← Eira

Eira — Privacy Policy

Effective date: 28 July 2026

Provider: Eira Health Pty Ltd (ACN 700 811 507) ("Eira", "we", "us"), a company registered in New South Wales, Australia

Contact: privacy@tryeira.com · https://tryeira.com

Eira is a wellness and cycle-tracking app. Because the information you record in Eira is deeply personal, this policy is written to be read — plainly, without legal fog. It describes exactly what we collect, why, who can see it, and the control you keep.

1. Who this applies to

This policy covers everyone who uses the Eira app or visits tryeira.com. Eira Health Pty Ltd is the data controller. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and where they apply to you, the EU/UK GDPR and other regional privacy laws.

2. What we collect

Account information. Your email address and sign-in credentials, managed by our authentication provider. If you sign in with Apple or Google, we receive the identifier and email your provider shares.

Health and wellness information you choose to record. This is sensitive information, and we treat it that way. It may include: your selected health tracks (e.g. menstrual cycle, PCOS, pregnancy, perimenopause); period dates and flow; daily mood and symptoms, including pain intensity ratings; intimacy and emergency contraception logs; fertility signs (cervical fluid, basal body temperature); medications and supplements you tick off; per-track health context you write (surgeries, medications, upcoming procedures, doctor's advice); food preferences and allergies; pregnancy due dates or postpartum dates; and documents you upload (such as doctor letters or results).

Sharing settings. If you use Partner Support, we store the connections you create, the share codes, and exactly which tracks you have chosen to share with each person.

Technical basics. Device and session identifiers needed to operate the app and diagnose errors. We do not currently run advertising or third-party marketing trackers in the app.

We collect this information directly from you. We do not buy data about you, and we do not collect from data brokers.

3. Why we collect it — and our lawful bases

We use your information only to run Eira for you: to show your cycle status and forecasts; to build your daily wellness plan; to compute patterns from your own logs; to generate AI reflections, insights, wellness plans, document summaries, and doctor-visit summaries you request; to power the sharing you explicitly configure; and to secure and improve the service.

Where the GDPR applies, our lawful bases are: performance of our contract with you (providing the app); your explicit consent for processing health data — given when you choose to record it, and withdrawable at any time by deleting the data or your account; and our legitimate interests in securing and improving the service. Where the Australian Privacy Principles apply, we collect sensitive information only with your consent and only for the functions described here.

4. AI processing — exactly what happens

Some features send your relevant data to our AI provider, Anthropic, to generate the output you requested (for example a daily plan, an insight narrative, or a plain-language summary of an uploaded document). What is sent is limited to what the feature needs. Under our arrangement with Anthropic, this content is processed to produce your output — it is not used to train AI models. Eira's AI is deliberately constrained: it never diagnoses and never gives advice about medications, dosing, surgery, or procedures. Pattern statements shown to you are computed from your own logs, not invented by the model.

5. Who can see your information

You. By default, only you.

People you choose, only what you choose. Partner Support shows a person you connect exactly the tracks you've shared with them — enforced on our servers, not just hidden in the interface. They see supportive guidance, never your raw daily logs unless a shared feature displays a specific element. You can change or revoke any person's access at any time, effective immediately, and revocation also clears AI-generated content that was based on the shared data.

Our service providers (processors). We use a small set of infrastructure providers to run Eira, each bound to process data only on our instructions: Convex (database and backend), Clerk (authentication), Anthropic (AI processing, as described above), and Cloudflare (website hosting, networking, and email routing). If we add providers (for example crash reporting, analytics, subscriptions, or notifications), we will update this policy before they handle your data.

No one else. We do not sell personal information. We do not share it for advertising. We do not give it to data brokers. We would disclose information only if validly required by law, and where lawful we will tell you before we do.

6. Storage and security

Your data is stored with our infrastructure providers, whose servers are located in the United States; by using Eira you consent to this cross-border handling, which we protect through the contractual and technical safeguards described here (and, where GDPR applies, recognised transfer mechanisms). Data is encrypted in transit. Access on your device is protected by your authenticated session, stored in your device's secure storage. Internally, access to production data is restricted to what is necessary to operate the service.

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and other regulators where required.

7. Retention and deletion

We keep your information while your account is active. Deleting your account genuinely deletes it: the in-app "Delete account" action wipes your records from our systems and instructs our processors to do the same, completed within 30 days, except for minimal records we are legally required to keep. You can also delete individual entries (logs, documents, connections) at any time and they are removed immediately.

8. Your rights and choices

You can access and correct your data directly in the app, export your doctor summary, control every share, and delete anything — or everything — whenever you choose. Depending on where you live, you may also have legal rights to access, correction, portability, restriction, objection, or deletion (under the APPs, GDPR/UK GDPR, CCPA/CPRA and similar laws). To exercise any of these, email privacy@tryeira.com — we respond to all requests, normally within 30 days.

If you are unsatisfied with our handling of a complaint, you can contact the OAIC (oaic.gov.au) or your local data protection authority.

9. Children

Eira is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child under 16 has created an account, contact us and we will delete it.

10. What Eira is not

Eira is a wellness and tracking app. It is not a medical device and does not provide medical advice, diagnosis, treatment, or contraception. Cycle estimates and fertile-window figures are informational estimates, not a basis for avoiding or achieving pregnancy. Always consult a qualified health professional for medical decisions.

11. Changes to this policy

If we change this policy, we will post the updated version here with a new effective date, and for material changes we will notify you in the app before they take effect. We will never retroactively weaken the protections on data you have already recorded without your consent.

12. Contact

Questions, requests, or complaints: privacy@tryeira.com · Eira Health Pty Ltd (ACN 700 811 507), New South Wales, Australia.