Consumer Health Data Privacy Policy
Washington My Health My Data Act
Last updated: 10 September 2026
This policy applies to Washington State residents and to consumer health data collected in Washington State. It covers only consumer health data, as the My Health My Data Act requires.
This policy is written for Washington's My Health My Data Act. We apply the same rules to the consumer health data of residents of Nevada under Nevada SB 370.
The business responsible is ФОП Sofiia Serhiivna Hetman (Гетьман Софія Сергіївна), ЄДР record number 2011600000000112030, Microdistrict 2, building 46, Lozova, Kharkiv region, 64606, Ukraine, admin@sofiayuzu.com. We are a sole trader. We have no affiliates — no parent, no subsidiary, no commonly controlled company.
We do not sell consumer health data. We do not use it or share it for advertising.
1. Categories of consumer health data we collect, why, and how we use it
All of it is entered by you, all of it is optional, and we collect it only to run the features of the tracker that you switch on.
| Category | What it is | Why we collect it and how it is used |
|---|---|---|
| Food and drink intake | Meals, portions, nutrients, water | To keep your diary, count nutrients against your targets, and show them back to you |
| Body measurements | Weight, and body photographs if you upload them | To record and chart change over time at your request |
| Sleep and physical activity | Sleep, steps, gym workouts, including figures read from a screenshot you upload | To record and chart them |
| Reproductive and sexual health | Menstrual cycle data, pregnancy-test and ovulation-test entries, discharge and vaginal symptoms, and sexual-activity entries if you use them | To run the cycle tracker and the well-being chips you switched on. Nothing here is used for anything else, and none of it is ever shared for advertising |
| Bodily functions | Bowel movement records | To run that tracker, if you use it |
| Mental and emotional state | Mood entries, including ones about low mood, obsessive thoughts and self-criticism; free-text well-being notes | To record them and show them back to you. Notes are never sent to any third party |
| Tests and measurements | Blood laboratory values, units and reference ranges, and the laboratory report file itself if you upload one | To transcribe the values you asked us to transcribe and to store them for you |
| Medications and supplements | Names, doses, composition | To keep your medicine list and, if you ask, to look up a general pharmacological class |
| Data we derive | Calorie and protein targets, charts, streaks, correlations, and a monthly meal plan draft | Calculated arithmetically from what you logged; the meal plan is drafted and then read by a person before it reaches you |
We do not collect precise location, and we do not buy, receive or infer health data about you from anyone else.
We do not use consumer health data for advertising, for profiling, for automated decisions about you, or to train any AI model.
2. Categories of sources
- You, directly, when you type or dictate an entry in the app.
- Files you choose to upload: laboratory report PDFs, photographs of laboratory forms, doctor's notes or prescriptions, photographs of meals, labels and packages, body photographs, and screenshots of step or sleep counts.
- Our own calculations from the entries above.
We collect consumer health data from no other source.
3. Categories of consumer health data we share, and who receives it
Under this Act, giving data to a service provider that processes it only on our instructions and under a written contract is not "sharing". We use such providers, and each receives the categories in section 1 to the extent it needs.
| Recipient | Category of recipient | What it receives | Contact |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database and file storage provider | All stored consumer health data | 101 Townsend St, San Francisco, CA 94107, USA |
| Clerk, Inc. | Sign-in provider | No consumer health data; account and session data only | 660 King Street, Unit 345, San Francisco, CA 94107, United States |
| Anthropic PBC | AI provider, transcribing what you send it | Only what you choose to send: the text you typed, the photographs and documents you upload. No name, no email, no account identifier | 548 Market St, San Francisco, CA 94104, USA |
| Apple, Google, Mozilla | Push services of your browser or phone | Notification delivery: only the notification text and your device's subscription endpoint. Reminders are written so they reveal nothing on a lock screen — they say you have a reminder, and the detail is inside the app | Each company's own privacy page |
| Your browser or phone maker (Apple, Google) | Speech-to-text when you dictate a meal | The audio you dictate, processed by your own device's speech service — never by us | Your device maker's privacy page |
Each of these acts as our processor under a written contract, is bound to use the data only for us, and is required to give your data the same or equal protection as this policy states. We will send you a copy of any of those contracts on request. The one exception in that table is the last row: your device's speech service runs for you, not for us, we have no contract with it, and the audio never reaches us — we receive only the finished text.
One recipient is not a processor. To have a monthly meal plan reviewed by a person, the draft plan, your calorie and protein targets, your goal, your allergy list and your account identifier are sent to a private chat on Telegram Messenger Inc. (an instant-messaging company acting on its own account, with which no data processing agreement exists). Your name and your email address are not sent. Under this Act that is sharing, and we ask for your separate consent before it happens.
Because there is no contract binding Telegram, the protections described in this policy do not follow the data there: the message travels through servers outside the United States, authorities in the countries it passes through may be able to reach it, and rights described here may be hard to enforce against Telegram. That is the specific risk of this one feature. If you do not consent, do not use the meal-plan feature; nothing else in the app is shared with Telegram.
4. Your rights, and how to use them
Write to admin@sofiayuzu.com with the subject line "Washington health data request". There is no charge, and you do not need an active subscription — these rights work whether or not you are a paying user.
You have the right to:
- Confirm whether we collect, share or sell your consumer health data, and to access it, including a list of all third parties and affiliates we have shared or sold it to, with contact information for each;
- Withdraw your consent to our collection of your consumer health data, and separately to our sharing of it. Withdrawing stops that processing going forward. It does not delete your account, and it does not undo processing that already happened while your consent was in place;
- Delete your consumer health data.
We answer within 45 days of receiving the request. If the request is complex we may need one further 45-day extension, and we will tell you inside the first 45 days if we do, and why.
For everything else: we usually answer within a week, and billing disputes and anything complex can take up to two weeks. Requests about your personal data are answered within one month (45 days if you are making a request under Washington State law), and any refund we owe you is paid within 14 days of your notice.
If we refuse a request, we will tell you why and how to appeal. Appeals go to the same address and are decided within 45 days. If we deny the appeal, we will give you a way to complain to the Washington State Attorney General at www.atg.wa.gov/file-complaint.
We may need to confirm that you control the account's email address before we act. That is to stop someone else obtaining your health data, and it is the only verification we do.
5. What deletion actually does
When you ask us to delete your consumer health data:
- we delete it from our live systems and from our file storage;
- we instruct every processor named in section 3 to delete their copies, and we tell any third party we shared it with to do the same;
- we do not use backups to bring deleted data back. Our database provider keeps a rolling point-in-time backup that is always on and that we cannot switch off, with a window of 30 days. Copies inside that window are overwritten on the provider's own schedule, and if we ever had to restore from a backup we would re-apply every deletion made in the meantime.
We say this plainly rather than promise that deletion is instant and total, because it is not.
6. Changes
If we start collecting a category of consumer health data, using it for a new purpose, or sharing it with a recipient that is not listed above, we will update this page and ask for your consent again before we do it — not after.
Last updated: 10 September 2026 · ФОП Sofiia Serhiivna Hetman (Гетьман Софія Сергіївна) · ЄДР 2011600000000112030 · Microdistrict 2, building 46, Lozova, Kharkiv region, 64606, Ukraine · admin@sofiayuzu.com