Legal

Privacy Policy

Last updated: August 6, 2026

We built superwoman to help you work with your body — not around it. That means your data, especially your cycle data, is treated with the same care. This policy explains exactly what we collect, how we use it, and the choices you always have.

Transparency

What We Collect

Waitlist & account data

Your name and email address when you request early access, plus your Google Account identifier, profile photo, timezone, onboarding state, and the profile and preference information you provide after creating an account.

Standard

Cycle & health data

Cycle length, period length, last period date, daily period logs (flow level, symptoms, notes), and the phase predictions we calculate.

Sensitive

Calendar & event data

Calendar identifiers and settings; event titles, descriptions, locations, dates and times, recurrence, reminders, organizers, attendees, RSVP state, guest permissions, availability, conference details, and synchronization metadata.

Standard

Google Calendar data

Google Calendar connection and read/write permission are required for the current superwoman experience. OAuth access and refresh tokens are encrypted server-side using Supabase Vault and are not stored in your browser.

Required

Google Contacts data

Read-only Contacts access is requested during the initial Google connection. We search names, email addresses, photos, saved contacts, and available Google “Other contacts” on demand for guest suggestions. Your address book is not edited, copied into, or retained by superwoman.

Required

Billing & referral data

When billing is activated, we may store Stripe customer, subscription, trial, price, invoice, promotion, referral, and payment-state identifiers. Complete card details are entered into and handled by Stripe, not stored by superwoman. Referral reward records do not expose the referred person's identity to the referrer.

When applicable

Technical data

IP address and limited request, browser, and device information may be processed by our hosting and security providers to deliver, secure, and troubleshoot the Service.

Standard

In-app product analytics

A pseudonymous browser identifier, app opens, query-free app routes, coarse feature actions, browser, operating-system and device categories, timestamps, and limited success or status signals. Product analytics is on by default for new accounts and can be turned off in Settings.

Your choice

Purpose

How We Use Your Data

Everything we collect has one purpose: making superwoman work for you. We use your data to:

  • Confirm your waitlist request and send the launch and product updates you agreed to receive
  • Calculate estimated cycle phases and show cycle-aware insights for the relevant event date
  • Provide the calendar replacement experience by displaying and synchronizing calendars and events
  • Create, edit, move, repeat, delete, and share calendar information at your direction
  • Manage guests, invitations, RSVP state, reminders, availability, and Google Meet details
  • Return read-only Google Contacts suggestions on demand when you add guests
  • Operate subscriptions, trials, invoices, promotion codes, and referral benefits through Stripe when billing is activated
  • Measure app opens, activation, retention, and coarse feature use so we can improve the product and its reliability
  • Debug issues and improve the reliability and performance of the app

We do not use your data for advertising, profiling outside the app, or any purpose unrelated to providing you with superwoman.

Google Data

Google API Limited Use

superwoman's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

  • Google user data is used only to provide or improve the user-facing calendar, scheduling, invitation, availability, conferencing, and read-only contact-suggestion features described here.
  • We do not sell Google user data, use it for advertising, build unrelated profiles from it, or transfer it for unrelated purposes.
  • People do not read Google user data except with your affirmative permission for support or security, when needed to investigate abuse or comply with law, or when appropriately aggregated and anonymized for internal operations where legally permitted.
  • Google Contacts access is read-only and requested with Calendar access during the initial connection. We use it only for on-demand guest suggestions and do not edit, copy, or retain your address book.

Health Data

A Commitment to Your Privacy

Your cycle and period data is sensitive health information. We treat it accordingly.

  • We never sell it — not to advertisers, data brokers, or anyone else.
  • We never share it with third parties for marketing, analytics, or research.
  • We use it only to run the app — specifically to calculate your cycle phases and personalise your calendar.
  • You control it — you can update cycle information and period logs, export supported data, or delete your account from Settings.

Where applicable law treats cycle information as sensitive or special-category data, we rely on your affirmative choice to provide and use it for the cycle-planning features described here.

Sharing

Who We Share With

We do not sell your data. We share it only with the following service providers, and only to the extent needed to operate superwoman.

Supabase

Infrastructure provider

Provides our database, authentication, Edge Functions, application storage, and Vault-based encryption for Google OAuth credentials.

Google

Required Calendar and read-only Contacts integration

superwoman exchanges calendar data with Google at your direction. Google returns matching read-only contact suggestions on demand when you add guests. Google's handling of data is subject to Google's Privacy Policy.

Cloudflare

Hosting, delivery, and security

Hosts and delivers the web application and processes limited request and technical information needed for performance, reliability, and security.

Google Analytics

Landing-site analytics

With your consent, measures visits and interactions on the public superwoman website using limited browser, device, and usage information. We do not send cycle or calendar content to Google Analytics.

PostHog

In-app product analytics

Processes limited, pseudonymous product-use events in its US Cloud so we can understand app opens, activation, retention, feature use, and reliability. We do not send PostHog your superwoman account ID, name, email address, timezone, calendar or event content, contacts, search text, or cycle and health data.

Stripe

Billing provider when payments are activated

Provides Checkout, subscriptions, the Customer Portal, invoices, applicable tax functions, promotion codes, referral credits, and payment processing. Stripe receives the billing, contact, and payment information you enter into Stripe surfaces.

Resend

Email provider

Receives your name and email address to send waitlist confirmations, early-access invitations, and the launch or product updates you agreed to receive.

Slack

Internal signup notifications

Receives the signup type, name, email address, and timestamp in a private operational channel when someone joins the waitlist or creates an account.

Legal authorities

When required by law

We may disclose your data if required by law, court order, or to protect the rights, property, or safety of superwoman, our users, or others.

Security

How We Protect It

  • Protected in transit and at rest. We use HTTPS for data in transit and rely on our infrastructure providers' storage and access controls for data at rest.

  • Database access controls. Row-level policies and authenticated server boundaries restrict access to application data.

  • Server-only Google credentials. Google OAuth tokens are encrypted with Supabase Vault. Browser clients have no direct table or function access to the credentials; authenticated server code and Edge Functions use them for Google operations and token refresh.

  • Stripe-hosted payment handling. When billing is activated, Stripe processes payment-card information. superwoman does not receive or store complete payment-card numbers.

Data typeRetention policy

Waitlist data

Retained while you are waiting for or using early access, unless you unsubscribe or ask us to delete it sooner.

Account & calendar data

Retained while your account is active. Associated application records are removed through database cascades when server-side account deletion completes.

Cycle & health data

Retained while needed for the cycle features you use and removed with associated application data when server-side account deletion completes.

Google OAuth tokens

Google access is revoked where possible and stored credentials are removed when account deletion completes. Revocation can also be managed in your Google Account.

In-app product analytics

PostHog product-analytics events are configured for a 12-month retention period. Turning Product analytics off stops new capture and clears the active browser analytics identifier.

Billing, backups & technical records

Active Stripe billing is cancelled during deletion. Billing, dispute, fraud-prevention, tax, transaction, backup, and infrastructure records may remain for applicable legal, accounting, security, or normal provider-expiry requirements.

Control

Your Rights

Access

Request a copy of all the personal data we hold about you.

Email support@superwoman.so

Correction

Update supported profile, calendar, and cycle information from the app.

Available in Settings

Deletion

Start permanent server-side account deletion with visible progress. The app reports a failure if deletion does not finish.

Available in Settings

Export

Export your calendar events in ICS or CSV format at any time.

Available in the app

Portability

Request your data in a structured, machine-readable format.

Email support@superwoman.so

Analytics, Google & billing controls

Turn Product analytics off, revoke Google access, reconnect Calendar and Contacts when required permissions are missing, and manage active billing through the Stripe Customer Portal.

Settings, Google Account, and Stripe Portal

Depending on where you live, applicable privacy law may provide additional rights, including the right to complain to a data protection authority.

Fine Print

Cookies, Children & Changes

Cookies

We use essential browser storage and session technologies needed to authenticate you and operate the app. The public superwoman website loads Google Analytics only after you accept optional analytics cookies. You can reject analytics or reopen Cookie settings from the footer at any time. Limited in-app product analytics is on by default for new accounts. You can turn it off at any time in Settings → Privacy → Product analytics; existing saved choices remain unchanged. Turning it off stops new PostHog capture and clears the active pseudonymous browser analytics identifier. Essential authentication, security, abuse prevention, synchronization, and operational processing continue because they are needed to provide and protect the Service. We do not use advertising cookies.

PostHog autocapture, session recording, heatmaps, performance capture, exception capture, and person profiles are disabled. A strict event-property allowlist excludes account identity and private content, removes full URLs, referrers, timezone, language, screen dimensions, raw user-agent data, and unreviewed properties, and sends only query-free app route paths. GeoIP enrichment is disabled for each event and PostHog is configured to discard client IP data. We use these events only to improve superwoman, not for advertising or to sell personal information.

You can block cookies in your browser settings, but this will prevent you from staying logged in.

Children's privacy

superwoman is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will promptly delete it.

Changes to this policy

If we make material changes, we will provide notice through the Service or another appropriate channel where required. Minor changes update the date at the top of this page.

Continued use after a change goes into effect means you accept the updated policy.

Legal bases & international processing

Where applicable law requires a legal basis, we rely as appropriate on performing our contract with you, your consent for optional or sensitive-data features, legitimate interests in operating, securing, and improving the Service, and legal obligations. Product analytics remains subject to the in-app choice described above.

Our providers may process information outside your province, state, or country, where it may be subject to local law. We use provider and contractual safeguards appropriate to the service and applicable requirements. PostHog processes the limited product-analytics events described above in the United States.

Questions about your data?

Contact Mariyam & Co Inc. for privacy questions or requests.

support@superwoman.so