Privacy Policy
Last updated: April 2026 · Effective date: April 2026
Your health data is yours. Embya is built on a privacy-first architecture: your IVF cycle data, hormone values, and journal entries are stored on your device and synced exclusively through Apple's iCloud / CloudKit. We do not operate a backend server. We cannot read, sell, or share your personal health information.
⚕️ Medical Disclaimer. Embya provides informational support only. Nothing in this app constitutes medical advice, diagnosis, or treatment. Always follow your clinic's protocol and consult your reproductive endocrinologist for medical decisions.
1. Who We Are
Embya ("we," "our," "us") is an iOS application developed by Kurtuluş Ahmet TEMEL. If you have any questions about this Privacy Policy, you can contact us at:
Email: support@kurtulusahmet.com
2. What Data Embya Collects
2.1 Data You Enter Directly
| Data Type | Examples | Where Stored |
| IVF Cycle Information |
Cycle type, start date, retrieval date, transfer date, outcome |
Device + iCloud (CloudKit) Encrypted |
| Hormone Values |
E2, LH, FSH, Progesterone, HCG, follicle count, endometrium thickness |
Device + iCloud (CloudKit) Encrypted |
| Medications |
Medication name, dose, schedule, log of taken doses |
Device + iCloud (CloudKit) Encrypted |
| Journal Entries |
Daily mood score (1–5), free-text journal, tags, AI response |
Device + iCloud (CloudKit) Encrypted |
| Profile Information |
First name (optional), age (optional), clinic name (optional), journey state |
Device + iCloud (CloudKit) Encrypted |
| Protocol Steps |
Named milestones, dates, completion status |
Device + iCloud (CloudKit) Encrypted |
2.2 Data Collected Automatically
| Data Type | Purpose | Provider |
| App usage events |
Understanding which features are used most (e.g., "hormone_entry_added"). Events do not include your health values. |
Firebase Analytics (Google) |
| Crash reports |
Diagnosing and fixing app crashes. Reports include device model, iOS version, and stack trace. No health data. |
Firebase Crashlytics (Google) |
| Purchase & subscription status |
Managing your Premium subscription and restoring purchases. |
RevenueCat |
3. How We Use Your Data
- To provide core app functionality — displaying your IVF timeline, hormone charts, medication schedule, and journal history.
- To generate AI-powered insights — when you request hormone interpretation or journal support, relevant data is sent to the Claude AI API (Anthropic). See Section 5 for details.
- To send local notifications — medication reminders and milestone alerts you set up are processed entirely on your device. We do not use push notifications for marketing.
- To improve the app — anonymized, aggregated analytics help us prioritize features and fix bugs.
- To manage your subscription — verifying Premium access via RevenueCat.
4. iCloud / CloudKit Sync
Your health data syncs across your Apple devices through Apple's CloudKit infrastructure. This means:
- Data is stored in your personal iCloud account, not on Embya's servers.
- Embya developers cannot access your iCloud data.
- Apple encrypts CloudKit data in transit and at rest. Apple's privacy policy governs this storage: apple.com/legal/privacy
- You can delete all synced data at any time by deleting your Embya data from iCloud in your iPhone Settings.
5. AI Features & Anthropic / Claude API
When you use AI-powered features (hormone interpretation, journal emotional support, Ask AI), the following data is sent to Anthropic's Claude API:
- Your hormone values and stimulation day context (for hormone interpretation)
- Your journal entry text (for emotional support responses)
- Your question text (for Ask AI)
- General context such as your journey stage and age range (if provided)
What is NOT sent: Your name, email, Apple ID, device identifiers, or any data not directly relevant to the AI query.
API calls are encrypted in transit (HTTPS/TLS). The Claude API key is encrypted using AES-GCM-256 and is never stored in plaintext in the app binary or logs.
Anthropic's data usage policy applies to API usage: anthropic.com/privacy
AI responses are generated for informational and emotional support purposes only. They do not constitute medical advice.
6. Third-Party Service Providers
Google Firebase (Analytics & Crashlytics)
Anonymized app usage analytics and crash reporting. No health data is included in events or crash reports.
RevenueCat
Manages in-app purchase verification and subscription status. RevenueCat receives your anonymized app user ID and purchase receipts — no health data.
Anthropic (Claude AI API)
Processes AI queries when you request hormone interpretation, journal support, or Ask AI responses. Only the data directly needed for each request is sent.
Apple (CloudKit & App Store)
Handles iCloud data sync and in-app purchase processing. Apple's privacy framework governs these interactions.
7. Sensitive Health Data
IVF-related data — including hormone values, cycle outcomes, and emotional journal entries — is considered sensitive health information. We treat it accordingly:
- Health data is never used for advertising, profiling, or sold to any third party.
- Health data is never included in analytics events. Events are limited to anonymized behavioral signals (e.g., which screen was viewed).
- AI queries contain the minimum data needed to generate a useful response.
- Crash reports never include your health values, journal text, or personally identifiable health information.
8. Data Retention & Deletion
Because Embya uses a backendless architecture:
- Your device data — deleted when you uninstall the app or reset the app's data.
- iCloud data — delete via Settings → [Your Name] → iCloud → Manage Account Storage → Embya → Delete Data.
- Firebase Analytics — anonymized events are retained per Google's standard retention policy (14 months by default). We cannot link these events to you as an individual.
- Crashlytics reports — retained for 90 days per Firebase policy.
- Anthropic (Claude API) — API inputs/outputs are governed by Anthropic's data retention policy. We do not store AI conversations on our servers.
- RevenueCat — purchase records are retained as required for legal and refund purposes.
To request deletion of any data associated with your account, email us at support@kurtulusahmet.com.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of any personal data we hold about you.
- Correction — update or correct inaccurate data (most data is directly editable in the app).
- Deletion — request erasure of your data from all systems we control.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing where we rely on legitimate interests.
- GDPR (EU/EEA users) — you have rights under the General Data Protection Regulation. Legal basis for processing: contract performance (core app features), legitimate interests (analytics), and consent (AI features).
- KVKK (Turkish users) — you have rights under the Kişisel Verilerin Korunması Kanunu. You may exercise these rights by contacting us at the address below.
- CCPA (California users) — you have the right to know, delete, and opt-out of sale of personal information. We do not sell personal information.
To exercise any of these rights, contact us at support@kurtulusahmet.com. We will respond within 30 days.
10. Children's Privacy
Embya is intended for adults who are undergoing or considering IVF treatment. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has used the app, please contact us immediately.
11. Security
- All data transmitted to third-party APIs is encrypted via TLS/HTTPS.
- The Claude API key is stored encrypted at rest using AES-GCM-256 and decrypted only in memory — it is never logged or written to disk.
- iCloud data is encrypted by Apple both in transit and at rest.
- We do not collect or store passwords.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through the app or by updating the "Last updated" date above. Continued use of Embya after changes constitutes your acceptance of the updated policy.
13. Contact
For any questions, concerns, or data requests regarding this Privacy Policy:
Kurtuluş Ahmet TEMEL
Email: support@kurtulusahmet.com
Website: kurtulusahmet.com