Last updated · 7 August 2026 · Version 1.1
Your data is health data. We treat it that way — every keystroke.
Ovaria is a product of Witz-u Pte Ltd and Epigenetics AI Limited (together the "Company", "we", "our", or "us"). Our registered address is 290 Orchard Road, #17-11 Paragon Medical Centre, Singapore 238859.
For the purposes of the Singapore Personal Data Protection Act 2012 ("PDPA"), Witz-u Pte Ltd and Epigenetics AI Limited are the organisations responsible for your personal data.
This policy explains what personal information we collect, how we use it, how we protect it, and the rights you have over it.
When you sign up, we collect your email address and, optionally, your name, date of birth, and profile details. If you sign in through Apple, Google or Singpass, we receive the account identifier those services provide us — no more.
Ovaria works because of the data you choose to share with it. We collect this data when you type it into the app, upload a file or photo, or start an on-device camera PPG reading. That can include:
Ovaria does not currently read data from Apple HealthKit, Android Health Connect, Google Fit, or third-party wearable services. If we add those integrations later, we will ask for your permission first and update this policy before collecting that data.
Sensitive category data. Menstrual, reproductive and biometric data are treated as "sensitive personal data" under the PDPA. We handle them with the elevated safeguards that classification requires.
We collect device type, operating system version, app version, crash and diagnostic logs, and rough approximation of location (country, not fine location) — needed to keep the app secure and stable.
If you write to us, we keep the message so we can reply and continue to improve the product.
We do not use your identifiable health data to train third-party AI models without your explicit, separate opt-in consent.
Under the Singapore PDPA we rely on:
We do not process your data for behavioural advertising, and we will not use it for a purpose you have not been told about.
Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). Servers are located in Tier-1 data centres in Singapore, with regionally appropriate storage for users in other jurisdictions.
Access to production data is limited to a small number of engineers, is logged, and requires multi-factor authentication.
We hold ourselves to the standards of the Singapore PDPA and the Hong Kong PDPO. Independent SOC 2 Type II certification is on our 2026 roadmap.
We do not sell your personal data. Ever. That includes selling for the purpose of behavioural advertising, insurance underwriting, or any form of health-data brokerage.
We share limited data only with:
A current list of our data processors is available on request.
Where your data leaves the country you use the app in, we rely on Standard Contractual Clauses (for EEA transfers), UK International Data Transfer Agreements (for UK transfers), and equivalent instruments where relevant, ensuring the same protection travels with your data.
We keep your account data for as long as your account is active, plus a short grace period so you can restore it if you change your mind.
Health data is retained for the life of your account and deleted within 30 days of account deletion, other than de-identified aggregates that cannot be traced back to you.
Some data (such as transaction records) must be kept longer to satisfy tax and financial-reporting law.
You have the right to:
All of the above are available in-app under Settings › Privacy › My Data. Or you can write to us at the address below and we'll action your request within 30 days.
Our website uses cookies strictly necessary to deliver the site, and — with your consent — a small number of analytics cookies to understand how visitors reach us. We do not use advertising cookies or cross-site trackers. You can manage your preferences at any time via the cookie banner on our website.
Ovaria is designed for adults aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, please contact us and we will remove it.
If we make material changes to this policy, we will notify you in-app and by email at least 30 days before they take effect. The most current version is always available at this URL, with the last-updated date at the top of the page.
For any privacy question, data-subject request, or complaint, please write to our Data Protection Officer: