‹ Peri

Privacy Policy

Last updated September 2026

Peri is in open beta. This policy describes what the app actually does today, in plain terms. Where something is a limitation rather than a promise, it says so.

Where your health data is stored

Everything you log — cycle days, bleeding, sleep, energy, mood, brain fog, bloating, motivation, sex drive, training, symptoms, free-text notes, treatment and medication records, and any wearable data you import — is stored in your browser, on the device you logged it on. It is not uploaded to Peri. We do not run a server that holds your health data, so we cannot read it, and we could not hand it over if we were asked to. This has a consequence worth understanding before you rely on the app: because your data lives only in that browser, clearing your browser or site data, using a different browser or device, or uninstalling Peri can lose it. There is no cross-device sync.

Signing in with Google

Peri uses Google Sign-In to tell accounts apart. When you sign in, Google gives the app a signed token, and Peri reads four things from it: your Google account ID, your email address, whether Google considers that address verified, and your profile picture URL. That information stays on your device. It is used to keep your data separate from anyone else who signs in on the same browser, and to show your picture in the app. It is not sent to a Peri server. Ordinary sign-in does not ask for access to your Google Drive, your files, your contacts or anything else in your Google account. If Google ever shows you a screen asking Peri for Drive access during normal sign-in, that is a bug — please tell us.

Google Drive

One pre-existing account, configured before the public beta, stores its data in a private Google Drive application folder instead of the browser. That arrangement is specific to that account and is not how Peri works for you. If you are reading this as a new user, your account is local-first: no Drive access is requested, and nothing of yours is written to Google Drive.

Anonymous beta analytics

Peri collects a small amount of anonymous product telemetry during the beta. Nothing is collected until you press Continue on the consent screen, and nothing at all is collected if you leave the toggle off. Where that toggle starts depends on where you are. In the EEA, the United Kingdom and Switzerland it starts switched off, because consent there has to be something you actively give. Everywhere else it starts on, and one tap turns it off. If we cannot work out where you are — the lookup fails, or you are behind a VPN — it starts off, because off is the safer of the two guesses. That lookup uses your connection, happens once, and we neither receive nor store the country or your IP address: it produces a yes or no and nothing else. Whatever it starts as, the choice you leave it on when you press Continue is the one we save, and you can change it later. When it is on, the app records a random identifier generated on your device — not your name, email or Google account ID — and sends which parts of the app you opened, a rating if you give one, and a timestamp. There is a second identifier, and it is worth being clear about it: a random ID for the current visit, which lets us tell one visit apart from another. It is held in memory only, never written to your device, and a reload replaces it. It is not attached to feedback or survey submissions at all. If a batch does not reach us we retry it a few times and then give up. Each batch carries a random ID of its own so that a retry of one we already received is recognised and not counted twice. It is stored with that batch and expires with it after 90 days, like everything else here. It identifies the batch, not you: it is generated fresh for each one, is never reused, and is attached to nothing else you send. We also keep a small tally of how often delivery failed — counts only: how many batches were accepted, how many failed temporarily, how many were refused, how many gave up, and how many events we discarded because the queue was full. No error text, no addresses, no response contents. Some of that touches your health in a limited way, and it is worth being precise rather than reassuring: the app records that you saved a log of a particular kind, and a period log and a symptom log are two of those kinds. So we can see that you logged a period on a given day. We never receive what was in it — no symptom name, note, score, cycle day, sleep or wearable value, workout, treatment or medication leaves your device this way. The list of events we accept is fixed on our server, so anything outside it is rejected rather than stored.

Follow-up research and wearable requests

Two things you can choose to send us are not anonymous, and we are not going to call them that. If you turn on follow-up interviews and surveys, we ask how to reach you: email, WhatsApp or phone, and the address or number itself. You type it in. We do not take the email from your Google account, we do not read it from your profile, and we do not guess which method you would prefer — an address we lifted is not one you chose to give us. We store only the method, the detail you submitted, the time you submitted it and a short label for the version of this explanation you were shown — so we can tell what you actually agreed to — under a random ID created for that record alone. It is not linked to your usage data, your logs or your anonymous analytics ID, and it is used only to contact you about the Peri beta. You can change it or remove it at any time in Settings under Data & Privacy; removing it replaces the stored record, so the address or number itself is gone rather than marked. Deleting your account tries to remove it too, and tells you plainly if that did not work rather than claiming it did. It is deleted after 90 days regardless. If you tell us which wearable or app you would like Peri to support, we store that text, the time you sent it and a one-off random ID used for nothing else. Two requests from the same device cannot be connected to each other or to you. That box is free text: we ask for a product name and ask you not to put personal or health details in it, but it is stored as you write it, and nothing stops you. It also expires after 90 days. Neither of these switches analytics on, and both work with analytics switched off.

Feedback and surveys

Sending feedback, or answering a weekly survey, is a separate thing you choose to do. It works whether or not analytics is switched on, and doing it does not switch analytics on. The weekly survey is offered to everyone on the same seven-day rhythm, whether analytics is on or off — turning analytics down should not also mean never being asked what you think. What you type is stored exactly as you write it, along with which screen you were on and the app version. We ask you not to put personal or health details in those boxes, and the app says so above them — but nothing stops you, and if you write them we will have them. That is the honest position: this is the one place where health information can reach us, and it reaches us only because you typed it. If analytics is on, your message carries the same anonymous identifier as your usage data, so a bug report can be read against what the app was doing. If analytics is off, each submission gets a fresh one-off identifier instead, so declining analytics does not quietly earn you a permanent one. This telemetry is stored by Netlify, who host Peri, on our behalf.

Others who receive data

Google — for sign-in, and for Drive on the one configured account described above. Your use of Google Sign-In is also covered by Google's own privacy policy. Netlify — hosts the site and stores the anonymous beta telemetry described above. As our host Netlify handles every request to Peri, so it sees ordinary request metadata such as your IP address. Peri itself does not read, store or log your IP. What Netlify keeps, and for how long, is governed by Netlify rather than by us, and we are not going to describe it as though we controlled it. Google Fonts — the app loads its typeface from Google's font service, so Google receives your IP address and browser details when a page loads, as with any site using that service. Peri does not sell your data, does not share it with advertisers, and runs no advertising or cross-site tracking.

Exporting your data

Settings → Data & Privacy → Export data downloads a copy of your entries, treatment records, profile answers and preferences as a file on your device. Be aware of the limitation: Peri cannot currently read an exported file back in. The export is a copy you can keep or open elsewhere, not a backup you can restore from. If you clear your browser data, an export will not bring the app back to where it was.

Deleting your data

In Settings → Data & Privacy: "Delete all logs" removes your entries and treatment records from this device. Your profile answers and preferences stay. "Delete account", when signed in, removes your health data, profile and preferences from this device and signs you out. For the one Drive-backed account, it deletes the Drive files first and only then clears the device. It also clears your analytics consent and the anonymous identifier from this device. "Clear data from this device", when signed out, removes all Peri data in that browser, including data belonging to any other account that has signed in on it. One thing deletion does not do: anonymous telemetry you already sent stays in our beta records for now. It is not linked to your name, email or Google account, and once the anonymous identifier is cleared from your device there is nothing left connecting it to you — so we cannot go and pick your rows out on request, and we are not going to claim we can. It does not stay indefinitely. A job runs every day and deletes beta telemetry — usage events, feedback and survey answers alike — once it is more than 90 days old. That applies to everything already collected, not only to what arrives from now on.

What we have not established

Peri is an independent beta project, and it would be easy to imply more rigour than exists. So, plainly: Peri does not add its own encryption to the data in your browser — it relies on your device and browser security. Peri has not been certified or audited against HIPAA, GDPR or any other framework, and we make no compliance claim. Peri is not a medical device and has not been clinically validated.

Changes to this policy

If what the app does changes, this page changes with it. The date at the top is when it was last revised.

Contact

Questions about privacy, or anything above that does not match what you see in the app: hello@periapp.co.