MenoTracker
Consumer health data

Your health data, specifically.

This is MenoTracker's consumer health data privacy policy. It exists because laws such as Washington State's My Health My Data Act (chapter 19.373 RCW) ask health apps to say, separately and plainly, what health data they collect and what rights you have over it. It supplements our main privacy policy; where the two overlap, both are true — this one is just more specific. We honor the rights below for every user, wherever you live, including consumers in Washington and in states with materially similar laws such as Nevada.

Nº 01The consumer health data we collect, and why

  • Your menopause stage — the stage you select during onboarding (perimenopause, menopause, postmenopause). Collected to tailor what the app shows you.
  • Your symptom entries — for each entry: the date, the symptom type, a severity from 1 to 10, and a note if you typed one. Collected to show you your history and patterns — the service you asked for.
  • Your birth year — optional, only if you enter it. Used for context in your tracking.
  • AI pattern summaries — if you subscribe to Plus and open Insights, a summary of your recent entries is generated. That summary is itself health data and is treated as such.
  • Usage signals from a health app — with your consent (asked in the app from version 1.0.4), we record product events such as "a symptom was logged" or "a screen was opened". They never contain which symptom, its severity, your stage, or anything you typed — but the fact that your account uses a menopause app is itself health-related, which is why it is consent-gated and listed here.

We collect health data from one source: you, entering it in the app. We do not buy it, scrape it, infer it from advertising profiles, or pull it from Apple Health or Google Fit. We do not use geofencing anywhere, for anything.

Nº 02Consent

Your entries are collected because collecting them is the service you requested — a symptom tracker cannot track without them. The app also asks for your explicit consent in words, during onboarding, before your first entry is stored (from version 1.0.4). Anything beyond that necessity — product analytics and crash reporting — is opt-in: the app asks first, and a "no" costs you no feature. You can change your answer at any time in Settings, and withdraw consent for everything at once by deleting your account.

Nº 03Sharing — the categories, and the list

We do not sell consumer health data, and we never have. No advertising, no data brokers, no insurers, no employers. We have no affiliates. Health data reaches exactly the processors it takes to run the service, under contracts that bind them to our instructions:

  • Supabase (supabase.com) — hosts the database, in the European Union. All entries live here.
  • OpenAI (openai.com) — receives your last 30 days of entries only when you, as a Plus subscriber, request Insights; returns the summary; does not train on it. United States, under standard contractual clauses.
  • RevenueCat (revenuecat.com), Apple, Google — subscription state against a pseudonymous identifier. They do not receive your entries.
  • PostHog (posthog.com, EU hosting) — consent-gated usage events, content-free as described above.
  • Sentry (sentry.io) — consent-gated crash reports. No entry content.
  • Vercel (vercel.com) — hosts this website. The app's health data never passes through it.
  • Resend (resend.com) — delivers contact-form email. No health data unless you write it to us yourself.

If you ask, we will confirm whether we collect your health data and give you this list with contact details, as the Washington act requires.

Nº 04Your rights, and how to use them

  • Access — ask us to confirm what we hold and to show it to you, including who it was shared with.
  • Withdraw consent — turn analytics off in Settings at any time; withdraw consent for the health data itself by deleting your account.
  • Delete — delete individual entries in the app, or the whole account under Settings → Delete account. Deletion removes your data from our production systems immediately and from backups and archives within six months at the latest. We pass the deletion request on to the processors above.

For anything you cannot do in the app, email start@djump.io. We respond within 45 days; where a request is unusually complex we may take one extension of a further 45 days, and we will tell you if so.

Nº 05Appeals

If we refuse a request, you may appeal: reply to our refusal, or write to start@djump.io with the subject line "Appeal — consumer health data". We will answer in writing within 45 days, with reasons. If you are a Washington consumer and the appeal fails, you may raise it with the Washington State Attorney General at atg.wa.gov/file-complaint.

Nº 06Changes

If we ever intend to collect a new category of health data or use it for a new purpose, we will ask for your affirmative consent first — not bury it in an update to this page. Editorial changes are reflected in the effective date above.

Nº 07Contact

DJUMP, MB · Klaipėda, Lithuania
start@djump.io

← The main privacy policy