How We Handle Your Data

Transparency about what we collect, how we use it, and how you stay in control.

Built Different

Romy is purpose-built for women's health — not a generic AI with a health skin. This means every design decision prioritizes your safety and privacy.

  • No data selling. Your health data is never sold, licensed, or shared with advertisers.
  • No model training on your data. Your personal conversations are not used to train AI models.
  • Research is opt-in and anonymized. If you choose to contribute to research, data is fully anonymized first.

What We Collect → Process → Share

Collect

  • Chat messages
  • Health logs you enter
  • Profile info (age, conditions)
  • Community posts
  • Basic usage analytics

Process

  • AI generates responses
  • Patterns detected from logs
  • Long-term memory summaries
  • Artifact generation
  • Community insights (aggregated)

Share

  • Google Gemini (for AI responses)
  • Anonymized research (opt-in only)
  • Nothing else. Ever.

Your Controls

You have full control over your data at all times.

Technical Safeguards

  • Firebase Auth — secure Google OAuth and email/password authentication
  • Firestore Security Rules — server-enforced access control ensures you can only read your own data
  • App Check — protects API endpoints from unauthorized access and bots
  • Anonymization — research data is hashed and stripped of personally identifiable information
  • HTTPS Everywhere — all data in transit is encrypted via TLS

Questions?

Read our full Privacy Policy for legal details, or reach out at hello@romyhealth.co.

We use cookies for authentication and to improve your experience. Learn more