Privacy Policy
Last updated: April 2026
Effective date: April 2026
Who We Are
Period & Beyond is a product of Devcollar Private Limited, a company registered under the Companies Act 2013 in India.
- Registered name: Devcollar Private Limited
- Product: Period & Beyond
- Contact: support@periodandbeyond.com
- Website: periodandbeyond.com
When this policy says "we", "us", or "our", it refers to Devcollar Private Limited acting as the Data Fiduciary (data controller) under India's Digital Personal Data Protection Act 2023 (DPDPA).
The Short Version
We built Period & Beyond on a single principle: your health data belongs to you, not to us.
- Your period tracking data, symptoms, moods, notes, and all personal wellness information lives on your device only.
- We do not have a server that stores your health data.
- We do not sell your data. Ever.
- We do not show you ads.
- We collect only the minimum technical information needed to keep the app functioning well.
If you want the full details, read on.
What Data We Collect and Why
1. Health and Wellness Data (Stays on Your Device)
This includes everything you log in the app:
- Period dates, flow levels, duration
- Symptoms and pain levels
- Mood and emotional state
- Private notes
- Intimacy logs (if you use this feature)
- Cycle predictions and insights generated from your data
Where it lives: Exclusively on your device, in an encrypted local database. We cannot access this data. It does not travel to our servers. Even if we wanted to, we have no technical means to read it.
Legal basis under DPDPA: You give explicit consent during onboarding before any data is recorded.
2. Optional Profile Information (Stays on Your Device)
The app offers a profile section where you can voluntarily add personal details to give your experience a more personalised feel:
- Your name
- Your age
- Your email address
- An "About me" note
All of this is entirely optional. The app works fully without it. If you do add it, this information is stored only on your device — it is never sent to our servers, never used for analytics, and never shared with anyone.
Legal basis under DPDPA: Voluntary consent; you choose whether to provide this information.
3. Analytics and Performance Data (Anonymised)
To understand whether the app is functioning correctly and to fix technical problems, we collect anonymised, non-personal information such as:
- Device type and operating system version
- App version
- Crash reports and error logs
- General usage patterns (e.g. which screens are visited, how long sessions last)
What this does NOT include: Any health data, your name, your email address, or any information that could identify you personally.
Tool used: We use a privacy-respecting analytics tool (such as Google Analytics for Firebase or a self-hosted equivalent). The specific tool in use will be updated here when confirmed.
Legal basis under DPDPA: Legitimate interest in maintaining a functioning, safe application.
4. Voluntary Contact Data
If you contact us for support via support@periodandbeyond.com or through any contact form on the website, we collect:
- Your name (if you provide it)
- Your email address
- The content of your message
Purpose: To respond to your query.
Retention: We retain support correspondence for up to 12 months, then delete it.
Legal basis under DPDPA: Consent given by initiating contact.
5. Donation Data (If You Choose to Support Us)
If you make a voluntary donation through our "Support the App" mechanism:
- Payment processing is handled entirely by the payment provider (such as Razorpay or the relevant app store)
- We receive only a transaction confirmation and amount
- We do not store your card details, UPI ID, or full payment information
Legal basis under DPDPA: Consent given by initiating the donation.
6. Partner Sharing (If You Use This Feature)
If you choose to share your cycle information with a partner:
- You select exactly what data to share (period dates only, by default)
- Data is end-to-end encrypted on your device before being transmitted
- It passes through a minimal relay server operated by Devcollar Pvt. Ltd.
- The relay server never stores your health data — it holds encrypted messages only until your partner's device receives them (typically seconds), then permanently deletes them
- Your partner cannot access any data beyond what you explicitly choose to share
- You can revoke partner access at any time; their copy is deleted immediately
Legal basis under DPDPA: Explicit consent, given at the time you initiate partner sharing.
7. Future: Cloud Backup (Google Drive / iCloud)
We plan to offer an optional backup feature in a future version. If enabled:
- Your encrypted data will be stored in your own Google Drive or Apple iCloud account
- Devcollar Pvt. Ltd. will have no access to this storage
- The backup will be protected by the same encryption used on your device
- This feature will be fully opt-in; the app works completely without it
This section will be updated when the feature is released.
Data We Do Not Collect
We want to be explicit about what we never collect under any circumstances:
- We do not collect your location
- We do not collect your contact lists or call logs
- We do not collect information about other apps on your device
- We do not build advertising profiles
- We do not share any data with advertisers
- We do not sell data to any third party
Any personal information you optionally add to your profile (name, age, email, about me) stays on your device only and is never transmitted to us.
How Your Data Is Protected
We take security seriously, particularly given the sensitive nature of health data.
- Database encryption: Your local database is encrypted using SQLCipher (AES-256).
- Field-level encryption: Particularly sensitive fields (such as private notes) are encrypted with an additional layer of AES-256 encryption.
- Biometric protection: The app supports Face ID, fingerprint, and PIN authentication to prevent unauthorised access on your device.
- Stealth mode: The app can be configured to show a neutral preview in your device's task switcher and to require authentication every time it opens, protecting you in shared-device situations.
- Transit encryption: Any data that moves between devices (partner sharing) is end-to-end encrypted before leaving your device. Our relay server sees only encrypted data it cannot read.
Your Rights Under DPDPA 2023
As a user in India, you have the following rights:
Right to access: You can request a summary of the personal data we hold about you (this is limited, given that most data stays on your device).
Right to correction: You can correct your data directly within the app at any time.
Right to erasure (Right to be Forgotten): You can delete all your data from within the app at any time. Upon account deletion, any data held by us (analytics identifiers, support correspondence if applicable) will be permanently deleted within 30 days.
Right to withdraw consent: You can withdraw consent for analytics or partner sharing at any time in the app settings. Withdrawal does not affect data processed before withdrawal.
Right to grievance redressal: If you believe your rights have been violated, you can contact our Grievance Officer (see below).
Right to nominate: Under DPDPA, you have the right to nominate another individual to exercise your data rights in the event of your death or incapacity. To do so, contact us at support@devcollar.com.
Children's Privacy
Period & Beyond is intended for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. Age verification is performed during onboarding.
If you believe a minor has used the app and provided data, please contact us at support@devcollar.com and we will take immediate steps to delete that data.
Under DPDPA 2023, processing of data relating to children (under 18) requires verifiable parental consent. Our age gate is designed to prevent under-18 users from accessing the app.
Third-Party Services
The app uses a limited number of third-party services. Each has its own privacy policy.
| Service | Purpose | Data shared |
|---|---|---|
| Google Analytics / Firebase (or equivalent) | App performance monitoring | Anonymised device and usage data only |
| Payment provider (Razorpay / App Store / Play Store) | Donation processing | Payment transaction data only |
| Google Drive / Apple iCloud | Optional backup (future feature) | Encrypted backup files stored in your own account |
We do not use Facebook SDK, advertising networks, or any data broker services.
Data Transfers Outside India
Our relay server for partner sharing may be hosted on infrastructure located outside India (e.g. DigitalOcean servers in Singapore or another region). In all such cases:
- Only encrypted data passes through this infrastructure
- No plaintext health data ever leaves your device
- We apply equivalent safeguards required under DPDPA for cross-border data transfers
We will update this section with the specific server location once confirmed.
Retention Policy
| Data type | Retention period |
|---|---|
| Health and wellness data | Stays on your device; deleted immediately when you delete it or uninstall the app |
| Partner sharing relay data | Deleted from relay server within seconds of delivery; maximum 24 hours if partner device is offline |
| Analytics data | Aggregated and anonymised; individual session data retained for up to 13 months |
| Support correspondence | Up to 12 months from last contact |
| Donation records | As required by Indian tax and accounting laws (typically 7 years) |
| Account deletion requests | All identifiable data deleted within 30 days of request |
Cookies (Website Only)
Our website (periodandbeyond.com) may use cookies for basic functionality such as remembering your language preference. We do not use cookies for advertising or cross-site tracking. For full details, please see our Cookie Policy.
Changes to This Policy
If we make material changes to this policy, we will:
- Update the "Last updated" date at the top of this page
- Display a notice in the app or on the website
- For significant changes, request fresh consent where required under DPDPA
Continued use of the app after changes are posted constitutes acceptance of the updated policy.
Grievance Officer
In accordance with the Digital Personal Data Protection Act 2023, Devcollar Private Limited has appointed a Grievance Officer to address data-related concerns.
Name: Khan, S.
Designation: Director, Devcollar Private Limited
Organisation: Devcollar Private Limited
Email: support@devcollar.com
Response time: We will acknowledge your grievance within 48 hours and resolve it within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under DPDPA 2023.
Contact Us
For app support and general queries:
Email: support@periodandbeyond.com
Website: periodandbeyond.com
For legal, privacy, and DPDPA-related matters:
Email: support@devcollar.com
Company: Devcollar Private Limited, India
This Privacy Policy is the legally operative version. In case of conflict between the English and Hindi versions of this policy, the English version shall prevail.