Consumer Health Data Privacy Policy

Effective date: June 1, 2026
Last updated: September 20, 2026

This Privacy Policy explains how HealthTales, LLC (“HealthTales,” “we,” “us,” or “our”) collects, uses, and shares information when you use GLP101, our digital health education platform focused on GLP‑1 medications, behavior change, and self-guided learning for adults, and when you interact with our related websites, emails, and services (collectively, the “Services”).

By using the Services, you agree to the practices described in this Privacy Policy.

‍

1. Who we are and how to contact us

HealthTales, LLC is a company organized in the State of Minnesota, USA.

Mailing address:  

HealthTales, LLC
PO Box 7256
Minneapolis, MN 55407
USA  

Email: support@healthtales.co  

If you have questions about this Privacy Policy or our privacy practices, you can contact us at the email or mailing address above.

‍

2. Scope and audience

GLP101 is an education-only tool. None of our materials should be viewed as personalized clinical advice or a replacement for the guidance of a medical professional. The Services are designed for individuals located in the United States.

  • The Services are directed to users in the United States only.  
  • Access from outside the United States is incidental and not specifically targeted.  
  • The Services are intended primarily for adults 18 years of age or older.  
  • The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.  
  • Users aged 13–17 may only use the Services with the consent and supervision of a parent or legal guardian.

If we learn that we have collected personal information from a child under 13 without appropriate consent, we will delete that information.

‍

3. HIPAA status and health information

HealthTales and GLP101 are not a “covered entity” or “business associate” as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). We do not receive information from health plans, healthcare providers, or other HIPAA-covered entities in a way that would make us subject to the HIPAA Privacy Rule.

Most information you provide to us through GLP101 is not protected health information (“PHI”) under HIPAA. This Privacy Policy describes how we handle your information under applicable US consumer privacy and other laws, not under HIPAA.

Even though HIPAA does not apply to our Services in most cases, we treat health-related information with care and apply safeguards as described below.

‍

4. Information we collect

4.1 Information you provide to us

When you use the Services, we may collect:

Account information: 

  • First name  
  • Last name  
  • Email address  
  • Password  

Learning preference information:  

  • Topics you are interested in learning more about  
  • Your self-reported “stage” of the GLP‑1 journey (for example: Considering, On a GLP‑1, Struggling with side effects, Considering stopping/switching)

We do not ask you to provide information such as race/ethnicity, pregnancy status, sexual orientation, or biometric data. We also do not request that you enter detailed medical histories, diagnoses, or prescription records, and the platform is not designed as a portal for storing or transmitting your clinical records.

If you choose to share health-related information with us in free-text fields or communications (for example, if you email us), that information will be handled in accordance with this Privacy Policy.

‍

4.2 Information collected automatically

When you use the Services, we may automatically collect certain information, which may include:

Usage and engagement

  • Which videos or lessons you start, and whether you complete them  
  • Your progress through modules and learning paths  
  • Time spent on certain educational content  

Technical and device data (if implemented as we grow):

  • Basic device and browser information  
  • Date and time you access the Services  

We do not currently track detailed clickstream, precise location, or other advanced analytics beyond what is necessary to understand video and lesson completion and general usage. If this changes, we will update this Privacy Policy and, where required, offer you additional choices.

‍

5. Cookies, analytics, and advertising

5.1 Cookies and similar technologies

We use cookies and similar technologies to support authentication, security, and a consistent user experience. This includes:

  • Authentication cookies and tokens used by our identity provider to keep you signed in and to support secure, cross-origin login flows.
  • Session cookies to maintain your session and remember certain preferences.

At launch:

  • Our authentication provider uses third-party cookies for cross-origin authentication and “silent” re-authentication, so you can log in and remain logged in securely across relevant domains.
  • If you choose to sign in with your Google account, Google may set its own cookies or similar technologies as part of that login flow, governed by Google’s own privacy policies.

‍

5.2 Analytics and engagement

We use product and email analytics tools to understand how GLP101 is used and to improve our content and experience. This may include:

  • Tracking which lessons or videos are viewed and completed.
  • Measuring high-level user flows to identify where users are getting value or encountering friction.
  • Measuring open and click rates for emails we send, to improve relevance and timing.

These analytics are implemented in a way that focuses on product performance and engagement, not on building personal health profiles for sale or for advertising to third parties.

‍

5.3 Advertising and social platforms

We may advertise GLP101 on social media and other platforms, including paid campaigns that direct users to our website or app. Our intent is:

  • To promote GLP101 content and offerings.
  • To avoid using your individual health-related details to build or buy targeted advertising audiences for third parties.

We do not sell your personal information or allow third parties to use your information for their own independent marketing campaigns.

You may choose to opt out of non-essential marketing analytics and cookies, as described in the “Your rights and choices” section below and in any cookie-related controls we provide.

‍

6. How we use your information

We use the information we collect for the following purposes:

To provide and maintain the Services

  • Create and manage your account.
  • Authenticate your identity and keep you securely signed in.
  • Deliver educational content and track your progress through lessons and videos.
  • Remember your preferences and learning interests.

To improve and develop the Services

  • Understand which content is most helpful or engaging.  
  • Analyze aggregated usage patterns to improve curriculum design, user experience, and product performance.  
  • Develop new features, offerings, and educational tools.

To communicate with you

  • Send transactional emails such as account confirmations, password resets, security alerts, and administrative messages.  
  • Send marketing communications and newsletters **only** to users who have opted in on our marketing website or within the app.  
  • Respond to your questions, feedback, and support requests.

For security and compliance

  • Detect, prevent, and respond to security incidents and fraudulent or illegal activities.  
  • Comply with applicable laws, regulations, legal processes, and enforce our terms of use.

We do not use your personal information to sell your data or to allow third parties to use your information for their own independent marketing purposes.

‍

7. How we share your information

We do not sell your personal information. We do not share your user-identifiable data with sponsors, employers, payers, or pharmaceutical companies for their own independent purposes.

We may share information in the following limited ways:

Service providers (processors)

We share information with third-party vendors that perform services on our behalf, such as:

  • Authentication provider: To securely manage user authentication, sessions, and login flows (including third-party logins such as Google).
  • Cloud hosting and infrastructure: To host our application, databases, and related services.
  • Email and communication tools: To send transactional emails and newsletters, including measuring open and click rates.
  • Payment processor: To process subscription or other payments, if and when you purchase a paid offering.
  • These providers are permitted to use your information only to provide services to us and are bound by contractual obligations to keep your information secure.

Affiliate and referral features

If we include features that may generate affiliate or referral revenue (for example, links to external resources or products), we will clearly identify those features as such. These features will not change our commitment not to sell your personal information.

Legal and safety requirements

We may disclose information if we believe in good faith that such disclosure is necessary to:  

  • Comply with applicable laws, regulations, legal processes, or governmental requests.  
  • Protect the rights, property, or safety of HealthTales, our users, or others.  
  • Detect, investigate, and help prevent security, fraud, or technical issues.

Business transfers

If we are involved in a merger, acquisition, financing, or sale of all or a portion of our business, information may be transferred as part of that transaction, subject to any applicable legal requirements and with reasonable efforts to ensure the continuity of privacy protections.

‍

8. Data retention and deletion

We retain information for as long as necessary to provide the Services, fulfill the purposes described in this Policy, and comply with legal obligations.

  • Account data (such as your name, email, and account credentials): retained while your account is active and for a reasonable period thereafter, unless you request deletion or we are required by law to retain it longer.  
  • Learning history and engagement data (such as which lessons you viewed): retained while your account is active and for a reasonable period thereafter to support your learning experience and our product improvement efforts.  
  • De-identified or aggregated analytics (such as total views of videos and total downloads of resources): may be retained indefinitely for reporting, product planning, and research purposes, as this data does not identify individual users.  

When you request that we delete your account:

  • We will delete personal data such as your name, email, and any other directly identifiable information associated with your account.  
  • We will delete identifiable usage data associated with your profile (for example, lesson views tied specifically to your identity) where reasonably possible.  
  • We may retain de-identified or aggregated data (for example, total video views, total resource downloads, and total account counts) that do not identify you as an individual.

‍

9. Security

We use administrative, technical, and physical safeguards designed to protect your information from unauthorized access, use, or disclosure. These safeguards include:

  • Running GLP101 on HIPAA-eligible AWS infrastructure that is independently certified under frameworks such as SOC 2 Type II and ISO 27001 (as provided by AWS).
  • Encryption in transit using modern protocols (for example, TLS 1.2 or higher).
  • Encryption at rest using AES‑256 and AWS Key Management Service (KMS) for key management.
  • Authentication and access control via OAuth 2.1 with scope-based role-based access control (RBAC) to ensure that only authorized users and systems can access specific resources.
  • Network isolation using virtual private cloud (VPC)–isolated databases and security groups to limit exposure of internal services.
  • Web application firewall (WAF) to help protect against common web-based attacks.
  • Audit logging using AWS CloudTrail and related tools to record key security- and access-related events.
  • Secrets management using AWS Secrets Manager for secure storage and rotation of credentials and other sensitive configuration values.
  • PHI-aware analytics design, which includes allowlisted event forwarding and pseudonymous user identifiers, to limit the risk that analytics data is tied to directly identifiable health information.

‍

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. However, we continually work to protect your information and improve our practices over time.

‍

10. Breach notification

If we become aware of a security incident that affects the privacy or security of your personal information, we will investigate promptly and take appropriate steps to mitigate any harm.

We are committed to notifying affected users in accordance with applicable law and, where multiple state standards apply, we will strive to meet the most stringent notification requirements. Our goal is to notify you no later than 30 days after becoming aware of a qualifying security breach, or sooner if required by law.

‍

11. Your rights and choices

Regardless of where you live in the United States, we provide the following baseline rights and choices:

Delete your account and data

You may request that we delete your account and associated personal data. When we honor a deletion request, we will remove personal identifiers and identifiable usage data where reasonably possible, while retaining de-identified or aggregated analytics as described above.

Opt out of marketing communications

  • You can opt out of marketing emails and newsletters at any time by using the unsubscribe link in those emails or by contacting us at support@healthtales.co.  
  • Even if you opt out of marketing, we may still send you transactional or administrative messages related to your account or the Services.

Opt out of non-essential analytics and cookies

To the extent we use non-essential analytics or marketing cookies, we will provide a way for you to opt out, which may include browser-level settings, in-product controls, or instructions on our site.

To exercise these rights, you can:

  • Email us at support@healthtales.co, or  
  • Send a written request to our mailing address listed in this Policy.

We aim to respond to requests within 30 days of receipt, subject to any legal extensions or requirements.

‍

12. Third-party links and content

The Services may include links to third-party websites, services, or content that we do not operate or control. This may include educational resources, articles, tools, or products that we believe may be helpful to you.

  • This Privacy Policy does not apply to third-party sites or services.  
  • We are not responsible for the privacy practices of those third parties.  

We encourage you to review the privacy policies of any third-party services you visit or use.

‍

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time as our Services, practices, or legal requirements change.

  • When we make material changes, we will update the “Last updated” date at the top of this Policy.  
  • For significant changes, we will also provide additional notice, which may include email notifications and/or prominent in-app or on-site notices.

Your continued use of the Services after the effective date of an updated Privacy Policy will signify your acceptance of the changes to the extent permitted by law.

‍

14. How to contact us

If you have questions, concerns, or requests related to this Privacy Policy or our handling of your information, you can contact us at:

‍

HealthTales, LLC
PO Box 7256
Minneapolis, MN 55407
USA

Email: support@healthtales.co

‍