Privacy Policy

Last Updated: 07/20/2026  |  Effective Date: 07/20/2026

1. Introduction and Scope

This Privacy Policy (this "Policy") describes how [HealthyMama, Inc.] ("HealthyMama," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information and consumer health data when you use the HealthyMama mobile application and related services (collectively, the "Platform"). This Policy applies to all users of the Platform, including individuals in the trying-to-conceive ("TTC"), pregnancy, and postpartum stages.

1.1 Platform Description

HealthyMama is a maternal wellness platform available on the Apple App Store and Google Play. The Platform provides educational content, an AI-powered wellness companion, health-reading tracking tools, journaling features, and device integrations. The Platform is expressly designed as a supportive, non-clinical, wellness-oriented digital companion and is NOT a healthcare provider, telehealth service, medical device, or clinical decision-support system.

1.2 Applicability

This Policy applies to:

Separate privacy terms may apply to data shared with an OB practice under the OB-Referred pathway; see Section 5 below.

1.3 US-Only Data Residency

All personal information and consumer health data collected through the Platform is stored and processed exclusively within the United States, on HIPAA-compliant Microsoft Azure infrastructure. We do not transfer personal information outside the United States. The Platform is intended solely for use by individuals located in the United States.

2. Categories of Information We Collect

We collect the following categories of information when you use the Platform:

2.1 Account and Identity Information

2.2 Pregnancy and Reproductive Health Data

2.3 Clinical Readings

2.4 Wellness and Lifestyle Data

2.5 AI Companion Interaction Data

2.6 OB Practice Information

2.7 Device and Technical Data

2.8 Connected Device Data

3. Sensitive Data and Consumer Health Data Designation

3.1 Consumer Health Data

Under applicable state laws—including the Washington My Health My Data Act (MHMDA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Nevada SB 370—much of the information we collect constitutes consumer health data and/or sensitive personal information that is subject to heightened legal protections.

We expressly designate the following categories as consumer health data and/or sensitive personal information:

3.2 Heightened Treatment

Because this data is classified as consumer health data and/or sensitive personal information, we apply the following heightened protections:

3.3 Reproductive and Pregnancy Data: Additional Protections

We recognize that reproductive and pregnancy-related data is subject to increasing legal protection and heightened sensitivity in the current regulatory environment. We commit that:

3.4 Post-Dobbs Reproductive-Data Minimization and Legal-Process Strategy

In light of the evolving legal landscape following the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization (2022) and subsequent state legislation restricting reproductive healthcare, HealthyMama maintains an express commitment to data minimization and retention limitation specifically designed to reduce the volume of pregnancy-tracking data that would be available for compelled production.

Data-Minimization Commitments:

Legal-Process Requirements for Reproductive Health Data:

3.5 Biometric Data Disclosure (Illinois BIPA Protective Provision)

The Platform collects blood pressure readings (from certain devices that are yet to be determined) and blood glucose readings (from certain devices that are yet to be determined) synced from biometric-sensing devices connected to the Platform.

Important Legal Note Regarding BIPA Applicability:

Whether blood pressure readings and blood glucose readings constitute "biometric identifiers" or "biometric information" under the Illinois Biometric Information Privacy Act (740 ILCS 14/) ("BIPA") is uncertain. BIPA enumerates specific categories of biometric identifiers—retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry—and physiological measurements such as blood pressure and glucose levels may fall outside these enumerated categories. This disclosure is provided as a protective measure notwithstanding that uncertainty.

Biometric Data Practices (Protective Disclosure):

4. How We Use Your Information

4.1 Providing and Operating the Platform

4.2 AI Processing Activities and Transparency

Important: We are transparent about how AI processes your data within the Platform:

AI Transparency Disclosure:

Natalie is an automated artificial intelligence system—not a human being and not a clinician. When you interact with Natalie through the Platform, you are communicating with an AI-powered chatbot that generates responses using large language model technology. The Platform provides clear, real-time disclosure of this fact at or before the point of interaction. Natalie does not exercise clinical judgment, provide individualized medical advice, or make consequential healthcare decisions on your behalf.

HealthyMama is evaluating obligations under emerging AI transparency and governance laws, including:

4.3 What We Do NOT Use Your Data For

YOUR PERSONAL INFORMATION, USER CONTENT, AND CONSUMER HEALTH DATA ARE NOT USED TO TRAIN, FINE-TUNE, OR IMPROVE ANY AI OR MACHINE-LEARNING MODEL.

Specifically:

4.4 Aggregate and De-Identified Data

We may use aggregated, de-identified usage data (from which individual identity cannot reasonably be re-identified) to:

Such aggregate data is not consumer health data and is not subject to deletion requests.

5. Two Data Pathways: D2C and OB-Referred

5.1 Direct Consumer (D2C) Path

If you register without linking to an OB practice:

5.2 OB-Referred Path

If you self-select an onboarded OB practice during registration:

5.3 Data Already Transmitted to a Practice

If you revoke consent for data sharing or delete your account, data already transmitted to your OB practice is not retroactively retrievable or deletable by HealthyMama. Once in the practice's possession, that data is governed by the practice's own privacy practices and HIPAA obligations as a covered entity.

6. D2C OB Practice Identification and Commercial Use

IMPORTANT DISCLOSURE — PLEASE READ CAREFULLY

6.1 What We Collect

During onboarding, D2C users are prompted—but not required—to identify their current OB practice. Providing this information is entirely optional. If you choose not to identify your practice, your experience on the Platform is not affected.

6.2 How We Use This Information

If you voluntarily identify your OB practice, HealthyMama uses the aggregate, non-identifiable count of D2C users who have identified a given practice as a commercial lead-generation signal. Specifically, HealthyMama may approach that practice for a partnership conversation using aggregate data only (e.g., "a number of your patients are using the HealthyMama platform").

6.3 What We Will NEVER Do

6.4 Consent

We obtain your explicit, affirmative consent at the point of collection before using your identified OB practice for this commercial purpose. This consent is separate from your acceptance of this Privacy Policy or the Terms of Service. You will receive a clear disclosure at the moment you are asked to identify your practice, explaining that the practice may be contacted by HealthyMama using aggregate platform usage data. If you do not consent, your identified practice will not contribute to lead-generation outreach.

7. Wearable and Third-Party Device Integrations

7.1 Supported Integrations

The Platform supports integration with the following FDA-cleared Class II medical devices:

Both devices are OB-directed (your healthcare provider recommended or ordered their use). HealthyMama does not supply, sell, or recommend these devices.

7.2 Data Flow

When you connect a device:

7.3 Third-Party Privacy Terms and API Governance

Your use of Dexcom and Omron devices and their companion applications is governed by those companies' own terms of service and privacy policies. HealthyMama is not responsible for the data practices of device manufacturers.

You acknowledge that:

We encourage you to review:

8. Disclosure of Information to Third Parties

8.1 Service Providers and Sub-Processors

We share personal information with service providers who process data on our behalf solely to operate the Platform. These include:

All service providers are contractually obligated to use your data only for the specific service they provide to us and to maintain appropriate security measures.

8.2 OB Practices (OB-Referred Path Only)

For OB-Referred users who have consented to data sharing, structured reading data (and only the specific categories consented to) may be shared with the selected practice. See Section 5.2 for details.

8.3 No Sale of Consumer Health Data

We do NOT sell consumer health data. We do not sell, rent, lease, or trade personal information, consumer health data, or sensitive personal information to any third party for monetary or other valuable consideration. For purposes of the California Consumer Privacy Act, we do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA.

8.4 No Sharing for Advertising

We do not share personal information with third parties for cross-context behavioral advertising, targeted advertising, or profiling purposes.

8.5 Legal and Safety Disclosures

We may disclose personal information if we believe in good faith that disclosure is necessary to:

Reproductive and pregnancy data: We will not disclose reproductive health information, pregnancy status, or related data to law enforcement or government agencies except pursuant to a valid court order or warrant issued by a court of competent jurisdiction. A subpoena alone is insufficient. We will provide notice to affected users to the extent permitted by law. See Section 3.4 for our complete reproductive-data legal-process policy.

8.6 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the successor entity. We will provide notice of any such transfer and any choices you may have regarding your information.

9. Data Retention and Deletion

9.1 Retention Periods

We retain your personal information for as long as your account is active and for a reasonable period thereafter, as follows:

9.2 Account Deletion

You may request deletion of your account and associated data at any time by:

Upon receiving a verified deletion request, we will:

9.3 Data Already Shared

Deletion of your HealthyMama account does not retroactively delete:

9.4 Subscription vs. Account Deletion

Canceling your subscription ends access to paid features but does not delete your account or data. To delete your data, you must separately request account deletion.

10. Your Privacy Rights

10.1 General Rights

Depending on your state of residence, you may have some or all of the following rights regarding your personal information:

10.2 Consumer Health Data Rights

In addition to the general rights above, you have specific rights regarding consumer health data:

10.3 How to Exercise Your Rights

To submit a privacy request:

We will verify your identity before processing any request. We will respond within the timeframes required by applicable law (typically 45 days, extendable by an additional 45 days with notice).

10.4 Authorized Agents

You may authorize an agent to submit requests on your behalf. We will require verification of both the agent's authority and your identity.

11. State-Specific Privacy Rights

11.1 Washington — My Health My Data Act (MHMDA)

If you are a Washington state resident or consumer, the following applies:

11.2 California — CCPA/CPRA

If you are a California resident, the following applies:

California "Shine the Light": We do not disclose personal information to third parties for their direct marketing purposes.

11.3 Nevada — Consumer Health Data (SB 370)

If you are a Nevada resident, the following applies:

11.4 Other State Comprehensive Privacy Laws

If you are a resident of Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, or another state with a comprehensive consumer privacy law in effect at the time of your request, you may have rights to access, delete, correct, and port your data, and to opt out of targeted advertising, profiling, and sales. Because we do not engage in targeted advertising, profiling for decisions that produce legal effects, or sales of personal data, many opt-out rights are already honored by default.

To exercise any state-specific right, contact us using the methods in Section 10.3. We will process your request in accordance with the applicable state law.

12. Children's Privacy

The Platform is intended for use by adults only (individuals who have reached the age of majority in their state of residence). We do not knowingly collect personal information from children under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [DPO/privacy contact email] and we will promptly delete such information.

The Platform is designed for individuals who are pregnant, trying to conceive, or postpartum — user populations that are, by their nature, adults.

13. Security

13.1 Technical Safeguards

We implement and maintain administrative, technical, and physical security measures designed to protect your personal information and consumer health data, including:

13.2 Payment Data Security (PCI DSS)

HealthyMama does not directly collect, process, transmit, or store full payment card numbers, card verification values (CVV/CVC), or other sensitive cardholder data. All payment transactions are processed through PCI-DSS-compliant third-party payment processors and/or through the applicable App Store's billing infrastructure (Apple In-App Purchase or Google Play Billing). Your payment information is handled exclusively by these PCI-DSS-certified processors in accordance with Payment Card Industry Data Security Standards.

13.3 US-Only Data Residency

All personal information and consumer health data is stored exclusively in US-based data centers. We do not transfer data internationally.

13.4 State Data-Breach Notification

In the event of a security incident involving unauthorized access to, or acquisition of, personal information or consumer health data, HealthyMama will comply with all applicable state data-breach-notification laws in addition to any HIPAA breach-notification obligations (which apply only to the OB-Referred pathway where HealthyMama acts as a Business Associate).

Important: State breach-notification laws apply independently of HIPAA.

For D2C-pathway users, whose data generally does not constitute HIPAA-protected health information, state data-breach-notification statutes are the primary legal framework governing notification obligations in the event of a security incident. You should be aware that:

[Drafting note: A 50-state data-breach-notification compliance matrix should be maintained and updated periodically. This is particularly important given that D2C-pathway health data is not PHI and therefore falls outside HIPAA's breach-notification framework — state laws are the sole governing regime for that data. The compliance matrix should map triggering definitions, notification timelines, AG notification requirements, and content requirements for each state where the platform has users. See DWT 50-state summary and comparable resources.]

13.5 Limitations

No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable measures to protect your personal information, we cannot guarantee absolute security.

14. International Users

The Platform is intended solely for use within the United States. We do not market to, or knowingly collect data from, individuals outside the United States. If you access the Platform from outside the US, you do so at your own initiative and are responsible for compliance with local laws. We make no representation that the Platform is appropriate or available for use in other jurisdictions.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or Platform features. If we make material changes:

Your continued use of the Platform after the effective date of a revised Policy constitutes your acknowledgment of the changes. If you do not agree with the revised Policy, you must stop using the Platform and may request deletion of your data.

16. Contact Us / How to Exercise Your Rights

If you have questions about this Privacy Policy, wish to exercise any of your privacy rights, or have a privacy concern or complaint, please contact us:

Privacy Contact / Data Protection Inquiries:

[HealthyMama, Inc.]
Attn: [Privacy Officer]
4240 E Camelback Road, Suite 311
Phoenix, AZ 85018
Email: [info@healthymama.ai]

For California Residents: You may also submit requests via our designated methods as described in Section 10.3.

For Washington Residents: Consumer health data inquiries and MHMDA-specific requests may be submitted using the same contact methods above. We will process your request in accordance with the My Health My Data Act.

Response Times:

If you are dissatisfied with our response to your privacy concern, you may contact your state attorney general's office or applicable regulatory authority.