Floriva Privacy Policy
How the Floriva website handles the limited information it collects, and what the Floriva app is designed to keep on your device.
Effective date: May 28, 2026. This policy explains how Floriva handles personal information on the Floriva website at floriva.app. The Floriva mobile app is described separately below. Because period, fertility, and reproductive-health information is among the most sensitive personal data there is, we have tried to describe our actual practices plainly rather than make broad promises.
Who we are
Floriva is a privacy-focused period and reproductive-health product operated by Ventora Labs, a Wyoming corporation, located at Sheridan, Wyoming. For any privacy question, or to exercise your rights, contact us at [email protected]. References to "Floriva," "we," or "us" mean that operating entity.
What the website collects
The floriva.app website is primarily an informational and content site. We do not run product analytics, advertising SDKs, tracking pixels, social-media trackers, session replay, or third-party feedback widgets on the site. The only personal information we collect through the website is what you choose to give us when you request a free resource (a "lead magnet"): the email address you submit, which resource you requested, and the site page you requested it from.
Information collected automatically
- When you submit the resource form, our hosting provider (Cloudflare) processes your IP address and a one-way (SHA-256) hash of your email so we can rate-limit abuse and spam. The IP-derived value and email hash are stored only for that anti-abuse purpose.
- We record email-delivery events for the resource you requested (for example, that a delivery was sent, duplicated, suppressed, or failed) so we can operate the delivery reliably and respond to your requests.
- If error monitoring is enabled, our error-monitoring provider may receive limited technical diagnostics about website errors. It is configured without session replay and without sending personal information by default. It does not receive reproductive-health information.
- Cloudflare, as our hosting and network provider, processes standard server and security logs (such as IP address and request metadata) to serve and protect the site.
What we do NOT collect on the website
The website does not collect cycle history, period dates, symptoms, moods, fertility or TTC (trying-to-conceive) observations, birth-control details, pregnancy status, or any other in-app reproductive-health logs. We do not ask for your name, phone number, payment details, or precise geolocation on the website, and we do not use geofencing.
Why we use it and our legal bases (GDPR)
- To send the free resource you asked for and prevent duplicate or abusive requests: this is necessary to perform the service you requested, and our legitimate interest in operating the site securely (GDPR Art. 6(1)(b) and 6(1)(f)).
- If you are added to a follow-up email sequence about Floriva, we rely on your consent or, where permitted, our legitimate interest, and every email includes an unsubscribe link (GDPR Art. 6(1)(a)/(f); PECR/ePrivacy where applicable).
- Email addresses you submit are not health data, but we treat reproductive-health interest contextually with care. We do not collect special-category health data through the website (GDPR Art. 9).
Third parties and sub-processors
- Cloudflare - website hosting (Cloudflare Pages), serverless functions, the database that stores resource-request records (Cloudflare D1), file storage for the resources themselves (Cloudflare R2), the Turnstile anti-bot check on forms, and email delivery (Cloudflare Email Service) for the resource-delivery and follow-up emails to the address you submit.
- Error-monitoring provider - error and performance monitoring for the website (no session replay; personal-information sending disabled by default).
- We do not sell your personal information, and we do not share it with advertisers or data brokers.
International transfers
Our providers (including Cloudflare, plus our error-monitoring provider) may process data on infrastructure located in the United States and other countries. Where personal data of individuals in the EU/UK is transferred outside those regions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, as offered by those providers.
Data retention
We keep resource-request records (email address, requested resource, source page, and delivery events) for as long as needed to deliver the resource, prevent duplicate requests, manage your subscription status, and respond to privacy or deletion requests. Anti-abuse records (including the email hash and IP-derived value) are short-lived and used only for rate-limiting. If you unsubscribe or ask us to delete your record, we will do so subject to limited legal-retention needs.
Security
Resource downloads are delivered through expiring, signed links, and forms are protected by an anti-bot check (Cloudflare Turnstile) and rate-limiting. The website is served over HTTPS. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your privacy rights
- GDPR / UK GDPR: you may request access, correction, deletion, restriction, portability, and objection, and you may withdraw consent at any time. You can lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): you may request to know, access, delete, and correct your personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined.
- Washington My Health My Data Act, Nevada SB370, and similar consumer-health-data laws: to the extent any information we hold is treated as consumer health data, you may request to know what is collected and shared, access it, withdraw consent, and request deletion. We do not sell consumer health data and do not use geofencing around health facilities.
- To exercise any right, email [email protected], ideally from the address you used. We will verify and respond within the timeframe the applicable law requires.
Children
The Floriva website is not directed to children under 13 (or under the minimum age in your jurisdiction), and we do not knowingly collect their personal information through the website. If you believe a child has provided information, contact [email protected] and we will delete it.
Cookies and tracking
The website does not use advertising or analytics cookies or cross-site tracking. Cloudflare may set strictly necessary cookies or tokens for security and bot mitigation (for example, Turnstile). The follow-up email service may use standard email open/click measurement; unsubscribe links are included in those emails.
The Floriva mobile app
The Floriva app is a separate product reached through the current configured store links. It is designed so that cycle history, period dates, symptoms, moods, fertility/TTC observations, notes, and birth-control details remain local-first, with no account required for core tracking and no readable central cycle database. Optional encrypted sync sends only ciphertext Floriva cannot read. The app's full in-app privacy disclosures govern your use of the app.
Changes to this policy
We may update this policy as the website or our providers change. We will update the effective date above and, for material changes, provide a more prominent notice where appropriate.
Contact
Questions, requests, or complaints: [email protected]. Postal contact: Ventora Labs, a Wyoming corporation, Sheridan, Wyoming.