AshGrid · Health data

AshGrid Consumer Health Data Privacy Policy

Effective July 27, 2026 Last updated July 27, 2026

Consumer health data rights for Washington and Nevada residents under the My Health My Data Act and SB 370.

This policy applies to consumer health data as defined by the Washington My Health My Data Act and Nevada SB 370, and governs residents of Washington and Nevada. Where it conflicts with our general Privacy Policy, this policy controls for consumer health data.

Contact: privacy@ashgrid.co.

Operator

Interim notice. A formal legal entity for AshGrid is being organized. This table, and the effective date above, will be updated when formation completes. Until then, “we”, “us”, and “the Operator” refer to AshGrid’s founder, operating as a sole proprietorship.

Field Value
Legal entity AshGrid, operated by its founder as a sole proprietorship (formal entity being organized)
Entity type Sole proprietorship — pre-incorporation
Registered address Provided on request — write to privacy@ashgrid.co

1. Categories of consumer health data we collect

  • Health conditions and symptoms you choose to track, including the goals you select and the symptoms, notes, and outcomes you record.
  • Interventions you record: supplements, medications, protocols, amounts, and timing — including entries you keep in private tracking.
  • Measurements and bodily functions, whether entered by you or read from your device with permission: heart rate, heart rate variability, sleep, steps, energy expenditure, oxygen saturation, respiratory rate, body temperature, body weight, walking distance, and exercise minutes.
  • Health-related inferences: computed results, effect estimates, reliability scores, and interpretations derived from the above.
  • Demographic information used in a health context: age band, sex at birth, and state.

We do not collect precise location, and we do not use location to infer that you attempted to acquire health services.


2. How we collect it

Directly from you when you record it in the app; from Apple Health (HealthKit) or Android Health Connect only after you grant that permission at the OS level; and by computing inferences from data you already provided.

We do not purchase consumer health data, and we do not obtain it from data brokers or other third-party sources.


3. Why we collect it

  • To provide the service you asked for: recording observations and computing your results.
  • To compute community evidence, only if you separately opt in to aggregate contribution.
  • To keep the service secure and prevent abuse.
  • To meet legal obligations.

We do not use consumer health data for advertising, marketing, profiling for targeted advertising, or any purpose not listed above.


Under MHMDA, collecting and sharing require separate consent. In AshGrid they are separate choices, and neither is bundled into account creation or terms acceptance:

Consent When Revoke
Collect health data you enter When you record it Stop recording; delete entries
Collect device health data OS permission prompt, per data type Device settings, any time
Contribute to aggregate research A separate, neutrally-worded choice during setup, with no pre-selected default — you must actively pick one Profile → data contribution
Publish a community post Per post Delete the post

We use neutral wording and equal-prominence choices. We do not use dark patterns, and a refusal is never made harder than an acceptance. Each consent is recorded in an append-only log with its timestamp and version.


5. Sharing

We share consumer health data only with processors who act on our documented instructions and may not use it for their own purposes:

Processor Purpose
Supabase Database and authentication hosting (United States)
Google Cloud (Cloud Run, United States) Running the application
Anthropic Generating written summaries, under zero-retention and no-training terms

We do not sell consumer health data. MHMDA defines “sell” broadly as exchange for monetary or other valuable consideration; we do not engage in it, and we do not collect the signed valid authorization that a sale would require — because we do not sell.

If you opt in to aggregate contribution, your observations are de-identified and combined with others before any statistic is published, subject to a 30-person minimum cohort floor. De-identified aggregates are not consumer health data, and we do not attempt to re-identify them.


6. Your rights

If you are a Washington or Nevada resident, you have the right to:

  • Confirm whether we collect, share, or sell your consumer health data;
  • Access it, including a list of third parties with whom it has been shared;
  • Withdraw consent to collection and, separately, to sharing;
  • Delete your consumer health data — including, where applicable, from our backups and from our processors;
  • Appeal a denial, and to contact the Washington Attorney General if the appeal is denied.

How to exercise them

  • In app: Profile → Export my data (access/portability), Profile → data contribution (withdraw sharing), Profile → delete account (deletion).
  • By email: privacy@ashgrid.co with the subject “Consumer Health Data Request.”

We will verify your request through your account and respond within 45 days, extendable once by 45 days where permitted, with notice. There is no charge, and exercising a right will never degrade your service.

Deletion: on request we delete your consumer health data from our systems and notify our processors to do the same. De-identified aggregate statistics already computed are not deleted, because they are no longer linkable to you and cannot be isolated without re-identification — this is disclosed here and again at the point of deletion.


7. Data we keep, and for how long

We retain consumer health data while your account is active and delete it on request. Device data held in the ingest cache is hard-deleted after 2 days. Content sent to AI processors is subject to zero retention. Consent records are kept as long as needed to evidence the consent itself.


8. Security

Row-level security on every table, encryption in transit and at rest, column-level encryption for sensitive identifiers, secure-enclave token storage on device, and least-privilege administrative access with append-only audit records.


9. Changes

Material changes to how we collect, use, or share consumer health data will be posted here with a new date, and — as MHMDA requires — we will obtain your consent again before applying the change to data already collected.


10. Contact

The Operator named at the top of this document. privacy@ashgrid.co