EndoTracking is a health app used by people managing endometriosis — one of the most personal health conditions someone can navigate. We built this app because we believe you deserve a tool that respects your data as much as it respects your experience. This policy explains, in plain language, exactly what we collect, what we do with it, and what we never do.
The short version
- Your underlying health database stays on your device, but unmasked iOS session replay can transmit health content while it is displayed on screen.
- We do not sell your health data. Not ever, not to anyone.
- We do not use your health data for advertising.
- You can delete your local data at any time and request deletion of any account data we hold.
- We use Firebase for technical reliability services and, in app versions that offer accounts, sign-in; PostHog for pseudonymous product analytics and full iOS session replay; Apple AdServices on Apple devices for Apple Ads attribution; and RevenueCat for subscriptions. Replay can include health values, notes, medication names, and images displayed in the app. We do not use advertising identifiers or cross-app tracking.
1. Who we are
EndoTracking is operated by Op Studio. If you have any questions about this policy, you can reach us at [email protected]. We will respond within 5 business days.
2. What data we collect
Health and symptom data
When you log symptoms, pain levels, cycle dates, food entries, treatments, or medical context, that data is stored locally on your device using its secure on-device storage. This data is yours and does not automatically sync to our servers. On Android, EndoTrack disables cloud backup and device-transfer backup for its database and preferences. On Apple devices, Apple may include local app data in iCloud Backup if you enable it under your Apple ID; that backup is governed by Apple's privacy policy, not ours.
When you use the GP Report feature, a PDF is generated locally on your device. No content of that report is transmitted to EndoTracking servers.
Account information
The Android version does not require or offer an EndoTrack account. In app versions that offer optional sign-in, Firebase Authentication stores your email address and securely manages your credentials. We do not associate your detailed health data with your account on our servers.
Subscription and payment data
Payments are processed by the store where you downloaded the app: Apple's App Store or Google Play. We use RevenueCat to manage subscription status. Neither RevenueCat nor EndoTracking receives your full credit-card or bank details from those stores.
Analytics and crash diagnostics
We use PostHog for anonymous product analytics and Firebase Crashlytics (provided by Google) for crash diagnostics. Some app versions also use Firebase Performance Monitoring and Remote Config. These services receive anonymous product events or technical diagnostics such as app version, build number, screen name, workflow completion, device/OS information, performance measurements, and coarse country or region inferred from network information. On Apple devices, when Apple attributes an install to an Apple Ads campaign, PostHog may also receive non-identifying campaign, ad group, keyword, placement, country/region, and conversion metadata.
In iOS release builds, PostHog full session replay is enabled for product analysis. Replays are unmasked and can include text and images rendered on screen, including health values, diagnosis or stage, symptom selections, period details, written notes, food entries, medication names, and meal photos. Network request and response contents are not recorded; warning and error logs may be included. PostHog receives a pseudonymous app-install identifier rather than an EndoTrack account identifier, and we do not send IDFA, Android advertising ID, or another advertising identifier. This data is used only to operate, fix, and improve the app and measure our own Apple Ads campaigns. It is not used for behavioral advertising or cross-company tracking, and we never sell it.
EndoTracking does not send your data to any third-party AI or machine-learning service. Personal flare-risk trends and correlations are computed on your device.
What we do NOT collect
- Your name (unless you choose to enter it in your profile)
- Precise location or GPS data. Technical providers may infer a coarse country or region from network information.
- Your contacts. Original photo files remain in local app storage, but an image displayed during a replayed iOS session can be captured by PostHog.
- Data from Apple Health or Android health services unless an app version clearly asks for permission first
- Advertising identifiers such as IDFA or Android advertising ID. EndoTrack does not display third-party ads; Apple Ads attribution uses non-identifying first-party campaign metadata.
3. How we use your data
We use the data we collect for these purposes only:
- To run the app: On-device storage powers the diary; authentication keeps you signed in only in versions that offer optional accounts.
- To process your subscription: RevenueCat tells us whether your subscription is active so we can unlock premium features.
- To improve the app: Anonymous crash reports and aggregate feature usage help us fix problems and prioritize improvements.
- To measure our Apple Ads: On Apple devices, non-identifying attribution metadata helps us understand which campaign, ad group, keyword, or placement produced an install and subsequent aggregate conversion.
We do not use your data for marketing profiling, behavioral advertising, or any form of automated decision-making that affects you.
4. Who we share your data with
We work with a small number of trusted service providers:
- Google Firebase — Authentication, crash diagnostics, performance diagnostics, and remote configuration in app versions that use those services. EndoTrack does not send health values, written content, medication names, or account identifiers to Firebase diagnostics.
- PostHog — Pseudonymous product analytics and unmasked iOS session replay used to measure activation, conversion, and usability. Replay can include health-related text and images displayed on screen. Network request and response contents are disabled. We do not send an EndoTrack account identifier or advertising identifier.
- RevenueCat — Subscription management. RevenueCat receives an app-store subscriber identifier and purchase status, not your detailed health data or full payment-card details.
- Apple — App Store distribution, payment processing, device-level security, and privacy-preserving Apple Ads attribution through AdServices. Governed by Apple's terms.
- Google — Google Play distribution and payment processing on Android, plus the Firebase services described above. Governed by Google's terms.
We do not sell, rent, or license your data to any third parties. We do not share your data with data brokers, insurance companies, employers, or marketers. If we are ever required by law to disclose data, we will notify you as permitted by law before doing so.
5. Data retention and deletion
Your health and symptom data lives on your device. On Android, you can remove it from More → Delete all data; deleting the app also removes its local data. In versions that offer an account, use the in-app account deletion option if available or email us at [email protected]. We will process deletion requests for server-side account data within 30 days. Subscription transaction records retained by Apple, Google, or RevenueCat are governed by their legal and accounting obligations.
6. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain types of processing
- Data portability (receive your data in a machine-readable format)
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Children's privacy
EndoTracking is not designed for, and does not knowingly collect data from, children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.
8. Security
Your health data is stored locally using the security and data-protection features provided by iOS or Android. Protecting your device with a passcode or screen lock strengthens that protection. Where optional accounts are offered, credentials are handled by Firebase Authentication using industry-standard security controls. We regularly review our security practices and will provide notice of a breach when required by applicable law.
9. Changes to this policy
If we make material changes to this policy, we will notify you via an in-app notification at least 14 days before the changes take effect. The updated date at the top of this page will always reflect the most recent revision. Continued use of the app after changes take effect constitutes your acceptance of the revised policy.
10. Contact us
Questions about this policy? We're real people and we want to hear from you.
Email: [email protected]