Skip to content
gladlyHealth

Privacy & your data

Last updated 9 August 2026

The short version

You answer nine questions. Those answers are stored in our database and used to write the page you see next and, if you give us your email address, to send you a copy. We do not sell them, we do not send them to advertising platforms, and we do not use them to target adverts at you.

Because some of this is health information, there is a separate page — Consumer health data — covering it specifically, including the rights Washington and Nevada residents hold by law and the honest mechanics of deletion. This page is the general picture.

What we collect

  • Your quiz answers. Nine multiple-choice answers about sleep, temperature, mood, memory, your cycle and whether you have seen a doctor. The quiz has no free-text field.
  • Your email address, if you choose to give it — either on this site, or in a sign-up form inside Facebook or Instagram (Meta lead ads) if that is where you first met us. In the second case Meta was the collection point and holds its own copy under its own policies.
  • Which advert you arrived from. The campaign tags in the link you clicked. They describe the advert; stored alongside your row, they become part of what we delete when you ask.
  • Step counters. That a page was visited, a quiz started, a quiz finished — a count with no name or answer attached. Like any website, the servers that deliver these pages briefly handle your IP address to do it.
  • Consent records.When you agreed to the quiz and whether you ticked the optional program-updates box — kept so that “she agreed” is a fact with a date, not a guess.

If you pay the reservation deposit, the card details go to Stripe. We see the payment status and the email you used, never the card.

The part most health sites get wrong

Advertising and analytics tools work by loading someone else’s code into your browser, which can then read the page around it. That is how health information ends up at advertising companies without anyone deciding it should. The Federal Trade Commission has taken action against health services over exactly this.

We build against it in three specific ways:

  • No advertising pixel and no analytics script loads anywhere on this site. Not on the quiz, not on the result page, not on the landing page.
  • Your answers travel in the body of a request, never in a web address, and the code that reports funnel steps accepts one event name from a fixed list — there is no field to put a symptom in.
  • No session-recording tool runs on the quiz or the result page.

And the honest history, because a policy that hides it is worth nothing: between 29 July and 9 August 2026 a Meta advertising pixel did load on this site, sending Meta standard page-view signals — IP address, browser identifiers, the fact of a visit, never quiz answers. In the same period an optional AI chat relayed what visitors typed in it to OpenRouter and Anthropic to generate replies. Both were removed on 9 August 2026, and both are described in the consumer health data notice.

What we do with it

  • Write and send your result.
  • Email you about this program — only if you ticked the separate box asking for that. Every email has an unsubscribe link that works.
  • Understand, in aggregate, which adverts bring people who find this useful.

We do not use your answers to target adverts, we do not build advertising audiences from your data, and we do not build a profile of you for anyone else.

Who else touches it

Service providers, each doing one job: Cloudflare hosts the site and the database, Stripe processes payments, Resend delivers the emails, and Meta is the collection point when you sign up through a form inside Facebook or Instagram. Cloudflare and Resend act on our instructions. Stripe, as a payment company, also has independent legal duties of its own and keeps transaction records under its own rules.

How long we keep it

Quiz answers and email addresses are kept while this programme is being developed, at most 12 months from your last interaction, then deleted.

Your choices

Write to [email protected] and ask for a copy of what we hold, a correction, or deletion. Deletion covers the answers, the email address and everything tied to them in our database, and we instruct our service providers to do the same. Two honest mechanics, spelled out in the health data notice: automatic database backups can hold a deleted record for up to about 30 days before it is gone everywhere, and Stripe retains what payment law requires. We confirm when deletion is done, we do not ask you to justify it, and if you think we got it wrong you can appeal and a person will answer with reasons. For Washington and Nevada residents these are statutory rights; we honour them for everyone.

Not covered by HIPAA — and what does cover us

Gladly Healthis not currently a healthcare provider, so HIPAA does not apply to this site. We say that plainly because plenty of wellness services let people assume otherwise. What does apply: the FTC Act, which forbids saying one thing in a privacy policy and doing another, and state consumer-health-data laws such as Washington’s My Health My Data Act. When clinical care begins, the parts of the service that involve a clinician will fall under healthcare privacy rules, and this page will change to say so.

Children

This site is for adults. We do not knowingly collect information from anyone under 18.

Changes, and how to reach us

Past versions of this policy are kept, not overwritten. If a change affects what we do with information we already hold, we will not simply rely on it — where the law requires consent, we will ask for it before acting under the new terms.

Questions go to [email protected], and a person answers them.