Privacy Policy

Last updated: July 15th, 2026

We respect and protect the personal privacy of all users of the Service. It's important to us that you know how to control and protect your privacy. For this reason, we encourage you to read this Privacy Policy thoroughly.

This Privacy Policy explains our procedures concerning the information we collect from you or that you provide to us. We also let you know your rights and where you can control your information in the Service, with helpful examples. By using the Service, you acknowledge this notice. For each purpose described below, we state the applicable legal basis.

If you have any questions about how we use your information or want further information about this Privacy Policy and what it means, please contact us at support@myendora.health. We will endeavor to provide detailed answers to your questions promptly. You may also retrieve a copy of your data or request deletion by emailing support@myendora.health.

Additional information for individuals in the EU/EEA or UK, as well as for users who reside in California, can be found in separate sections of this Privacy Policy.

If you are an individual in the UK, please also refer to Section II – UK Privacy Policy.

Controller & Scope

  • Data Controller: MERIJAD, a company incorporated in France, registered address: 28 Avenue des Tilleuls, 91440 Bures-sur-Yvette, France.
  • Joint controllers: None.
  • Service covered: Endora mobile application (iOS and Android), Web app, and the website myendora.health (collectively, the "Service").
  • Territorial scope: We make the Service available worldwide.
  • Language: This Privacy Policy is published in English.

I. General Privacy Policy

1. Interpretation and Definitions

Interpretation

Words with an initial capital letter have the meanings defined under the following conditions. The following definitions have the same meaning regardless of whether they appear in singular or plural.

Definitions

For the purposes of this Privacy Policy:

  • "You" means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
  • "We", "Us" or "Our" refers to MERIJAD.
  • "Application" means the software program provided by us and downloaded by you on any electronic device, named Endora.
  • "Service" refers to the Application, the Web app, and the website myendora.health.
  • "Third-party Social Media Service" refers to any website or social network through which a user can log in or create an account to use the Service (e.g., Apple, Google).
  • "Personal Data" is any information relating to an identified or identifiable individual.
  • "Device" means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • "Do Not Track (DNT)" is a concept promoted by certain US regulators (e.g., FTC) for mechanisms allowing internet users to control the tracking of their online activities across websites.

2. What information do we collect?

The information we collect and process depends on how you use the Service. Some features require certain information to function (e.g., cycle tracking); other information is optional but may affect your experience if not provided. The Service supports offline use for certain features, but cloud backup and sync require an account and network connectivity.

Information you actively provide in the app (including health data) — Legal basis: Consent

Endora is a women's health companion designed to help users track their cycles and wellness, visualize trends, and receive AI-powered insights (see "Core app features" below). You may choose to log, among other things:

  • Menstrual cycle details, symptoms and pain levels
  • Health data such as sleep hours, sport activities and steps, water intake, food/alimentation, body weight, resting heart rate, symptoms, and stomach photos related to bloating
  • Emotions/mood and other wellness signals

You control what you log. Health-related features are provided only with your explicit consent, which you can withdraw at any time in the app.

Data from Apple Health and Android Health Connect — Legal basis: Explicit consent

Endora offers an optional integration with Apple Health (HealthKit) on iOS and Health Connect on Android. If — and only if — you choose to connect it and grant the corresponding permissions, we read the following data types from these platforms:

  • Daily step count
  • Exercise sessions (duration of physical activity)
  • Sleep (duration, bed and wake times)
  • Hydration (water intake)
  • Body weight
  • Resting heart rate

How we use it. This data is used solely to auto-fill your daily health journal (so you don't have to log it by hand), to power your personal analytics and insights, and — only if you have also consented to AI-powered features — to enrich the personalized insights described in Section 3b.

Read-only. Access is strictly read-only: we never write data to Apple Health or Health Connect.

Where it is stored. Synced data is stored with your other health data in our Firebase environment (primary hosting region: Belgium, EU), tied to your account.

Sharing. This data is shared only with the service providers described in Sections 3 and 3b, strictly to provide the Service. We never sell it, never use it for advertising, and never use it to determine credit-worthiness, insurance eligibility, or employment suitability.

Your control and deletion. You can disconnect the integration at any time in the app, and revoke the underlying permissions in the Health Connect app (Android) or the Health app (iOS). Disconnecting stops future syncing; previously synced data remains stored with your other health data until it is deleted. You can delete it by deleting your account in the app or by emailing support@myendora.health (see Section 5).

Account and authentication — Legal basis: Consent

To enable cloud backup, sync, and cross-device access, an account is required. We support email/password, Apple, and Google sign-in. We process: name, email, and password hash (for email sign-in).

Operational and usage data — Legal basis: Consent

When you interact with the Service, we may collect event-level usage data (e.g., screen views, taps), performance metrics, crash logs, and diagnostics to improve stability and performance. We also collect country/region, IP address, Device identifiers (IDFA/GAID) (as applicable), push notification tokens, and similar telemetry where enabled.

Notifications and communications — Legal basis: Consent

With your opt-in, we process data to send in-app messages, push notifications, email or SMS (e.g., cycle reminders, product updates, or promotions). You can manage these preferences at any time in Profile → Edit Profile.

Images you upload

If you choose to upload images (e.g., stomach photos for bloating tracking), they are processed to provide the requested features and stored securely.

Third-party social media services (for login) — Legal basis: Consent

If you log in via Apple or Google, we receive identifiers and profile information those services share (e.g., name, email). You can revoke access via your social account settings.

Core app features (overview)

Endora provides:

  • Cycle & Symptom Tracking
  • Personalized Insights & Recommendations (including AI-powered features)
  • Endora – AI Companion
  • Gamification & Motivation via "Endolots"
  • Notifications & Reminders
  • Data Visualization
  • Optional Beta Testing & Feedback
  • Account & Cloud Sync (Firebase)
  • Optional, read-only sync with Apple Health (iOS) and Health Connect (Android) — see "Data from Apple Health and Android Health Connect" above.

In-app privacy controls

You can manage key privacy controls in Profile → Edit Profile, including: view/edit profile, enable/disable specific health categories, connect/disconnect Apple/Google services, connect/disconnect the Apple Health / Health Connect sync, opt-in/opt-out of push and email marketing.

Important: We do not deploy a cookie/consent banner (CMP) in the EEA because we do not use web cookies for advertising. For app telemetry and notifications, we rely on your in-app consent and settings.

3. How do we share the information?

We do not sell personal data.

We share personal data only as described below, and only with appropriate safeguards and contractual protections:

  • Service Providers / Vendors. We use reputable vendors to support the Service, such as:
    • Analytics & crash reporting: Google (e.g., Firebase Analytics/Crash, where enabled)
    • Messaging/notifications: Apple (APNs) and Google (FCM)
    • Cloud/hosting: Firebase (primary hosting region: Belgium)
    • AI services: OpenAI (for AI-powered features; see Section 3b for details)
    • Subscriptions: RevenueCat (RevenueCat, Inc., USA) — receives a pseudonymous user ID and purchase/receipt information to manage subscriptions; it never receives health data These providers process data solely to perform services for us and are contractually required to provide the same or equal level of data protection as described in this Privacy Policy.
  • Payments. We may provide paid products and/or services (e.g., in-app purchases). Payment processing is handled by Apple and Google (as applicable). We do not store card details. Your purchases are governed by the respective store's privacy policy and terms.
  • Business transfers. We may share or transfer information in connection with, or during negotiations of, any merger, sale of assets, financing, or acquisition of all or part of our business to another company. Before any formal transfer, we will provide at least two weeks' notice identifying the transferee and the applicable privacy terms. You will have at least two weeks to decide whether to keep or delete your account and data before the transfer settles.
  • Legal compliance and safety. We may disclose information to law enforcement or authorities where required by law or where reasonably necessary to protect users, our rights, or the Service. We review such requests to ensure they are lawful and proportionate.
  • Advertising SDKs. We do not serve personalized ads in the EEA/UK without consent. If advertising features are introduced, we will request consent and update this section accordingly.

Opt-outs and controls

You can opt out of marketing communications and adjust notifications in Profile → Edit Profile or your device settings. You can request access, export, or deletion of your data at support@myendora.health.

3b. AI-Powered Features & Third-Party AI Services

Endora uses artificial intelligence to power several features. To provide these features, certain data is processed by a third-party AI service provider, OpenAI (OpenAI, L.L.C., San Francisco, CA, USA).

What data is shared

  • Endora AI Companion: Health tracking summaries (symptoms, sleep, meals, cycle data, mood, weight, contraception method), profile information, and chat messages you send to Endora. If you have connected Apple Health or Health Connect, these summaries also include the health data synced from those platforms (steps, activity minutes, sleep, hydration, weight, resting heart rate).
  • Meal Image Analysis: Photos of meals you upload for nutritional analysis.
  • Food Categorization: Names of food items you log, for normalization and categorization purposes.

Purpose

Data is shared with OpenAI solely to:

  • Power the Endora AI companion and provide personalized health insights
  • Analyze meal photos for nutritional content
  • Categorize and normalize food item names

How data is processed

All data sent to OpenAI is processed server-side through our secure backend (Firebase Cloud Functions). Your data is never sent directly from your device to OpenAI. Communications between our servers and OpenAI are encrypted in transit.

Data protection

  • Data sent to OpenAI via API is not used by OpenAI to train or improve their models, in accordance with OpenAI's API data usage policy.
  • All data is encrypted in transit between our servers and OpenAI.
  • We share your first name with OpenAI to personalize insights and the Endora chat. We do not share your last name, email address, or account credentials with OpenAI.

International transfers

Data processed by OpenAI may be transferred to and processed in the United States. For users in the EU/EEA or UK, this transfer is covered by appropriate safeguards including Standard Contractual Clauses (SCCs). See the GDPR and UK sections below for more information.

Your control

AI-powered features are an integral part of the Service. Your explicit consent to AI data processing is collected during onboarding and is required to create an account. You can withdraw your consent at any time by contacting support@myendora.health; we will then stop processing your data for AI-powered features, which disables them (Endora chat, meal photo analysis). You can also delete your account at any time.

4. How do we use the information?

We use information to operate and improve the Service and provide a personalized, helpful experience:

  • Provide and improve the Service (including personalization and feature development) — Legal basis: Consent
  • Diagnostics, security, and troubleshooting — Legal basis: Consent
  • User support and responses to requests (including data subject requests) — Legal basis: Consent
  • Account and sync functionality — Legal basis: Consent
  • Communications (e.g., product updates, reminders, tips, and—where opted-in—marketing) via in-app, push, email, or SMS — Legal basis: Consent
  • Payments and fraud prevention related to purchases — Legal basis: Consent
  • Business transfers (see above) — Legal basis: Legitimate interests; notice provided

5. Retention of the information

We retain data only as long as necessary for the purposes described or as required by law:

  • Account data: retained while the account is active and for up to 6 months after deletion (to allow for dispute resolution, fraud prevention, and backups), after which it is irreversibly deleted or anonymized.
  • Health data (including data synced from Apple Health / Health Connect): retained while your account is active; deleted or anonymized within 6 months after account deletion, or sooner if you delete it in the app or request deletion.
  • Analytics and crash logs: retained for 6 months.
  • Marketing consent logs: retained for 6 months to evidence consent.

You can delete data using in-app controls or by emailing support@myendora.health (see "Exercising your rights" below).

6. Why and how do we transfer the information?

Primary hosting is in Belgium (EU) via Firebase. In the ordinary course of business, data shared with OpenAI for AI-powered features (see Section 3b) and with RevenueCat for subscription management (see Section 3) may be processed in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) and encryption in transit. For all other data, we do not transfer personal data outside the EEA/UK. If an additional exceptional transfer becomes necessary (e.g., a specific support interaction), we will implement appropriate safeguards and notify you as required.

7. How do we protect the security of your information?

We implement administrative, technical, and physical security measures designed to protect your information, including:

  • System vulnerability scanning and periodic penetration testing
  • Access controls, encryption in transit and at rest (where applicable), and data integrity protections
  • Organizational and legal measures with our vendors and personnel

While we strive to use commercially acceptable means to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We continuously improve our safeguards but cannot guarantee absolute security.

In general, your data is stored on your device and within our Firebase environment (EU region). We do not operate our own data centers.

For EU: GDPR Privacy

Legal bases we rely on

Depending on the processing activity, we rely on one or more of the following legal bases:

  • Consent: account creation/authentication, health features, analytics & crash reporting, notifications/push/email/SMS, personalized content/recommendations, payments and receipts handling, and responding to support or data requests.
  • Legitimate interests: business transfers (with notice) and necessary security measures proportionate to risks (where consent is not applicable).

We are happy to clarify the specific legal basis for any processing on request.

Your rights under the GDPR

Subject to conditions and exceptions in law, you have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate data
  • Erase data ("right to be forgotten")
  • Object to processing (where applicable)
  • Restrict processing (where applicable)
  • Portability of data you provided to us
  • Withdraw consent at any time (this does not affect lawfulness prior to withdrawal)

Exercising your GDPR rights

Contact support@myendora.health. We may need to verify your identity before responding. You also have the right to lodge a complaint with your local supervisory authority in the EEA.

For California: CCPA/CPRA Privacy

Your rights (subject to exceptions):

  • Right to know the categories and specific pieces of personal information collected, the sources, purposes, and categories of third parties with whom we share it
  • Right to access and portability
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of "sale" or "sharing" for cross-context behavioral advertising (we do not sell personal information)
  • Right to non-discrimination for exercising your rights

Exercising your CCPA/CPRA rights

Email support@myendora.health. We will respond within timeframes required by law. Any opt-out is browser/device-specific.

Do Not Sell or Share My Personal Information

We do not sell personal information. If, in the future, we engage in cross-context behavioral advertising, we will provide appropriate opt-out mechanisms and update this Policy.

CalOPPA / Do Not Track

Our website and app do not respond to DNT signals. Some third parties may track your activities; you can set DNT preferences in your browser.

California Minors (Bus. & Prof. Code §22581)

California residents under 18 who are registered users may request removal of content they posted publicly by contacting support@myendora.health. This does not guarantee complete removal if retention is required by law or the content has been copied by others.

8. Children's Privacy

Our Service is not directed to children under 13. We do not knowingly collect personal data from anyone under 13. In the EU/EEA, the applicable age of digital consent in your country applies (for example, 15 in France); where required, we do not process data of users below that age without appropriate consent. If you are a parent or guardian and believe your child has provided us personal data, please contact support@myendora.health so we can take appropriate action.

9. How do we notify you of changes to this Privacy Policy?

We may update this Privacy Policy from time to time. We will notify you by posting the new Privacy Policy on this page and, where appropriate, by a prominent notice in the Service prior to the change becoming effective. The "Last updated" date at the top will be revised accordingly. Changes are effective when posted unless otherwise stated.

10. How to contact us

If you have concerns about your information or questions about this Privacy Policy, please email support@myendora.health. You may request access, export, or deletion of your data via the same email.

II. UK Privacy Policy

Last updated: July 15th, 2026

We respect and protect the personal privacy of all users of the Service. It's important to us that you know how to control and protect your privacy. For this reason, we encourage you to read this Privacy Policy thoroughly.

This UK Privacy Policy explains our procedures concerning information we collect from you or that you provide to us when you use the Service in the United Kingdom. In summary, we process limited personal data necessary to provide the Service (e.g., account credentials, device identifiers, analytics/crash diagnostics where enabled, and optional health data you choose to log). Health features are offered only with your explicit consent. By using the Service, you acknowledge this notice.

If you have any questions about how we use your information or want further information about this UK Privacy Policy and what it means, please contact support@myendora.health.

1. Interpretation and Definitions

Interpretation and Definitions are as set out in Section I.1 above. In the UK, references to GDPR are to the UK GDPR and the Data Protection Act 2018.

2. What information do we collect?

The information we collect and process in the UK depends on how you use the Service. Where you enable health features, we rely on explicit consent. You may log cycle details, symptoms, and health data (e.g., sleep, sport, water intake, food/alimentation, weight, stomach photos for bloating). With your explicit consent, we also read health data from Apple Health (iOS) or Health Connect (Android) — steps, exercise duration, sleep, hydration, weight, and resting heart rate — as described in Section I.2 ("Data from Apple Health and Android Health Connect"). We also process account data (name, email, password hash for email sign-in), device/IP information, analytics, performance metrics, crash logs, and push tokens where you have consented. You can manage privacy settings in Profile → Edit Profile and withdraw consent at any time.

3. How do we share the information?

We do not sell personal data. We share data with service providers strictly as necessary to operate the Service, including Google/Firebase (analytics, crash, hosting), Apple/Google (notifications, sign-in, store purchases), RevenueCat (subscription management — pseudonymous user ID and purchase information; no health data), and OpenAI (for AI-powered features such as Endora AI companion, meal photo analysis, and food categorization — see Section I.3b of the General Privacy Policy for full details). All providers are bound by contractual safeguards requiring them to provide the same or equal level of data protection as described in this Privacy Policy. If advertising features are introduced, we will request consent first and update this policy.

Payments for in-app purchases are processed by Apple and Google under their privacy policies. We do not store your card details.

We may disclose information to comply with law, protect users, or in connection with business transfers (with prior notice as described in Section I.3).

4. How do we use the information?

We use information to provide and improve the Service, including personalization, diagnostics, support, communications (product updates, reminders, and—where opted in—marketing via in-app, push, email, or SMS). Legal bases are primarily consent (including explicit consent for health data) and, where applicable, legitimate interests for proportionate security needs.

5. Retention of the information

  • Account data: retained while active and for up to 6 months after deletion.
  • Health data (including data synced from Apple Health / Health Connect): retained while your account is active; deleted or anonymized within 6 months after account deletion, or sooner if you delete it or withdraw consent.
  • Analytics/crash data: retained for 6 months.
  • Marketing consent logs: retained for 6 months.

You may delete data in-app or email support@myendora.health.

6. Why and how do we transfer the information?

Data is hosted in the EU (Belgium) with Firebase. In the ordinary course of business, data shared with OpenAI for AI-powered features (see Section 3b of the General Privacy Policy) and with RevenueCat for subscription management may be processed in the United States. These transfers are protected by the UK Addendum to the Standard Contractual Clauses (SCCs) and encryption in transit. For all other data, we currently do not transfer personal data outside the UK/EEA. If an additional exceptional transfer is needed, we will implement appropriate safeguards (e.g., IDTA or UK Addendum to the SCCs) and notify you where required.

7. How do we protect the security of your information?

We implement organizational and technical measures as described in Section I.7 (e.g., encryption in transit/at rest where applicable, access controls, vulnerability testing). No method is 100% secure, but we continuously improve our safeguards.

8. Children's Privacy

Our Service is not directed to children under 13. We do not knowingly collect personal data from children, and where a higher age of digital consent applies, we honour it. If you believe a child has provided personal data, contact support@myendora.health.

9. Changes to this UK Privacy Policy

We will notify you in the Service and update the "Last updated" date before changes take effect. Please review periodically.

10. Contact

For privacy questions or to exercise your rights under the UK GDPR and Data Protection Act 2018, contact support@myendora.health. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

How to exercise your rights (all regions)

Email support@myendora.health to access, export, correct, delete, or otherwise exercise your privacy rights. If you wish to retrieve or remove your data, simply send an email request to support@myendora.health. We may need to verify your identity before acting on your request.