1. Who we are
Reyha Limited operates the Reyha app and is the data controller under the UK GDPR and the Data Protection Act 2018. We are registered with the Information Commissioner's Office (registration reference ZC219493). You can reach us at tatum@reyha.app or Reyha Limited, 76 Hecham Close, London E17 5QT, England and Wales.
2. The data we collect — and where it lives
Reyha is built to keep your most personal information on your own device. There are two categories.
Stays on your device — never sent to Reyha's servers
Your name and, if you choose to add it, your date of birth; your cycle data (period dates, cycle length, and cervical mucus observations); everything you log (flow, physical and emotional signals, symptoms, mood, energy); your contraception method; your health context and life-stage information; your activity level; and your notification preferences. This information is stored only in the app on your phone. We do not receive it, and we cannot see it.
Sent to our server — only if you connect a wearable or health app
If you connect a wearable or health app, its readings — heart rate, heart-rate variability, skin-temperature deviation, sleep, and activity (steps, exercise minutes, active calories, training load) — are sent to our secure server so the app can learn your patterns over time. Reyha reads these from your phone's health hub — Apple Health on iOS or Google Health Connect on Android. Any wearable or health app that writes to your health hub (for example Apple Watch, Google Pixel Watch, Samsung, Garmin, Oura, Fitbit or Whoop) can feed Reyha this way; what reaches us depends on the readings your device shares with the health hub. This is the only personal data that leaves your device, and only while wearable sync is switched on.
No account
Reyha does not ask you to create an account. There is no email address, password, or login. When you first open the app, a random identifier is generated and stored on your device; it is used only to associate your wearable readings with your device on our server. It is not linked to your name or any real-world identity, and we cannot use it to contact or identify you. Because this identifier still links those readings to you, we treat them as pseudonymous — not fully anonymous — personal data, and protect them under the UK GDPR.
No advertising, no tracking
Reyha shows no ads and collects no usage analytics.
3. Our legal basis for using your data
For the wearable and health-device readings that sync to our server — which are special-category (health) data — our legal basis is your explicit consent (UK GDPR Article 9(2)(a)), given when you accept our privacy approach during setup and when you connect a device, and confirmed each time you keep wearable sync switched on. You can withdraw that consent at any time by turning wearable sync off or disconnecting your device.
The information that stays on your device is processed only on your device to make the app work; we do not receive or store it on our servers. We rely on legitimate interests only for the basic security of the wearable-sync service. We do not rely on "contract," because there is no account.
4. How we use your data
The information on your device powers your cycle-phase estimates, daily guidance, and personalisation — all computed on your phone. The wearable readings on our server are used to improve the accuracy of those estimates for you over time. Health data obtained from Apple Health or Google Health Connect is used only to provide Reyha's features to you; we never use it for advertising, and we never share it for advertising or data-mining. We do not sell your data, and we do not use it to train AI models.
5. Personalisation and AI
Personalisation happens on your device, using the information stored there. Your cycle data is not sent to any third party or AI provider.
If in future we introduce features that would require sending any of your data off your device — for example AI-assisted insights, or syncing your cycle data across devices — we will tell you exactly what would be sent, ask for your specific consent first, and update this policy. Nothing new will leave your phone without you knowing.
6. Who we share data with
Your on-device information is not shared with anyone, because it never leaves your phone.
For the wearable readings on our server, we use:
- Supabase — our hosting and database provider, which stores your wearable readings and runs the random-identifier system, under a written data-processing agreement.
- Your phone's health hub and your wearable — Reyha reads your wearable readings from Apple Health (iOS) or Google Health Connect (Android), which your device or its app writes to. This is the source you authorise; you can disconnect or revoke Reyha's access at any time in your phone's settings.
All processors are bound by written agreements. We do not share your data with advertisers or data brokers.
7. How long we keep your data
The information on your device stays until you delete it or reset the app; resetting removes it permanently and we hold no copy. The wearable readings on our server are kept while your device stays connected. You can delete them at any time from Profile → Privacy & data, which removes them from our server immediately. Choosing "Reset app data" in Profile also deletes your random identifier and everything associated with it from our server, immediately and permanently. We keep no copy, except where the law requires limited retention.
8. Your rights
You have the right to access, correct, delete, object to, and restrict the processing of your data, to receive a portable copy, and to withdraw consent. Because you can do these directly in the app:
- Access and portability: Profile → Privacy & data → Export my data gives you a full copy.
- Erasure: Delete server data removes your wearable readings from our server; Reset app data (in Profile) wipes everything — your on-device data and your server-side readings and identifier.
- Withdraw consent: turn wearable sync off, or disconnect your device.
Because your data is held only under a random identifier, we cannot identify you from our records alone (UK GDPR Article 11). This means we generally cannot action a rights request sent by email — please use the in-app controls, which act on your data directly. If you need help, contact us at tatum@reyha.app. You also have the right to complain to the Information Commissioner's Office (ico.org.uk · 0303 123 1113).
9. Data security
Data in transit is protected with TLS encryption. Data on our server is encrypted at rest and protected with row-level security, so each identifier can only ever reach its own data. We do not browse your data. We will notify you and the ICO of any qualifying personal-data breach within 72 hours.
10. International data transfers
Your wearable readings are stored by Supabase in the EU (West EU — Ireland), within the European Economic Area. Transfers from the UK to the EEA are covered by the UK's adequacy regulations, so no additional safeguards are required. Your wearable readings are not transferred outside the EEA.
11. Children
Reyha is not intended for anyone under 18. We do not knowingly collect data from under-18s, and we will delete any such data promptly if we are notified of it.
12. Medical disclaimer
Reyha is a wellness and self-tracking tool. It is not a medical device and does not provide medical advice, diagnosis, or treatment. Always speak to a qualified healthcare professional about medical concerns or decisions.
13. Changes to this policy
We will notify you of any material change at least 14 days in advance, in the app. Because there is no account, we notify you in the app rather than by email.
14. Contact us
Reyha Limited
76 Hecham Close
London E17 5QT
England and Wales
Privacy enquiries: tatum@reyha.app
Information Commissioner's Office: ico.org.uk · 0303 123 1113