๐ŸŒ™

Privacy Policy

myCrescent โ€” Sickle Cell Tracker

Last updated: 30 April 2026 ยท Version 2.2
myCrescent is built for people living with sickle cell disease. Because we process health information โ€” one of the most sensitive categories of personal data under UK law โ€” we want to be completely transparent about what we collect, why, where it goes, and your rights over it.
The short version: Your health data is stored on your device and securely synced to your account in the cloud. It is encrypted in transit and at rest, protected by your authentication credentials, and is not accessible to anyone outside the service providers listed in this policy, who process it only to deliver the service. We never share, sell, or use your health data for advertising. You can export or delete everything at any time.

1. Who we are (data controller)

The data controller responsible for your personal data is:

Rayscent Ltd (trading as "myCrescent")

Company number: 17120455

Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

ICO registration: ZC117860

Contact: privacy@mycrescent.app

Rayscent Ltd is registered with the UK Information Commissioner's Office (ICO) and pays the statutory data protection fee as required by the Data Protection (Charges and Information) Regulations 2018.

2. What data we collect

2.1 Account data

2.2 Health data ("special category data" under UK GDPR Article 9)

The following fields are treated as special category data and are subject to stricter legal protection:

2.3 Technical data

2.4 What we do not collect

3. Why we process your data (lawful basis)

Under UK GDPR we must identify a lawful basis for every category of processing. Because health data is special category data, we need a basis under both Article 6 and Article 9:

PurposeArt. 6 basisArt. 9 basis (health data)
Creating and operating your account6(1)(b) โ€” contractn/a
Storing and syncing your health tracker data6(1)(a) โ€” consent9(2)(a) โ€” explicit consent
Running the SicklySense AI assistant6(1)(a) โ€” consent9(2)(a) โ€” explicit consent
Processing premium payments6(1)(b) โ€” contractn/a
Sending service emails (magic links, receipts)6(1)(b) โ€” contractn/a
Security, fraud prevention, rate limiting6(1)(f) โ€” legitimate interestsn/a
Product analytics and frontend crash/error monitoring6(1)(a) โ€” consent9(2)(a) โ€” explicit consent

Your explicit consent for health data processing is obtained through the in-app consent flow before synced health-data processing continues. Some accounts may still see the current Settings-based consent controls while the dedicated first-open consent screen rollout is completed. You can withdraw consent at any time from Settings โ†’ Privacy โ†’ Consent, which stops new cloud sync of health data and disables in-app analytics plus crash monitoring for your signed-in session. If you also want your account and stored data erased, you can separately choose deletion from the account controls.

4. Who we share data with (processors)

We use the following carefully selected third-party processors. Each one has a data processing agreement with Rayscent Ltd and processes data only on our documented instructions.

ProcessorPurposeData sharedLocationTransfer mechanism
SupabaseCloud database and authenticationAccount + health dataEU (Frankfurt)Within UK/EEA โ€” no transfer
VercelApp hosting, serverless functions, KV storeEmail, session tokens, push subscriptions, encrypted medication namesEU edge + USUK IDTA / EU SCCs
PostHogProduct analytics and frontend crash/error monitoringRedacted usage events, crash diagnostics, and standard request metadataEU cloudUK IDTA / EU SCCs
AnthropicSicklySense AI assistantYour chat messages only (no name, email, or profile attached)USUK IDTA / EU SCCs
StripePayment processingEmail, plan, payment amount (no card data seen by us)EU + USUK IDTA / EU SCCs
ResendTransactional email (magic links, receipts)Email address + message contentUSUK IDTA / EU SCCs
Google / Apple / MozillaPush notification deliveryAnonymous push endpoint + encrypted notification payloadUSUK IDTA / EU SCCs
Google / Apple (OAuth only)Optional sign-inEmail + name from your Google/Apple accountUSUK IDTA / EU SCCs

We do not share your data with advertisers, data brokers, or marketing networks under any circumstances.

5. SicklySense AI assistant

The SicklySense AI assistant is powered by Anthropic's Claude model. When you use it:

The AI assistant is opt-in: a separate consent checkbox is shown before you can use it for the first time. You can disable it at any time from Settings โ†’ Privacy.

6. International transfers

Some of our processors (Anthropic, Stripe, Resend, Vercel US edge, push providers) are based in the United States. When personal data leaves the UK, we rely on one of the following legal safeguards:

You can request a copy of the safeguards in place for any specific transfer by emailing privacy@mycrescent.app.

7. How long we keep your data (retention)

Data typeRetention period
Account data (email, auth)For as long as your account is active, then 30 days after deletion request
Health data (cloud copy)Deleted within 30 days of account deletion request
Health data (on your device)Until you uninstall the app or clear storage
Magic link tokens15 minutes
Session tokens30 days (renewed on use)
Premium activation codesUntil redeemed, then 12 months for support
Payment records (Stripe metadata)7 years (UK tax / accounting law requirement)
Redacted analytics and crash logsUp to 24 months

8. Your rights under UK GDPR

You have the following rights over your personal data. We will respond to requests within one calendar month.

To exercise any of these rights, email privacy@mycrescent.app. We will verify your identity before releasing any data. Requests are free unless clearly unfounded or excessive.

9. How to complain

If you are unhappy with how we handle your data, please contact us first at privacy@mycrescent.app โ€” we will always try to resolve concerns directly.

You also have the right to complain to the UK Information Commissioner's Office:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk/make-a-complaint

10. Data security

We take the security of your health data seriously. Our technical and organisational measures include:

11. Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the risk is high, we will also notify you directly by email without undue delay.

12. Children and young people

Sickle cell disease often begins in childhood, so we recognise that children and their carers may want to use myCrescent.

13. Cookies

myCrescent does not use tracking cookies, advertising cookies, or cross-site fingerprinting. The app uses browser localStorage and IndexedDB only to hold your data locally. PostHog analytics and monitoring are configured with in-memory identity only rather than persistent cookies.

14. Changes to this policy

We will update this policy when our processing changes or when the law requires it. The "last updated" date at the top will change and, for significant changes (new processors, new purposes, changes to retention), we will notify you in the app and by email before the change takes effect.

15. Contact us

For any privacy question or to exercise your rights:

Rayscent Ltd is a company registered in England and Wales under company number 17120455. ICO registration ZC117860.