Consumer Health Data Privacy Policy
This Consumer Health Data Privacy Policy supplements our general Privacy Policy and is intended for residents of Washington and Nevada. It describes how Eltria UG (haftungsbeschränkt) ("we", "us") collects, uses, shares, and protects consumer health data under:
- The Washington My Health My Data Act, RCW 19.373 ("MHMDA")
- The Nevada Consumer Health Data Privacy Act, NRS 603A.300–360 ("Nevada CHDPA")
- Any other US state consumer-health-data privacy law as it takes effect
For questions or to exercise the rights described below, contact privacy@eltria.de.
1. What is "consumer health data"
We adopt the statutory definition. Under RCW 19.373.010, consumer health data is:
"personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status."
The statute lists thirteen categories that fall under "physical or mental health status," including individual health conditions, treatments, diseases or diagnoses, surgical procedures, medication use, vital signs, diagnostic testing, gender-affirming care, reproductive or sexual health, biometric data, genetic data, precise location indicating health-service access, and data identifying anyone seeking health-care services.
Of those categories, the only one we touch is vital signs — and then only the subset you choose to sync from your device's health source. We do not collect any of the other twelve categories.
2. What consumer health data we collect
If you grant the Service access to your device's health source (Apple's HealthKit framework on iOS, or Google's Health Connect on Android), we read:
- Sleep records — total time asleep per night — for the rolling 90-day window described in our retention policy. We do not read sleep stage detail (REM, deep, core, awake breakdown).
- Activity records — daily step count, distance, active energy, exercise minutes, workout type — for the same 90-day window
We do not read heart rate, heart rate variability, mindfulness, blood pressure, glucose, body composition, menstrual or fertility data, mental-health data, or any of the other categories your device's health source may expose. The OS-level permission sheet you see when you first connect — Apple's HealthKit prompt on iOS or Google's Health Connect prompt on Android — lists only the categories above.
We also generate inferences from this data — your personality profile incorporates patterns we observe in your sleep and activity records (for example, sleep regularity correlating with certain personality dimensions). Those inferences are themselves consumer health data because they relate to your physical or mental health status; we treat them under this policy with the same protections.
3. Sources
We collect consumer health data only from your own device's health source — Apple Health (via Apple's HealthKit framework) on iOS, or Google Health Connect on Android — accessed with your explicit permission. We do not receive consumer health data from any third-party data broker, advertising partner, employer, healthcare provider, or insurer.
Our use of data obtained through Google Health Connect is additionally subject to Google's Health Connect Permissions Policy: we use Health Connect data solely to provide and improve the personality-profile features described in §4, we do not transfer it to third parties except the processors listed in §6, and we do not use it for advertising.
4. Purposes for which we use consumer health data
We use the consumer health data described above for these purposes only:
- To generate your personality profile — sleep and activity patterns are inputs to the AI prompt that produces your profile
- To display your historical analyses — past profiles are stored so you can revisit them and see how patterns change over time
- To honour requests under your rights (described in §7 below) — for example, returning a copy of your data when you ask for one
- To meet legal obligations — retention, audit, and rights-fulfilment evidence as required by GDPR, MHMDA, Nevada CHDPA, and other applicable laws
We do not use consumer health data for advertising, marketing, profiling for cross-context behavioural advertising, employment decisions, insurance decisions, credit decisions, or any other consequential decision about you.
5. Authorization (your affirmative consent)
Before we read any consumer health data from your device, two consent moments occur:
- The OS-level permission sheet — operated by your device (Apple's HealthKit prompt on iOS, Google's Health Connect prompt on Android). It lists the specific categories we are requesting (the sleep and activity records named in §2). Tapping Allow at this prompt is your affirmative grant under MHMDA RCW 19.373.030.
- Our in-app "Health Privacy" sheet — shown immediately before the OS prompt, summarising in plain English what we will read, who will receive it (OpenAI as our AI processor; AWS as encrypted-storage host), how long we keep it (90 days), and how to disconnect.
You may withdraw your authorization at any time by opening the Service, going to the Connect tab, finding the health card (labelled Apple Health on iOS or Health Connect on Android), and tapping Disconnect. Disconnecting:
- Stops further reads from your device's health source immediately
- Triggers deletion of the consumer health data we have stored, from our live systems, as part of the disconnect action
- Backup copies are overwritten in the next backup cycle (we keep daily backups for 7 days)
Withdrawing authorization does not affect the lawfulness of any analysis we generated before withdrawal. We do not delete past personality profiles automatically when you disconnect Health — those remain part of your account record until you delete the account or the analysis individually. You can delete a specific analysis from the History screen.
6. Who receives consumer health data
Consumer health data is shared with the following recipients, each under a written agreement that limits processing to our documented instructions and prohibits them from using the data for their own purposes (RCW 19.373.060):
| Recipient | Role | What they receive | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI processor (model provider) | The structured prompt for the analysis run, including your sleep and activity records as part of that prompt. OpenAI's API agreement prohibits training its models on our API inputs or outputs. If we ever change our AI provider or add an additional one, we will update this policy and obtain your re-consent before the change takes effect. | United States |
| Amazon Web Services (AWS) | Infrastructure (encrypted storage of the read records before and after analysis) | All consumer health data at rest, encrypted as described in §10 | Ireland (eu-west-1) |
Neither Apple nor Google is a recipient of consumer health data under this policy. Apple's HealthKit framework (on iOS) and Google's Health Connect (on Android) are the on-device sources from which we read; the data leaves your device only to reach our AWS-hosted database. Apple and Google do not see what we have read from your device's health source.
We do not share consumer health data with: data brokers, advertising or marketing partners, social networks, employers, insurers, healthcare providers, government agencies (except in response to a valid court order in our jurisdiction; we will notify you unless legally prohibited), or any third party for cross-context behavioural advertising.
6.1 International transfers
OpenAI and AWS-stored data may be processed in the United States. For users in the EU/EEA/UK/Switzerland, these transfers rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework. For US-resident consumers under MHMDA and Nevada CHDPA, these transfers are within the United States and no cross-border mechanism is required.
7. Your rights
Under MHMDA, the Nevada CHDPA, and other applicable US state consumer-health-data laws, you have the rights below. They apply regardless of your state of residence — we do not gate consumer-health-data rights on state-level proof.
- Right to confirm — confirm whether we are collecting, sharing, or selling your consumer health data, and access a list of the third parties (named in §6) with whom we share it (RCW 19.373.040(1)(a))
- Right to know / access — receive a copy of the consumer health data we hold about you, plus the third-party recipients (RCW 19.373.040(1)(a))
- Right to delete — ask us to delete the consumer health data we hold, including from archived or backup systems (RCW 19.373.040(1)(c))
- Right to withdraw authorization — withdraw your consent to collection and sharing at any time (RCW 19.373.040(1)(b)). The "as easy to withdraw as to give" obligation in GDPR Article 7(3) applies as well — see §5 above for the disconnect control.
- Right to appeal — appeal any denial of the rights above (RCW 19.373.040(1)(h))
7.1 How to exercise these rights
You can exercise the rights to confirm, access, delete, and withdraw authorization directly in the Service:
- Withdraw authorization + delete — Connect tab → health card (Apple Health on iOS, Health Connect on Android) → Disconnect
- Access (full data export) — Profile → Settings → Download My Data; you receive, in the format you choose, either a human-readable PDF report or a structured, machine-readable JSON file. The export includes a list of the third parties and processors with whom we share consumer health data, together with a contact mechanism for each (RCW 19.373.040).
- Delete the entire account — Profile → Settings → Delete account
If you cannot use the in-app controls, email privacy@eltria.de. Include your account email so we can verify the request. We do not require you to create a new account to submit a request.
7.2 Identity verification
For requests received by email, we verify your identity by matching the request to the email address on your account. For deletion or sensitive-data requests, we additionally require you to authenticate inside the Service before we act. If we cannot verify your identity through commercially reasonable efforts, we may ask for additional information (RCW 19.373.040(1)(e)). We do not collect more identifying information than necessary to verify the request.
7.3 Turnaround
We respond to consumer health data requests within 45 days of receipt (RCW 19.373.040(1)(g)). Where the request is complex or we are dealing with a high volume of requests, we may extend that period by a single further 45 days, and will tell you of the extension and the reasons for it within the original 45-day window.
For users to whom GDPR also applies (residents of the EU/EEA/UK/Switzerland), we apply the shorter one-month response window of GDPR Article 12(3), extendable by up to two further months. The shorter applicable deadline always wins.
7.4 Frequency and fees
We respond to information requests free of charge up to twice in any 12-month period. For requests that are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or refuse the request — in which case we will explain why and how to appeal (RCW 19.373.040(1)(f)). We bear the burden of demonstrating the request is excessive.
7.5 Appeals
If we deny a request, you may appeal by emailing privacy@eltria.de with the subject line "MHMDA appeal". We respond to appeals in writing within 45 days, with the decision and the reasons for it.
If your appeal is unsuccessful, you may file a complaint with the Washington Attorney General at atg.wa.gov/file-complaint, or with the Nevada Attorney General at ag.nv.gov/Complaints.
8. We do not sell consumer health data
We do not sell consumer health data. This commitment is unconditional: we do not sell consumer health data for monetary or other valuable consideration, with or without an authorization, and have no intention to do so.
Because we do not sell, we do not request the six-element authorization-to-sell described in RCW 19.373.030 / 19.373.070. If we ever changed this practice, we would update this policy, give prior disclosure, and obtain the explicit six-element authorization required by statute before any sale.
9. We do not use geofences around health-care facilities
RCW 19.373.080 prohibits geofences around entities that provide in-person health-care services where the geofence is used to identify or track consumers seeking health-care services, to collect consumer health data, or to send notifications, messages, or advertisements related to consumer health data or health-care services.
We do not implement geofences of any kind. The Service does not read your device location; your phone never tells us where you are. The only "location-shaped" data we touch is whatever your synced workouts already contain (workout GPS routes from Apple Health on iOS or Health Connect on Android, if your activity records include them), and we use it only for the purpose for which you authorized it.
10. How we secure consumer health data
We restrict access to consumer health data to the employees, processors, and contractors for whom access is necessary to deliver the Service or to honour the consents you have given (RCW 19.373.050). Access is reviewed regularly and revoked when no longer necessary.
Specifically:
- Encryption at rest: Health records are encrypted in our database using authenticated AES-128 (Fernet specification: AES-128 in CBC mode with HMAC-SHA256 for integrity; encryption keys held in AWS Secrets Manager with IAM-scoped access). This application-layer encryption runs on top of AWS-managed disk-level AES-256 encryption on the database volumes.
- Encryption in transit: All API traffic uses TLS 1.2 or higher.
- Access control: Production infrastructure uses least-privilege IAM roles. Engineer access to production data passes through an audited break-glass workflow that requires an explicit reason, logs the actor and the session duration, and is reviewed.
- Logging: Reads and writes against consumer health data are logged with timestamps, actor identity, and operation type. Logs are retained for 90 days.
- Backups: Daily encrypted backups, retained for 7 days, then overwritten.
If we discover a breach affecting consumer health data, we follow the breach-notification process in our general Privacy Policy §6 (notify the supervisory authority within 72 hours under GDPR Article 33; notify affected users without undue delay where the breach is likely to result in high risk under GDPR Article 34; comply with state breach-notification statutes including Cal. Civ. Code § 1798.82 and RCW 19.255 where applicable).
11. How long we keep consumer health data
Health records (whether read from Apple Health on iOS or Google Health Connect on Android) are retained on a rolling 90-day window: records older than 90 days are deleted by a daily retention job. When you disconnect the health source or delete your account, the records are removed from our live systems as part of that action; backup copies follow the 7-day rotation described in §10.
This is shorter than the retention we apply to most other data in the Service, deliberately, because consumer health data carries a higher sensitivity. The full retention table is in our general Privacy Policy §4.
12. Processors
Each processor named in §6 acts only on our documented written instructions, under a binding contract that prohibits the processor from using the data for its own purposes, from combining it with data from other sources for non-permitted use, or from sharing it onward without our authorization (RCW 19.373.060). If a processor violates these instructions, the processor itself becomes subject to MHMDA as a regulated entity (RCW 19.373.060).
13. Changes to this policy
We may update this policy to reflect changes in the Service, applicable law, or our practices. When we make material changes — including any new categories of consumer health data we collect or any new use we put the data to — we will notify you in advance and obtain your affirmative consent before the new use begins (RCW 19.373.020). Previous versions are archived and available on request.
14. Contact
For any consumer health data question, request, or appeal, contact:
- Health-data-specific email:
privacy@eltria.de - Privacy escalations:
privacy@eltria.de(for appeals and complex matters) - Postal address:
Eltria UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany
You may also contact us through the channels described in our general Privacy Policy §11.