Consumer Health Data Privacy Policy
<<<<<<< HEAD Last Updated: August 21, 2026 ======= Last Updated: August 22, 2026 >>>>>>> origin/worktree-refactored-wiggling-blossom
This Consumer Health Data Privacy Policy is a standalone policy required by the Washington My Health My Data Act (MHMDA) and comparable state consumer-health-data laws. It applies to all US users of Food Signals, regardless of state — we do not limit these protections to Washington or Nevada residents. It supplements, and does not replace, our general Privacy Policy.
1. What Counts as Consumer Health Data Here
For the purposes of this policy, "consumer health data" means:
- Body measurements and profile information — height, weight, waist measurement, age, and sex, where you choose to provide them, when used to calculate BMI or your personalised nutritional targets. - Symptom logs — which symptoms you record and their severity. - Injection-event logs — the timing of injection events you log and, where you choose to record it, a relative dose-change category such as First Dose, Increased, Same, Reduced, or Restarted After Break, and your injection-interval preference if you set one. We do not collect or store the name of your medication or a numerical dosage amount. - Meal and food logs — the foods, meals, and drinks you record, and however they're recorded (photo, description, or selecting a previous entry). - Body mass index (BMI) and other nutritional information derived from your data, where computed from information you provide. - Personal patterns and insights derived from your logged information, where those insights relate to your health, symptoms, nutrition, or response patterns (for example, an observed correlation between a symptom and something logged nearby in time). - Consent and access records — the record of the consents you've given for consumer health data, and the log of who has accessed it and when.
This is a subset of the broader data described in our Privacy Policy — this document exists because several US states give this specific category of data extra protection.
2. Sources of Consumer Health Data
We collect consumer health data primarily directly from you, when you:
- enter information during account setup or in your profile;
- record meals, food, water, or symptoms;
- record injection events or set an injection-interval preference; or
- provide body measurements or other information used to calculate nutritional targets.
We also generate consumer health data from information you provide, including calculated BMI, nutritional targets, and the personal patterns or insights described in Section 1.
We do not obtain your medication information, medical records, or any other consumer health data from pharmacies, healthcare providers, insurers, or data brokers. The only source of the consumer health data described in this policy is you, directly, or our own systems deriving it from what you've provided.
3. We Only Collect This Data With Your Affirmative Opt-In
We do not collect any consumer health data unless you have affirmatively opted in. Specifically:
- Creating a Food Signals account requires checking a dedicated, unticked-by-default consent checkbox for health-data collection — separate from the Terms of Service / Privacy Policy checkbox — before your account can be created.
- No symptom, injection-event, meal, body-measurement, or derived-pattern record is collected, stored, or transmitted for any account that has not granted this consent.
4. We Do Not Sell Consumer Health Data
We do not sell, and have never sold, consumer health data. We also do not share consumer health data with any third party for the purpose of targeted advertising, and we do not use it to build behavioural advertising profiles. The only parties who ever receive any part of your consumer health data are the processors named in our Privacy Policy §3 (our AI provider, who helps generate your food suggestions, and Cloudflare, who hosts the Service) and, only if you separately opt in, your dietitian. Apple, Google, Brevo, and our marketing-website analytics providers do not receive consumer health data — see Privacy Policy §3 for exactly what each processor receives.
5. Your Rights Over Your Consumer Health Data
You have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data (we are not selling it, for anyone).
- Access the consumer health data we hold about you.
- Obtain information about sharing — the categories of third parties or affiliates with whom we have shared your consumer health data. As described in Section 4, that is currently our AI provider and Cloudflare, and your dietitian only if you've opted in.
- Withdraw your consent to future collection at any time, from Settings → Privacy → "Your data & consent rights" in the app, or by contacting us. Because collecting this data is required for the app's core logging features to work, withdrawing this specific consent closes your account — see our Privacy Policy and the in-app consent-rights screen for how this works in practice.
- Delete your consumer health data, fulfilled within 30 days of a deletion request — the same 30-day window described in our general Privacy Policy §5, and within the time required by applicable law.
We have never sold your consumer health data, to anyone, for any purpose.
To exercise any of these rights, please contact us or use the in-app controls described above.
6. Geofencing
Food Signals does not use geofencing around any entity providing in-person healthcare services to identify or track people seeking healthcare services, to collect consumer health data, or to send consumer health-related notifications, messages, or advertisements. We also do not use location information to selectively provide or withhold the privacy protections described in this policy — every US user gets the same protections regardless of which state they're in.
7. Data Security and Breach Notification
Consumer health data is protected by the same security measures described in our Privacy Policy §6 (encryption in transit, access controls). In the event of a breach involving consumer health data that is likely to cause harm, we will notify affected US users without unreasonable delay and no later than 60 days, consistent with the FTC Health Breach Notification Rule (some US state breach laws may require a shorter timeframe, which we will follow where it applies), and will notify the Australian Office of the Australian Information Commissioner (OAIC) within 30 days where the Australian Notifiable Data Breaches scheme applies.
8. Contact
For questions about this policy or to exercise your rights, please contact us.
9. Changes to This Policy
We will notify you of material changes to this policy the same way we notify you of material changes to our general Privacy Policy — by email or in-app notice at least 14 days before the change takes effect. The current version is always available at this URL.