개인정보 처리방침
Cyra의 데이터 처리, 보관, 삭제, 제3자 서비스 정보를 확인하세요.
데이터 사용
앱 기능 제공, 동기화, 지원 응답, 안정성 개선에 필요한 정보만 다룹니다.
삭제와 보관
계정 또는 데이터 삭제는 앱 안의 삭제 기능이나 지원 이메일을 통해 요청할 수 있습니다.
추적 제한
광고 목적의 제3자 추적이나 개인정보 판매를 전제로 설계하지 않았습니다.
This Privacy Policy explains how Cyra collects, uses, and protects information when you use the app. Cyra handles sensitive health data — we take that responsibility seriously.
1. Information We Collect
1.1 You provide
- Account: email/password (password stored as a bcrypt hash), Apple ID identifier, or Google account identifier
- Health logs: menstrual cycle data, symptoms, mood, diet (carbohydrate and sugar intake), exercise, medications and supplements, sleep hours, weight
- Onboarding history: PCOS diagnosis status and retrospective symptom history you enter at setup
1.2 Automatically collected
- Subscription state via RevenueCat
- Crash and error logs (90-day retention)
1.3 Not collected
- Location, contacts, photo library, microphone, IDFA
- Advertising identifiers — Cyra contains no advertising SDK
2. How We Use Information
| Purpose | Data used |
|---|---|
| Authentication | Email, Apple identifier, or Google identifier |
| Health log storage and sync | All health log data via Supabase |
| AI pattern analysis and chat | Pseudonymised symptom and log summaries (see Section 3) |
| Proactive alerts | Log data processed server-side to detect symptom patterns |
| In-app purchases | RevenueCat transaction IDs |
| Bug diagnosis | Crash and error logs |
3. AI Analysis and Anthropic
Cyra uses Claude (Anthropic PBC, USA) to generate pattern insights and power the AI chat feature. When you use these features, a pseudonymised summary of your health logs — and, in AI Chat, the messages you type — is sent to Anthropic. Specifically:
- Data sent: PCOS diagnosis status; symptom, menstrual cycle, mood, diet, exercise, sleep, and weight log summaries; medications and supplements you list; and the messages you type into AI Chat
- Your account email, display name, and account identifiers are never transmitted to Anthropic
- Anthropic does not use this data to train its models (see Anthropic's API data privacy policy)
- Under Anthropic's standard commercial API terms, request inputs and outputs are deleted from Anthropic's systems within 30 days. Cyra does not have a zero-data-retention agreement with Anthropic, so this 30-day window applies
- All transmission is encrypted with HTTPS/TLS
- We describe this as pseudonymised rather than anonymous: direct identifiers are removed before transmission, but the underlying logs remain associated with your account in our own systems, and the resulting output is written back to your account. It is therefore still personal data
- Messages you type into AI Chat are transmitted as you wrote them, not summarised. Please avoid entering names or other identifying details you do not want sent to Anthropic
3.1 Your explicit consent
Cyra will not send any data to Anthropic until you grant consent in the app. You are asked for consent during onboarding via the “AI Data Sharing” screen, which lists the exact categories of data above, names Anthropic as the recipient, and links to Anthropic's privacy policy.
3.2 Revoking consent
You can revoke your consent at any time in the app: Settings → AI Data Sharing. When revoked, Cyra stops sending data to Anthropic; AI pattern insights and AI Chat become unavailable, while the rest of the app continues to work normally. You may re-enable consent from the same screen.
4. Menstrual and Reproductive Health Data
Cyra collects menstrual cycle and reproductive health data. We treat this category with heightened protection:
- This data is never sold, shared with advertisers, or disclosed to third parties for commercial purposes
- We will not voluntarily disclose menstrual or reproductive health data to law enforcement absent a legally binding court order, and we will notify you of any such request to the extent permitted by law
- Data is stored in Supabase with Row Level Security — only you can read your records
5. Third-Party Services
| Recipient | Data shared | Retention |
|---|---|---|
| Supabase Inc. (USA) | Email, identifier, health logs | Deleted on account deletion |
| RevenueCat Inc. (USA) | App user ID, transaction IDs | 5 years from transaction |
| Anthropic PBC (USA) | Pseudonymised symptom and log summaries, and AI Chat messages as typed | Deleted within 30 days (Anthropic standard API retention) |
| Apple Inc. | Apple identifier (Sign in with Apple) | Per Apple's policy |
| Google LLC | Google identifier (Sign in with Google) | Per Google's policy |
6. Data Retention
| Data | Period |
|---|---|
| Account and health logs | Deleted immediately on account deletion |
| Subscription records | 5 years (pseudonymised) for legal compliance |
| Error logs | 90 days |
7. Your Rights — Account & Data Deletion
7.1 Delete your account in-app
Settings → Account → Delete Account. Your account credentials, all health logs, AI chat history, and cloud-synced data are permanently removed immediately.
7.2 Email request
If you cannot access the in-app option, email [email protected] with your registered email. Processed within 3 business days.
7.3 Revoke Sign in with Apple
iPhone Settings → [Your Name] → Password & Security → Sign in with Apple → Cyra → Stop Using Apple ID.
7.4 Revoke Sign in with Google
Visit myaccount.google.com/permissions and revoke Cyra's access.
8. Security
- HTTPS/TLS for all network traffic
- Passwords hashed with bcrypt
- API keys stored in iOS Keychain
- Supabase Row Level Security for user data isolation
- Health log summaries sent to Anthropic are stripped of account identifiers before transmission
9. Cookies and Tracking
No cookies. No IDFA. No advertising SDK. RevenueCat may use an anonymous device identifier for subscription status only.
10. Children's Privacy
Not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children.
11. International Transfers
All third-party processors are based in the United States. Transfers are governed by each provider's data processing agreements.
12. Changes
Material changes announced via in-app notice or email at least 7 days before taking effect (30 days for significant changes affecting health data handling).
13. Contact
Email: [email protected]. We respond within 3 business days.
지원이 필요하신가요?
앱, 계정, 결제, 데이터 삭제 문의는 이메일로 보내주세요.