocapture and session replay are disabled. You can turn usage analytics off in Settings → Privacy & Security.
Crash reporting and usage analytics may run until you turn the corresponding toggle off (opt-out model). The app works fully without them.
Legal basis under DPDPA: Legitimate interest in maintaining a functioning, safe application, together with the ability to withdraw via in-app settings.
5. In-App Feedback (If You Submit It)
If you send feedback through the in-app Feedback feature, we receive:
- Your message text
- Optional attachments you choose to include
- Technical metadata such as app version, device model, and operating system version
- Your app-generated user identifier (so we can manage the ticket)
Important: Feedback is free text. Please do not include sensitive health details you do not want on our servers. Anything you type or attach may be stored on our Hostinger-hosted infrastructure in India (with possible backups in Singapore) so we can respond and improve the product.
Retention: We retain feedback tickets for up to 12 months after resolution or last activity, unless a longer period is needed to handle an open dispute.
Legal basis under DPDPA: Consent given by submitting feedback.
6. Voluntary Contact Data
If you contact us for support via support@periodandbeyond.com or through any contact form on the website, we collect:
- Your name (if you provide it)
- Your email address
- The content of your message
Website contact forms may be processed by third-party form and spam-protection providers (for example Web3Forms and hCaptcha) acting as processors for that submission.
Purpose: To respond to your query.
Retention: We retain support correspondence for up to 12 months, then delete it.
Legal basis under DPDPA: Consent given by initiating contact.
7. Website newsletter and Write for Us
If you subscribe to the website newsletter or submit a pitch via Write for Us, we store:
- Your email address
- For pitches: your name, proposed topic, pitch text, and optional portfolio link
- Language preference (English or Hindi) and, for newsletter signups, the page you subscribed from
We send a confirmation email from hello@periodandbeyond.com (delivered through Hostinger mail). Newsletter mail includes an unsubscribe link. Pitch confirmations explain the next review steps. We do not send newsletter issues until we operate a separate campaign product; this is confirmation and transactional mail only.
Purpose: Confirm your request and, for newsletter subscribers, send future journal updates you asked for.
Retention: Newsletter addresses are kept until you unsubscribe or ask us to delete them. Pitch submissions are kept while we review them and for up to 12 months after a decision, unless we publish a piece with you (then the published article is public).
Legal basis under DPDPA: Consent given by submitting the form.
8. Voluntary Support (Email Only)
There is currently no in-app donation or payment mechanism. Period & Beyond is free.
If you wish to voluntarily support development, you may contact us at support@periodandbeyond.com. Any arrangement would be handled outside the app and confirmed in writing. We do not process card, UPI, or store billing data inside the app today.
Legal basis under DPDPA: Consent, if and when you initiate contact for that purpose.
9. Future Features (Not Available Today)
The following are not currently available in the app. This section will be updated before launch of any such feature:
- Partner sharing or any end-to-end encrypted relay
- Cloud backup to Google Drive / iCloud operated as an in-app product feature
- In-app donations or subscriptions
How to request deletion of data we hold
To request deletion of data held by Devcollar Private Limited, email support@devcollar.com with the subject "Data Deletion Request".
Health and wellness data on your device can also be deleted in the app via Settings → Clear All Data, or by uninstalling the app. We delete non-compliance data we hold on our servers within 30 days of your request. Legal agreement records may be retained for the compliance period described below; they do not contain health data.
Data We Do Not Collect
We want to be explicit about what we never collect under any circumstances:
- We do not collect your location
- We do not collect your contact lists or call logs
- We do not collect information about other apps on your device
- We do not build advertising profiles
- We do not share any data with advertisers
- We do not sell data to any third party
How Your Data Is Protected
We take security seriously, particularly given the sensitive nature of health data.
- Encrypted local database: Your primary health and wellness database data — including cycle preferences — is stored in a local SQLite database protected with SQLCipher (AES encryption of the entire database file at rest). The encryption key is stored in the device Keychain / Keystore. Ordinary app settings (language, notification preferences, theme, and similar) may be stored separately on your device outside that encrypted database file.
- Biometric protection: The app can require Face ID / fingerprint (with your device’s OS passcode fallback) before access when you enable biometrics and auto-lock.
- Stealth mode and (on Android) app disguise: Optional features that help reduce casual visibility of intimacy-related UI or the app icon on shared devices.
- Local encrypted backup: Password-protected
.pbkexport/import for device-to-device transfer you control.
Your Rights Under DPDPA 2023
As a user in India, you have the following rights:
Right to access: You can request a summary of the personal data we hold about you (this is limited, given that most health data stays on your device).
Right to correction: You can correct your data directly within the app at any time.
Right to erasure (Right to be Forgotten): You can delete your health and wellness data from within the app at any time (Clear All Data / uninstall). Upon a deletion request for data we hold on our servers that is not required for legal compliance (for example support correspondence or feedback tickets), we will permanently delete it within 30 days. Legal agreement records may be retained for the compliance period described above where retention is necessary under applicable law; they do not contain your health data.
Right to withdraw consent: You can withdraw consent for analytics in the app settings. Withdrawal does not affect data processed before withdrawal. Withdrawing consent for optional features does not erase the fact that you previously accepted our Terms while using the app.
Right to grievance redressal: If you believe your rights have been violated, you can contact our Grievance Officer (see below).
Right to nominate: Under DPDPA, you have the right to nominate another individual to exercise your data rights in the event of your death or incapacity. To do so, contact us at support@devcollar.com.
Children's Privacy
Period & Beyond is intended for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. Age verification is performed during onboarding via self-reported date of birth.
If you believe a minor has used the app and provided data, please contact us at support@devcollar.com and we will take immediate steps to delete data under our control.
Under DPDPA 2023, processing of data relating to children (under 18) requires verifiable parental consent. Our age gate is designed to prevent under-18 users from accessing the app.
Third-Party Services
The app and website use a limited number of third-party services. Each has its own privacy policy.
| Service | Purpose | Data shared |
|---|---|---|
| Hostinger | Website, API, database, and transactional email for periodandbeyond.com (legal records, feedback, newsletter, pitches) | Infrastructure hosting and confirmation mail — no automatic health data sync |
| Sentry (EU-hosted) | Anonymised crash and error reporting | Anonymised device and error data only |
| PostHog (EU Cloud) | Anonymous product usage milestones | Anonymised milestone data only |
| Web3Forms / hCaptcha (website contact) | Contact form delivery and spam protection | Contact form fields and anti-bot signals |
We do not use Facebook SDK, advertising networks, or any data broker services.
Data Transfers Outside India
Legal agreement records, feedback tickets, newsletter subscribers, and Write for Us pitches are stored primarily in India on Hostinger infrastructure. Hostinger may keep backups in Singapore. Confirmation emails are sent through Hostinger mail.
Crash and usage analytics processors are located in the European Union: Sentry (EU ingest) and PostHog EU Cloud. Only the anonymised technical and milestone data described in section 4 is transmitted to those processors — never health data.
We will update this section if primary server locations change.
Retention Policy
| Data type | Retention period |
|---|---|
| Health and wellness data | Stays on your device; deleted when you clear data or uninstall the app |
Local .pbk backups | Under your control wherever you save the file |
| Legal agreement records | 7 years from acceptance (compliance), unless law requires longer |
| Analytics data | Aggregated and anonymised; individual session data retained for up to 13 months |
| Feedback tickets | Up to 12 months from resolution or last activity |
| Support correspondence | Up to 12 months from last contact |
| Newsletter subscribers | Until you unsubscribe or request deletion |
| Write for Us pitches | Until review is complete, then up to 12 months after a decision |
| Account deletion requests | Identifiable non-compliance data deleted within 30 days of request |
Cookies (Website Only)
Our website (periodandbeyond.com) may use cookies for basic functionality such as remembering your language preference. We do not use cookies for advertising or cross-site tracking. For full details, please see our Cookie Policy.
Changes to This Policy
If we make material changes to this policy, we will:
- Update the "Last updated" date at the top of this page
- Display a notice in the app or on the website
- For significant changes, request fresh consent where required under DPDPA
Continued use of the app after changes are posted constitutes acceptance of the updated policy.
Grievance Officer
In accordance with the Digital Personal Data Protection Act 2023, Devcollar Private Limited has appointed a Grievance Officer to address data-related concerns.
Name: Khan, S.
Designation: Director, Devcollar Private Limited
Organisation: Devcollar Private Limited
Email: support@devcollar.com
Response time: We will acknowledge your grievance within 48 hours and resolve it within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under DPDPA 2023.
Contact Us
For app support and general queries:
Email: support@periodandbeyond.com
Website: periodandbeyond.com
For legal, privacy, and DPDPA-related matters:
Email: support@devcollar.com
Company: Devcollar Private Limited, India
This Privacy Policy is the legally operative version. In case of conflict between the English and Hindi versions of this policy, the English version shall prevail.