This Consumer Health Data Privacy Policy is a separate document required by the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Act (SB 370), and the consumer health data provisions of the Connecticut Data Privacy Act. It is published at www.woosha.app/consumer-health-data-privacy and is linked separately from the homepage of our website and from within the Woosha app.
It explains how Epic Media, LLC collects, uses, shares, and protects consumer health data, and how you can exercise your rights over that data. It should be read alongside our general Privacy Policy. Where the two differ in respect of consumer health data, this document governs for residents of the states listed above.
Consumer health data means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. In Woosha, this includes:
Bodily functions, vital signs, and reproductive or sexual health information are consumer health data under these laws. Woosha collects reproductive health information only if you choose to enable cycle tracking.
All of the consumer health data we hold is provided by you directly, by entering it into the app. We do not buy consumer health data, we do not obtain it from data brokers, we do not derive it from your location, and we do not infer it from your activity outside Woosha.
A limited amount of technical information is collected automatically when you use the app (device type, operating system version, timezone, app version, crash reports, and an IP address used for authentication). We do not use this technical information to infer anything about your health.
We collect and use consumer health data only for the following purposes, each of which is necessary to provide you with the features you have chosen to use:
We do not use consumer health data for advertising, for targeted advertising, for profiling, or to build any commercial profile of you. We do not use it to train artificial intelligence or machine learning models.
Epic Media, LLC does not sell consumer health data, and has never sold consumer health data. Sale, under these laws, means the exchange of consumer health data for monetary or other valuable consideration.
If this ever changes, we will not sell any consumer health data without first obtaining your separate, written, revocable authorization to sell, in the specific form those laws require, which is distinct from the consent described in Section 6 below. That authorization would identify the data to be sold, the purchaser, the purpose, and your right to revoke, and would be valid for no longer than one year.
We share consumer health data only with service providers who process it on our behalf, under contracts that require them to process it only on our instructions and to maintain appropriate security. Those providers are:
Recipient | Category of data shared | Purpose |
Supabase, Inc. | All account and user-generated content, including consumer health data | Database hosting, authentication, and file storage in the United States |
Anthropic, PBC | Wellness data, and, for certain features, free text exactly as you typed it, as described in our AI Disclosure. Shared only if you have separately enabled AI features | Generating AI insights, reframing suggestions, and prompts |
Functional Software, Inc. (Sentry) | Error logs, device information, and a user identifier. Error payloads may incidentally include fragments of data being processed at the time of the error | Crash reporting and error diagnosis |
RevenueCat, Inc. | Purchase events and an app-specific user identifier. No health data | Subscription management |
We do not share consumer health data with advertisers, data brokers, analytics companies, insurers, employers, or any affiliate for that affiliate’s own purposes. We do not share it with any other Epic Media application without your explicit consent given at the time of combination.
We may disclose consumer health data where we are legally compelled to do so, as described in Section 9 of our Privacy Policy. We will not disclose it voluntarily to any government agency, and where we receive a request for reproductive health data we will require valid legal process, will challenge overly broad requests where legally permissible, and will notify you where the law permits us to.
We collect and share consumer health data only with your consent, and we ask for that consent separately from any other agreement.
Consent is not bundled, is not obtained through pre-ticked boxes or through your continued use of the app, and refusing consent for an optional feature does not restrict your access to the rest of Woosha.
If you are a resident of Washington, Nevada, or Connecticut, you have the following rights in relation to your consumer health data:
Most rights can be exercised directly in the app. You can view all of your data at any time, export it from Settings, then My Data, and delete your account and its associated data from Settings, then My Data, then Delete All Data.
You may also email privacy@woosha.app with the subject line “Consumer Health Data Request.” Please tell us which state you reside in and which right you wish to exercise. We will verify your identity, usually by confirming control of the email address associated with your account, and we will not use information provided for verification for any other purpose.
We will respond within 45 days of receipt. Where reasonably necessary we may extend that period by a further 45 days, and we will tell you before doing so and explain why.
When you exercise your right to delete, we delete your consumer health data from our active systems and direct each of our service providers to do the same. Your logged content and your sign-in record are removed together in a single server-side operation, so we do not retain your email address or linked Google or Apple identifier after deletion.
One limitation applies, and we set it out rather than leaving it implicit. Our database provider takes automated daily backups which are retained for a limited period, currently between 7 and 30 days depending on our service plan, before being overwritten. A copy of deleted data may persist in a backup until it expires. Backups are held by our provider, are not accessible to us in the ordinary course, and we do not restore deleted user data from them except where necessary to recover from a system failure.
Data that has already been transmitted to our AI provider is subject to that provider’s retention period, described in our AI Disclosure, and will expire in accordance with it. We cannot recall it earlier.
If we refuse to act on your request, we will tell you why. You may appeal by emailing privacy@woosha.app with the subject line “Consumer Health Data Appeal” within a reasonable period after receiving our decision. We will respond to your appeal in writing within 45 days, explaining the reasons for our decision.
If your appeal is denied, you may complain to the Attorney General of your state:
The Washington My Health My Data Act is enforceable by consumers directly under the Washington Consumer Protection Act, in addition to enforcement by the Attorney General.
We retain consumer health data for as long as your account remains active, because the value of the app depends on being able to show you your own history over time. When you delete your account, consumer health data is removed from our active systems within 30 days, subject to the two limitations described in Section 7.
We do not retain de-identified data derived from consumer health data unless it has been de-identified to a standard that makes re-identification not reasonably possible. Where we hold such data, we maintain it in de-identified form, publicly commit not to re-identify it, and contractually require the same of any recipient.
We restrict access to consumer health data to those who need it to provide, maintain, or secure the Service. Access is limited by role, protected by authentication, and enforced at the database level through row-level security so that your records are accessible only to you. Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Journal entries support optional on-device encryption.
No system is perfectly secure. If consumer health data is affected by a security incident, we will notify you as required by applicable state law and, because Woosha is a health application not covered by HIPAA, by the Federal Trade Commission’s Health Breach Notification Rule where it applies.
Epic Media, LLC is a single-member limited liability company. Access to production systems containing consumer health data is limited to the owner and to any contractor engaged to maintain the Service, each of whom is bound by confidentiality obligations and permitted to access consumer health data only where necessary for a specific technical purpose.
If we make a material change to this policy, we will notify you within the app before the change takes effect, and we will ask you to review and re-accept it before continuing to use features that involve consumer health data. We will not apply a material change retroactively to data already collected without obtaining your consent.
Every published version of this policy is versioned and dated, and we preserve a record of the version you accepted.
Epic Media, LLC
Attn: Consumer Health Data Requests
Huntsville, Alabama, United States
Email: privacy@woosha.app