Tidewell ("Tidewell," "we," "us," or "our") is a menstrual cycle and women's health tracking application, operated by Digital Whims LLC. This Privacy Policy explains what information we collect, how we use and protect it, and the choices and rights you have.
We can be reached at support@mytidewell.com for any privacy question, request, or concern described in this Policy.
This Policy applies to the Tidewell website and application (the "Service"), however you access it. It does not apply to third-party sites or services you may reach through links in the Service.
Tidewell is a reproductive and women's health tracker. References in this Policy to "Health Data" cover the full range of information you may choose to log now or as the Service adds new tracking features over time, including but not limited to: menstrual cycle dates and flow, symptoms, mood, medications and medication compliance, daily health notes, and other self-reported wellness or self-exam observations (for example, breast self-exam notes) — whatever specific data types the Service supports at a given time. This Policy is written to cover that category generally so it does not need to be rewritten each time a new Health Data type is added; any materially new purpose or new third party involved in processing it would still trigger the update process described in Section 15.
When you create an account, we collect information necessary to identify and authenticate you, such as your Google account identifier (if you sign in with Google) or a username and password you set directly, and, where applicable under our age-verification process, a date of birth used solely to determine which age-appropriate mode of the Service applies to you (see Section 11, Children's Privacy).
Health Data is anything you choose to log in the Service about your cycle, symptoms, mood, medications, or other wellness observations, as described in Section 2. You control what you log; nothing here is required to use core features. Tidewell uses end-to-end encryption for most Health Data on accounts that have completed E2E setup — see Section 4.
If you use the Service in local-only mode, your Health Data is stored solely on your own device (in browser-local storage) and is never transmitted to or stored on our servers. We have no access to, and no copy of, local-only data. Switching between local-only and cloud storage is a choice you make in Settings, and is described further in Section 4.
We automatically receive limited technical information needed to operate the Service, such as your general geographic region (derived from IP address, used only to apply the correct age/jurisdiction rules described in Section 11 — we do not store precise location), browser/device type, and session information needed to keep you signed in.
For accounts that have completed Tidewell's end-to-end encryption ("E2E") setup, most Health Data (including cycle dates, symptoms, mood, medications, and daily logs) is encrypted on your own device before it ever reaches our servers, using an encryption key derived from your device and account credentials. This means that, for E2E-enabled accounts, we store only encrypted data we cannot read, and we do not have the technical ability to decrypt it — including in response to our own internal requests. Some limited fields necessary for the Service to function (such as scheduling reminders) may not be end-to-end encrypted; we describe which fields these are, and why, in the in-app E2E setup information.
You may also choose local-only storage (Section 3.3), which keeps Health Data off our servers entirely.
We use the information described in Section 3 to:
We do not use your Health Data to train third-party AI or machine learning models, and we do not use it for advertising.
Tidewell allows an account holder to grant another person (a "delegate") view or edit access to their profile — for example, a caregiver or partner. If you grant delegate access, the delegate can see the categories of information you authorize, subject to the same encryption protections described in Section 4. You can revoke delegate access at any time in Settings.
We do not sell your personal information or Health Data, as those terms are defined under applicable law, and we do not share it for cross-context behavioral advertising.
We share information only with the following categories of service providers, each acting on our behalf and under contractual confidentiality and security obligations, solely to operate the Service:
We may also disclose information where required by law, to protect the rights, safety, or property of Tidewell or others, or in connection with a merger, acquisition, or sale of assets, in which case we will provide notice as required by law before your information becomes subject to a different privacy policy.
We retain your information for as long as your account is active, or as needed to provide the Service. If you delete your account, we delete your account and Health Data, along with associated records such as device links, recovery data, delegate grants, and encryption key material, from our active systems. Some information may be retained for a limited period where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
You can request account and data deletion directly within Settings, or by contacting us at support@mytidewell.com.
Depending on where you live, you may have some or all of the following rights regarding your information: to access, correct, or delete it; to obtain a copy in a portable format; to withdraw consent where processing is based on consent; to object to or restrict certain processing; and to not be discriminated against for exercising these rights.
If GDPR or the UK GDPR applies to you, you have the rights above under those laws, and may lodge a complaint with your local data protection authority. Our legal bases for processing are described in Section 10.
If you are a California resident, the CCPA/CPRA gives you rights to know, delete, correct, and limit use of sensitive personal information (which includes health information), and to not be discriminated against for exercising these rights. Residents of other states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah) have similar rights under their respective laws. To exercise these rights, contact us at support@mytidewell.com.
If the Washington My Health My Data Act applies to your information, please see our separate Washington Consumer Health Data Privacy Notice, which describes the categories of consumer health data we collect, why, and how to exercise your MHMDA-specific rights, including the right to withdraw consent.
Contact us at support@mytidewell.com with your request. We will verify your identity before acting on requests involving account or Health Data access, and will respond within the time required by applicable law.
Where GDPR or UK GDPR applies, we process your information on the following legal bases:
Tidewell is designed to be usable by minors in a manner appropriate to their age and jurisdiction, and applies different account modes automatically based on the age you provide and your general region at signup:
We do not knowingly collect more personal information from children than described above. A parent or guardian who believes we have collected more than permitted may contact us at support@mytidewell.com to request review or deletion.
Our service providers may process information in the United States or other countries outside your own. Where we transfer personal information out of the EEA or UK, we rely on appropriate safeguards, such as Standard Contractual Clauses, as required by applicable law.
Tidewell currently sets only the strictly necessary session cookie required to keep you signed in. We do not use analytics or advertising cookies. If that changes, we will update our Cookie Notice and, where required (for example in the EEA/UK), obtain your opt-in consent before setting any non-essential cookie.
We use technical and organizational measures designed to protect your information, including end-to-end encryption for Health Data on E2E-enabled accounts (Section 4), encryption in transit, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We may update this Policy from time to time. We will post the updated Policy with a new effective date and version tag. Where a change materially affects how we process Health Data specifically, we will seek your renewed consent separately, consistent with our internal consent-versioning practice, rather than relying on continued use alone.
Digital Whims LLC
Email: support@mytidewell.com
Governing state for purposes of this notice: North Carolina
© 2026 Digital Whims LLC. All rights reserved.