Consumer Health Data Privacy Policy
Last updated: September 6, 2026
This is a separate policy, required by the Washington My Health My Data Act. It is also written to satisfy Nevada SB 370 and the consumer-health-data provisions of the Connecticut Data Privacy Act. It covers only consumer health data. Our general Privacy Policy covers everything else, and nothing here replaces it.
Applies to: anyone whose consumer health data we collect. Washington and Nevada residents have specific statutory rights described below; we extend the same rights to everyone.
ATTORNEY REVIEW: MHMDA requires this policy to be linked prominently from the homepage, and Washington defines "homepage" to include any page where personal information is collected — which, because IP addresses are logged, is every page. Confirm the link must appear in the global footer on every route, and that "Consumer Health Data Privacy Policy" is the correct, unabbreviated link text.
ATTORNEY REVIEW: MHMDA bars us from collecting, using, or sharing any category of consumer health data not disclosed in this policy. This document must be re-reviewed against the shipped product before every launch, and specifically before the v2 Ledger tier adds document upload.
1. What we mean by consumer health data
Information that identifies your past, present, or future physical or mental health status — including what can be inferred from what you tell us or do. For this product, that means fertility, infertility, plans to conceive, treatment you are receiving or considering, and what your health plan does or does not cover for it.
2. Categories of consumer health data we collect
What you tell us directly:
- That you are considering, starting, in the middle of, or appealing a denial for fertility treatment
- Your treatment path: IUI, IVF, freeze-all with frozen transfer, IVF with genetic testing, egg freezing, and add-ons such as donor gametes or ICSI
- Your age band (not your date of birth)
- Diagnosis flags you choose to check — for example male-factor, tubal-factor, diminished ovarian reserve, or a cancer diagnosis leading to fertility preservation
- Relationship and definition-of-infertility flags — whether you are single, partnered, or LGBTQ+, and how many cycles of prior treatment you have had. We ask because health plans define "infertility" in ways that decide whether your treatment qualifies.
- Number of prior IUI or IVF cycles, and how many cycles you plan
- Coverage facts: your state, employer size band, plan type, whether your plan is self-funded, and any carve-out benefit vendor such as Progyny or Carrot
- Money you type in: a clinic quote, your deductible, your out-of-pocket maximum, an HSA balance, a household income band
- Documents you choose to upload (paid tier only): bills, Explanation of Benefits, denial letters, clinic statements. These contain diagnosis and procedure codes, dates of service, and amounts.
What we work out about you (inferences):
- That you are likely seeking or receiving fertility treatment, and roughly where you are in it
- Whether a state fertility mandate likely applies to your plan
- Whether your plan is likely self-funded, and therefore which appeal path applies
- Whether you likely meet your plan's definition of infertility
- Your likely out-of-pocket cost range, by phase of treatment
Technical data: your IP address and general region, page requests, and browser type. We treat these as consumer health data when they appear alongside anything above, because on this site they can reveal that you are seeking fertility care.
We do not collect: your name, date of birth, Social Security number, government ID, immigration status, insurance member or group ID, precise geolocation, biometric data, genetic sequence data, or medical records from any provider or portal.
3. Where we get it
- From you. Almost all of it. You type it into the planner, or you upload a document.
- From your device, automatically: IP address, browser type, page requests.
- From Stripe, if you pay: a confirmation that a payment succeeded, the last four digits of the card, and the email you gave Stripe.
That is the complete list. We do not buy data. We do not get data from brokers, advertising networks, social platforms, employers, clinics, insurers, or public records. Nobody sends us information about you.
4. Why we collect it, and how we use it
| Purpose | What it means |
|---|---|
| Produce your estimate | Run your answers through our rules engine to estimate coverage and out-of-pocket cost by phase. This is the service you asked for. |
| Save and show your plan | Paid tier: store your inputs so we can rebuild your plan when you open your link, and so you can edit it for 30 days. |
| Read your documents | Paid Ledger tier only: extract the numbers from a bill or EOB so we can compare it to what your plan should have paid. |
| Email you | Send your plan link, respond to support, and send guidance if you asked for it. |
| Take payment | Through Stripe. |
| Keep the service working and secure | Logs, error monitoring, fraud prevention, and honoring your privacy requests. |
| Improve the product, in aggregate | Counts and drop-off rates, never tied to you. If we want to look at your individual answers, we ask separately and you can say no. |
| Product research | Only if you separately opted in. You can withdraw that at any time. |
We do not use consumer health data for advertising of any kind, do not use it to build a profile of you, do not use it to train advertising models, and do not use it to score you for lenders, clinics, or insurers.
5. Categories of consumer health data we share, and with whom
We share consumer health data only with the service providers we need to run the product, and only for the purposes above. Every one is under a written contract that forbids using your data for anything else, forbids selling it, and forbids using it to train models.
| Category of third party | Specific party | Categories of consumer health data shared |
|---|---|---|
| Cloud hosting and application infrastructure | [HOSTING PROVIDER] | All categories, in transit and in storage |
| Database hosting | [DATABASE PROVIDER] | Saved plan inputs and inferences; extracted document fields; email address |
| Payment processing | Stripe, Inc. | Email address and transaction data. No health data. |
| Transactional email delivery | [EMAIL PROVIDER] | Email address and message content, which may reference your plan |
| AI document extraction (paid Ledger tier only) | Anthropic | The contents of a document you upload, for the duration of the request only |
| AI companion ("Ask Halden" — free planner, opt-in, and the saved/paid guide page) | Anthropic | Your guide's cost ranges, coverage verdict, and sources, plus your question, for the duration of the request only |
| Legal compliance | Courts, regulators, law enforcement | Only what a valid legal process actually requires |
Affiliates. We have no affiliates and share consumer health data with none.
ATTORNEY REVIEW: MHMDA requires a list of the categories of third parties and a list of the specific affiliates with which consumer health data is shared. Confirm the corporate structure has no affiliates, and confirm whether naming specific vendors (as done here) is required or is a voluntary-but-safer choice that we then must keep accurate on pain of a §5 deception claim.
We do not sell your consumer health data
We do not sell consumer health data, as Washington, Nevada, and California each define "sell." No money, no other valuable consideration, ever.
Washington and Nevada both require a signed, specific written authorization before any such sale — not a checkbox and not a term buried in a policy. We have never asked for one, and we do not intend to. If that ever changed, you would receive a standalone authorization request that you could refuse without losing access to anything you paid for.
We do not use geofencing
We do not use geofencing around any fertility clinic, pharmacy, hospital, or any other health facility, for any purpose. Washington and Nevada ban it. We would not do it regardless.
6. Your rights
You have the right to:
1. Know and access. Ask us to confirm whether we hold consumer health data about you, get a copy of it, and get a list of every third party with which we have shared it — including how to contact each one.
2. Delete. Ask us to delete your consumer health data. When you do, we delete it from our active systems and instruct every service provider and third party who received it to delete it too. Backups are cleared within 30 days. We keep only the minimum record that a deletion happened and any payment record the law requires us to retain.
3. Withdraw consent. Take back any consent you gave — to processing, to email, to document upload, to product research — at any time, and as easily as you gave it. Withdrawing consent stops future processing. To also erase what we already have, use the delete right as well; we will tell you clearly if you need both.
4. Not be discriminated against. Exercising any of these rights costs you nothing and changes nothing about the price you pay or the plan you receive.
How to exercise them
- Fastest: click "Delete my plan" on your plan page, or the "Delete my data" link in the footer of any email we send. One click. No account, no form, no phone call.
- By email: privacy@[DOMAIN]. Say what you want. If we cannot tell which record is yours, we will ask for the email address or plan link you used — and nothing more.
- By mail: Halden, [MAILING ADDRESS].
Our timeline: we respond within 45 days. If we need more time we will tell you why within those 45 days and take at most 45 more. It is free.
Authorized agents. You can have someone act for you. We will ask for proof that you authorized them.
If we say no
We will tell you why, in writing, and tell you how to appeal. Send an appeal to privacy@[DOMAIN] with "Appeal" in the subject line. We will decide within 45 days and explain the decision. If we still say no, we will give you a link to submit a complaint to your state Attorney General.
- Washington: file with the Washington State Attorney General — https://www.atg.wa.gov/file-complaint . MHMDA violations are also a per se violation of the Washington Consumer Protection Act, which means you can sue us directly.
- Nevada: file with the Nevada Attorney General's Bureau of Consumer Protection.
- Connecticut: file with the Connecticut Attorney General.
- California: file with the California Privacy Protection Agency or the California Attorney General.
ATTORNEY REVIEW: Confirm the 45-day response and 45-day appeal windows are the shortest required across MHMDA, Nevada SB 370, CTDPA (as amended effective July 1, 2026), and CCPA. Confirm the appeal mechanism language satisfies each statute's specific wording requirement, and that the AG complaint links are the correct ones to publish.
ATTORNEY REVIEW: MHMDA's deletion right requires us to notify all affiliates, processors, contractors, and third parties that received the data and to instruct them to delete it. Confirm every vendor contract actually contains a deletion-on-instruction clause before this promise ships.
7. Changes to this policy
We will not collect, use, or share any category of consumer health data that this policy does not list. If we want to, we will update this policy, post it, notify you, and ask for your consent again first — before the new practice starts.
8. Contact
privacy@[DOMAIN] Halden, [MAILING ADDRESS]
References
Verified 2026-09-06.
- Washington My Health My Data Act, RCW 19.373 (HB 1155). §§4–9 effective March 31, 2024; June 30, 2024 for small businesses. Washington AG overview and FAQ — https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy
- Required elements of the Consumer Health Data Privacy Policy under MHMDA §4, and the homepage-link requirement — Hintze Law, "My Health My Data Act, Part 8: Notice Obligations" — https://hintzelaw.com/blog/wa-my-health-my-data-act-pt8-notice
- K&L Gates, "The Countdown to Complete Your Consumer Health Data Privacy Policy Under the Washington My Health My Data Act" — https://www.klgates.com/The-Countdown-to-Complete-Your-Consumer-Health-Data-Privacy-Policy-Under-the-Washington-My-Health-My-Data-Act-3-19-2024
- Nevada SB 370 (2023): effective March 31, 2024; consent before collection/sharing; signed authorization with 1-year expiry and 6-year retention before sale; geofencing prohibition; AG enforcement, no private right of action — https://bassberry.com/news/nevada-consumer-health-data-law-takes-effect-on-march-31-2024/
- Connecticut Data Privacy Act consumer health data amendments (SB 3, 2023), effective July 1 and Oct. 1, 2023 — https://www.orrick.com/en/Insights/2023/07/The-Consumer-Health-Data-Amendments--to-the-Connecticut-Data-Privacy-Act
- Connecticut SB 1295 (2025), effective July 1, 2026 — https://www.wiley.law/alert-Major-Changes-to-Connecticut-Consumer-Privacy-Law-Will-Take-Effect-July-1-2026
- California AB 254 (2023), CMIA coverage of reproductive or sexual health application information, effective Jan. 1, 2024 — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB254
- FTC Health Breach Notification Rule, effective July 29, 2024 — https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule