Privacy Policy

Last updated: 3 September 2026

Sister Health is designed to help you understand your own health information. Because much of the information you choose to log is sensitive health information, protecting your privacy is central to how we operate the service.

This Privacy Policy explains what personal information Sister Health collects, why we use it, where it is processed, who may receive it, how long we keep it, how we protect it, and the rights you have over it.

1. Who we are

Sister Health is operated by Sister Health Ltd, a company registered in England and Wales under company number 17232888.

Registered office:
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

Sister Health Ltd is the data controller for personal information processed through the Sister Health app and sisterhealthapp.com.

For privacy questions, data-protection requests or complaints, contact: info@sisterhealth.app

ICO registration number: ZC236816

2. The short version

You choose what health information you log in Sister Health. We use that information to provide your tracking history, identify patterns, generate personalised insights and create reports you request.

Much of the information you log is sensitive health information. Under UK data-protection law, health information is special-category personal data. Information relating to sexual activity may also be special-category information about your sex life.

We do not sell your personal information and we do not share your health information with advertisers or data brokers.

Our primary application infrastructure and stored health records are hosted using Amazon Web Services in London (eu-west-2). Our database, backups and file storage are encrypted at rest using AES-256, and information transmitted between the app and our systems is protected using HTTPS/TLS.

Personalised insights, cycle explanations and Doctor’s Report summaries are generated using Amazon Bedrock. We use an EU cross-region inference profile, so this processing may take place in AWS regions elsewhere within the EU.

The Sister Health mobile apps do not currently use third-party analytics or crash-reporting tools.

Sister Health is intended for people aged 18 and over.

Sister Health is based in the United Kingdom but is available internationally. Depending on where you live, additional privacy laws and rights may apply.

3. What information we collect

Account information

When you create a Sister Health account, we collect:

  • your first name;
  • your last name; and
  • your email address.

Authentication is handled using Keycloak and OpenID Connect.

Keycloak is self-hosted within our AWS infrastructure. The Sister Health application does not receive or store your password in its application database.

Health information you choose to log

Most of the information you choose to record in Sister Health is health information.

Depending on which features you use, this may include:

  • pain levels, locations and descriptions;
  • energy;
  • bloating;
  • sleep duration and quality;
  • mood;
  • cycle phase;
  • temperature;
  • menstruation dates;
  • bleeding, flow and spotting;
  • symptoms;
  • medications you record;
  • food-intake categories;
  • bowel-movement observations;
  • exercise and activity;
  • travel;
  • periods of high stress;
  • sexual activity, including the date and whether protection was used; and
  • free-text notes you choose to enter.

We treat this information as sensitive health information and, where applicable, special-category personal data.

Information derived from your logs

We may calculate or derive information from what you record, including:

  • typical cycle length;
  • typical bleed length;
  • cycle regularity;
  • patterns across your tracking history; and
  • information used to provide personalised insights.

We protect derived health information in the same way as other health information you provide.

Personalised insights and cycle information

Sister Health may use information from your tracking history to provide personalised daily insights and explanations relating to your cycle.

Information used for these features may include relevant check-in information, onboarding answers, cycle information and free-text notes.

More information about this processing is provided in section 6.

Doctor’s Reports

If you choose to generate a Doctor’s Report, Sister Health uses information from your tracking history to create a summary covering the time period and focus areas you select.

The report is generated at your request. You decide whether to export it and who you choose to share it with.

Device and notification information

If you enable reminders or push notifications, we process your device push-notification token and your reminder preferences.

Authentication and session tokens are stored using secure storage provided by your device operating system, including iOS Keychain and Android Keystore. Session tokens are erased when you sign out or delete your account.

Push notifications are relayed using Expo, followed by Apple Push Notification Service (APNs) or Google Firebase Cloud Messaging (FCM) depending on your device.

Notification text may contain cycle-related information, such as a reminder that your period may be approaching. If you enable notifications, limited health-related notification content may therefore pass through the services required to deliver the notification.

You can control whether notifications appear on your device through your device settings.

Technical and diagnostic information

We process limited technical and operational information where necessary to operate, secure, monitor and troubleshoot Sister Health.

Operational application logs are retained for up to 30 days.

The Sister Health iOS and Android apps do not currently use third-party analytics or crash-reporting tools.

Operational logging and production access controls are kept under review, and we seek to minimise the amount of identifiable health information included in technical logs.

Communications and support

If you contact Sister Health by email or ask us for support, we process the information contained in your correspondence.

We use Google for business email and correspondence.

App-generated verification, password-reset and email-change messages are sent through Amazon Simple Email Service (Amazon SES) from our AWS infrastructure in London (eu-west-2).

In-app feedback is also sent through Amazon SES to Sister Health.

Community

Sister Club is currently coming soon and is not operating as an in-app community.

Sister Health may provide a link to our Facebook community. If you choose to use Facebook, your use of that service is also subject to Meta/Facebook’s own privacy terms and settings.

Information you choose to post in the Facebook group is not part of your Sister Health health-tracking record.

Website information

Our website, sisterhealthapp.com, is hosted using Netlify.

When you visit the website, hosting infrastructure may process technical information needed to provide and secure the website, such as IP address and request information.

If you submit information through a website form, we process the information you choose to provide, which may include your name, email address and phone number.

We do not currently use advertising pixels or session-recording tools on the website.

Where cookies or similar technologies are used, we provide information and choices where required by applicable law.

4. How and why we use your information

We process personal information only where we have an appropriate legal reason to do so.

For users in the UK, our principal lawful bases under the UK GDPR are described below. Different or additional legal bases may apply where another country’s privacy law applies to our processing.

Providing your Sister Health account and service

We use your account information and information you choose to log to:

  • create and operate your account;
  • save and display your tracking history;
  • provide cycle information;
  • provide features you request; and
  • maintain your history over time.

For UK users:

Article 6 lawful basis: performance of our contract with you.

Where special-category health or sex-life information is involved, we rely on an appropriate Article 9 condition, including explicit consent where required.

Personalised patterns, insights and cycle explanations

We process information you log to identify patterns and provide personalised observations and explanations based on your own history.

For UK users:

Article 6 lawful basis: performance of our contract with you.

Where special-category information is involved, an appropriate Article 9 condition also applies, including explicit consent where required.

Doctor’s Reports

We process your health information when you ask Sister Health to create a Doctor’s Report.

For UK users:

Article 6 lawful basis: performance of our contract with you.

Where special-category information is involved, an appropriate Article 9 condition also applies.

Notifications and reminders

If you enable reminders or notifications, we process your device token, notification preferences and the information necessary to provide the notification.

Security, troubleshooting and improving Sister Health

We may process appropriate account and technical information to:

  • maintain the security of Sister Health;
  • troubleshoot errors;
  • monitor reliability;
  • prevent misuse; and
  • improve operation of the service.

For UK users, our Article 6 lawful basis is our legitimate interests in securely operating and improving Sister Health, where those interests are not overridden by your rights.

Where special-category information is involved, an appropriate additional legal condition will also apply.

Service communications

We use your email address where necessary to send account, security and important service communications, such as account verification, password resets and material service changes.

Product updates and other emails

We may occasionally send information about Sister Health and product updates where permitted by applicable law.

You can ask us not to receive non-essential emails by contacting info@sisterhealth.app.

We are continuing to develop our email preference and unsubscribe controls.

We do not use the health information you log to target third-party advertising.

Legal obligations

We may process personal information where necessary to comply with applicable legal obligations.

5. Health information and consent

Health information and information about your sex life receive additional protection under UK data-protection law and may receive similar additional protection under privacy laws in other countries.

Where we rely on consent or explicit consent to process this information, you may withdraw that consent.

Withdrawal does not affect processing that lawfully took place before consent was withdrawn.

Because processing health information is fundamental to Sister Health’s tracking, pattern, insight and reporting features, withdrawing consent may mean that we can no longer provide some or all of those features to you.

To withdraw consent or exercise a privacy right, contact: info@sisterhealth.app

You can also delete your Sister Health account and associated health information as explained in section 10.

6. Personalised insights and Amazon Bedrock

Sister Health uses automated technology to help provide personalised insights, cycle explanations and Doctor’s Report summaries based on information you choose to log.

We use Amazon Bedrock, including Claude Haiku 4.5, for this processing.

Information submitted for this purpose may include relevant check-in information, onboarding information, cycle information and free-text notes.

We do not deliberately include your:

  • name;
  • email address; or
  • Sister Health user identifier in prompts sent to the model.

However, if you choose to include personally identifying information in a free-text note, that information may form part of the information processed for these features.

Sister Health uses an EU geographic cross-region inference profile for Amazon Bedrock. This means requests may be processed in AWS regions within the EU rather than exclusively in London.

Sister Health has not enabled Amazon Bedrock model invocation logging. Prompts and responses are therefore not stored in our AWS account through that logging feature.

Amazon Bedrock does not use Sister Health’s prompts and responses to train the underlying model. AWS may process information for security and abuse-prevention purposes in accordance with its applicable Amazon Bedrock policies.

The model is instructed to provide non-diagnostic observations rather than medical diagnoses.

Sister Health insights and explanations are informational only. They are not intended to diagnose a medical condition or replace advice from an appropriately qualified healthcare professional.

They are not used to make decisions about your eligibility for healthcare, insurance, employment, credit or other decisions producing legal or similarly significant effects.

Generated insights are stored as health information within Sister Health’s encrypted database and protected in the same way as your other health information.

7. Who we share your information with

We use service providers to provide and operate Sister Health.

Where organisations process personal information on our behalf, we require appropriate contractual and data-protection safeguards.

Amazon Web Services

Amazon Web Services (AWS) provides Sister Health’s core infrastructure, including:

  • Amazon RDS MySQL database hosting;
  • Amazon S3 file storage;
  • AWS CloudFront;
  • Amazon SES transactional email;
  • Amazon CloudWatch;
  • Amazon ECS/Fargate;
  • encrypted backups; and
  • Amazon Bedrock.

Our primary stored application and health information is hosted in AWS London (eu-west-2).

Amazon Bedrock may process relevant information within other EU AWS regions as described above.

Expo

We use Expo, Inc. for application build/update services and push-notification delivery.

If you enable push notifications, Expo may process your device push token and notification content required to relay the notification.

Expo is based in the United States.

Apple and Google push services

Depending on your device, notifications may also be processed by:

  • Apple Push Notification Service (APNs); or
  • Google Firebase Cloud Messaging (FCM).

These services receive information necessary to deliver notifications to your device.

Google

We use Google for Sister Health business email and correspondence.

Netlify

Netlify hosts the Sister Health public website and may process limited technical information associated with website visits.

Moonward

Sister Health works with Moonward, based in Australia, as its external application-development provider.

Our development and production environments are separate. Production health records are not copied into or used in development environments.

Moonward may currently have limited technical access to production systems where necessary to provide technical and development support. We are further restricting production access as part of our security controls so that identifiable production health information is not available to development personnel where it is not required.

Moonward has confirmed that the external technical services listed above comprise the services currently used by the live app to process user information.

Legal or corporate requirements

We may disclose personal information where required by law.

If Sister Health Ltd is involved in a merger, acquisition, restructuring or sale, relevant information may transfer as part of that transaction subject to applicable privacy and data-protection requirements.

We do not sell your personal information.

We do not share your health information with advertisers or data brokers.

We do not use the health information you log for third-party advertising.

8. Where your information is processed

Our primary Sister Health application infrastructure and stored health records are hosted using Amazon Web Services in London, United Kingdom (eu-west-2).

Our database, file storage, identity infrastructure and transactional email infrastructure are primarily located in this region.

Some processing may occur in other countries.

This may include:

  • EU countries, through Amazon Bedrock’s EU cross-region inference;
  • the United States, including through Expo and infrastructure used by relevant service providers;
  • Australia, while authorised Moonward personnel retain any necessary production-system access; and
  • other locations from which our business-email, website-hosting or device-notification providers provide their services.

Where applicable law requires safeguards for an international transfer of personal information, we take steps to use recognised transfer mechanisms, contractual protections or other appropriate safeguards.

9. How we protect your information

We use technical and organisational measures designed to protect personal information, with particular care given to sensitive health information.

Our MySQL database is hosted using Amazon RDS and encrypted at rest using AES-256 through AWS Key Management Service.

Automated database backups are also encrypted.

Files stored using Amazon S3 are encrypted at rest using AES-256 server-side encryption and are configured to prevent public access.

The Sister Health app communicates with our API using HTTPS/TLS, with certificates managed through AWS.

Authentication is handled using Keycloak and OpenID Connect.

Requests for health information are restricted to the authenticated user’s own records, with additional ownership checks where individual records are accessed or changed.

Authentication/session tokens are stored using secure storage provided by your device operating system, including iOS Keychain and Android Keystore.

Our production and development environments use separate infrastructure, databases, identity environments, file storage and domains. Production health records are not used in development or testing.

We regularly review and improve our access controls, logging and production security as Sister Health develops.

No system can guarantee absolute security.

10. How long we keep your information

We keep personal information only for as long as necessary for the purposes for which it is processed, subject to applicable legal and regulatory requirements.

Health information

Your health information is retained while your Sister Health account remains active so that you can maintain your history and use features that depend on information collected over time.

Operational logs

Operational application logs used for monitoring and troubleshooting are retained for up to 30 days.

Database backups

Sister Health uses encrypted automated database backups and point-in-time recovery.

The current backup retention window is 1 day.

There are no manual database snapshots currently retained.

Account and health-data deletion

Full account and associated health-record deletion is implemented in Sister Health.

When you delete your account, you are required to re-enter your password.

On confirmation:

  • your Keycloak identity is deleted;
  • your Sister Health user record is deleted;
  • associated health records are deleted;
  • session tokens on your device are erased; and
  • you can no longer sign in to or recover that account.

Deleted information may remain recoverable within our encrypted backup and point-in-time recovery system for up to approximately 24 hours.

AWS automatically removes recovery data after the one-day retention window. Sister Health does not currently retain manual database snapshots that would cause deleted information to remain beyond this window.

Other information

We may retain limited information for longer where reasonably necessary to:

  • comply with legal obligations;
  • establish or defend legal claims;
  • maintain appropriate records of consent;
  • respond to privacy requests or complaints; or
  • maintain appropriate security and business records.

We do not keep personal information for longer than reasonably necessary for these purposes.

11. Your privacy rights

Depending on where you live and the circumstances, applicable privacy or data-protection law may give you rights in relation to your personal information.

These may include the right to:

  • access personal information we hold about you;
  • receive a copy of certain information in a portable format;
  • correct inaccurate or incomplete information;
  • request deletion of your personal information;
  • request that processing be restricted;
  • object to certain uses of your information; and
  • withdraw consent where we rely on consent.

These rights may vary between countries and are not absolute in every circumstance.

To exercise a privacy right, contact: info@sisterhealth.app

For requests made under UK data-protection law, we will normally respond without undue delay and within one month.

If another applicable privacy law provides you with different rights or response periods, we will handle your request in accordance with that law.

We may ask for information reasonably necessary to verify your identity before acting on a request.

12. International users

Sister Health Ltd is established in the United Kingdom and our primary data-protection framework is UK law.

Sister Health is available internationally. Depending on where you live or use Sister Health, additional local privacy laws may apply to our processing of your personal information.

Where those laws apply to Sister Health, we will respect the privacy rights and obligations that apply to our processing.

If you are outside the United Kingdom and have a question about your privacy rights, contact info@sisterhealth.app.

13. Privacy complaints

If you are concerned about how Sister Health has handled your personal information, contact: info@sisterhealth.app

For complaints falling under UK data-protection law, we will acknowledge receipt within 30 days, investigate the complaint appropriately and communicate the outcome without undue delay. This reflects the UK complaints requirements now in force.

If you remain unhappy, you may have the right to complain to the privacy or data-protection regulator responsible for your location.

For UK users, this is the Information Commissioner’s Office (ICO).

ICO registration number: ZC236816

Users elsewhere may also have the right to complain to their applicable local privacy regulator.

14. Age requirement

Sister Health is intended for people aged 18 and over.

We do not knowingly provide Sister Health app accounts to anyone under 18.

If you believe someone under 18 has created an account or provided personal information through the app, contact info@sisterhealth.app and we will investigate and take appropriate action.

15. Cookies and similar technologies

The Sister Health iOS and Android apps do not currently use third-party analytics or crash-reporting tools.

The Sister Health website may use cookies and similar technologies necessary to operate and secure the website.

We do not currently use advertising pixels or session-recording tools.

Where non-essential cookies or similar technologies are introduced, we will provide appropriate information and choices before they are used where required by applicable law.

16. Changes to this Privacy Policy

We may update this Privacy Policy as Sister Health develops or where legal, regulatory or technical changes require us to do so.

The latest version will always be available at: sisterhealthapp.com/privacy-policy

Where a change materially affects how we use personal information, we will take reasonable steps to bring the change to your attention, for example through the app or by email.

The date at the top of this policy shows when it was most recently updated.

17. Contact us

For privacy questions, privacy-rights requests or complaints:

Sister Health Ltd
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom

Email: info@sisterhealth.app

ICO registration number: ZC236816