PRIVACY POLICY

Privacy Policy for Locket

Effective date: August 8, 2026 · Chao-Wei Tsang · support@lockethealth.com

1. Your health data stays on your device

When you log periods, symptoms, temperatures, moods, or notes in Locket, all of the following holds. Where this policy says "we cannot," it describes the architecture, not a promise.

2. What leaves your device

In this release, the Locket app sends none of your data to Locket's servers. Your entries, and everything computed from them, stay on your phone. One category of technical data does leave: crash reports, engineered to contain no health data (Section 5). Two further capabilities are part of Locket's design and will be described here in full, with a new effective date and notice in the app, before either is turned on:

Once either is active, our servers will see standard connection data (such as IP address) when your device talks to them; we will not use it to build profiles or combine it with anything else.

3. Apple Health

If you connect Apple Health, Locket requests read-only access to fifteen cycle-related categories: menstrual flow, spotting (intermenstrual bleeding), persistent intermenstrual bleeding, prolonged menstrual periods, irregular menstrual cycles, infrequent menstrual cycles, cervical mucus quality, ovulation test results, progesterone test results, sexual activity, contraceptive use, pregnancy, pregnancy test results, lactation, and basal body temperature. We list all of them here — including the most sensitive — because you should not have to guess. You approve each type individually in the iOS permission sheet, may decline any of them, and can revoke access at any time in iOS Settings → Privacy & Security → Health.

Imported records are processed entirely on your device and encrypted like everything else. We never write to Apple Health. We do not use data obtained through HealthKit — or any health data — for advertising or marketing, and we never disclose it to third parties. Health data is used solely to provide the app's features to you.

4. Backups are yours

You can export your ledger as a single encrypted backup file protected by a password you choose. Where you keep that file — your own cloud storage, email, a USB stick — is your decision, and the file is unreadable without your password. We never receive it. Because backups are yours, we also cannot recover them: if you lose both the file's password and your device, we cannot restore your data.

5. Crash reports

The Locket app includes one piece of third-party diagnostic software: Sentry, our crash-reporting service. If the app crashes or hits a serious error, Sentry receives a report of technical facts: device model, OS and app version, and where in the code the failure happened. We use these reports for one purpose — finding and fixing bugs. Reports are configured to never include your entries, your encryption key, or any health data. The app strips rather than gathers: no user identifier is attached, and every navigation breadcrumb is discarded before a report is sent — the trail of screens you visited could otherwise imply what you were logging. Sentry is also configured not to store the IP address your device connects from, so a crash does not tell us your location. Sentry processes these reports as our service provider and may not use them for anything else. In App Store terms, this is "Diagnostics" data, not linked to your identity — there is still no account to link it to.

Beyond that, nothing: the app contains no analytics and no advertising software. It does not track you across other apps or websites, does not read your device's advertising identifier, and will never show Apple's App Tracking Transparency prompt — crash reports are not used to track anyone, so there is nothing to ask permission for. The only other way the app reaches the network today is links you deliberately tap (for example, help articles from Clue or Flo, which open in your browser and are governed by those sites' policies); see Section 2 for the two designed exceptions and their status.

Of Apple's system frameworks, Locket uses HealthKit (read-only, Section 3), the Keychain (key storage, Section 1), and Face ID / Touch ID (the optional app lock). It uses no iCloud sync, no push notifications, no location services, no Sign in with Apple, and no in-app purchases. Separately, if you have enabled "Share With App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements, or install a beta through TestFlight, Apple may also collect crash reports under Apple's own privacy policy and show us the anonymized result. That is an iOS feature you control, not something Locket adds.

6. The website and the waitlist

lockethealth.com is a static site. Fonts and every other asset are served from our own domain, and — like any website — the hosting provider that serves these pages sees your IP address in its standard server logs; we do not use those logs to identify or profile visitors. Three things to know:

7. How long anything is kept

8. Your choices and rights

9. Consumer health data notice

This section serves as our consumer health data privacy policy under Washington's My Health My Data Act, Nevada's SB 370, and similar consumer health data laws.

10. Children

Locket is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us an email address, contact us and we will delete it.

11. Where Locket is offered

Locket and this website are directed to people in the United States. If you visit from the EU, UK, or elsewhere, the only personal data we could receive is a waitlist email you choose to send — handled as Section 6 describes: used for one purpose, on the basis of your consent, kept no longer than Section 7 says, never transferred to anyone else, and deleted on request. The website's analytics keeps nothing that identifies you (Section 6). If Locket becomes available in your region, this policy will be updated with the disclosures your local law requires before launch there.

12. Security and breach notification

Security measures are described throughout this policy because they are the product: on-device AES-256-GCM encryption, OS-protected key storage, a fail-closed data layer, and servers that hold no readable personal data. In the unlikely event of a breach of data we or our service providers hold (waitlist email addresses, crash diagnostics) or a security failure affecting the app, we will notify affected people and regulators as applicable law requires, including the FTC Health Breach Notification Rule where it applies.

13. Changes to this policy

We will post changes here with a new effective date. For material changes, we will provide notice in the app or by email to the waitlist. We will never change what the architecture makes impossible without telling you first — a new version of the app that transmitted different data would say so plainly before you install it.

14. Contact

support@lockethealth.com · Chao-Wei Tsang