Consumer Health Data Privacy Policy

Version 1.1 · Effective 2026-08-30

The short version. If you connect your device's health source — Apple Health on iOS or Google Health Connect on Android — to the Service, the sleep and activity records we read qualify as consumer health data under Washington's My Health My Data Act (MHMDA) and Nevada's SB 370. This policy explains exactly what we collect, who we share it with, how long we keep it, and the rights you have under those laws. It is in addition to our general Privacy Policy — that policy still applies; this one adds the health-data specific commitments those state laws require.

This Consumer Health Data Privacy Policy supplements our general Privacy Policy and is intended for residents of Washington and Nevada. It describes how Eltria UG (haftungsbeschränkt) ("we", "us") collects, uses, shares, and protects consumer health data under:

For questions or to exercise the rights described below, contact privacy@eltria.de.

1. What is "consumer health data"

We adopt the statutory definition. Under RCW 19.373.010, consumer health data is:

"personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status."

The statute lists thirteen categories that fall under "physical or mental health status," including individual health conditions, treatments, diseases or diagnoses, surgical procedures, medication use, vital signs, diagnostic testing, gender-affirming care, reproductive or sexual health, biometric data, genetic data, precise location indicating health-service access, and data identifying anyone seeking health-care services.

Of those categories, the only one we touch is vital signs — and then only the subset you choose to sync from your device's health source. We do not collect any of the other twelve categories.

2. What consumer health data we collect

If you grant the Service access to your device's health source (Apple's HealthKit framework on iOS, or Google's Health Connect on Android), we read:

We do not read heart rate, heart rate variability, mindfulness, blood pressure, glucose, body composition, menstrual or fertility data, mental-health data, or any of the other categories your device's health source may expose. The OS-level permission sheet you see when you first connect — Apple's HealthKit prompt on iOS or Google's Health Connect prompt on Android — lists only the categories above.

We also generate inferences from this data — your personality profile incorporates patterns we observe in your sleep and activity records (for example, sleep regularity correlating with certain personality dimensions). Those inferences are themselves consumer health data because they relate to your physical or mental health status; we treat them under this policy with the same protections.

3. Sources

We collect consumer health data only from your own device's health source — Apple Health (via Apple's HealthKit framework) on iOS, or Google Health Connect on Android — accessed with your explicit permission. We do not receive consumer health data from any third-party data broker, advertising partner, employer, healthcare provider, or insurer.

Our use of data obtained through Google Health Connect is additionally subject to Google's Health Connect Permissions Policy: we use Health Connect data solely to provide and improve the personality-profile features described in §4, we do not transfer it to third parties except the processors listed in §6, and we do not use it for advertising.

4. Purposes for which we use consumer health data

We use the consumer health data described above for these purposes only:

We do not use consumer health data for advertising, marketing, profiling for cross-context behavioural advertising, employment decisions, insurance decisions, credit decisions, or any other consequential decision about you.

5. Authorization (your affirmative consent)

Before we read any consumer health data from your device, two consent moments occur:

  1. The OS-level permission sheet — operated by your device (Apple's HealthKit prompt on iOS, Google's Health Connect prompt on Android). It lists the specific categories we are requesting (the sleep and activity records named in §2). Tapping Allow at this prompt is your affirmative grant under MHMDA RCW 19.373.030.
  2. Our in-app "Health Privacy" sheet — shown immediately before the OS prompt, summarising in plain English what we will read, who will receive it (OpenAI as our AI processor; AWS as encrypted-storage host), how long we keep it (90 days), and how to disconnect.

You may withdraw your authorization at any time by opening the Service, going to the Connect tab, finding the health card (labelled Apple Health on iOS or Health Connect on Android), and tapping Disconnect. Disconnecting:

Withdrawing authorization does not affect the lawfulness of any analysis we generated before withdrawal. We do not delete past personality profiles automatically when you disconnect Health — those remain part of your account record until you delete the account or the analysis individually. You can delete a specific analysis from the History screen.

6. Who receives consumer health data

Consumer health data is shared with the following recipients, each under a written agreement that limits processing to our documented instructions and prohibits them from using the data for their own purposes (RCW 19.373.060):

RecipientRoleWhat they receiveLocation
OpenAI, L.L.C. AI processor (model provider) The structured prompt for the analysis run, including your sleep and activity records as part of that prompt. OpenAI's API agreement prohibits training its models on our API inputs or outputs. If we ever change our AI provider or add an additional one, we will update this policy and obtain your re-consent before the change takes effect. United States
Amazon Web Services (AWS) Infrastructure (encrypted storage of the read records before and after analysis) All consumer health data at rest, encrypted as described in §10 Ireland (eu-west-1)

Neither Apple nor Google is a recipient of consumer health data under this policy. Apple's HealthKit framework (on iOS) and Google's Health Connect (on Android) are the on-device sources from which we read; the data leaves your device only to reach our AWS-hosted database. Apple and Google do not see what we have read from your device's health source.

We do not share consumer health data with: data brokers, advertising or marketing partners, social networks, employers, insurers, healthcare providers, government agencies (except in response to a valid court order in our jurisdiction; we will notify you unless legally prohibited), or any third party for cross-context behavioural advertising.

6.1 International transfers

OpenAI and AWS-stored data may be processed in the United States. For users in the EU/EEA/UK/Switzerland, these transfers rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework. For US-resident consumers under MHMDA and Nevada CHDPA, these transfers are within the United States and no cross-border mechanism is required.

7. Your rights

Under MHMDA, the Nevada CHDPA, and other applicable US state consumer-health-data laws, you have the rights below. They apply regardless of your state of residence — we do not gate consumer-health-data rights on state-level proof.

7.1 How to exercise these rights

You can exercise the rights to confirm, access, delete, and withdraw authorization directly in the Service:

If you cannot use the in-app controls, email privacy@eltria.de. Include your account email so we can verify the request. We do not require you to create a new account to submit a request.

7.2 Identity verification

For requests received by email, we verify your identity by matching the request to the email address on your account. For deletion or sensitive-data requests, we additionally require you to authenticate inside the Service before we act. If we cannot verify your identity through commercially reasonable efforts, we may ask for additional information (RCW 19.373.040(1)(e)). We do not collect more identifying information than necessary to verify the request.

7.3 Turnaround

We respond to consumer health data requests within 45 days of receipt (RCW 19.373.040(1)(g)). Where the request is complex or we are dealing with a high volume of requests, we may extend that period by a single further 45 days, and will tell you of the extension and the reasons for it within the original 45-day window.

For users to whom GDPR also applies (residents of the EU/EEA/UK/Switzerland), we apply the shorter one-month response window of GDPR Article 12(3), extendable by up to two further months. The shorter applicable deadline always wins.

7.4 Frequency and fees

We respond to information requests free of charge up to twice in any 12-month period. For requests that are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse the request — in which case we will explain why and how to appeal (RCW 19.373.040(1)(f)). We bear the burden of demonstrating the request is excessive.

7.5 Appeals

If we deny a request, you may appeal by emailing privacy@eltria.de with the subject line "MHMDA appeal". We respond to appeals in writing within 45 days, with the decision and the reasons for it.

If your appeal is unsuccessful, you may file a complaint with the Washington Attorney General at atg.wa.gov/file-complaint, or with the Nevada Attorney General at ag.nv.gov/Complaints.

8. We do not sell consumer health data

We do not sell consumer health data. This commitment is unconditional: we do not sell consumer health data for monetary or other valuable consideration, with or without an authorization, and have no intention to do so.

Because we do not sell, we do not request the six-element authorization-to-sell described in RCW 19.373.030 / 19.373.070. If we ever changed this practice, we would update this policy, give prior disclosure, and obtain the explicit six-element authorization required by statute before any sale.

9. We do not use geofences around health-care facilities

RCW 19.373.080 prohibits geofences around entities that provide in-person health-care services where the geofence is used to identify or track consumers seeking health-care services, to collect consumer health data, or to send notifications, messages, or advertisements related to consumer health data or health-care services.

We do not implement geofences of any kind. The Service does not read your device location; your phone never tells us where you are. The only "location-shaped" data we touch is whatever your synced workouts already contain (workout GPS routes from Apple Health on iOS or Health Connect on Android, if your activity records include them), and we use it only for the purpose for which you authorized it.

10. How we secure consumer health data

We restrict access to consumer health data to the employees, processors, and contractors for whom access is necessary to deliver the Service or to honour the consents you have given (RCW 19.373.050). Access is reviewed regularly and revoked when no longer necessary.

Specifically:

If we discover a breach affecting consumer health data, we follow the breach-notification process in our general Privacy Policy §6 (notify the supervisory authority within 72 hours under GDPR Article 33; notify affected users without undue delay where the breach is likely to result in high risk under GDPR Article 34; comply with state breach-notification statutes including Cal. Civ. Code § 1798.82 and RCW 19.255 where applicable).

11. How long we keep consumer health data

Health records (whether read from Apple Health on iOS or Google Health Connect on Android) are retained on a rolling 90-day window: records older than 90 days are deleted by a daily retention job. When you disconnect the health source or delete your account, the records are removed from our live systems as part of that action; backup copies follow the 7-day rotation described in §10.

This is shorter than the retention we apply to most other data in the Service, deliberately, because consumer health data carries a higher sensitivity. The full retention table is in our general Privacy Policy §4.

12. Processors

Each processor named in §6 acts only on our documented written instructions, under a binding contract that prohibits the processor from using the data for its own purposes, from combining it with data from other sources for non-permitted use, or from sharing it onward without our authorization (RCW 19.373.060). If a processor violates these instructions, the processor itself becomes subject to MHMDA as a regulated entity (RCW 19.373.060).

13. Changes to this policy

We may update this policy to reflect changes in the Service, applicable law, or our practices. When we make material changes — including any new categories of consumer health data we collect or any new use we put the data to — we will notify you in advance and obtain your affirmative consent before the new use begins (RCW 19.373.020). Previous versions are archived and available on request.

14. Contact

For any consumer health data question, request, or appeal, contact:

You may also contact us through the channels described in our general Privacy Policy §11.