Privacy Policy
Last Updated: 07/20/2026 | Effective Date: 07/20/2026
1. Introduction and Scope
This Privacy Policy (this "Policy") describes how [HealthyMama, Inc.] ("HealthyMama," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information and consumer health data when you use the HealthyMama mobile application and related services (collectively, the "Platform"). This Policy applies to all users of the Platform, including individuals in the trying-to-conceive ("TTC"), pregnancy, and postpartum stages.
1.1 Platform Description
HealthyMama is a maternal wellness platform available on the Apple App Store and Google Play. The Platform provides educational content, an AI-powered wellness companion, health-reading tracking tools, journaling features, and device integrations. The Platform is expressly designed as a supportive, non-clinical, wellness-oriented digital companion and is NOT a healthcare provider, telehealth service, medical device, or clinical decision-support system.
1.2 Applicability
This Policy applies to:
- Direct Consumer (D2C) Users: Individuals who download and register for the Platform without linking to an OB practice.
- OB-Referred Users: Individuals who register and self-select an onboarded OB practice from a dropdown during registration, establishing a user-initiated practice connection.
Separate privacy terms may apply to data shared with an OB practice under the OB-Referred pathway; see Section 5 below.
1.3 US-Only Data Residency
All personal information and consumer health data collected through the Platform is stored and processed exclusively within the United States, on HIPAA-compliant Microsoft Azure infrastructure. We do not transfer personal information outside the United States. The Platform is intended solely for use by individuals located in the United States.
2. Categories of Information We Collect
We collect the following categories of information when you use the Platform:
2.1 Account and Identity Information
- Full name
- Email address
- Date of birth
- Account credentials (password, stored in hashed form)
2.2 Pregnancy and Reproductive Health Data
- Current reproductive stage (TTC, pregnant, or postpartum)
- Gestational age and estimated due date
- Health conditions you identify during onboarding, including gestational diabetes mellitus (GDM) and preeclampsia risk factors
2.3 Clinical Readings
- Blood pressure readings (sourced from an Omron BP monitor via device sync or manual entry)
- Blood glucose readings (sourced from a Dexcom continuous glucose monitor (CGM) via device sync or manual entry)
- Timestamps, frequency, and reading history associated with each submission
2.4 Wellness and Lifestyle Data
- Weight entries
- Food intake records and food photos
- Nutritional information
- Mood tracking entries
- Cravings logs
- Milestone journals and written reflections
- Uploaded images (including ultrasound images, belly photos, and other personal images)
2.5 AI Companion Interaction Data
- Messages you send to the AI companion (Natalie)
- Natalie's responses (classification category, response content, timestamps)
- Session metadata (interaction frequency, topic categories)
2.6 OB Practice Information
- OB-Referred Path: The OB practice you select from the onboarded-practice dropdown during registration.
- D2C Path (optional): If you voluntarily identify your OB practice during onboarding (prompted but not required), that practice name. See Section 6 regarding how this information is used.
2.7 Device and Technical Data
- Device type, operating system, and version
- Unique device identifiers
- IP address (anonymized for analytics)
- App usage analytics (screens viewed, features used, session duration)
- Push notification tokens
- App store purchase and subscription identifiers
2.8 Connected Device Data
- Dexcom CGM integration metadata (sync status, connection timestamps)
- Omron BP monitor integration metadata (sync status, connection timestamps)
- Device-originated readings transmitted through authorized APIs
3. Sensitive Data and Consumer Health Data Designation
3.1 Consumer Health Data
Under applicable state laws—including the Washington My Health My Data Act (MHMDA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Nevada SB 370—much of the information we collect constitutes consumer health data and/or sensitive personal information that is subject to heightened legal protections.
We expressly designate the following categories as consumer health data and/or sensitive personal information:
- Pregnancy and reproductive health status (TTC, pregnant, postpartum, gestational age, due date)
- Health conditions (gestational diabetes, preeclampsia risk factors)
- Blood pressure readings and blood glucose readings
- Mood and emotional health tracking entries
- AI companion conversation content (to the extent it contains or reveals health-related information)
- Weight, nutritional intake, and related wellness data linked to pregnancy
- Any other data that identifies or is reasonably linkable to a consumer and that describes or reveals past, present, or future physical or mental health status
3.2 Heightened Treatment
Because this data is classified as consumer health data and/or sensitive personal information, we apply the following heightened protections:
- We obtain affirmative consent before collecting consumer health data (not merely through acceptance of this Policy);
- We do not sell consumer health data;
- We do not share consumer health data for cross-context behavioral advertising;
- We limit internal use to the specific purposes disclosed in Section 4;
- We honor deletion requests as described in Section 9;
- We provide dedicated rights regarding consumer health data as described in Section 10; and
- We maintain access controls and encryption for consumer health data at rest and in transit.
3.3 Reproductive and Pregnancy Data: Additional Protections
We recognize that reproductive and pregnancy-related data is subject to increasing legal protection and heightened sensitivity in the current regulatory environment. We commit that:
- We will not disclose pregnancy status, reproductive health data, or related information to law enforcement absent a valid court order or warrant;
- We will not use pregnancy or reproductive data for any purpose unrelated to providing the Platform services you have requested;
- We will not share pregnancy-specific data with insurers, employers, or data brokers; and
- We will maintain geofencing compliance as required by applicable state law (see Section 11.1).
3.4 Post-Dobbs Reproductive-Data Minimization and Legal-Process Strategy
In light of the evolving legal landscape following the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization (2022) and subsequent state legislation restricting reproductive healthcare, HealthyMama maintains an express commitment to data minimization and retention limitation specifically designed to reduce the volume of pregnancy-tracking data that would be available for compelled production.
Data-Minimization Commitments:
- Pregnancy-status data (gestational age, estimated due date, pregnancy stage, and transitions between pregnancy stages including from pregnant to postpartum) is retained only for the minimum duration necessary to provide active Platform services and is purged according to the accelerated retention schedule described in Section 9;
- We do not maintain historical archives of pregnancy-status transitions after the applicable retention period;
- We do not infer or record the reason for any change in pregnancy status (e.g., the Platform does not distinguish between live birth, miscarriage, stillbirth, termination, or other outcomes); and
- We design our data architecture to minimize the creation and retention of metadata from which pregnancy outcomes could be inferred.
Legal-Process Requirements for Reproductive Health Data:
- HealthyMama will not disclose reproductive health data (including pregnancy status, gestational age, due dates, pregnancy-stage transitions, and related clinical readings) to any law enforcement agency, government entity, or private litigant except pursuant to a valid court order or warrant issued by a court of competent jurisdiction;
- A subpoena, civil investigative demand, or administrative request alone is insufficient to compel disclosure of reproductive health data;
- Where legally permitted, HealthyMama will provide advance notice to the affected user before complying with any court order or warrant seeking reproductive health data, and will afford the user an opportunity to move to quash or modify the order;
- HealthyMama will evaluate any legal process seeking reproductive health data for facial validity, jurisdictional authority, and constitutional concerns (including potential conflicts with user's rights under the jurisdiction in which the user resides); and
- HealthyMama maintains the data-minimization commitments above in part so that less reproductive health data exists to produce in response to compelled legal process.
3.5 Biometric Data Disclosure (Illinois BIPA Protective Provision)
The Platform collects blood pressure readings (from certain devices that are yet to be determined) and blood glucose readings (from certain devices that are yet to be determined) synced from biometric-sensing devices connected to the Platform.
Important Legal Note Regarding BIPA Applicability:
Whether blood pressure readings and blood glucose readings constitute "biometric identifiers" or "biometric information" under the Illinois Biometric Information Privacy Act (740 ILCS 14/) ("BIPA") is uncertain. BIPA enumerates specific categories of biometric identifiers—retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry—and physiological measurements such as blood pressure and glucose levels may fall outside these enumerated categories. This disclosure is provided as a protective measure notwithstanding that uncertainty.
Biometric Data Practices (Protective Disclosure):
- What We Collect: Blood pressure readings (systolic/diastolic values and timestamps) and blood glucose readings (mg/dL values and timestamps) transmitted from connected Omron and Dexcom devices via their respective APIs.
- Purpose: Readings are collected solely to (a) store and display them for your personal health tracking, (b) run the three-tier routing response system (a simple range check against published ACOG reference ranges), and (c) where you are an OB-Referred user who has consented to data sharing, transmit structured reading data to your selected practice.
- Consent: By connecting a biometric-sensing device to the Platform and syncing readings, you provide affirmative consent to HealthyMama's collection, processing, storage, and use of such readings for the purposes described above. You may withdraw consent at any time by disconnecting the device integration in account settings.
- Retention: Biometric readings are retained for the duration of your active account plus [TBD — retention period, not to exceed three (3) years after account inactivity, subject to counsel confirmation]. Upon account deletion or consent withdrawal, biometric readings are destroyed within [TBD — number of days] days.
- Destruction: Upon satisfaction of the purpose for collection (account closure, consent withdrawal, or expiration of the retention period), biometric readings are permanently destroyed using industry-standard secure deletion methods. We do not retain biometric readings beyond the applicable retention period.
- No Sale or Disclosure: We do not sell, lease, trade, or otherwise profit from biometric readings. We do not disclose biometric readings to any third party except (a) to an OB practice with your explicit consent (OB-Referred path only), (b) to service providers contractually bound to equivalent protections, or (c) as required by valid legal process (subject to the legal-process protections in Section 3.4 above).
4. How We Use Your Information
4.1 Providing and Operating the Platform
- Creating and maintaining your account
- Delivering educational content keyed to your gestational stage
- Operating the AI companion (Natalie) to provide informational wellness responses
- Running the three-tier reading response system (simple range check of submitted readings against published ACOG reference ranges)
- Storing and displaying your wellness logs, journals, mood entries, and uploaded images
- Processing subscription payments and managing your billing relationship
- Providing customer support
4.2 AI Processing Activities and Transparency
Important: We are transparent about how AI processes your data within the Platform:
- Message classification: When you send a message to Natalie, the AI system classifies it into one of four categories (educational, restricted-topic redirect, emergency escalation, or crisis-resource referral) to determine the appropriate response type.
- Range checks: When you submit a clinical reading, the system performs a simple comparison against published ACOG reference ranges to determine which of three fixed routing messages to deliver. This is not a clinical assessment.
- Content surfacing: The AI may reference or surface relevant pre-authored educational content from the course library during conversations.
AI Transparency Disclosure:
Natalie is an automated artificial intelligence system—not a human being and not a clinician. When you interact with Natalie through the Platform, you are communicating with an AI-powered chatbot that generates responses using large language model technology. The Platform provides clear, real-time disclosure of this fact at or before the point of interaction. Natalie does not exercise clinical judgment, provide individualized medical advice, or make consequential healthcare decisions on your behalf.
HealthyMama is evaluating obligations under emerging AI transparency and governance laws, including:
- Colorado AI Act (SB 24-205, effective June 30, 2026): This Act applies to deployers of "high-risk AI systems" that make or substantially factor into "consequential decisions" affecting access to healthcare services. HealthyMama is evaluating whether the Three-Tier reading-response system and/or the Natalie AI companion constitute high-risk AI systems under the Act's definitions.
- California BOT Act (Cal. Bus. & Prof. Code § 17940 et seq.): This Act requires clear disclosure when a user is communicating with an automated system. HealthyMama provides such disclosure in-context within the Platform.
4.3 What We Do NOT Use Your Data For
YOUR PERSONAL INFORMATION, USER CONTENT, AND CONSUMER HEALTH DATA ARE NOT USED TO TRAIN, FINE-TUNE, OR IMPROVE ANY AI OR MACHINE-LEARNING MODEL.
Specifically:
- Your AI conversation history is NOT used as training data for the underlying large language model (LLM) or any other model;
- Your journal entries, mood logs, images, and other user-generated content are NOT used as AI training data;
- Dr. Pachtman's licensed educational course content is NOT used as AI training data;
- We do NOT sell or share your personal information for cross-context behavioral advertising;
- We do NOT use your data to build consumer profiles for sale to third parties; and
- We do NOT use clinical readings or health conditions for any purpose other than operating the three-tier response and storing data for your personal tracking.
4.4 Aggregate and De-Identified Data
We may use aggregated, de-identified usage data (from which individual identity cannot reasonably be re-identified) to:
- Evaluate platform quality, safety, and performance;
- Refine the AI companion's do-not-answer taxonomy and safety guardrails;
- Conduct internal research on platform usage patterns; and
- Generate aggregate statistical reports that do not identify individual users.
Such aggregate data is not consumer health data and is not subject to deletion requests.
5. Two Data Pathways: D2C and OB-Referred
5.1 Direct Consumer (D2C) Path
If you register without linking to an OB practice:
- All of your interactions with the Platform are fully user-directed;
- There is no healthcare provider in the data loop;
- No practice is formally associated with your account;
- Your data is not transmitted to any OB practice, hospital, or healthcare entity;
- HealthyMama is not acting as a Business Associate of any covered entity with respect to your data; and
- Your data is governed exclusively by this Privacy Policy and applicable consumer health data laws.
5.2 OB-Referred Path
If you self-select an onboarded OB practice during registration:
- The practice connection is user-declared and user-initiated (the practice does not order monitoring or initiate the connection);
- Your data within the Platform remains governed by this Privacy Policy;
- Certain data may be shared with your selected practice subject to your granular consent at the time of registration. [TBD: Specific data categories, cadence, and format of practice data sharing are pending final product and legal determination.]
- Data shared with the practice is structured, raw data (readings and timestamps) without HealthyMama-generated interpretations, flags, or risk scores;
- AI conversation history, mood logs, journal entries, and uploaded images are NEVER shared with the practice under any consent pathway;
- The practice may receive notification of Tier 2 or Tier 3 reading events. [TBD: Alert mechanics, consent structure, and scope are pending final determination.]
- Where data is shared with a practice that is a HIPAA-covered entity, HealthyMama operates as a Business Associate under a signed Business Associate Agreement, and HIPAA protections apply to that shared data; and
- You may view what data has been shared with your practice, when, and through what channel, and you may revoke or pause sharing at any time.
5.3 Data Already Transmitted to a Practice
If you revoke consent for data sharing or delete your account, data already transmitted to your OB practice is not retroactively retrievable or deletable by HealthyMama. Once in the practice's possession, that data is governed by the practice's own privacy practices and HIPAA obligations as a covered entity.
6. D2C OB Practice Identification and Commercial Use
IMPORTANT DISCLOSURE — PLEASE READ CAREFULLY
6.1 What We Collect
During onboarding, D2C users are prompted—but not required—to identify their current OB practice. Providing this information is entirely optional. If you choose not to identify your practice, your experience on the Platform is not affected.
6.2 How We Use This Information
If you voluntarily identify your OB practice, HealthyMama uses the aggregate, non-identifiable count of D2C users who have identified a given practice as a commercial lead-generation signal. Specifically, HealthyMama may approach that practice for a partnership conversation using aggregate data only (e.g., "a number of your patients are using the HealthyMama platform").
6.3 What We Will NEVER Do
- Your individual identity is never shared with the practice. The outreach is always aggregate ("a number of your patients"), never individually identifying ("Jane Smith is using HealthyMama").
- Your name, email, readings, health conditions, or any other personal information is never disclosed to the practice through this mechanism.
- We do not disclose that any specific individual is a HealthyMama user.
6.4 Consent
We obtain your explicit, affirmative consent at the point of collection before using your identified OB practice for this commercial purpose. This consent is separate from your acceptance of this Privacy Policy or the Terms of Service. You will receive a clear disclosure at the moment you are asked to identify your practice, explaining that the practice may be contacted by HealthyMama using aggregate platform usage data. If you do not consent, your identified practice will not contribute to lead-generation outreach.
7. Wearable and Third-Party Device Integrations
7.1 Supported Integrations
The Platform supports integration with the following FDA-cleared Class II medical devices:
- Dexcom Continuous Glucose Monitor (CGM): Blood glucose readings synced via the Dexcom API.
- Omron Blood Pressure Monitor: Blood pressure readings synced via the Omron API.
Both devices are OB-directed (your healthcare provider recommended or ordered their use). HealthyMama does not supply, sell, or recommend these devices.
7.2 Data Flow
When you connect a device:
- You authorize data transmission from the device manufacturer to HealthyMama via their API;
- Readings are stored on the Platform for your personal tracking and three-tier routing;
- We do not transmit your readings back to the device manufacturer; and
- We do not modify device operation or calibration.
7.3 Third-Party Privacy Terms and API Governance
Your use of Dexcom and Omron devices and their companion applications is governed by those companies' own terms of service and privacy policies. HealthyMama is not responsible for the data practices of device manufacturers.
You acknowledge that:
- Data obtained by HealthyMama through the Dexcom and Omron APIs is also subject to those manufacturers' API terms of service, developer agreements, and data-use restrictions;
- HealthyMama's use of device-originated data is limited to the purposes authorized under the applicable API terms and as described in this Policy;
- Device manufacturers may modify, restrict, suspend, or discontinue API access at any time, which may affect the Platform's ability to receive device data;
- HealthyMama does not control and is not responsible for the data that device manufacturers collect through their own apps and services independently of the Platform; and
- You should review the privacy policies and terms of service of each device manufacturer independently.
We encourage you to review:
- Dexcom's Privacy Policy (available at dexcom.com)
- Omron's Privacy Policy (available at omronhealthcare.com)
8. Disclosure of Information to Third Parties
8.1 Service Providers and Sub-Processors
We share personal information with service providers who process data on our behalf solely to operate the Platform. These include:
- Cloud hosting: Microsoft Azure (HIPAA-compliant US data centers)
- AI model provider: [TBD — name of LLM provider] (subject to data processing agreement prohibiting use of user prompts/responses for model training)
- Payment processing: Apple App Store and Google Play (subscription billing); PCI-DSS-compliant third-party processors
- Analytics: [TBD — analytics provider, if any] (receives only de-identified or aggregated usage data)
- Email/communications: [TBD — provider] (for transactional communications only)
All service providers are contractually obligated to use your data only for the specific service they provide to us and to maintain appropriate security measures.
8.2 OB Practices (OB-Referred Path Only)
For OB-Referred users who have consented to data sharing, structured reading data (and only the specific categories consented to) may be shared with the selected practice. See Section 5.2 for details.
8.3 No Sale of Consumer Health Data
We do NOT sell consumer health data. We do not sell, rent, lease, or trade personal information, consumer health data, or sensitive personal information to any third party for monetary or other valuable consideration. For purposes of the California Consumer Privacy Act, we do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA.
8.4 No Sharing for Advertising
We do not share personal information with third parties for cross-context behavioral advertising, targeted advertising, or profiling purposes.
8.5 Legal and Safety Disclosures
We may disclose personal information if we believe in good faith that disclosure is necessary to:
- Comply with a valid court order, subpoena, or warrant (we do not voluntarily disclose to law enforcement absent legal compulsion);
- Protect the safety of a user or the public in an emergency involving risk of death or serious bodily harm;
- Enforce our Terms of Service; or
- Protect HealthyMama's legal rights.
Reproductive and pregnancy data: We will not disclose reproductive health information, pregnancy status, or related data to law enforcement or government agencies except pursuant to a valid court order or warrant issued by a court of competent jurisdiction. A subpoena alone is insufficient. We will provide notice to affected users to the extent permitted by law. See Section 3.4 for our complete reproductive-data legal-process policy.
8.6 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the successor entity. We will provide notice of any such transfer and any choices you may have regarding your information.
9. Data Retention and Deletion
9.1 Retention Periods
We retain your personal information for as long as your account is active and for a reasonable period thereafter, as follows:
- Account information: Duration of active account plus [TBD — retention period pending legal determination] following account closure
- Clinical readings (BP, glucose): Duration of active account plus [TBD — retention period, not to exceed three (3) years, subject to biometric-data provisions in Section 3.5]
- AI conversation history: Duration of active account plus [TBD — retention period]
- User-generated content (journals, images, mood logs): Duration of active account; deleted upon account deletion request
- Pregnancy-status and reproductive health data: Subject to accelerated retention — retained only for duration of active account; purged within [TBD — accelerated timeline] days of account closure or status change (see Section 3.4)
- De-identified aggregate data: Retained indefinitely (not subject to deletion requests)
- Financial/transaction records: As required by tax and financial regulations
- Audit and compliance logs: [TBD — retention period]
9.2 Account Deletion
You may request deletion of your account and associated data at any time by:
- Using the in-app account deletion feature; or
- Contacting us at [DPO/privacy contact email].
Upon receiving a verified deletion request, we will:
- Delete your account information, user content, clinical readings, AI conversation history, mood logs, journal entries, uploaded images, and device integration data within [TBD — number of days] days;
- Destroy biometric readings (BP, glucose) per the schedule in Section 3.5;
- Retain only information required for legal, financial, or regulatory compliance (which will be minimized and access-restricted); and
- Confirm deletion to you in writing.
9.3 Data Already Shared
Deletion of your HealthyMama account does not retroactively delete:
- Data already transmitted to an OB practice (OB-Referred path) — that data is governed by the practice's HIPAA obligations; or
- De-identified aggregate data from which your identity cannot be reconstructed.
9.4 Subscription vs. Account Deletion
Canceling your subscription ends access to paid features but does not delete your account or data. To delete your data, you must separately request account deletion.
10. Your Privacy Rights
10.1 General Rights
Depending on your state of residence, you may have some or all of the following rights regarding your personal information:
- Right to Know / Access: Request a copy of the personal information we have collected about you.
- Right to Delete: Request deletion of your personal information, subject to limited exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Opt Out of Sale/Sharing: We do not sell or share personal information, so this right is already honored by default.
- Right to Limit Use of Sensitive Personal Information: Request that we limit use of sensitive personal information to purposes necessary to provide the Platform.
- Right to Withdraw Consent: Withdraw any previously granted consent (withdrawal does not affect the lawfulness of processing prior to withdrawal).
- Right to Appeal: If we deny your privacy request, you have the right to appeal that decision.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
10.2 Consumer Health Data Rights
In addition to the general rights above, you have specific rights regarding consumer health data:
- Right to confirm whether we are collecting, sharing, or selling your consumer health data;
- Right to withdraw consent for future collection of consumer health data;
- Right to delete consumer health data and direct any processors to delete it;
- Right to know specifically what consumer health data we collected from you and what entities received it; and
- Right to a list of all third parties and affiliates with whom we have shared your consumer health data during the prior [12/24] months.
10.3 How to Exercise Your Rights
To submit a privacy request:
- Email: [DPO/privacy contact email]
- In-App: Account Settings > Privacy > Submit Request
- Mail: [HealthyMama, Inc.], [Address], [City, State ZIP]
We will verify your identity before processing any request. We will respond within the timeframes required by applicable law (typically 45 days, extendable by an additional 45 days with notice).
10.4 Authorized Agents
You may authorize an agent to submit requests on your behalf. We will require verification of both the agent's authority and your identity.
11. State-Specific Privacy Rights
11.1 Washington — My Health My Data Act (MHMDA)
If you are a Washington state resident or consumer, the following applies:
- Consent Before Collection: We obtain your separate, affirmative consent before collecting your consumer health data. Your consent is specific to the categories of data collected and the purposes of collection.
- Consent Before Sharing: We will not share your consumer health data with any third party without obtaining your separate, valid authorization. This authorization is distinct from consent to collect.
- Right to Delete: You may request deletion of all consumer health data we hold. Upon receipt of a verified request, we will delete the data and direct all processors to delete it within 30 days.
- No Sale: We do not sell consumer health data.
- Geofencing Prohibition: We do not use geofencing technology around healthcare facilities (including hospitals, clinics, OB/GYN offices, and reproductive health centers) to collect consumer health data, identify consumers seeking healthcare services, or send notifications, messages, or advertisements to consumers based on their proximity to such facilities.
- Consumer Health Data Privacy Authorization: Where required by the MHMDA, we will obtain a signed consumer health data privacy authorization before engaging in any activity that requires such authorization.
- Private Right of Action: Washington consumers have a private right of action for violations of the MHMDA, enforceable under the Washington Consumer Protection Act.
11.2 California — CCPA/CPRA
If you are a California resident, the following applies:
- Categories of PI Collected: Identifiers, health information, pregnancy/reproductive information, geolocation data (city-level only), internet activity, and inferences.
- Sensitive Personal Information: Health data, reproductive data, and precise geolocation (if collected) constitute sensitive personal information under the CPRA. You have the right to limit our use and disclosure of sensitive personal information to purposes necessary to perform the services you request.
- No Sale/No Sharing: We do not "sell" or "share" (as defined under the CCPA/CPRA) your personal information or sensitive personal information.
- Right to Know: You may request the categories and specific pieces of personal information collected, the sources, the business purposes, and the third parties with whom information is shared.
- Right to Delete: You may request deletion. We will delete and direct our service providers to delete, subject to permitted exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- No Discrimination: We will not deny services, charge different prices, or provide a different level of quality for exercising your CCPA/CPRA rights.
- CMIA Compliance: To the extent the California Confidentiality of Medical Information Act (CMIA) applies to information collected through the Platform, we comply with its requirements regarding authorization and confidentiality of medical information.
- Authorized Agent: You may use an authorized agent. We may require signed authorization and identity verification.
California "Shine the Light": We do not disclose personal information to third parties for their direct marketing purposes.
11.3 Nevada — Consumer Health Data (SB 370)
If you are a Nevada resident, the following applies:
- Consumer Health Data Protections: Under Nevada SB 370, we are prohibited from selling consumer health data without your valid authorization.
- Right to Delete: You may request deletion of consumer health data.
- No Sale: We do not sell consumer health data as defined under Nevada law.
- Opt-Out: You have the right to opt out of any future sale of consumer health data (although we do not currently engage in such sales). To submit an opt-out request, contact us at [DPO/privacy contact email].
- Existing NRS 603A Rights: You may also submit a verified request to opt out of the sale of covered information under NRS 603A.345.
11.4 Other State Comprehensive Privacy Laws
If you are a resident of Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, or another state with a comprehensive consumer privacy law in effect at the time of your request, you may have rights to access, delete, correct, and port your data, and to opt out of targeted advertising, profiling, and sales. Because we do not engage in targeted advertising, profiling for decisions that produce legal effects, or sales of personal data, many opt-out rights are already honored by default.
To exercise any state-specific right, contact us using the methods in Section 10.3. We will process your request in accordance with the applicable state law.
12. Children's Privacy
The Platform is intended for use by adults only (individuals who have reached the age of majority in their state of residence). We do not knowingly collect personal information from children under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [DPO/privacy contact email] and we will promptly delete such information.
The Platform is designed for individuals who are pregnant, trying to conceive, or postpartum — user populations that are, by their nature, adults.
13. Security
13.1 Technical Safeguards
We implement and maintain administrative, technical, and physical security measures designed to protect your personal information and consumer health data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- HIPAA-compliant Microsoft Azure cloud infrastructure (US data centers only)
- Role-based access controls with principle of least privilege
- Multi-factor authentication for administrative access
- Regular security assessments and vulnerability testing
- Audit logging of data access and system events
- Incident response procedures and breach notification protocols
13.2 Payment Data Security (PCI DSS)
HealthyMama does not directly collect, process, transmit, or store full payment card numbers, card verification values (CVV/CVC), or other sensitive cardholder data. All payment transactions are processed through PCI-DSS-compliant third-party payment processors and/or through the applicable App Store's billing infrastructure (Apple In-App Purchase or Google Play Billing). Your payment information is handled exclusively by these PCI-DSS-certified processors in accordance with Payment Card Industry Data Security Standards.
13.3 US-Only Data Residency
All personal information and consumer health data is stored exclusively in US-based data centers. We do not transfer data internationally.
13.4 State Data-Breach Notification
In the event of a security incident involving unauthorized access to, or acquisition of, personal information or consumer health data, HealthyMama will comply with all applicable state data-breach-notification laws in addition to any HIPAA breach-notification obligations (which apply only to the OB-Referred pathway where HealthyMama acts as a Business Associate).
Important: State breach-notification laws apply independently of HIPAA.
For D2C-pathway users, whose data generally does not constitute HIPAA-protected health information, state data-breach-notification statutes are the primary legal framework governing notification obligations in the event of a security incident. You should be aware that:
- Notification timing varies by state (ranging from 30 to 90 days, with some states requiring notification without unreasonable delay and specific-day caps);
- Some states require notification to the state attorney general and/or other regulatory bodies in addition to affected individuals;
- The definition of 'personal information' triggering notification obligations varies by state and may include health data, biometric data, and login credentials;
- HealthyMama maintains incident-response procedures designed to identify, contain, and assess security incidents promptly and to provide notifications within the timeframes required by each applicable state's breach-notification law; and
- In the event of a breach involving data of users in multiple states, HealthyMama will comply with the most protective applicable notification requirements.
[Drafting note: A 50-state data-breach-notification compliance matrix should be maintained and updated periodically. This is particularly important given that D2C-pathway health data is not PHI and therefore falls outside HIPAA's breach-notification framework — state laws are the sole governing regime for that data. The compliance matrix should map triggering definitions, notification timelines, AG notification requirements, and content requirements for each state where the platform has users. See DWT 50-state summary and comparable resources.]
13.5 Limitations
No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable measures to protect your personal information, we cannot guarantee absolute security.
14. International Users
The Platform is intended solely for use within the United States. We do not market to, or knowingly collect data from, individuals outside the United States. If you access the Platform from outside the US, you do so at your own initiative and are responsible for compliance with local laws. We make no representation that the Platform is appropriate or available for use in other jurisdictions.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or Platform features. If we make material changes:
- We will update the "Last Updated" date at the top of this Policy;
- We will provide prominent in-app notice of the changes;
- For changes affecting the collection or sharing of consumer health data, we will obtain new affirmative consent where required by applicable law; and
- We will provide at least thirty (30) days' advance notice before material changes take effect, except where a shorter period is required to comply with law or address an immediate safety concern.
Your continued use of the Platform after the effective date of a revised Policy constitutes your acknowledgment of the changes. If you do not agree with the revised Policy, you must stop using the Platform and may request deletion of your data.
16. Contact Us / How to Exercise Your Rights
If you have questions about this Privacy Policy, wish to exercise any of your privacy rights, or have a privacy concern or complaint, please contact us:
Privacy Contact / Data Protection Inquiries:
[HealthyMama, Inc.]Attn: [Privacy Officer]
4240 E Camelback Road, Suite 311
Phoenix, AZ 85018
Email: [info@healthymama.ai]
For California Residents: You may also submit requests via our designated methods as described in Section 10.3.
For Washington Residents: Consumer health data inquiries and MHMDA-specific requests may be submitted using the same contact methods above. We will process your request in accordance with the My Health My Data Act.
Response Times:
- General requests: Within 45 days (extendable by 45 days with notice)
- Washington MHMDA deletion requests: Within 30 days
- Urgent safety concerns: As promptly as possible
If you are dissatisfied with our response to your privacy concern, you may contact your state attorney general's office or applicable regulatory authority.