Effective date: July 28, 2026
This privacy policy describes how the Chart35 mobile and web application (the “App”) collects, uses, stores, and shares your information. The App is operated by Jacob Stephens through Stephens Page LLC (the “Developer,” “we,” “us,” or “our”). Contact: jacob@stephens.page.
This policy is intentionally specific to what the App actually does. It is not a generic template.
The App is a fertility-cycle charting tool based on the Creighton Model FertilityCare™ System. All observations are stored on your device by default and never leave it unless you choose account sync or sharing. Synced observations are encrypted on your device before backup, and we cannot read them. Paid Chart35 Sync is processed by Stripe; Stripe receives billing and account information, never your observations or encrypted chart blob. For an eligible purchase link from the US Google Play app, Google Play receives a one-use reporting token and limited transaction/refund details, but not your Chart35 email, billing address, observations, or encrypted chart. The App contains no advertising. Self-hosted analytics loads only if you accept the cookie banner; no third party is involved.
analytics.stephens.page. No third party is involved and no cookie is set. It records the page visited, the referring site, and coarse device details such as browser, operating system, screen size, and country — never your observations or any other personal information. In-app navigation and session recording are both switched off, so no chart view, date, or account identifier reaches it. You can decline or revoke at any time via the in-app Cookie Policy page. This replaced Google Analytics 4; declining now also clears any _ga cookies it previously set.AD_ID).| Purpose | Data used |
|---|---|
| Provide the core charting functionality | Your observations, cycles, settings (stored locally) |
| Authenticate you across devices | Email, password hash, JWT cookie |
| Sync your data across your own devices | End-to-end encrypted observations, cycles, settings |
| Let you share a read-only chart with your practitioner | Filtered observations + cycles (the notes field is stripped) |
| Send transactional emails (verification, password reset, email-change confirmation, and security notices when you change your account email) | Email, first name |
| Start, manage, and verify a Chart35 Sync subscription | Email, billing address, plan, consent record, Stripe customer/subscription identifiers and status. When you change your Chart35 account email, we update the contact email on your Stripe customer record when billing is configured. |
| Launch and report an eligible US Google Play external-content purchase | One-use Play token; app package; external transaction identifiers; transaction/refund time, pre-tax amount, tax amount, currency, US tax-region code, recurring status, and test-purchase marker when applicable. We do not send Google Play your Chart35 email, billing address, payment method, observations, or encrypted chart. |
| Notify the Developer of new account creation | Email, first name (admin notification only) |
| Improve the App via aggregate analytics (opt-in) | Standard Umami page-view data (self-hosted, cookieless) |
| Diagnose crashes and stability issues | Anonymous Play Console crash logs (Google-side) |
We do not use your data for advertising, profiling, behavioral targeting, or any third-party marketing.
When you create an account, the App derives an AES-256-GCM encryption key from your password using PBKDF2 with a unique per-user salt. This key never leaves your device. Before observations are uploaded for backup, they are encrypted with this key. The server stores only the encrypted blob and an additional server-side encryption layer at rest. If you forget your password, your encrypted data cannot be recovered by us — the password reset flow will let you regain access to your account but the previously synced data will be lost.
Your provider-share link uses a separate filtered payload (with the notes field stripped) so a recipient can read your chart but cannot see your written notes.
| Vendor | Purpose | What they receive |
|---|---|---|
| Google Fonts | Web fonts | Standard HTTP referrer headers from page loads |
| Umami (self-hosted, analytics.stephens.page) | Anonymous usage stats — opt-in only | Page visited, referring site, and coarse device details. No cookie, no cross-site identifier, no in-app navigation, no session recording. Not a third party: it runs on our own server. |
| Resend | Sends account and billing transactional emails | Your email address, first name, and the email body |
| Stripe | Hosted subscription checkout, tax calculation/monitoring, receipts, and self-service billing | Your name, email, billing address, payment details, selected plan, Chart35 user reference, and subscription status. Stripe does not receive chart observations. |
| Let's Encrypt | TLS certificate issuer | Public DNS records only |
| Google Play Services and Google Play Developer API | App distribution, crash logs, eligibility/information screen for enrolled US external-content links, and required external transaction/refund reporting | Anonymous Play Console signals; for an eligible Android link-out, a one-use Play token plus app package, non-PII transaction IDs, transaction/refund amounts and times, currency, US tax-region code, and recurring/test status. Google does not receive chart observations, the encrypted chart blob, Chart35 email, billing address, or payment method from this reporting flow. |
We do not use Firebase, Crashlytics, Sentry, Mixpanel, PostHog, Amplitude, Segment, Facebook SDK, or any advertising network.
We do not sell or rent your data. We do not share data with third parties for marketing. The only situations in which your data is disclosed are:
You can, at any time:
If you are in the EEA, UK, or Switzerland, the lawful bases under GDPR Article 6 are:
Health information can be special-category data under GDPR. Where GDPR applies to processing by the Developer, we request explicit consent when required and provide the additional safeguard of end-to-end encryption. Local-only charting remains under your control on your device.
You have the right to access, rectify, erase, restrict, port, and object. You may also lodge a complaint with your local supervisory authority. Contact jacob@stephens.page to exercise these rights.
Stephens Page LLC, operated by Jacob Stephens, is the data controller for server-side Chart35 account and Sync processing.
California residents have the right to know what we collect (see Section 2), the right to delete, the right to correct, the right to opt-out of “sale” or “sharing” (we do not sell or share for cross-context behavioral advertising), and the right to non-discrimination. Email jacob@stephens.page to exercise these rights.
Because use of a fertility app and its billing relationship can reveal or permit an inference about health interests, we treat billing metadata conservatively. Our distinct Consumer Health Data Privacy Policy lists the health-data categories, sources, purposes, recipients, and request/appeal process. We do not sell consumer health data or use geofencing around health facilities.
The App is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with information, contact jacob@stephens.page and we will delete it.
Our server is currently hosted in the United States. If you use the App from outside the United States, your data will be transferred to and stored on infrastructure in the United States. For EEA/UK users, we rely on appropriate safeguards (Standard Contractual Clauses where applicable to sub-processors).
We may update this policy from time to time. Material changes will be announced in-app and the effective date above will be updated. Before collecting, using, or sharing additional consumer health-data categories or using them for additional purposes, we will disclose the change and obtain affirmative consent when required.