MyHealth — Washington Consumer Health Data Privacy Policy
Required by the Washington My Health My Data Act (MHMDA), RCW chapter 19.373 (RCW 19.373.020 / .030 / .040).
Version (policy_version): 2.8 · Effective: 2026-07-14
This is a standalone Consumer Health Data Privacy Policy. It supplements, and is read together with, our general Privacy Policy and our Subprocessors page. Where this policy and the general Privacy Policy differ for consumer health data covered by the MHMDA, this policy controls for that data.
1. Who this policy is for
This policy applies to "consumer health data" as defined by the Washington My Health My Data Act when it relates to a "consumer" under that Act — that is, a natural person who is a Washington State resident, or a natural person whose consumer health data is collected in Washington — and who is acting in an individual or household capacity (not in an employment context).
Under the MHMDA, consumer health data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status — including health conditions, diagnoses, treatments, medications, vaccinations, bodily functions, vital signs, symptoms, diagnostic testing, reproductive or sexual health information, and any data that identifies a consumer seeking health care services.
Important position. Because MyHealth is a health application, we treat the fact that a person has a MyHealth account — and the identifiers tied to it (name, email, and the account number we assign) — as consumer health data when that person is a Washington consumer. This affects how we handle deletion (see Section 8).
This policy does not change rights you may have under our general Privacy Policy or under other laws.
2. Who we are
The entity responsible for the MyHealth app is:
BAS ARTIFICIAL INTELLIGENCE LTDA ("BAS AI", "MyHealth", "we", "us")
Tax ID (CNPJ): 64.106.409/0001-70
Address: Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil
Website: www.bas-ai.com
Data Protection Officer (Encarregado): Guilherme Bastian.
Privacy contact for consumer health data requests: dpo@bas-ai.com
3. The categories of consumer health data we collect
We collect consumer health data only that you provide or authorize — there is no background or passive collection of health data. Depending on how you use MyHealth, the categories may include:
- Health conditions, diagnoses, and health problems you record or that the AI extracts from documents you upload (and that you confirm before saving).
- Lab and exam results (markers, values, units, reference ranges, trends over time).
- Medications (name, active ingredients, dose, schedule) and vaccinations (vaccine, disease, dose).
- Allergies (allergen and class).
- Measurements and vital signs, including body composition / bioimpedance.
- Symptoms, appointments, procedures/surgeries, and clinical notes you record.
- Family medical history you record.
- Reproductive and menstrual data you record or import — menstrual flow, intermenstrual bleeding, ovulation tests, cervical mucus quality, pregnancy tests, and, if you are female and 40 or older, a self-declared menopause phase (with the option not to answer). We do not import sexual activity records.
- Sleep, daily wearable scores, and device events (e.g., ECG classification, irregular rhythm, fall) imported only from connected sources you authorize (Apple Health, Oura, WHOOP).
- Lifestyle habits you declare (smoking and years of use, alcohol, physical activity, sleep).
- Non-sensitive daily contexts you record when asked, occasionally and optionally: coffee/caffeine, energy levels, hydration, how your workout felt (light/normal/hard), and routine changes during the week (e.g., travel, a new workout, changes in diet or sleep). When your AI-processing and international-transfer consents are active, these are shared with our AI provider only in weekly aggregated form — day counts and the routine-change category, never the individual daily entry, never free text (see Section 6).
- Daily self-observed entries you record, when enabled: alcohol consumption (substance use) and stress / night context (mental health) — dated daily entries. Opt-in, off by default, not available on minors' profiles. Your mood check-in remains part of the existing well-being feature.
- Progress reports and follow-up decisions you record — your own reports about the evolution of a tracked item (for example, the outcome of a verbal assessment by a professional), including the report text, your keep/close decision, the date, and the version of the text you confirmed, kept in an immutable trail. These are always stored and displayed as your report (never as a documented clinical fact), the app does not verify or endorse the reported course of care, and only you can close follow-up of an item, always with express confirmation; professionals' names are optional in the report. On minors' profiles, the legal guardian records in representation, identified in the entry.
- Emergency card information (blood type, allergies, and notes).
- Documents and images you upload (photos, PDFs of exams and records) and the structured data the AI extracts from them.
- Messages you send to our in-app support channel (support tickets you write to us), to the extent you include health information in them.
- AI-generated educational outputs about your record (e.g., conditions, alerts, insights) — produced as supportive, non-diagnostic information with a human in the loop and no significant effect on access to care, credit, or insurance.
- The identifiers linked to your account (name, email, and the account number we assign — a random, non-sequential 8-digit number we generate for each profile and display in-app, used to locate your account for support; generated by us, not collected from you) — which, because this is a health app, we treat as consumer health data for Washington consumers (see Section 1).
We do not collect precise geolocation, your phone contacts, or microphone data. We do not use third-party trackers or analytics SDKs that see health data.
4. How we collect consumer health data
- Directly from you, when you type, record, or import data into the app.
- From documents and photos you choose to upload, from which our AI extracts structured records that you confirm before they are saved. The camera and photo gallery are accessed only at the moment you decide to upload (just-in-time permission).
- From sources you connect, with your authorization — Apple Health (HealthKit), Oura, and WHOOP — which act as independent sources you control, not as our vendors.
We collect consumer health data only with your consent for a specified purpose, or as strictly necessary to provide the product or service you have requested (RCW 19.373.030). Our system only performs a given operation when the matching consent is active; this is enforced automatically on our server on every operation. You can turn a purpose off at any time.
Consent for the sensitive health journal — separate collection authorization. The daily alcohol/stress journal is consumer health data and is not necessary to provide the core product, so we obtain your separate, specific consent BEFORE collecting it (purpose daily_journal), presented separately from our Terms and from the general clinical consent, off by default, and revocable at any time. Our server refuses to write this data unless the consent is active. This section does not apply to minors' profiles, where the sensitive journal is unavailable.
These sensitive-journal entries (alcohol, stress/night context) are not shared with our AI provider. This differs from the non-sensitive daily contexts (coffee/caffeine, energy levels, hydration, workout perception, routine changes), which — under your active AI-processing and international-transfer consents — are shared with our AI provider only in weekly aggregated form (day counts and the routine-change category, never the individual daily entry, never free text). We do not sell consumer health data and do not seek a "valid authorization" to sell.
You may access/confirm, delete, and withdraw consent at any time (RCW 19.373.040). Withdrawing consent stops collection and deletes these entries.
5. Why we collect it (purposes) and how it is used
We use consumer health data to:
- Organize and structure your health record — extracting values from documents, building your timeline and trends, and classifying records.
- Provide AI-assisted, educational analysis of your record (supportive reading, alerts, insights) — assistant only, never a medical device, never a diagnosis or prescription, with a human (you) in the loop and no significant decision made about you. The AI does not check drug interactions or contraindications and does not cross-reference your allergies against your medications.
- Power the in-app assistant (chat), which can read your record and, at your request, propose draft records for you to review and save (the AI never saves on its own).
- Answer and resolve your support requests — we store and read the messages you send to in-app support. When helpful, a support operator may use an AI-assisted draft reply (human-in-the-loop): its inputs are the support conversation plus non-clinical account context — never your clinical record — and a human reviews the draft before you receive it. This runs only while your AI-processing and international-transfer consents are active.
- Send you the notices you turn on (e.g., when an analysis is ready) — notice content is generic and contains no health data.
- Send you an opt-in "novelty" notice when your connected wearable or health data produces a new finding (for example, after your wearable indicates poorer sleep, an elevated resting heart rate, or a drop in heart-rate variability) — because deciding to send this notice is derived from consumer health data, it is off by default and requires your separate consent (RCW 19.373.030); the notice content is generic and contains no consumer health data, and no consumer health data is shared to deliver it — Apple's push service (APNs) receives only a delivery token and fixed generic text ("something new is in your data"), never the finding itself.
- Operate billing and prevent abuse — using only metadata of AI usage (function and token count) and usage/quota balance, never the analyzed health content.
- Keep the service secure and working — security, integrity, fraud prevention, and stability diagnostics that contain no health content.
We do not use consumer health data for targeted advertising, and we do not use it to train AI models.
6. The categories of sources from which we collect consumer health data
- The consumer (you) — directly entered, recorded, or uploaded data.
- Documents and images you upload to the app.
- Health and wearable sources you connect and authorize — Apple Health (HealthKit), Oura, and WHOOP.
7. Sharing: categories of consumer health data shared, and with whom
We do not sell consumer health data, and we do not seek any "valid authorization" to sell it (RCW 19.373.070 / .110). We do not share consumer health data for advertising, marketing, or behavioral targeting.
We share consumer health data only with a minimal set of processors ("vendors"), each under a binding data processing agreement that limits them to processing data on our documented instructions (RCW 19.373.060), and only as necessary to provide the service you requested or as you separately consent. We do not have corporate affiliates that receive your consumer health data.
| Processor (third party) | Role / purpose | Categories of consumer health data shared | Location | Key safeguards |
|---|---|---|---|---|
| Supabase (Supabase, Inc.) | Database, authentication, document storage, and server functions that run the app | Pseudonymized clinical data; account identifiers (name, contact email, phone, national document) held encrypted in a separate vault; uploaded documents; account metadata | São Paulo, Brazil (sa-east-1) | DPA in effect (signed 2026-06-18, includes EU Standard Contractual Clauses and safeguards); encryption in transit and at rest; additional authenticated field-level encryption (AES-256 via pgsodium) of vaulted identifiers; row-level isolation; daily backups (14-day retention) |
| Anthropic, PBC (Claude API) | AI analysis of your record, extraction of data from documents, the chat assistant, and — on a support operator's request — drafting a human-reviewed suggested reply to your support message | Pseudonymized clinical content (values, dates, notes, lifestyle habits, cycle, wearable aggregates, and non-sensitive daily contexts in weekly aggregated form — day counts and routine-change categories, never the individual daily entry) plus your sex, age, country, and year of birth (without day/month) — no direct identifiers and no emergency contacts. For document analysis, the redacted copy of the uploaded image/PDF, handled transiently. And, only when a support operator requests an AI-assisted draft, the content of your support thread (which may include health information you typed), sent as written — not redacted — and only if your AI/international-transfer consent is active | United States (international transfer under SCC) | Commercial Terms + Standard Contractual Clauses in effect (2026-06-17); contractual non-training (your data is not used to train or improve models); limited retention (as a rule ~30 days, then deleted); TLS |
| Resend | Sending transactional emails (one-time access codes and account notices) | No health content — only your email address and the email's text | US / global | DPA in effect (2026-06-17); EU-US Data Privacy Framework + SCC; TLS |
On redaction before AI processing. Before clinical content is sent to Anthropic, we replace your direct identifiers with sex, age, country, and year of birth (without day/month), used only to regionalize educational guidance. For uploaded documents, the app attempts an on-device, best-effort redaction (covering) of four of your identifiers — name, national document (CPF), email, and phone — and the redacted copy is the one sent; the original file stays intact in your record. This redaction is best-effort and is not de-identification: it is directed only at your own four identifiers, and when the redaction process runs but finds nothing to cover (for example, because your identity vault is empty), the original may proceed to the AI. We do not represent that identifiers are guaranteed to be removed.
Support messages are an exception to redaction. The best-effort redaction described above applies to documents you upload. It does not apply to the free-text messages you send to in-app support: when a support operator requests an AI-assisted draft, your support thread is sent to Anthropic as written (un-redacted) — it may therefore include health information you chose to type — solely so a human-reviewed suggested reply can be drafted. This happens only while your AI-processing and international-transfer consents are active, under the same processor terms, Standard Contractual Clauses, and limited (~30-day) retention shown above; no new processor is involved, and your clinical record is never sent for this purpose.
Apple processes your subscription and in-app purchases as merchant of record; no health content is in the payment flow. Apple Health, Oura, and WHOOP are sources you connect, not recipients — they do not receive data from your health record.
7.1 Sharing you direct between consumers: hereditary conditions with linked family members
MyHealth offers two consumer-directed sharing features, in which the recipient is a family member you choose (who must also be a user of the app) — not a vendor, affiliate, or advertiser:
- Read-only family link: you may invite a family member to view your record (read-only, all-or-nothing, single-use code, revocable at any time), under your specific consent.
- Hereditary-condition sharing (item by item): you may enable, item by item, tracked health conditions (a condition, its year of onset, and status — never exams, documents, values, medications, free text, or routine; this minimization is enforced in code by the database) to be offered to your linked family members, who may incorporate them into their own family history only by express, item-by-item acceptance.
For the hereditary-condition feature we obtain, before any sharing occurs, a valid authorization consistent with RCW 19.373.070: the authorization screen names the specific consumer health data shared (the named condition, year of onset, and status), the purpose (the recipient's family history), the recipient (your linked family members), and states that the authorization is revocable at any time, in one tap, free of charge and without justification — revocation immediately withdraws the offer from all linked family members. We keep a record of the authorization (who, when, and the version of the text displayed).
Permanence notice (shown at the moment you enable each item): an item a family member has already accepted becomes part of their family history, as their own record — deactivation does not delete it from their record; only they can remove it, and they may do so at any time. If you request deletion of your data or delete your account, we remove from the recipient's record every reference to your identity and account, keeping only the degree of kinship, condition, and period, which is consumer health data of the recipient themselves. Minors' profiles do not participate as a source by their own decision.
7.2 Data manager you authorize (consumer-directed delegation by an adult)
You may authorize another adult you choose (the "Manager" — who must also be a user of the app) to view your full health record and to register, edit, and upload documents on your behalf. This is consumer-directed sharing — the Manager is not a vendor, affiliate, or advertiser, and declares to act under your authorization, in your interest, in a personal, family, non-commercial context.
Before any access is granted we obtain the separate, distinct consent required by RCW 19.373.030(2), on your device, after reinforced identity confirmation: the consent screen names who the Manager is, the specific consumer health data covered (your full record), what the Manager can do (view; register, edit, and upload documents) and what the Manager can never do (change your consents, delete your account, manage sharing/links, change your credentials, make purchases, or bulk-export your record — the block on consents, account deletion, links, and credentials is enforced technically server-side; the block on purchases and bulk export is enforced technically in the app), and states that the authorization is revocable at any time, in one tap, free of charge and without justification, with immediate effect — revocation immediately ends the management powers; the read-only link remains until you also remove it (both options are shown side by side in the app). We keep a record of the consent (who, when, and the version of the text displayed), an immutable authorship trail of everything the Manager records (shown to you), and show you an in-app activity summary the Manager cannot turn off. What the Manager records is your consumer health data and remains in your record after revocation, under your rights (access, deletion, withdrawal of consent). Minors' profiles cannot appoint a Manager.
8. Your rights as a Washington consumer (RCW 19.373.040)
If you are a Washington consumer, you have the right to:
- Confirm and access — to confirm whether we are collecting, sharing, or selling your consumer health data, and to access that data, including a list of all third parties and affiliates with whom we have shared it and a way to contact them. (We do not sell your data and have no affiliates that receive it; the third parties are the processors listed in Section 7.)
- Delete — to have your consumer health data deleted. When we receive and authenticate a deletion request, we delete your consumer health data from our active systems. Because our processors only hold your data within our own database and storage (Supabase), or transiently before automatic deletion (Anthropic, as a rule ~30 days), or with no health content at all (Resend), removing it from our systems removes it at the processor as well. Residual copies present in routine backups roll off within the backup retention window and are not restored to active use.
- Withdraw consent — to withdraw your consent to the collection and sharing of your consumer health data at any time. You can turn off a processing purpose (for example, "AI Processing") directly in the app; after withdrawal we stop the corresponding processing.
How deletion works in MyHealth. You can delete your account directly in the app, in Profile › Privacy › Delete my account. On confirmation we permanently remove, in cascade, your encrypted identity vault and all clinical data (exams, conditions, medications, vaccines, documents, measurements, history, appointments, AI conversations, sleep, wearable scores, device events, lifestyle habits, medication-intake and check-in logs), your uploaded files, your wearable connection data, and your AI usage/quota metadata — including the data of any dependents you manage — and we close your account. Where you manage a minor, deletion offers you the option to transfer guardianship of that minor to an existing co-guardian (so the minor's record survives with them) instead of deleting it.
For Washington consumers, we treat the identifiers tied to your health account (name, email, and the account number we assign) as consumer health data and delete them on your request. The only data that may be retained is a minimal tax/accounting record for a consumer who actually completed a purchase, kept encrypted and dissociated from the health-account context and held solely to meet a legal accounting obligation — this is not your consumer health data and is never used to infer your health status. Consumers who never transacted, and minors, have their identity deleted with the rest of the record.
What remains after deletion is limited to: (a) a de-linked, pseudonymized record of consent events (cryptographically dissociated from your identity), kept only to evidence that consent was given and withdrawn; and (b) security/access logs kept for a short period (up to six months) that record metadata of access (time, action, source IP) and never the clinical content — used only for security and fraud detection, never to infer your health status.
9. How to exercise your rights, and how to appeal
To make a request (confirm/access, delete, or withdraw consent), use either:
- In the app — most actions are self-service: review and export your record, delete your account, and turn purposes on or off in Profile › Privacy and Profile › Consents.
- By email — write to dpo@bas-ai.com with the subject "Washington MHMDA request" and tell us which right you wish to exercise.
We take prompt steps to authenticate your request (to protect your data we may ask you to verify your identity or your control of the account). We respond within 45 days of receiving the request; if reasonably necessary, we may extend once by an additional 45 days and will tell you why within the first 45 days.
Authorized agents. You may use an authorized agent to make a request on your behalf; we may require proof of the agent's authority and verification of your identity.
Appeals. If we decline to act on your request, we will tell you why. You may appeal by replying to our decision or writing to dpo@bas-ai.com with the subject "Washington MHMDA appeal." We will respond to the appeal within a reasonable time and explain our decision. If your appeal is denied, you may contact the Washington State Office of the Attorney General (https://www.atg.wa.gov/file-complaint).
10. No sale; no targeted advertising
We do not sell consumer health data and do not seek valid authorization to sell it. We do not use consumer health data for targeted advertising, profiling for advertising, or sharing with data brokers. If this ever changes, we will update this policy and obtain any consent or authorization the law requires before doing so.
11. Geofencing
We do not use geofences around health care facilities, and we do not use precise location to identify or track consumers seeking health services (RCW 19.373.090).
12. Security
We protect consumer health data with encryption in transit and at rest, authenticated field-level encryption (AES-256 via pgsodium) of the identifiers held in a separate vault, strict row-level isolation between accounts, server-side enforcement of consent on every operation, and access controls with security/access logging. No method of transmission or storage is perfectly secure, but we maintain technical and organizational measures appropriate to the sensitivity of health data.
13. Changes to this policy
We will not collect, use, or share categories of consumer health data, or use it for purposes, not described here without first updating this policy and, where required, obtaining your affirmative consent. Material changes will be posted here with a new version and effective date. A link to this policy is published prominently on our homepage.
Changelog:
- 2026-07-13 (v2.5): Disclosed the non-sensitive daily contexts (coffee/caffeine, energy levels, hydration, workout perception, and routine changes) as a category of consumer health data (Section 3) and their sharing with our AI provider only in weekly aggregated form — day counts and routine-change categories, never the individual daily entry, never free text — under your active AI-processing and international-transfer consents (Sections 4 and 6). The sensitive daily journal (alcohol, stress/night context) remains not shared with the AI provider. Triggers in-app re-consent of the updated policy. No new processor (Supabase, Anthropic, Resend unchanged).
- 2026-07-07 (v2.5): Added an opt-in "novelty" notification to our purposes (Section 5): when your connected wearable or health data produces a new finding (currently poorer sleep, elevated resting heart rate, or reduced heart-rate variability), we may send you a notice that something new is in your data. Because deciding to send it is derived from consumer health data, it is off by default and requires your separate consent (RCW 19.373.030); the notice content is generic with no consumer health data, and no consumer health data is shared to send it — Apple's push service (APNs) receives only a delivery token and fixed generic text, never the finding. No new processor (Supabase, Anthropic, Resend unchanged; Apple/APNs already the push transport).
- 2026-07-05 (v2.4): Added the sensitive daily health journal — opt-in daily entries of alcohol consumption (substance use) and stress / night context (mental health) — to the categories of consumer health data (Section 3), and a separate collection authorization for it (Section 4): the journal is off by default, requires your separate, specific consent before collection (purpose
daily_journal), is server-enforced, is not available on minors' profiles, and is not shared with our AI provider; withdrawing consent stops collection and deletes these entries. No new processor (Supabase, Anthropic, Resend unchanged). - 2026-07-05 (v2.3): Added in-app support messages (to the extent you include health information) and the account number we assign to the categories of consumer health data treated as CHD; added answering and resolving support requests to our purposes (store and read; an operator may use a human-reviewed AI-assisted draft whose inputs are the support conversation plus non-clinical account context, never your clinical record); disclosed that, only with your active AI/international-transfer consent, support-thread content may be shared with Anthropic un-redacted for that drafting, under existing processor terms/SCC and ~30-day retention; noted that support messages are an exception to document redaction. No new processor (Supabase, Anthropic, Resend unchanged).
14. Contact
- Privacy contact (DPO/Encarregado): dpo@bas-ai.com
- Entity: BAS ARTIFICIAL INTELLIGENCE LTDA — www.bas-ai.com — Rua Gomes de Carvalho, 911, Vila Olímpia, São Paulo/SP, ZIP 04547-003, Brazil
- General Privacy Policy: https://www.bas-ai.com/myhealth/legal/privacidade
- Subprocessors page: https://www.bas-ai.com/myhealth/legal/subprocessadores
- Washington Attorney General (complaints): https://www.atg.wa.gov/file-complaint