Privacy Policy
Last updated: September 6, 2026
ATTORNEY REVIEW: Confirm the effective date, and confirm whether this policy should be dated forward (posted with a future effective date) so existing waitlist subscribers get advance notice of a material change. See "Changes to this policy."
We built this for people who are already dealing with enough. So here is the short version, first, in plain words.
The short version
- You can get a cost estimate without giving us your name, your email, or an account. In the free flow, your answers stay in your own browser. They are not sent to us.
- We never sell your information, and we never share it for advertising. Not for money, not for "analytics partnerships," not for anything.
- There are no ad pixels, no trackers, and no session recording on this site. No Google Analytics, no Meta pixel, no TikTok, no Hotjar, no FullStory, no Segment.
- If you buy a Full Guide or join the Ledger waitlist, we store what you gave us, and you can delete it in one click.
- If you upload documents, we pull out the numbers we need and delete the original file.
- We are not a doctor's office, a clinic, or an insurance company. That means HIPAA does not cover us. Other laws do. We explain which ones below, because it matters.
1. Who we are
Halden is operated by Halden, a [STATE] [ENTITY TYPE], at [MAILING ADDRESS].
Questions, requests, or complaints: privacy@[DOMAIN].
ATTORNEY REVIEW: Fill in the entity, state of formation, and a real mailing address. Several state health-data laws and the FTC Health Breach Notification Rule assume a physical address for notices. Confirm whether a registered agent address is acceptable here or whether a street address is required.
2. Why HIPAA does not apply, and what does
People assume that anything touching health is "HIPAA protected." That is not how HIPAA works.
HIPAA covers health plans, most health care providers who bill electronically, health care clearinghouses, and the vendors who handle data on their behalf. We are none of those. You are not our patient. We do not bill your insurer. We do not treat you. So HIPAA's rules do not apply to us. You will never see us claim compliance with HIPAA, because that claim would be false.
It also matters that in June 2025 a federal court struck down, nationwide, the HIPAA rule that had added special protections for reproductive health information. So even for the clinics and insurers HIPAA does cover, that extra layer is gone.
Here is what actually governs us:
| Law | What it means for you |
|---|---|
| FTC Health Breach Notification Rule (as amended, effective July 29, 2024) | We are the kind of online health service this rule covers. If your health information is disclosed to anyone without your permission — including to an advertising company — that counts as a breach, and we must tell you within 60 days, tell the FTC, and in larger incidents tell the media. |
| FTC Act, Section 5 | If we say we protect your data and then don't, that is an illegal deceptive practice. The FTC has enforced exactly this against GoodRx, BetterHelp, Premom, and Flo — all for sending health data to advertising platforms. |
| Washington My Health My Data Act | If you are in Washington, you get specific rights over your "consumer health data," and we must publish a separate policy explaining them. We have: see our Consumer Health Data Privacy Policy. Washingtonians can sue us directly for violations. |
| California CMIA, as amended by AB 254 (effective Jan. 1, 2024) | California treats information about fertility and plans to conceive, collected by a reproductive-health digital service, as protected medical information. We do not disclose it without your written authorization. |
| California Consumer Privacy Act (CCPA/CPRA) | Health information is "sensitive personal information." You get rights to know, delete, correct, and limit. We do not sell or share it. |
| Nevada SB 370 (effective March 31, 2024) | Nevada requires your consent before we collect or share consumer health data, and bans using geofencing around health facilities. We don't geofence anything. |
| Connecticut Data Privacy Act, including its consumer-health-data provisions and the amendments effective July 1, 2026 | Consumer health data is sensitive data. Consent first. |
| Other state privacy laws | Colorado, Oregon, Texas, Virginia, and others treat health data as sensitive. We apply the strictest rule to everyone, everywhere, rather than sorting people by state. |
ATTORNEY REVIEW: Confirm the analysis that the product is a "vendor of personal health records" or "PHR related entity" under the amended HBNR given that (a) we take user-entered health information and (b) in the paid Ledger tier we ingest EOBs and clinic bills, which are records originating from a health care provider or health plan. If we are covered, we owe an actual breach-notification runbook, not just a policy sentence.
Decision made 2026-09-06 (founder, not counsel): treat this as covered — build as if AB 254 applies rather than argue we're outside its "reproductive or sexual health digital service" definition. Lower risk if the classification question is ever actually litigated (already compliant either way), at the cost of more consent friction. Concretely still open, and this is genuinely a lawyer's job, not a best guess: CMIA authorization forms have prescribed content and formatting — not just a checkbox — and getting that wrong by improvising it ourselves could read worse than not trying. Section 1 of consent-strings.md (consent to process) is the one that needs reworking into that shape before launch; don't treat this policy decision as having already solved the drafting.
ATTORNEY REVIEW: Confirm we do not trip any state law by describing appeal rights — see the Terms of Service flags on unauthorized practice of law and insurance adjuster/producer licensing.
3. What we collect
If you just use the free planner
Nothing goes to our servers — unless you choose to ask Halden a question.
Your answers — your state, employer size, age band, diagnosis flags, treatment path, any clinic quote or deductible you type in — live in your own browser's session storage. Close the tab and they are gone. We do not have a copy.
The one exception is the "Ask Halden" companion. If you check its consent box and ask a question, the answers you've entered so far and your question are sent to our server and, for that single request only, to our AI vendor, so Halden can answer from your actual numbers instead of guessing. We do not store your answers or your question anywhere — it is not written to a database, because the free planner does not have one — and the vendor's contract with us forbids retaining it past the request or training on it. We do keep a short record that consent was given (which version of the consent text, and when) in our ordinary 30-day server logs — not your answers or your question, just that the box was checked. Asking Halden is optional; the rest of the planner works identically whether you use it or not. See content/legal/consent-strings.md §3c for the exact consent copy and its one-click withdrawal.
The only thing our systems see otherwise is what any web server sees when you load a page: your IP address, a timestamp, the page you asked for, and your browser type. We use a first-party, cookieless analytics setup that counts page views without following you and without building a profile of you.
ATTORNEY REVIEW: This section (and §10's AI vendor paragraph below) describes a founder decision to ship Ask Halden live in the free flow without waiting for review — see
docs/products/ASK_HALDEN.mdfor the full reasoning. Confirm the consent model (checkbox once per browser session, not re-shown per step) is adequate "specific" and "unambiguous" consent under MHMDA before this is relied on past an initial launch.
If you buy a Full Guide
To create and store your plan, we collect:
- The answers you already gave the planner (state, employer size band, plan type, carve-out vendor, age band, relationship and definition-of-infertility flags, prior treatment counts, diagnosis flags, treatment path, and any numbers you typed).
- Your email address, so we can send you the link to your plan.
- A payment confirmation from Stripe. Stripe processes the card. We never see or store your full card number. We receive a transaction ID, the last four digits, and whether it succeeded.
If you join the Ledger waitlist
Your email address, the date, and which consents you gave.
If you upload documents (paid Ledger tier)
Bills, Explanation of Benefits, denial letters, or clinic statements you choose to send us. See "Documents" under retention below — this is the part we handle most carefully.
4. What we work out about you
Being straight about this matters more than the collection list.
From what you tell us, our software infers things:
- whether a state fertility mandate probably applies to your plan,
- whether your employer plan is probably self-funded,
- that you are probably pursuing fertility treatment, and roughly where in it you are,
- from your diagnosis and relationship flags, whether you probably meet your plan's definition of infertility,
- a likely out-of-pocket cost range.
These are estimates produced by a rules engine, not facts, and not determinations. They are health inferences about you, which is exactly why the health-privacy laws above apply. We treat them with the same protection as what you typed in.
5. What we never collect
Your name. We don't ask.
Your date of birth. We ask for an age band, because coverage rules turn on it.
Your Social Security number, government ID, or immigration status.
Your member ID, group number, or insurance card. In the free flow we ask what kind of plan you have, not who you are on it.
ATTORNEY REVIEW: The v2 Ledger tier may need member and group IDs to reconcile bills. Before that ships, this line must change and the risk analysis must be redone.
Your medical records. We are not connected to your clinic or your portal.
Your exact location. We use the state you pick. We do not use GPS, and we do not geofence clinics or pharmacies — Washington and Nevada both ban that outright, and we would not do it anyway.
Payment card numbers.
Anything about your children.
6. What we do with it
Only these things:
- Produce your estimate and your plan. This is the whole point.
- Email you your plan link, and support you if something breaks.
- Email you guidance — only if you asked for it, and only until you tell us to stop.
- Take payment, through Stripe.
- Keep the service working and secure — server logs, error monitoring, fraud prevention.
- Improve our rules data in aggregate. For example: "the Illinois self-funded path is where most people drop off." Never anything that identifies you, and never your inputs individually unless you separately opted in to product research.
We do not use your information to train advertising models, to build a profile of you, or to score you for lenders, clinics, or anyone else.
7. We do not sell your data or share it for advertising
To be exact, using the definitions state laws use:
- We do not sell your personal information or your consumer health data, for money or for any other thing of value.
- We do not share it for cross-context behavioral advertising.
- We do not run targeted advertising based on it.
- We have never done any of this and have no plan to. If that ever changed, it would require your separate, specific, opt-in consent — and under Washington and Nevada law, a signed authorization, not a checkbox.
Because there is no selling or sharing, there is nothing for a "Do Not Sell or Share My Personal Information" link to turn off. We still honor Global Privacy Control signals when your browser sends one.
ATTORNEY REVIEW: Confirm whether we must still post a "Do Not Sell or Share" link under the CCPA regulations effective January 1, 2026 even when we do not sell or share, or whether this disclosure is sufficient.
8. No ad tech. No session replay.
There is no third-party advertising or tracking script anywhere on this site. Our build fails automatically if anyone adds one. This is not a preference we could quietly drop; it is how we stay on the right side of the FTC and the state health-data laws.
We also do not use session replay or heatmap tools. Nothing records your screen, your mouse, or your keystrokes.
The only non-first-party requests any page makes are Stripe, on the checkout page only, and Google Fonts, for typography.
ATTORNEY REVIEW: Google Fonts served from Google's servers transmits IP addresses to Google and has drawn German court decisions on that basis. Should we self-host the fonts to eliminate the last third-party request? Recommend yes; confirm.
9. How long we keep things
| What | How long | Why |
|---|---|---|
| Free planner answers | Until you close the tab | They never leave your browser, unless you ask Halden a question (below) |
| An Ask Halden question, free or paid | Not stored — used only for that single request, then discarded | It's a live request/response, not a record; see §10 |
| A saved or paid plan | 30 days, then automatically deleted by a nightly job | The plan is a decision tool for a moment in time, not a record |
| Uploaded documents (paid Ledger tier) | The original file is deleted within 24 hours of us extracting the numbers | See below |
| Fields extracted from your documents | 90 days by default, then deleted | Long enough to finish an appeal cycle |
| Waitlist email address | Until you unsubscribe or ask us to delete it | |
| Consent records (what you agreed to, and when) | 6 years | Washington and Nevada require sale authorizations be retained 6 years; we keep all consent records on the same clock so we can prove what you did and did not agree to |
| Payment records | 7 years | Tax and accounting law |
| Server and security logs | 30 days |
Extract, then purge. When you upload a bill or an EOB, we read it, pull out the specific fields we need — dates of service, billed amount, allowed amount, plan paid, your responsibility, denial codes — and then delete the original document. We do not keep a copy of the file, an image of it, or a backup of it. What remains is a short list of numbers, and that list is deleted after 90 days unless you tell us to keep it longer.
One-click delete. Every plan page and every email we send carries a delete link. One click removes your plan, your extracted fields, and your email from our systems. It takes effect immediately, and finishes clearing our backups within 30 days. We keep only the minimum record that a deletion happened, and any payment record we are legally required to retain.
ATTORNEY REVIEW: Confirm the 6-year consent retention period and whether it conflicts with a consumer's deletion right under CCPA, MHMDA, or CTDPA. Our position is that consent records are retained under a legal-obligation and legal-claims exemption. Confirm that is right and that it is worded defensibly.
ATTORNEY REVIEW: The PRD sets a 30-day plan expiry; this policy sets 90 days for document-extracted fields. Confirm both, and confirm 90 days is long enough for a full internal-appeal cycle (180 days to file, 30 or 60 days for a decision) — a user mid-appeal may need their data past day 90. Should we offer an explicit extension rather than silently deleting?
10. Who else touches your data
We use a small number of vendors. Each is contractually barred from using your information for anything except providing the service to us — no advertising, no resale, no model training.
| Vendor | What they do | What they see |
|---|---|---|
| [HOSTING PROVIDER] | Runs the website and servers | Whatever passes through the service; IP addresses in logs |
| [DATABASE PROVIDER] | Stores paid plans and waitlist emails | Stored plan data, at rest, encrypted |
| Stripe | Processes payments | Your card details and email — directly, not through us |
| [EMAIL PROVIDER] | Sends your plan link and any guidance you asked for | Your email address and the message |
| Anthropic | Paid Ledger tier only: reads uploaded documents to extract the numbers | The text of the document you uploaded, for the length of the request |
| Anthropic | "Ask Halden" companion (free planner, opt-in, and the saved/paid guide page): answers a question, grounded only in your own already-computed guide | Your guide's cost ranges, coverage verdict, and sources, plus your question, for the length of the request |
About the AI vendor, specifically. The underlying estimate is never AI: computeGuide is a deterministic rules engine, and the same answers always produce the same numbers, whether or not you ever touch Ask Halden. AI is used in two places, both narrow, and both the same vendor, Anthropic (Claude): reading a document you chose to upload (paid Ledger tier), and the "Ask Halden" companion, which answers a question about a guide already computed by the rules engine — it narrates and explains those numbers, it does not compute them or invent a source of its own. Under our enterprise agreement, that vendor does not train on your content and does not retain it beyond the request. Where the vendor offers a HIPAA business associate agreement, we sign it as an extra contractual safeguard — not because HIPAA applies to us (it does not), but because it is the strictest standard contract available.
ATTORNEY REVIEW: Named 2026-09-06 — Anthropic is in fact the only AI vendor this product uses anywhere (confirmed against the codebase:
@anthropic-ai/sdkis the sole LLM dependency), so this isn't a guess. What's still unconfirmed: whether naming it here (rather than "an AI service") is itself the legally safer or legally required choice — the general question the flags below already raised — and, separately and more urgent now that a real name is attached to it, whether "under our enterprise agreement" is literally true. Confirm a signed agreement with Anthropic actually contains written zero-retention and no-training terms before this sentence is relied on; if no such agreement exists yet, this sentence overstates the current state of things and needs to say so.
ATTORNEY REVIEW: Confirm this framing. A BAA with a vendor when we are not a covered entity or business associate creates contractual obligations without HIPAA status. Is signing it net-positive, or does it create an argument that we have held ourselves out as HIPAA-regulated? Also confirm the LLM vendor's zero-retention and no-training terms in writing before this sentence ships.
ATTORNEY REVIEW: Fill in every remaining vendor name — hosting, database, and email are still bracketed; the AI vendor (Anthropic) was filled in 2026-09-06, see the flag above. Under MHMDA and Nevada SB 370 we must disclose the categories of third parties AND, for MHMDA, the specific affiliates. Confirm whether naming vendors specifically (rather than by category) is required or merely safer.
We will also disclose information if the law genuinely requires it. Our commitment: we will demand a valid legal process, we will not hand over reproductive health information in response to an informal request, and we will tell you unless a court forbids us. This is a real risk in the current legal environment, and the honest mitigation is that we hold very little for a very short time.
ATTORNEY REVIEW: Review this law-enforcement paragraph carefully. Can we commit to notifying users? Should we publish a transparency report? Should we adopt a formal policy of resisting out-of-state subpoenas concerning reproductive health data, and does any shield law in our state of formation support that?
11. How we protect it
- Everything is encrypted in transit (TLS) and at rest.
- Plans are keyed by a random 128-bit identifier, not by your name or email. A plan link is not guessable.
- Access to production data is limited to the people who need it, with multi-factor authentication and logging.
- No third-party scripts run on our pages, which removes the single most common way health data leaks.
- We minimize by design: the free flow never sends your answers to us at all.
- We run a nightly purge job and monitor that it actually ran.
No system is perfectly secure. If your information is ever exposed or disclosed without your permission, we will notify you — and the FTC, and where required your state Attorney General — on the timelines the Health Breach Notification Rule sets, which is within 60 days of discovering it.
ATTORNEY REVIEW: We need a written incident response plan naming who decides a breach occurred, who notifies, and by when. The HBNR requires notice to the FTC within 10 business days for incidents affecting 500 or more people, plus media notice. Confirm the trigger analysis and build the runbook before launch.
12. Your rights
Wherever you live, you can:
- See what we hold about you.
- Get a copy in a portable format.
- Correct anything wrong.
- Delete everything, in one click.
- Withdraw a consent you gave, at any time, as easily as you gave it.
- Opt out of emails, from any email's footer.
- Object to how we handle your data, without being punished for it. Nothing you do here changes the price you pay or the plan you receive.
We do not require you to create an account to exercise any of these. Email privacy@[DOMAIN] or use the delete link in your plan or email.
We answer within 45 days. If we need longer, we will tell you why and take at most 45 more. We will not charge you.
If you are in California, you may use an authorized agent. If you are in Washington, see the Consumer Health Data Privacy Policy, which sets out your MHMDA rights and how to appeal a refusal. If we deny a request, we will tell you why and how to appeal, and if the appeal fails we will give you a link to complain to your state Attorney General.
ATTORNEY REVIEW: Confirm the 45-day response window is the shortest applicable across CCPA, MHMDA, CTDPA, Nevada SB 370, and any other law reaching us, and confirm the appeal mechanism satisfies the state comprehensive privacy statutes that require one.
13. Children
This service is for adults. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, email privacy@[DOMAIN] and we will delete it.
ATTORNEY REVIEW: Fertility preservation is a real need for adolescent cancer patients, whose parents may use this tool. Should the cutoff be 18, or 13 with parental-consent handling? Note that the Connecticut amendments effective July 1, 2026 expand protections to ages 13-17 and ban targeted advertising and data sales for that group regardless of consent. Confirm the cutoff and whether COPPA is implicated.
14. Where your data lives
We store and process data in the United States. We do not offer this service outside the US, and we are not designed for people in the EU or UK.
ATTORNEY REVIEW: Confirm whether we need a GDPR position at all given a US-only offering, and whether we should geo-block or simply disclaim.
15. Changes to this policy
If we change something that matters, we will post the new policy, change the date at the top, and email anyone who gave us an address — before the change takes effect, not after.
We will not apply a new use to information we already hold about you unless you agree to it. Under Washington and Nevada law we cannot collect, use, or share categories of health data we did not disclose here without asking you again, and we will not try.
16. Contact
privacy@[DOMAIN] Halden, [MAILING ADDRESS]
If we cannot resolve it, you can complain to the FTC (reportfraud.ftc.gov) or to your state Attorney General. Washington residents: the Washington Attorney General's office handles My Health My Data complaints, and MHMDA violations are enforceable by you directly under the Washington Consumer Protection Act.
References
Verified 2026-09-06.
- FTC, Health Breach Notification Rule, final rule, 89 Fed. Reg. 47028 (May 30, 2024), effective July 29, 2024 — https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule
- FTC, "Updated FTC Health Breach Notification Rule puts new provisions in place to protect users of health apps and devices" (Apr. 26, 2024) — https://www.ftc.gov/business-guidance/blog/2024/04/updated-ftc-health-breach-notification-rule-puts-new-provisions-place-protect-users-health-apps
- FTC, "Complying with FTC's Health Breach Notification Rule" — https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
- FTC, GoodRx enforcement action (Feb. 1, 2023; $1.5M civil penalty; first HBNR enforcement) — https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising
- FTC, BetterHelp (Mar. 2, 2023; $7.8M) — https://www.ftc.gov/news-events/news/press-releases/2023/03/ftc-gives-final-approval-order-banning-betterhelp-sharing-sensitive-health-data-advertising
- FTC, Easy Healthcare / Premom (May 17, 2023; second HBNR action; $100,000 penalty) — https://www.ftc.gov/news-events/news/press-releases/2023/05/ovulation-tracking-app-premom-will-be-barred-sharing-health-data-advertising-under-proposed-ftc
- FTC, Flo Health (final order June 2021) — https://www.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google
- Washington My Health My Data Act, RCW 19.373 (HB 1155); Washington AG guidance and FAQ; §§4–9 effective Mar. 31, 2024 (June 30, 2024 for small businesses) — https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy
- Hintze Law, "My Health My Data Act, Part 8: Notice Obligations" (required elements of the Consumer Health Data Privacy Policy) — https://hintzelaw.com/blog/wa-my-health-my-data-act-pt8-notice
- Maxwell v. Amazon.com, W.D. Wash. (filed Feb. 2025) — first MHMDA class action — https://www.orrick.com/en/Insights/2025/02/First-Lawsuit-Filed-Under-Washingtons-My-Health-My-Data-Act
- California AB 254 (2023), amending the Confidentiality of Medical Information Act to cover reproductive or sexual health application information; effective Jan. 1, 2024 — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB254
- ArentFox Schiff, "California Adopts Privacy Protections for Digital Reproductive and Sexual Health Information" — https://www.afslaw.com/perspectives/health-care-counsel-blog/california-adopts-privacy-protections-digital-reproductive
- California Consumer Privacy Act, statute text effective Jan. 1, 2026 (CPPA) — https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf ; California AG CCPA page — https://oag.ca.gov/privacy/ccpa
- Nevada SB 370 (2023), consumer health data; effective Mar. 31, 2024; AG enforcement, no private right of action — https://bassberry.com/news/nevada-consumer-health-data-law-takes-effect-on-march-31-2024/
- Connecticut Data Privacy Act consumer health data amendments (SB 3, 2023) — https://www.orrick.com/en/Insights/2023/07/The-Consumer-Health-Data-Amendments--to-the-Connecticut-Data-Privacy-Act
- Connecticut SB 1295 (2025), CTDPA overhaul effective July 1, 2026 (35,000-consumer threshold; no threshold where sensitive data is processed; ages 13–17 protections) — https://www.wiley.law/alert-Major-Changes-to-Connecticut-Consumer-Privacy-Law-Will-Take-Effect-July-1-2026
- Purl v. U.S. Dep't of Health & Human Services, No. 2:24-cv-228-Z (N.D. Tex. June 18, 2025) — vacated the HIPAA Reproductive Health Care Privacy Rule nationwide; Fifth Circuit appeal dismissed — https://www.hklaw.com/en/insights/publications/2025/06/hipaas-reproductive-health-rule-is-vacated-nationally ; https://www.americanbar.org/groups/health_law/news/2025/signaling-end-purl-case/
- New York S929 (2025) Health Information Privacy Act — passed both chambers Jan. 2025, vetoed by Governor Hochul Dec. 2025; successor bill S9269 introduced 2026 and not enacted as of this date — https://www.mofo.com/resources/insights/260316-nyhipa-returns-in-2026-revised-bill ; https://www.nysenate.gov/legislation/bills/2025/S929