Privacy Policy

    Last updated: August 16, 2026

    1. Introduction

    Blasto ("we", "our", or "us") operates the Blasto mobile application and this website (together, "the Service"). IVF data is among the most personal data there is, and this policy is written to be read rather than to cover us: it explains what we collect, who processes it, how long we keep it, and how you get rid of it.

    In short: we do not sell your data, we do not share it with advertisers or data brokers, and you can export or delete everything yourself at any time.

    2. Information We Collect

    Almost everything here is information you choose to enter. The app works with none of it filled in.

    • Account information: Your email address, and your name if you provide one. If you sign in with Google or Apple we receive your name and email address from that provider and use them only to create and run your account.
    • Treatment data: Treatment stage, cycle dates, clinic name and protocol details you enter.
    • Medication records: Medication names, dosages, schedules, and the doses you log.
    • Symptom and mood logs: Entries, intensity ratings and any notes you write.
    • Appointments: Dates, times, types, locations and notes.
    • Results: Egg retrieval numbers, blood work entries and ultrasound records.
    • Community content: Posts, comments and reactions you share in the community feature. Anything you post there is visible to other members — treat it as public.
    • Voice companion audio: When you talk to the AI companion, your speech is streamed to our voice provider to generate a reply. It is processed for that purpose and not stored — we keep only a count of sessions and turns, to meter the monthly allowance.
    • Usage data: In-app events such as which screens you open and which features you use, recorded as counts, identifiers and flags. Medical content is never included in analytics.
    • Diagnostics: Crash reports and performance data, stripped of identifying information before they leave your device.
    • Subscription status: Whether you have an active subscription. We never see or store your payment details.
    • Correspondence: What you send us when you contact support, submit feedback or request beta access through this website.

    We do not collect your location. Appointments the app adds to your device calendar are written on the device and never sent to us.

    3. How We Store Your Data

    Your data is stored using Firebase, a Google Cloud service. It is encrypted in transit using industry-standard TLS and encrypted at rest by the platform, with access controls limiting who can reach it. No system is perfectly secure, and we will not claim otherwise — but nothing about your treatment leaves the app in the clear.

    4. Third-Party Services

    These providers process data on our behalf, only to make the Service work. None of them are permitted to use it for their own purposes:

    • Firebase (Google): Authentication, database storage and server functions.
    • ElevenLabs: Powers the AI voice companion. Audio is processed to generate a reply and is not retained afterwards.
    • RevenueCat: Manages subscriptions. It receives your account identifier and your subscription status, and never receives your health or treatment data.
    • Sentry: Crash and error reporting, so we can fix problems. Reports carry no email address, no IP address, and none of your symptoms, medications or messages.
    • PostHog: Product analytics, so we can see which parts of the app are used and where people get stuck. It receives your account identifier, the screens you open and actions such as "logged a medication" - never the medication, symptom, result or message itself. Hosted in the European Union.
    • Brevo: Delivers account emails such as address verification and password resets.
    • Apple and Google: Whichever app store you downloaded Blasto from processes subscription payments. The store handles the transaction and tells us only whether your subscription is active.

    5. Google API Services

    Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

    • We only request access to the data necessary to provide the Service (name, email, profile picture for authentication).
    • We do not use Google user data for serving advertisements.
    • We do not transfer Google user data to third parties unless necessary to provide the Service, required by law, or with your explicit consent.
    • We do not use Google user data for purposes unrelated to the Service.

    6. How We Use Your Information

    • To provide the app's features and keep your data in sync across your devices
    • To personalise what you see based on the treatment stage you are in
    • To send the notifications you have turned on, such as medication and appointment reminders
    • To run the community feature, including moderation, reporting and blocking
    • To manage subscriptions and premium access
    • To fix crashes and improve the app
    • To respond to your support requests
    • To meet our legal obligations

    We do not use your data to train advertising profiles, and we do not use your health data to train third-party AI models.

    7. Data Sharing

    We do not sell, rent or trade your personal information. Your health and treatment data is never shared with advertisers or data brokers. We share data only with the processors listed in section 4, where the law requires it, or to protect the safety and rights of our users or the public. Community posts are shared with other members of the community by definition — that is what posting means.

    8. Exporting and Deleting Your Data

    Both are self-service, and neither requires you to ask us:

    • Export: Profile → Export My Data in the app produces a machine-readable copy of everything we hold about you.
    • Delete: Profile → Delete Account permanently deletes your account and all associated data — profile, medications, symptoms, appointments, results, tasks, community posts and comments, voice-session records and analytics events — along with your sign-in record itself.

    If you have uninstalled the app or cannot sign in, email support@moonsify.com from the account's email address and we will delete it for you. Full instructions, including exactly what is deleted and what is retained, are on the account deletion page.

    Deleting your account does not cancel a paid subscription — subscriptions are billed by the app store and must be cancelled there first.

    9. Data Retention

    We keep your data for as long as your account exists. When you delete your account, it is removed from our live systems immediately; residual copies in encrypted backups and operational logs age out within 30 days. We retain nothing beyond that except where the law requires it.

    10. Your Rights Under GDPR

    If you are in the European Economic Area or the UK, you have the following rights under the General Data Protection Regulation:

    • Right of access: A copy of the personal data we hold about you — available immediately through Export My Data.
    • Right to rectification: Correction of inaccurate or incomplete data, editable in the app at any time.
    • Right to erasure: Deletion of your personal data, available immediately through Delete Account.
    • Right to data portability: A machine-readable copy of your data, which is what the export produces.
    • Right to restrict processing: You may ask us to limit how we use your data.
    • Right to object: You may object to our processing of your personal data.
    • Right to withdraw consent: Where processing rests on consent, you may withdraw it at any time.

    To exercise the rights that are not self-service, contact us at support@moonsify.com. We respond within 30 days. You also have the right to complain to your local data protection authority.

    If you live in California or another US state with comparable privacy law, you have equivalent rights to know, delete and correct your data, and to opt out of its sale or sharing — we do not sell or share personal information as those laws define it, and we do not discriminate against anyone for exercising these rights.

    11. Children's Privacy

    Blasto is not intended for anyone under 18. We do not knowingly collect data from children, and if we learn that we have, we will delete it.

    12. Medical Disclaimer

    Blasto is a personal tracking and community support tool. It is not a medical device and does not provide medical advice, diagnosis or treatment, and nothing in it — including anything shared by other members — is a substitute for your clinic. Always consult your healthcare provider about your treatment.

    13. Changes to This Policy

    We may update this policy from time to time. Material changes will be posted here and in the app, with the "Last updated" date changed. Continuing to use the Service after a change means you accept the updated policy.

    14. Contact Us

    Questions about this policy or how we handle your data: