Healthya Privacy Policy
At a glance. Healthya is an AI companion app supporting older adults with daily health and conversation. This policy explains what we collect, with whom we share it, and how you can exercise your rights. We do not sell or share your personal information for advertising.
1. Who we are
Healthya is a service operated by Deeper Emptiness AI ("we", "us"), which acts as the business/Controller of the personal information described in this policy.
Contact: hello@healthia.app
2. Information we collect
We collect the following categories (CCPA §1798.140(v)):
| Category | Examples |
|---|---|
| Identifiers | Phone number, email address, sign-in provider identifiers (Sign in with Apple / Google), account (user) ID, device IDs, push tokens |
| Personal information (Cal. Civ. Code §1798.80) | Display name, birth year, gender (optional, only if you choose to provide it) |
| Internet / electronic activity | App usage logs, feature timestamps, crash / performance reports |
| Geolocation — approximate (optional) | City / district level, used for local personalization (e.g., weather-based conversation) and to find nearby care facilities such as hospitals and pharmacies (rounded to roughly 1 km before being sent to our maps provider — see section 5). We do not store precise coordinates for these purposes. Optionally, a generalized "activity area" (last 7 days, rounded to roughly 1–2 km blocks) may be shared with your linked family. |
| Geolocation — precise (optional, emergency only) | Your precise location captured once, at the moment you place a 911 call, and shared with your linked family so they can help. See section 7. |
| Audio / visual (optional) | Microphone signal (real-time only, not stored); meal, medication / prescription, and symptom photos you choose to upload (symptom photos are deleted right after analysis) |
| Health & fitness from connected health apps (optional) | Read-only measurements imported from Apple Health or Google Health Connect: sleep and sleep stages, steps, distance, active energy, and workout sessions; vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate); blood sugar and weight; fitness and gait (VO2 max, heart rate variability, walking steadiness / speed); and mental wellness (mindfulness sessions and mood). See section 8. |
| Health activity records | Meal logs (time, type, optional photo / nutrition analysis), exercise (duration, type), medication (name, dose, schedule, intake), hydration (intake events), sleep (start / end times) |
| Self-reported health | Symptoms, mood, emotion notes |
| Religious / faith affiliation (optional, sensitive) | Collected only if you volunteer it in conversation, used for occasional faith-friendly greetings. We never infer it without your statement and never share it with family. See section 10. |
| AI memory | Distilled one-line "moments" from conversation, encrypted verbatim quotes, and semantic embeddings used so the assistant can remember your context |
| Inferences | Personality, interests, and mood inferred from conversation |
3. Sources
- Information you provide (signup, consent, conversation, photo upload)
- Device-generated information (device IDs, push tokens)
- Sign-in providers you choose to use (Apple, Google) — they return a verified identity token and your name
- Connected health apps (Apple Health / Google Health Connect), only with your permission
- Information your linked family provides via the family app
- Outputs from third-party services (e.g., Vertex AI responses)
4. Purposes of use
- AI companion conversation and memory of your context
- Text-to-speech for natural voice responses
- Daily plans, meal / medication / hydration reminders, and lifestyle support
- Daily summaries combining your activity with optional health-app measurements
- Emergency support — first-aid reference, one-tap 911 dialing, and optional family alerts (see section 7)
- Care navigation (optional) — helping you find nearby hospitals / pharmacies and showing general symptom guidance (informational only, not a diagnosis)
- Local personalization (approximate location for weather-based conversation)
- Family support (optional) — short summaries to enable family caregiving
- Account management, including phone-number recovery you pre-authorize for a linked family member
- Legal compliance, fraud prevention, and security auditing
5. Service providers
We share information only with the following providers under confidentiality and purpose-limited agreements. None of them receive your data for advertising, and we do not share with data brokers.
| Recipient | Data sent | Purpose |
|---|---|---|
| Google Vertex AI (Gemini) | Display name, birth year, recent conversation, learned facts, meal / medication photos | Conversation understanding, daily summaries, and meal / medication analysis. Enterprise terms — not used for model training. |
| Google Vertex AI Live | Voice PCM (streaming) | Real-time voice conversation. No recordings retained. |
| Google Cloud Vision | Meal and medication / prescription photos | Text recognition and image analysis to read labels and food. |
| Google Vertex AI (text embeddings) | Short conversation snippets | Semantic search so the assistant can recall relevant context. |
| Google Cloud Text-to-Speech | Response text | Voice synthesis. Your voice is not sent. |
| Google Places (Google Maps Platform) | Approximate location (rounded to ~1 km) and a care category (hospital / pharmacy) | Finding nearby care facilities. No personal identifier is sent; not used for advertising. |
| Google Search (via Vertex AI grounding) | Your web-lookup question text; generic region-scoped news queries | Real-time factual lookup during conversation and the daily news brief. Not used for advertising. |
| OpenWeather | Approximate (city / district level) location | Weather information used to start friendly conversation. Precise coordinates are not sent. |
| USDA FoodData Central | Food names only (no personal identifiers) | Nutrition reference lookup for meals. |
| U.S. government health services — RxNorm / RxNav, openFDA, MedlinePlus, DailyMed (NLM / FDA), CMS Care Compare | Medication names, or a hospital's ZIP / name for ratings (no personal identifiers) | Standardizing medication information, drug labels / images, health-topic summaries, and hospital quality data. Public services. |
| Twilio (Verify) | Phone number, one-time verification code | SMS verification for sign-in and account / phone-number recovery. |
| Resend | Email address and request details | Sending account and rights-request notification emails. |
| Expo Push (relaying to Apple APNs / Google FCM) | Push tokens, notification payloads | Notification delivery. |
| Supabase (infrastructure) | A subset of the above for storage | Service operation, with row-level security isolating your data. |
TTS audio cache. We cache synthesized audio responses keyed by a hash of the response text (no user identifier). The cache is shared across users — your individual identity is never associated with cached audio. Withdrawing TTS consent stops future synthesis requests; cache eviction is governed by our standard retention policy rather than per-user deletion.
Video calling. Video calling is not offered in the current version of the app. We do not route any video or audio to a video-calling provider.
6. Sharing with linked family
When you link a family member through the Healthya Family app, certain information may be visible to that family member in their app. Family sharing is opt-in and is gated by your consent settings in Settings → Data Use Consent.
6.1 What family always sees (regardless of consent)
- Your display name and the fact that you are linked to them
- Connection activity (link request, acceptance, removal)
6.2 What family sees when health-sharing consent is ON
The Share health activities with family consent grants the linked family read-only access to:
- Meals — time, type (breakfast / lunch / dinner / snack), photo (if you uploaded), AI nutrition analysis (food name, calories, caution notes), suggested next meal
- Exercise — type and duration (minutes)
- Medication — registered medications (name, dose, schedule), intake events, photos of pill bottles / prescriptions you uploaded
- Hydration — water intake events
- Sleep — sleep start / end timestamps and sleep stages (including measurements imported from a connected health app, if enabled)
- Device health metrics (if you connected a health app) — steps, distance, active energy, vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate), blood sugar / weight, and fitness / gait measurements imported from Apple Health or Google Health Connect
- Recent activity timestamp — when you were last active in the app
Mental-wellness data (mindfulness minutes and self-logged mood imported from a connected health app) is never shared with family — it is redacted server-side even when health-sharing consent is on. Free-form conversation content, AI memory, learned preferences, voice signals, and consent history are also never shared with family.
6.3 Optional location sharing with family
- Activity area — if you enable Share activity area with family, your linked family can see a generalized activity area from the last 7 days (rounded to roughly 1–2 km blocks; never an exact point or a live trail). Older data is automatically deleted on a rolling 7-day window.
- Emergency location — handled separately under section 7.
6.4 What family sees when consent is OFF or withdrawn
If you decline a sharing consent — or withdraw it at any time — the family app will display a clear notice that you have not granted access, and the related categories will be hidden from family view (server-side enforcement via row-level security, not just client filtering). Withdrawal takes effect on the next family-app data refresh.
6.5 Withdrawal and re-consent
- You can toggle each sharing consent at any time in Settings → Data Use Consent.
- The change is logged in your consent history (Settings → My information rights → Consent history) as immutable evidence (CCPA Right to Know).
- Unlinking a family member also removes their visibility regardless of the consent state.
6.6 Family member's obligations
The linked family member agrees, in the family app's consent flow, to treat the disclosed information as confidential, not screen-capture or share externally, and to use it only for caregiving purposes.
7. Emergency location sharing (911)
This is the one case where we use your precise location. Healthya is not an emergency response service and cannot guarantee that help will arrive; it provides first-aid reference, one-tap 911 dialing (you place the call yourself), and optional alerts to your linked family.
- Consent. Precise emergency location sharing is governed by the optional Share location with family in emergencies consent. It is off until you turn it on (we strongly recommend keeping it on).
- When. Only at the moment you place a 911 call from the app. We capture your location once (using a recent fix or a single fresh fix). We do not track you continuously.
- What we share. The push notification to your family contains your name only — never coordinates. The precise coordinates are stored on our server and shown to your linked family only after they open the alert, retrieved under row-level security.
- If consent is off or location permission is unavailable, the alert is still sent without any location.
- What we keep. We keep only the single most recent emergency record per person — a new 911 call overwrites the previous one. It is automatically deleted 7 days after the call, and also deleted immediately if you withdraw this consent or delete your account.
8. Connected health apps (Apple Health / Google Health Connect)
If you enable Connect health app (optional), Healthya reads the following from Apple Health (iOS) or Google Health Connect (Android), with your separate OS-level permission:
- Sleep start / end times, total sleep minutes, and sleep stages (deep / REM), where available
- Steps, walking / running distance, and floors climbed
- Active energy (calories)
- Workout sessions (type, start time, duration)
- Vital signs — heart rate, resting heart rate, blood pressure, oxygen saturation, body temperature, respiratory rate
- Blood sugar (glucose) and body weight
- Fitness and gait — VO2 max, heart rate variability, walking steadiness, walking speed, six-minute walk distance (some are iOS-only, imported where available)
- Mental wellness — mindfulness session minutes and self-logged mood (Apple Health State of Mind). This category is used only in your own app and is never shared with family (see section 6.2)
Read-only. Healthya only reads this data; it never writes back to your health app. We use it solely to make your in-app daily summary reflect your real measurements.
Apple / Google requirement. Data obtained from Apple Health or Google Health Connect is never used for advertising or marketing, is never sold, and is never shared with data brokers. It is stored under your account with row-level security. You can turn the connection off at any time in Settings; on withdrawal, the imported health metrics are deleted (within 30 days).
9. Do Not Sell or Share notice
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. No opt-out is required because the protection applies automatically. (CCPA §1798.120 / CPRA)
10. Sensitive Personal Information
SPI under CPRA includes health information, audio signals, precise geolocation, and religious or philosophical beliefs. We collect precise geolocation only for emergency 911 family sharing (section 7), with your opt-in, and never for advertising. We collect faith affiliation only if you volunteer it in conversation, solely for occasional faith-friendly greetings — never inferred, never shared with family, and removable anytime in Settings → What the AI has learned. We do not use SPI beyond service delivery and the purposes you have explicitly consented to. You may restrict SPI use via the in-app Consent history screen. (CPRA §1798.121 — Right to Limit Use of SPI)
11. Retention
- Active retention while your account is in use. After 24 months of inactivity we will notify and deactivate.
- Account deletion request: all data removed within 30 days (consent ledger preserved as legal evidence for statutory periods).
- Consent withdrawal: related data removed within 30 days (WA MHMDA).
- Activity-area location: auto-deleted on a rolling 7-day window; removed immediately if you withdraw the consent.
- Emergency alert records: see section 7.
- Legal hold periods take precedence where applicable.
12. Your rights
Depending on your residency, you have the rights below. We grant the same rights to all users regardless of location.
12.1 Rights granted to all users
- Right to Know. Request a copy of the information we hold about you.
- Right to Delete. Request deletion of your information.
- Right to Correct. Request correction of inaccurate information.
- Right to Portability. Receive your information in a machine-readable format (JSON / CSV).
- Right to Limit SPI. Restrict use of health / voice / location data.
- Opt-out of Sale / Share. We do not sell or share — applies automatically.
- Opt-out of Automated Decision-Making. Request exclusion from AI-based profiling (CPRA Reg 2025).
- Non-discrimination. No penalty for exercising your rights.
- Right to Appeal. Appeal denied requests within 60 days (VCDPA / CPA / CTDPA).
- Authorized Agent. A trusted family member may submit requests on your behalf (CCPA §1798.135).
12.2 How to exercise
- In-app — Settings → My information rights:
- Right to Know — generates a downloadable ZIP (JSON + CSV) of your data within minutes. Request it via the download link at the end of this policy (in the app) or by email. Once per 30 days. Photos you uploaded (meal, medication, and symptom images) are not included in the automatic export but are available on request by email.
- Right to Correct — review and edit "What the AI has learned about you".
- Right to Delete — account deletion screen.
- Right to Limit SPI / Withdraw Consent — per-item withdrawal in the Consent history screen.
- Email: hello@healthia.app (subject line: [Rights Request]).
- Processing time: in-app actions are typically completed immediately. Email-based requests are resolved within 45 days of receipt (one 45-day extension where permitted). WA MHMDA-driven consent deletions: 30 days.
13. Consumer Health Data (WA MHMDA · NV SB370 · CT)
This section is the Consumer Health Data Privacy Policy required by Washington's My Health My Data Act and analogous laws. "Consumer Health Data" includes information related to physical or mental health status, medications, diagnoses, treatments, precise location, and inferences thereof.
13.1 Categories collected
- Meal, medication, hydration, sleep, and exercise records and photos
- Sleep, steps, activity, vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate), blood sugar, weight, fitness / gait, and mental-wellness measurements (mindfulness, mood) imported from a connected health app (optional)
- Inferred physical / emotional state from conversation
- Symptoms you report and the general symptom guidance / recommended care setting shown to you
- Pill bottle, prescription, and symptom photos (if uploaded)
- Voice signals (real-time processing, not stored)
- Precise location captured once during a 911 call (optional)
13.2 Sources
- Your direct input and voice
- Microphone input (optional consent)
- Photo uploads (optional consent)
- Connected health app (optional consent)
13.3 Purposes
- Daily health support (meal / medication / hydration / sleep / exercise / mood)
- Emergency support (optional)
- Family caregiving summaries (optional)
13.4 Third parties
Same as section 5 (service providers) and section 6 (linked family). No advertising sharing.
13.5 Withdrawal and deletion
You can withdraw consent per item in the in-app Consent history screen. Upon withdrawal, related Consumer Health Data is deleted within 30 days, including downstream processor copies.
13.6 No geofencing
We do not use geofencing around healthcare facilities for data collection or advertising. (WA MHMDA RCW 19.373.030)
13.7 No sale (opt-in)
We never sell Consumer Health Data, and we do not share it without separate opt-in consent.
14. Biometric notice (Illinois BIPA)
We use voice only for speech-to-text. We do not generate, store, or use voiceprints (biometric identifiers). Raw audio is discarded immediately after conversion.
Illinois residents are protected under 740 ILCS 14 (BIPA), which includes written consent and retention policy rights. Voice features will not activate if you decline the related consent.
15. Children
The service is intended for users 18+. If a sub-13 account is discovered we will immediately deactivate and delete the data (COPPA 16 CFR Part 312). We do not engage in targeted advertising to users under 16 (MD MODPA).
16. Security
We implement reasonable technical and administrative safeguards (encryption in transit and at rest, row-level security, device-keychain storage of credentials, access control, audits) consistent with the NY SHIELD Act and industry standards. No system is absolutely secure.
17. International transfers
The service operates in multiple countries including the United States. Information may be transferred internationally; in such cases the higher of local law or this policy applies.
18. Changes to this policy
Material changes are notified in-app and by email at least 7 days before effective date. Significant scope changes require renewed consent.
19. Contact
- Privacy contact: hello@healthia.app
- Rights requests: hello@healthia.app (subject line: [Rights Request])
- Operating company: Deeper Emptiness AI (mailing address available on request via hello@healthia.app)