Petal

Privacy Policy

Last updated: September 6, 2026

Petal is an iPhone app that tracks your menstrual cycle. This policy explains what data the app handles. The short version is simple: Petal has no network code, and I collect nothing.

The short version

  • Petal has no accounts, no analytics, no advertising, no tracking, and no third-party software inside it.
  • Your periods, symptoms, notes and settings live on your phone. They are never sent to me; I run no servers and have no way to see them.
  • iCloud sync, Apple Health writing, and the Face ID lock are all off until you turn them on.
  • You can export, import, or delete everything at any time from Insights → Settings.

1. Who I am

Petal is made and published by Nischal Khadka, an independent developer, under the name twofox. For anything about this policy, write to support@twofox.app.

2. What I collect

Nothing. The app does not ask you to create an account, does not collect your name, email address or contact details, does not record how you use it, and contains no analytics, crash-reporting or advertising software from anyone. The app's privacy manifest declares no tracking and no collected data, and that is simply true: the app has no code that talks to a server of mine.

3. What the app stores on your device

  • Cycle history — the period start and end days you log.
  • Per-day log — symptoms, flow level, and any note you write for a day.
  • Settings — your cycle and period length answers, which symptom chips you show, whether predictions are paused, reminder, sync, Health and app-lock switches.

This data is shared between the app and its widget through a private container that only Petal can read. Deleting the app deletes all of it from the device.

4. iCloud sync (optional)

If you turn on iCloud sync, your Petal data is stored in your private iCloud database (Apple CloudKit) so it follows you to a new phone. That data belongs to your Apple Account: it is stored by Apple, encrypted in transit and at rest, and I cannot read, access or share it. Apple's handling is described in Apple's privacy policy. Sync is off by default. You can switch it off in the app, and remove the iCloud copy under iOS Settings → your name → iCloud → Manage Account Storage → Petal.

5. Apple Health (optional, write-only)

If you turn on Health writing, Petal adds your logged period days and flow to the Menstruation category in Apple Health. Petal only ever writes; it never reads anything from Health. iOS asks for permission the first time, and you can revoke it in the Health app at any time. Turning the switch off removes the days Petal added.

6. Face ID / Touch ID lock (optional)

The app lock uses the device's own authentication. Petal never sees your face or fingerprint data; iOS only tells the app whether the unlock succeeded.

7. Notifications

Period reminders are local notifications, scheduled entirely on your device. Nothing is sent from a server. They are off until you turn them on, and the notification permission is only requested after you do.

8. Widgets

Home Screen and Lock Screen widgets read the same on-device storage as the app. Lock Screen widgets show a number and a small glyph, never the words "period" or "fertile". The widget's log button updates that storage on your device; nothing is sent anywhere.

9. Third parties

There are none. No third-party SDKs, no advertising networks, no analytics providers. I do not sell, rent or share data with anyone; there is no data to share.

10. Deleting your data

  • In the app: Insights → Settings → Delete my data erases everything on the phone and, if sync is on, the iCloud copy too.
  • On your device: delete the app. iOS removes the app's private storage, including the widget's copy.
  • In iCloud: iOS Settings → your name → iCloud → Manage Account Storage → Petal → Delete data from iCloud.

11. Children

Petal is intended for people who menstruate and is rated accordingly on the App Store. It does not collect personal information from anyone, including children.

12. Your rights

Privacy laws such as the GDPR and CCPA give you rights to access, correct, delete or export personal data a company holds about you. Petal holds no personal data about you, so every one of those rights is satisfied by the controls on your own device and Apple Account described above. If you believe I have got any of this wrong, write to me and I will answer.

13. Not medical advice

Petal's predictions are estimates based on the dates you log. They are not medical advice and should not be used for contraception or to diagnose any condition.

14. Changes to this policy

If this policy changes, the updated version will be published at this address with a new "last updated" date. I will never quietly start collecting data under an old policy.

15. Contact

Questions about privacy: support@twofox.app.
For help using the app, see Help & support.