Healthya Privacy Policy

Applies to: Healthya (senior app) · Effective: June 21, 2026 · Last updated: August 1, 2026 · Consent version: 2026-07-17

At a glance. Healthya is an AI companion app supporting older adults with daily health and conversation. This policy explains what we collect, with whom we share it, and how you can exercise your rights. We do not sell or share your personal information for advertising.

1. Who we are

Healthya is a service operated by Deeper Emptiness AI ("we", "us"), which acts as the business/Controller of the personal information described in this policy.

Contact: hello@healthia.app

2. Information we collect

We collect the following categories (CCPA §1798.140(v)):

CategoryExamples
IdentifiersPhone number, email address, sign-in provider identifiers (Sign in with Apple / Google), account (user) ID, device IDs, push tokens
Personal information (Cal. Civ. Code §1798.80)Display name, birth year, gender (optional, only if you choose to provide it)
Internet / electronic activityApp usage logs, feature timestamps, crash / performance reports
Geolocation — approximate (optional)City / district level, used for local personalization (e.g., weather-based conversation) and to find nearby care facilities such as hospitals and pharmacies (rounded to roughly 1 km before being sent to our maps provider — see section 5). We do not store precise coordinates for these purposes. Optionally, a generalized "activity area" (last 7 days, rounded to roughly 1–2 km blocks) may be shared with your linked family.
Geolocation — precise (optional, emergency only)Your precise location captured once, at the moment you place a 911 call, and shared with your linked family so they can help. See section 7.
Audio / visual (optional)Microphone signal (real-time only, not stored); meal, medication / prescription, and symptom photos you choose to upload (symptom photos are deleted right after analysis)
Health & fitness from connected health apps (optional)Read-only measurements imported from Apple Health or Google Health Connect: sleep and sleep stages, steps, distance, active energy, and workout sessions; vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate); blood sugar and weight; fitness and gait (VO2 max, heart rate variability, walking steadiness / speed); and mental wellness (mindfulness sessions and mood). See section 8.
Health activity recordsMeal logs (time, type, optional photo / nutrition analysis), exercise (duration, type), medication (name, dose, schedule, intake), hydration (intake events), sleep (start / end times)
Self-reported healthSymptoms, mood, emotion notes
Religious / faith affiliation (optional, sensitive)Collected only if you volunteer it in conversation, used for occasional faith-friendly greetings. We never infer it without your statement and never share it with family. See section 10.
AI memoryDistilled one-line "moments" from conversation, encrypted verbatim quotes, and semantic embeddings used so the assistant can remember your context
InferencesPersonality, interests, and mood inferred from conversation

3. Sources

4. Purposes of use

5. Service providers

We share information only with the following providers under confidentiality and purpose-limited agreements. None of them receive your data for advertising, and we do not share with data brokers.

RecipientData sentPurpose
Google Vertex AI (Gemini)Display name, birth year, recent conversation, learned facts, meal / medication photosConversation understanding, daily summaries, and meal / medication analysis. Enterprise terms — not used for model training.
Google Vertex AI LiveVoice PCM (streaming)Real-time voice conversation. No recordings retained.
Google Cloud VisionMeal and medication / prescription photosText recognition and image analysis to read labels and food.
Google Vertex AI (text embeddings)Short conversation snippetsSemantic search so the assistant can recall relevant context.
Google Cloud Text-to-SpeechResponse textVoice synthesis. Your voice is not sent.
Google Places (Google Maps Platform)Approximate location (rounded to ~1 km) and a care category (hospital / pharmacy)Finding nearby care facilities. No personal identifier is sent; not used for advertising.
Google Search (via Vertex AI grounding)Your web-lookup question text; generic region-scoped news queriesReal-time factual lookup during conversation and the daily news brief. Not used for advertising.
OpenWeatherApproximate (city / district level) locationWeather information used to start friendly conversation. Precise coordinates are not sent.
USDA FoodData CentralFood names only (no personal identifiers)Nutrition reference lookup for meals.
U.S. government health services — RxNorm / RxNav, openFDA, MedlinePlus, DailyMed (NLM / FDA), CMS Care CompareMedication names, or a hospital's ZIP / name for ratings (no personal identifiers)Standardizing medication information, drug labels / images, health-topic summaries, and hospital quality data. Public services.
Twilio (Verify)Phone number, one-time verification codeSMS verification for sign-in and account / phone-number recovery.
ResendEmail address and request detailsSending account and rights-request notification emails.
Expo Push (relaying to Apple APNs / Google FCM)Push tokens, notification payloadsNotification delivery.
Supabase (infrastructure)A subset of the above for storageService operation, with row-level security isolating your data.

TTS audio cache. We cache synthesized audio responses keyed by a hash of the response text (no user identifier). The cache is shared across users — your individual identity is never associated with cached audio. Withdrawing TTS consent stops future synthesis requests; cache eviction is governed by our standard retention policy rather than per-user deletion.

Video calling. Video calling is not offered in the current version of the app. We do not route any video or audio to a video-calling provider.

6. Sharing with linked family

When you link a family member through the Healthya Family app, certain information may be visible to that family member in their app. Family sharing is opt-in and is gated by your consent settings in Settings → Data Use Consent.

6.1 What family always sees (regardless of consent)

6.2 What family sees when health-sharing consent is ON

The Share health activities with family consent grants the linked family read-only access to:

Mental-wellness data (mindfulness minutes and self-logged mood imported from a connected health app) is never shared with family — it is redacted server-side even when health-sharing consent is on. Free-form conversation content, AI memory, learned preferences, voice signals, and consent history are also never shared with family.

6.3 Optional location sharing with family

6.4 What family sees when consent is OFF or withdrawn

If you decline a sharing consent — or withdraw it at any time — the family app will display a clear notice that you have not granted access, and the related categories will be hidden from family view (server-side enforcement via row-level security, not just client filtering). Withdrawal takes effect on the next family-app data refresh.

6.5 Withdrawal and re-consent

6.6 Family member's obligations

The linked family member agrees, in the family app's consent flow, to treat the disclosed information as confidential, not screen-capture or share externally, and to use it only for caregiving purposes.

7. Emergency location sharing (911)

This is the one case where we use your precise location. Healthya is not an emergency response service and cannot guarantee that help will arrive; it provides first-aid reference, one-tap 911 dialing (you place the call yourself), and optional alerts to your linked family.

8. Connected health apps (Apple Health / Google Health Connect)

If you enable Connect health app (optional), Healthya reads the following from Apple Health (iOS) or Google Health Connect (Android), with your separate OS-level permission:

Read-only. Healthya only reads this data; it never writes back to your health app. We use it solely to make your in-app daily summary reflect your real measurements.

Apple / Google requirement. Data obtained from Apple Health or Google Health Connect is never used for advertising or marketing, is never sold, and is never shared with data brokers. It is stored under your account with row-level security. You can turn the connection off at any time in Settings; on withdrawal, the imported health metrics are deleted (within 30 days).

9. Do Not Sell or Share notice

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. No opt-out is required because the protection applies automatically. (CCPA §1798.120 / CPRA)

10. Sensitive Personal Information

SPI under CPRA includes health information, audio signals, precise geolocation, and religious or philosophical beliefs. We collect precise geolocation only for emergency 911 family sharing (section 7), with your opt-in, and never for advertising. We collect faith affiliation only if you volunteer it in conversation, solely for occasional faith-friendly greetings — never inferred, never shared with family, and removable anytime in Settings → What the AI has learned. We do not use SPI beyond service delivery and the purposes you have explicitly consented to. You may restrict SPI use via the in-app Consent history screen. (CPRA §1798.121 — Right to Limit Use of SPI)

11. Retention

12. Your rights

Depending on your residency, you have the rights below. We grant the same rights to all users regardless of location.

12.1 Rights granted to all users

12.2 How to exercise

13. Consumer Health Data (WA MHMDA · NV SB370 · CT)

This section is the Consumer Health Data Privacy Policy required by Washington's My Health My Data Act and analogous laws. "Consumer Health Data" includes information related to physical or mental health status, medications, diagnoses, treatments, precise location, and inferences thereof.

13.1 Categories collected

13.2 Sources

13.3 Purposes

13.4 Third parties

Same as section 5 (service providers) and section 6 (linked family). No advertising sharing.

13.5 Withdrawal and deletion

You can withdraw consent per item in the in-app Consent history screen. Upon withdrawal, related Consumer Health Data is deleted within 30 days, including downstream processor copies.

13.6 No geofencing

We do not use geofencing around healthcare facilities for data collection or advertising. (WA MHMDA RCW 19.373.030)

13.7 No sale (opt-in)

We never sell Consumer Health Data, and we do not share it without separate opt-in consent.

14. Biometric notice (Illinois BIPA)

We use voice only for speech-to-text. We do not generate, store, or use voiceprints (biometric identifiers). Raw audio is discarded immediately after conversion.

Illinois residents are protected under 740 ILCS 14 (BIPA), which includes written consent and retention policy rights. Voice features will not activate if you decline the related consent.

15. Children

The service is intended for users 18+. If a sub-13 account is discovered we will immediately deactivate and delete the data (COPPA 16 CFR Part 312). We do not engage in targeted advertising to users under 16 (MD MODPA).

16. Security

We implement reasonable technical and administrative safeguards (encryption in transit and at rest, row-level security, device-keychain storage of credentials, access control, audits) consistent with the NY SHIELD Act and industry standards. No system is absolutely secure.

17. International transfers

The service operates in multiple countries including the United States. Information may be transferred internationally; in such cases the higher of local law or this policy applies.

18. Changes to this policy

Material changes are notified in-app and by email at least 7 days before effective date. Significant scope changes require renewed consent.

19. Contact

Request a copy of my data (download) — once per 30 days.

Healthya 개인정보처리방침

적용 대상: Healthya(시니어 앱) · 시행일: 2026년 6월 21일 · 최종 갱신: 2026년 8월 1일 · 동의 버전: 2026-07-17

핵심 요약. Healthya는 어르신의 일상 건강과 대화를 돕는 AI 동반자 앱입니다. 본 방침은 어떤 정보를 수집하고, 누구와 공유하며, 어떻게 권리를 행사할 수 있는지 설명합니다. 저희는 광고 목적으로 개인정보를 판매하거나 공유하지 않습니다.

1. 회사 정보

Healthya는 Deeper Emptiness AI("당사")가 운영하는 서비스이며, 당사는 본 방침에 기재된 개인정보의 사업자/처리자(Controller)입니다.

문의: hello@healthia.app

2. 수집하는 정보

다음 항목을 수집합니다(CCPA §1798.140(v) 분류 기준).

분류예시
식별자전화번호, 이메일 주소, 소셜 로그인 식별자(Apple/Google 로그인), 계정(사용자) ID, 기기 ID, 푸시 토큰
개인정보(Cal. Civ. Code §1798.80)닉네임, 출생 연도, 성별(선택 — 직접 입력한 경우에만)
인터넷/전자적 활동앱 사용 로그, 기능 사용 시각, 충돌/성능 보고
위치 — 대략(선택)시·구 단위로, 지역 맞춤(예: 날씨 기반 대화)과 근처 병원·약국 등 케어 시설 찾기에 활용합니다(지도 제공자에 전송하기 전 약 1 km 단위로 반올림 — 5항 참조). 이 목적들로 정밀 좌표를 저장하지 않습니다. 선택 시, 최근 7일의 일반화된 "활동 영역"(약 1~2 km 블록 단위로 반올림)을 연결된 가족에게 공유할 수 있습니다.
위치 — 정밀(선택, 응급 전용)911 발신 순간에 1회 캡처되는 정밀 위치로, 가족이 도울 수 있도록 연결된 가족에게 공유됩니다. 7항 참조.
음성/영상(선택)마이크 신호(실시간 처리만, 저장 안 함); 직접 업로드한 식사·약/처방전·증상 사진(증상 사진은 분석 직후 삭제)
건강 앱에서 가져온 건강·운동 정보(선택)Apple 건강 또는 Google Health Connect에서 읽어오는 측정값(읽기 전용): 수면·수면 단계, 걸음 수, 거리, 활동 칼로리, 운동 세션; 활력징후(심박·혈압·산소·체온·호흡수); 혈당·체중; 체력·보행(VO2max·심박변이도·보행 안정성/속도); 정신건강(마음챙김·기분). 8항 참조.
건강 활동 기록식사 기록(시각, 종류, 선택 사진/영양 분석), 운동(시간, 종류), 복약(이름, 용량, 일정, 복용), 수분(섭취), 수면(시작/종료 시각)
본인 보고 건강정보증상, 기분, 감정 메모
종교/신앙(선택, 민감)대화에서 직접 언급한 경우에만 수집하며, 가벼운 신앙 인사에 사용합니다. 언급 없이 추론하지 않고, 가족과 공유하지 않습니다. 10항 참조.
AI 기억대화에서 추출한 한 줄 "순간", 암호화된 사용자 발화 인용, 맥락 기억을 위한 의미 임베딩
추론 정보대화로부터 추론된 성향, 관심사, 기분

3. 수집 출처

4. 이용 목적

5. 서비스 제공자(수탁자)

아래 제공자에게만 기밀 유지 및 목적 제한 계약하에 정보를 제공합니다. 어느 제공자도 광고 목적으로 데이터를 받지 않으며, 데이터 브로커와 공유하지 않습니다.

수신자전송 데이터목적
Google Vertex AI (Gemini)닉네임, 출생 연도, 최근 대화, 학습된 사실, 식사·약 사진대화 이해, 하루 요약, 식사·약 분석. 엔터프라이즈 약관 — 모델 학습에 사용 안 함.
Google Vertex AI Live음성 PCM(스트리밍)실시간 음성 대화. 녹음 보관 안 함.
Google Cloud Vision식사·약/처방전 사진라벨·음식 인식을 위한 텍스트 인식 및 이미지 분석.
Google Vertex AI(텍스트 임베딩)짧은 대화 조각관련 맥락을 떠올리기 위한 의미 검색.
Google Cloud Text-to-Speech응답 텍스트음성 합성. 이용자 음성은 전송하지 않음.
Google Places(Google Maps Platform)대략 위치(약 1 km 반올림)와 케어 분류(병원/약국)근처 케어 시설 찾기. 개인 식별자 미전송, 광고 미사용.
Google Search(Vertex AI grounding 경유)웹 조회 질문 텍스트; 지역 범위의 일반 뉴스 질의대화 중 실시간 사실 조회 및 매일 뉴스 브리핑. 광고 미사용.
OpenWeather대략(시·구 단위) 위치친근한 대화 시작을 위한 날씨 정보. 정밀 좌표는 전송 안 함.
USDA FoodData Central음식 이름만(개인 식별자 없음)식사 영양 정보 조회.
미국 정부 건강 서비스 — RxNorm / RxNav, openFDA, MedlinePlus, DailyMed(NLM / FDA), CMS Care Compare약 이름, 또는 평가 조회용 병원 ZIP/이름(개인 식별자 없음)약품 정보 표준화, 의약품 라벨/이미지, 건강 주제 요약, 병원 품질 정보. 공공 서비스.
Twilio(Verify)전화번호, 일회용 인증 코드로그인 및 계정/전화번호 복구를 위한 SMS 인증.
Resend이메일 주소 및 요청 내용계정 및 권리 요청 관련 안내 이메일 발송.
Expo Push(Apple APNs / Google FCM로 중계)푸시 토큰, 알림 페이로드알림 전달.
Supabase(인프라)위 항목 중 저장에 필요한 부분서비스 운영. 행 수준 보안(RLS)으로 본인 데이터 격리.

TTS 오디오 캐시. 합성된 음성 응답을 응답 텍스트의 해시(사용자 식별자 없음)를 키로 캐싱합니다. 캐시는 사용자 간 공유되며, 개인 신원이 캐시된 오디오와 연결되지 않습니다. TTS 동의 철회 시 이후 합성 요청은 중단되며, 캐시 제거는 개별 삭제가 아닌 표준 보유 정책을 따릅니다.

화상통화. 현재 버전에서는 화상통화를 제공하지 않습니다. 어떠한 영상·음성도 화상통화 제공자로 전송하지 않습니다.

6. 연결된 가족과의 공유

Healthya Family 앱을 통해 가족을 연결하면, 일부 정보가 해당 가족의 앱에 표시될 수 있습니다. 가족 공유는 옵트인이며, 설정 → 데이터 이용 동의의 동의 설정으로 통제됩니다.

6.1 동의 여부와 무관하게 가족이 항상 보는 것

6.2 건강 공유 동의가 켜져 있을 때 가족이 보는 것

가족과 건강 활동 공유 동의는 연결된 가족에게 다음에 대한 읽기 전용 접근을 부여합니다.

정신건강 데이터(건강 앱에서 가져온 마음챙김 시간과 본인이 기록한 기분)는 건강 공유 동의가 켜져 있어도 서버에서 제거되어 절대 가족과 공유되지 않습니다. 자유 형식 대화 내용, AI 기억, 학습된 선호, 음성 신호, 동의 이력 또한 절대 가족과 공유되지 않습니다.

6.3 가족과의 선택적 위치 공유

6.4 동의가 꺼져 있거나 철회된 경우

공유 동의를 거부하거나 언제든 철회하면, 가족 앱은 접근 권한이 없음을 명확히 안내하고 관련 항목은 가족 화면에서 숨겨집니다(클라이언트 필터링이 아닌 행 수준 보안으로 서버에서 강제). 철회는 가족 앱의 다음 새로고침 시 반영됩니다.

6.5 철회 및 재동의

6.6 가족 구성원의 의무

연결된 가족은 가족 앱의 동의 절차에서, 공개된 정보를 기밀로 취급하고 화면 캡처나 외부 공유를 하지 않으며 돌봄 목적으로만 사용할 것에 동의합니다.

7. 응급 위치 공유(911)

정밀 위치를 사용하는 유일한 경우입니다. Healthya는 응급 대응 서비스가 아니며 구조가 도착함을 보장할 수 없습니다. 응급처치 안내, 원탭 911 발신(통화는 본인이 직접 누름), 연결된 가족에 대한 선택적 알림을 제공합니다.

8. 건강 앱 연동(Apple 건강 / Google Health Connect)

건강 앱 연동(선택)을 켜면, Healthya는 OS의 별도 권한을 받아 Apple 건강(iOS) 또는 Google Health Connect(Android)에서 다음을 읽어옵니다.

읽기 전용. Healthya는 이 데이터를 읽기만 하며, 건강 앱에 다시 쓰지 않습니다. 앱 내 하루 요약이 실제 측정값을 반영하도록 하는 용도로만 사용합니다.

Apple/Google 정책 요건. Apple 건강 또는 Google Health Connect에서 얻은 데이터는 광고·마케팅에 사용되지 않고, 판매되지 않으며, 데이터 브로커와 공유되지 않습니다. 행 수준 보안으로 본인 계정에 저장됩니다. 설정에서 언제든 연동을 끌 수 있으며, 철회 시 가져온 건강 측정값은 삭제됩니다(30일 이내).

9. 판매·공유 금지 고지

당사는 개인정보를 판매하지 않으며, 교차 맥락 행동 광고를 위해 공유하지 않습니다. 보호가 자동 적용되므로 별도 옵트아웃이 필요 없습니다. (CCPA §1798.120 / CPRA)

10. 민감 개인정보(SPI)

CPRA상 SPI에는 건강정보, 음성 신호, 정밀 위치, 종교·철학적 신념이 포함됩니다. 당사는 정밀 위치를 오직 응급 911 가족 공유(7항)를 위해, 이용자 옵트인하에만 수집하며, 광고에는 절대 사용하지 않습니다. 신앙 정보는 이용자가 대화에서 직접 언급한 경우에만 수집하며, 가벼운 신앙 인사에만 사용합니다 — 추론하지 않고, 가족과 공유하지 않으며, 설정 → AI가 학습한 정보에서 언제든 삭제할 수 있습니다. SPI는 서비스 제공과 이용자가 명시적으로 동의한 목적 외에는 사용하지 않습니다. 앱 내 동의 이력 화면에서 SPI 이용을 제한할 수 있습니다. (CPRA §1798.121 — SPI 이용 제한권)

11. 보유 기간

12. 이용자의 권리

거주지에 따라 아래 권리를 가집니다. 당사는 위치와 무관하게 모든 이용자에게 동일한 권리를 부여합니다.

12.1 모든 이용자에게 부여되는 권리

12.2 행사 방법

13. 소비자 건강정보(WA MHMDA · NV SB370 · CT)

본 항목은 워싱턴주 My Health My Data Act 및 유사 법령이 요구하는 소비자 건강정보 처리방침입니다. "소비자 건강정보"에는 신체·정신 건강 상태, 약물, 진단, 치료, 정밀 위치 및 이에 대한 추론이 포함됩니다.

13.1 수집 항목

13.2 출처

13.3 목적

13.4 제3자

5항(서비스 제공자) 및 6항(연결된 가족)과 동일합니다. 광고 목적 공유 없음.

13.5 철회 및 삭제

앱 내 동의 이력 화면에서 항목별로 동의를 철회할 수 있습니다. 철회 시 관련 소비자 건강정보는 다운스트림 수탁자 사본을 포함해 30일 이내 삭제됩니다.

13.6 지오펜싱 금지

당사는 의료시설 주변 지오펜싱을 데이터 수집이나 광고에 사용하지 않습니다. (WA MHMDA RCW 19.373.030)

13.7 판매 금지(옵트인)

당사는 소비자 건강정보를 판매하지 않으며, 별도 옵트인 동의 없이 공유하지 않습니다.

14. 생체정보 고지(일리노이 BIPA)

음성은 오직 음성→텍스트 변환에만 사용합니다. 당사는 음성 지문(생체 식별자)을 생성·저장·이용하지 않습니다. 원본 음성은 변환 직후 폐기됩니다.

일리노이 거주자는 740 ILCS 14(BIPA)의 보호를 받으며, 여기에는 서면 동의 및 보유 정책에 관한 권리가 포함됩니다. 관련 동의를 거부하면 음성 기능이 활성화되지 않습니다.

15. 아동

본 서비스는 18세 이상을 대상으로 합니다. 만 13세 미만 계정이 발견되면 즉시 비활성화하고 데이터를 삭제합니다(COPPA 16 CFR Part 312). 만 16세 미만 이용자에 대한 타게팅 광고를 하지 않습니다(MD MODPA).

16. 보안

당사는 전송·저장 시 암호화, 행 수준 보안, 자격증명의 기기 키체인 저장, 접근 통제, 감사 등 합리적인 기술적·관리적 보호조치를 NY SHIELD Act 및 업계 표준에 부합하게 적용합니다. 어떤 시스템도 절대적으로 안전하지는 않습니다.

17. 국외 이전

본 서비스는 미국을 포함한 여러 국가에서 운영됩니다. 정보가 국외로 이전될 수 있으며, 그 경우 현지법과 본 방침 중 더 높은 보호가 적용됩니다.

18. 방침 변경

중대한 변경은 시행일 최소 7일 전 앱 내 및 이메일로 통지합니다. 중대한 범위 변경은 재동의가 필요합니다.

19. 문의

내 데이터 사본 요청(다운로드) — 30일 1회.