Healthya Privacy Policy
At a glance. Healthya is an AI companion app supporting older adults with daily health and conversation. This policy explains what we collect, with whom we share it, and how you can exercise your rights. We do not sell or share your personal information for advertising.
1. Who we are
Healthya is a service operated by Deeper Emptiness AI ("we", "us"), which acts as the business/Controller of the personal information described in this policy.
Contact: hello@healthia.app
2. Information we collect
We collect the following categories (CCPA §1798.140(v)):
| Category | Examples |
|---|---|
| Identifiers | Phone number, email address, sign-in provider identifiers (Sign in with Apple / Google), account (user) ID, device IDs, push tokens |
| Personal information (Cal. Civ. Code §1798.80) | Display name, birth year, gender (optional, only if you choose to provide it) |
| Internet / electronic activity | App usage logs, feature timestamps, crash / performance reports |
| Geolocation — approximate (optional) | City / district level, used for local personalization (e.g., weather-based conversation) and to find nearby care facilities such as hospitals and pharmacies (rounded to roughly 1 km before being sent to our maps provider — see section 5). We do not store precise coordinates for these purposes. Optionally, a generalized "activity area" (last 7 days, rounded to roughly 1–2 km blocks) may be shared with your linked family. |
| Geolocation — precise (optional, emergency readiness) | If you grant emergency location sharing to a linked family member, the app refreshes a single stored precise location about every 5 minutes while the app is open on your screen, so that a usable location already exists the moment you call 911. Only the most recent one is kept — each refresh overwrites the last, so no trail or history is stored. Nothing is collected while the app is in the background or closed. See section 7. |
| Audio / visual (optional) | Microphone signal (real-time only, not stored); meal, medication / prescription, and symptom photos you choose to upload (symptom photos are deleted right after analysis) |
| Health & fitness from connected health apps (optional) | Read-only measurements imported from Apple Health or Google Health Connect: sleep and sleep stages, steps, distance, active energy, and workout sessions; vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate); blood sugar and weight; fitness and gait (VO2 max, heart rate variability, walking steadiness / speed); and mental wellness (mindfulness sessions and mood). See section 8. |
| Health activity records | Meal logs (time, type, optional photo / nutrition analysis), exercise (duration, type), medication (name, dose, schedule, intake), hydration (intake events), sleep (start / end times) |
| Body measurements (optional) | Height and weight you enter yourself, together with your sex and birth year, used only to size meal and snack suggestions. You may decline — meal suggestions still work without them. These values are stored under your own account, are never visible to your linked family, and the raw height / weight and any body-mass figure derived from them are never sent to our AI provider (see section 5). If you have connected a health app, a recent weight measured by your device may be used instead of the weight you typed. |
| Self-reported health | Symptoms, mood, emotion notes |
| Religious / faith affiliation (optional, sensitive) | Collected only if you volunteer it in conversation, used for occasional faith-friendly greetings. We never infer it without your statement and never share it with family. See section 10. |
| AI memory | Distilled one-line "moments" from conversation, encrypted verbatim quotes, and semantic embeddings used so the assistant can remember your context |
| Inferences | Personality, interests, and mood inferred from conversation |
Where this information can appear on your phone. Some of it is shown outside the app, where anyone holding or glancing at your phone may see it — this is a normal part of how reminders and widgets work, not sharing with us or anyone else:
- Notifications — reminder text appears on your lock screen. Medication reminders deliberately use a neutral wording instead of the medicine's name.
- Home-screen and lock-screen widgets — the "Today's plan" widget shows your remaining care items and their times (again, medication is shown as a neutral label), and the "3-Day Wins" widget shows the goal titles you wrote yourself, including on the iOS lock screen. If you would rather not have a goal title visible there, choose a title that does not reveal anything you want kept private, or remove the widget.
3. Sources
- Information you provide (signup, consent, conversation, photo upload)
- Device-generated information (device IDs, push tokens)
- Sign-in providers you choose to use (Apple, Google) — they return a verified identity token and your name
- Connected health apps (Apple Health / Google Health Connect), only with your permission
- Information your linked family provides via the family app
- Outputs from third-party services (e.g., Vertex AI responses)
4. Purposes of use
- AI companion conversation and memory of your context
- Text-to-speech for natural voice responses
- Daily plans, meal / medication / hydration reminders, and lifestyle support
- Sizing meal and snack suggestions to you, using your optional height, weight, sex, and birth year
- Daily summaries combining your activity with optional health-app measurements
- Emergency support — first-aid reference, one-tap 911 dialing, and optional family alerts (see section 7)
- Care navigation (optional) — helping you find nearby hospitals / pharmacies and showing general symptom guidance (informational only, not a diagnosis)
- Local personalization (approximate location for weather-based conversation)
- Family support (optional) — short summaries to enable family caregiving
- Account management, including phone-number recovery you pre-authorize for a linked family member
- Legal compliance, fraud prevention, and security auditing
5. Service providers
We share information only with the following providers under confidentiality and purpose-limited agreements. None of them receive your data for advertising, and we do not share with data brokers.
| Recipient | Data sent | Purpose |
|---|---|---|
| Google Vertex AI (Gemini) | Display name, birth year, recent conversation, learned facts, meal / medication photos | Conversation understanding, daily summaries, and meal / medication analysis. Enterprise terms — not used for model training. |
| Google Vertex AI Live | Voice PCM (streaming) | Real-time voice conversation. No recordings retained. |
| Google Cloud Vision | Meal and medication / prescription photos | Text recognition and image analysis to read labels and food. |
| Google Vertex AI (text embeddings) | Short conversation snippets | Semantic search so the assistant can recall relevant context. |
| Google Cloud Text-to-Speech | Response text | Voice synthesis. Your voice is not sent. |
| Google Places (Google Maps Platform) | Approximate location (rounded to ~1 km) and a care category (hospital / pharmacy) | Finding nearby care facilities. No personal identifier is sent; not used for advertising. |
| Google Search (via Vertex AI grounding) | Your web-lookup question text; generic region-scoped news queries | Real-time factual lookup during conversation and the daily news brief. Not used for advertising. |
| OpenWeather | Approximate (city / district level) location | Weather information used to start friendly conversation. Precise coordinates are not sent. |
| USDA FoodData Central | Food names only (no personal identifiers) | Nutrition reference lookup for meals. |
| U.S. government health services — RxNorm / RxNav, openFDA, MedlinePlus, DailyMed (NLM / FDA), CMS Care Compare | Medication names, or a hospital's ZIP / name for ratings (no personal identifiers) | Standardizing medication information, drug labels / images, health-topic summaries, and hospital quality data. Public services. |
| Google Maps (Android) / Apple Maps (iOS) | Your device's IP address and the map area being displayed | Drawing the map when you look for nearby care. No account identifier is sent. |
| Google Translate (translate.google gateway) | Your device's IP address and the address of the health page being translated | Showing a US government health article in your language when you open it in the app. Used only for reference articles you choose to open; your own records are never sent. |
| Twilio (Verify) | Phone number, one-time verification code | SMS verification for sign-in and account / phone-number recovery. |
| Resend | Email address and request details | Sending account and rights-request notification emails. |
| Expo Push (relaying to Apple APNs / Google FCM) | Push tokens, notification payloads | Notification delivery. |
| Supabase (infrastructure) | A subset of the above for storage | Service operation, with row-level security isolating your data. |
TTS audio cache. We cache synthesized audio responses keyed by a hash of the response text (no user identifier). The cache is shared across users — your individual identity is never associated with cached audio. Withdrawing TTS consent stops future synthesis requests; cache eviction is governed by our standard retention policy rather than per-user deletion.
Video calling. Video calling is not offered in the current version of the app. We do not route any video or audio to a video-calling provider.
6. Sharing with linked family
When you link a family member through the Healthya Family app, certain information may be visible to that family member in their app. Family sharing is opt-in and is gated by your consent settings in Settings → Data Use Consent.
6.1 What family always sees (regardless of consent)
- Your display name and the fact that you are linked to them
- Connection activity (link request, acceptance, removal)
6.2 What family sees when health-sharing consent is ON
The Share health activities with family consent grants the linked family read-only access to:
- Meals — time, type (breakfast / lunch / dinner / snack), photo (if you uploaded), AI nutrition analysis (food name, calories, caution notes), suggested next meal
- Exercise — type and duration (minutes)
- Medication — registered medications (name, dose, schedule), intake events, photos of pill bottles / prescriptions you uploaded
- Hydration — water intake events
- Sleep — sleep start / end timestamps and sleep stages (including measurements imported from a connected health app, if enabled)
- Device health metrics (if you connected a health app) — steps, distance, active energy, vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate), blood sugar / weight, and fitness / gait measurements imported from Apple Health or Google Health Connect
- Recent activity timestamp — when you were last active in the app
- AI daily summary — a short AI-written paragraph about your day, the emotional tone the assistant inferred from your conversations (together with the assistant's stated reasoning), and the general topics you talked about. This is a summary, not a transcript: your actual words are stripped out before the summary is stored, so family never sees what you literally said.
- Weekly and monthly reports — patterns across the period (meals, medication, sleep, exercise), health-screening flags produced by fixed rules, an AI-written recap, and a monthly summary intended to help you and your family prepare for a doctor's visit.
What this means in practice. Because the daily summary describes your mood and the subjects you raised, a family member with health-sharing access can learn how you seemed to be feeling and what was on your mind — even though they cannot read your conversations. If you would rather they not see this, turn health sharing off in Settings → Data Use Consent.
What family never sees. The literal text of your conversations, your AI memory and learned preferences, your voice, your faith affiliation, the height and weight you entered, and your consent history are never shared with family. Mindfulness minutes and self-logged mood imported from a connected health app are also never shared — they are redacted server-side even when health-sharing consent is on.
6.3 Optional location sharing with family
- Activity area — if you grant Share activity area with family (granted separately for each linked family member), that family member can see a generalized activity area from the last 7 days (rounded to roughly 1–2 km blocks; never an exact point or a live trail). Older data is automatically deleted on a rolling 7-day window.
- Emergency location — handled separately under section 7.
6.4 What family sees when consent is OFF or withdrawn
If you decline a sharing consent — or withdraw it at any time — the family app will display a clear notice that you have not granted access, and the related categories will be hidden from family view (server-side enforcement via row-level security, not just client filtering). Withdrawal takes effect on the next family-app data refresh.
6.5 Withdrawal and re-consent
- You can toggle each sharing consent at any time in Settings → Data Use Consent.
- The change is logged in your consent history (Settings → My information rights → Consent history) as immutable evidence (CCPA Right to Know).
- Unlinking a family member also removes their visibility regardless of the consent state.
6.6 Family member's obligations
The linked family member agrees, in the family app's consent flow, to treat the disclosed information as confidential, not screen-capture or share externally, and to use it only for caregiving purposes.
7. Emergency location sharing (911)
This is the one case where we use your precise location. Healthya is not an emergency response service and cannot guarantee that help will arrive; it provides first-aid reference, one-tap 911 dialing (you place the call yourself), and optional alerts to your linked family.
- Consent. Precise emergency location sharing is off until you turn it on, and you turn it on separately for each linked family member. We strongly recommend keeping it on for at least one person.
- When we collect it. So that a usable location exists at the moment you need it, the app refreshes your stored precise location about every 5 minutes while the app is open on your screen. We do this in advance because placing a 911 call sends your phone to the dialer, which would cut off a fresh GPS reading at exactly the wrong moment. Nothing is collected while the app is in the background or closed, and we never build a location history.
- What is stored. Exactly one location per person. Each refresh overwrites the previous one, so there is no trail, no route, and no record of everywhere you have been — only where you were most recently while using the app.
- Who can see it. A family member you have granted this permission can view that single most recent location in their app, under row-level security. Please note that this is not limited to emergencies — if you have granted the permission, they can open the map and see your most recent location at any time. Family members you have not granted it to cannot see any location, even during an emergency.
- When you call 911. The push notification to your family contains your name only — never coordinates. Placing the call does not itself capture a new location; it sends the alert, and the family member opens the location already stored.
- If the permission is off or location access is unavailable, the alert is still sent, with no location attached.
- What we keep. The stored location is automatically deleted 7 days after it was last refreshed, and immediately if you withdraw the permission or delete your account.
8. Connected health apps (Apple Health / Google Health Connect)
If you enable Connect health app (optional), Healthya reads the following from Apple Health (iOS) or Google Health Connect (Android), with your separate OS-level permission:
- Sleep start / end times, total sleep minutes, and sleep stages (deep / REM), where available
- Steps, walking / running distance, and floors climbed
- Active energy (calories)
- Workout sessions (type, start time, duration)
- Vital signs — heart rate, resting heart rate, blood pressure, oxygen saturation, body temperature, respiratory rate
- Blood sugar (glucose) and body weight
- Fitness and gait — VO2 max, heart rate variability, walking steadiness, walking speed, six-minute walk distance (some are iOS-only, imported where available)
- Mental wellness — mindfulness session minutes and self-logged mood (Apple Health State of Mind). This category is used only in your own app and is never shared with family (see section 6.2)
Read-only. Healthya only reads this data; it never writes back to your health app. We use it solely to make your in-app daily summary reflect your real measurements.
Apple / Google requirement. Data obtained from Apple Health or Google Health Connect is never used for advertising or marketing, is never sold, and is never shared with data brokers. It is stored under your account with row-level security. You can turn the connection off at any time in Settings; on withdrawal, the imported health metrics are deleted (within 30 days).
9. Do Not Sell or Share notice
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. No opt-out is required because the protection applies automatically. (CCPA §1798.120 / CPRA)
10. Sensitive Personal Information
SPI under CPRA includes health information, audio signals, precise geolocation, and religious or philosophical beliefs. We collect precise geolocation only for 911 emergency readiness and family sharing (section 7) — with your opt-in, only while the app is open on your screen, keeping only the single most recent location, and never for advertising. We collect faith affiliation only if you volunteer it in conversation, solely for occasional faith-friendly greetings — never inferred, never shared with family, and removable anytime in Settings → What the AI has learned. We do not use SPI beyond service delivery and the purposes you have explicitly consented to. You may restrict SPI use via the in-app Consent history screen. (CPRA §1798.121 — Right to Limit Use of SPI)
11. Retention
- Active retention while your account is in use. After 24 months of inactivity we will notify and deactivate.
- Account deletion request: all data removed within 30 days (consent ledger preserved as legal evidence for statutory periods).
- Consent withdrawal: related data removed within 30 days (WA MHMDA).
- Activity-area location: auto-deleted on a rolling 7-day window; removed immediately if you withdraw the consent.
- Emergency alert records: see section 7.
- Legal hold periods take precedence where applicable.
12. Your rights
Depending on your residency, you have the rights below. We grant the same rights to all users regardless of location.
12.1 Rights granted to all users
- Right to Know. Request a copy of the information we hold about you.
- Right to Delete. Request deletion of your information.
- Right to Correct. Request correction of inaccurate information.
- Right to Portability. Receive your information in a machine-readable format (JSON / CSV).
- Right to Limit SPI. Restrict use of health / voice / location data.
- Opt-out of Sale / Share. We do not sell or share — applies automatically.
- Opt-out of Automated Decision-Making. Request exclusion from AI-based profiling (CPRA Reg 2025).
- Non-discrimination. No penalty for exercising your rights.
- Right to Appeal. Appeal denied requests within 60 days (VCDPA / CPA / CTDPA).
- Authorized Agent. A trusted family member may submit requests on your behalf (CCPA §1798.135).
12.2 How to exercise
- In-app — Settings → My information rights:
- Right to Know — generates a downloadable ZIP (JSON + CSV) of your data within minutes. Request it via the download link at the end of this policy (in the app) or by email. Once per 30 days. Photos you uploaded (meal, medication, and symptom images) are not included in the automatic export but are available on request by email.
- Right to Correct — review and edit "What the AI has learned about you".
- Right to Delete — account deletion screen.
- Right to Limit SPI / Withdraw Consent — per-item withdrawal in the Consent history screen.
- Email: hello@healthia.app (subject line: [Rights Request]).
- Processing time: in-app actions are typically completed immediately. Email-based requests are resolved within 45 days of receipt (one 45-day extension where permitted). WA MHMDA-driven consent deletions: 30 days.
13. Consumer Health Data (WA MHMDA · NV SB370 · CT)
This section is the Consumer Health Data Privacy Policy required by Washington's My Health My Data Act and analogous laws. "Consumer Health Data" includes information related to physical or mental health status, medications, diagnoses, treatments, precise location, and inferences thereof.
13.1 Categories collected
- Meal, medication, hydration, sleep, and exercise records and photos
- Height and weight you enter yourself (optional), and the meal / snack portion guidance derived from them
- Sleep, steps, activity, vital signs (heart rate, blood pressure, oxygen, temperature, respiratory rate), blood sugar, weight, fitness / gait, and mental-wellness measurements (mindfulness, mood) imported from a connected health app (optional)
- Inferred physical / emotional state from conversation
- Symptoms you report and the general symptom guidance / recommended care setting shown to you
- Pill bottle, prescription, and symptom photos (if uploaded)
- Voice signals (real-time processing, not stored)
- A single most-recent precise location, refreshed while the app is open so it is ready if you call 911 (optional — see section 7)
13.2 Sources
- Your direct input and voice
- Microphone input (optional consent)
- Photo uploads (optional consent)
- Connected health app (optional consent)
13.3 Purposes
- Daily health support (meal / medication / hydration / sleep / exercise / mood)
- Emergency support (optional)
- Family caregiving summaries (optional)
13.4 Third parties
Same as section 5 (service providers) and section 6 (linked family). No advertising sharing.
13.5 Withdrawal and deletion
You can withdraw consent per item in the in-app Consent history screen. Upon withdrawal, related Consumer Health Data is deleted within 30 days, including downstream processor copies.
13.6 No geofencing
We do not use geofencing around healthcare facilities for data collection or advertising. (WA MHMDA RCW 19.373.030)
13.7 No sale (opt-in)
We never sell Consumer Health Data, and we do not share it without separate opt-in consent.
14. Biometric notice (Illinois BIPA)
We use voice only for speech-to-text. We do not generate, store, or use voiceprints (biometric identifiers). Raw audio is discarded immediately after conversion.
Illinois residents are protected under 740 ILCS 14 (BIPA), which includes written consent and retention policy rights. Voice features will not activate if you decline the related consent.
15. Children
The service is intended for users 18+. If a sub-13 account is discovered we will immediately deactivate and delete the data (COPPA 16 CFR Part 312). We do not engage in targeted advertising to users under 16 (MD MODPA).
16. Security
We implement reasonable technical and administrative safeguards (encryption in transit and at rest, row-level security, device-keychain storage of credentials, access control, audits) consistent with the NY SHIELD Act and industry standards. No system is absolutely secure.
17. International transfers
The service operates in multiple countries including the United States. Information may be transferred internationally; in such cases the higher of local law or this policy applies.
18. Changes to this policy
Material changes are notified in-app and by email at least 7 days before effective date. Significant scope changes require renewed consent.
19. Contact
- Privacy contact: hello@healthia.app
- Rights requests: hello@healthia.app (subject line: [Rights Request])
- Operating company: Deeper Emptiness AI (mailing address available on request via hello@healthia.app)