Privacy Policy

Last updated: Oct. 30th, 2025

We respect and protect the personal privacy of all users of the Service. It's important to us that you know how to control and protect your privacy. For this reason, we encourage you to read this Privacy Policy thoroughly.

This Privacy Policy explains our procedures concerning the information we collect from you or that you provide to us. We also let you know your rights and where you can control your information in the Service, with helpful examples. By using the Service, you acknowledge this notice. For each purpose described below, we state the applicable legal basis.

If you have any questions about how we use your information or want further information about this Privacy Policy and what it means, please contact us at support@myendora.health. We will endeavor to provide detailed answers to your questions promptly. You may also retrieve a copy of your data or request deletion by emailing support@myendora.health.

Additional information for individuals in the EU/EEA or UK, as well as for users who reside in California, can be found in separate sections of this Privacy Policy.

If you are an individual in the UK, please also refer to Section II – UK Privacy Policy.


Controller & Scope

  • Data Controller: MERIJAD, a company incorporated in France, registered address: 28 Avenue des Tilleuls, 91440 Bures-sur-Yvette, France.
  • No joint controllers.
  • Service covered: Lotus mobile application (iOS and Android), Web app, and the website myendora.health (collectively, the "Service").
  • Territorial scope: We make the Service available worldwide.
  • Language: This Privacy Policy is published in English.

I. General Privacy Policy

1. Interpretation and Definitions

Interpretation

Words with an initial capital letter have the meanings defined under the following conditions. The following definitions have the same meaning regardless of whether they appear in singular or plural.

Definitions

For the purposes of this Privacy Policy:

  • "You" means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
  • "We", "Us" or "Our" refers to MERIJAD.
  • "Application" means the software program provided by us and downloaded by you on any electronic device, named Lotus.
  • "Service" refers to the Application, the Web app, and the website myendora.health.
  • "Third-party Social Media Service" refers to any website or social network through which a user can log in or create an account to use the Service (e.g., Apple, Google).
  • "Personal Data" is any information relating to an identified or identifiable individual.
  • "Device" means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • "Do Not Track (DNT)" is a concept promoted by certain US regulators (e.g., FTC) for mechanisms allowing internet users to control the tracking of their online activities across websites.

2. What information do we collect?

The information we collect and process depends on how you use the Service. Some features require certain information to function (e.g., cycle tracking); other information is optional but may affect your experience if not provided. The Service supports offline use for certain features, but cloud backup and sync require an account and network connectivity.

Information you actively provide in the app (including health data) — Legal basis: Consent

Lotus is a women's health companion designed to help users track their cycles and wellness, visualize trends, and receive AI-powered insights (see "Core app features" below). You may choose to log, among other things:

  • Menstrual cycle details, symptoms and pain levels
  • Health data such as sleep hours, sport activities, water intake, food/alimentation, symptoms, and stomach photos related to bloating
  • Emotions/mood and other wellness signals

You control what you log. Health-related features are provided only with your explicit consent, which you can withdraw at any time in the app.

Account and authentication — Legal basis: Consent

To enable cloud backup, sync, and cross-device access, an account is required. We support email/password, Apple, and Google sign-in. We process: name, email, and password hash (for email sign-in).

Operational and usage data — Legal basis: Consent

When you interact with the Service, we may collect event-level usage data (e.g., screen views, taps), performance metrics, crash logs, and diagnostics to improve stability and performance. We also collect country/region, IP address, Device identifiers (IDFA/GAID) (as applicable), push notification tokens, and similar telemetry where enabled.

Notifications and communications — Legal basis: Consent

With your opt-in, we process data to send in-app messages, push notifications, email or SMS (e.g., cycle reminders, product updates, or promotions). You can manage these preferences at any time in Profile → Edit Profile.

Images you upload

If you choose to upload images (e.g., stomach photos for bloating tracking), they are processed to provide the requested features and stored securely.

Third-party social media services (for login) — Legal basis: Consent

If you log in via Apple or Google, we receive identifiers and profile information those services share (e.g., name, email). You can revoke access via your social account settings.

Core app features (overview)

Lotus provides:

  • Cycle & Symptom Tracking
  • Personalized Insights & Recommendations (including AI-powered features)
  • Endora – AI Companion
  • Gamification & Motivation via "Endolots"
  • Notifications & Reminders
  • Data Visualization
  • Optional Beta Testing & Feedback
  • Account & Cloud Sync (Firebase)
  • Potential future integrations (e.g., wearables), following the same protection standards.

In-app privacy controls

You can manage key privacy controls in Profile → Edit Profile, including: view/edit profile, enable/disable specific health categories, connect/disconnect Apple/Google services, opt-in/opt-out of push and email marketing.

Important: We do not deploy a cookie/consent banner (CMP) in the EEA because we do not use web cookies for advertising. For app telemetry and notifications, we rely on your in-app consent and settings.

3. How do we share the information?

We do not sell personal data.

We share personal data only as described below, and only with appropriate safeguards and contractual protections:

  • Service Providers / Vendors. We use reputable vendors to support the Service, such as:
    • Analytics & crash reporting: Google (e.g., Firebase Analytics/Crash, where enabled)
    • Messaging/notifications: Apple (APNs) and Google (FCM)
    • Cloud/hosting: Firebase (primary hosting region: Belgium)

    These providers process data solely to perform services for us and are bound by confidentiality and data protection obligations.

  • Payments. We may provide paid products and/or services (e.g., in-app purchases). Payment processing is handled by Apple and Google (as applicable). We do not store card details. Your purchases are governed by the respective store's privacy policy and terms.
  • Business transfers. We may share or transfer information in connection with, or during negotiations of, any merger, sale of assets, financing, or acquisition of all or part of our business to another company. Before any formal transfer, we will provide at least two weeks' notice identifying the transferee and the applicable privacy terms. You will have at least two weeks to decide whether to keep or delete your account and data before the transfer settles.
  • Legal compliance and safety. We may disclose information to law enforcement or authorities where required by law or where reasonably necessary to protect users, our rights, or the Service. We review such requests to ensure they are lawful and proportionate.

Advertising SDKs: We do not serve personalized ads in the EEA/UK without consent. If advertising features are introduced, we will request consent and update this section accordingly.

Opt-outs and controls

You can opt out of marketing communications and adjust notifications in Profile → Edit Profile or your device settings. You can request access, export, or deletion of your data at support@myendora.health.

4. How do we use the information?

We use information to operate and improve the Service and provide a personalized, helpful experience:

  • Provide and improve the Service (including personalization and feature development) — Legal basis: Consent
  • Diagnostics, security, and troubleshootingLegal basis: Consent
  • User support and responses to requests (including data subject requests) Legal basis: Consent
  • Account and sync functionalityLegal basis: Consent
  • Communications (e.g., product updates, reminders, tips, and—where opted-in—marketing) via in-app, push, email, or SMS — Legal basis: Consent
  • Payments and fraud prevention related to purchases Legal basis: Consent
  • Business transfers (see above) — Legal basis: Legitimate interests; notice provided

5. Retention of the information

We retain data only as long as necessary for the purposes described or as required by law:

  • Account data: retained while the account is active and for up to 6 months after deletion (to allow for dispute resolution, fraud prevention, and backups), after which it is irreversibly deleted or anonymized.
  • Health data: retained for 6 months unless you delete it sooner in the app or request deletion.
  • Analytics and crash logs: retained for 6 months.
  • Marketing consent logs: retained for 6 months to evidence consent.

You can delete data using in-app controls or by emailing support@myendora.health (see "Exercising your rights" below).

6. Why and how do we transfer the information?

Primary hosting is in Belgium (EU) via Firebase. We do not transfer personal data outside the EEA/UK in the ordinary course of business. If an exceptional transfer becomes necessary (e.g., a specific support interaction), we will implement appropriate safeguards (e.g., Standard Contractual Clauses) and notify you as required.

7. How do we protect the security of your information?

We implement administrative, technical, and physical security measures designed to protect your information, including:

  • System vulnerability scanning and periodic penetration testing
  • Access controls, encryption in transit and at rest (where applicable), and data integrity protections
  • Organizational and legal measures with our vendors and personnel

While we strive to use commercially acceptable means to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We continuously improve our safeguards but cannot guarantee absolute security.

In general, your data is stored on your device and within our Firebase environment (EU region). We do not operate our own data centers.

For EU: GDPR Privacy

Legal bases we rely on

Depending on the processing activity, we rely on one or more of the following legal bases:

  • Consent: account creation/authentication, health features, analytics & crash reporting, notifications/push/email/SMS, personalized content/recommendations, payments and receipts handling, and responding to support or data requests.
  • Legitimate interests: business transfers (with notice) and necessary security measures proportionate to risks (where consent is not applicable).

We are happy to clarify the specific legal basis for any processing on request.

Your rights under the GDPR

Subject to conditions and exceptions in law, you have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate data
  • Erase data ("right to be forgotten")
  • Object to processing (where applicable)
  • Restrict processing (where applicable)
  • Portability of data you provided to us
  • Withdraw consent at any time (this does not affect lawfulness prior to withdrawal)

Exercising your GDPR rights

Contact support@myendora.health. We may need to verify your identity before responding. You also have the right to lodge a complaint with your local supervisory authority in the EEA.

For California: CCPA/CPRA Privacy

Your rights (subject to exceptions):

  • Right to know the categories and specific pieces of personal information collected, the sources, purposes, and categories of third parties with whom we share it
  • Right to access and portability
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of "sale" or "sharing" for cross-context behavioral advertising (we do not sell personal information)
  • Right to non-discrimination for exercising your rights

Exercising your CCPA/CPRA rights

Email support@myendora.health. We will respond within timeframes required by law. Any opt-out is browser/device-specific.

Do Not Sell or Share My Personal Information

We do not sell personal information. If, in the future, we engage in cross-context behavioral advertising, we will provide appropriate opt-out mechanisms and update this Policy.

CalOPPA / Do Not Track

Our website and app do not respond to DNT signals. Some third parties may track your activities; you can set DNT preferences in your browser.

California Minors (Bus. & Prof. Code §22581)

California residents under 18 who are registered users may request removal of content they posted publicly by contacting support@myendora.health. This does not guarantee complete removal if retention is required by law or the content has been copied by others.

8. Children's Privacy

Our Service is not directed to children under 13. We do not knowingly collect personal data from anyone under 13. If you are a parent or guardian and believe your child has provided us personal data, please contact support@myendora.health so we can take appropriate action.

9. How do we notify you of changes to this Privacy Policy?

We may update this Privacy Policy from time to time. We will notify you by posting the new Privacy Policy on this page and, where appropriate, by a prominent notice in the Service prior to the change becoming effective. The "Last updated" date at the top will be revised accordingly. Changes are effective when posted unless otherwise stated.

10. How to contact us

If you have concerns about your information or questions about this Privacy Policy, please email support@myendora.health. You may request access, export, or deletion of your data via the same email.


II. UK Privacy Policy

Last updated: Oct. 30th, 2025

We respect and protect the personal privacy of all users of the Service. It's important to us that you know how to control and protect your privacy. For this reason, we encourage you to read this Privacy Policy thoroughly.

This UK Privacy Policy explains our procedures concerning information we collect from you or that you provide to us when you use the Service in the United Kingdom. In summary, we process limited personal data necessary to provide the Service (e.g., account credentials, device identifiers, analytics/crash diagnostics where enabled, and optional health data you choose to log). Health features are offered only with your explicit consent. By using the Service, you acknowledge this notice.

If you have any questions about how we use your information or want further information about this UK Privacy Policy and what it means, please contact support@myendora.health.

1. Interpretation and Definitions

Interpretation and Definitions are as set out in Section I.1 above. In the UK, references to GDPR are to the UK GDPR and the Data Protection Act 2018.

2. What information do we collect?

The information we collect and process in the UK depends on how you use the Service. Where you enable health features, we rely on explicit consent. You may log cycle details, symptoms, and health data (e.g., sleep, sport, water intake, food/alimentation, stomach photos for bloating). We also process account data (name, email, password hash for email sign-in), device/IP information, analytics, performance metrics, crash logs, and push tokens where you have consented. You can manage privacy settings in Profile → Edit Profile and withdraw consent at any time.

3. How do we share the information?

We do not sell personal data. We share data with service providers strictly as necessary to operate the Service, including Google/Firebase (analytics, crash, hosting), Apple/Google (notifications, sign-in, store purchases), all under appropriate contractual safeguards. If advertising features are introduced, we will request consent first and update this policy.

Payments for in-app purchases are processed by Apple and Google under their privacy policies. We do not store your card details.

We may disclose information to comply with law, protect users, or in connection with business transfers (with prior notice as described in Section I.3).

4. How do we use the information?

We use information to provide and improve the Service, including personalization, diagnostics, support, communications (product updates, reminders, and—where opted in—marketing via in-app, push, email, or SMS). Legal bases are primarily consent (including explicit consent for health data) and, where applicable, legitimate interests for proportionate security needs.

5. Retention of the information

  • Account data: retained while active and for up to 6 months after deletion.
  • Health data: retained for 6 months unless you delete it sooner or withdraw consent.
  • Analytics/crash data: retained for 6 months.
  • Marketing consent logs: retained for 6 months.

You may delete data in-app or email support@myendora.health.

6. Why and how do we transfer the information?

Data is hosted in the EU (Belgium) with Firebase. We currently do not transfer personal data outside the UK/EEA in the ordinary course. If an exceptional transfer is needed, we will implement appropriate safeguards (e.g., IDTA or UK Addendum to the SCCs) and notify you where required.

7. How do we protect the security of your information?

We implement organizational and technical measures as described in Section I.7 (e.g., encryption in transit/at rest where applicable, access controls, vulnerability testing). No method is 100% secure, but we continuously improve our safeguards.

8. Children's Privacy

Our Service is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@myendora.health.

9. Changes to this UK Privacy Policy

We will notify you in the Service and update the "Last updated" date before changes take effect. Please review periodically.

10. Contact

For privacy questions or to exercise your rights under the UK GDPR and Data Protection Act 2018, contact support@myendora.health. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).


How to exercise your rights (all regions)

Email support@myendora.health to access, export, correct, delete, or otherwise exercise your privacy rights. If you wish to retrieve or remove your data, simply send an email request to support@myendora.health. We may need to verify your identity before acting on your request.