What Cara is
Cara is a privacy-first period tracker for iOS and Android. We believe your cycle data is yours alone. This policy explains how we handle it. Spoiler: we don't handle it at all — you do, on your device.
What we collect
Nothing is sent to us. Here's what stays on your phone:
- Cycle dates — when your period started and ended
- Symptoms and notes — mood, flow, pain, custom notes you enter
- Biometric template — your Face ID / Touch ID / Android biometric pattern (managed by your phone's operating system, never sent to Cara or anywhere else)
That's it. Everything is stored in cara.db, an encrypted local database on your device.
What we don't do
- No analytics. We don't track how you use Cara.
- No advertising. Cara has no ads and never will.
- No accounts. You don't sign up, log in, or create a profile.
- No cloud sync. Your data never leaves your phone.
- No third-party SDKs. No tracking libraries, no crash reporters, no marketing tools.
- No in-app purchases. Cara is free and stays free.
- No camera, microphone, location, contacts, or photos. We don't ask for them.
How your data is protected
Encryption at rest
Your cycle database is encrypted using SQLCipher AES-256, the same encryption standard used by security-conscious apps and organizations worldwide. Even if someone steals your phone and extracts the database file, they cannot read your data without the encryption key.
Encryption key storage
- iOS: Apple Keychain (protected by device PIN/Face ID/Touch ID)
- Android: Android Keystore (protected by device unlock method)
You cannot access the encryption key directly — only your phone's operating system can.
Biometric lock (optional)
You can optionally protect Cara with Face ID, Touch ID, or your Android biometric. If enabled, Cara requires biometric verification each time you open it.
Required-Reason iOS API usage
Cara uses the following iOS system APIs for core functionality:
- UserDefaults (CA92.1) — to store app preferences and settings locally
- File timestamp access (C617.1) — to verify file integrity during sync and backup operations
- System boot time (35F9.1) — to track app session duration and ensure data consistency
These are logged in our PrivacyInfo.xcprivacy file as required by Apple's guidelines. None of these APIs transmit data off your device.
Permissions
Cara asks for only one permission: Face ID / Touch ID / Biometric (optional, user-controlled). Cara never requests camera, microphone, location, contacts, photos, calendar, or HealthKit data.
Data deletion
When you uninstall Cara, everything is deleted immediately. There is no Cara server, no cloud account, and no backup of your data anywhere else. Uninstall = permanent deletion.
Children's privacy
Cara is intended for users age 13 and older. Since Cara collects no data whatsoever, there's nothing to protect except the app's core function. If a child under 13 uses Cara, their data remains entirely on their device, exactly like for anyone else.
International users (GDPR, CCPA, etc.)
- You own your data. It never leaves your device.
- You have the right to know what we collect. We collect nothing.
- You have the right to delete your data. Uninstall Cara and it's gone.
- You have the right to data portability. Cara's database is standard SQLite; export it with standard tools.
Changes to this policy
If we update this policy, we'll notify you in-app and post the updated version here. We'll never weaken your privacy protections without asking you first.
Contact us
Questions about this policy or privacy concerns: privacy@cara.digitaldisconnections.com. We read every message and respond within 48 hours.
Cara Privacy Policy — Effective May 17, 2026