Effective date: 2026-08-21
Privacy Policy
This policy explains the limited data handling that currently occurs, what does not occur, and the review required before any future Google advertising could be enabled.
Privacy at a glance
The current product is designed to answer a few practical questions quickly: what stays in the browser, what ordinary requests can expose to infrastructure providers, and what information is created only when someone chooses to contact support.
Calculator inputs
- Processed in your browser and not sent to an external calculation API.
- No user account, child profile, stored longitudinal growth record, or health-record database.
- Not persisted in localStorage, sessionStorage, or IndexedDB by calculator code.
Infrastructure
Ordinary page and asset requests may expose technical request data to the verified hosting, delivery, DNS, and security providers described below.
Support email
Information leaves the device for support only when a person voluntarily sends a message through email and network providers.
Current advertising and analytics
Advertising, Google Analytics, third-party audience analytics, CMP code, and an advertising consent signal are not active in the current site implementation.
What leaves your browser?
Loading the website
Ordinary page and asset requests can reach hosting, delivery, DNS, and security infrastructure. Possible technical data includes an IP address, requested URL, user agent, timestamp, request status or duration, and network or security events; the exact fields and retention depend on the provider and configuration.
Using a calculator
Submitted dates, measurements, units, and results remain in browser-side calculation state under the current implementation. Calculator components do not call an external calculation API or place those values in a URL query.
Sending support email
A message leaves the device only because the sender chooses to send it. The email provider and ordinary network infrastructure then process the information needed to deliver and handle that message.
What Child Growth Lab does not currently do
- It does not require a user account, child profile, name, or child contact information.
- It does not create a stored child health record or a longitudinal measurement history.
- It does not send calculator inputs or results to Google, advertisers, analytics, or audience services.
- It does not use calculator measurements, results, or inferred health information to build advertising audiences.
- It does not currently activate AdSense ads, analytics, a CMP, or an advertising consent signal.
These are current product facts, not a determination that any particular privacy law applies or does not apply.
Current advertising and analytics status
Advertising is not currently enabled. No AdSense ad script or ad slot is loaded. No Google Analytics or third-party audience analytics is loaded. No CMP or advertising consent signal is active.
The google-adsense-account metadata associates the site with a publisher account. The ads.txt record identifies an authorized digital-advertising seller relationship. These setup records support account association, verification, and sales authorization; neither one loads an advertisement, creates an ad request, sets an advertising cookie, or sends calculator inputs to Google.
Calculator inputs and results
Dates, measurements, units, sex-specific reference selection, and other calculator inputs are processed in your browser to produce a result. Calculator components do not call an external calculation API. The site does not create a user account, child profile, health-record database, or long-term measurement history.
Under the current implementation, Child Growth Lab does not send calculator inputs or results to Google, advertisers, analytics services, email services, or other third parties. Inputs are not embedded in URL queries, advertising parameters, or audience identifiers. Calculator inputs and results will not be passed as ad-targeting parameters or used to create a health audience.
The calculator code does not persist calculator inputs in localStorage or sessionStorage, and does not use IndexedDB for them. Values may exist temporarily in browser memory while the page is open. Page source, browser extensions, device software, screenshots, and other aspects of the user-controlled environment are outside a universal deletion guarantee.
Infrastructure and service providers
Vercel provides website hosting and content delivery. Cloudflare provides DNS, security, and request processing. Ordinary requests to load a page or asset may let these providers process an IP address, requested URL, user agent, date and time, request duration or status, basic device or browser information, and network or security events.
Infrastructure request logs are not a child measurement database. Provider processing, retention, and security depend on the relevant configuration, contracts, policies, and applicable requirements. Child Growth Lab does not promise a single fixed retention period for provider-controlled logs and does not claim that infrastructure never records visits.
Support email and voluntarily provided information
Email information is created only when someone voluntarily sends a message to support@childgrowthlab.com. It may include the sender address, message headers and time, body, attachments, and technical or reproduction details the sender chooses to provide. It may be used to answer a question, reproduce an error, verify a source, address accessibility or privacy concerns, and maintain reasonable security and correction records.
The support address is not a secure medical portal. Do not email a child's name, full real birth date, home address, school, medical-record or identity number, photograph, video, laboratory or imaging material, or a complete diagnosis, medication, or growth record. Send only the minimum fictional, synthetic, or de-identified information needed to explain the issue.
Email passes through mail and network infrastructure and is not promised to have end-to-end encryption. See Contact for preferred problem-reporting details and the limits of support.
Children and sensitive health information
Child Growth Lab is written for parents, caregivers, healthcare professionals, and other adults. It is not designed as an interactive service directed to children. The site does not require a child to create an account or provide a name or contact information, and it does not create a child health profile.
Health information is not used for personalized advertising, and known activity of users under 13 must not be used for personalized advertising. Users should not send identifiable child health information by email. A website discussing children's health does not thereby have permission to collect children's personal information.
If a future page or traffic context requires child-directed or age-treatment controls, those controls must be assessed through the relevant Google tools and applicable requirements before advertising is enabled. This policy does not claim COPPA, GDPR, CCPA, HIPAA, or other legal certification.
Retention, disclosure, and security
Calculator inputs
The site does not receive or retain browser-local calculator inputs. Because it does not receive them, the support inbox cannot retrieve or delete values held only in a user's browser environment.
Infrastructure logs
Providers may retain logs as configured for delivery, security, abuse prevention, and troubleshooting. No single fixed period is promised for provider-controlled logs.
Support email
Voluntary messages are retained only while reasonably needed for response, security, correction, and necessary records. A sender may request deletion of information they supplied that the site can reasonably identify and control. Legal, security, abuse- prevention, or correction-record needs may prevent immediate deletion of every copy.
Disclosure and service providers
Child Growth Lab does not receive browser-local calculator inputs or results for sale or disclosure, and does not use them for advertising audiences. Providers may process ordinary request data for hosting, delivery, DNS, security, and email. Limited information may be disclosed when legally required, to address a security event, or to protect the site and its users.
Security and practical limitations
Data minimization and browser-local calculations reduce the need to send health inputs to a server. Having no accounts or child-record database reduces long-term storage risk, while infrastructure providers supply delivery and security capabilities.
No website, network, browser, device, or email system can guarantee absolute security. Email is not a channel for transmitting medical records. Users should avoid sending sensitive or identifying information and should keep their own browser and device secure.
If advertising is enabled later
If Google advertising is enabled later, this policy and the implementation must be updated before any ad tag loads. Google ad tags may process the current page URL, IP address, browser or device information, ad-request information, cookie or similar local-storage identifiers, and ad impressions or interactions. The exact enabled providers and data flow would then need to be disclosed.
Google requires publishers to provide appropriate privacy disclosures for AdSense. For applicable personalized advertising in the EEA, the UK, and Switzerland, current Google publisher requirements call for a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework version then supported by Google. Google CMP certification does not certify complete compliance with the GDPR or other applicable law.
Calculator inputs, results, and child measurements will not be passed as ad-targeting parameters or audience data. Google Publisher Policies state that personalized advertising must not be based on health information, including actual or inferred health information, or on activity by users known to be under 13 or areas directed to children under 13. Any child-directed or COPPA treatment, age treatment, consent, or other legal requirement must be separately assessed before activation; an applicable non-personalized ads or limited ads treatment may be required in some contexts.
Privacy questions and policy changes
Send a privacy question to support@childgrowthlab.com using only the minimum information necessary. A sender may ask about access to, correction of, or deletion of information they voluntarily emailed and that Child Growth Lab can reasonably identify and control. The site cannot provide calculator inputs it never received, and may not be able to identify or control anonymous, security, or provider-held logs. Applicable rights and handling may differ by location and circumstances.
A material change must update this policy, its effective date, the privacy validator, and tests before release. Material changes include enabling advertising, analytics, or a CMP; adding cookies, browser storage, a provider, or a database; beginning to receive or store calculator inputs; or changing support-email handling or retention.
Related information: Contact, About, Terms of Use, and Medical Disclaimer.