Effective date: August 21, 2026. Version 1.0. Applies to: the Her Almanac mobile application ("the app"), published by Rowan Digital LLC, a North Carolina limited liability company ("Rowan Digital," "we," "us"). This policy is the privacy policy for the app and for heralmanac.app.
The short version
Everything you record in Her Almanac is stored only on your phone, encrypted, and is never transmitted to us. We operate no servers that hold your information, there are no accounts and no login, and the app contains no analytics, advertising, or crash-reporting software. We have no technical ability to see, recover, share, or sell anything you write down. The app has one optional network feature, and it runs only if you ask it to: a weather lookup for a city you type in, described below. This policy is short because there is very little to disclose.
What we receive
We receive nothing you record. The app has no account system and no login. Everything you record, which includes cycle events, symptoms, moods, journal entries, medications, health conditions and records, appointments together with the questions you plan to ask and the answers you receive, and an optional profile name and photo, is stored only on your device. It is encrypted at rest using AES-256, with the key held in your device's secure storage. It is never transmitted to us or to anyone else by the app.
Because that information never leaves your device, we cannot access it, recover it, disclose it, sell it, or produce it in response to a subpoena, a court order, or a request from any law enforcement or government agency in any state or country. That is not a promise about how we would behave. It is a description of what we are technically able to do. We do not possess your information, so there is nothing for us to hand over.
The one network feature: optional weather
This feature is off until you turn it on, and you never have to. If you choose to type a city name, the app sends that city name to Open-Meteo, a weather service operated by OpenMeteo GmbH in Switzerland, and uses what comes back to paint the app's background scenery. Two requests are made: one containing the city name you typed, and one containing the latitude and longitude that Open-Meteo returns for it.
The requests carry no account identifier, no advertising identifier, no device identifier, and no health information of any kind. Today they carry no key or credential at all. If we move to a paid weather subscription, they will carry a key that identifies Rowan Digital's account with the weather service and nothing about you. As with any internet request, the receiving server can see the internet address (IP address) your request came from; the app does not store it, and we never see it. Open-Meteo states that it may keep webserver log files that can include the coordinates in the request, that it does not share them with any third party, and that it deletes them after ninety days. It says its servers operate in Europe and North America. Its own terms are at open-meteo.com/en/terms.
The app does not ask for and does not have location permission. The city you type is not checked against where you actually are, and it can be any city you like. You can skip the feature, change the city, or remove it at any time in the app, and with the feature unused the app performs no network activity at all and works fully in airplane mode.
Backups are yours, and only yours
You can export a backup file that is encrypted with a password you choose. The file is created on your device and saved wherever you choose to put it through your phone's file picker. We never receive it and never see the password. Without that password the file is unreadable by anyone, including us. If you lose both the file's password and your device, no one can recover your information. This is a deliberate design, not a limitation we can waive.
One thing to keep in mind: once you save or send a backup file somewhere else, whether that is a cloud drive, an email, or another phone, it is subject to whatever rules apply to that place, and our promises about your device cannot follow it there. Choose where you put it accordingly.
Notifications
Reminders you set (like appointment nudges) are scheduled on your device by your device. Their content is marked private so it is hidden on your lock screen. Nothing about them is sent to us.
Permissions the app requests
- Notifications, to show reminders you set.
- Exact alarms and boot-completed, so reminders survive a phone restart.
- Internet, used only for the optional weather feature described above.
File access through your phone's own file picker, and only when you choose to export or restore a backup. The app sees only the single file you pick.
The app does not request location permission of any kind, and it does not request contacts, calendar access, or body sensors. If you choose to add a profile photo, you pick it through your phone's own photo picker, and the app receives only the single image you pick. Nothing in the app transmits any of this anywhere.
Deletion
In the app, Profile, then Privacy & Security, then Delete All My Data erases everything on your device instantly and permanently. There is no grace period, no retained copy, and nothing on our side to delete, because there was never anything on our side. Uninstalling the app also removes its data.
Since we hold nothing, we have no retention period and no deletion queue. What you keep, you keep for as long as you want it; what you erase is gone when you erase it.
Analytics, advertising, and third parties
There are none. The app contains no analytics software, no advertising software, no crash-reporting or attribution services, no social integrations, and no embedded web views. The only outside service the app contacts is the optional weather service described above.
We do not sell your information, and we do not share it, because we do not have it. We have never done so and we have no mechanism by which we could. If that ever changed, we would have to change this policy first, say so plainly, and ask you.
Your phone's operating system and the app store you installed from have their own privacy policies, which we do not control and which apply to your relationship with them rather than with us.
Children
Her Almanac is intended for adults and is not directed to children under 13. We do not knowingly receive personal information from a child under 13, and because the app has no accounts and transmits nothing to us, there is no channel through which we could. We also do not ask your age or your date of birth, and we do not want you to tell us. If you contact us by email and tell us you are under 13, we will delete your message rather than reply to it, and we will not keep a record of it.
Consumer health data laws, and your rights
Some of what you record in Her Almanac, including cycle events, symptoms, and anything you note about reproductive or sexual health, is treated as sensitive health information under laws such as Washington's My Health My Data Act, Nevada's consumer health data law, Connecticut's consumer data privacy law and Virginia's consumer protection act, California's Confidentiality of Medical Information Act, the California Consumer Privacy Act, and the EU and UK General Data Protection Regulation. We take that seriously, and the app is built so that the protections those laws are aimed at are structural rather than promised.
We do not receive your health information, and we have no way to. It stays on your device, under your control, encrypted. Nothing about it is transmitted to us, sold, or shared with anyone, for money or for anything else, and we do not intend that ever to change. We do not use geofencing, we do not track you across apps or websites, and we do not build profiles.
Rights that these laws give you, such as the right to know what is held about you, to get a copy of it, to correct it, and to have it deleted, are built into the app rather than into a request form. You can read everything you have recorded, export it, correct it, and erase all of it permanently, at any time, without asking us and without waiting for us. There is nothing for us to confirm, produce, or delete, and no list of third parties to give you, because there are none.
If you have a question about any of this, write to us at the address below and we will answer in writing. If you believe we have not honored something this policy says, you may also contact the attorney general in your state.
Before you begin recording anything, the app asks you to confirm that you understand what it stores on your device. If we ever build a feature that would send any of it anywhere, we will describe that feature plainly, ask for your permission first in the app rather than in a document like this one, and treat a decision to say no as final.
How your information is protected
Everything you record is encrypted on your device at rest using AES-256, with the encryption key held in your device's secure storage and never transmitted anywhere. You can set an app PIN and a recovery answer for a second layer. Reminders you schedule are marked private so their content stays hidden on your lock screen. Backup files you export are encrypted with a password you choose and that we never see. Because we hold no copy of your information, there is no company database that could be breached, and no incident on our side could expose what you have written down.
Changes to this policy
If the app ever changes how it handles data (for example, a future optional feature), we will update this policy, change the effective date, and describe the change plainly. The core promise, that your health data stays on your device, is the foundation of the product.
Contact
Rowan Digital LLC, Wilmington, North Carolina, United States. Email hello@heralmanac.app.
Rowan Digital LLC is the publisher of Her Almanac on Google Play and the Apple App Store and is the company responsible for this policy. If you need a postal address for a formal notice, write to us at the email address above and we will provide one promptly.