← Back

Privacy Policy

Last updated: 20 September 2026.

ODNENDO (“ODNENDO”, “we”, “us”) is operated by The OG Labs Ltd. This policy explains what personal data we collect through the ODNENDO app, why, who we share it with, and the rights you have over it. We built this app to document symptoms, not to diagnose or treat them — the same principle applies to this policy: we tell you plainly what actually happens to your data, not what would sound reassuring.

Contact: support@odnendo.com

Information we collect

  • Account information: your email address and password (password is stored and verified by our authentication provider, Supabase — we never see or store it in plain text). If you sign in with Google or Apple instead, we receive the email address and account identifier those providers share with us, not your password.
  • Profile information: display name (optional), year of birth (collected at signup solely to confirm you meet our minimum age requirement), and endometriosis status if you choose to share it.
  • Journal content: whatever you write or say in a journal entry, the transcript if you use voice input, and the structured data our AI extraction derives from it (symptom episodes, severity, timing, contextual factors, and any medication/diet/behavior/procedure changes you mention).
  • Apple Health cycle dates: in the iOS app, you can choose to import menstrual cycle start dates and confirmed period end dates that Apple Health makes available. We do not request other Apple Health data, write to Apple Health, or import anything in the background.
  • Consent records: a timestamped history of the consents you've given or withdrawn (terms, medical disclaimer, OpenAI processing, and historical research participation) — kept while your account exists as an append-only log, even if you later change a choice, so there is always an accurate record of what you agreed to and when.

We do not run analytics or advertising trackers in this app, and we do not collect location data.

How your journal entries are processed

After you explicitly consent to OpenAI processing during onboarding, when you save an entry, its text (typed, or transcribed from voice) is sent to OpenAI to extract structured symptom data, and voice recordings are sent to OpenAI to be transcribed. Only the entry content itself is sent — not your email, name, or any other account field. Audio is never stored by us; it exists only for the duration of the transcription request. We configure our requests to OpenAI so they are not retained for later reuse on OpenAI's side, though OpenAI's own policies allow it to retain API input/output for a limited period (around 30 days) for abuse-monitoring purposes, separate from anything we control. If you type or say identifying details (a name, a location, a clinician's name) inside an entry, that text is not filtered or redacted before processing — it is treated the same as the rest of the entry.

Your original entries and the structured data derived from them are stored in our database, hosted by Supabase.

Apple Health imports

Apple's permission screen controls whether ODNENDO can read your menstrual cycle records and how much history is available. Importing is optional and begins only when you tap Import from Apple Health. The cycle dates Apple shares are copied to your ODNENDO account so they can appear in Cycle, Timeline, and Report. Matching dates already in ODNENDO are not duplicated, and dates you previously removed are not silently restored.

Imported Apple Health dates are stored by Supabase with your other cycle records. They are not sent to OpenAI for transcription or symptom extraction. Revoking ODNENDO's Apple Health permission prevents later imports, but it does not delete dates already copied to ODNENDO; you can remove those dates in Cycle or delete your account.

Why we process this data (legal basis)

  • Explicit consent — for the health/symptom data itself, which is a special category of personal data under Article 9 GDPR / UK GDPR. We ask for this consent during onboarding, before any journal entry is processed. Apple Health access has its own optional system permission and manual import action. You can withdraw access in iOS Settings and remove imported dates in ODNENDO or by deleting your account.
  • Performance of a contract — for basic account operation (authentication, storing your entries so you can retrieve them).
  • Legitimate interests — for security, fraud prevention, and keeping the service running.

Who we share data with

Supabase (database, authentication, file storage) and OpenAI (voice transcription and symptom extraction) act as our data processors, under their respective data processing terms. Apple Health cycle dates are stored by Supabase but are not sent to OpenAI. We do not sell your personal data, and we do not share it with advertisers or data brokers. Research enrollment and research use of journal data are disabled. See our Research Policy.

International data transfers

Because our processors operate infrastructure that may be located outside your own country, your data may be transferred internationally. Where this involves a transfer out of the UK or EU to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses, as provided in our processors' own data processing agreements.

How long we keep your data

We keep your account and journal data for as long as your account exists. Deleting your account (available any time in Settings) permanently and immediately deletes your profile, journal entries, structured extraction data, and consent history — this includes cycle dates imported from Apple Health and cannot be undone. Consent records are the one exception kept as an append-only audit log while your account exists, for exactly the reason described above. Separately, OpenAI's own abuse-monitoring retention window (described above) applies independently of anything we control.

Security

Your account is protected by the authentication and database security controls provided by Supabase, and all traffic between your device and our servers is encrypted in transit (HTTPS). We do not currently offer end-to-end or on-device encryption of journal content, and we won't claim otherwise. No system is perfectly secure; we take reasonable, industry-standard measures but cannot guarantee absolute security.

Your rights

If you are in the UK or European Economic Area (GDPR / UK GDPR)

You have the right to access, correct, delete, or export your data, to restrict or object to certain processing, and to withdraw consent at any time. Many of these are self-service already: view your original entries and download an export in Settings, or delete your account outright. You also have the right to lodge a complaint with your national data protection authority — in the UK, the Information Commissioner's Office (ICO).

If you are in Australia

You have rights under the Australian Privacy Principles (Privacy Act 1988), including access to and correction of your personal information, and the right to complain to the Office of the Australian Information Commissioner (OAIC).

If you are a California resident (CCPA/CPRA)

You have the right to know what personal information we collect, to request its deletion, and to opt out of its sale — we do not sell personal information, so there is nothing to opt out of. You will not be discriminated against for exercising these rights.

Wherever you are, you can exercise these rights by using the tools in Settings or by emailing support@odnendo.com.

Age requirement

You must be at least 16 years old to create an account. We ask for your year of birth at signup specifically to enforce this, and use it for no other purpose.

Changes to this policy

If we make material changes to this policy, we will update the date at the top of this page and, where appropriate, notify you directly.