Privacy Policy

Last updated:

At Misa, your privacy is not a formality. It’s foundational to everything we build. This Privacy Policy explains how Misa Wellness, PBC (“Misa,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use our website, mobile application, and related services (collectively, the “Platform”). By using our Platform, you agree to the collection and use of your information as described in this Privacy Policy.

1. Information We Collect

We collect information in the following ways:

Information You Provide Directly

Information Collected Automatically

Information from Third-Party Integrations

If you connect wearable devices or third-party health apps (such as Oura or Whoop), we may receive data from those services, including sleep metrics, heart rate variability, and activity data. This sharing is subject to your authorization and the privacy policies of those third-party services.

2. How We Use Your Information

We use your information to:

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following limited circumstances:

4. Health Data & Sensitive Information

Misa handles health and menstrual cycle data as sensitive personal information. We apply additional protections to this data, including:

You have the right to access, correct, and delete your health data at any time through your account settings or by contacting us.

5. Data Retention & De-identification

We retain your personal information only for as long as your account is active or as needed to provide you with the Platform’s core services.

Please note that during the beta period, data deletion capabilities are actively being developed and may be subject to technical limitations.

6. Cookies & Tracking Technologies

Our website sets no cookies. It loads no advertising trackers and does not follow you across other sites, and we do not engage in cross-site behavioral advertising.

Analytics. We use Vercel Web Analytics, provided by the company that also hosts this site, to count page views and see which pages people read and which links they arrive through. It is built to work without cookies: it stores nothing on your device and gives you no persistent identifier. So that a single visit is not counted twice, it derives a temporary value from your request — your IP address among other things, which is not itself retained — and that value cannot be reversed, is discarded and regenerated daily, and so cannot be used to recognise you the next day or to assemble a profile of you over time. What we see is aggregate: totals by page, referring link, country, browser, and device type.

The one thing this site stores in your browser is a record of the campaign link you arrived from — the “utm” parameters and ad click identifiers that may be attached to a link in an email or an advertisement. It is kept in your browser’s session storage, which means it is scoped to that single tab and is erased when you close it. If you go on to join the waitlist, that record is attached to your profile so we can tell which campaign reached you. If you do not join the waitlist, it is never sent anywhere and simply disappears with the tab.

You can clear it at any time through your browser’s settings for site data. Should we introduce any technology that stores information on your device or identifies you personally, we will update this policy and ask for your consent before it runs.

7. Your Privacy Rights

Depending on where you live, you may have the following rights regarding your personal information:

To exercise any of these rights, please contact us at privacy@joinmisa.com. We will respond to your request within 30 days.

8. Law Enforcement & Data Defense

As a California-based Public Benefit Corporation, Misa is committed to protecting your privacy autonomy — particularly as it relates to reproductive and menstrual health data.

9. California Privacy Rights (CCPA/CPRA & CMIA)

As a California-based Public Benefit Corporation, Misa complies with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the Confidentiality of Medical Information Act (CMIA). If you are a California resident, you have the following additional rights:

To exercise any of your California privacy rights, contact us at privacy@joinmisa.com.

10. European Economic Area, United Kingdom & Switzerland

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent UK and Swiss law give you the rights described below. Misa Wellness, PBC is the “controller” of your personal data for the purposes of that law.

Our legal bases for processing. We rely on:

Your rights. In addition to the rights in Section 7, you have the right to object to processing carried out on the basis of our legitimate interests, the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and the right to lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. We would ask that you come to us first so we have the chance to put things right.

International transfers. Misa is based in California and our service providers are located primarily in the United States, so personal data you give us is transferred outside the EEA, the UK, and Switzerland. Where we make such a transfer we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and on any additional safeguards those clauses require. You may request a copy of the relevant safeguards by writing to us at the address in Section 14.

Retention. We keep personal data only for as long as it serves the purpose it was collected for, as described in Section 5. Waitlist contact details are kept until you unsubscribe or ask us to delete them.

How to reach us. To exercise any of these rights, write to privacy@joinmisa.com. We will respond within one month, and will tell you if we need longer because the request is complex.

11. Children’s Privacy

Our Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor without parental consent, we will promptly delete it. If you believe we have inadvertently collected information from a minor, please contact us immediately.

12. Data Security

We implement industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, secure servers, access controls, and regular security assessments. While we work hard to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect any unauthorized access to your account.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the “Last Updated” date and, where appropriate, by sending you an email or in-app notification. We encourage you to review this policy periodically.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Misa Wellness, PBC
Email: privacy@joinmisa.com
Los Angeles, CA

We are committed to working with you to resolve any privacy concerns you may have.