Skip to content
SIGIL
About Stay in the loop

Privacy Policy

Last updated: 13 August 2026

1. What this policy covers

This policy explains how Sigil Health Inc. (“Sigil,” “we,” “us”) handles information collected through our website at sigilhealth.com and through the mailing list you can join on it.

This policy does not cover the Sigil app or the Sigil wearable device. Those products collect health and biometric information, and they are governed by a separate privacy policy and consent agreement provided to you when you enroll as a tester or set up a device. Nothing in this document describes how that information is handled.

2. Who we are

Sigil Health Inc. is a Delaware corporation based in Austin, Texas. We are the party responsible for the information described in this policy. For privacy questions, write to privacy@sigilhealth.com.

3. Information we collect

Information you give us

  • Your email address, when you subscribe to our mailing list.
  • Anything you choose to write to us, if you send us an email — including your name, your message, and whatever else it contains.

The subscription form also contains a hidden field that automated bots fill in and people do not. If it is filled in, we discard the submission. We do not store what was entered.

Information collected automatically

Our hosting provider records standard server logs when your browser requests a page. These include your IP address, browser type and version, the page you requested, the page that referred you, and the time of the request. We use these to keep the site running and to detect abuse.

Advertising and conversion tracking

We advertise on Facebook and Instagram, and we use the Meta Pixel — a piece of tracking code from Meta Platforms, Inc. — to measure whether those ads work. When the pixel runs, Meta receives:

  • Your IP address, browser type, and device information.
  • The page you are viewing and the page that referred you there, including the ad identifier if you arrived from one of our ads.
  • Identifiers stored in cookies that Meta sets or reads in your browser, which Meta can match to your Facebook or Instagram account if you have one.
  • The fact that you subscribed to our mailing list, recorded as a conversion event.
  • A hashed version of your email address, if you type it into the subscription form. Meta’s pixel reads the field as you submit it and sends the address as a SHA-256 hash rather than as plain text. Meta calls this Advanced Matching, and we share the hashed identifier with Meta for advertising measurement and marketing.

Hashing is not anonymization. The hash cannot be reversed into your email address, but it is stable and unique to that address, so Meta compares it against hashes of the addresses on its own accounts to recognize you. It identifies you, and privacy law treats it as personal information. We describe it as hashed because that is what we send, not because it makes you anonymous.

Meta uses this information for its own purposes as well as ours, including to target advertising to you across its services and other websites. Its handling of that data is governed by Meta’s Privacy Policy. Section 9 explains how to opt out, and section 10 explains why the pixel does not run in Europe.

If you never enter your email address on this site, no hashed identifier is created. Opting out under section 9, by either method, stops all of this — the pixel does not load at all, so nothing is read from the form.

Product analytics and session recording

We use Microsoft Clarity — an analytics and session-recording tool from Microsoft Corporation — to understand how people actually use this site, so we can find the parts that are confusing or broken. Clarity does more than count page views: it records how you move through a page and lets us play that back. When Clarity runs, Microsoft receives:

  • Your IP address, browser type, operating system, device type, screen size, and approximate location inferred from your IP address.
  • The pages you view on this site, the order you view them in, how long you stay, and the page that referred you.
  • A recording of your interaction with each page — mouse movement, clicks and taps, scrolling, and the text of the page as you saw it — which Microsoft reconstructs into a replayable session and into aggregate heatmaps.
  • Identifiers stored in cookies that Clarity sets in your browser to recognize the same visitor across pages and across visits.

The email field is masked. Every email input on this site carries an attribute instructing Clarity to replace its contents with placeholder characters before the recording leaves your browser, so the address you type is not part of the replay we can watch. This is the only field on the site you type into. We do not use Clarity’s features for attaching your identity to a recording, so a session is identified to us by a random Clarity identifier and not by name or email address.

Microsoft processes this information as an independent controller as well as on our behalf, and may use it for its own purposes, including improving its products and services. Its handling of that data is governed by the Microsoft Privacy Statement. Section 9 explains how to opt out, and section 10 explains why Clarity does not run in Europe.

What we do not collect

We do not collect any health, biometric, or sensitive personal information through this website, and we do not ask you for your name, your address, or a password. Beyond the tracking described above, we keep no record of our own about which pages an individual visitor viewed — the server logs, the Meta Pixel, and Clarity are the whole of it, and the last two are records held by Meta and Microsoft rather than by us.

4. Cookies and third-party requests

Loading a page on this site causes your browser to contact three companies other than us.

  • Meta. The pixel described in section 3 sets and reads cookies in your browser to recognize you across visits and across other sites carrying Meta’s code. These cookies typically last up to about three months and renew on each visit. Blocking them, or blocking third-party cookies generally in your browser settings, prevents this tracking.
  • Microsoft. Clarity, described in section 3, sets cookies in your browser to tie the pages of one visit together and to recognize a returning visitor. They are set under this site’s own domain rather than Microsoft’s, so blocking third-party cookies does not remove them; the reliable way to stop Clarity is to opt out under section 9. The visitor cookie typically lasts up to about a year and the session cookie expires within a day.
  • Google. The site loads its typefaces from Google Fonts, so Google receives your IP address and browser information when a page loads. This request carries no cookies and is not used to track you. Google’s handling of it is governed by Google’s Privacy Policy.

We set no cookies of our own beyond the Clarity cookies described above, which are written by Microsoft’s code under our domain. This site has no login, no shopping cart, and no session of ours to remember.

5. How we use information

  • To send you the research briefings and product updates you subscribed to.
  • To reply to questions and messages you send us.
  • To operate, secure, debug, and improve the website.
  • To understand how the site is actually used — which pages people read, where they get stuck, and what is broken on their device — so we can fix it. This is what Microsoft Clarity is for.
  • To measure whether our advertising works, and to reach people likely to be interested in Sigil. This is what the Meta Pixel is for.
  • To comply with legal obligations and enforce our Terms of Service.

We do not use your information to make automated decisions that produce legal or similarly significant effects for you.

6. How we share information

We do not sell your personal information for money. We do disclose information to Meta for advertising, which California law treats as “sharing” and which may also meet that law’s broad definition of a “sale.” We also disclose browsing and interaction information to Microsoft through Clarity, and because Microsoft may use it for its own purposes we treat that disclosure as covered by the same opt-out. Section 9 explains how to opt out of both. We disclose information in these situations only:

  • Advertising partners. Meta, through the pixel described in section 3, receives the browsing information listed there together with a hashed identifier derived from your email address. We share those hashed identifiers with advertising partners for measurement and marketing. Meta is bound by its Business Tools Terms in how it may use them, and it also uses that information for its own purposes.
  • Analytics providers. Microsoft, through Clarity as described in section 3, receives the browsing and interaction information listed there, including the session recordings. Microsoft is bound by the Clarity terms of use in how it may act for us, and it also uses that information for its own purposes.
  • Service providers. Companies that host the website and deliver our email, acting on our instructions under contract, and only to the extent needed to provide those services.
  • Legal requirements. When required by law, subpoena, or valid legal process, or where necessary to protect our rights, safety, or property.
  • Business transfers. If Sigil is acquired, merged, or reorganized, information may transfer as part of that transaction. Any acquirer would remain bound by this policy for information collected under it, and we would notify subscribers of a change in control.

7. How long we keep it

We keep your email address until you unsubscribe or ask us to delete it, and for a short period afterward so we can honor the unsubscribe request. Server logs are retained for a limited period under our hosting provider’s default retention settings and are then deleted. Email correspondence is kept as long as needed to resolve your inquiry and to maintain a record of it.

Information collected by the Meta Pixel, including the hashed identifier described in section 3, is held by Meta under its own retention schedule, which we do not control. We see only aggregate advertising reports, not records about individual visitors.

Session recordings and analytics collected by Clarity are stored by Microsoft on its own servers, under its own retention schedule, which we also do not control. We do not download or keep copies of recordings; we view them in Microsoft’s dashboard, and when Microsoft expires a recording it is gone from our view too.

8. Your choices

  • Opt out of advertising tracking and session recording. See section 9 — the methods described there stop both the Meta Pixel and Clarity, and they work for everyone, not only California residents.
  • Unsubscribe. Every email we send includes an unsubscribe link, and it works with one click. You can also email us to be removed.
  • Access, correction, and deletion. Write to privacy@sigilhealth.com and we will tell you what we hold about you, correct it, or delete it. We will respond within the time frames the law requires, and within 30 days in any case.
  • Control cookies in your browser. Every major browser can block third-party cookies or clear the ones already stored. Doing so stops the Meta Pixel from recognizing you by cookie across visits. It does not stop the hashed-email matching described in section 3, which does not rely on cookies, and it does not stop Clarity, whose cookies are first-party — to stop either, opt out under section 9.
  • Adjust your Meta ad settings. If you have a Facebook or Instagram account, Meta’s own ad preferences let you limit how activity collected off its services is used to target you.

We will not treat you differently for exercising any of these rights.

9. California residents

Under the California Consumer Privacy Act, as amended by the CPRA, we disclose the following about the preceding 12 months.

The categories of personal information we collected are identifiers (email address, hashed email address, IP address, cookie identifiers), internet or network activity (server log information, pages viewed, ad interactions, and the session recordings and interaction data described in section 3), and approximate geolocation inferred from your IP address by our analytics provider. We collected them from you directly and automatically from your browser, for the business purposes described in section 5. We disclosed identifiers and internet activity to the advertising, analytics, and service providers described in section 6.

We share identifiers — including the hashed email address described in section 3 — and internet activity with Meta for cross-context behavioral advertising. We disclose internet activity and approximate geolocation to Microsoft through Clarity; Microsoft may use it for its own purposes, so we let you opt out of it on the same terms. We do not sell personal information for monetary consideration, and we do not sell or share the personal information of consumers we know to be under 16.

Your privacy choices — opting out of sharing

You can stop us from sharing your information for advertising, and stop the session recording described in section 3, in either of these ways:

  • Turn on Global Privacy Control. Global Privacy Control (GPC) is a setting built into some browsers and available as an extension in others, which tells every site you visit that you are opting out. We detect the GPC signal and load neither the Meta Pixel nor Microsoft Clarity when it is present. This is the fastest method and requires nothing from us. Instructions are at globalprivacycontrol.org.
  • Email us. Write to privacy@sigilhealth.com with “Opt out of sharing” in the subject line. We do not require you to create an account or verify your identity to opt out.
  • Use Microsoft’s own opt-out. For Clarity specifically, Microsoft publishes a standing opt-out at clarity.microsoft.com/terms that applies across every site using it.

GPC is a browser setting, so you will need to enable it on each browser and device you use. If you opt out by either method, we will not ask you to opt back in for at least 12 months.

Other California rights

You have the right to know what we collect, to request deletion or correction, to opt out of sale or sharing, to limit the use of sensitive personal information (we collect none through this site), and to be free from discrimination for exercising these rights. To exercise any of them, email privacy@sigilhealth.com. You may use an authorized agent; we may ask for proof of authorization.

10. Visitors in the EEA, UK, and Switzerland

We run neither the Meta Pixel nor Microsoft Clarity for visitors in the EEA, the UK, or Switzerland. Advertising trackers and session recording both require your prior consent in those regions, and rather than ask for it, we do not load either one at all. Because the pixel never runs, no hashed identifier is created from your email address; because Clarity never runs, no recording of your visit is made and no Clarity cookie is set. Nothing on this site tracks you for advertising or analytics purposes if you are visiting from one of them.

We process the rest of your information on the following legal bases:

  • Consent — for sending you marketing and research emails. You may withdraw consent at any time, which does not affect processing carried out before you withdrew it.
  • Legitimate interests — for operating, securing, and debugging the website, and for responding to messages you send us.
  • Legal obligation — where the law requires us to retain or produce information.

You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. To exercise these rights, email privacy@sigilhealth.com. You also have the right to lodge a complaint with your local data protection supervisory authority, and we would ask that you raise the issue with us first so we have a chance to resolve it.

11. International transfers

Sigil operates in the United States, and information collected through this site is stored and processed there. If you access the site from outside the United States, you are sending your information to a country whose data protection laws may differ from those of your own.

12. Security

We use reasonable administrative and technical safeguards to protect the information we hold, including encrypted connections to the website and access controls on our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children

This website is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has given us information, email privacy@sigilhealth.com and we will delete it.

14. Changes to this policy

We may update this policy as the site changes — for example, if we add another tracking or analytics tool, we will say so here before doing it. We will revise the “Last updated” date at the top.

15. Contact us

Questions, requests, or complaints about this policy go to privacy@sigilhealth.com.

Sigil Health Inc.
Austin, Texas, United States

Sigil

Privacy Policy Terms of Service Your Privacy Choices

Sigil is a general wellness product, not intended to diagnose, treat, cure, or prevent any disease.

2026 SIGIL