Privacy Policy
This policy explains what personal information Verity collects, why we use it, who we share it with, how long we keep it, and the rights you have.
We have written it in plain English so you can read it once and know where you stand. Short legal names (POPIA, GDPR) appear where they help a regulator. They do not change the plain meaning.
Verity is a hormonal-health companion for women aged 18 and over. Tagline: Your body’s truth, in your hands. The app is not a medical device. It does not diagnose, prescribe, or give medication doses.
This policy covers:
- the Verity app for iOS (bundle id
com.veritywomen.app) and Android (packageapp.verity.mobile); and - the website https://veritywomen.com.
1. Who we are
Verity is operated by its founders, Pierre van Rooyen and Elvera Van Rooyen, as an unincorporated venture. There is no company registration number yet. If we register a company, we will update this policy with the entity name and number.
For data-protection law they are the responsible party (South Africa’s Protection of Personal Information Act, 2013 — POPIA) and the controller (the EU/UK GDPR, where it applies): the people who decide why and how your information is used. They trade as Verity.
Information Officer: Elvera Van Rooyen (Information Regulator registration 2026-065680) Privacy: privacy@veritywomen.com Support: support@veritywomen.com Website: https://veritywomen.com This policy: https://veritywomen.com/privacy Terms of Service: https://veritywomen.com/terms
A postal street address is available on request from privacy@veritywomen.com.
2. What we collect
Most of what Verity holds is health information. The law treats that as especially sensitive — “special personal information” under POPIA, and “special-category data” under the GDPR. We only collect it if you choose to use Verity and give the consents described in section 3.
You can use Verity without an account. Then your record stays on that phone. An account is optional. It is how we keep a copy of some of your record if the phone is lost, and it is required to invite a support person or to ask live Ask Vera in your own words.
Account (only if you create one)
- Email address.
- A password. We store a one-way hash of the password, not the password itself. We cannot read it back.
- If you sign in with Google, Google confirms who you are. We receive a token, your email, and a Google user id. We do not receive your Google contacts, Drive, photos, or search history.
- If you sign in with Apple on iPhone, Apple confirms who you are. We receive an identity token. We receive your email only if you choose to share it (Apple may give us a Hide My Email relay address). The first time you authorise Verity, Apple may also send a name. We do not receive your Apple contacts, iCloud files, photos, or payment details.
- Sign in with Apple is not a working login on Android. On Android the button says it is not ready; a tap does not send anything to Apple.
Profile
What you tell us about yourself in the app, for example:
- display name;
- age or date of birth;
- life stage (for example, regular cycles, perimenopause, menopause, postmenopause);
- whether you are on HRT;
- the concerns you pick during set-up.
An optional profile photo stays on that phone. We store a file name in your profile so the app can show it. We do not copy the photo into our cloud backup.
Health and cycle logs
What you choose to log, for example:
- cycle entries (period days, flow, spotting);
- symptoms — including mood, mental-health, sexual and intimate-health symptoms — and how strong they felt;
- energy and sleep;
- food and exercise;
- free-text notes you type.
HRT
Hormone-therapy type, how you take it, dose, brand, start date, changes, and how you said you felt.
Health-background survey
Longer “health background” answers (the in-app health-profile survey) stay on that phone. They are not copied into your cloud account.
Documents
Letters, scans and similar files you add in Verity stay on that phone. There is no documents upload to our servers.
Doctor report
You can build a PDF to take to a clinician. That file is created on your phone. If you share it (email, messaging, files), it leaves through the app you choose, under that app’s rules. We do not receive a copy of the share.
Support-person mode
If you invite someone:
- a one-time invite code (it lasts about three days);
- the link between your accounts;
- the categories you have turned on for them, if any;
- notes they write about how you seemed.
They see nothing of yours until you opt in, category by category. The categories you can share are: symptoms, sleep and energy, cycle, and HRT. Vera chats, the health-background survey, and documents cannot be shared. There is no switch for those.
If you are the support person, we store the notes you write about the person you support, and your own account details. You do not get their health record unless they turn a category on.
Vera — ready answers (Ask Vera)
Ask Vera’s ready answers are pre-written articles from a cited evidence library, served on your device. Reading them does not send the question to an AI model and does not need a network call for the answer. We do not collect the text of those taps as a health record.
Those articles are general educational information from cited sources. A clinician review is underway. They are not currently clinician-signed in the production app. They are not medical advice.
Vera — live Ask Vera (optional, uses an AI model)
Live Ask Vera is on. You type a question in your own words.
- The app sends the question to the Verity API on our server in the EU, which sends it to OpenRouter (a third-party AI service, typically on US infrastructure) so a language model can draft an answer. Ask Vera is not medical advice and is not a medical device.
- On that OpenRouter account we turn on Zero Data Retention and we block providers that train on prompts. Every live request also asks OpenRouter not to retain the prompt and not to use it for training. We do not have a signed data-processing agreement with OpenRouter. We do not claim HIPAA, a Business Associate Agreement, or that health data never leaves the phone.
- Sent with the question, so the answer can fit you: age, life stage, HRT status, recent symptoms, and how you have been eating. Not your name or email.
- Extra consent ticks appear before your first live question. You must agree that Vera is AI, not a doctor, and that the question is sent to our AI provider.
- You need an account. There is a monthly allowance: 15 live questions a calendar month. There is no paid plan and no in-app purchase.
- Crisis, dose, or otherwise unsafe questions are stopped on our server. They never reach the model, are not stored as a conversation, and do not use up a question.
- If the live call fails, you see an honest “unavailable” message. The app must not invent a fake health answer.
What we log on the server about live use: a user id and an outcome code (for example, that an answer was given, or that a question was blocked). Never the question text, the answer text, or the API key, in those logs.
Where the conversation itself lives:
- Without an account, any on-device demo chat stays on that phone.
- The one-time cloud backup when you first sign in copies logs, HRT and profile. It does not copy documents, the health-background survey, or Vera chats that were already on the phone.
- If you use live Ask Vera while signed in, we keep that conversation with your account on our EU server so it can show again in the app. Deleting your account deletes it.
Live answers are AI-generated and can be wrong. They are not clinician-reviewed.
Consent records
Which boxes you ticked, the consent version shown (currently 1.1), and the time. None of the onboarding boxes is pre-ticked. The four onboarding consents are:
1. storing your health data on your device and in the cloud; 2. that Vera is an AI companion, not a medical professional; 3. the Privacy Policy and Terms of Service; 4. that you are 18 or older.
Live Ask Vera has its own extra ticks, stored with a separate version stamp, before the first live question.
If you join as a support person, you tick the same four kinds of box. The health-data box is about notes you write about the person you support, not about your own hormones.
Technical data
To run the app we necessarily see ordinary connection information: that a signed-in request reached our server, roughly when, from an IP address, and which account the sign-in belongs to. We do not collect advertising identifiers. We do not embed advertising or social-media tracking SDKs. We do not currently use a separate crash-reporting company (for example Sentry or Crashlytics).
If you turn on Help improve Verity (Settings → Privacy & data; it starts off), we record technical usage: that the app opened, and which screen names you visited. A copy of those events can live on our EU server. We also send that same kind of technical usage to Google Analytics (Firebase). Neither copy includes health logs, HRT details, symptoms, chat, or your email. Developer copies of the app are not sent to Google. You can turn the switch off at any time.
On the website (veritywomen.com), we use Google Analytics to understand which pages people open and how the site is used. Google receives ordinary visit data (for example IP address used to estimate location, device and browser type, and pages viewed). That is technical visit data for the marketing site. It is not your in-app health record.
Reminders
If you turn reminders on (morning or evening check-in, or an HRT check-in a few weeks after a change), they are scheduled on your phone. We do not currently send those reminders through a separate push server. The app uses Expo’s notifications library to talk to your phone’s own reminder system.
Website
If you visit veritywomen.com or join a waitlist, we may keep the email address you type so we can write to you, and we send a confirmation email. You can ask us to delete that address.
What we do not do
- We do not sell your data.
- We do not share it with advertisers or ad networks.
- We do not use your health data to target ads.
- We do not put a provider API key or model id in the app.
- We do not claim HIPAA, a Business Associate Agreement, or a signed data-processing agreement with OpenRouter.
3. Why we use your data
| What we do | Why, in plain language | Legal basis |
|---|---|---|
| Store what you log, show trends, and build your doctor report | That is the app you asked for | Health data: your explicit consent (POPIA s 27(1)(a); GDPR Art. 9(2)(a) where it applies). Account and similar non-health details: performing our contract with you (GDPR Art. 6(1)(b) where it applies). |
| Keep a cloud copy of logs, HRT and profile if you create an account | So a lost phone does not take the whole record | Same consents; you can stay local-only instead |
| Serve Vera’s curated Q&A on the device | General educational information you chose to open | Your consent; the answer itself does not leave the phone |
| Send a live question to an AI provider | So Vera can answer in your own words | Extra explicit consent before the first live question |
| Support-person notes and optional shared categories | So someone you trust can notice what you asked them to see | Your opt-in per category, and their consent to store notes about you |
| Password-reset and similar service emails | So you can get back into the account | Contract / your request |
| Record technical app use if you turn on Help improve Verity | So we can see which screens people open — not to read your health record | Your consent (that switch). You can turn it off any time |
| Keep the service running, fix bugs, stop abuse | So the app stays up and other people’s records stay theirs | Legitimate interests in running a secure service (GDPR Art. 6(1)(f); POPIA s 11), balanced against your rights |
| Meet the law | For example, a regulator request we are required to answer | Legal obligation |
You can withdraw consent at any time by stopping use, turning a support-person category off, not using live Ask Vera, turning Help improve Verity off in Settings → Privacy & data, or deleting your account (section 7). Withdrawal does not undo work already done lawfully. Some parts of the app will stop working without consent — that is the honest result, not a punishment. Turning the analytics switch off does not stop the rest of the app working.
We do not use your information for a new purpose that would surprise you. If that ever changes, we will ask again.
4. Who we share data with
We do not sell your information. We do not give it to advertisers.
We share it only with the people and companies needed to run Verity, and only as much as that job requires.
Named companies and systems today:
| Who | What they do | Where |
|---|---|---|
| Contabo | Hosts the Verity API and database on a VPS | Lauterbourg, France (EU) |
| MongoDB Community, which we operate | The database software on that same VPS. We do not use MongoDB Atlas. MongoDB the company does not receive your data as a cloud customer of theirs | Same server in France |
| OpenRouter | Writes live Ask Vera answers. Receives the question and the small profile context above — only if you use live Ask Vera and have given the extra consent. Our OpenRouter account has Zero Data Retention on and training off. No signed data-processing agreement. | Typically United States infrastructure; may process outside South Africa and the EU |
| Resend | Sends password-reset and other transactional email (for example a waitlist confirmation) | Email delivery; Resend is a US company with EU sending options |
| Sign-in, only if you tap Continue with Google | Google’s infrastructure, under Google’s terms | |
| Google Analytics (website) | Measures visits to veritywomen.com: pages viewed, approximate location from IP, device and browser. Does not receive health logs, HRT details, chat, or in-app account data | Google’s infrastructure; typically United States |
| Google Analytics / Firebase (app) | If you turn on Help improve Verity, measures technical app use: that the app opened, which screen names you visited, and similar engagement. Does not receive health logs, HRT details, symptoms, chat, or your email. Developer copies of the app are not sent | Google’s infrastructure; typically United States |
| Apple | Sign-in, only if you tap Continue with Apple on iPhone. We receive an identity token; an email only if you share one (Apple may give a Hide My Email relay address); a name only on the first authorisation. | Apple’s infrastructure, under Apple’s terms |
| Expo | The notifications library on your phone. If we later use Expo’s push service to deliver a reminder you have opted into, Expo would see a device token, not your health logs | Device, and Expo if push is used |
If you join the waitlist on the website, a Cloudflare worker stores the email so we can write to you. That is only the waitlist address, not your in-app health record. Separately, Google Analytics records ordinary page-visit data on the website (see the table above).
Support person. If you invite one, they see only what you have turned on, plus the notes they write. That is sharing you chose.
Authorities. We will share information if the law requires it, or to protect someone’s vital interests in an emergency.
A buyer of the venture. If Verity is later transferred to a registered company or a buyer, your information would move with the service, still under this policy or a replacement we will show you. We will not treat that as a chance to start selling data.
We do not keep a separate “subprocessors” web page. The list above is the list.
International transfers
Your phone may be in South Africa, the EU, the UK, the US, or elsewhere. Our server is in France.
- Creating an account stores the backed-up record in France. If you live outside the EU, that is an international transfer. You consent to it when you agree to this policy and create an account. We also have a written hosting contract with Contabo.
- A live Ask Vera question may be processed by OpenRouter outside South Africa and the EU (often the United States). You agree to that in the extra ticks before the first live question. We rely on that consent, on OpenRouter’s account terms, and on the Zero Data Retention and no-training settings on that account. We do not have a signed data-processing agreement or EU Standard Contractual Clauses with OpenRouter.
- Google Analytics (website visits, and app technical usage if you turn on Help improve Verity) is typically processed in the United States. You agree to the app part when you turn that switch on. Website measurement is the marketing site only.
5. How long we keep data
- Account, profile, logs, HRT, support-person link and notes, live Vera conversations we store for a signed-in account, and the live-use ledger (user id + outcome only): kept while the account is active. Deleted when you delete the account (section 7).
- Consent records: kept with the account so we can show what you agreed to. They are deleted with the account today.
- Health-background survey, documents, and profile photo: on the phone, until you delete them in the app, delete the account (which also clears the on-device store), or uninstall. Uninstalling does not by itself delete a cloud account.
- Local-only use (no account): on that phone only, until you delete it in the app or uninstall.
- Invite codes: about three days, or until used or cancelled.
- Password-reset codes: short-lived; they die if you change the password, wipe data, or delete the account.
- Waitlist email: until you unsubscribe or ask us to delete it.
- Ordinary technical logs (for example that a request reached the server): only as long as we need them to run and protect the service.
- Technical app-usage events (Help improve Verity): the copy on our EU server is kept only as long as we need it to see whether the app is working. The copy sent to Google Analytics is kept by Google for the retention period set on that property (we keep it as short as the product allows). Turning the switch off stops new events. It does not erase what Google already received. You can ask us at privacy@veritywomen.com.
We complete an account deletion well within 30 days, and usually at once.
Phone backups (iCloud, Google backup, and the like) are outside Verity. They may keep a copy under that provider’s rules until that backup ages out.
6. Your rights
You have rights over your information. How they are named depends on where you live. In practice you can:
- Access what we hold (POPIA s 23; GDPR Art. 15).
- Correct what is wrong (POPIA s 24; GDPR Art. 16). Most fields in Verity can be edited in the app.
- Delete (section 7; GDPR Art. 17; POPIA s 24).
- Get a copy — Verity has a JSON export in Settings → Privacy & data (GDPR Art. 20 portability).
- Object or restrict certain uses (GDPR Arts. 18 and 21), and withdraw consent.
- Complain to a regulator.
South Africa — Information Regulator Website: https://inforegulator.org.za POPIA complaints: POPIAComplaints@inforegulator.org.za Enquiries: enquiries@inforegulator.org.za Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Toll-free: 0800 017 160
If you are in the EEA or UK, you can also complain to your local data-protection authority (in the UK, the ICO). GDPR applies to us where the law says it does — for example if we offer the app to people in the EEA/UK. We honour the rights above; this policy is not a claim that we have a separate EU office.
United States. We do not sell personal information or health data, and we do not share it for advertising. US state laws differ (for example California’s CPRA). We do not claim a full US-state privacy programme. If you have a request, email privacy@veritywomen.com and we will help.
You do not have to pay to use these rights. We may need to confirm it is you. We will answer as soon as we reasonably can.
7. Deleting your account and data
In the app: Settings → Privacy & data. Type DELETE to confirm.
That hard-deletes your data from our systems. It is not a “deactivate” that we can undo. It removes your authentication record, your rows on our server, and the Verity store on that phone.
We complete this well within 30 days, and usually immediately.
We do not currently keep a hashed “deletion receipt.” We delete the account and the data. If the law requires a minimal proof that a deletion happened, we may later keep a de-identified timestamp (a date, with no name and no health data). We do not do that today.
Support-person notes
- If you end the link, notes already written about you stay in your record. You can delete a note. You cannot edit someone else’s note.
- If you delete your account, notes about you go with your record.
- If a support person deletes their account, the notes they wrote about you are removed from your record too. The app tells them that before they confirm.
Signing out is not deletion. Your cloud copy stays until you delete the account.
8. Data on your device
Verity keeps a copy of your record on the phone so the app works offline and feels fast.
That copy sits in Verity’s own storage area. Your phone’s operating system keeps other apps out of it. We do not add a separate layer of encryption on top of that store today (the on-device store is MMKV, with no extra encryption key).
What an account actually backs up: logs, HRT record, and profile. Documents, the health-background survey, and Vera chats already on the phone are not part of that backup. Live Ask Vera conversations you have while signed in are stored with the account as described in section 2.
Deleting the app removes local data. A device backup may still hold a copy. Use the in-app delete if you also need the server copy gone.
If you would rather nothing left the phone at all, use Verity without an account. Then we do not hold a cloud copy. You cannot invite a support person or use live Ask Vera that way.
9. Children
Verity is for adults aged 18 and older. We do not knowingly collect information from anyone under 18. The onboarding gate asks you to confirm you are 18+. If we learn we have data about a child, we delete it.
10. Security
What is true, stated plainly:
- Traffic between the app and our API travels over HTTPS, so it cannot be read on the way.
- Cloud data requires sign-in.
- The API checks every request against your account, so one account is not served another person’s record.
- The database sits on our VPS in France and is not meant to be open to the public internet.
- We do not add extra encryption at rest on the server (MongoDB Community, no disk encryption).
- We do not add extra encryption on the phone store, beyond the phone’s own app sandbox.
Once data is on the server, people who look after that server can reach what is on it. We do not claim the record is “encrypted and stored privately.”
No system is perfectly secure. If a breach affects you, we will tell you and the relevant regulator, as the law requires (including POPIA’s notification duties and, where GDPR applies, the usual 72-hour regulator notice).
11. Changes and contact
We will update this policy as Verity changes. The date at the top is the latest version. For a material change we will tell you in the app or by email where we can, and ask for a new consent if the law requires it.
Questions or requests: privacy@veritywomen.com. App help: support@veritywomen.com.
A postal street address is available on request from privacy@veritywomen.com.