Privacy Policy
Effective: June 12, 2026
HiDoula exists to help doulas and families coordinate around one of the most personal moments there is. That only works if the privacy bar is high. This policy explains, in plain English, what we collect, what we deliberately avoid, and the choices you have.
1. What we collect
- Account and contact data: your name, email address, and (for doulas) practice details you provide.
- Practice branding: practice logos you upload, if any. We store them so your practice name and mark can appear on the pages and documents you brand.
- Billing metadata: doula subscription records via Stripe. Your card data goes directly to Stripe and never touches our servers; we keep only billing metadata such as purchase status and receipts.
- Operational metadata: information our systems need to run the service: timestamps, due dates, labor-status category, appointment times, names of people in a care space, and who is connected to whom.
- Contacts and reach-out preferences: the names, phone numbers, email addresses, mailing addresses, and preferred contact method (call, text, or another app) you add for the people you support and your own care team, so the app can put the right one-tap launch in front of you and, for doulas, reach and bill their clients. You choose what to add, whether you type it in or, in our mobile app, pick it from your phone’s own contacts. We store only the entries you select.
- Invoicing and payment details (for doulas): if you use the practice tools, we store the invoices you create (amounts, line items, dates, and status) and the payment-method handles you choose to show your clients, such as a Venmo, PayPal, Zelle, or Square handle, or a note that you take cash. HiDoula does not process the payment and never stores card or bank-account numbers. Your client pays you directly through whatever method you list.
- Device and log data: IP address, browser/device information, and security logs used to keep the service reliable and detect abuse.
2. Calls and messages stay on your phone
HiDoula does not carry your calls or messages. When you reach a member of your care team or support circle, the app simply opens your phone’s own apps: the dialer, your texting app, or another app you choose. It hands off to them, and the content of those calls and messages never passes through HiDoula and is never stored on our servers. We keep only the contact entry and your chosen reach-out preference, as described above.
Earlier versions of HiDoula included an in-app message thread. That feature has been retired in favor of your phone’s own apps. Any messages you exchanged before then remain available to you as a clearly-labeled, read-only archive. We do not delete your history, but no new in-app messages are sent or received through HiDoula.
3. User-created care content
Birth plan text, notes, and contraction notes, along with the message history in your read-only archive, are treated differently from everything above. HiDoula is designed to minimize our access to user-created care content: where supported, this content is encrypted on your device before it syncs, using keys held on your devices. We do not intend to access it in plaintext, and we do not use it for advertising, profiling, or model training. Operational metadata (such as that a contraction entry exists and its timing) is still processed by our systems so the product can work.
4. Consumer health data
Information related to pregnancy, birth plans, contraction timing, appointments, labor, and postpartum support is sensitive personal and health-related information, and we treat it that way: it is collected only to provide the service you asked for, shared only with the people you connect, protected with the measures described in this policy and our security overview, and never sold. Our standalone Consumer Health Data Policy covers this category in detail.
5. What we deliberately do not do
- We do not sell personal data, and we never sell health-related information.
- No advertising trackers or third-party ad networks anywhere in the product.
- No analytics inside the app, and no session-replay tools anywhere. We use Google Analytics on our public marketing pages only (with IP anonymization and ad personalization disabled) to understand how visitors find HiDoula. Analytics never runs inside the app: your care space, tracker, and any health-related screens are analytics-free, and no health information is ever sent to analytics.
- We do not route your calls or text messages through HiDoula. The app opens your phone’s own apps to connect you; their content stays between you and the person you reach.
- We do not use care content to train advertising or profiling systems.
6. How we use data
Only to operate HiDoula: showing your information to you and the people you connect, sending the emails and notifications you ask for, processing subscription payments, responding to support requests, and keeping the service secure and reliable.
7. Subprocessors
We rely on a small set of infrastructure providers. Each receives only what its role requires:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and storage | Account data, operational metadata, and encrypted care content (encrypted on device before sync where supported) |
| Vercel | Application hosting and content delivery | Request and connection data needed to serve the app (IP address, device/browser information, logs) |
| Stripe | Payment processing for the doula subscription | Billing name, email, and payment details (card data goes directly to Stripe and never touches our servers). No care content. |
| Email delivery providers (Hostinger for sending; ImprovMX for inbound forwarding) | Transactional email (sign-in links, invitations, notifications) and support-mail forwarding | Email address and the minimum message content needed to deliver the email. No care content in email bodies or subjects. |
| Google LLC (Google Analytics) | Marketing-site analytics: page views on our public marketing pages only | Anonymized page-view data from marketing pages (IP anonymization on; Google signals and ad personalization off). Prohibited: any in-app pages, any health-related data, and any user identifiers. |
Beyond these providers and the people you choose to connect with, we share personal data only when required by law or to protect the safety and integrity of the service, and we will tell you when the law allows us to.
8. Cookies and tracking
We keep tracking to a minimum. The app itself uses only the cookies and local storage needed to sign you in and run the service; it has no advertising or analytics trackers. Our public marketing pages use Google Analytics for anonymized page-view counts, and that is the only non-essential tracking anywhere in HiDoula.
Consent banner. Whether marketing-page analytics runs at all depends on your consent. The first time you visit, a consent banner appears, and analytics is gated through Google’s consent mode, so it stays off until consent is recorded. The banner is geo-aware: if you are in the EU or UK, analytics is opt-in and does not run unless you choose “Accept”; elsewhere (including the US) the banner serves as notice, and you can decline at any time.
Global Privacy Control. We honor the Global Privacy Control (GPC) browser signal. If your browser or extension sends GPC, we treat it as a choice to decline non-essential analytics, and the banner reflects that.
How your choice is stored, and how to change it. Your analytics choice is saved on your own device, in your browser’s local storage (under the key hidoula:consent:analytics) and a matching hd_consent cookie, so we can remember it without identifying you. To change your decision, reopen the consent banner and update your choice, send a GPC signal from your browser, or clear HiDoula’s cookies and site data to be asked again on your next visit.
9. California Notice at Collection
This notice is for California residents and supplements the rest of this policy. At or before the point of collection, we tell you the categories of personal information we collect and why. The categories we collect are:
- Identifiers and contact data: name, email address, and the contact entries (including phone, email, and mailing address) you add for the people you support and your care team.
- Commercial information: doula subscription and billing metadata (processed by Stripe; we do not store card numbers), and, for doulas using the practice tools, invoices they create and the payment-method handles they choose to display.
- Internet and device activity: IP address, browser/device information, and security logs.
- Health-related and sensitive information: pregnancy, birth-plan, contraction-timing, appointment, labor, and postpartum information you choose to enter.
Purposes. We use these categories only to provide and operate HiDoula: running your care space, processing payments, sending the emails and notifications you ask for, responding to support, and keeping the service secure and reliable. We do not use sensitive personal information to infer characteristics about you.
No sale, no sharing for ads. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months. Because we do not sell or share in this sense, there is nothing to opt out of, but we still honor the Global Privacy Control (GPC) signal as an opt-out preference.
California residents may request access, deletion, correction, and the other rights described in “Your rights” below, and we will not discriminate against you for exercising them. To make a request, email hello@hidoula.app.
10. Retention and deletion
We keep your data while your account is active so the service can work. You can request account deletion or a copy of your data at any time by emailing hello@hidoula.app; we will verify the request and act on it within 30 days. In-product deletion and export tools are available or in progress; email works today regardless. Some records (such as billing records and security logs) may be retained where the law requires it.
11. Your rights
You can ask us to access, export, correct, or delete your personal data, and we honor those requests regardless of where you live. Depending on your jurisdiction you may also have specific statutory rights. For example, consumer-health-data rights under laws such as Washington’s My Health My Data Act, rights under other U.S. state privacy laws, or GDPR-style rights of access, rectification, erasure, portability, and objection if you are in the EU or UK. To exercise any of these, email hello@hidoula.app. If you believe we have not handled your data properly, you may also contact your local data protection or consumer-protection authority.
12. If something goes wrong
If a security incident affects your personal data, we will notify affected users and the relevant authorities as required by applicable law, including breach-notification rules that apply to health-related consumer data, such as the FTC Health Breach Notification Rule, without unreasonable delay, and we will tell you plainly what happened and what we are doing about it.
13. Honest limits
- Data on your own device may still be accessible to anyone with access to your unlocked device; device passcodes and screen locks matter.
- People you share a care space with can see what you share with them; choose your invitees with care.
- Once HiDoula hands a call or message off to your phone’s own apps, those apps and their providers (your phone carrier, your messaging app) handle it under their own terms, not ours.
- No encryption system eliminates all risk.
14. Children
HiDoula is not directed to anyone under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact hello@hidoula.app and we will delete it.
15. Changes
We will notify you of material changes to this policy by email or in-app notice before they take effect, and we will not weaken how we handle previously collected health-related data without asking first.
16. Contact
Privacy questions and requests: hello@hidoula.app. General questions: hello@hidoula.app.