Consumer Health Data Privacy Policy
Effective August 24, 2026
This Consumer Health Data Privacy Policy describes how reThrive Labs LLC ("we," "us," "freddy") collects, uses, shares, and protects "consumer health data" as that term is defined under the Washington My Health My Data Act (RCW 19.373) ("MHMDA"). It supplements our general Privacy Policy and our Terms of Service, both of which remain in effect. Where this policy and the general Privacy Policy address the same subject, the more protective provision applies to Washington consumers.
This policy is also intended to address comparable consumer health data provisions under Nevada's SB 370 and Connecticut's Senate Bill 3 for consumers in those states.
Categories of consumer health data we collect
We collect the following categories of consumer health data, all of which originate from the data sources that you elect to connect to freddy:
- Biometric data: heart rate, heart-rate variability, blood oxygen saturation, body temperature, electrodermal activity, and other physiological measurements reported by your connected devices.
- Sleep data: sleep stages, sleep duration, sleep timing, sleep efficiency, and related metrics.
- Activity and exercise data: workouts, steps, distance, calories, training load, recovery metrics, and related physical-activity measurements.
- Precise geolocation: when you connect a source that records the route of an activity (for example a GPS-enabled wearable or training platform), the activity data we receive can include precise location coordinates, such as the start point and the recorded route of a run or ride. This is part of the health data you connect: we store it encrypted, and it is available to you and to the AI assistant you connect through your personal MCP endpoint, the same as any other metric. We do not use it to determine, track, profile, or infer your location or your presence at any place, and we do not derive geofences from it.
- Body measurements: weight, body composition, height, and similar measurements where reported by a connected provider.
- Nutrition and dietary data: energy, water, macronutrients (protein, carbohydrates, fats), micronutrients (vitamins and minerals), caffeine, and related dietary intake, where reported by a connected source.
- Continuous glucose data: blood-glucose readings and trends from continuous glucose monitors, where you connect a CGM provider.
- Mental and behavioral health data: mindfulness and meditation sessions, and related mental-wellbeing metrics, where reported by a connected source.
- Medication and treatment data: medication and treatment information such as insulin delivery and inhaler use, where reported by a connected source.
- Reproductive and cycle data: menstrual-cycle and related fertility data, where reported by a connected provider.
- Device-derived inferences: derived metrics computed by the connected provider (e.g., readiness scores, recovery scores, sleep scores) that we sync alongside the underlying measurements.
- Environmental data: air quality, radon, CO₂, particulate matter, temperature, and humidity from connected home sensors, where it relates to your living environment and wellbeing.
- Other health-related data: as we add support for new sources and devices, additional categories of health, fitness, physiological, reproductive, mental-wellbeing, and related data you choose to connect, which we treat as consumer health data under this policy where it identifies your health status. We only ever collect the categories your connected sources report and that you authorize.
- Account identifiers: email address, the OAuth identifiers or API keys associated with your connected providers, your freddy account identifier, and — if you allow notifications in the freddy app — the push notification token for each device you sign in on, with its install identifier, app and OS version, and time zone — to the extent these are linked to the health data above and therefore constitute "consumer health data" under MHMDA's broad definition.
Sources of consumer health data
All consumer health data in freddy is sourced from the third-party accounts and devices that you connect to your freddy account through OAuth or an API key you supply. We do not purchase consumer health data, we do not infer it from non-health behavioral data such as purchases or browsing, and we do not collect it through pixels, cookies, or other passive tracking. The data sources available to connect are shown in the app and described in our Privacy Policy under "Connected data sources".
How we use consumer health data
We use consumer health data to operate the personal MCP endpoint you have signed up for:
- To sync data from the providers you have connected and store it under your account.
- To return that data to the AI client you have connected to your personal MCP URL, at your direction.
- To operate basic account functions such as authentication, audit logging of MCP requests, and billing for the optional paid plans.
- Support and troubleshooting: if you ask us for help in the in-app support chat, the Anthropic Claude model that helps us draft replies is shown your support conversation, any screenshots you attach, and basic account details: your plan, the date you signed up, and how many sources you have connected. You can additionally switch on "Help us debug this" to let us look into a problem. While it is on, our support tools show technical information about your connected sources and about the AI apps you have connected to freddy: which sources are connected, sync status, error codes, for each metric a source has sent how many records it holds and the dates they cover, and which AI apps hold access along with when they last asked freddy for something. The model that helps us draft replies is shown the connected-source half of that only. Never your health values, and never the questions you ask. "Help us debug this" is off unless you turn it on, it switches itself off when the conversation is closed, and you can turn it off yourself at any time.
We do not use consumer health data for marketing, advertising, behavioral targeting, profiling, automated decision-making, research, or model training. We do not infer health conditions from non-health behavioral data such as purchases, browsing, or location.
With whom we share consumer health data
We do not "sell" consumer health data, and we do not "share" consumer health data as those terms are defined under MHMDA (RCW 19.373.010(20), (22)). We will not sell or share consumer health data without first obtaining a valid authorization that complies with RCW 19.373.030.
We disclose consumer health data only to the limited set of service providers ("processors") that are strictly necessary to deliver the service, each of which is bound by contractual confidentiality obligations and processes the data only on our instructions:
- Railway — hosting and database infrastructure (United States). Stores the encrypted database.
- Stripe — payment processor for the optional paid plans bought on our website, both PRO subscriptions and one-time BELIEVER purchases (United States). Receives only billing-related data, not consumer health data.
- Resend — transactional email provider (United States). Receives email addresses and transactional message content; does not receive consumer health data.
- Sentry — application error monitoring (United States). Sentry receives crash stack traces and request URLs only; request bodies, breadcrumb payload data, and additional context attached to errors are filtered out before transmission. Sentry does not receive consumer health data.
- Anthropic — Claude models used to help answer support requests (United States). Receives your support conversation, any screenshots you attach, and basic account details: your plan, the date you signed up, and how many sources you have connected. While "Help us debug this" is on, it also receives technical information about your connected sources. We do not send it your health values.
- Apple — push notification delivery to iPhone and iPad, and payment handling for the optional PRO subscription bought in the freddy app on iPhone or iPad (United States). Receives a device token and the notification text, and, for purchases, billing-related data only. We do not send it your health values.
- Google — push notification delivery to Android devices, and payment handling for the optional PRO subscription bought in the freddy app on Android (United States). Receives a device token and the notification text, and, for purchases, billing-related data only. We do not send it your health values.
- RevenueCat — subscription management for purchases made through the App Store or Google Play (United States). Receives your account identifier, the purchase records for your subscription, and technical connection data such as your IP address. Does not receive consumer health data.
- Cloudflare — edge network providing DNS, TLS termination, and protection against denial-of-service and abusive traffic (globally distributed network; company incorporated in the United States). Decrypts and inspects requests and responses in transit, which can include consumer health data. It does not store consumer health data: responses carrying it are not cached at the edge. Where a request triggers one of its security protections, Cloudflare records that request's metadata (IP address, user-agent string, and URL path) in its own security log for a short period.
We also transmit consumer health data, at your direction, to the AI client you have connected to your MCP URL. That client is acting as your agent, not as our processor or affiliate, and is governed by its own terms and privacy policy. You authorize that transmission by connecting the client and by issuing queries; you can withdraw that authorization at any time by disconnecting the client or deleting your freddy account.
We do not share consumer health data with affiliates (we have none), advertisers, data brokers, or any third party other than as described above. If we receive a valid legal process compelling disclosure of consumer health data (such as a subpoena or court order), we will, where legally permitted and operationally feasible, notify you in advance so you can challenge the request.
Your rights under MHMDA
As a Washington consumer, you have the following rights with respect to your consumer health data:
- Right to confirm whether we are collecting, sharing, or selling your consumer health data, and to access that data.
- Right to a list of all third parties and affiliates with whom we have shared or sold your consumer health data. We do not sell or share consumer health data, so this list comprises only the processors named in the section above.
- Right to withdraw consent for the collection and sharing of your consumer health data.
- Right to deletion of your consumer health data from our records and from those of our processors.
You can exercise these rights at any time:
- Access: via your personal MCP endpoint, the dashboard data viewer, or the CSV export tool at your dashboard. You may also email [email protected] for a formal Subject Access Request.
- Withdraw consent — per provider: disconnect the provider from your dashboard. All data synced from that provider is deleted immediately.
- Withdraw consent — account-wide: click Delete account from your dashboard. This action takes effect with one click + a confirmation prompt — the same level of effort as the consent click you made at signup — and permanently deletes your account record and all consumer health data within 30 days. We provide this as a one-action withdrawal mechanism to satisfy MHMDA's requirement (RCW 19.373.030) that consent withdrawal be at least as easy as consent.
- Subject access or other requests by email: contact [email protected]. We respond within 45 days of receipt and may extend by an additional 45 days where reasonably necessary, with notice to you within the original 45-day window.
We will not discriminate against you for exercising any of these rights — there is no premium tier you lose access to, and no functional degradation other than the loss of data syncing from providers you have disconnected.
You can appeal a denial of any rights request by emailing [email protected] with the subject line MHMDA appeal. We will respond to your appeal in writing, with reasons, within 45 days of receipt. If we deny your appeal, you may file a complaint with the Washington State Attorney General at atg.wa.gov/file-complaint.
How we obtain your consent
We collect consumer health data only after you have given separate, specific, freely given, unambiguous, opt-in consent — distinct from your acceptance of our general Terms of Service. At signup, you check a separate consent box authorizing freddy to collect and process consumer health data from the providers you choose to connect. You then provide additional, specific consent by connecting each individual provider through that provider's own OAuth flow or by entering an API key. You can withdraw consent for any provider at any time by disconnecting it.
Users who created freddy accounts before this policy's effective date gave their initial consent under our prior consent framework, which we treat as preserved here. If you would like to refresh your consent under this updated framework, please email [email protected].
Security and retention
Consumer health data is stored in a PostgreSQL database on infrastructure located in the United States. Requests in transit are decrypted and inspected at the edge location nearest you, which may be outside the United States; no consumer health data is retained there. Provider credentials (OAuth tokens, API keys) and the contents of synced health metrics are encrypted at the application layer using AES-256-GCM before being written to the database. Some larger items — chiefly the full raw payloads of certain activity records — are held in a separate object-storage system rather than inline in the database; that storage is on the same United States infrastructure and the payloads are encrypted with the same AES-256-GCM encryption before being written to it. All connections use TLS. Your MCP endpoint is served only over HTTPS.
Consumer health data is retained for as long as the relevant provider is connected and your account is active. Disconnecting a provider deletes that provider's data immediately. Deleting your account deletes all consumer health data within 30 days.
Support chat content — your messages, any screenshots or other files you attach, and the reply drafts our support tools build from them — is retained while your account is active and deleted when you delete your account. A draft is a copy of the information it was built from, so any draft built while your "Help us debug this" grant was live is cleared when that grant ends.
Geofencing
freddy does not implement, deploy, or use any geofence around any in-person healthcare facility, mental health facility, reproductive or sexual health facility, or other location where consumer health data might be inferred from a consumer's presence. Where activity data you connect includes precise location coordinates (for example the recorded route of a run or ride), we store that data encrypted as part of your health data, as described under "Categories of consumer health data we collect" above. We never use it to determine, track, or infer your presence at any location, and we do not build geofences from it.
Changes to this policy
If we materially change the categories of consumer health data we collect, the purposes for which we use it, or the categories of recipients with whom we share it, we will update this policy and notify affected consumers by email at the address associated with their account before the change takes effect.
For consumer health data questions or to exercise your rights
[email protected]