Consumer Health Data Privacy Policy

<<<<<<< HEAD Last Updated: August 21, 2026 ======= Last Updated: August 22, 2026 >>>>>>> origin/worktree-refactored-wiggling-blossom

This Consumer Health Data Privacy Policy is a standalone policy required by the Washington My Health My Data Act (MHMDA) and comparable state consumer-health-data laws. It applies to all US users of Food Signals, regardless of state — we do not limit these protections to Washington or Nevada residents. It supplements, and does not replace, our general Privacy Policy.


1. What Counts as Consumer Health Data Here

For the purposes of this policy, "consumer health data" means:

- Body measurements and profile information — height, weight, waist measurement, age, and sex, where you choose to provide them, when used to calculate BMI or your personalised nutritional targets. - Symptom logs — which symptoms you record and their severity. - Injection-event logs — the timing of injection events you log and, where you choose to record it, a relative dose-change category such as First Dose, Increased, Same, Reduced, or Restarted After Break, and your injection-interval preference if you set one. We do not collect or store the name of your medication or a numerical dosage amount. - Meal and food logs — the foods, meals, and drinks you record, and however they're recorded (photo, description, or selecting a previous entry). - Body mass index (BMI) and other nutritional information derived from your data, where computed from information you provide. - Personal patterns and insights derived from your logged information, where those insights relate to your health, symptoms, nutrition, or response patterns (for example, an observed correlation between a symptom and something logged nearby in time). - Consent and access records — the record of the consents you've given for consumer health data, and the log of who has accessed it and when.

This is a subset of the broader data described in our Privacy Policy — this document exists because several US states give this specific category of data extra protection.


2. Sources of Consumer Health Data

We collect consumer health data primarily directly from you, when you:

We also generate consumer health data from information you provide, including calculated BMI, nutritional targets, and the personal patterns or insights described in Section 1.

We do not obtain your medication information, medical records, or any other consumer health data from pharmacies, healthcare providers, insurers, or data brokers. The only source of the consumer health data described in this policy is you, directly, or our own systems deriving it from what you've provided.


3. We Only Collect This Data With Your Affirmative Opt-In

We do not collect any consumer health data unless you have affirmatively opted in. Specifically:


4. We Do Not Sell Consumer Health Data

We do not sell, and have never sold, consumer health data. We also do not share consumer health data with any third party for the purpose of targeted advertising, and we do not use it to build behavioural advertising profiles. The only parties who ever receive any part of your consumer health data are the processors named in our Privacy Policy §3 (our AI provider, who helps generate your food suggestions, and Cloudflare, who hosts the Service) and, only if you separately opt in, your dietitian. Apple, Google, Brevo, and our marketing-website analytics providers do not receive consumer health data — see Privacy Policy §3 for exactly what each processor receives.


5. Your Rights Over Your Consumer Health Data

You have the right to:

We have never sold your consumer health data, to anyone, for any purpose.

To exercise any of these rights, please contact us or use the in-app controls described above.


6. Geofencing

Food Signals does not use geofencing around any entity providing in-person healthcare services to identify or track people seeking healthcare services, to collect consumer health data, or to send consumer health-related notifications, messages, or advertisements. We also do not use location information to selectively provide or withhold the privacy protections described in this policy — every US user gets the same protections regardless of which state they're in.


7. Data Security and Breach Notification

Consumer health data is protected by the same security measures described in our Privacy Policy §6 (encryption in transit, access controls). In the event of a breach involving consumer health data that is likely to cause harm, we will notify affected US users without unreasonable delay and no later than 60 days, consistent with the FTC Health Breach Notification Rule (some US state breach laws may require a shorter timeframe, which we will follow where it applies), and will notify the Australian Office of the Australian Information Commissioner (OAIC) within 30 days where the Australian Notifiable Data Breaches scheme applies.


8. Contact

For questions about this policy or to exercise your rights, please contact us.


9. Changes to This Policy

We will notify you of material changes to this policy the same way we notify you of material changes to our general Privacy Policy — by email or in-app notice at least 14 days before the change takes effect. The current version is always available at this URL.