Doula Genie logo
Doula Genie

Privacy & Security

Last updated September 1, 2026

This page explains, in plain language, how Doula Genie handles the information doulas and clients share here — including health-related details like notes on a pregnancy, appointments, and private messages.

Are we a HIPAA-covered service?

Independent doulas generally aren't HIPAA-covered entities the way a hospital or insurer is, so we don't claim HIPAA compliance. That doesn't mean health information here is treated casually — we handle it the way any responsible health app should, and we take seriously the FTC's Health Breach Notification Rule, which applies to apps like this one even outside HIPAA (see "If something ever goes wrong" below).

What information we handle

A client's profile, appointments, uploaded documents (like birth plans or intake forms), notes their doula writes, and private messages between a doula and their client. Some of this is health-related by nature — that's the point of the app — so we treat all of it as sensitive, not just the parts explicitly marked as health information.

Who can actually see it

A client's notes, appointments, documents, and messages are visible only to that client's own assigned doula, and to the client themselves — never to any other doula, and never to any other client. This isn't just a policy we follow; it's enforced by the app on every request, and we periodically re-verify it with real tests rather than assuming it still holds.

One exception: Doula Genie's designated administrator (used for account support, security, and the account deactivation/deletion described below) has the same access a client's assigned doula has, across all accounts. That access is limited to the one administrator account — it is never extended to other doulas or clients.

How your information is protected

Every connection to this app — your browser, our servers, our database, and our file storage — uses encrypted (HTTPS/TLS) connections only. There is no unencrypted path anywhere in the system.

Data at rest is encrypted (AES-256) by our database and file storage providers, as part of their own infrastructure — the same standard used by managed cloud services generally.

Uploaded documents and photos are only ever reachable through this app's own access checks — there's no direct link or shortcut that bypasses those checks, including for us.

If something ever goes wrong

If client health information were ever exposed in a data breach, we're committed to notifying affected users within 60 days, consistent with the FTC's Health Breach Notification Rule — the standard that applies to health apps like this one, regardless of HIPAA status.

How long we keep your information, and how removal works

By default, a client's or doula's information is kept for as long as the account is in use — there isn't yet a self-service "delete my account" button, or an automatic deletion process on a fixed timeline. If you'd like that to change, contact us (below) and we'll act on it directly, in one of two ways:

Deactivation blocks sign-in right away and removes the account from active use, but keeps the underlying information intact — this is reversible, for situations like a temporary pause rather than a permanent departure.

Permanent deletion removes the account's sign-in entirely and erases its information for real — notes, appointments, uploaded documents, private messages, and labor alerts are all deleted from our systems. This cannot be undone, and we treat it accordingly: it's a deliberate, confirmed action, not something that happens by accident or automatically.

Questions or requests

For privacy or security questions, or to request that your account be deactivated or permanently deleted, contact tremayne@housen2cash.com.