Privacy Policy
MenoLisa
Macura Solutions LLC
Last Updated: August 30, 2026
The short version
- We do not sell your personal information, and we never have.
- Your health information is never used for advertising. Nothing about your symptoms, your questionnaire answers, your health profile, or your logs is ever sent to any advertising platform.
- We do use advertising and analytics tools on our website, which receive limited technical identifiers about your visit — but no health information. Section 6 explains exactly what they get, and how to opt out.
- Health information you enter is sent to our AI provider to generate your plan and Lisa’s answers. Section 5.1 says precisely what.
- You can delete everything at any time, yourself, at menolisa.com/delete-account.
1. Introduction
Macura Solutions LLC (“MenoLisa,” “we,” “us,” or “our”), a Wyoming, USA limited liability company, operates MenoLisa — a consumer wellness product for women in perimenopause and menopause, comprising a personalized 8-week plan, a symptom tracker, an AI assistant called Lisa, and summaries you may share with a healthcare professional.
This Privacy Policy explains what personal information we collect through our website (menolisa.com), our mobile application, and our related services (together, the “Service”), how we use and share it, how long we keep it, and what choices and rights you have. It is the same policy for the website, the app, and our app store listings.
MenoLisa is not a medical service and is not a covered entity or business associate under HIPAA. The information you give us is not protected health information under HIPAA, and HIPAA’s protections do not apply to it. It is protected by this policy and by the consumer privacy laws described in Sections 9 through 12. We do not connect to Apple Health, Health Connect, or any external medical device, and we do not receive information about you from your doctor, your pharmacy, or your insurer.
We are the controller of the information described here. If you do not agree with this policy, please do not use the Service.
2. Information We Collect
2.1 Account information
- Email address — used to sign you in and to send account and billing messages. Note how you give it to us: the questionnaire on our website does not ask for an email address. Your account is created without one, and the address you enter on the payment page becomes the address on your account. If you sign up in the mobile app, you give it directly.
- First name — if you tell us what Lisa should call you.
- Authentication records — we use passwordless sign-in, so we store the single-use six-digit codes we issue and their expiry, plus session tokens. We never store a password, because there isn’t one.
2.2 Questionnaire and health profile
This is the information used to build your plan. Depending on where you sign up and what you choose to answer, it includes:
- Age band (a range, not a date of birth), and height and weight
- Your main symptoms and concerns — for example hot flashes, night sweats, sleep problems, brain fog, mood changes, anxiety, joint pain, weight changes, low energy, low libido
- How severely your worst symptom affects you, and how long you have had symptoms
- Menopause type — whether natural, surgical, medically induced, or unknown
- Hormone therapy status — whether you are using, have used, have declined, or are considering hormone therapy
- Medical safety information (mobile app only) — whether you have a history of breast cancer, blood clots or stroke, or liver disease, or prefer not to say. This is asked so that the plan can avoid suggestions that would be inappropriate for you. You may always answer “prefer not to say.”
- Whether you have discussed your symptoms with a doctor, and what you have already tried
- Your goals — for example sleeping through the night, thinking clearly, feeling like yourself, understanding your patterns, or having data for your doctor
- Your fitness level, current eating and relaxation habits, and the time of day you prefer to train
We previously collected information about physical limitations and injuries. We no longer ask for it and no longer store it.
2.3 What you log while using the Service
- Symptom logs — the symptom, its severity, the time of day, any triggers you select (such as stress, poor sleep, alcohol, caffeine, spicy food, a skipped meal, exercise, heat, work, travel, or hormonal causes), and any free-text notes you write. This includes anything you choose to log about your period or reproductive health.
- “Good day” entries and hydration, if you use them.
- Plan completion records — which tasks you marked complete, the day each is attributed to, and the time we received it. Both timestamps are used to calculate eligibility for the 8-Week Guarantee.
- Your generated plan — the exercises, cardio, relaxation sessions, and nutrition and habit tasks in it.
- Rewards data — points, streaks, levels, and badges, derived from the above.
- Your Menopause Score — a non-clinical wellness indicator we calculate from what you report. It is not a medical measurement or a diagnosis.
2.4 Conversations with Lisa
Your messages to Lisa and the conversation history, together with the profile and recent symptom context supplied to generate a relevant answer. Please do not enter information about other people, and please do not send anything you would not want stored.
2.5 Payment information
Payments are processed by Stripe. Stripe collects your card details, name, billing address, and email directly — we never receive or store your full card number. We receive and store a Stripe customer and subscription identifier, your subscription status and renewal date, the amount and currency, the last-four digits and card brand, and the billing country. We do not send Stripe any of your health information.
2.6 Technical and usage information
- Device and connection data — device and browser type, operating system, IP address, approximate location derived from your IP address at country level, access times, and error and diagnostic logs.
- Usage data — which features and screens you use and what actions you take.
- Push notification token — if you enable notifications in the app, so we can deliver reminders you asked for.
- Website analytics and advertising identifiers — described in Section 6.
2.7 Support correspondence
If you email us, we keep your message, your address, and our reply, so we can help you and keep a record of what was agreed — particularly for refund and guarantee claims.
2.8 AI operational records
For every AI request we make on your behalf we record the model used, the number of tokens, the cost, and how long it took, so we can monitor spend and performance. These records contain no message content. If you delete your account, the identifier is removed from these rows and what remains cannot be linked back to you.
3. How We Use Your Information
- To provide the Service — create and secure your account, generate and progress your plan, run the tracker, calculate your Score and rewards, and produce your summaries and reports.
- To generate AI content — Lisa’s answers, your plan, and written insights (Section 5.1).
- To process payments — take payment, manage renewals and cancellations, and handle refunds, guarantee claims, and payment disputes.
- To communicate with you — sign-in codes, a welcome message, payment and renewal notices (we email you about 3 days before each renewal charge), replies to your support requests, and important service or policy announcements. These are service messages and are not marketing.
- To send reminders you turned on — push notifications, which you can disable at any time.
- To keep the Service safe and honest — prevent and investigate fraud and abuse, including refund and guarantee abuse, enforce our Terms, and secure our systems.
- To improve the Service — understand which features are used and where they fail, in aggregate.
- To advertise our own product — measure whether our ads work, using the limited identifiers described in Section 6 and never your health information.
- To comply with law — meet tax, accounting, and other legal obligations and respond to lawful requests.
We do not use your information to train AI models, ours or anyone else’s, and we do not permit our providers to train their models on it. We do not make decisions with legal or similarly significant effects about you by automated means. Generating your plan is automated, but it does not affect your legal rights.
Legal bases (where GDPR or similar law applies). We process your information to perform our contract with you (providing the Service and taking payment); with your explicit consent for health information and for AI processing of it, and for non-essential cookies and advertising; for our legitimate interests in securing, improving, and marketing the Service, balanced against your rights; and to comply with legal obligations. You may withdraw consent at any time, which does not affect processing already carried out.
4. We Do Not Sell Your Information
We do not sell your personal information or your health information for money, and we never have. We do not share your health information with advertisers, data brokers, or analytics companies. We do not use your health information to target ads to you, and we do not allow anyone else to.
Section 6 describes limited sharing of technical identifiers with advertising and analytics providers, which some U.S. state laws define as “sharing” for cross-context behavioral advertising. We treat it that way and give you an opt-out.
5. Service Providers We Share With
We share information only as described here. Every provider is bound by contract to protect it and to use it solely to provide services to us.
5.1 OpenAI — our AI provider (please read)
To generate Lisa’s answers, your 8-week plan, and your written summaries, we send the following to OpenAI, L.L.C. (San Francisco, California, USA):
- The messages you send to Lisa, and recent conversation history
- Recent symptom entries — the symptom, severity, triggers, and timing
- Your health profile — age band, menopause type, hormone therapy status, main concerns, safety information, fitness level, and goals
- Your first name, where it is used to address you
We do not send OpenAI your email address, your payment details, or your account identifier. OpenAI processes this only to return a response to us. Under our API agreement, OpenAI does not use it to train its models and retains it only briefly for abuse monitoring before deletion. OpenAI’s policy is at openai.com/policies/privacy-policy.
Your consent. By using Lisa or by purchasing a plan, you consent to your health information being sent to OpenAI for this purpose. This is a core part of how the Service works. You can stop chat data being sent by not using Lisa; because plan generation is the product itself, the only way to withdraw consent for it is to stop using the Service and delete your account, which you may do at any time.
5.2 Everyone else
- Supabase, Inc. — our database, authentication, and file storage. Holds essentially all of your account, profile, health, and plan data. United States.
- Vercel, Inc. — hosting for our website and API, and website analytics and performance measurement. Processes request data including IP addresses. United States.
- Stripe, Inc. — payments and subscription billing. Receives your payment and billing details directly from you, plus an account identifier. Stripe receives none of your health information.
- Resend — delivery of our transactional emails. Receives your email address and the content of those messages (sign-in codes, welcome, payment and renewal notices). It receives no health information.
- Expo — push notification delivery. Receives your device push token and the text of the notification. Keep notification text free of anything you would not want visible on a lock screen; we write ours accordingly.
- Meta Platforms, Inc. — advertising measurement on our website only. Section 6 sets out exactly what it receives, which does not include health information.
5.3 Other disclosures
We may also disclose information:
- When you ask us to — for example, a report you choose to download and give to your doctor. Once you share it, this policy no longer governs it.
- To comply with law — in response to a subpoena, court order, or other lawful request. We review each request, require valid legal process, disclose no more than necessary, and will notify you unless we are legally prohibited from doing so.
- To protect people — where we reasonably believe disclosure is necessary to prevent serious harm, fraud, or a threat to someone’s safety, or to establish or defend a legal claim.
- In a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, information may transfer to the successor. We will notify you beforehand where practicable, the successor will remain bound by this policy for information collected under it, and we will obtain your consent before your health information becomes subject to a materially less protective policy.
We will never sell your health information in a bankruptcy or asset sale as an unrestricted asset.
6. Advertising, Analytics, and Cookies
We advertise MenoLisa online, and we measure whether those ads work. This section explains exactly what that involves, because it is the part of a health app’s privacy practice that deserves the most scrutiny.
The line we draw, stated plainly:
No information about your symptoms, your questionnaire answers, your health profile, your plan, your logs, or your Menopause Score is ever sent to Meta or to any other advertising or analytics provider — not in any form, hashed or otherwise. Our advertising measurement is limited to knowing that somebody reached a step in our signup flow. It never carries what she said about her health.
6.1 What Meta receives
We use the Meta Pixel and Meta’s Conversions API on our website only — not in the mobile app — to measure five steps: a page view, completing the questionnaire, reaching the price page, starting checkout, and purchasing. For those events Meta may receive:
- A random account identifier we generate, which is meaningless outside our systems
- Your first name and country, and — for a purchase only — the name, phone, and billing address you gave to Stripe, each irreversibly hashed before it is sent, so Meta can tell whether you are someone it already knows without us handing over the underlying values
- Your email address, hashed, for a purchase only
- Meta’s own
_fbpand_fbccookies, your IP address, browser user-agent, and the page URL - The purchase amount — the same single price everyone pays, which discloses nothing about you
The event names themselves are Meta’s generic e-commerce names — “Lead,” “ViewContent,” “Purchase” — and carry no product or health context.
Until August 30, 2026, our “Lead” event also carried a count of the symptoms selected and the goal chosen. That was inconsistent with the commitment above. Both were removed on that date and no health-derived value is sent in any parameter of any event.
6.2 Analytics
We use Vercel Analytics and Speed Insights on our website to count visits and measure page performance. They are privacy-oriented, do not use cookies to track you across sites, and do not build an advertising profile of you. We do not use Google Analytics.
6.3 Cookies and similar technologies
- Strictly necessary — your sign-in session and security. The Service does not work without these, and they are not used for advertising.
- Advertising — Meta’s
_fbpand_fbc, as above.
The mobile app does not use advertising cookies or an advertising SDK, and does not use your device advertising identifier.
6.4 Your choices
- Browser controls — block or delete cookies in your browser settings, or use a tracking-protection or ad-blocking extension. This stops the browser-side pixel.
- Global Privacy Control — we honor a GPC signal sent by your browser as an opt-out of sharing for cross-context behavioral advertising.
- Meta’s own controls — your Meta Ad Preferences let you manage how Meta uses off-platform activity.
- Ask us — email support@macurasolutions.us with “Opt out of ad measurement” and the email address on your account, and we will suppress your account from advertising measurement.
Opting out does not affect your subscription, your plan, or any part of the Service, and we will not treat you differently for it.
7. Security
- In transit — all traffic is encrypted with TLS.
- At rest — our database and file storage are encrypted at rest by our infrastructure provider.
- Row-level isolation — our database enforces per-user access rules, so one account cannot read another’s data even if an application error occurred.
- No passwords — sign-in uses a single-use six-digit code that expires, so there is no password to be reused, guessed, or leaked in someone else’s breach.
- Least privilege — administrative access is limited to the people who need it to operate and support the Service, and administrative interfaces are protected.
- Payment isolation — card data is handled entirely by Stripe and never reaches our systems.
What you can do: because sign-in depends on your email inbox, securing that inbox — with a strong, unique password and two-factor authentication — is the single most effective protection for your MenoLisa account.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as required by applicable law, without undue delay.
8. Retention and Deletion
- While your account exists — we keep your information so the Service can work. Your history is the product.
- Deletion is self-service and immediate. Delete your account in the app or at menolisa.com/delete-account. This works whether or not you still have the app installed. Deletion cancels any active subscription first, so you are not billed again, and then removes your account and your data — profile, questionnaire answers, symptom logs, conversations with Lisa, plan and completion records, rewards, preferences, and push tokens. It cannot be undone, so please export anything you want to keep first.
- Inactive accounts — an account created during signup that is never paid for and holds no email address is deleted automatically after 7 days.
- Backups — residual copies may persist in encrypted backups for a limited period before being overwritten in the ordinary course. They are not used to restore a deleted account.
- What we must keep — transaction and tax records (typically up to seven years, as law requires), records of a refund or guarantee claim, and records needed to establish or defend a legal claim or to prevent recurring fraud. These are billing records and support correspondence, not your health data.
- De-identified data — we may keep aggregated or de-identified data that cannot reasonably be linked back to you. We do not attempt to re-identify it.
9. Consumer Health Data
This section is provided for residents of Washington, Nevada, Connecticut, and other states with specific consumer health data laws. It restates, in one place, how we handle information that reveals your past, present, or future physical or mental health.
- What we collect: the health information listed in Sections 2.2, 2.3, and 2.4 — your symptoms and their severity and triggers, your menopause type, your hormone therapy status, the safety history described in Section 2.2, your height and weight, your goals, your plan and completion records, your Menopause Score, and your conversations with Lisa.
- How we collect it: directly from you, and only from you. We do not buy, license, or otherwise obtain health information about you from any third party, and we do not infer it from your activity elsewhere.
- Why we collect it: solely to provide the Service to you — to generate and progress your plan, to answer your questions, to show you your own history, and to produce the summaries you ask for.
- Who we share it with: only OpenAI, to generate your plan and Lisa’s responses (Section 5.1), and Supabase, which stores it on our behalf. That is the complete list.
- We do not sell consumer health data. We have never sold it and we will not sell it. Where law requires a separate signed authorization before any sale, we will not seek one, because we do not intend ever to sell it.
- We do not use it for advertising, our own or anyone else’s, and we do not share it with any advertising platform (Section 6).
- We do not use it to train AI models, and our providers are contractually barred from doing so.
- Your consent: we collect this information only when you choose to enter it, for the purposes stated above, and we ask for it in context so you can see why. You may withdraw consent at any time by deleting your account.
- Your rights: you may confirm whether we hold your consumer health data, access it, obtain a list of the third parties it has been shared with, and delete it. Deleting your account deletes it. To exercise these rights directly, email support@macurasolutions.us. We respond within 45 days, extendable once by a further 45 days where necessary, and we will tell you if we need more time. If we deny a request, we will explain why and how to appeal; if an appeal is denied, you may complain to your state attorney general.
10. Your Rights and Choices
Wherever you live, you may:
- Access a copy of the information we hold about you
- Correct anything inaccurate — much of it you can edit yourself in the app
- Delete your information, in full, yourself, at any time (Section 8)
- Obtain a portable copy in a structured, machine-readable format
- Withdraw consent — turn off notifications, stop using Lisa, opt out of ad measurement, or delete your account
- Opt out of sharing for cross-context behavioral advertising (Section 6.4)
- Be free from discrimination for exercising any of these rights. We will not deny you the Service, charge you a different price, or give you a lesser experience.
Email support@macurasolutions.us to exercise any right. We will verify your identity by confirming control of the email address on your account, and we will respond within the time your law requires — in any case within 45 days, with one extension where permitted. An authorized agent may act for you with written permission.
10.1 California
Under the CCPA as amended by the CPRA, you have the rights above, plus the right to know the categories of personal information we collect, the purposes, and the categories of third parties we disclose to — all set out in Sections 2, 3, and 5 — and the right to limit use of sensitive personal information.
We do not sell personal information and have not in the preceding twelve months. We share the limited identifiers in Section 6.1 for cross-context behavioral advertising; you may opt out at Section 6.4 or by sending a GPC signal. Your health information is sensitive personal information and we use it only to provide the Service you asked for — a use that does not require a “limit” option — and never to infer characteristics about you. We do not knowingly collect or sell the personal information of anyone under 16.
10.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states
You have rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not sell your data and do not conduct such profiling. Your health information is sensitive data, and we process it only with your consent, for the purposes in Section 9. Where your state provides an appeal process for a denied request, we will tell you how to use it.
10.3 EU, EEA, UK, and Switzerland
Under the GDPR and UK GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, including objection to processing based on legitimate interests. Health data is a special category under Article 9; we process it only on the basis of your explicit consent, which you may withdraw at any time by deleting your account. The legal bases for our other processing are in Section 3. You may lodge a complaint with your local supervisory authority; we would appreciate the chance to address your concern first.
MenoLisa is offered from the United States and is not currently directed to the EU, EEA, UK, or Switzerland. We honor these rights for anyone who asks, regardless of where they live.
11. International Transfers
We are based in Wyoming, USA, and our providers store and process information there. If you use the Service from elsewhere, your information will be transferred to and processed in the United States, which may not offer the same protections as your home country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, and on your explicit consent for health data. Contact us for details of the safeguards in place.
12. Children
MenoLisa is for adults aged 18 and over. We do not direct the Service to children and do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe a minor has given us information, contact support@macurasolutions.us and we will remove it.
13. Changes to This Policy
We may update this policy. We will change the “Last Updated” date above, and for material changes — particularly any change to how we handle health information — we will give you advance notice by email or in the Service. We will not use health information we already hold for a materially different purpose without your consent. Continued use after a change takes effect is your acceptance of it.
14. Contact Us
For any privacy question, request, or complaint — including access, correction, deletion, portability, or an opt-out:
Macura Solutions LLC
30 N Gould St, Ste N
Sheridan, WY 82801, United States
Email: support@macurasolutions.us
We acknowledge privacy requests within five (5) business days and complete them within the time your law requires, and in any case within 45 days.