Legal
Privacy Policy
Effective: August 25, 2026 · Last updated: August 25, 2026
This Privacy Policy explains how Alexandra Schneider and Anusha Saraf, operating as LOUARA (“LOUARA,” “we,” “us,” or “our”), collect, use, and protect your personal information when you use the LOUARA application and related services (the “Service”). Because we process health-related information, we treat your data with a correspondingly high standard of care.
1. Who we are
LOUARA is operated by Alexandra Schneider and Anusha Saraf, as individual co-founders and joint data controllers. LOUARA is a menstrual-cycle guidance app: it helps you understand how your body changes across your cycle and turns that into simple, everyday guidance. When you connect a wearable such as WHOOP, LOUARA uses the data you already collect to add cycle-aware context to it.
For privacy questions or to exercise your rights, contact us at hello@louara.com.
2. Scope
This policy applies to all users of the Service. It describes the information we collect directly from you, from your device, and from third-party services you choose to connect, including WHOOP.
3. Information we collect
a. Information you provide
Account details (name, email), cycle information you enter (dates, phase, self-reported inputs), and messages you send to our in-app assistant.
b. Health data from connected sources
With your permission, we access health metrics from Apple HealthKit and wearable devices you connect. This may include sleep, heart rate, heart-rate variability (HRV), body-temperature data, activity, and related signals.
c. WHOOP data
If you choose to connect your WHOOP account, we access WHOOP data through the WHOOP API under the scopes you authorize. This may include recovery, strain, sleep, physiological cycle, workout, HRV, resting heart rate, and profile data. See Section 5.
d. Environmental data
We collect environmental context derived from your approximate location, such as UV index, humidity, and weather, to generate cycle-aware forecasts. We use approximate rather than precise location for this purpose.
e. Usage and device data
App interactions, device identifiers, and diagnostic and log data used to operate and improve the Service.
We do not knowingly collect data from anyone under 18. See Section 12.
4. How we use your information
We use your information to provide the core Service (cycle-aware guidance); to power our in-app assistant; to maintain, secure, troubleshoot, and improve the Service; to communicate with you; and to comply with legal obligations.
How our forecasting works
Your data may be processed through automated systems—a retrieval-augmented generation (RAG) pipeline and large-language-model components operated by a third-party AI service provider—and stored in a vector database, to produce the personalized outputs you see. That provider processes your data only to generate your response and does not use it to train its own models.
We do not sell data that identifies you, use your data for advertising, or use data from connected sources such as WHOOP or Apple HealthKit to train or improve our own machine-learning models. We use connected-source data only to generate guidance for you when you request it; it is never added to a training dataset or fed back into a learning pipeline.
5. WHOOP integration
Our WHOOP integration is designed to add value for WHOOP members by placing the recovery, sleep, and strain data you already track into the context of your menstrual cycle.
We access WHOOP data only after you authorize the connection through WHOOP's OAuth 2.0 consent screen, and only for the scopes you approve. We use WHOOP data solely to provide LOUARA's features to you, the connecting member. We do not sell WHOOP data, use it for advertising, or use it to train or improve our models.
We store WHOOP-derived data on infrastructure logically separated by data source and user account, so it is never accessible to any process used for hardware or model development. We retain it as described in Section 8.
You can revoke LOUARA's access at any time within the LOUARA app or directly in your WHOOP account settings. On revocation, we stop accessing new WHOOP data and delete or de-identify previously retrieved WHOOP data in accordance with Section 8. Our use of WHOOP data complies with WHOOP's applicable developer and API terms.
6. Legal bases for processing (GDPR / UK GDPR)
Where the GDPR applies, we rely on your explicit consent for processing health and other special-category data, including WHOOP, HealthKit, and cycle data; performance of a contract to deliver the Service you request; and our legitimate interests in securing and improving the Service. You may withdraw consent at any time (see Section 9).
8. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. When you close your account or disconnect a source, we delete or de-identify the associated data within 30 days, unless a longer period is required by law.
9. Your rights and choices
Depending on your location, including under the GDPR and California's CCPA/CPRA, you may have the right to access, correct, delete, or export your data; withdraw consent; object to or restrict certain processing; and disconnect a linked source such as HealthKit or WHOOP at any time. To exercise these rights, contact us using the details in Section 14. We will not discriminate against you for exercising them. You may also disconnect wearable sources directly in the respective app.
10. Data security
We use administrative, technical, and organizational safeguards, including encryption in transit and at rest, access controls, and data segregation by source and user to protect your information. No system is perfectly secure, but we work to protect health data at an elevated standard. If a security incident affects your data, we will notify you and, where WHOOP data is involved, WHOOP, without undue delay and consistent with applicable law and WHOOP's API Terms of Use.
11. International data transfers
We may process and store information in countries other than yours, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses for those transfers.
12. Children's privacy
The Service is intended for users 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the revised version with a new effective date and, where required, notify you.
14. Contact us
Alexandra Schneider and Anusha Saraf, operating as LOUARAhello@louara.com
Alexandra Schneider
1178 Broadway
3rd Floor #1000
New York, NY 10001