Legal
Privacy Policy
Last updated: August 6, 2026
We built superwoman to help you work with your body — not around it. That means your data, especially your cycle data, is treated with the same care. This policy explains exactly what we collect, how we use it, and the choices you always have.
Transparency
What We Collect
Waitlist & account data
Your name and email address when you request early access, plus your Google Account identifier, profile photo, timezone, onboarding state, and the profile and preference information you provide after creating an account.
StandardCycle & health data
Cycle length, period length, last period date, daily period logs (flow level, symptoms, notes), and the phase predictions we calculate.
SensitiveCalendar & event data
Calendar identifiers and settings; event titles, descriptions, locations, dates and times, recurrence, reminders, organizers, attendees, RSVP state, guest permissions, availability, conference details, and synchronization metadata.
StandardGoogle Calendar data
Google Calendar connection and read/write permission are required for the current superwoman experience. OAuth access and refresh tokens are encrypted server-side using Supabase Vault and are not stored in your browser.
RequiredGoogle Contacts data
Read-only Contacts access is requested during the initial Google connection. We search names, email addresses, photos, saved contacts, and available Google “Other contacts” on demand for guest suggestions. Your address book is not edited, copied into, or retained by superwoman.
RequiredBilling & referral data
When billing is activated, we may store Stripe customer, subscription, trial, price, invoice, promotion, referral, and payment-state identifiers. Complete card details are entered into and handled by Stripe, not stored by superwoman. Referral reward records do not expose the referred person's identity to the referrer.
When applicableTechnical data
IP address and limited request, browser, and device information may be processed by our hosting and security providers to deliver, secure, and troubleshoot the Service.
StandardIn-app product analytics
A pseudonymous browser identifier, app opens, query-free app routes, coarse feature actions, browser, operating-system and device categories, timestamps, and limited success or status signals. Product analytics is on by default for new accounts and can be turned off in Settings.
Your choicePurpose
How We Use Your Data
Everything we collect has one purpose: making superwoman work for you. We use your data to:
- Confirm your waitlist request and send the launch and product updates you agreed to receive
- Calculate estimated cycle phases and show cycle-aware insights for the relevant event date
- Provide the calendar replacement experience by displaying and synchronizing calendars and events
- Create, edit, move, repeat, delete, and share calendar information at your direction
- Manage guests, invitations, RSVP state, reminders, availability, and Google Meet details
- Return read-only Google Contacts suggestions on demand when you add guests
- Operate subscriptions, trials, invoices, promotion codes, and referral benefits through Stripe when billing is activated
- Measure app opens, activation, retention, and coarse feature use so we can improve the product and its reliability
- Debug issues and improve the reliability and performance of the app
We do not use your data for advertising, profiling outside the app, or any purpose unrelated to providing you with superwoman.
Google Data
Google API Limited Use
superwoman's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- Google user data is used only to provide or improve the user-facing calendar, scheduling, invitation, availability, conferencing, and read-only contact-suggestion features described here.
- We do not sell Google user data, use it for advertising, build unrelated profiles from it, or transfer it for unrelated purposes.
- People do not read Google user data except with your affirmative permission for support or security, when needed to investigate abuse or comply with law, or when appropriately aggregated and anonymized for internal operations where legally permitted.
- Google Contacts access is read-only and requested with Calendar access during the initial connection. We use it only for on-demand guest suggestions and do not edit, copy, or retain your address book.
Health Data
A Commitment to Your Privacy
Your cycle and period data is sensitive health information. We treat it accordingly.
- We never sell it — not to advertisers, data brokers, or anyone else.
- We never share it with third parties for marketing, analytics, or research.
- We use it only to run the app — specifically to calculate your cycle phases and personalise your calendar.
- You control it — you can update cycle information and period logs, export supported data, or delete your account from Settings.
Where applicable law treats cycle information as sensitive or special-category data, we rely on your affirmative choice to provide and use it for the cycle-planning features described here.
Sharing
Who We Share With
We do not sell your data. We share it only with the following service providers, and only to the extent needed to operate superwoman.
Supabase
Infrastructure provider
Provides our database, authentication, Edge Functions, application storage, and Vault-based encryption for Google OAuth credentials.
Required Calendar and read-only Contacts integration
superwoman exchanges calendar data with Google at your direction. Google returns matching read-only contact suggestions on demand when you add guests. Google's handling of data is subject to Google's Privacy Policy.
Cloudflare
Hosting, delivery, and security
Hosts and delivers the web application and processes limited request and technical information needed for performance, reliability, and security.
Google Analytics
Landing-site analytics
With your consent, measures visits and interactions on the public superwoman website using limited browser, device, and usage information. We do not send cycle or calendar content to Google Analytics.
PostHog
In-app product analytics
Processes limited, pseudonymous product-use events in its US Cloud so we can understand app opens, activation, retention, feature use, and reliability. We do not send PostHog your superwoman account ID, name, email address, timezone, calendar or event content, contacts, search text, or cycle and health data.
Stripe
Billing provider when payments are activated
Provides Checkout, subscriptions, the Customer Portal, invoices, applicable tax functions, promotion codes, referral credits, and payment processing. Stripe receives the billing, contact, and payment information you enter into Stripe surfaces.
Resend
Email provider
Receives your name and email address to send waitlist confirmations, early-access invitations, and the launch or product updates you agreed to receive.
Slack
Internal signup notifications
Receives the signup type, name, email address, and timestamp in a private operational channel when someone joins the waitlist or creates an account.
Legal authorities
When required by law
We may disclose your data if required by law, court order, or to protect the rights, property, or safety of superwoman, our users, or others.
Security
How We Protect It
Protected in transit and at rest. We use HTTPS for data in transit and rely on our infrastructure providers' storage and access controls for data at rest.
Database access controls. Row-level policies and authenticated server boundaries restrict access to application data.
Server-only Google credentials. Google OAuth tokens are encrypted with Supabase Vault. Browser clients have no direct table or function access to the credentials; authenticated server code and Edge Functions use them for Google operations and token refresh.
Stripe-hosted payment handling. When billing is activated, Stripe processes payment-card information. superwoman does not receive or store complete payment-card numbers.
Waitlist data
Retained while you are waiting for or using early access, unless you unsubscribe or ask us to delete it sooner.
Account & calendar data
Retained while your account is active. Associated application records are removed through database cascades when server-side account deletion completes.
Cycle & health data
Retained while needed for the cycle features you use and removed with associated application data when server-side account deletion completes.
Google OAuth tokens
Google access is revoked where possible and stored credentials are removed when account deletion completes. Revocation can also be managed in your Google Account.
In-app product analytics
PostHog product-analytics events are configured for a 12-month retention period. Turning Product analytics off stops new capture and clears the active browser analytics identifier.
Billing, backups & technical records
Active Stripe billing is cancelled during deletion. Billing, dispute, fraud-prevention, tax, transaction, backup, and infrastructure records may remain for applicable legal, accounting, security, or normal provider-expiry requirements.
Control
Your Rights
Access
Request a copy of all the personal data we hold about you.
Email support@superwoman.so
Correction
Update supported profile, calendar, and cycle information from the app.
Available in Settings
Deletion
Start permanent server-side account deletion with visible progress. The app reports a failure if deletion does not finish.
Available in Settings
Export
Export your calendar events in ICS or CSV format at any time.
Available in the app
Portability
Request your data in a structured, machine-readable format.
Email support@superwoman.so
Analytics, Google & billing controls
Turn Product analytics off, revoke Google access, reconnect Calendar and Contacts when required permissions are missing, and manage active billing through the Stripe Customer Portal.
Settings, Google Account, and Stripe Portal
Depending on where you live, applicable privacy law may provide additional rights, including the right to complain to a data protection authority.
Fine Print
Cookies, Children & Changes
Children's privacy
superwoman is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will promptly delete it.
Changes to this policy
If we make material changes, we will provide notice through the Service or another appropriate channel where required. Minor changes update the date at the top of this page.
Continued use after a change goes into effect means you accept the updated policy.
Legal bases & international processing
Where applicable law requires a legal basis, we rely as appropriate on performing our contract with you, your consent for optional or sensitive-data features, legitimate interests in operating, securing, and improving the Service, and legal obligations. Product analytics remains subject to the in-app choice described above.
Our providers may process information outside your province, state, or country, where it may be subject to local law. We use provider and contractual safeguards appropriate to the service and applicable requirements. PostHog processes the limited product-analytics events described above in the United States.
Questions about your data?
Contact Mariyam & Co Inc. for privacy questions or requests.