Last updated: 1st July, 2026
Effective date: 1st July, 2026
1. Introduction
This Privacy Policy explains how Leading Her Way LLC (“Leading Her Way”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal information when you use the Leading Her Way: Cycle Sync mobile application.
Leading Her Way is a menstrual cycle tracking and wellness application that helps you understand your cycle, plan your days around your cycle phases, journal how you feel, and receive personalized guidance.
We have designed the App to collect only what is needed to provide its features, and this policy describes exactly what we collect and why.
By using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services.
2. Who We Are (Data Controller)
The data controller responsible for your personal information is:
Entity: Leading Her Way LLC
Address: Sharjah Media City, Sharjah, UAE
Privacy contact: team@leading-her-way.com
3. Summary of What We Collect
Account & identity
Email address, password (stored only as a secure hash), name, profile picture, Apple/Google sign-in identifiers
Source: You / Apple / Google
Health & cycle data (sensitive)
Age, life stage, last period start date, cycle-length range, period length, body signals/symptoms, menstruation status, cycle predictions
Source: You (onboarding & in-app logging)
Wellness & journaling (sensitive)
Mood, energy levels, journal notes, daily check-in inputs, goals, work style, productivity and self-care preferences
Source: You
Calendar data
Events from calendars you choose to connect (event title, start/end times)
Source: Apple / Google / Outlook calendars you connect
Subscription & purchase
Subscription status, plan, transaction identifiers (processed by the app stores and RevenueCat)
Source: Apple App Store / RevenueCat
Device & technical
Device type, operating system, app version, language, crash and diagnostic information
Source: Automatically
Notification preferences
Which reminders you enable and their timing
Source: You
We do not sell your personal information.
4. Information We Collect in Detail
4.1 Account and Authentication Data
When you create an account you may provide an email address and password, or sign in using Sign in with Apple or Sign in with Google. When you use a social sign-in, we receive a secure identity token and basic profile information (such as your email address and name) from that provider — we never receive your Apple or Google password. Passwords you set directly are stored only in hashed form on our servers. You may optionally add a profile picture, which requires your permission to access your photo library.
4.2 Health, Cycle, and Wellness Data (Sensitive Information)
To provide cycle tracking and personalized guidance, we collect the information you give us, including:
This information is used to calculate your cycle phases, predict upcoming periods and phases, and generate personalized recommendations and guidance.
4.3 Personalized Recommendations
The App generates daily guidance, recommendations, and workload insights based on your cycle data and the inputs you provide. To do this, our backend sends the relevant inputs (such as your cycle information, wellness inputs, and — where you use calendar/workload features — your event titles and timing) to Google's Gemini AI service, which returns the generated guidance.
We use Gemini only to generate these in-app features, through Google's paid, enterprise AI offering (the Gemini API via Google Cloud / Vertex AI). Your data is not used by us or by Google to train or improve any AI models, and we do not use it for advertising. We send only the information needed to produce your recommendations.
4.4 Subscription and Payment Data
Premium features are offered through paid subscriptions. Purchases are processed by Apple App Store and subscription/entitlement status is managed through RevenueCat.
We do not receive or store your full payment card details. We link a RevenueCat “App User ID” to your account identifier so that your subscription status can be applied to your account.
4.5 Device and Diagnostic Data
We automatically collect limited technical information such as device model, operating system version, app version, and crash/diagnostic data to keep the App reliable and secure.
4.6 Notifications
The App can send you reminders (for example, period reminders, phase-change reminders, daily check-ins, journaling and wellness reminders). These reminders are scheduled locally on your device based on your preferences and cycle data; we do not need to track your device to deliver them. You can disable notifications at any time in your device settings.
5. Calendar Integrations
A core feature of Leading Her Way is the ability to align your schedule and workload with your cycle phases. To do this, you can optionally connect one or more external calendars. Calendar connection is always opt-in, and you can disconnect at any time.
For every calendar type, we request read-only access. We do not create, edit, or delete events in your connected calendars, and we do not delete events on your behalf. (Separately, you may create your own manual events inside the App; those are described in section 5.5.)
The following calendar sources are supported.
5.1 Apple Calendar (iOS only)
How it connects: Through the calendar permission on your iOS device. iOS will ask you to grant the App access to your calendars.
Permission requested: Read access to your device calendars (the system prompt reads: “Allow Leading Her Way to access your calendar to align your schedule with your cycle phases.”).
What we read: Upcoming events within a rolling look-ahead window of approximately 30 days. We use only each event's title and its start and end times. The device may also return other event fields (such as location and notes), but the App does not display, store, or transmit them.
Where this happens: Reading your Apple Calendar events happens on your device. We do not receive your raw device calendar through Apple's servers.
What leaves your device: See section 5.4 (Workload Analysis) for the limited information sent to our servers.
How to revoke: Disconnect Apple Calendar in the App, or turn off calendar access for the App in iOS Settings → Privacy & Security → Calendars.
5.2 Google Calendar
How it connects: Through Google's OAuth sign-in. When you connect Google Calendar, Google shows you a consent screen describing the access being requested.
Permission/scope requested: https://www.googleapis.com/auth/calendar.readonly — read-only access to your Google calendars. We request this scope only when you choose to connect Google Calendar (it is separate from using Google to sign in).
What we read: Your list of readable calendars and their upcoming events within an approximately 30-day look-ahead window.
We use only each event's title and its start and end times. The Calendar API response may include other fields (such as location and description), but the App does not display, store, or transmit them.
Where this happens: Your device communicates directly with Google's Calendar API using a Google access token. The token is held on your device to keep the connection active.
What leaves your device: See section 5.4 (Workload Analysis).
How to revoke: Disconnect Google Calendar in the App. You can also review and revoke the App's access at any time in your Google Account at myaccount.google.com/permissions. Disconnecting in the App stops further syncing; because the same Google account may also be your sign-in identity, disconnecting the calendar does not sign you out of the App.
Google API Services compliance: Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide the App's in-app features, do not transfer it except as needed to provide those features, and do not use it for advertising.
5.3 Outlook / Microsoft Calendar
How it connects: Through Microsoft's OAuth sign-in (Microsoft Graph). You will see a Microsoft consent screen describing the access requested.
Permission/scopes requested: Calendars.Read (read-only calendar access), plus openid, profile, and offline_access (the latter allows the connection to refresh without asking you to sign in repeatedly).
What we read: Your list of calendars and their upcoming events within an approximately 30-day look-ahead window. We use only each event's title (subject) and its start and end times. The Microsoft Graph response may include other fields (such as location and a short body preview), but the App does not display, store, or transmit them.
Where this happens: Your device communicates directly with Microsoft Graph using a Microsoft access token. The access and refresh tokens are stored securely on your device (in the device's secure storage) and are used only to keep the connection active.
What leaves your device: See section 5.4 (Workload Analysis).
How to revoke: Disconnect Outlook in the App (which deletes the stored tokens from your device), and/or remove the App's access in your Microsoft account at account.microsoft.com/privacy.
5.4 What Calendar Information Is Sent to Our Servers (“Workload Analysis”)
To analyze how busy your upcoming days are relative to your cycle phases, the App sends a limited subset of your connected-calendar events to our servers:
Our servers use this information to compute workload insights that are shown back to you alongside your cycle phases.
5.5 Manual Events You Create
You can also create your own events inside the App (not linked to any external calendar). These manual events (title, start, and end time) are stored on our servers so they are available across your sessions, and you can edit or delete them at any time within the App.
6. How We Use Your Information
We use your information to:
We do not use your health, cycle, or journaling data for advertising, and we do not sell your personal information.
7. Legal Bases for Processing (EEA / UK Users)
Where the EU/UK GDPR applies, we rely on the following legal bases:
Consent — for processing your health and cycle data (special-category data under Article 9 GDPR) and for connecting external calendars. You may withdraw consent at any time.
Performance of a contract — to provide the Services you request, including account management and subscriptions.
Legitimate interests — to secure, maintain, and improve the Services, where not overridden by your rights.
Legal obligation — to comply with applicable laws.
8. How We Share Information
We share information only as described below, and only as necessary:
Recipient
Purpose
Data shared
Apple / Google
Authentication (Sign in with Apple/Google)
Identity tokens, basic profile
Google (Calendar API)
Read-only Google Calendar access you enable
Calendar access token (device-side)
Microsoft (Graph)
Read-only Outlook Calendar access you enable
Calendar access token (device-side)
Apple App Store
Subscription billing
Purchase/transaction data
RevenueCat
Subscription/entitlement management
App User ID, subscription status
Expo (EAS)
App delivery and over-the-air updates
Technical/device data
Google Cloud Platform (GCP)
Hosting our backend and database (region: europe-west1, Belgium)
All data stored server-side
Google (Gemini AI)
Generating recommendations & workload insights
Cycle/wellness inputs, and event titles/timing where calendar features are used (not used for model training)
We may also disclose information to comply with the law, respond to lawful requests, protect our rights and users' safety, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will notify you of any change in control of your personal information.
9. International Data Transfers
Our backend and database are hosted on Google Cloud Platform (GCP) in the europe-west1 (Belgium) region, within the European Economic Area (EEA). Data you store with us is held on servers located in the EEA.
Some of our sub-processors may, however, process limited personal information outside the EEA:
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. When you delete your account, we delete your personal information.
11. Data Security
We apply technical and organizational measures to protect your personal information, particularly your health, cycle, and wellness data:
12. Your Privacy Rights
Depending on where you live, you may have the right to:
To exercise these rights, contact us at team@leading-her-way.com. We will respond within the timeframe required by applicable law.
12.1 EEA / UK Residents
You have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your supervisory authority.
12.2 California Residents (CCPA / CPRA)
You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under California law. We will not discriminate against you for exercising your rights.
13. Deleting Your Account and Data
You can delete your account at any time from within the App (Profile settings), which triggers deletion of your account and associated data on our servers. Disconnecting a calendar removes its connection and stored tokens from your device. You may also revoke the App's access to Google and Microsoft from your Google and Microsoft account settings, respectively.
14. Children's Privacy
The Services are not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. Contact Us
If you have questions or requests regarding this Privacy Policy or your personal information, contact:
Leading Her Way LLC
Email: team@leading-her-way.com
Address: Sharjah Media City, Sharjah, UAE
Effective date: 1st July, 2026
1. Introduction
This Privacy Policy explains how Leading Her Way LLC (“Leading Her Way”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal information when you use the Leading Her Way: Cycle Sync mobile application.
Leading Her Way is a menstrual cycle tracking and wellness application that helps you understand your cycle, plan your days around your cycle phases, journal how you feel, and receive personalized guidance.
We have designed the App to collect only what is needed to provide its features, and this policy describes exactly what we collect and why.
By using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services.
2. Who We Are (Data Controller)
The data controller responsible for your personal information is:
Entity: Leading Her Way LLC
Address: Sharjah Media City, Sharjah, UAE
Privacy contact: team@leading-her-way.com
3. Summary of What We Collect
Account & identity
Email address, password (stored only as a secure hash), name, profile picture, Apple/Google sign-in identifiers
Source: You / Apple / Google
Health & cycle data (sensitive)
Age, life stage, last period start date, cycle-length range, period length, body signals/symptoms, menstruation status, cycle predictions
Source: You (onboarding & in-app logging)
Wellness & journaling (sensitive)
Mood, energy levels, journal notes, daily check-in inputs, goals, work style, productivity and self-care preferences
Source: You
Calendar data
Events from calendars you choose to connect (event title, start/end times)
Source: Apple / Google / Outlook calendars you connect
Subscription & purchase
Subscription status, plan, transaction identifiers (processed by the app stores and RevenueCat)
Source: Apple App Store / RevenueCat
Device & technical
Device type, operating system, app version, language, crash and diagnostic information
Source: Automatically
Notification preferences
Which reminders you enable and their timing
Source: You
We do not sell your personal information.
4. Information We Collect in Detail
4.1 Account and Authentication Data
When you create an account you may provide an email address and password, or sign in using Sign in with Apple or Sign in with Google. When you use a social sign-in, we receive a secure identity token and basic profile information (such as your email address and name) from that provider — we never receive your Apple or Google password. Passwords you set directly are stored only in hashed form on our servers. You may optionally add a profile picture, which requires your permission to access your photo library.
4.2 Health, Cycle, and Wellness Data (Sensitive Information)
To provide cycle tracking and personalized guidance, we collect the information you give us, including:
- Your age;
- The start date of your last period (or that it is unknown);
- Your typical cycle length (selected as a range) and period length;
- Body signals and symptoms you experience;
- Energy patterns, mood, and daily check-in inputs;
- Journal entries (mood, energy, and free-text notes);
- Your goals, work style, productivity style, social-interaction and self-care preferences;
- Your current menstruation status.
This information is used to calculate your cycle phases, predict upcoming periods and phases, and generate personalized recommendations and guidance.
4.3 Personalized Recommendations
The App generates daily guidance, recommendations, and workload insights based on your cycle data and the inputs you provide. To do this, our backend sends the relevant inputs (such as your cycle information, wellness inputs, and — where you use calendar/workload features — your event titles and timing) to Google's Gemini AI service, which returns the generated guidance.
We use Gemini only to generate these in-app features, through Google's paid, enterprise AI offering (the Gemini API via Google Cloud / Vertex AI). Your data is not used by us or by Google to train or improve any AI models, and we do not use it for advertising. We send only the information needed to produce your recommendations.
4.4 Subscription and Payment Data
Premium features are offered through paid subscriptions. Purchases are processed by Apple App Store and subscription/entitlement status is managed through RevenueCat.
We do not receive or store your full payment card details. We link a RevenueCat “App User ID” to your account identifier so that your subscription status can be applied to your account.
4.5 Device and Diagnostic Data
We automatically collect limited technical information such as device model, operating system version, app version, and crash/diagnostic data to keep the App reliable and secure.
4.6 Notifications
The App can send you reminders (for example, period reminders, phase-change reminders, daily check-ins, journaling and wellness reminders). These reminders are scheduled locally on your device based on your preferences and cycle data; we do not need to track your device to deliver them. You can disable notifications at any time in your device settings.
5. Calendar Integrations
A core feature of Leading Her Way is the ability to align your schedule and workload with your cycle phases. To do this, you can optionally connect one or more external calendars. Calendar connection is always opt-in, and you can disconnect at any time.
For every calendar type, we request read-only access. We do not create, edit, or delete events in your connected calendars, and we do not delete events on your behalf. (Separately, you may create your own manual events inside the App; those are described in section 5.5.)
The following calendar sources are supported.
5.1 Apple Calendar (iOS only)
How it connects: Through the calendar permission on your iOS device. iOS will ask you to grant the App access to your calendars.
Permission requested: Read access to your device calendars (the system prompt reads: “Allow Leading Her Way to access your calendar to align your schedule with your cycle phases.”).
What we read: Upcoming events within a rolling look-ahead window of approximately 30 days. We use only each event's title and its start and end times. The device may also return other event fields (such as location and notes), but the App does not display, store, or transmit them.
Where this happens: Reading your Apple Calendar events happens on your device. We do not receive your raw device calendar through Apple's servers.
What leaves your device: See section 5.4 (Workload Analysis) for the limited information sent to our servers.
How to revoke: Disconnect Apple Calendar in the App, or turn off calendar access for the App in iOS Settings → Privacy & Security → Calendars.
5.2 Google Calendar
How it connects: Through Google's OAuth sign-in. When you connect Google Calendar, Google shows you a consent screen describing the access being requested.
Permission/scope requested: https://www.googleapis.com/auth/calendar.readonly — read-only access to your Google calendars. We request this scope only when you choose to connect Google Calendar (it is separate from using Google to sign in).
What we read: Your list of readable calendars and their upcoming events within an approximately 30-day look-ahead window.
We use only each event's title and its start and end times. The Calendar API response may include other fields (such as location and description), but the App does not display, store, or transmit them.
Where this happens: Your device communicates directly with Google's Calendar API using a Google access token. The token is held on your device to keep the connection active.
What leaves your device: See section 5.4 (Workload Analysis).
How to revoke: Disconnect Google Calendar in the App. You can also review and revoke the App's access at any time in your Google Account at myaccount.google.com/permissions. Disconnecting in the App stops further syncing; because the same Google account may also be your sign-in identity, disconnecting the calendar does not sign you out of the App.
Google API Services compliance: Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide the App's in-app features, do not transfer it except as needed to provide those features, and do not use it for advertising.
5.3 Outlook / Microsoft Calendar
How it connects: Through Microsoft's OAuth sign-in (Microsoft Graph). You will see a Microsoft consent screen describing the access requested.
Permission/scopes requested: Calendars.Read (read-only calendar access), plus openid, profile, and offline_access (the latter allows the connection to refresh without asking you to sign in repeatedly).
What we read: Your list of calendars and their upcoming events within an approximately 30-day look-ahead window. We use only each event's title (subject) and its start and end times. The Microsoft Graph response may include other fields (such as location and a short body preview), but the App does not display, store, or transmit them.
Where this happens: Your device communicates directly with Microsoft Graph using a Microsoft access token. The access and refresh tokens are stored securely on your device (in the device's secure storage) and are used only to keep the connection active.
What leaves your device: See section 5.4 (Workload Analysis).
How to revoke: Disconnect Outlook in the App (which deletes the stored tokens from your device), and/or remove the App's access in your Microsoft account at account.microsoft.com/privacy.
5.4 What Calendar Information Is Sent to Our Servers (“Workload Analysis”)
To analyze how busy your upcoming days are relative to your cycle phases, the App sends a limited subset of your connected-calendar events to our servers:
- Only the event title, start time, and end time are sent.
- Event location and notes/descriptions are not sent to our servers — they are not displayed or stored by the App and never leave your device.
- A maximum of 50 upcoming events is included in a workload submission.
Our servers use this information to compute workload insights that are shown back to you alongside your cycle phases.
5.5 Manual Events You Create
You can also create your own events inside the App (not linked to any external calendar). These manual events (title, start, and end time) are stored on our servers so they are available across your sessions, and you can edit or delete them at any time within the App.
6. How We Use Your Information
We use your information to:
- Provide core features: cycle tracking, phase and period predictions, and journaling;
- Generate personalized daily guidance and recommendations;
- Align your calendar/workload with your cycle phases (where you connect a calendar);
- Schedule reminders and notifications you have enabled;
- Create and manage your account and authenticate you;
- Process and manage subscriptions and entitlements;
- Maintain, secure, troubleshoot, and improve the Services;
- Comply with legal obligations and enforce our terms.
We do not use your health, cycle, or journaling data for advertising, and we do not sell your personal information.
7. Legal Bases for Processing (EEA / UK Users)
Where the EU/UK GDPR applies, we rely on the following legal bases:
Consent — for processing your health and cycle data (special-category data under Article 9 GDPR) and for connecting external calendars. You may withdraw consent at any time.
Performance of a contract — to provide the Services you request, including account management and subscriptions.
Legitimate interests — to secure, maintain, and improve the Services, where not overridden by your rights.
Legal obligation — to comply with applicable laws.
8. How We Share Information
We share information only as described below, and only as necessary:
Recipient
Purpose
Data shared
Apple / Google
Authentication (Sign in with Apple/Google)
Identity tokens, basic profile
Google (Calendar API)
Read-only Google Calendar access you enable
Calendar access token (device-side)
Microsoft (Graph)
Read-only Outlook Calendar access you enable
Calendar access token (device-side)
Apple App Store
Subscription billing
Purchase/transaction data
RevenueCat
Subscription/entitlement management
App User ID, subscription status
Expo (EAS)
App delivery and over-the-air updates
Technical/device data
Google Cloud Platform (GCP)
Hosting our backend and database (region: europe-west1, Belgium)
All data stored server-side
Google (Gemini AI)
Generating recommendations & workload insights
Cycle/wellness inputs, and event titles/timing where calendar features are used (not used for model training)
We may also disclose information to comply with the law, respond to lawful requests, protect our rights and users' safety, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will notify you of any change in control of your personal information.
9. International Data Transfers
Our backend and database are hosted on Google Cloud Platform (GCP) in the europe-west1 (Belgium) region, within the European Economic Area (EEA). Data you store with us is held on servers located in the EEA.
Some of our sub-processors may, however, process limited personal information outside the EEA:
- Google (Gemini AI / Vertex AI) — processes the inputs sent to generate your recommendations and workload insights;
- RevenueCat — processes subscription/entitlement data (App User ID and subscription status);
- Expo (EAS) — processes technical/device data for app delivery and over-the-air updates;
- Apple, Google, and Microsoft — process authentication and, where you connect them, calendar access tokens.Where personal information is transferred outside the EEA/UK to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable) — to ensure your information remains protected. You may request more information about these safeguards using the contact details in this policy.
10. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. When you delete your account, we delete your personal information.
11. Data Security
We apply technical and organizational measures to protect your personal information, particularly your health, cycle, and wellness data:
- Encryption in transit. All data sent between the App and our servers is encrypted using TLS/HTTPS.
- Encryption at rest. Data stored on our servers, hosted on Google Cloud Platform, is encrypted at rest.
- Password security. Passwords are never stored in plain text; we store only a secure, salted hash.
- Secure on-device storage. Authentication tokens and connected-calendar access tokens (Google, Microsoft) are stored using device's secure storage (Apple Keychain / Android Keystore, via Expo SecureStore) rather than in plain application storage.
- Data minimization. As described in Section 5, we read only the minimum calendar fields needed (event title, start time, end time). Other fields such as location and notes are never stored or transmitted to our servers.
- Access controls. Access to personal information, and especially to health and cycle data, is restricted to authorized personnel who need it to operate and support the Services, under confidentiality obligations.
- Incident response. If we become aware of a data breach affecting your personal information, we will notify affected users and the relevant authorities as required by applicable law.
12. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your information (“right to be forgotten”);
- Object to or restrict certain processing;
- Withdraw consent at any time (including disconnecting calendars and disabling notifications);
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at team@leading-her-way.com. We will respond within the timeframe required by applicable law.
12.1 EEA / UK Residents
You have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your supervisory authority.
12.2 California Residents (CCPA / CPRA)
You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined under California law. We will not discriminate against you for exercising your rights.
13. Deleting Your Account and Data
You can delete your account at any time from within the App (Profile settings), which triggers deletion of your account and associated data on our servers. Disconnecting a calendar removes its connection and stored tokens from your device. You may also revoke the App's access to Google and Microsoft from your Google and Microsoft account settings, respectively.
14. Children's Privacy
The Services are not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. Contact Us
If you have questions or requests regarding this Privacy Policy or your personal information, contact:
Leading Her Way LLC
Email: team@leading-her-way.com
Address: Sharjah Media City, Sharjah, UAE