ThouShaltNot Consumer Health Data Privacy Policy

Effective date: August 28, 2026
Last updated: August 28, 2026

This Consumer Health Data Privacy Policy explains how Prodigal Org, a Texas nonprofit organization recognized as tax-exempt under Section 501(c)(3) of the Internal Revenue Code, doing business as Prodigal.org (“Prodigal,” “we,” “us,” or “our”), collects, uses, shares, and protects consumer health data through ThouShaltNot paid accountability.

This policy applies specifically to consumer health data. Our general Terms and Privacy Policy describes our broader information practices.

1. Consumer health data covered by this policy

For purposes of this policy, we treat information as consumer health data when it is linked or reasonably linkable to a person and identifies or may support an inference about that person’s physical or mental health status, sexual health or sexual well-being, or use of behavioral or accountability support related to sexual well-being.

An automated block is not a diagnosis, confession, or reliable conclusion about a person. Ordinary pages can be blocked by mistake. We nevertheless treat the categories below conservatively because a flagged URL or use of the Service may reveal or support a sensitive inference.

2. Categories of consumer health data we collect and how we use them

2.1 Flagged browsing activity

When a paid account connects a supported browser, we collect each blocked-page event reported by that browser, whether or not the user proceeds. We also collect a separate event when the user chooses to proceed. A blocked page may have been identified by an explicit-content rule, a local page-text signal, optional social-media blocking, or the user’s custom block list.

A particular block or proceed event may not reveal consumer health data. The protections in this policy apply when an event identifies or may support a covered health inference.

An event may include:

  • the full flagged URL, which may contain a domain, path, query parameters, search terms, or other information placed in the URL by a website;
  • whether the event was a block or a proceed event;
  • the automated signal category;
  • the date and time of the event and receipt;
  • the connected browser and user-supplied device label;
  • an Incognito indicator, when available;
  • a Boolean indicating whether on-screen text was available to the local classifier, but not the text itself; and
  • installation and random monitored identifiers used to associate the event with the correct account and partners.

We use this information to provide the activity feed the user requested, determine whether paid proceed functionality is available, distinguish blocks from proceeds, send limited accountability notifications, investigate reliability or security problems, respond to verified requests, and comply with law.

2.2 Browser protection and presence information

For each paid connected browser, we collect information such as the browser family, user-supplied device label, extension version, time zone, connection and last-seen times, recent presence days, no-signal periods, and whether the extension has Incognito access.

We use this information to show whether a connected browser appears to be reporting, alert users and partners to certain protection-status changes, help the user manage connected browsers, troubleshoot the Service, and protect accounts. A loss of signal does not prove that a person removed or disabled the extension; a browser or device may be closed, offline, or unused.

2.3 Accountability participation and relationship information

We collect the fact that a person enrolled in paid accountability, the email addresses of invited partners, invitation and relationship status, acceptance, decline, removal, and withdrawal dates, the versions of disclosures and consents accepted, and related notification records.

We use this information to administer the accountability relationship, determine whether an active partner exists, control access to the partner portal and proceed functionality, send relationship notices, preserve consent evidence, prevent invitation abuse, and respond to verified requests.

2.4 Sensitive inferences

A flagged URL, event pattern, or use of ThouShaltNot may suggest information about sexual interests, sexual activity, sexual well-being, behavioral support, or related accountability support. We use automated signals only to provide the blocking and accountability functions requested by the user. We do not use them to diagnose a condition, determine sexual orientation, or make advertising, employment, credit, housing, insurance, or other eligibility decisions.

3. Sources of consumer health data

We receive consumer health data from:

  • the monitored user and the account information, choices, consents, browser labels, custom block list, and partner invitations they provide;
  • the ThouShaltNot extension connected by the monitored user;
  • browser and installation status generated while providing the Service;
  • automated local blocking rules and classifier results; and
  • actions taken by invited or active accountability partners, such as accepting, declining, or withdrawing from a relationship.

We do not obtain consumer health data from data brokers, advertising networks, health care providers, pharmacies, insurers, employers, or public records. We do not collect precise geolocation information or use health-related geofences.

4. How consumer health data is processed

The extension examines URLs and visible page text locally to decide whether to block a page. It does not send page text, matched words, screenshots, images, form contents, messages, passwords, or other page contents to Prodigal. Unflagged browsing URLs are not intentionally sent to Prodigal’s accountability databases.

When a paid connected browser reports a block or proceed event, the full flagged URL and the limited event information described above are encrypted in transit and processed by the hosted Service. Identity and activity information are kept in separate databases. Activity uses a random monitored identifier, with a controlled mapping used when association is necessary for authorized partner access, notifications, rights requests, deletion, security, or service operation. This separation is a safeguard; the hosted information remains reasonably linkable and is not treated as legally deidentified.

5. Consumer health data we share

We may share the following categories:

  • flagged URLs and associated block or proceed information;
  • browser, device-label, Incognito, protection, and presence information;
  • paid-accountability participation and partner-relationship status; and
  • identifiers necessary to provide, secure, support, or delete the Service.

We share these categories only as described below.

5.1 Accountability partners selected by the user

After an invited partner independently accepts, the partner may sign in to see the monitored user’s first name, recent block and proceed events, full flagged URLs, dates and times, signal categories, browser and device labels, Incognito event indicators, connected-browser status, Incognito-access status, recent presence days, and recent no-signal periods. An active partner may also see recent relationship updates involving another partner, including the other partner’s email address.

Partners see only events occurring after their acceptance and while their relationship remains active. Removing a partner or a partner’s withdrawal ends future portal access to that monitored person’s information. A partner is an independent person, not a Prodigal employee or processor, and may retain information by taking a screenshot, forwarding an email, or otherwise making a copy. Prodigal cannot retrieve copies held outside its systems.

Notification emails do not include flagged URLs or activity-feed details. They may identify the monitored person by first name, describe an event or status category, and identify an affected partner by email address.

5.2 Service providers

We disclose consumer health data or associated sensitive account information to service providers only as needed to operate the Service. Current providers that may process such information include:

  • Supabase, for account authentication and hosted identity and activity database infrastructure;
  • Vercel, for web hosting, API execution, and operational logs;
  • Resend, for account, invitation, relationship, and accountability email delivery; and
  • Stripe, for checkout, subscription management, and payment processing. Stripe does not receive the flagged activity feed or full flagged URLs.

Other security and platform providers, including Cloudflare and the Google and Microsoft browser platforms, may process technical information needed to secure, distribute, or run the Service. We do not intentionally provide them with the hosted flagged-activity feed for advertising or profiling.

Service providers must process information for the contracted service and protect it as required by applicable law and their agreements with us.

5.3 Legal and organizational recipients

We may disclose consumer health data when reasonably necessary to comply with law or valid legal process; protect the rights, safety, and security of users, Prodigal, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.

If Prodigal undergoes a merger, reorganization, financing, bankruptcy, or transfer of the Service, information may be disclosed as part of that transaction subject to applicable confidentiality, consent, and consumer health data requirements.

Prodigal has no affiliates with which it shares consumer health data as of the effective date of this policy.

6. No sale, advertising, or third-party tracking

We do not sell consumer health data. We do not use or disclose it for targeted advertising, cross-context behavioral advertising, data brokerage, or unrelated profiling.

We do not permit an advertising network or other third party to collect consumer health data over time across unrelated websites or online services when a person uses our websites, extension, or partner portal. The extension’s local examination of browser pages is performed to provide the user-requested filtering and accountability functions described in this policy.

7. Consent and withdrawal

Before a paid connected browser begins transmitting flagged activity, we present a specific consumer health data collection disclosure and a separate consumer health data sharing disclosure. These disclosures are separate from general acceptance of our Terms. We record the applicable disclosure and policy versions and the time of consent.

You may withdraw consent to future collection or sharing by using an available account control or emailing accountability@prodigal.org. You may remove an individual partner to end that partner’s future access. To stop future hosted collection from connected browsers, disable paid accountability or disconnect all paid browser installations. To stop subscription renewal, you must also cancel through the billing portal; withdrawing consent, removing a partner, disconnecting a browser, or uninstalling the extension does not by itself cancel billing.

Paid accountability and proceed functionality cannot operate without the collection and sharing needed to provide them. Withdrawing consent may therefore disable those paid features, but it does not prevent continued use of the free local blocking features.

Withdrawal applies prospectively and does not reverse a disclosure already made. You may separately request deletion of existing information.

8. Consumer rights and requests

Subject to applicable law, you may have the right to:

  • confirm whether we collect, use, share, or sell consumer health data about you;
  • access the consumer health data we maintain about you;
  • receive a list of third parties and affiliates with whom we shared or sold your consumer health data and available contact information for them;
  • review and request correction of inaccurate consumer health data;
  • withdraw consent and ask us to stop future collection or sharing;
  • request deletion of consumer health data;
  • appeal our refusal to act on a request; and
  • exercise these rights without unlawful discrimination.

You may submit a request or appeal by emailing accountability@prodigal.org. You may also use the authenticated account-deletion control for permanent account deletion. Describe the right you want to exercise and provide the email address associated with the Service. We may take commercially reasonable steps to authenticate your identity and authority. We will not require you to create a new account solely to make a request, although we may ask you to use an existing authenticated account.

We will respond without undue delay and within the period required by applicable law, generally within 45 days. Where permitted and reasonably necessary, we may extend the response period once and will explain the extension. If we deny a request, we will explain the decision and how to appeal. If an appeal is denied, we will provide information about contacting the appropriate state attorney general where required.

If we grant a valid deletion request, we will delete the covered information from our active systems and notify applicable processors, contractors, affiliates, and other third parties as required by law. Information already copied or retained independently by an accountability partner may remain outside our control.

9. Retention and deletion

We use the following ordinary retention schedule for information that may include or be associated with consumer health data:

  • flagged block and proceed events are scheduled for deletion after 7 days;
  • daily browser-presence entries are retained for up to 14 days;
  • resolved browser no-signal episodes are scheduled for deletion after 30 days;
  • expired, declined, or withdrawn-before-acceptance invitation and delivery records are scheduled for deletion after 90 days;
  • notification-job metadata is scheduled for deletion after 90 days;
  • an accepted relationship and versioned consent evidence are retained while active and for up to 2 years after the relationship ends, unless the account is deleted sooner;
  • identity and security audit records are scheduled for deletion after 2 years; and
  • local extension information remains in browser storage until removed by the extension, browser, reset action, or uninstall process.

Installation, account, subscription, support, and security records are retained while needed to provide the Service and afterward as reasonably necessary for payment, tax, accounting, fraud prevention, security, dispute resolution, and legal obligations. We do not retain sensitive information longer than reasonably necessary for a disclosed purpose.

Managed database backups are retained for up to 7 days before rotation. If a backup is restored, we will reapply applicable deletion and retention controls before returning the restored system to ordinary use.

10. Security and limited human access

We use administrative, technical, and organizational safeguards designed for the sensitivity of the information, including transport encryption, separate identity and activity databases, random monitored identifiers, hashed browser credentials, service-role access controls, restricted partner access, short-lived security tokens, anti-bot challenges, rate limits, and event idempotency.

Prodigal personnel do not routinely review flagged URLs. Authorized personnel may access limited information when necessary to provide support with your specific consent, investigate security or abuse, maintain the Service, respond to a verified request, or comply with law. No security measure is perfect.

11. Changes to this policy

We may update this policy to reflect product, provider, or legal changes. We will post the updated version and revise the date above. We will provide additional notice of material changes where appropriate. Before collecting, using, or sharing an additional category of consumer health data, or using it for an additional purpose not disclosed here, we will provide the disclosure and obtain affirmative consent when required by law.

12. Contact

Prodigal Org

Consumer health data requests and appeals: accountability@prodigal.org

Mailing address: 5900 Balcones Drive, STE 12393, Austin, TX 78731