Consumer Health Data Privacy Policy

Last updated: August 27, 2026

This policy is provided with reference to the Washington My Health My Data Act (RCW 19.373), the California Consumer Privacy Act (CCPA/CPRA), and other applicable state consumer health data laws.

1. Consumer health data we collect

None. Halea is a local-first, serverless app. Halea Health does not collect, receive, store, or process your consumer health data. The categories below are handled by the app entirely on your device and are never transmitted to us:

  • Menstrual cycle start and end dates
  • Cycle length and predictions
  • Physical symptoms (cramps, headaches, skin changes, etc.)
  • Mood and emotional state
  • Energy levels and sleep quality
  • Biometric data read from Apple Health / Health Connect (temperature, heart rate variability, blood oxygen, sleep scores)
  • Fertility-related data (fertile window estimates, ovulation predictions)

2. Where your health data lives

  • On your device: everything you log stays in the app's local storage.
  • In your own backups (optional): backups go only to your own iCloud or Google Drive, encrypted on your device before they are uploaded. We cannot access them. See Data security for the one case where that encryption is not possible.

3. Sharing of consumer health data

We do not sell consumer health data — and we also cannot: we never possess it. There are no service providers or processors handling your health data on our behalf, because none of it reaches any infrastructure we operate. The only sharing that exists is sharing you perform yourself: exporting a doctor report or your data from the app and sending it, from your device, to a recipient you choose.

4. Consent

Access to Apple Health / Health Connect data is granted through the operating system's own permission prompts and can be revoked at any time in your device settings. All other logging happens only when you enter data yourself.

5. Your rights

The rights granted by consumer health data laws are satisfied structurally, and you exercise them directly on your device:

  • Right to know: everything the app has is visible in the app; we hold nothing.
  • Right to withdraw: revoke Health permissions in device settings; stop logging at any time.
  • Right to delete: delete entries in the app, delete the app, and remove your own backups — deletion is complete and immediate, with no server-side copies or retention windows.
  • Right to export: export your data from the app in standard formats.
  • Non-discrimination: the app works the same regardless of what you choose to log or share.

6. Data security

Your health data is protected by your device's security (including the app's biometric lock, if enabled) and, for backups, by encryption Halea applies on your device before anything is uploaded. The key is random, 256-bit, and never sent to Apple, Google, or us. It reaches your other devices through iCloud's end-to-end encrypted key sync or Google Block Store — channels Apple and Google cannot read — so restoring onto a new phone still works. You can set a recovery passphrase as a second way in. Halea cannot reset that passphrase; if we could, it would not be protecting anything.

Encryption depends on there being a way back to the key. Where a device cannot store a key that would survive onto a replacement phone and no recovery passphrase is set, Halea uploads the backup unencrypted rather than create one that could never be opened again — a backup you cannot restore is not a backup. Your cloud provider's own encryption in transit and at rest still applies, and on iOS with Advanced Data Protection the backup is end-to-end encrypted by Apple. The Backup screen shows which case applies to you.

Because there is no server, there is no server to breach.

7. Questions

Contact us at [email protected]. We will respond within 15 days.