Safr logoSafr
Home Terms Support Download

Privacy Policy

Last updated: August 2, 2026

In short Safr is a period and cycle tracker. Most of your cycle and health data, your logs, answers, and settings, stays on your device. We never sell your health data or share it with ad networks. Optional analytics use a random device id (never your name or email) and never include your detailed logs. A few features (AI chat, optional photo analysis, and connecting Oura) send specific data to trusted services, only when you use them. You can export or delete your data at any time. The details are below.

This Privacy Policy explains how Grow Labs LLC (“Grow Labs,” “we,” “us,” or “our”) handles your information when you use the Safr mobile application and related services (the “Service”). By using Safr, you agree to the practices described here. For UK and EU data-protection law, Grow Labs LLC is the data controller.

1. Where your data lives

Safr is built to keep your sensitive information with you. The cycle and health data you log, your onboarding answers, and your settings are stored locally on your device. That data is not sent to our servers as part of normal use. Specific, clearly labeled features are the exceptions: AI chat, optional photo analysis, connecting Oura, and (if you opt in) pseudonymous analytics, and each is described below.

2. Information we collect

a. Information you provide (stored on your device)

  • Profile: your name (if you enter one), birth year, and cycle details such as cycle length, period length, cycle history, and last period start.
  • Cycle & health logs: period, intercourse, discharge, cervical-mucus, symptom, Plan B / emergency-contraception, LH-test, and pregnancy-test logs.
  • Onboarding answers: such as why you use Safr and your cycle-related preferences.
  • Support messages: what you send us when you contact support.
Special-category (health) data. Information about your cycle, intercourse, and reproductive health is sensitive personal data. Where UK/EU law applies, we process it on the basis of your explicit consent, which you can withdraw at any time by deleting the data or your account in the app.

b. Data from Oura (only if you connect it)

If you choose to connect Oura, you authorize Safr, through Oura's secure OAuth sign-in, to import overnight body-temperature data from the Oura cloud API. This is used to detect the temperature shift around ovulation and inform your cycle insights. Your Oura access tokens are stored in your device's secure keystore, and the token exchange is handled through our backend. Imported temperature is held with your other on-device data. You can disconnect Oura at any time from within Safr or from your Oura account; disconnecting clears the saved Oura tokens on your device and Safr stops importing new Oura data. To fully revoke Safr's access to your Oura account, you can also remove it at your Oura account (cloud.ouraring.com). Ōura Health Oy is based in the EU.

c. Apple Health (if you enable it)

If you grant access, Safr can read temperature data you have in Apple Health to support the same cycle insights. This stays on your device alongside your other data.

d. Usage analytics (only if you turn it on)

Analytics is off until you turn it on. If you do, Safr shares a limited, pseudonymous picture of how the app is used, grouped by a random device id, never your name or email. Here is the whole of it.

What we send

  • How you move through the app: screens you open, features you use, taps like opening a calendar day or changing a reminder or setting, and whether you add, edit, or delete an entry, but never the contents of what you log.
  • Whether you allowed or declined a system prompt (such as notifications, or Apple's App Tracking Transparency prompt for US users), and your onboarding progress.
  • The goals you pick for using Safr (you can choose more than one, such as fertility awareness, pregnancy risk estimation, or cervical mucus analysis) and your approximate age in years, never your date of birth or birth year.
  • App version and platform, a build tag so we can leave out our own test installs, and, for a subscription, whether it was a free trial plus the amount and currency.
  • Wearable actions, such as connecting or disconnecting Oura, its permission result, the wearable you chose, and tapping contact support. The imported Oura temperature itself is never sent.

What we never send

  • Your name or email, or the contents of anything you log.
  • Your other onboarding answers, such as worry frequency or the specific birth-control method you record for yourself.
  • Your cycle or period length, your pregnancy-risk estimates, or your period, intercourse, mucus, symptom, Plan B, or LH-test details.
  • Your chat and AI conversations, or your photos.

There is one extra, fully anonymous summary, sent when you finish onboarding. It pairs the goal you picked with a coarse category of how you currently prevent pregnancy (such as hormonal, barrier, behavioral, other, or none), so we can see, in aggregate, what people who come to Safr for each goal already use. It carries no name, email, device id, account, or IP-based location and creates no profile, so it cannot be linked back to you, and it never includes the specific method you record for yourself.

Goals, age, and that anonymous summary are recorded for adults only. For under-18s it depends on region: in the UK and EU/EEA Safr sends "unknown" for the goal and attaches no age (UK Children's Code), and elsewhere someone 16 or older who opted in is recorded. We never record any of this for anyone under 16. See Section 6.

e. Subscriptions and diagnostics

  • Subscriptions: purchases are processed by the Apple App Store (on iOS) or Google Play (on Android); we receive subscription status, not your full payment-card details.
  • Diagnostics: basic crash and performance information to keep the app working.

3. How we use your information

  • To provide Safr's core features, interpreting temperature trends and your logged cycle history to estimate fertile and non-fertile windows and produce personalized daily insights.
  • To power AI chat and optional photo analysis when you use them.
  • To operate, secure, maintain, debug, and improve the Service.
  • To process subscriptions and prevent fraud and abuse.
  • To provide support and respond to you.
  • To comply with legal obligations.

We do not sell your personal information or your health data, and we do not use your health data for advertising.

4. AI chat, photo analysis, and check-in features

If you use Safr's AI chat, your message and a summary of your Safr data (such as your cycle dates, logged symptoms, intercourse and Plan B entries, and your in-app risk estimate) are sent, through our backend, to OpenAI in the United States so the assistant can give you a personalized answer. If you use optional photo analysis (for example, cervical-mucus, LH-test, or pregnancy-test photos), the image you choose is sent the same way. The first time you use either feature, Safr asks for your explicit agreement before anything is sent, and if you don't agree, nothing is sent. We do not use these features to advertise to you or to sell your data. If you don't use these features, this data isn't sent.

The pregnancy check-in also uses AI in two places, under the health-data consent you give in onboarding. If you type a note during the check-in, that text and a short summary of related facts you logged are sent the same way (through our backend, to OpenAI) so the app can reflect back what you shared. And when you view your estimate, a compact summary of your cycle facts and check-in answers (never your typed notes or photos) is sent the same way to write the personal analysis shown under your number. These requests are not stored by Safr, and OpenAI does not train on them.

5. How we share information (our processors)

We share information only as needed to run Safr, with service providers acting on our behalf:

  • Ōura Health Oy (EU), source of the wearable temperature data you authorize.
  • OpenAI: powers AI chat, optional photo analysis, and the pregnancy check-in's reflection and estimate analysis (via our backend).
  • PostHog: pseudonymous product analytics, only if you opt in (Section 6).
  • Singular: ad measurement, US-only, for users 16+ who opted into usage data. Without Apple's tracking permission Singular acts only as our processor for anonymous, aggregate campaign reporting (Apple SKAdNetwork) and shares nothing user-level with ad networks; user-level attribution additionally requires you to allow Apple's tracking prompt on iOS (on Android it is on by default with an opt-out in Settings). Section 6.
  • Meta (Meta Platforms, Inc.): ad measurement, US-only, for users 16+ who opted into usage data. The two ad-measurement events (registration and subscription) are forwarded to Meta on our behalf by our measurement partner Singular; the app itself sends Meta nothing. Without Apple's tracking permission no advertising identifier is included and Meta's "Limited Data Use" restriction is applied, so the events serve only aggregate campaign measurement; user-level attribution additionally requires you to allow Apple's tracking prompt on iOS (on Android it is on by default with an opt-out in Settings). Section 6.
  • Apple App Store: subscription payments on iOS.
  • Google Play (Google LLC): subscription payments on Android.
  • Superwall: subscription and paywall presentation.
  • Our cloud hosting / backend: to run the AI proxy, the Oura token exchange, and data-deletion requests.

We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer. Each provider is bound by contractual confidentiality and security obligations.

6. Your consent choices

  • Usage analytics is off until you opt in (“Share usage data,” in onboarding or Settings) and can be turned off any time. When it is off, Safr does not send your product-analytics events. The one exception is a single anonymous signal that records only that analytics was declined or turned off (so we can measure how many people opt in): it carries no name, email, device id, account, or IP-based location, only a coarse region (your country), and it creates no profile, so it cannot be linked back to you.
  • Ad measurement is US-only and limited to users 16 and over. Two non-health signals are involved, in two distinct modes. The signals: a "registration" event when you finish onboarding (before any paywall, with no purchase details), and a subscription event carrying the product, plan, amount, and currency when you subscribe. No health, cycle, intercourse, symptom, or risk data is ever included. The modes: (a) Aggregate measurement. If you opted into usage data ("Share usage data," in onboarding or Settings), these two events are also processed for us by our measurement partner Singular, acting under contract as our service provider, keyed to a random device-scoped id, with data sharing to ad partners restricted. On iOS this powers Apple's privacy-preserving SKAdNetwork reports, which tell ad platforms only anonymous, aggregate campaign results: no identifier, profile, or user-level data about you is given to any ad network in this mode, and Apple designed it to work without the tracking permission. In this mode Singular also forwards the two events to Meta (Meta Platforms, Inc.) on our behalf, with no advertising identifier and with Meta's "Limited Data Use" restriction applied, so Meta may use them only for aggregate campaign measurement, not to identify, profile, or target you. You can turn this off in Settings ("Share data with ad partners" off, or "Share usage data" off). (b) User-level attribution. On iOS this is controlled solely by Apple's App Tracking Transparency prompt: unless you tap Allow, your device advertising identifier (IDFA) is never read and nothing user-level is shared with ad networks. If you tap Allow, Singular may match your install to the ad you tapped and forward the two events user-level to the ad network that showed it, including TikTok and Meta (Meta Platforms, Inc.). On Android, where no such system prompt exists, user-level attribution is on by default for eligible US users using the Google advertising ID (resettable in Android's privacy settings), and you can turn it off at any time in Settings ("Share data with ad partners"). Outside the United States (including the UK, EU/EEA, and Canada) Safr does not send anything to or via ad-measurement services at all, on either platform.
  • Oura is connected only when you explicitly authorize it, and you can disconnect at any time.
  • AI chat and photo analysis ask for your explicit agreement before they first send your message or photo to OpenAI. If you don't agree, nothing is sent.

7. Research: the Safr Cycle Science Study

Safr runs an ongoing observational study of how well wearable temperature tracking reflects real menstrual cycles and pregnancy outcomes. Taking part is optional. Only adults are invited: you must be 18 or older, and you must sync a temperature wearable (Apple Watch or Oura Ring).

Your choice. We ask you once, right after you connect a wearable. You can join or decline, and you can change your mind at any time in Settings under App preferences. Your choice never affects what Safr can do for you.

What we use if you join. The cycle data you log or sync while enrolled, plus your existing history from before you joined: wearable temperature readings, period dates and flow, LH (ovulation) test results, cervical mucus observations (never photos), symptom tags (never written notes), logged sexual activity including protection use, emergency contraception dates, pregnancy test results, your birth year, your cycle statistics, the pregnancy prevention approach and birth control method you picked during setup, whether a temperature wearable is connected, and your reasons for using Safr. We never use your name, contact details, free text notes, photos, chat messages, or advertising identifiers for research.

How it is protected. Research data is keyed to a random study ID created on your device when you join. The study ID is never connected to your name, your email, your device identifiers, or your analytics profile. Results are only ever reported in aggregate, combined across many participants, so no individual can be identified.

Follow up. If you stop logging, we may show you a short in-app message or notification asking about your pregnancy status, because outcomes matter for the research. Answering is always optional.

Leaving and deletion. You can leave the study at any time in Settings. We then stop using your new data for research. To also delete the research data already collected under your study ID, email [email protected]. Data already included in published aggregate results cannot be recalled, but it never identifies you.

Legal basis and retention. For UK and EU users, the legal basis is your consent (Article 6(1)(a) UK/EU GDPR) and your explicit consent for health data (Article 9(2)(a)), with research safeguards under Article 89. Withdrawing consent does not affect the lawfulness of processing before withdrawal. Raw research data is kept for the duration of the study and for up to 5 years after it ends, then deleted or irreversibly anonymised.

8. Legal bases (UK/EU users)

  • Consent: for health-data processing, connecting Oura, and optional analytics. You may withdraw it at any time. (Ad measurement does not run for UK/EU users at all; it is US-only, governed by the usage-data opt-in for aggregate measurement, plus, for user-level attribution, Apple's tracking prompt on iOS or an on-by-default setting with an in-app opt-out on Android.)
  • Contract: to provide the Service you sign up for, including subscriptions.
  • Legitimate interests: to secure, maintain, and improve the Service, balanced against your rights.
  • Legal obligation: where the law requires processing.

9. Data security

We protect your information with technical and organizational safeguards. Most of your data stays on your device, in Safr's private app storage, which is protected by your device's built-in app data protection, which encrypts app storage at the file level and ties it to your device passcode. Sensitive credentials such as your Oura access tokens (if you connect Oura) are kept in your device's secure keystore (the iOS Keychain). Data sent to our backend or providers is encrypted in transit (HTTPS). No system is perfectly secure, but we work to protect your data and respond promptly to incidents.

If a data breach affects your personal data and the law requires it, we will notify you and the relevant authorities without undue delay.

10. Data retention

On your device: your data stays until you delete it in the app or remove the app.

Analytics, if you opt in: we retain product-analytics data (held by PostHog) for up to 2 years, after which it is deleted. On our current plan, event data is kept for about a year and any session data for 30 days, which are shorter. If you delete your data in the app or ask us to, we remove your analytics records sooner.

Deletion requests: when you delete your data in the app we erase it from your device, opt out and reset your analytics identifier, detach advertising attribution, and request erasure of the server-side analytics record tied to your device identifier. Server-side deletion is actioned within one month; copies in routine backups are overwritten within 90 days. We keep limited records only where the law requires it.

11. Your rights and how to use them

Depending on where you live, you may have the right to access, export, correct, delete, restrict, or object to processing of your data, and to withdraw consent. Safr gives you direct controls:

  • Export (Art. 15 / 20): Settings → “Your data” → Export my data gives you a structured JSON copy of what Safr stores on your device.
  • Delete (Art. 17): Settings → Delete all my data wipes your on-device data, opts out and resets analytics, detaches advertising attribution, and requests erasure of server-side analytics records tied to your device identifier.
  • Withdraw consent: disconnect Oura, or turn off analytics / advertising attribution, in Settings; to withdraw consent for health-data processing, delete your data (Settings → Delete all my data), since Safr needs that data to function.

You can also email [email protected] to exercise any right. UK and EU users may also complain to their local data-protection authority (in the UK, the ICO).

To protect your data, we may need to verify your identity before acting on a request, usually by confirming it comes from your registered email. We respond within one month. If we need more time or cannot act on a request, we will explain why.

12. Children's privacy

Safr follows the children's-privacy and minimum-age rules in the markets where it operates. We apply a region-aware minimum age, checked at onboarding: 16 in the US (above COPPA's 13), 18 in the UK, and the applicable digital-consent age (13 to 16) elsewhere in the EU/EEA. Ad measurement is available only to US users 16 and over (aggregate measurement with the usage-data opt-in; user-level attribution on iOS only after allowing Apple's App Tracking Transparency prompt, on Android on by default with an opt-out in Settings); it is turned off everywhere else. We do not knowingly collect data from children below the applicable age; if you believe a child has provided us data, contact us and we will delete it. When the age gate turns someone away, Safr records only an anonymous count of that block: no name, email, device id, account, or IP-based location, just a broad age band and the country from your device's language setting. It cannot be linked back to a person or used to build a profile. It only lets us see where under-age signups come from so we can reduce them.

13. International data transfers

Grow Labs LLC operates from the United States, and some providers (for example, analytics and AI processing) may process data in the United States, while Oura is based in the EU. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards such as the UK IDTA or EU Standard Contractual Clauses.

14. United States

Grow Labs LLC is based in the United States, at 8 The Green, Suite A, Dover, DE 19901. If you live in the US, the following applies in addition to the rest of this policy. We have two detailed US notices: our US State Privacy Law Notice (covering California, Virginia, Colorado, Connecticut, and other state privacy laws) and our Consumer Health Data Privacy Notice (covering the Washington My Health My Data Act and Nevada SB370).

Your health and cycle data is never sold and never shared with advertising networks. We do not sell your personal information, and we do not sell your consumer health data. We will not share or sell your consumer health data without your separate, valid authorization.

One thing to be clear about. If you are a US adult, Safr handles limited, non-health commercial data, such as that you finished onboarding, or that you started a subscription (with the product, plan, amount, and currency), in two ways so we can measure our ads. First, with your usage-data opt-in, our measurement partner Singular processes these events for us as a service provider (with sharing to ad partners restricted) to produce anonymous, aggregate campaign reports through Apple's SKAdNetwork; no ad network receives user-level data about you in this mode. Second, only if you also tap Allow on Apple's App Tracking Transparency prompt, Singular may additionally forward these events user-level to the ad network that showed you the ad (including TikTok and Meta (Meta Platforms, Inc.)). Under some state laws that second, user-level mode may count as a "sale" or a "share." We do this only in the United States; outside the US we send nothing to or via ad-measurement services. User-level sharing never happens unless you allow Apple's prompt, none of it applies to anyone under 16, and you can turn all of it off any time in Settings ("Share data with ad partners" or "Share usage data") or, for the tracking permission, in iOS Settings under Privacy & Security, then Tracking. See the "Do Not Sell or Share My Personal Information" section in our US State Privacy Law Notice.

Your choices and rights. Depending on your state, you may have the right to know what we collect, to access or delete your data, to correct it, to opt out of any sale or sharing for targeted advertising, and to limit the use of sensitive information. You can export or delete your data in the app (Settings, then Your data) or email [email protected]. We will not discriminate against you for exercising these rights. The two notices linked above explain each right and how to use it.

15. Changes to this policy

We may update this Privacy Policy from time to time. When changes are material, we will update the “Last updated” date and, where appropriate, notify you in the app.

16. Contact us

Grow Labs LLC
Email: [email protected]

Health disclaimer: Safr is an education and cycle-tracking app. It is not a contraceptive and does not prevent pregnancy. Never rely on it to avoid pregnancy. For contraception or medical advice, talk to a healthcare professional.
© 2026 Grow Labs LLC. All rights reserved. Privacy  ·  US Privacy  ·  Consumer Health Data  ·  Terms  ·  Support