Privacy Policy
Ripply
Privacy Policy — Ripply (ContractionTimer)
Last updated: 2026-07-21
1. Summary
By default, your health data (contractions) stays on your device. Only two cases cause data to leave your phone:
- Partner mode, which you enable explicitly: it shares your tracking (and, if you choose, your one-time location) read-only with the loved one you invite, through our sync infrastructure.
- Anonymous usage analytics and session recordings (PostHog): which screens are viewed and where you tap, with no contraction data or personal data, masked on your device before sending (see below).
Outside of partner mode, no health data leaves your device without an explicit action from you (for example, exporting to your midwife).
2. Data collected
Health data (stored locally by default)
Ripply records locally:
- The start and end timestamps of each contraction (date, time)
- The computed duration and interval of each contraction
- Your interface preferences (theme, haptics, keep-screen-on, optional maternity address)
This data is stored on your iPhone via SwiftData (a database protected by iOS system encryption NSFileProtectionComplete). It is never sold, shared with advertisers, or used for advertising. Any transmission is limited to the two cases described below (partner mode, manual export).
Data transmitted when partner mode is enabled
Partner mode is optional and off by default. If you enable it and invite a loved one, the app syncs to our infrastructure (operated via Supabase):
- A snapshot of your ongoing tracking: contraction rhythm, duration and interval, milestone state (5-1-1 / 4-1-1 / 3-1-1), and any estimate information you chose to share.
- Your one-time location (GPS coordinates and the approximate corresponding address), only if you choose to share it at a specific milestone (never continuous tracking; the snapshot expires automatically server-side).
- An anonymous device identifier and the technical information needed for pairing (the invite code is transmitted as a hash, never in clear text).
The loved one you invite accesses this information read-only. You can revoke access at any time; revocation removes access immediately, and shared session data expires automatically (session within 24 h, invite code within 10 min, location per the duration you chose). A "Delete shared data now" button allows immediate erasure.
Anonymous usage data (analytics)
We use PostHog to improve the app. PostHog collects only:
- Screens viewed (e.g. timer, history, export, paywall)
- Usage actions (e.g. opening export, finishing onboarding)
This data is tied to a locally generated random identifier, with no link to your identity, name, or the content of your contractions. PostHog never receives the timestamps, durations or intervals of your contractions, nor your location: in the session recordings described below, these are masked on your device before sending.
3. Health data
Contraction data and location are sensitive health and location data under the General Data Protection Regulation (GDPR). Accordingly:
- On the device, they are protected by iOS system encryption (
NSFileProtectionComplete) and stay within the app sandbox. - They are transmitted off the device only (a) via partner mode that you enable, (b) via the export function you trigger, or (c) never for analytics (see section 2).
- Data transmitted in partner mode travels over HTTPS.
- Deleting the app erases local data. Data shared server-side expires automatically or can be deleted via the dedicated function.
4. Third-party services and infrastructure
- PostHog (posthog.com) — anonymous usage analytics (section 2), hosted in the European Union. PostHog receives no health or location data, including in session recordings, where such data is masked on your device.
- Supabase (supabase.com) — partner mode infrastructure (database and sync), hosted in the European Union (Paris). Used only when you enable partner mode.
- RevenueCat (revenuecat.com): subscription and Premium purchase management since 10 September 2026. Receives an anonymous device identifier and your purchase status as reported by the App Store, never your health data, your location or your payment details.
- Apple (App Store): payment, renewal and refunds.
No advertising trackers, no social network integrations, no sale of data.
5. Children
The app is not intended for children under 13 and collects no data about them.
6. Your rights (GDPR)
You exercise your rights of access, rectification and deletion directly from the app (local history) or by uninstalling it. For data transmitted via partner mode, revoking access and the "Delete shared data now" button let you erase it; data not deleted expires automatically. For any further request, contact the developer (section 8).
7. Medical disclaimer
Ripply is not a medical device. The app is a tool to help you keep track of contraction timing and in no way replaces the advice, monitoring or recommendations of a healthcare professional (midwife, doctor, obstetrician).
In case of doubt, emergency or complication, contact your maternity ward immediately or call your local emergency number.
Session recording (screenshots with masking)
Since September 2026, Ripply may record usage sessions through PostHog, to understand where people get stuck in the app.
- What it is: a series of screenshots of the app screen, replayed like a video, with the places that were tapped. No audio, no camera, no content from other apps. Nothing is recorded while the app is in the background.
- What is masked: your contractions (durations, intervals, charts), the birth date, the maternity ward address and your summaries. Masking is applied on your device, before sending: these never appear in a recording.
- Hosting and retention: PostHog servers in the European Union, kept for 30 days, then deleted automatically.
- Identification: the recording is tied to the same random identifier as the other usage metrics, which cannot identify you.
8. Contact
For any question about this privacy policy, contact the developer via the app's App Store page.