Legal
Consumer Health Data Privacy Policy
Draft pending legal review
This is a working draft. It is being reviewed and finalized with counsel, and it will be updated before public launch. The highlighted items in brackets are still being completed, including the effective date. Please do not rely on this draft as a final or binding document.
Draft for attorney review. Not final. Not legal advice. Prepared by Automate AI LLC for counsel to review, correct, and finalize. This is a standalone policy in the form required by the Washington My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut consumer-health provisions. It supplements, and where it conflicts as to consumer health data, controls over, our Privacy Policy.
Effective date: [TO BE SET] · Version: [TO BE SET]
A distinct, prominent link to this policy must appear on the homepage of replaycouples.com (required by MHMDA) and in the app.
Contact: [consumer health data contact], [privacy@ email], Automate AI LLC, [address].
1. Why this policy exists and who it covers
Information you provide to Replay, such as reflections describing your relationship, your feelings, and your emotional state, may constitute consumer health data under Washington, Nevada, and Connecticut law, because it can relate to mental or behavioral health. This policy explains, specifically for that category, what we collect, how we use it, whom we share it with, and your rights.
It applies to Washington, Nevada, and Connecticut residents, and we apply it to all United States users as a matter of practice. ATTORNEY: confirm the state list, including any additional states whose consumer-health provisions apply at launch.
2. Categories of consumer health data we collect
| Category | Specific data | Source |
|---|---|---|
| Mental or behavioral health information | The encrypted reflections you record, which may describe feelings, relationship conflict, and emotional state | Directly from you, only when you choose to record |
| Derived processing data | Sanitized, de-identified, blame-neutral text generated on your device from your reflections | Derived on your device |
| Safety-signal metadata | Content-free records that a safety-related signal was identified, with type, severity, and timestamp | Generated automatically by the app’s safety features |
We do not collect: precise geolocation; biometric data or voiceprints; health data from health care providers, insurers, pharmacies, health apps, data brokers, or any third-party source; purchase histories indicating health status; or any consumer health data about you from anyone other than you.
We do not infer health conditions for advertising or marketing, and we do not perform any advertising profiling.
3. How consumer health data is protected
Reflections are end-to-end encrypted on your device before transmission. Plaintext and raw audio never leave your device, and neither we nor our hosting provider can read them. Only sanitized, de-identified, blame-neutral text is transmitted to our processors, under contractual terms prohibiting retention and model training. See the Privacy Policy for the full technical description and its limits.
4. Purposes for collecting and using consumer health data
We collect and use it solelyto: provide the features you request in the app; operate the app’s safety features, including surfacing crisis resources; maintain security and integrity; and comply with legal obligations.
We do not use it for advertising, marketing, profiling, research, product development on identifiable data, or any purpose beyond those stated. We will not use it for a materially different purpose without first obtaining your separate, affirmative consent.
5. Consent, and how to withdraw it
We collect consumer health data only after your separate, affirmative, opt-in consent, obtained apart from any general terms acceptance, and recorded with its version and timestamp. Optional cloud AI processing requires its own separate consent.
You may withdraw consent at any timein the app’s privacy settings, or by contacting [privacy@ email]. Withdrawal stops the associated processing going forward; the app then degrades conservatively to on-device processing. Withdrawal does not affect processing already carried out.
6. We do not sell consumer health data
We do not sell consumer health data and will not sell it. A “sale” under these laws includes exchange for anything of value. Because we do not sell it, we do not seek the separate valid authorization the law would require. If this ever changes, we will obtain that authorization first and update this policy.
7. No geofencing
We do not use a geofence around any facility, including any health care facility, to identify or track consumers seeking health services, to collect consumer health data, or to send notifications, messages, or advertising related to consumer health data. MHMDA specifically prohibits this.
8. With whom we share consumer health data
We share only the sanitized, de-identified derived text, and only with the processors below, each acting on our instructions under contract, none of whom is permitted to use it for their own purposes:
| Recipient | Category of data shared | Purpose |
|---|---|---|
| Anthropic, PBC | Sanitized, de-identified text | AI reasoning to generate your reflections |
| Voyage AI | Sanitized, de-identified text | Embeddings for pattern matching |
| ElevenLabs | Blame-neutral output lines only (never crisis or safety-held content) | Optional voice synthesis |
| Supabase | Ciphertext we cannot read, and content-free metadata | Hosting and authentication |
We do not share consumer health data with data brokers, advertisers, analytics providers, or affiliates for their own use. We may disclose information where required by law or to protect against a serious threat to health or safety, as described in the Privacy Policy.
9. Your rights
You have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data;
- Access it, including a list of all third parties and affiliates with whom we have shared it;
- Withdraw consent to collection and sharing;
- Delete it; and
- Not be discriminated against for exercising these rights.
How to exercise: use the in-app controls in Settings, visit replaycouples.com/delete-account, or contact [privacy@ email].
Verification: we verify by confirming control of the account email; we will not require more information than necessary.
Timing: we respond within 45 days of receipt, extendable once by 45 days where reasonably necessary, with notice to you.
Deletion: on a deletion request we delete the data from our records and our backups on our deletion schedule, and we notify all processors and any affiliates holding it to delete it as well, consistent with their contractual zero-retention obligations. Because content is end-to-end encrypted, we cannot selectively read or extract individual statements within an entry; we delete entries and accounts in full. ATTORNEY: confirm this satisfies MHMDA’s deletion-and-notification requirements, including as to backups and processors.
Appeals: if we deny your request, we will tell you why and how to appeal. Write to [appeals contact] within [60] days; we will respond in writing within 45 days. If we deny your appeal, you may submit a complaint to the Washington Attorney General at [link], the Nevada Attorney General, or the Connecticut Attorney General, as applicable.
10. Employees and contractors with access
Access to systems holding consumer health data is restricted to the personnel and contractors for whom it is necessary to provide the Service, under confidentiality obligations and least-privilege access controls. Because entry content is end-to-end encrypted, no employee or contractor can read it.
11. Retention
We retain consumer health data only as long as necessary for the purposes in §4, or as required by law, and we honor deletion requests as described in §9. Content-free safety-signal metadata is retained until account deletion because the safety features consult prior signals.
12. Security
See the Privacy Policy. In summary: end-to-end encryption, hardware-backed keys, encryption in transit and at rest, row-level access controls, least-privilege access, and a written incident-response runbook.
13. Changes
We will not make a material change reducing your protections without your affirmative consent. Changes are versioned, and the app re-obtains consent when legal wording changes.
14. Contact
[consumer health data contact], [privacy@ email], Automate AI LLC, [address].
Attorney checklist for this document
- Confirm the state list in §1 and whether additional states’ consumer-health provisions apply at launch.
- Confirm §2 category descriptions satisfy MHMDA’s specificity requirement for categories collected, sources, and purposes.
- Confirm §8’s recipient list satisfies MHMDA’s requirement to name affiliates and third parties, and whether naming categories rather than entities is sufficient or whether specific naming is required.
- Confirm §9’s deletion mechanics, including backups, processor notification, and the E2EE limitation.
- Confirm the appeal contacts and the complaint-submission links.
- Confirm the homepage-link placement satisfies MHMDA.
- Confirm whether MHMDA’s private right of action (via the Washington Consumer Protection Act) creates exposure requiring any additional disclosure or operational change.