HeySis Privacy Policy

Effective date: July 22, 2026 · Contact: wantbefree48@gmail.com

HeySis is a cycle-tracking and educational wellness app with an AI companion, Mia (the "App"). This policy explains what data the App processes, why, where it goes, and the choices and rights you have. It applies to the App and to this website.

Our starting point is simple: your diary is yours. HeySis works without an account, keeps your diary on your device by default, has no advertising SDK, no third-party analytics SDK and no social login. We never sell your data, never share it with data brokers, and never use your health data for advertising or marketing.

1. Who is responsible

The App is operated by the HeySis team (the "we" in this policy). For any privacy question or request, contact wantbefree48@gmail.com. We will identify the formal legal entity and, where required, appointed representatives in this policy before wide commercial release; the contact above is authoritative for all data requests in the meantime.

2. The short version

3. Data we process

Data you enter in the App. Period dates and flow, symptoms, mood, energy, discharge, test results, sex and libido, activity, stress, notes; your first name or nickname, birth year and cycle goal if you choose to provide them; and the cycle statistics and predictions the App calculates from your entries. This data is stored in the App's private local database on your device and is excluded from operating-system cloud backup.

Apple Health data (optional). If you grant Health permission, the App may read only the categories shown on the system permission screen — for example steps, sleep or wrist temperature — as background context for Mia. Health access is optional and revocable at any time in iOS Settings. If you separately enable period-log sharing, HeySis writes only period flow and selected symptoms to Apple Health — never notes, mood, sexual activity or Mia conversations. HeySis never uses Health data for advertising, marketing, data mining or disclosure to data brokers.

Messages to Mia. What you write in the chat, processed as described in section 6.

Technical data. When the App talks to our backend (only for the optional online features), our infrastructure processes standard technical data such as IP address, request time, app version and abuse signals, for security and operation of the service. Our servers do not log the content of AI conversations ("no-store").

First-party product analytics. If enabled in the App's privacy settings, HeySis sends a small set of structural usage events to our Supabase backend: for example a screen or button identifier, whether Mia answered online or on device, response-latency range, app build, OS major version, locale and a random installation identifier. These events never contain Health or cycle values, dates, symptoms, mood, diary text, names or Mia messages. There is no third-party analytics SDK, advertising identifier or cross-app tracking. You can turn this off at any time in Profile → Data & privacy.

App Store ad attribution. If you installed HeySis after seeing one of our ads on the App Store, Apple can tell us which of our own campaigns brought that install. We receive campaign-level fields only — campaign, ad group, keyword and ad identifiers, country or region and conversion type — through Apple's AdServices API. Because HeySis never shows a tracking prompt, Apple withholds the click timestamp from us. It contains no device identifier, no advertising identifier and nothing that identifies you, and it never leaves our backend. We store it beside your anonymous HeySis account so we can tell which advertising pays for itself. It is covered by the same switch as product analytics: turn that off and no attribution is sent either.

Support communications. If you email us, we receive your email address and what you write. Please do not include cycle details or Health data in support emails.

What we do not collect: advertising identifiers, contacts, precise location, browsing history, or any data from third-party trackers — the App contains none.

4. Why we process data, and on what legal basis

We never show you ads, never sell or share your data with advertising networks, never profile you for marketing, and never make automated decisions with legal effect about you. Measuring which of our own App Store campaigns brought an install (see "App Store ad attribution" above) is the one marketing purpose we have, it uses campaign-level data only, and it is opt-out.

5. Optional cloud sync — end-to-end encrypted

Diary sync across your devices is off by default. If you turn it on in Profile, your diary entries are end-to-end encrypted on your device (AES-GCM) before they leave it: the content of each day — flow, symptoms, mood, notes — reaches our backend only as ciphertext, and the 256-bit encryption key is stored in your personal iCloud Keychain, never on our servers. We could not read your synced diary even if we wanted to. For honesty's sake: entry dates and modification timestamps are not encrypted — devices need them to reconcile edits — and they are protected by row-level security tied to your anonymous session. Sync runs through the PowerSync replication service to our backend hosted on Supabase in Frankfurt, Germany (EU). Identity for sync is an anonymous session — no email or phone number is attached to it. Turning sync off stops replication; deleting your data in the App (section 9) also deletes the synced ciphertext.

6. Optional online AI assistant (Mia)

Mia can work fully on-device. Before the online AI is used for the first time, the App asks for your explicit consent and shows what would be shared. If you accept, your message plus a limited context needed for the answer — which may include your name, age, cycle dates and statistics, symptoms, mood, recent notes and permitted Health values — is sent through our backend (Supabase Edge Functions, Frankfurt, EU) to a third-party AI model provider (currently DeepSeek) to generate the answer.

The model provider processes the request to generate the answer; its own retention and processing terms apply to that processing, and it may be located outside the EU/EEA (see section 11).

7. Optional sharing circle

You may invite a partner or a close person to see limited cycle information. Sharing happens only after you create an invite code and the other person accepts it. You choose what is shared; either side can end sharing at any time, which stops further sharing immediately and removes the shared status from our backend. Invitations and shared status are processed by our Supabase backend (Frankfurt, EU). If you enable notifications, delivery uses the Apple Push Notification service; the push token is deleted when you disable notifications or delete your data.

8. Who else processes data (processors)

We use a small number of service providers, only for the purposes described above:

We do not sell personal data and we do not share it with advertisers or data brokers. If we change providers, we will update this policy.

9. Deleting your account and data

You are always able to delete your data yourself, directly in the App — no emails, calls or forms required:

  1. Open Profile → Delete all data.
  2. Confirm. The App immediately deletes your local diary and settings, deletes the synced copy on our servers if sync was on, revokes any sharing circle connections and shared statuses, and unregisters push notifications. The anonymous backend account is emptied and orphaned — nothing personal remains attached to it.

Deletion is effective immediately and cannot be undone. Removing the App from your device also deletes all local data.

Deleting your data does not cancel a HeySis Premium subscription — subscriptions are billed by Apple, not by us, so they live in your Apple Account. Cancel it in Settings → your name → Subscriptions, or it renews as usual. When a subscription exists, our servers keep the minimum Apple sends us to know whether it is active: an Apple transaction identifier, the product, the environment and the expiry date. That row carries no health data, and deleting your account unlinks it from you.

If anything doesn't work, or you want us to double-check that nothing remains server-side, email wantbefree48@gmail.com and we will confirm within 30 days.

10. How long we keep data

11. International transfers

Our backend is hosted in the EU (Frankfurt, Germany). Two situations can take data outside the EU/EEA: Apple services (per Apple's terms) and the AI model provider processing consent-gated requests (section 6), which may process data in other jurisdictions. Where GDPR applies, such transfers rely on your explicit consent to the online AI feature and on appropriate safeguards where available. If you are not comfortable with this, simply keep Mia on-device — the App asks first and works fully without it.

12. Security

No system is perfectly secure; we honestly promise minimization, end-to-end encryption of synced diary content, encryption in transit and at rest, and no third-party trackers — and we will notify affected users of any breach as required by law.

13. Law enforcement and legal requests

We do not voluntarily share your data with authorities. We would disclose data only when required by a valid, binding legal process, we would challenge overbroad requests, and where legally permitted we would notify you. Because HeySis stores your diary on your device and holds no identifying account data, in most cases there is very little we could be compelled to produce.

14. Children

HeySis is not directed at children under 13, and we do not knowingly process their data. Local law may set a higher minimum age or require parental consent. If you believe a child's data has been entered, contact us and we will help remove it.

15. Your rights

Depending on where you live (GDPR/UK GDPR, US state privacy laws and others), you may have the right to access, correct, delete, restrict or object to processing, port your data, withdraw consent at any time, and not be discriminated against for exercising your rights.

Most of these you can do instantly yourself: everything the App knows is visible and editable in the App, consent toggles live in Settings, exports are available from Profile, and deletion is described in section 9. For anything else, email wantbefree48@gmail.com; we respond within 30 days. Where GDPR applies, you also have the right to lodge a complaint with your local supervisory authority.

16. Do Not Track and similar signals

This website serves static pages, sets no cookies and runs no analytics, so there is nothing to opt out of on the website. The App contains no third-party trackers; its minimized first-party product analytics can be disabled in the App's privacy settings.

17. Changes to this policy

We may update this policy when features or providers change. Material changes will be announced in the App or on this page and reflected by a new effective date. Earlier versions are available on request.

18. Prevailing language

This policy is published in English, Russian and Korean. If the versions ever disagree, the English version prevails.