Last updated September 1, 2026
This page explains, in plain language, how Doula Genie handles the information doulas and clients share here — including health-related details like notes on a pregnancy, appointments, and private messages.
Independent doulas generally aren't HIPAA-covered entities the way a hospital or insurer is, so we don't claim HIPAA compliance. That doesn't mean health information here is treated casually — we handle it the way any responsible health app should, and we take seriously the FTC's Health Breach Notification Rule, which applies to apps like this one even outside HIPAA (see "If something ever goes wrong" below).
A client's profile, appointments, uploaded documents (like birth plans or intake forms), notes their doula writes, and private messages between a doula and their client. Some of this is health-related by nature — that's the point of the app — so we treat all of it as sensitive, not just the parts explicitly marked as health information.
A client's notes, appointments, documents, and messages are visible only to that client's own assigned doula, and to the client themselves — never to any other doula, and never to any other client. This isn't just a policy we follow; it's enforced by the app on every request, and we periodically re-verify it with real tests rather than assuming it still holds.
One exception: Doula Genie's designated administrator (used for account support, security, and the account deactivation/deletion described below) has the same access a client's assigned doula has, across all accounts. That access is limited to the one administrator account — it is never extended to other doulas or clients.
Every connection to this app — your browser, our servers, our database, and our file storage — uses encrypted (HTTPS/TLS) connections only. There is no unencrypted path anywhere in the system.
Data at rest is encrypted (AES-256) by our database and file storage providers, as part of their own infrastructure — the same standard used by managed cloud services generally.
Uploaded documents and photos are only ever reachable through this app's own access checks — there's no direct link or shortcut that bypasses those checks, including for us.
If client health information were ever exposed in a data breach, we're committed to notifying affected users within 60 days, consistent with the FTC's Health Breach Notification Rule — the standard that applies to health apps like this one, regardless of HIPAA status.
By default, a client's or doula's information is kept for as long as the account is in use — there isn't yet a self-service "delete my account" button, or an automatic deletion process on a fixed timeline. If you'd like that to change, contact us (below) and we'll act on it directly, in one of two ways:
Deactivation blocks sign-in right away and removes the account from active use, but keeps the underlying information intact — this is reversible, for situations like a temporary pause rather than a permanent departure.
Permanent deletion removes the account's sign-in entirely and erases its information for real — notes, appointments, uploaded documents, private messages, and labor alerts are all deleted from our systems. This cannot be undone, and we treat it accordingly: it's a deliberate, confirmed action, not something that happens by accident or automatically.
For privacy or security questions, or to request that your account be deactivated or permanently deleted, contact tremayne@housen2cash.com.