Effective date: July 18, 2026
Chart35 is designed so fertility observations stay on your device unless you choose encrypted Sync or provider sharing. We do not sell consumer health data, use it for advertising, or use geofencing around health-care facilities. This policy supplements the Chart35 Privacy Policy.
| Category | Source | Why we use it |
|---|---|---|
| Fertility observations, cycle dates, pattern settings, intercourse flags, and notes | You enter this on your device | Local charting. If you choose Sync, the device encrypts it before upload; the server cannot read the content. |
| Derived chart information such as cycle boundaries and peak-day marks | Calculated on your device from your entries | Display and analyze your chart locally; include it in an encrypted backup if you choose Sync. |
| Filtered provider-share chart | You expressly create a share link | Show the selected read-only chart to anyone holding the time-limited link. Free-text notes are excluded; charted intercourse indicators remain in the share. |
| Account and encrypted-sync metadata | You provide account details; our server records sync time/status | Authentication, encrypted backup, multi-device continuity, security, export, and deletion. |
| Billing relationship and subscription status, which may reveal an association with a fertility app | You select a plan; Stripe returns customer/subscription status | Start and manage Chart35 Sync, prevent duplicate subscriptions, enforce entitlement, send required notices, and maintain consent evidence. |
| App/site usage signals | Your browser, only after analytics opt-in | Aggregate product improvement. We do not send chart entries or user IDs to Google Analytics. |
We share only what is necessary for a function you request:
We do not sell consumer health data, share it for cross-context behavioral advertising, combine it with data-broker profiles, or permit a processor to use it for an unrelated purpose.
Subject to applicable law, you may ask us to:
You can export local chart data, revoke sharing, and delete your account in Chart35 Settings. You may also email jacob@stephens.page with the subject “Consumer Health Data Request.” We may verify that you control the relevant account. We will respond within the period required by applicable law. If we deny a request, our response will explain why and how to appeal by replying with “Appeal.” You may contact the Washington State Attorney General if an appeal is denied.
Charting locally does not send observations to us. Creating an account and choosing Sync causes the device to upload end-to-end encrypted data. Creating a provider-share link is a separate action. Before Stripe Checkout, Chart35 presents a separate unchecked consent describing automatic renewal and the billing information sent to Stripe. You may withdraw future consent, but withdrawal does not affect processing already completed or records we must retain by law.
Synced chart content is encrypted on your device with AES-256-GCM before upload. Transport uses HTTPS. Passwords are hashed. Billing webhook signatures are verified, and Chart35 stores compact event references rather than full Stripe payloads. Account-linked health and entitlement records are deleted with the account. Stripe and legally required consent/transaction records may be retained for the periods described in the Privacy Policy.
We will post material changes before collecting, using, or sharing additional categories of consumer health data and will obtain affirmative consent when required. Questions and requests: jacob@stephens.page.