Privacy Policy
Postpartum Recovery Tracker — effective August 9, 2026
Effective date
August 9, 2026
This Privacy Policy explains how Mertapp ("Mertapp," "we," "us," or "our") collects, uses, stores, and discloses information when you use the Postpartum mobile application (the "App"). The App handles sensitive postpartum recovery information, so please read this policy carefully.
1. Information you provide
Account information: your email address, Firebase user identifier, and optional display name. You may also use the App through an anonymous Firebase account.
Recovery and health information: birth date and type, feeding method, recovery areas and goals, pain, energy, mood, anxiety, sleep, bleeding, symptoms, incision or perineal discomfort, medications, supplements, notes, and check-in dates.
Appointment information: appointment dates, titles, notes, and questions you prepare for a healthcare professional.
Preferences: reminder time, notification preference, appearance, subscription status, and partner-sharing setting.
Support communications: information you choose to include when contacting us.
2. Information collected automatically
We use Firebase Analytics to understand basic App activity, such as onboarding, sign-in, and check-in events. Analytics may process device and app information, approximate location derived from IP address, usage events, and identifiers generated by Firebase. We do not place your recovery notes, symptoms, medication entries, or other health-entry content into analytics events.
We use Firebase Crashlytics to diagnose crashes and reliability problems. Crash reports may include crash traces, device and operating-system details, app state, and Firebase or Crashlytics installation identifiers.
Your device operating system may also provide technical information needed to schedule local notifications.
3. How information is collected
We collect information directly from you when you complete onboarding, create an account, record a check-in, add an appointment, change settings, or contact support. Technical and usage information is collected automatically through the Firebase software included in the App. We do not collect data from contacts, photos, cameras, microphones, precise location, or connected health platforms unless a future feature clearly asks for permission first.
4. How we use information
We use information to provide recovery tracking, timelines, reminders, insights, reports, account access, cloud backup and restoration; personalize the App based on your choices; maintain security; diagnose errors; understand aggregate feature use; respond to support requests; enforce our Terms of Use; and comply with law.
We do not use your health entries for advertising, sell your personal information, or use your entries to train artificial-intelligence models.
5. Local storage and cloud backup
The App stores your profile, check-ins, and appointments locally on your device. When Firebase is available, the App creates an anonymous account and stores a backup in Cloud Firestore under that account identifier. Linking an email address makes that backup recoverable after reinstalling the App or changing devices. An unlinked anonymous backup may become inaccessible if the App is removed or its local credentials are lost.
Firestore access rules are designed so an authenticated account can access only the records under its own user identifier. Do not share your password or device access with others.
6. Legal bases where applicable
Where the European Economic Area, United Kingdom, or similar law applies, we process information as necessary to perform our contract with you by operating the App; based on your consent where consent is requested, such as operating-system notification permission; for our legitimate interests in security, support, analytics, and reliability, balanced against your rights; and to meet legal obligations. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing.
7. When information is disclosed
Service providers: Google processes data for Firebase Authentication, Cloud Firestore, Firebase Analytics, and Firebase Crashlytics on our behalf. These providers may use subprocessors under their contractual and security obligations.
App stores and payments: if paid features are offered, Apple or Google processes purchases under its own privacy policy. We may receive product, transaction, and entitlement information, but we do not receive your full payment-card details.
Legal and safety: we may disclose information when reasonably necessary to comply with law, protect rights and security, investigate misuse, or respond to a valid legal request.
Business transfer: information may transfer as part of a merger, financing, acquisition, or sale, subject to this policy and applicable law.
We do not disclose your health information to advertisers.
Partner updates, reports, and exports: the App never sends your information to another person on its own. When you tap Send update to partner, Create PDF Report, or Export data, the App prepares that content on your device and hands it to your operating system's share sheet. You choose the recipient and the app that delivers it, and that app handles the content under its own terms and privacy policy. Nothing leaves your device until you complete that step.
8. Retention and deletion
We keep account and recovery data while your account or anonymous App installation remains active and as needed to provide the service. Local data remains until you use Delete account, clear the App data, or uninstall the App. Profile → Delete account deletes the local profile, check-ins, appointments, cloud records, and Firebase account associated with the current sign-in. Deletion is permanent and cannot be undone.
Firebase Crashlytics generally retains crash stack traces and associated identifiers for 90 days before removal begins. Analytics and service records may remain for the periods configured in Firebase or required for security, fraud prevention, legal compliance, dispute resolution, and enforcing agreements. De-identified or aggregated information that can no longer reasonably identify you may be retained.
9. Your choices and rights
You can review and change profile information in the App, turn reminders off, deny or revoke notification permission in device settings, sign out, and delete your account and associated recovery data in Profile. You may also contact us to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where those rights apply. We may need to verify your identity before completing a request. You may complain to your local data-protection authority.
The App does not currently provide an in-app control for Firebase Analytics. Where required by law, contact us about an analytics objection or deletion request.
10. Security
We use reasonable administrative and technical safeguards, including authenticated Firestore access controls and encryption offered by Firebase in transit and at rest. No storage or transmission system is completely secure, and we cannot guarantee absolute security. Protect your device, email account, and password, especially because the App contains sensitive information.
11. International processing
Mertapp and its service providers may process information outside your country. Firebase Authentication is operated from United States data centers, while other Firebase services may use global infrastructure. Where required, transfers rely on recognized safeguards such as adequacy decisions or contractual protections.
12. Age limitation
The App is intended for adults aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us so we can investigate and delete it.
13. Changes to this policy
We may update this policy to reflect changes to the App, law, or our practices. We will update the effective date and provide additional notice when required. Continued use after an update means the revised policy applies, subject to rights that cannot legally be waived.
14. Contact us
Mertapp is the operator responsible for the App. For privacy questions or requests, contact hezarfentech@gmail.com. Do not include urgent medical information in an email to support.