Privacy Policy
Last updated:
At Misa, your privacy is not a formality. It’s foundational to everything we build. This Privacy Policy explains how Misa Wellness, PBC (“Misa,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use our website, mobile application, and related services (collectively, the “Platform”). By using our Platform, you agree to the collection and use of your information as described in this Privacy Policy.
1. Information We Collect
We collect information in the following ways:
Information You Provide Directly
- Account information: name, email address, date of birth, and password
- Health and cycle data: menstrual cycle dates, cycle length, symptoms, mood, energy levels, and other wellness reflections you log
- Physical data: height, weight, fitness level, dietary preferences, and wellness goals
- Communications: messages you send to our support team or submit through contact forms
Information Collected Automatically
- Device information: IP address, device type, operating system, and browser type
- Usage data: pages visited, features used, time spent on the Platform, and click patterns
- Log data: error reports, performance data, and access timestamps
- Cookies and similar tracking technologies (see Section 6)
Information from Third-Party Integrations
If you connect wearable devices or third-party health apps (such as Oura or Whoop), we may receive data from those services, including sleep metrics, heart rate variability, and activity data. This sharing is subject to your authorization and the privacy policies of those third-party services.
2. How We Use Your Information
We use your information to:
- Provide, personalize, and improve your experience on the Platform
- Deliver cycle-synced nutrition, movement, and mindfulness recommendations tailored to you
- Send you app notifications, reminders, and wellness insights
- Respond to your inquiries and provide customer support
- Conduct internal research using de-identified and aggregated data to improve our services — this data is stripped of all personal identifiers and cannot be re-linked to you
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following limited circumstances:
- Service Providers: We share data with trusted third-party vendors who help us operate the Platform (e.g., cloud hosting, email delivery). These vendors are contractually bound to protect your data and use it only for the purposes we specify. Today those vendors are our website host, which also provides the aggregate analytics described in Section 6, and our email marketing provider, which holds the name and email address you give us when you join the waitlist.
- Wearable & Integration Partners: If you connect a third-party device or service, we share only the data necessary to enable that integration, with your consent.
- Legal Requirements: We may disclose information if required by law, regulation, or legal process, or to protect the rights, property, or safety of Misa, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and your rights.
- With Your Consent: We may share information for other purposes with your explicit consent.
4. Health Data & Sensitive Information
Misa handles health and menstrual cycle data as sensitive personal information. We apply additional protections to this data, including:
- Encryption of health data at rest and in transit
- Strict internal access controls limiting who can view your health data
- We do not share your identifiable health data with advertisers or data brokers
- We do not use your health data to make automated decisions that significantly affect you without human oversight
You have the right to access, correct, and delete your health data at any time through your account settings or by contacting us.
5. Data Retention & De-identification
We retain your personal information only for as long as your account is active or as needed to provide you with the Platform’s core services.
- Data Scrubbing for Research: To support our mission as a Public Benefit Corporation, we may de-identify and aggregate health and cycle data for internal research purposes. Once de-identified, data is stripped of all personal identifiers — including your name, email, and IP address — so that it can no longer be linked back to you.
- Irreversibility: We commit to maintaining this data in de-identified form and will not attempt to re-identify any individual user from our research datasets.
- User-Initiated Deletion: If you request deletion of your account, we will purge your identifiable personal information from our active databases within 30 days. Any data retained thereafter for research will exist only in a fully anonymized, aggregate format that does not constitute ‘personal information’ under California law.
- Retention Limits: We periodically review our databases to ensure we are not holding sensitive data longer than necessary for your wellness journey.
Please note that during the beta period, data deletion capabilities are actively being developed and may be subject to technical limitations.
6. Cookies & Tracking Technologies
Our website sets no cookies. It loads no advertising trackers and does not follow you across other sites, and we do not engage in cross-site behavioral advertising.
Analytics. We use Vercel Web Analytics, provided by the company that also hosts this site, to count page views and see which pages people read and which links they arrive through. It is built to work without cookies: it stores nothing on your device and gives you no persistent identifier. So that a single visit is not counted twice, it derives a temporary value from your request — your IP address among other things, which is not itself retained — and that value cannot be reversed, is discarded and regenerated daily, and so cannot be used to recognise you the next day or to assemble a profile of you over time. What we see is aggregate: totals by page, referring link, country, browser, and device type.
The one thing this site stores in your browser is a record of the campaign link you arrived from — the “utm” parameters and ad click identifiers that may be attached to a link in an email or an advertisement. It is kept in your browser’s session storage, which means it is scoped to that single tab and is erased when you close it. If you go on to join the waitlist, that record is attached to your profile so we can tell which campaign reached you. If you do not join the waitlist, it is never sent anywhere and simply disappears with the tab.
You can clear it at any time through your browser’s settings for site data. Should we introduce any technology that stores information on your device or identifies you personally, we will update this policy and ask for your consent before it runs.
7. Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete information
- Deletion: request that we delete your personal information
- Portability: request that we provide your data in a portable format
- Opt-out: opt out of marketing communications at any time
- Restriction: request that we limit how we process your information
To exercise any of these rights, please contact us at privacy@joinmisa.com. We will respond to your request within 30 days.
8. Law Enforcement & Data Defense
As a California-based Public Benefit Corporation, Misa is committed to protecting your privacy autonomy — particularly as it relates to reproductive and menstrual health data.
- Zero-Disclosure Policy: Misa will not voluntarily disclose your health data to law enforcement or private litigants unless required by a final, non-appealable court order.
- California Shield Law (AB 352 / AB 254): In compliance with California law, Misa will not disclose your reproductive health information to out-of-state agencies seeking to investigate or prosecute lawful healthcare activities.
- Challenge to Requests: We commit to challenging any legal request we believe is overbroad or lacks sufficient legal basis before complying.
9. California Privacy Rights (CCPA/CPRA & CMIA)
As a California-based Public Benefit Corporation, Misa complies with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the Confidentiality of Medical Information Act (CMIA). If you are a California resident, you have the following additional rights:
- Right to Limit Use of Sensitive Personal Information: You have the right to direct Misa to limit the use of your health and cycle data to only what is necessary to perform the services reasonably expected by you — that is, providing personalized cycle-synced wellness guidance.
- Right to Know & Delete: You may request a copy of the specific pieces of personal information we have collected about you, or request that we delete your information at any time.
- Right to Opt-Out of Automated Decision-Making: You have the right to opt out of the use of automated technologies that provide personalized wellness recommendations.
- Notice of Internal Research: We may use de-identified and aggregated data for internal research purposes to improve our services. This data is stripped of all personal identifiers and cannot be re-linked to you.
- California Shield Law Protection (AB 352 / AB 254): In accordance with California law, Misa will not disclose your reproductive health information to out-of-state law enforcement agencies seeking to investigate or prosecute lawful healthcare activities.
- No Sale of Data: Misa does not sell your personal information.
To exercise any of your California privacy rights, contact us at privacy@joinmisa.com.
10. European Economic Area, United Kingdom & Switzerland
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent UK and Swiss law give you the rights described below. Misa Wellness, PBC is the “controller” of your personal data for the purposes of that law.
Our legal bases for processing. We rely on:
- Your explicit consent for health and cycle data. That data is a “special category” of personal data under Article 9, and we process it only where you have explicitly agreed. You may withdraw that consent at any time, which does not affect processing already carried out.
- Your consent for marketing email, including the waitlist. Every message we send carries a one-click unsubscribe.
- Performance of a contract where processing is necessary to provide the Platform to you.
- Our legitimate interests in keeping the Platform secure and working, where those interests are not overridden by your rights.
- Compliance with a legal obligation where the law requires us to retain or disclose information.
Your rights. In addition to the rights in Section 7, you have the right to object to processing carried out on the basis of our legitimate interests, the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and the right to lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. We would ask that you come to us first so we have the chance to put things right.
International transfers. Misa is based in California and our service providers are located primarily in the United States, so personal data you give us is transferred outside the EEA, the UK, and Switzerland. Where we make such a transfer we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and on any additional safeguards those clauses require. You may request a copy of the relevant safeguards by writing to us at the address in Section 14.
Retention. We keep personal data only for as long as it serves the purpose it was collected for, as described in Section 5. Waitlist contact details are kept until you unsubscribe or ask us to delete them.
How to reach us. To exercise any of these rights, write to privacy@joinmisa.com. We will respond within one month, and will tell you if we need longer because the request is complex.
11. Children’s Privacy
Our Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor without parental consent, we will promptly delete it. If you believe we have inadvertently collected information from a minor, please contact us immediately.
12. Data Security
We implement industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, secure servers, access controls, and regular security assessments. While we work hard to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect any unauthorized access to your account.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the “Last Updated” date and, where appropriate, by sending you an email or in-app notification. We encourage you to review this policy periodically.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Misa Wellness, PBCEmail: privacy@joinmisa.com
Los Angeles, CA
We are committed to working with you to resolve any privacy concerns you may have.