Legal
Consumer Health Data Privacy Policy
Effective date: · Applies to the app “Takt — Zyklus & Periode” and to the website taktcycle.com
This English version is the authoritative one. A German translation is available at Datenschutzerklärung für Gesundheitsdaten (USA).
The essentials in five lines
- Takt has no server.
- We cannot see your entries, and we have no technical route to them.
- The app does not know who you are.
- We share consumer health data with no one.
- We do not sell consumer health data, and we never have.
The full text below is the authoritative one; these five lines are a selection from it and do not replace it.
Why this is a separate document
Washington’s My Health My Data Act (MHMDA), Nevada SB 370 and California’s Confidentiality of Medical Information Act as amended by AB 254 each require a distinct consumer health data privacy policy, linked from the homepage, from anyone who collects or processes consumer health data. None of the three has a revenue threshold or a user-count threshold. All three apply from the first user, and their definitions of “collect” and “process” reach processing that happens entirely on your own phone. So this document exists even though nothing you enter into Takt ever reaches us.
Virginia is a fourth angle, and a different kind. Its Consumer Protection Act, as amended by SB 754 (effective July 1, 2025; Va. Code § 59.1-200(85)), does not require a separate policy the way the three above do. Instead it forbids collecting or sharing “reproductive or sexual health information” without the consumer’s consent — with no threshold, and with a private right of action (§ 59.1-204). Cycle, fertility and pregnancy data fall squarely within it. Takt records this data only on your own device, with your consent, and shares it with no one, so the prohibition is met by the architecture rather than by a promise. This document speaks to Virginia residents as well; section 8 says what it means for you.
Our general Privacy Policy describes the same product under European law. It does not replace this one, and the two do not contradict each other. Where they describe the same fact, they say the same thing.
1. The short version
Takt has no server. Everything you enter — bleeding, temperature, cervical mucus, symptoms, notes — is stored encrypted on your device and is not transmitted to us or to anyone else. There is no account, no login, no sync, no analytics, no advertising code and no crash reporting. We cannot see your entries, and we have no technical route to them.
You can check this instead of believing it. Put the phone in airplane mode. Takt keeps working — entering, calculating, the analysis, the doctor’s report. Only buying or restoring a subscription needs a connection, because that runs through the App Store or Google Play.
We do not sell consumer health data, and we do not share it with anyone. Sections 5 and 6 explain why that is a fact about the architecture and not a promise about our intentions.
2. Categories of consumer health data we collect
“Collect” here follows the state statutes, not the app-store definition: it covers data that Takt records, stores, computes with, or displays, even when all of that happens on your device and nothing is transmitted. Every category below is stored only on your device.
Nothing in this list is mandatory. Every field you leave empty stays empty; Takt does not fill in or estimate anything. The signs marked optional are switched off when you install the app.
| Category | What Takt records |
|---|---|
| Menstruation and bleeding | none · spotting · light · medium · heavy, per day |
| Basal body temperature | 35.0–40.0 °C, in steps of 0.05 |
| Cervical mucus | dry · creamy · watery · stretchy |
| Cervix | three-step (optional, off by default) |
| Resting pulse | 40–160 bpm (optional, off by default) |
| Intercourse | a single yes for that day (optional, off by default) — there is no protected/unprotected distinction |
| Symptoms | multiple choice from 15 predefined symptoms: cramps · fatigue · bloating · mood swings · breast tenderness · headache · food cravings · back pain · skin problems · nausea · sleep problems · abdominal pain · digestive problems · hot flushes · night sweats |
| Day-level severity for two symptoms | mild · moderate · severe — only for hot flushes and night sweats, and voluntary there as well |
| Free-text note | whatever you write; you decide what goes in, so it may contain anything |
| Year of birth | the year only, never a full date; optional, asked once |
| Settings and calculated results | which signs you track, your cycle presets, your reminders, interface language, whether the app lock is on — and everything Takt computes from your entries: cycle day, phase, retrospectively confirmed ovulation, forecast window, cycle statistics, the doctor’s report |
| Life path events | events and periods you set yourself: pill or ring · IUD · pregnancy (including how it ended: with a birth, or earlier) · breastfeeding · illness · medication · operation · therapy · diet or weight · sport · relationship · job · move · a hard time · a good time · holiday · anything else in your own words — each with a day or a period, how sure you are of the date, an optional note and your own reading of it ("rather good" / "rather hard") |
| Doctor's visits | appointments (date, time, the practice name you type), your reason in one sentence, your topics for the consultation, a note about the visit, items you pay for yourself (service and amount), and a note for the report if you choose to pass one on |
| Values you import yourself | entries from a cycle app you switch from — the same categories as above, from a different source (section 4). You enter temperature and resting pulse yourself; Apple Health is not a source (section 4) |
Why each of these counts. Bleeding, cervical mucus, cervix and intercourse are reproductive and sexual health information, and menstruation is named in all three statutes. Basal body temperature and resting pulse are bodily functions and vital signs. Symptoms and their day-level severity are symptoms. The free-text note, the year of birth and everything Takt derives from your entries fall under the catch-all the statutes use for information that is derived, extrapolated or inferred, or that is used to associate a person with the categories above. Three of these deserve a paragraph of their own.
Menopause and hormonal transition
Takt does not measure hormone levels and makes no statement about them. It records what you enter. But hot flushes and night sweats are commonly read as signs of a hormonal transition, and California’s CMIA expressly lists “hormone levels” among the information it protects. We therefore treat these entries — and the day-level severity that belongs to them — as consumer health data and name them here, rather than argue about where the boundary runs. Takt forms no score from the severity, applies no threshold to it, and draws no conclusion about your stage of life. The value stays the value you entered.
Year of birth
Washington’s MHMDA does not list age as a category of its own, but it does have a catch-all: information used to associate or identify a consumer with the listed health categories, including data that is derived, extrapolated, inferred or algorithmic, is consumer health data. Your year of birth becomes exactly that the moment Takt uses it — and it uses it for one purpose only: the clinical normal range for cycle variation depends on age, so without it the doctor’s report applies the more permissive threshold. Takt asks for it where the doctor’s report is put together, not at first launch, and leaving it unanswered is a full answer. You can add or remove it at any time in the cycle settings.
Pregnancy and postpartum
Takt has no pregnancy mode: it does not ask whether you are pregnant, it does not follow a pregnancy week by week, and it offers no postpartum programme. What you can record yourself is an event on your life path — a pregnancy, including how it ended (with a birth, or earlier), breastfeeding, an illness, a medication, an operation, a therapy. Takt never distinguishes between a miscarriage and a termination, and it stores no such distinction. We name the category here because California’s CMIA expressly covers “pregnancy outcome”, and because you should be able to see what is there as plainly as what is absent. These entries sit in the same encrypted block on your device as everything else, and they leave it only if you share a file yourself. If Takt ever gains a mode that follows a pregnancy week by week, this policy will say so before that mode ships.
What Takt never asks for
Your name, your email address, your full date of birth, your location, your contacts, your phone number, a device identifier or an advertising identifier. There is no account and no registration. The app does not know who you are. It records no genetic data, no biometric identifiers and no gender identity. An illness, a medication or a treatment you can set as an event on your life path; Takt does not read it, does not link it to anything and does not evaluate it.
3. Purposes
Every purpose below is served on your device. None of them involves transmitting anything.
| Category | Purpose |
|---|---|
| Bleeding | Determining where a cycle begins and ends, cycle length, period length, and showing your entries back to you |
| Basal body temperature | Retrospective ovulation confirmation by the symptothermal method (coverline, three-over-six rule), the temperature curve, the doctor’s report |
| Cervical mucus | Second sign for the double confirmation of an ovulation that has already happened; determining the fertile window |
| Cervix, resting pulse | Additional signs you can switch on; shown back to you, used in the analysis |
| Intercourse | Recorded only. It is never rated, and it enters no calculation. It appears only in a retrospective view that names the position of a day relative to a confirmed ovulation |
| Symptoms | Showing them back to you over time, and the symptom-and-phase patterns in the analysis |
| Day-level severity (hot flushes, night sweats) | Making a course over months legible where a bare yes stops saying anything. No score, no threshold, no assessment |
| Free-text note | Showing it back to you |
| Year of birth | One purpose: choosing the age-correct clinical normal range for cycle variation in the doctor’s report |
| Settings | Running the app the way you set it up, and scheduling local reminders on your device |
| Calculated results | The forecast window, the analysis, the statistics and the doctor’s report — all computed on the device, rule-based and documented |
We do not use any of this data for advertising, marketing, profiling, scoring, market research, product analytics, or to train any model. That is not a policy we could quietly change: there is no transmission and no copy anywhere else, so there is nothing to use.
4. Sources
There are exactly two, and you open both of them yourself.
- You. Almost everything comes from what you enter in the app — temperature and resting pulse included. Both are signs of their own, with their own entry.
- A file you import. If you switch from another cycle app, Takt can read an export file you supply — from Clue (including password-protected archives), Flo, drip, Natural Cycles, a Takt backup, or a generic CSV table. You choose the file; nothing is fetched from anywhere. Imported values land in the same encrypted block on your device as everything else.
Apple Health and Health Connect are not a source at all. No system permission, no permission dialog, no ongoing access, no import — and no file route either: the one that existed until 31 Aug 2026 has been removed.
We receive consumer health data from no other source. No data brokers, no advertising networks, no partners, no public records, no other apps. We receive nothing at all, because there is nowhere for anything to arrive.
5. Categories of third parties with whom we share consumer health data: none
We share consumer health data with no one. Not with affiliates, not with processors, not with service providers, not with advertising or analytics partners, not with data brokers, and not in anonymised or aggregated form.
This is a statement about the architecture, and it can be checked:
- There is no server of ours. Takt has no backend. There is no place at our end for data to arrive.
- The app works without a network. In airplane mode, everything except the store purchase keeps working. An app that is fully functional offline is not sending anything.
- There is no third-party code that could send anything. No analytics or statistics tools (no Google Analytics, no Firebase, no Matomo), no crash reporting (no Crashlytics, no Sentry), no advertising SDK, no advertising ID, no cross-app tracking, and no third-party subscription service (no RevenueCat, no Adapty). Subscriptions run through the store interfaces alone.
- We have no key. The data is encrypted by the operating system with a key that does not leave the device (section 7).
Two things we will not leave unsaid.
Files you share yourself. Takt can produce a full backup (JSON), a table (CSV) and a doctor’s report (PDF), all generated on the device. As soon as you pass such a file to your operating system’s share sheet, it leaves your device, and where it goes is your choice: an email goes through your email provider, a cloud upload sits with that cloud provider. Those destinations have their own privacy terms. We are not involved and learn nothing about it. A cycle export is a health document; it deserves the care you would give a letter from your doctor.
The stores. Apple and Google know that you downloaded and paid for Takt. That is the one data trail an app without a server still produces, and we cannot take it away from you. It says nothing about your cycle, because no store reaches that far. It is purchase data, not consumer health data — but it exists, and we would rather name it than pretend otherwise.
6. We do not sell consumer health data
We do not sell consumer health data, and we never have. There is no exchange of your entries for money or for any other valuable consideration, in any form.
MHMDA does not permit a company to sell consumer health data on the strength of a privacy policy. It requires a separate, written authorization, signed by you, distinct from any consent to collect or share, with a defined content and an expiry. Nevada SB 370 works the same way. We will never ask you for such an authorization, because there is no sale to authorize. If that were ever to change, it could not happen quietly: it would take a signed document from you, and this policy would say so first.
For the same reason, no one has to “opt out” of a sale here. There is nothing to opt out of.
7. Where the data actually lives
All entries sit in a single encrypted block in your operating system’s key store — the iOS Keychain on iPhones, the Android Keystore on Android devices. The encryption is performed by the operating system with a key that does not leave the device and that we have no access to.
Takt keeps no unencrypted copy anywhere — with one exception, and only if you create it yourself: what a Takt widget has to draw on your home screen. A widget cannot look inside the encrypted block; what it displays has to sit readable next to it. How much that is, you decide twice — when you place it (ring only, or ring with text) and at any time in the app’s More section, under the app group, at the widget entry (More → App → Widget). At the quietest setting what sits there is a ring without a date, exactly as every fresh installation shows it. None of it is transmitted anywhere, and deleting all data removes it too (section 8). If you place no widget, this store does not come into existence.
Takt keeps itself out of the device backup. Without that, an operating system would carry the encrypted block into your Apple or Google account backup — not to us, but to a second location all the same. Takt counteracts this in four ways at once:
- iOS: the key store entry is bound to this one device; even from a backup it cannot be restored on any other device.
- iOS: in addition, Takt’s files are excluded from the backup at file level.
- Android: the app is excluded from the device backup.
- Android: a separate rules file additionally excludes the direct device-to-device transfer, which the first setting no longer covers on its own on newer systems.
So that this state cannot be lost unnoticed, an automated test checks it on every change to the program: if one of the four falls away, the test fails before a new version can be built. This matters for the risk this policy is about. The narrower the set of places your entries exist, the smaller the surface for unauthorised access — and here that set is one device, with no copy at our end, and no backup carries your entries to another device.
The flip side, said plainly: the block on your device is the only copy of your history. A device backup will not carry it to a new phone. If you delete the app, it is gone — and we cannot restore it, because we never had it. Make a backup file first if your history matters to you.
Two further protections are built in:
- Protection mode: if Takt cannot read the stored block at startup, the app blocks all writing and does not overwrite what is there. No input is better than lost data.
-
App lock (optional, off by default): Face ID, Touch ID, other biometrics, or
your device passcode. The check is performed by the operating system; Takt only learns
“succeeded” or “did not succeed” and stores no biometric features itself. On Android,
FLAG_SECUREadditionally prevents a preview in the app switcher.
No location, and no geofencing. Takt does not request location access at all. It therefore cannot and does not operate a geofence around any health care facility, clinic, pharmacy or provider, and it collects no location data from which such a thing could be built.
8. Your rights, and the concrete way to exercise them
Under MHMDA and Nevada SB 370 you have the right to confirm whether we collect, share or sell your consumer health data and to access that data, the right to delete it, and the right to withdraw your consent to its collection and sharing.
For your cycle data, these rights run against us into a void — not because we refuse them, but because we do not have the data. Information from us about your entries would be empty information. So you exercise them in the app itself, immediately and without an application to anyone:
- Confirm and access → in the app’s More section, under the data group, choose the backup entry — labelled “Back up your data”. The JSON backup is complete and machine-readable; the CSV table opens in any spreadsheet. It takes seconds.
- Correct → change any entry at any time in the day editor.
- Delete, individually → delete single entries in the app.
- Delete, completely → at the bottom of the More screen, below all groups — labelled “Delete all data”. This removes your entries, all settings, the main encrypted block, any block that was set aside after a read error, and the widget images. Uninstalling the app removes the encrypted block as well.
- Withdraw consent → in the app’s More section, under the legal group — labelled “Manage consent”. Withdrawal takes effect going forward. Your already-stored entries stay unchanged on your device until you delete them yourself — we cannot touch them.
If you would rather send us a request. Write to the address in section 10. You do not have to give a reason, and it costs nothing.
- We answer within 45 days of receiving your request.
- Where it is reasonably necessary, we may extend that period once by a further 45 days. If we do, we will tell you within the first 45 days, and why.
- To answer a request about a specific person we would have to be able to identify that person. We cannot — there is no account and no identifier. In practice, our answer will confirm that we hold no consumer health data about you, and it will point you to the paths above, which give you more, faster, than we could.
If we refuse a request, we will tell you why, and you can appeal. Send your appeal to the same address, marked as an appeal. We will decide within a reasonable period and tell you in writing how we decided and on what grounds. If we deny the appeal, you may lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint, or with the attorney general of your own state.
Residents of California and Nevada have equivalent rights under the statutes named at the top of this document and exercise them the same way.
Virginia works differently. SB 754 (Va. Code § 59.1-200(85)) does not set up a rights-request process; it forbids collecting or sharing your reproductive or sexual health information without your consent and gives you a private right of action if that is breached (§ 59.1-204). Because Takt holds this data only on your device, with your consent, and shares it with no one, there is nothing here to act against — but the right stands, and it runs against anyone who does otherwise.
9. Why this document exists although the app stores show “Data Not Collected”
Takt’s privacy label in the App Store and on Google Play says that no data is collected. That is correct: both stores define “collect” as data that leaves the device and reaches the developer, and nothing does.
The state statutes define it differently. Under MHMDA and its counterparts, collecting and processing include recording, storing and computing on the device itself — the definition was written that way deliberately, so that a local-only architecture would not become a way around the rules. Both statements are true at once, and they answer different questions. The store label says nothing reaches us. This document says what happens on your phone, and what your rights are in respect of it.
10. Contact
TRAJA Projects
Owner: Bao Anh Tran
Sulzbacher Straße 48
90489 Nürnberg
Germany
Email: traja.projects@gmail.com
Please write in English or German. Please do not send us health data unless it is unavoidable — for a support request we do not need it. Describe the problem, not your cycle.
11. Changes to this policy
We update this policy when the app or the law changes. The version published on this page is the one that applies; the effective date at the top shows its state. If something material changes about how your data is handled, we say so in the app rather than quietly on a subpage. In particular, this policy will be extended before any new category of health data — a postpartum module, for instance — is collected for the first time.
For completeness: Takt is not a medical device and does not replace medical advice.