Consumer Health Data Privacy Policy

Last Updated: August 4, 2026

This Consumer Health Data Privacy Policy is a standalone policy required by the Washington My Health My Data Act (MHMDA) and comparable state consumer-health-data laws. It applies to all US users of Food Signals, regardless of state — we do not limit these protections to Washington or Nevada residents. It supplements, and does not replace, our general Privacy Policy.


1. What Counts as Consumer Health Data Here

For the purposes of this policy, "consumer health data" means:

This is a subset of the broader data described in our Privacy Policy — this document exists because several US states give this specific category of data extra protection.


2. We Only Collect This Data With Your Affirmative Opt-In

We do not collect any consumer health data unless you have affirmatively opted in. Specifically:


3. We Do Not Sell Consumer Health Data

We do not sell, and have never sold, consumer health data. We also do not share consumer health data with any third party for the purpose of targeted advertising, and we do not use it to build behavioural advertising profiles. The only parties who ever receive any part of your consumer health data are the processors named in our Privacy Policy §3 (the AI providers who help generate your food suggestions, and Cloudflare, who hosts the Service) and, only if you separately opt in, your dietitian.


4. Your Rights Over Your Consumer Health Data

You have the right to:

To exercise any of these rights, please contact us or use the in-app controls described above.


5. No Geofencing

This policy, and the consent and rights it describes, apply to your account the same way regardless of which US state you are in. We do not detect your location to selectively withhold these protections.


6. Data Security and Breach Notification

Consumer health data is protected by the same security measures described in our Privacy Policy §6 (encryption in transit, access controls). In the event of a breach involving consumer health data that is likely to cause harm, we will notify affected US users within 60 days, consistent with the FTC Health Breach Notification Rule, and will notify the Australian Office of the Australian Information Commissioner (OAIC) within 30 days where the Australian Notifiable Data Breaches scheme applies.


7. Contact

For questions about this policy or to exercise your rights, please contact us.


8. Changes to This Policy

We will notify you of material changes to this policy the same way we notify you of material changes to our general Privacy Policy — by email or in-app notice at least 14 days before the change takes effect. The current version is always available at this URL.