Consumer Health Data Privacy Notice
The short version
The wellness protocols you save and the creators you follow can reveal a health interest, so we treat that activity as consumer health data. We use it to provide and secure the Platform. We never sell it or share it for advertising or profiling.
1. What this notice covers
This notice explains how MyProtocol LLC, a Connecticut limited liability company that operates MyProtocol, handles consumer health data, including under Washington’s My Health My Data Act and similar laws in other states. MyProtocol LLC is the controller responsible for the consumer health data described here. This notice sits alongside our Privacy Policy, which covers all of your personal information. Where this notice and the Privacy Policy address the same topic, this notice controls for consumer health data.
MyProtocol is a place to publish and follow wellness routines. We are not a healthcare provider, and we do not provide medical advice or maintain medical records.
2. What we treat as consumer health data
We do not ask you for diagnoses, conditions, or medical history. Even so, some of your activity can reveal an interest in a health or wellness topic, and we treat the following as consumer health data:
- The wellness protocols you save.
- The creators you follow.
- The collections you build.
- Any health-related information you choose to write into a protocol, note, comment, discussion, or reply.
- Technical request data that may reveal which wellness page was requested, such as an IP address, browser information, and the requested URL.
3. Where this data comes from
This data comes from you, through the actions you take on the Platform: saving protocols, following creators, building collections, and publishing content. We do not buy health data about you from data brokers or other outside sources.
Technical request data comes automatically from your browser or device when you ask the Platform to load a page. We do not use that request data to infer or identify a diagnosis or health condition, and we do not maintain it as an account-linked history of the protocol pages you view.
4. How we use it
We use consumer health data only to:
- Provide the features you ask for, such as saving a protocol or following a creator.
- Show you your saved protocols, followed creators, and collections.
- Keep the Platform secure and prevent abuse.
- Comply with legal obligations.
5. What we never do with it
- We never sell it.
- We never share it for advertising, cross-context behavioral targeting, or profiling.
- We never provide it to data brokers.
- We never use it to build advertising profiles, and we run no third-party analytics or ad pixels on the Platform.
6. Who can access it
Your saves, creator follows, and collections are stored in the database provided by Supabase, which also provides authentication and file storage under a contract that limits it to running the Platform for us. Vercel hosts and delivers the Platform. It processes your IP address, browser information, and requested URL in technical request logs used to deliver and secure the site. We do not maintain an account-linked history of the protocol pages you view. We do not transmit your saves, creator follows, or collections to advertising networks, analytics providers, or data brokers.
Text you submit for publication, including a protocol, community note, comment, discussion, or reply, is screened for safety and checked for duplicates by OpenAI as our service provider, as described in our Privacy Policy. We may also disclose data where required by law or to protect rights and safety.
7. How long we keep it
We keep account-linked consumer health data for as long as your account is active, so the Platform can keep showing you your saved protocols, followed creators, and collections. Technical request data is processed in hosting logs for delivery and security under the provider’s operational retention settings; we do not keep it as account-linked wellness-view history. When you delete your account, the account-linked data is deleted with it: your account is deactivated immediately, you can restore it for 30 days, and the permanent deletion completes within 45 days of your request, with residual copies leaving routine backups within about a week after that. Two narrow exceptions: if your activity triggered a notification in another member’s inbox, for example when you follow a creator, that notification may remain in their inbox; and if content you wrote was the subject of a moderation action or a copyright notice, our record of that action can include a copy or description of the content and is kept for the period described in our Privacy Policy. You can also remove individual items at any time by unsaving a protocol, unfollowing a creator, or deleting a collection.
8. Your rights
For consumer health data, you have the right to:
- Confirm and access. Confirm whether we hold consumer health data about you and access it.
- Delete. Request that we delete your consumer health data.
- Withdraw consent. Withdraw any consent you gave to collect or share it. Withdrawing consent may mean some features no longer work.
To make a request, email privacy@myprotocol.com. We may need to verify your identity first, and we will respond within the timeframe required by applicable law.
Appeals. If we deny your request, you may appeal by replying to our decision or writing to privacy@myprotocol.com again. We will respond to your appeal in writing. If we deny the appeal, you may contact the Washington State Attorney General at atg.wa.gov/file-complaint.
9. Changes to this notice
We may update this notice from time to time and will update the “Last updated” date when changes are posted. For material changes, we may provide additional notice.
10. Contact
MyProtocol LLC is the controller responsible for this notice. If you have questions or wish to exercise your rights, please email privacy@myprotocol.com.
