Vina Privacy Policy
Last updated: 16/07/2026
1. Data controller
- Application: Vina
- Controller: Héctor López Roldán (HLR Studio)
- Contact email: hello@hlrstudio.dev
- Location: Zaragoza, Spain
This Privacy Policy explains how the personal data of people who use the Vina mobile application (hereinafter, "the App") is collected, used and protected.
Vina is designed to help you remember to take or use a contraceptive method, and to show information related to your cycle.
2. Data we process
Depending on how you use the App, we may process the following categories of data. Some of them are special category data (health data) within the meaning of Article 9 GDPR (contraceptive method, cycle, symptoms, mood), which receive reinforced protection.
2.1. Health and usage data you enter (local storage)
By default, this data is stored locally on your device (local Hive-type databases and system preferences):
- Chosen contraceptive method (e.g. pill, ring, patch, injection, IUD, implant).
- Cycle configuration (active days, break days, cycle start, IUD or implant insertion/removal dates, etc.).
- History of recorded periods.
- Health check-ups you set up (gynecological check-up, cervical screening, prescription renewal, STI test, self-exam, or any you create), how often they repeat, and any notes you write on them.
- History of completed check-ups: type, date, and any notes or results you choose to record.
- Notes, mood and symptoms you record.
- Adherence log (whether you took or used the method, streaks, percentages).
- Reminder schedule and language, theme and notification preferences.
The App can be used completely anonymously and locally, without creating an account. In that case, your data does not leave your device except as described in sections 2.4 and 2.5 (both optional).
2.2. Account and cloud sync (optional — only if you sign in)
If you choose to sign in with your Google account to back up and sync across devices:
- Firebase Authentication is used. By default the session is anonymous (a technical identifier with no personal data); when you link Google, your account's email address and name are stored.
- All the history described in section 2.1 (cycle, method, periods, notes, mood, symptoms, adherence, and health check-ups with their history) is uploaded and synced to the cloud via Cloud Firestore, associated with your user identifier, so that it is available on your devices and as a backup.
- You can disconnect the account and delete all your data (local and in the cloud) from the App's Settings.
2.3. Technical and usage data (analytics, errors, advertising)
The App uses Google/Firebase services:
- Firebase Analytics: aggregated usage statistics. Analytics events do NOT include your health data (cycle, notes, symptoms): only usage metadata (screens visited, basic actions, counters).
- Firebase Crashlytics: logging of technical errors and crashes.
- Google Mobile Ads / AdMob: advertising for the free version.
These services may automatically collect device and advertising identifiers, system version, model, language, approximate country and technical events. In the European Economic Area, advertising is governed by your choice in the consent notice shown in the App (see section 4); if you do not consent, non-personalised ads are served or processing is limited.
2.4. Partner mode (optional)
If you enable partner mode to share information with another person, a summary of your cycle (cycle day, phase and estimated next period) is published to the cloud for that person to consult. Mood and symptoms are only shared if you expressly enable them (they are off by default). Your notes and your health check-ups or their history are never shared. You can revoke access at any time, which removes the link on both sides. Push notifications (Firebase Cloud Messaging) are used to notify your partner and do not include specific cycle data.
2.5. Health integration (optional)
If you enable it, the App can write and read menstrual flow data in Apple Health (iOS) or Health Connect (Android). This integration is off by default and requires your explicit consent through the operating system.
2.6. Premium subscriptions
Subscription management (purchase, restore) is handled through RevenueCat and the app stores (App Store / Google Play), which process the identifiers needed to validate the purchase. We do not process or store your payment card details.
Under no circumstances do we sell your personal data to third parties.
3. Purposes of processing
We use the data for the following purposes:
- Providing and maintaining the App
- Saving your contraceptive method and cycle configuration.
- Showing you the "Today" section, the calendar and other personalised data.
- Local reminders and notifications
- Scheduling notifications on your device at the configured time.
- Reminding you to take or use your contraceptive method.
- Improving the quality of the App
- Analysing in aggregate how the App is used (Firebase Analytics).
- Detecting technical failures and errors (Crashlytics).
- Advertising (where enabled)
- Showing ads via Google AdMob.
- Where applicable, personalising advertising according to your consent settings (for example, non-personalised ads in the EU if so configured).
4. Legal basis for processing
In accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), the legal bases are:
- Performance of a contract / provision of the service (Art. 6(1)(b)) To provide you with the App's core functionality (saving your configuration on the device, showing your cycle, scheduling reminders).
- Explicit consent for health data (Arts. 6(1)(a) and 9(2)(a)) Processing your special category data (cycle, method, symptoms, mood) beyond your own device requires your explicit consent. Specifically:
- Cloud sync of your health history only happens if you voluntarily sign in (section 2.2).
- Partner mode only shares information if you enable it, and mood/symptoms only if you expressly enable them (section 2.4).
- The Health integration only works if you enable it and grant the system permission (section 2.5).
You can withdraw your consent at any time: by disconnecting the account, revoking partner mode, disabling the Health integration, deleting your data from Settings, or uninstalling the App.
- Consent for advertising (under ePrivacy/GDPR rules) For personalised advertising in the EEA, via the consent notice shown in the App. You can review your choice by returning to that notice.
- Legitimate interest (Art. 6(1)(f)) To keep the App secure, prevent abuse and errors, and produce aggregated usage statistics that do not include your health data.
5. Data retention
- Data stored on your device (cycle, method, histories) is kept for as long as you have the App installed or until you delete the data or uninstall the App.
- If you have signed in, your synced history is kept in the cloud (Cloud Firestore) until you use the "Delete my data" option in Settings or request its erasure. Important: uninstalling the App deletes local data, but not the cloud copy; to delete it, use "Delete my data" before uninstalling, or write to us.
- Technical and usage data managed by Firebase and similar services is retained in accordance with each provider's policies, applying reasonable retention and anonymisation periods as far as possible.
The "Delete my data" option erases your history both locally and in the cloud, and revokes partner links.
6. Disclosure of data to third parties
We do not sell your personal data to third parties.
However, in order to provide the service, we work with the following processors / providers:
- Google LLC and its affiliates — Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging, Firebase Analytics, Crashlytics, Remote Config and Google Mobile Ads (AdMob). They host the account, the cloud sync of your history (if you sign in), the partner mode summary, push notifications, analytics, error logging and advertising.
- RevenueCat, Inc. — premium subscription management.
- Apple Inc. and Google (Health Connect) — only if you enable the Health integration, to read/write menstrual flow on your device.
- Apple App Store / Google Play — processing of subscription payments.
In addition, in partner mode, the person you authorise will be able to see the cycle summary you share (this is not a "provider", but another user to whom you grant access; you can revoke it whenever you want).
These services may process data on servers located outside the European Economic Area. Their providers state that they apply appropriate international transfer mechanisms in accordance with the GDPR (for example, the EU Standard Contractual Clauses).
Should other providers be used in the future, this Privacy Policy will be updated to include them.
7. International transfers
When using services such as Firebase or AdMob, international data transfers may take place (for example, to the United States or other countries).
In such cases, we seek to ensure there is an appropriate legal basis, including, where applicable:
- The signing of Standard Contractual Clauses approved by the European Commission.
- Other safeguards recognised by the GDPR.
8. Your rights
As a user, you have the right to:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Request the erasure of your data (right to be forgotten).
- Request the restriction of processing.
- Object to processing where the legal basis is legitimate interest.
- Request data portability, where applicable.
You can exercise these rights by contacting the controller at: hello@hlrstudio.dev Please state clearly which right you wish to exercise and, where necessary, provide the information needed to identify you.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
9. Minors
The App is intended for adults. If you are under 14, you must use the App with the consent and supervision of your mother, father or legal guardian.
If it is detected that data from a minor has been collected without the corresponding consent, we will attempt to delete it as soon as possible.
10. Security
Reasonable technical and organisational measures are applied to protect the data:
- Use of standard security mechanisms of the systems hosting the services (such as Firebase).
- Regular updates of the App to fix errors and vulnerabilities.
No system is completely secure, but we will work to minimise the risks.
11. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect changes in the App, in legislation or in the services used (for example, new providers).
In the event of significant changes, we will try to inform you through the App itself or by other reasonable means.
12. Contact
For any questions about this Privacy Policy or about the processing of your data, you can write to:
hello@hlrstudio.dev