Strua — Consumer Health Data Notice
Effective date: September 22, 2026 · Last updated: September 22, 2026
This notice covers consumer health data only. It applies to anyone protected by a consumer health data law — including residents of Washington and Nevada, and anyone whose health data is collected while they are in those states, whether or not they live there. Our general practices are in the Privacy Policy; this document exists so the health-data specifics stand on their own.
The short version
Strua processes your private entries locally on your device to provide the tools you ask for. Strua does not receive their contents through ordinary use of the tools.
Separately, the account, subscription, technical and support information we do receive may count as consumer health data, because of what Strua is for — a person holding a Strua account is telling us something about their interest in mental-health tools, even if we never see a word they wrote.
We treat that information as consumer health data and describe it here.
What we collect, where it comes from, and why
| Category | Source | Why we have it |
|---|---|---|
| Email address | You, at sign-up | To create your account, sign you in, and contact you about it |
| Password (hashed) | You, at sign-up | To secure your account. We cannot read it |
| Subscription status, plan, renewal date, Stripe identifiers | You and Stripe, at purchase | To provide the paid features you bought and take payment |
| The contents of emails you send us | You, when you write to us | To answer you. If you paste an entry into an email, we receive it |
| Page views and content-free feature counts | Your browser, automatically | To understand in aggregate which parts of the site are used |
| Server and function logs (e.g. IP address, timestamp) | Your browser, automatically | To serve requests, keep the service running, and prevent abuse |
| Your entries, reflections, mood check-ins, journal and worry dumps | You, as you use the tools | To provide the tool you asked for. Processed on your device and not transmitted to Strua's servers through ordinary use of the tools — the exception is anything you choose to send us, below. Listed here because processing them is what Strua does, even though we do not receive them |
Not transmitted to Strua through ordinary use of the tools: the contents of your entries, and any mood, distress, helpfulness or crisis information.
Which tool you opened. The page address sent to our analytics is rewritten in your browser first, so a tool, meditation or ritual address arrives as a generic placeholder and the analytics record does not name it. Referral-tag names and values on an inbound link are checked against a short fixed list before they are sent, and anything else becomes "other" (see Consent below). The mask covers what you open inside the app; a public page on the site — the crisis-resources page, a technique or condition guide — is counted by its own address like any web page. Audio (meditations, soundscapes, walkthroughs) streams from our database provider's file storage, and that request names the audio file and carries your IP address, not your account.
Loading a page does send its address to our hosting provider, because that is how the page reaches you. We do not retain those requests or have any access to them — our hosting plan gives us no page-request log. The only logs we can read are our own serverless function logs, which record an event, its outcome and, where relevant, an identifier such as a masked email address or a payment-customer id, kept for at least 24 hours and at most 7 days per our hosting plan — never a page address and never the contents of an entry (we checked every log statement in that code).
And one exception you control: if you paste an entry into an email to us, or export and send us one, we receive it, and it may contain exactly the kind of information above. That is your choice, not something the app does.
How we process it
Your entries are processed on your own device, in your browser, by the tool you opened. The contents of what you write are not transmitted to us through ordinary use of the tools.
The information we do receive is processed by us and by the providers listed below: stored in our database so you can sign in, passed to Stripe so a payment can be taken, delivered as email so we can answer you, logged by our hosting provider so pages can be served, and counted in aggregate so we know which parts of the site are used. We do not profile you, score you, or use any of it to target advertising. The automated steps are checking whether an account qualifies for a promotional access period, and Cloudflare's human-verification check on the sign-in forms.
Who we share it with
We do not sell consumer health data, and we do not share it for advertising. We have never done either.
We share only with the providers needed to run the service, each under terms restricting their use:
| Recipient | What it receives |
|---|---|
| Supabase | Email, hashed password, subscription record, a few account records (Strua Notes choice, age confirmation, the document version you agreed to, onboarding status, and for clinicians the Clinician Access Program application: name, email, state, licence type and number, practice name, referral source), and audio-file requests with your IP address (authentication, database and file storage) |
| Cloudflare | Your IP address and browser signals during the human-verification check (Turnstile) on the sign-up, sign-in, email-verification, password-reset, account-deletion and clinician application forms (bot protection on our instructions; Cloudflare also uses what it receives to improve its bot-detection service) |
| Netlify | Requests to the site and its functions (hosting) |
| Stripe | Email, payment details, subscription data (payment) |
| Resend | Email address and message content (account email we send you; delivered through Resend's own infrastructure, Amazon SES) |
| Google Workspace | Any email you send us, including anything you paste into it (hosting the mailbox we answer from); and, if you opted in, your address on the Strua Notes send list (plain-text email from that mailbox, addresses hidden, no tracking) |
| Plausible | Page addresses (masked inside the app; public site pages by their own address) and content-free counts, plus the technical data any browser sends including IP address, from which it derives an approximate location, a browser and device category and a rotating daily identifier; the raw IP address is not retained. No cookies, no cross-site profiles (analytics) |
We disclose information for legal or safety purposes only to the extent applicable law permits or requires, limited to the information appropriate for that purpose, and we will tell you where the law requires it and otherwise where we are able to. This does not mean we monitor what you write in the tools; we do not receive it (a copy you choose to email us is handled as support mail).
Affiliates: Strua, LLC has no affiliates or parent company. Nothing is shared with one.
Consent
We process your account, payment and support information as necessary to provide the services you request — signing you in, giving you the access you bought, taking payment, and answering you when you write to us. Washington's Act permits collection and sharing to the extent necessary to provide a service the consumer asked for (RCW 19.373.030).
Where applicable law requires consent for any additional collection or sharing of consumer health data, we obtain that consent before the processing happens.
Analytics — what we do, and what we are not claiming. Understanding in aggregate which parts of the site are used is useful to us, and it is not strictly necessary to deliver the exercise you opened. So rather than argue it out of scope, we cover it in this notice and treat it as consumer health data, and we hold it to the same rules as everything else here: not sold, not shared for advertising. It reaches us only as aggregate counts that are not linked to you, so there is no individual analytics record we could locate and delete; the technical data the provider receives is turned into a rotating daily identifier and the raw address discarded.
What is actually sent, so you can judge it yourself:
- Page addresses are rewritten in your browser before they are sent. A tool, meditation, ritual or practice address arrives as a generic placeholder, so the address itself does not name what you opened. A referrer from our own site is rewritten the same way (a referrer from another site arrives as your browser sends it), and query parameters are stripped to a short allowlist of referral-tag names, and their values are checked too (see "Referral tags" below).
- Event properties carry no tool identity, no mood, distress, helpfulness or crisis information, and no text. An automated test in our codebase blocks any code that tries to send them.
- No cookies are set and no profile is built across sites. Our analytics provider turns the technical data every browser sends, including the IP address, into a rotating daily identifier and does not retain the raw address. What comes back to us is counts.
Referral tags. A link to Strua can carry a referral tag (ref=, utm_source= and the like).
Before anything is sent to analytics, both the tag names and their values are checked against a
short fixed list of the tags our own links use — a platform name, "bio", "guides", "profile" and so
on. A value not on that list, whatever someone put in a link, is replaced with "other" before it leaves
your browser. Our own tags name where a link sits, never a tool, a condition or you.
The analytics described above run today without a separate consent prompt; this notice is how we tell you exactly what they send. If we ever want to collect or share consumer health data beyond what this notice describes, we will ask you first, in a separate and specific request. Declining will not cost you the features you already have.
Your rights
You may:
- Confirm whether we are collecting, sharing or selling consumer health data about you — and know who we have shared it with.
- Withdraw your consent to our collecting and sharing your consumer health data.
- Delete your consumer health data, subject to applicable law.
- Access a copy of it, and correct it if it is wrong.
Washington's My Health My Data Act provides confirmation, access, withdrawal and deletion rights (RCW 19.373.040); the right to a list of recipients covers third parties and affiliates, with contact details for third parties. We offer correction in addition.
We will not discriminate against you for exercising any of these — no worse price, no degraded service, no penalty. Some requests do have unavoidable consequences that are not penalties: if you withdraw consent to the collection we need to run your account, or ask us to delete the data you sign in with, the account stops working. We will tell you that before we act, not after.
Deleting. You may request deletion of your consumer health data, including data held on our behalf by service providers, subject to applicable law. Copies you made — exports, things you shared, your own device or cloud backups — are outside our reach and you will need to delete those yourself.
Reviewing or changing your data
To see what we hold: most of it is already visible to you in Settings — your email address, your plan and its renewal date. For anything else, or for a copy you can keep, email Dr.G@strua.app and we will send it.
To change it: your password is editable in Settings. To change the email address on your account, email us from the current address and we will do it. For anything else you think is wrong, email us and we will correct it.
How to make a request
Email Dr.G@strua.app from the address on your account, saying what you want. We will confirm receipt and respond within 45 days, extendable once by a further 45 days where the law permits and we tell you why.
If you no longer have access to the email address on your account, write from another address and tell us; we will agree a reasonable way to confirm it is you without asking for documents we do not need. Where the law allows a request through an authorised representative, we accept one the same way. We may need to confirm you are who you say you are before we act — usually by verifying you control the account email. The clocks differ slightly and we apply whichever is more protective of you: Washington's 45 days runs from when we receive your request, Nevada's from when we have authenticated it, and Nevada requires deletion, plus notice to everyone we shared with, within 30 days of authentication.
If we refuse
If we decline a request, we will tell you why in writing and explain how to appeal. To appeal, reply to that decision or email Dr.G@strua.app with the word appeal. A person will review it — for Strua that is the owner, Dr. Nicholas Gehle — and you will get a written decision within 45 days, with the reasons.
If your appeal is denied, our written decision will include contact information for the attorney general of your state. You may complain to the Washington State Attorney General at atg.wa.gov/file-complaint, or to the Nevada Attorney General at ag.nv.gov/Complaints.
Deleting the data on your own device
An emailed deletion request cannot remotely clear your browser storage. What you wrote in Strua is on your device rather than with us — unless you sent us a copy — so a request to us does not reach it. Deleting your account from within the app does clear that browser's data for the account, as the Privacy Policy describes; other browsers and devices are not touched, and removing the app icon may or may not clear it, depending on your device, so do not rely on that either way; Strua runs in your browser's storage.
To clear it: clear site data for strua.app in your browser settings (Chrome and Edge: Settings → Privacy → Site settings; Safari: Settings → Safari → Advanced → Website Data; Firefox: Settings → Privacy → Cookies and Site Data), or use the in-app deletion controls where offered. Exports, shares and device backups you made are outside Strua and must be deleted where they live.
Nevada
If you are covered by Nevada's health-data law you may ask us to stop collecting, stop sharing, and stop selling your covered health data, and to delete it. Email Dr.G@strua.app. We do not sell it and never have, but you are entitled to say so on the record and we will note it.
Nevada's deletion clock is shorter than Washington's. Nevada requires us to act within 30 days of confirming who you are, and gives anyone we shared your data with their own 30 days once notified. As above, we apply whichever clock is more protective of you.
Backups: our database plan keeps no scheduled backups of its own (checked on the day this notice took effect), so deleting a record from the live database is the deletion. Two providers keep short-lived copies of technical data on their own schedules: our email provider keeps a record of account email it sent for 30 days, and our hosting provider's function logs expire within 1 to 7 days. Nevada allows a period to purge backups; ours is shorter than that.
Apart from Stripe's own fraud prevention on its checkout and billing pages and Cloudflare's human check on the sign-in forms, each under its own privacy policy, no third party collects consumer health data about you through Strua over time and across different Internet websites or online services. There are no advertising or social tracking scripts on the site, our analytics provider does not build cross-site profiles, and the address sent to analytics is masked so it does not name the tool you opened. (Our hosting provider still receives the real address in the ordinary course of serving the page — see above.)
You may also ask us for a list of every third party with whom we have shared or sold your consumer health data. (We have never sold any.)
Changes and contact
If this notice changes materially we will tell you before the change takes effect, and will not apply a new use to information already collected where that use requires separate consent.
Strua, LLC · Dr.G@strua.app · Florida, United States.