IYIYGroup.
Legal & privacy
Back to Home
Privacy-First & Offline-First Policy
iOS & Android

Privacy Policy for Liora

Application: Liora•Developer / Publisher: IYGroup•Effective & Last Updated: October 7, 2026

Welcome to Liora ("the App", "we", "us", or "our"), developed and published by IYGroup. Liora is designed from the ground up with a privacy-first, offline-first philosophy. We believe your reproductive health and intimate wellness data belongs exclusively to you.

This Privacy Policy explains how Liora handles information across our mobile application (iOS and Android) and our optional cloud services.

This Privacy Policy applies to the Liora mobile application across iOS (Apple App Store) and Android (Google Play). Official Policy URL: iygroup.vascario.com/privacy/liora

1. Core Privacy Architecture: Offline-First by Design

Local Storage by Default

Liora functions completely offline without requiring an account, email, or internet connection. Sensitive cycle records and pain logs are stored locally in private SQLite databases.

No Ads or Data Brokerage

We do not sell, rent, monetize, or share your personal health information with data brokers, advertisers, or third-party tracking ad networks.

Zero Mandatory Accounts

You can use all core tracking features indefinitely without creating an account or providing personally identifiable information.

2. Information We Handle

A. Information Stored Exclusively on Your Device (Local-Only)

The following information is processed and stored locally on your device and is never uploaded to our servers:

  • Menstrual & Cycle Logs: Period start and end dates, flow intensity (spotting, light, medium, heavy), and full cycle history.
  • Intimacy & Sexual Activity: Logs of sexual activity, protection methods, and personal reflections.
  • Daily Symptoms, Moods & Notes: Granular daily logs, energy levels, physical symptoms, and custom notes.
  • Pain Map & Relief Tracking: Body pain coordinates (front/back), pain severity scores (1–10), remedies tried, and relief ratings.
  • Life-Impact Check-Ins: Logged disruptions to sleep, work, education, social plans, or physical routines.
  • Healthcare Discussion Questions: Draft questions prepared for clinical visits and doctor-facing care reports.
  • Biometric Authentication Data: Face ID, Touch ID, or fingerprint authentication is processed entirely by your device’s OS (local_auth). Liora never receives or stores your biometric credentials.

B. Information Processed When You Use Optional Cloud Features

If you explicitly choose to sign in (via Apple or Google) to enable Partner Sharing, Cross-Device Sync, or Cloud Push Notifications, we collect and store only the minimal necessary data in secure cloud infrastructure (Google Cloud / Firebase):

Data CategoryPurpose & DetailsRetention
Account CredentialsFirebase User ID (UID), optional display name, and authentication token from Sign in with Apple or Google Sign-In.Maintained until account deletion.
Partner Summary SnapshotHigh-level summary fields strictly needed for your partner to support you: current cycle phase, cycle day, estimated next-period window, typical period length, partner note, and today’s moods/symptoms (if scope is enabled).Overwritten on each sync; deleted on account erasure.
Partner Care Signals & OffersReal-time care signals (e.g. crampy, low energy), care suggestions (e.g. bring tea, make dinner), and responses (Yes please / Not today).Active for 24 hours (TTL: 3 days).
Partner DoodlesEphemeral drawings shared between connected partners (transmitted as temporary base64 image data).Replaced by latest drawing / short TTL.
Device Push TokensApple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) tokens, platform type, app version, and timezone for notification scheduling.Until token invalidation or account deletion.
Notification SettingsPreferences for discreet mode, quiet hours, PMS alerts, period reminders, and partner updates.Until updated or account deleted.
Subscription & Purchase StatusSubscription entitlement status (active/inactive, renewal dates) processed via RevenueCat to share Premium benefits across connected partners.Maintained during subscription lifecycle.

C. What is NEVER Shared with the Cloud or Partners

Even when Cloud and Partner Sharing features are active:

❌ Full cycle & bleeding history is NEVER uploaded.
❌ Flow intensity records are NEVER uploaded.
❌ Intimacy & sexual activity records are NEVER uploaded.
❌ Private daily notes & life-impact logs are NEVER uploaded.
❌ Doctor appointment questions & pain maps are NEVER uploaded.
❌ Unencrypted backups are NEVER uploaded.

3. Partner Sharing & Consent Controls

Partner sharing requires explicit mutual opt-in and provides strict user controls:

  • Invite Codes: Connections can only be established when you generate a temporary invite code and explicitly share it with your partner.
  • Granular Privacy Scopes: You have full control over what your partner can see. You can independently toggle sharing for: Cycle Phase, Predictions & Next-Period Windows, Moods, Symptoms (disabled by default), Care Signals, and Fertility Windows.
  • Instant Pause: You can pause partner sharing at any time for 1 day, 7 days, or indefinitely. When paused, no data or care offers are accessible to your partner.
  • Immediate Revocation: You can unlink a partner at any moment in Settings. Unlinking immediately cuts off partner access and deletes the connection state permanently.

4. Data Security, Encryption & Portability

  • Encrypted Local Backups: You can export your data to an encrypted .liora file protected by AES-256-GCM encryption with PBKDF2-HMAC-SHA256 key derivation (600,000 iterations), a random 96-bit nonce, and a 128-bit salt. Your passphrase is never saved, transmitted, or accessible to us.
  • Plain Exports (JSON / CSV): You may export your raw data in standard JSON or CSV formats at any time via the system share sheet.
  • Doctor PDF Reports: PDF clinical health summaries are generated entirely on-device and shared only through your operating system's native share sheet.
  • Discreet Notifications: When enabled, push notifications omit sensitive health terminology (such as "period" or specific symptom names) from lock-screen previews.
  • Transport Security: All cloud communication uses encrypted HTTPS/TLS 1.3 connections with strict payload validation and authorization checks.

5. Third-Party Service Providers

We integrate with trusted third-party infrastructure providers to deliver optional cloud functionality:

Google Cloud / Firebase

Cloud Infrastructure & Auth

Optional cloud services: secure database (Cloud Firestore), anonymous and third-party authentication, and push messaging (Firebase Cloud Messaging).

Apple Inc.

Platform Services

Sign in with Apple authentication, Apple Push Notification service (APNs), and App Store in-app purchase distribution.

RevenueCat

Subscription Verification

In-app subscription management and entitlement verification to validate cross-device and partner Premium access.

6. Your Rights and Data Erasure (GDPR / CCPA)

Regardless of where you reside, you have full sovereignty over your data:

  • Access & Portability: View your data in the app at any time, or export it in full via encrypted backup, JSON, CSV, or clinical PDF summary.
  • Correction: Edit or remove any logged cycle, symptom, mood, or check-in entry directly within the app.
  • Local Data Erasure: In the app under Settings → Privacy & Data, tap Delete All Data to wipe all local SQLite tables and preferences permanently.
  • Cloud Account Erasure: Signed-in users can permanently delete their cloud account under Settings → Account → Delete Account. This triggers immediate, irreversible deletion of your cloud profile, auth credentials, partner links, signals, offers, doodles, and push tokens.
  • App Removal: Uninstalling the Liora app immediately erases all local data stored on your device.

7. Medical Disclaimer

Liora is not a medical device or contraceptive method. Cycle predictions, period start windows, and symptom insights are statistical heuristics for personal wellness and informational purposes only.

They must not be used for birth control, contraception, pregnancy prevention, or clinical diagnosis. Always consult a qualified healthcare provider for medical concerns.

8. Children's Privacy (COPPA & GDPR Compliance)

Liora is not directed toward children under the age of 13 (or under 16 in the European Union). We do not knowingly collect or solicit personal data from children. If you believe that a minor has provided us with personal information, please contact us so we can promptly delete the account and associated records.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When changes are made, we will update the "Last Updated" date at the top of this policy and notify users through an in-app notice where appropriate.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data privacy in Liora, please contact us:

Developer / Publisher: IYGroup
Application: Liora