Consumer Health Data Privacy Policy

Effective date: July 18, 2026

Chart35 is designed so fertility observations stay on your device unless you choose encrypted Sync or provider sharing. We do not sell consumer health data, use it for advertising, or use geofencing around health-care facilities. This policy supplements the Chart35 Privacy Policy.

1. Consumer health data we collect

CategorySourceWhy we use it
Fertility observations, cycle dates, pattern settings, intercourse flags, and notesYou enter this on your deviceLocal charting. If you choose Sync, the device encrypts it before upload; the server cannot read the content.
Derived chart information such as cycle boundaries and peak-day marksCalculated on your device from your entriesDisplay and analyze your chart locally; include it in an encrypted backup if you choose Sync.
Filtered provider-share chartYou expressly create a share linkShow the selected read-only chart to anyone holding the time-limited link. Free-text notes are excluded; charted intercourse indicators remain in the share.
Account and encrypted-sync metadataYou provide account details; our server records sync time/statusAuthentication, encrypted backup, multi-device continuity, security, export, and deletion.
Billing relationship and subscription status, which may reveal an association with a fertility appYou select a plan; Stripe returns customer/subscription statusStart and manage Chart35 Sync, prevent duplicate subscriptions, enforce entitlement, send required notices, and maintain consent evidence.
App/site usage signalsYour browser, only after analytics opt-inAggregate product improvement. We do not send chart entries or user IDs to Google Analytics.

2. How consumer health data is shared

We share only what is necessary for a function you request:

We do not sell consumer health data, share it for cross-context behavioral advertising, combine it with data-broker profiles, or permit a processor to use it for an unrelated purpose.

3. Your choices and rights

Subject to applicable law, you may ask us to:

You can export local chart data, revoke sharing, and delete your account in Chart35 Settings. You may also email jacob@stephens.page with the subject “Consumer Health Data Request.” We may verify that you control the relevant account. We will respond within the period required by applicable law. If we deny a request, our response will explain why and how to appeal by replying with “Appeal.” You may contact the Washington State Attorney General if an appeal is denied.

4. Consent

Charting locally does not send observations to us. Creating an account and choosing Sync causes the device to upload end-to-end encrypted data. Creating a provider-share link is a separate action. Before Stripe Checkout, Chart35 presents a separate unchecked consent describing automatic renewal and the billing information sent to Stripe. You may withdraw future consent, but withdrawal does not affect processing already completed or records we must retain by law.

5. Security and retention

Synced chart content is encrypted on your device with AES-256-GCM before upload. Transport uses HTTPS. Passwords are hashed. Billing webhook signatures are verified, and Chart35 stores compact event references rather than full Stripe payloads. Account-linked health and entitlement records are deleted with the account. Stripe and legally required consent/transaction records may be retained for the periods described in the Privacy Policy.

6. Changes and contact

We will post material changes before collecting, using, or sharing additional categories of consumer health data and will obtain affirmative consent when required. Questions and requests: jacob@stephens.page.