Legal

Privacy & Health Data Policy

Applies to: Her Journey: Phase | Her Journey: Carry | Her Journey: Wisdom
Operated by Ziggy Tech Ventures LLC, Las Vegas, NV

Last updated: March 17, 2026

Contents

  1. 1.Who We Are
  2. 2.Health Data We Collect
  3. 3.How We Use Your Data
  4. 4.Data Sharing & Processors
  5. 5.Storage & Security
  6. 6.Washington MHMDA Compliance
  7. 7.FTC Health Breach Notification
  8. 8.Wearable & Connected Devices
  9. 9.Not Medical Advice
  10. 10.Data Retention & Deletion
  11. 11.Children's Privacy (COPPA)
  12. 12.Law Enforcement Requests
  13. 13.Sensitive Health Data Protections
  14. 14.Your Rights (CCPA / GDPR)
  15. 15.Contact
§1

Who We Are

Ziggy Tech Ventures LLC is a Nevada limited liability company (EIN 41-4738365) operating the Her Journey Suite of applications. Our primary contact for all privacy and legal matters is ziggytech@icloud.com.

The "Her Journey Suite" collectively refers to Her Journey: Phase (menstrual cycle tracking), Her Journey: Carry (pregnancy journey), and Her Journey: Wisdom (menopause navigation). All three apps share the privacy commitments described in this document.

§2

Health Data We Collect

Her Journey: Phase

  • Menstrual cycle dates and patterns
  • Ovulation predictions and tracking data
  • Mood logs and emotional wellness entries
  • Symptom logs (physical and emotional)
  • Partner access preferences and relationship context data
  • Account email, onboarding responses, app usage data

Her Journey: Carry

  • Pregnancy dates and estimated due date
  • Week-by-week milestone tracking and journal entries
  • Mood and symptom logs specific to pregnancy
  • Baby movement notes and kick counter data
  • Support circle membership data
  • Account email, onboarding responses, app usage data

Her Journey: Wisdom

  • Menopause symptom logs
  • Hormone protocol logs and HRT/supplement tracking
  • Wisdom circle Q&A data and community contributions
  • Account email, onboarding responses, app usage data
§3

How We Use Your Data

We use your health data exclusively for your benefit — to power the wellness features you chose. Here is our complete commitment:

What we do

  • Power core wellness features of your chosen app
  • Generate personalized insights and recommendations within the app
  • Deliver notifications and reminders you've requested
  • Support your account management and data portability

What we never do

  • Sell your data to any third party — ever
  • Share with data brokers or aggregators
  • Use for advertising targeting
  • Allow Meta, Google Ads, or any ad network access to your health data
  • Share with employers, insurers, or healthcare systems without explicit written consent
  • Use individual health entries to train external AI models
§4

Data Sharing & Processors

We do not sell your data. Ever. We do not share your health data with advertisers, data brokers, or any third party for commercial purposes.

Sub-Processors

Your data passes through two infrastructure providers, both acting strictly as data processors under our instruction:

SupabaseDatabase & Authentication

Stores your health data and manages authentication. Supabase operates under SOC 2 compliance and processes data solely as a data processor on our behalf. Data is encrypted in transit (TLS) and at rest (AES-256).

VercelHosting & Edge Network

Serves the application globally. Vercel does not have access to your health data stored in our database.

No other third parties receive your health data. We do not integrate advertising SDKs, analytics that transmit health data externally, or any data broker APIs.

§5

Storage & Security

We take the security of your reproductive health data seriously. Here is how we protect it:

Encryption at rest

All health data stored in Supabase is encrypted at rest using AES-256.

Encryption in transit

All data transmitted between your device and our servers uses TLS 1.2 or higher.

Access controls

Database access is restricted to authenticated users viewing only their own data via row-level security (RLS) policies enforced by Supabase.

No plaintext health data in logs

We do not log your specific health entries in server logs or analytics.

Breach notification

In the event of a breach, we notify affected users without unreasonable delay per FTC Health Breach Notification Rule requirements.

§6

Washington My Health My Data Act (MHMDA)

We comply fully with the Washington My Health My Data Act and apply it as a standard for all users, not just Washington state residents.

Affirmative Consent

We obtain your explicit, affirmative consent before collecting any consumer health data. Consent is logged with a timestamp and policy version number.

Right to Access

You have the right to know what health data we hold about you. Request an export at any time from Settings or by emailing ziggytech@icloud.com.

Right to Correct

You have the right to correct any inaccurate health data. All health entries can be edited directly in the app.

Right to Delete

You have the right to request deletion of your consumer health data. Requests are processed within 30 days.

No Data Sale

We do not sell consumer health data as defined by the MHMDA. This is a firm, unconditional commitment.

Law Enforcement

We notify users of law enforcement requests for their health data unless legally prohibited from doing so.

§7

FTC Health Breach Notification

We comply with the FTC Health Breach Notification Rule (16 C.F.R. Part 318). In the event of a security breach involving your health information, we will notify all affected users without unreasonable delay — and within all legally required timeframes. Our notification will describe what happened, what data was involved, and steps you can take to protect yourself.

§8

Wearable & Connected Health Devices

Apple HealthKit

We may request access to Apple HealthKit data (heart rate, HRV, cycle tracking, sleep, activity) to enhance your wellness insights. HealthKit data is used solely within the app — it is never shared with third parties, never used for advertising, and never uploaded to our servers without your explicit consent. Revoke HealthKit access at any time in iOS Settings › Privacy & Security › Health.

Google Fit / Wear OS

The same commitment applies for Android users. Health data from connected wearables is used only for in-app wellness features — never shared, never sold, never used for ads.

FDA Disclaimer

Wearable-based insights are not FDA-cleared medical devices. Do not use these insights to make medical decisions. Always consult a qualified healthcare provider.

Data Minimization

We request only the specific data types needed for currently active features. Additional permissions are requested only when you activate new features — with a clear explanation each time.

§9

Not Medical Advice

Her Journey: Phase is a wellness tool — not a medical device or healthcare provider. Nothing in this app constitutes medical advice, diagnosis, or treatment.

Using this app does not create a doctor-patient relationship. Always consult a qualified healthcare professional — your doctor, OB-GYN, or midwife — for menstrual irregularities, fertility concerns, or any health symptom that concerns you. When in doubt, call your doctor.

§10

Data Retention & Deletion

We retain your data for as long as your account is active. You can permanently delete your account and all associated health data at any time from Settings › Account › Delete Account, or by emailing ziggytech@icloud.com.

Deletion is permanent and irreversible. All health entries, logs, onboarding data, and account information will be removed within 30 days. Export your data from Settings before deleting.

§11

Children's Privacy (COPPA)

Her Journey: Phase is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us immediately at ziggytech@icloud.com.

§12

Law Enforcement Requests

We do not proactively share your health data with law enforcement. We require a valid legal process (warrant, court order, or subpoena) before producing any user data, and we review all requests for legal sufficiency.

We notify you of law enforcement requests for your data unless legally prohibited. In jurisdictions where reproductive health data may be subject to subpoena, we apply strict data minimization — collecting only what is needed for app functionality, and retaining no location data tied to reproductive health events.

§13

Sensitive Health Data Protections

Reproductive health data — including menstrual cycles, ovulation, and fertility information — receives our highest level of protection.

This data will never be shared with:

  • Employers or potential employers
  • Health insurers, life insurers, or disability insurers
  • Law enforcement, government agencies, or courts — except by valid court order or warrant, which we will contest if legally permissible
  • Data brokers, aggregators, or analytics platforms
  • Any entity for the purpose of tracking reproductive choices or outcomes

We collect only the minimum data necessary for app functionality. We do not collect or store location data tied to reproductive health events. In jurisdictions where reproductive health data may be subject to legal compulsion, we apply data minimization as a first line of defense.

§14

Your Rights (CCPA / GDPR)

California residents (CCPA/CPRA): You have the right to know, access, correct, delete, and opt out of the sale of your personal and health information. We do not sell personal information. Submit requests to ziggytech@icloud.com with subject "CCPA Rights Request — Phase."

EU/EEA/UK residents (GDPR): You have rights of access, rectification, erasure ("right to be forgotten"), restriction, portability, and objection. Our lawful basis for processing health data is your explicit consent (Article 9(2)(a) GDPR). Withdraw consent at any time in Settings. To exercise GDPR rights, contact ziggytech@icloud.com with subject "GDPR Rights Request — Phase."

Access

Know what data we hold about you

Settings › Export My Data or email us

Correction

Fix inaccurate entries

Edit directly in-app or contact us

Deletion

Remove all your data permanently

Settings › Delete Account or email us

Portability

Receive your data in a readable format

Settings › Export My Data

Withdraw Consent

Stop health data collection

Email ziggytech@icloud.com

Opt-Out (CCPA)

Opt out of sale (we don't sell, but you can assert the right)

Email ziggytech@icloud.com

Complaint

Lodge a formal complaint

CA: CPPA (cppa.ca.gov) · EU: your local DPA

§15

Contact

Ziggy Tech Ventures LLC
Las Vegas, Nevada
ziggytech@icloud.com

For privacy rights requests, use subject: "Privacy Rights Request — Phase"
For health data deletion: "Health Data Deletion — Phase"
We will respond within 45 days of a verified request.