Version: 1.4 · Effective date: 25.08.2026 · Last updated: 25.08.2026
This policy applies to the 8 women apps for iOS and Android and to the 8 women website at https://8women.in.ua. Together we call them the Service.
We do not store any health data. None. We do not collect it, we do not receive it, and we hold no copy of it: your cycle, your reflections and your breathing diary exist only on your phone. Section 3 explains exactly what that means and how it is enforced.
1. Who we are
The data controller is PE Volkov IvanYurkivska St. 40, apt. 15, Kyiv, 01001, UkraineRegistration record: 20021208-00535Telephone +380 50 157 1549Contact for any privacy matter: moc.liamg%40au.ni.nemow8.
We process personal data under Ukraine's Law No. 2297-VI "On Personal Data Protection" and, for people in the European Economic Area and the United Kingdom, under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
No representative, because we hold no sensitive data. The only personal data that reaches our servers is ordinary account, purchase and technical data (section 2). We process no special categories of data (Article 9 GDPR) and no criminal-offence data (Article 10) on our servers — your menstrual-cycle and other health-adjacent data never leave your device (section 3), and the onboarding answers rest on your explicit consent and can be refused entirely. On that basis we rely on the exemption in Article 27(2)(a) GDPR and UK GDPR and do not appoint an EU or UK representative. You can reach us directly, or your local supervisory authority, using the contacts in this policy.
2. What we collect
We collect the minimum needed to run the Service. This is the complete list of personal data that leaves your device and reaches our servers.
About the onboarding answers. Answers about your goals and breathing experience may touch on your wellbeing, so out of caution we treat them as health data and ask for your explicit consent in these exact words: «I agree that 8 women may process the onboarding answers I choose to give, to suggest practices and programs that fit me.» You can skip every question, and the Service works fully without them.
We do not ask for your gender. We do not run advertising, ad tracking, or any cross-app or cross-site tracking. We do not sell personal data, and we do not share it with data brokers. Nothing you record in the Service is ever shared with or sold to advertisers — and the most sensitive part cannot be, because it never reaches us. No analytics or crash-reporting SDK is present in the apps. The website runs no analytics and sets no cookies beyond the strictly necessary ones named above, so it shows no cookie banner because it needs none.
Nothing in section 2 is bundled: you can use the Service with a working account while refusing every item whose basis is consent, and refusing them changes nothing except the feature they belong to.
3. What never leaves your device
The following is written only to storage on your own phone, in an app container that is excluded from iCloud, iTunes and Android backups. It does not sync, it is not uploaded, and we have no way to read it:
● Menstrual-cycle data — period and cycle dates, cycle lengths, the calendar, and your day-by-day symptom notes.● Опора reflections, your breathing diary, homework answers, quiz attempts, and your favourite practices.
We hold no copy of this information, cannot recover it for you, and never process it. If our servers were ever breached, the attacker would find no cycle data, no reflections and no diary — they are not there. Because it is deliberately kept out of backups, it does not transfer when you change or reset your phone. We know this is inconvenient. We chose it anyway: the alternative is a server somewhere holding a record of your cycle, and we did not want that server to exist.
What this means for your rights. The rights in section 10 — access, export, correction, deletion — apply to the data we hold. We cannot exercise them over the data in this section, not because we refuse but because we have no way to reach it. That data is entirely yours: it is on your phone, you can read it in the app at any time, and you delete it by deleting your account on that device or by removing the app. If you ever want a copy, export it from the app; we cannot produce it for you.
4. How we use what we do collect
To create and secure your account. To give you the content you bought and restore it when you reinstall or change device. To suggest practices based on your onboarding answers. To send the notifications you opted into. To answer you when you write to support. To keep the Service secure. To meet accounting, tax and other legal obligations.
We do not make automated decisions that produce legal effects or similarly significantly affect you. We do not use your data to train artificial-intelligence models, and we do not provide it to anyone else for that purpose.
5. Payments
In the apps, purchases are handled by Apple (App Store) and Google (Google Play). We never see your card details — only the entitlement that tells our servers to unlock your content.
On the website, payments are handled by Monobank (JSC Universal Bank) under its own terms. Your card data goes to the bank, not to us; we receive the transaction status and reference. Website purchases are also governed by our public offer at https://8women.in.ua/en/terms
6. Who else touches your data
● Supabase — our backend: authentication, database and file storage. Acts as our processor under a data-processing agreement. Hosted in the European Union (Paris, `eu-west-3`).● Website hosting provider — hosting for the website, our processor under a data-processing agreement, servers located in the European Union. We give the provider's current name on request: .moc.liamg%40au.ni.nemow8● Apple and Google — sign-in, in-app purchases, and notification delivery through Apple APNs and Google Firebase Cloud Messaging. Firebase is used for message delivery on Android only; Firebase Analytics is not integrated.● Vimeo — video hosting and playback. When you play a video, Vimeo receives technical data such as your IP address and playback events, and uses it for its own purposes. For that data Vimeo is an independent controller under its own privacy policy, not merely our processor.● Monobank (JSC Universal Bank) — payment processing for website purchases, acting as an independent controller for the payment itself.
We do not transfer your data to anyone else. If that ever changes, this section changes first.
7. Cookies and the website
The website sets strictly necessary cookies only — those without which the site cannot do what you asked it to do: keep your session alive and let checkout work. Storing them does not require your consent, because the law exempts cookies that are strictly necessary to provide the service you requested; any personal data we then process through them rests on our legitimate interest in running the site.
We use no analytics cookies, no advertising cookies and no cross-site trackers, so no consent banner is required and none is shown. If we ever introduce analytics, we will publish the change here before it goes live and will ask for your consent wherever the law requires it.
8. Notifications
Push notifications are opt-in. iOS and Android ask your permission first, and you can withdraw it at any time in system settings or inside the app. Withdrawing is as easy as giving it. We send only service messages — new content and the reminders you set yourself. We never send third-party marketing, and we never sell or share your push token.
9. Health and wellbeing
The Service supports breathing and wellbeing practices and offers an optional menstrual-cycle calendar. Cycle data and reflections stay on your device and are never collected or processed by us (section 3).
The Service is a wellness tool. It is not a medical device. It does not diagnose, treat, cure or prevent any condition; the cycle calendar must not be used for contraception or to plan or prevent pregnancy; and nothing in the Service replaces advice from a qualified professional. The public offer lists the conditions for which you should speak to a doctor before practising.
Опора collects nothing. It does not record which screens you open, does not analyse your state, keeps no history of your visits on our servers, and notifies no one — not us, not anyone else. What you write there stays on your phone under section 3.
Опора is available to every registered user, always and free of charge. It displays a clear notice that it does not replace a doctor or a therapist, and it lists emergency contacts for your region — in Ukraine 103 and the 7333 psychological support line, in the European Economic Area and the United Kingdom 112, and the local equivalent in every other country where the Service is available.
10. How long we keep data, and your rights
We keep your account data for as long as your account exists. If your account is inactive for three years, we delete it and everything attached to it, after warning you at your email address first.
Signing out deletes nothing — your account and your on-device data both survive it.
Deleting your account (Profile → «Видалити акаунт») erases your server-side records and your authentication credentials, and wipes the on-device data listed in section 3 on the device where you do it. If you use the Service on more than one device, delete the app on the others too. Deletion is completed within 30 days.
Records we must keep for accounting and tax purposes are retained for 1095 days (3 years) after the transaction, as required by Article 44.3 of the Tax Code of Ukraine, even if you delete your account. Technical connection records (section 2) are kept for 90 days and then deleted.
You may ask us to give you access to your data, correct it, delete it, export it in a portable form, restrict or object to how we use it, and you may withdraw any consent at any time without affecting what we did lawfully beforehand. Write to .moc.liamg%40au.ni.nemow8
We answer within one month. If a request is unusually complex or you have made several, we may extend that by up to two further months; we will tell you within the first month and explain why.
If you think we have handled your data badly, please tell us first — but you may also complain to the supervisory authority in Ukraine, the Ukrainian Parliament Commissioner for Human Rights, or to the data protection authority of the country where you live, if it has one.
11. Age
You must be at least 16 to create an account. We do not knowingly collect data from anyone younger.
The Service is rated 16+ on the App Store and carries the rating assigned through the IARC questionnaire on Google Play, because it covers reproductive and menstrual health. The stores use their own rating scales, which do not always match our minimum account age; where they differ, the stricter of the two applies to you.
12. Where your data is stored and sent
We are established in Ukraine. Our backend data is stored in the European Union (Paris) and the website is hosted in the European Union — we chose European hosting deliberately, for the protection its rules give the data even though we are not obliged to use it.
Our service providers (section 6) may process technical data outside the European Economic Area. Such transfers take place under the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914) and, for providers in countries the Commission has found to provide an adequate level of protection, under the relevant adequacy decision under Article 45 GDPR. A copy of the applicable Standard Contractual Clauses is available on request from .moc.liamg%40au.ni.nemow8
13. Security
Everything travels over HTTPS/TLS. Our database provider encrypts data at rest. We enforce row-level security so that each account can reach only its own rows. Access to production data is limited to named individuals, protected by two-factor authentication, and reviewed regularly. The most sensitive data in the product — your cycle — is not in our systems at all, which is the strongest security measure we could give it.No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you directly without undue delay.
14. Where the Service is available
The apps are published on the App Store and Google Play worldwide, except:
● mainland China, which we have chosen not to enter;● Russia, Belarus, the Democratic People's Republic of Korea, Iran, Syria, Cuba, and the occupied territories of Ukraine, where we do not distribute the Service at all.
The website does not sell into any of those territories either.
15. Changes to this policy
We may update this policy. When we do, we post the new version here with a new effective date. If a change materially affects your rights, we tell you in the app and by email before it takes effect, and where the change relies on your consent we ask for it again. Every published version is archived and available on request.
16. Contact
PE Volkov IvanYurkivska St. 40, apt. 15, Kyiv, 01001, Ukraine20021208-00535+380 50 157 1549moc.liamg%40au.ni.nemow8
17. Additional information for certain regions
European Economic Area and United Kingdom. If you are in the EEA or the United Kingdom, the GDPR and the UK GDPR apply to our processing. The legal basis for each category of data is given in the table in section 2: performance of a contract (Art. 6(1)(b)), your consent or explicit consent (Art. 6(1)(a) and Art. 9(2)(a)), our legitimate interest in keeping the Service secure (Art. 6(1)(f)), and compliance with a legal obligation (Art. 6(1)(c)). You have the rights in Articles 15–22: access, rectification, erasure, restriction, objection and portability, and you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You may lodge a complaint with the supervisory authority of the country where you live or work — the list of EEA authorities is maintained by the European Data Protection Board, and in the United Kingdom it is the Information Commissioner's Office. The basis on which we do not appoint an Article 27 representative is explained in section 1.Switzerland. The Swiss Federal Act on Data Protection gives you equivalent rights; you may complain to the Federal Data Protection and Information Commissioner.
United States. We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under California and other state privacy laws. Residents of states with comprehensive privacy laws may request access, correction, deletion and portability, and may appeal a refusal, by writing to moc.liamg%40au.ni.nemow8. We do not use or disclose sensitive personal information for any purpose other than providing the Service.
Brazil. Under the LGPD you may request confirmation of processing, access, correction, anonymisation, portability and deletion, and information about with whom we share data. Our contact for these requests is .moc.liamg%40au.ni.nemow8
Ukraine. We process personal data under Law No. 2297-VI. This policy, shown to you before you create an account, is our notice under Article 12 of that Law: it tells you the composition and content of the personal data we collect, the purpose of collecting it, and the persons to whom it is transferred (sections 2, 4 and 6). You may exercise the rights granted by Article 8 of that Law by writing to .moc.liamg%40au.ni.nemow8