Persephone Privacy Policy
Last updated: 1 August 2026
Sound Grounds Limited ("SoundGrounds", "we", "us", "our"), NZBN 9429053247445, is a New Zealand company and the publisher of Persephone, a mobile app that helps women understand their health through perimenopause, menopause, HRT and GLP-1 medication. This policy explains what information Persephone collects, how we use it, and the choices you have. It is written to comply with the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020.
Persephone helps you understand your health by logging and connecting information you choose to enter about your cycle, medication, symptoms, mood, weight and sleep. Persephone does not diagnose conditions or provide medical advice.
Information we collect
We only collect information needed to provide the app's features. Some data is entered manually by you; some is optionally synced from a connected health platform if you choose to enable that.
Account information
- Email address, used for sign-in and account recovery
- Password, stored as a salted hash by our authentication provider, never in plain text — we do not have access to your password
Health and cycle information you log
- Menstrual cycle dates
- HRT and GLP-1 medication names, doses and schedules
- Injection site rotation history, for injectable medication
- Symptoms and their severity
- Mood
- Daily check-ins (combined mood/symptom entries)
- Weight
- Sleep duration
Health information synced from a connected source (optional)
Steps, resting heart rate, sleep (including stage breakdown), weight, body fat percentage and menstruation flow, if you choose to connect a platform such as Apple Health or Health Connect. This only happens if you explicitly enable the connection, and you can disconnect at any time.
Purchase information
Subscription status (active or not), managed via our subscription platform, RevenueCat. Payment details themselves — card numbers and similar — are handled entirely by Apple's or Google's app store and are never seen by Persephone or RevenueCat.
Device and diagnostic information
- A device push-notification token, so we can send you notifications you've asked for, such as medication reminders or check-in prompts. You can disable notifications at any time in your device settings.
- Crash and error diagnostic data, via Firebase Crashlytics, collected automatically only in production builds, to help us fix bugs.
We do not collect location data, contacts, photos, or browsing history, and we do not use advertising trackers.
How we use your information
We use your information to:
- Provide the app's core features — logging, reminders, insights
- Show you patterns and relationships across the health data you've logged
- Send you notifications you've opted into
- Diagnose and fix crashes or bugs
- Maintain the security of your account
We do not use your health data for advertising, and we do not sell your data to third parties.
AI-generated insights
Persephone identifies patterns in the information you log — for example, relationships between sleep, medication and symptoms — and describes them to you in plain language. To generate these insights, a snapshot of your recently logged data (the past 90 days of check-ins, symptoms, medication doses and cycle entries, plus your cycle status and medication focus) is sent to Anthropic, our AI provider, solely to generate your insight text. Anthropic processes this data on our behalf to provide this feature and does not use it to train their models. These insights are informational only. They are not a diagnosis and are not medical advice. Always speak with a qualified healthcare professional before making decisions about your health or medication.
Who we share information with
We share information only with the service providers that help us run the app, and only to the extent needed for them to provide their service:
- Supabase — hosts our database, authentication and backend functions
- Google Firebase — Cloud Messaging for push notification delivery, and Crashlytics for crash and diagnostic reporting
- RevenueCat — manages subscription status with Apple's and Google's app stores
- Anthropic — processes a snapshot of your recently logged data to generate your AI insight card, as described above; not used to train their models
These providers operate infrastructure outside New Zealand, so your information may be processed or stored overseas. Where this happens, we rely on providers with their own robust security and privacy commitments, consistent with the requirements of the Privacy Act 2020 for information disclosed outside New Zealand.
We do not sell your data. We do not share your health data with data brokers or advertisers.
Data security
- Row Level Security is enabled on every database table, so your data is only ever accessible to your own account, enforced at the database level
- Data is encrypted in transit (HTTPS/TLS) between the app and our backend
- Data is encrypted at rest using industry-standard AES-256 encryption, in line with Supabase's published security practices
Your rights and choices
- Access — you can view all data you've logged in the app at any time
- Correction — you can edit or correct anything you've logged directly in the app
- Export — you can generate a clinician PDF report of your own data at any time from within the app
- Deletion — you can delete your account at any time from within the app. This permanently deletes your account and all associated data, including your profile, medications, doses, cycle entries, symptoms, check-ins and health connections
- Notifications — you can disable push and local notifications at any time in your device settings
- Health platform sync — you can disconnect Apple Health, Health Connect, or other connected platforms at any time
Under the Privacy Act 2020, you also have the right to ask for access to, and correction of, any personal information we hold about you. For any request not covered by the tools above — for example, a full copy of your data in another format — contact us using the details below.
Data retention
We retain your data for as long as your account is active. If you delete your account, your data is permanently deleted and cannot be recovered.
Children's privacy
Persephone is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect data from children.
International users
Persephone is available to women everywhere, not only in New Zealand. This policy is written to comply with New Zealand law, since Sound Grounds Limited is a New Zealand company. If you are located elsewhere, additional local laws may also apply to how your information is handled; we aim to handle all health information carefully and consistently with the principles in this policy regardless of where you are.
Changes to this policy
If we make material changes to this policy, we will notify users within the app before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Contact us
If you have any questions about this policy or how we handle your information, contact us at support@soundgrounds.nz.
