Consumer Health Data Privacy Policy
Effective: April 24, 2026. Version: 1.0. Applies under Washington MHMDA, Nevada SB 370, California CMIA, and similar state laws. Supplements our main Privacy Policy.
1. What is consumer health data?
Consumer health data is personal information that identifies a consumer's past, present, or future physical or mental health status. For Focarly, this may include self-reported mentions of focus challenges, stress, or mood; inferences we might draw from your usage patterns about your general state; and information about executive function support you seek.
IMPORTANT: Focarly does NOT diagnose, treat, or make medical inferences. However, because some information you share may be classified as consumer health data under state law, we treat it with enhanced protections.
2. What health-adjacent data we collect
- Free-text messages you send to the AI coach
- Self-descriptions in onboarding (e.g., “I struggle with focus”)
- Usage patterns that might indicate engagement with productivity support
We do NOT:
- Diagnose any condition
- Store your data as “ADHD,” “depression,” or any other condition
- Derive clinical inferences
- Share health-adjacent data with any third party except as listed in our main Privacy Policy
3. Your consent
By explicitly agreeing during onboarding, you consent to Focarly's processing of any health-adjacent data that may be captured during your use of the Service. You may withdraw this consent at any time through Settings → Privacy → Consent Preferences.
4. Sharing
We do NOT sell consumer health data. We do NOT share consumer health data with:
- Advertisers
- Data brokers
- Marketing affiliates
- Social media platforms for advertising
We process consumer health data only with the processors listed below, and with internal staff on a need-to-know basis.
- Anthropic PBC(US, EU-US DPF + SCCs) — generates coach replies. Your messages are sent to Anthropic's API and are not used to train their models, per our Data Processing Agreement.
- Supabase Inc. (EU Frankfurt region) — primary database, authentication, and file hosting. Data stays inside the EU.
- ElevenLabs Inc.(US, EU-US DPF + SCCs) — handles voice both ways: transcribes the voice messages you send (Scribe) and synthesizes the coach's spoken replies from text. Vendor may retain transmitted audio and text per their published DPA. Focarly does not store audio.
5. Your rights under state laws
- Right to know what consumer health data we have
- Right to withdraw consent
- Right to deletion (hard delete within 30 days)
- Right to appeal our decisions
- Right to be free from discrimination for exercising rights
To exercise: Settings → Privacy → Consumer Health Data Rights, or email privacy@focarly.com. We respond within 30 days.
6. Washington MHMDA-specific rights
You have the right to a signed, notarized authorization requirement for any sale (we do not sell) and the right to enforce your rights through private right of action. You may also file a complaint with the Washington State Attorney General.
7. Audit trail
We maintain an auditable record of your consents, withdrawals, and data rights requests. You can view your consent history in Settings → Privacy.
8. Breach notification
In the event of a breach involving consumer health data, we will notify affected Washington residents and other applicable state residents within the time periods required by law.
9. Contact
Consumer health data privacy: privacy@focarly.com
DPO: dpo@focarly.com