Consumer Health Data Privacy Policy
Last updated October 10, 2026
This policy describes the consumer health data that Cladose LLC collects through the Metryst app, as required by Washington's My Health My Data Act and similar state laws. It applies to Metryst users wherever they live.
In this policy, "records" means the Events (intimate encounter records), Periods (menstrual period records), unavailable dates and timeline markers you create in Metryst, including their details, answers and notes, and any of these a linked partner sends you that you accept.
Categories of consumer health data we collect
- Records of intimate encounters ("Events"), including dates and times, activities, positions, locations and other selected details, answers to questions, and notes.
- Menstrual period records and cycle settings, and period forecasts calculated from them.
- Unavailable dates and their optional reasons, and timeline markers and their notes, to the extent they reveal health or sexual activity.
- Records a linked partner sends you and you accept.
- Facts that can indicate sexual or reproductive activity: account-level service facts (for example, that a share was sent or accepted) and, only if you turn on usage statistics, facts such as whether you created your first Event and which features you used on a given day.
Why we collect and use it
- To provide Metryst as you request: store, sync, back up and restore your records, and show your history, insights and forecasts.
- To deliver records to a linked partner when you choose to send them.
- To keep the service secure and fix errors.
- If you turn on usage statistics, to understand which features are used so we can improve Metryst.
Sources
- You, through what you enter in the app.
- A partner you have linked with, when they send you a record and you accept it.
- The Metryst app on your devices (for example, forecasts, service facts and, if enabled, usage statistics).
Categories of consumer health data we share
- The records you choose to send to a linked partner.
- All categories above are processed by our service providers on our behalf, under their service agreements with us, which limit their use of the data to providing their services to us.
We do not sell consumer health data.
Third parties that receive consumer health data
- A partner whose account you have linked with, for the records you choose to send.
- Our service providers (processors): Supabase (database, server functions and account services); Apple (Sign in with Apple and App Store purchases; Apple receives purchase information, not your records); and Zoho (email), only if you include health information in an email to us.
Cladose has no affiliates that receive consumer health data.
Your rights and how to use them
- Confirm and access: ask whether we collect, share or sell your consumer health data, get a copy, and get a list of the third parties and affiliates that received it. You can also use Export My Data in Settings, then Account.
- Withdraw consent: turn off usage statistics in Settings at any time; stop sharing by not sending items or by ending a partner link; withdraw consent to collection by deleting your account.
- Delete: use Delete Account in Settings, then Account, or ask us by email. We delete your data from our active systems and notify our service providers. Copies in backups expire within 6 months.
To make a request, email privacy@cladose.com. We may need to verify your identity. We respond within 45 days (we may extend once by up to 45 days and will tell you if we do). Requests are free.
If we decline your request, you can appeal by replying to our decision or emailing privacy@cladose.com with "Appeal" in the subject. We will respond in writing within 45 days. If your appeal is denied, we will tell you how to contact your state's Attorney General to submit a complaint.