
Consumer Health Data Privacy Policy
Consumer Health Data Privacy
Required disclosures for residents of Washington, Nevada, and Connecticut.
Last updated: August 18, 2026
What this policy covers
This Consumer Health Data Privacy Policy explains how Daylogue LLC collects, uses, shares, and protects consumer health data under the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 (NRS Chapter 629), and Connecticut SB 3. It is published separately from our general Privacy Policy as required by those laws. To the extent there is any conflict between this policy and our Privacy Policy, this policy controls for consumer health data.
What we treat as consumer health data
- Check-in and quick-note entries (text and voice transcripts)
- Mood, energy, and stress self-ratings
- AI-generated wellness narratives, summaries, reads, and pattern outputs
- Health metrics you voluntarily connect through Apple Health or Health Connect — sleep, steps, exercise minutes, stand time, walking distance, workout records, mindful minutes, and (only if you separately enable the category) resting heart rate, heart-rate variability, respiratory rate, blood oxygen, body temperature, weight, body mass index, body fat, walking steadiness, sound-exposure levels, and waking temperature
- Life-context notes you provide (for example marking a day as a rest day, travel, illness, or a new baby) and personal experiment records you create
- Inferences derived from any of the above
How we collect it
We collect consumer health data only when you provide it directly through a check-in, journal entry, quick note, voice session, SMS reply (if you opt into SMS), or a connected integration you authorize. We do not buy, license, or otherwise acquire consumer health data from data brokers.
Category-level control.Health-data collection is not one vague toggle. In Settings you choose what Daylogue may notice, per category: Sleep, Activity & movement, Heart & recovery, Mindfulness, Cycle context, Body composition, Mobility, and Sound exposure. Every category except Sleep, Activity & movement, and Mindfulness is off by default and is collected only if you turn it on. Turning a category off stops future collection and processing for that category.
What each category covers.Sleep is hours and quality. Activity & movement is steps, exercise minutes, stand time, walking distance, and workouts. Heart & recovery is resting heart rate, heart-rate variability, respiratory rate, blood oxygen, and body temperature. Mindfulness is mindful minutes. Body composition is weight, body mass index, and body fat. Mobility is walking steadiness. Sound exposure is how loud your surroundings and headphones have been. Cycle context is one measurement, waking temperature — menstrual flow, ovulation results, and sexual activity are available in Apple Health and are never collected. Body composition, Mobility, and Sound exposure are separate from Activity & movement on purpose: sharing a step count is not the same decision as sharing a body weight.
A note about SMS. If you opt into SMS check-ins or quick notes, the content of your text messages necessarily passes through your mobile carrier and our SMS provider (Twilio) in plain text before reaching us — that is exposure to two additional parties on top of a service that already reads your entry text to write narratives and surface patterns. Our outbound messages never include your health details or journal content, and nothing about your body ever appears in a notification preview or on a lock screen.
How we use it
- To provide check-ins, narratives, and pattern features.
- To run AI inference on AWS Bedrock under Daylogue's current service configuration and written terms.
- To transcribe voice through Deepgram under Daylogue's current service configuration and written terms. Current retention terms are listed on the subprocessor page.
- To generate de-identified, aggregated participation and theme metrics for employer-context organization dashboards. In those organizations, owners and administrators never see individual entries, transcripts, or numeric mood scores, whatever sharing settings anyone chooses.
- To disclose specific signals to a solo provider you are working with, where you have turned that signal on for them by name. This is described in full below.
We do not use consumer health data for advertising, profiling for advertising, or to train any AI model.
No AI mode.On supported accounts and platforms, No AI mode prevents newly submitted content from being sent to Daylogue's AI and voice services. It is not a local-only mode: entries still sync to and are stored by Daylogue. Rules-based patterns require a separate choice, use structured fields and eligible accepted manual tags, and omit sensitive tags. Content protected while No AI mode is on is not backfilled if AI is enabled later.
What we never do
- We do not sell consumer health data.
- We do not share it with data brokers.
- We do not use geofencing around any in-person health-care facility, mental-health-care facility, or reproductive- or sexual-health facility for any purpose, including advertising, identification, or notification.
Who we share it with
Sub-processors that are bound by written confidentiality and security obligations and process data on our instructions: Supabase (database), AWS Bedrock (AI inference), Deepgram (voice-to-text), Resend (transactional email), Stripe (payments), and Vercel (hosting). The full list is at /trust#subprocessors.
There is one other kind of recipient, and only if you create it. If you are working with a coach, consultant, or other provider who uses Daylogue Collab, we disclose to that named person whatever you have turned on for them, and nothing else. They are not a sub-processor and do not act on our instructions. The next two sections describe exactly what that means.
Sharing with a provider (Collab)
Collab is for one provider — a coach, consultant, or freelancer — working with their own clients. If a provider invited you to Daylogue, the organization-dashboard rules above do not describe your situation. This does.
Everything starts off. Your provider sees nothing about you until you turn on a specific signal for them by name. There are five, and each one is a separate decision:
- A 7-day average of your mood
- A 7-day average of your energy
- A 7-day average of your stress
- Theme words, drawn from a fixed list of everyday words we maintain — never your own wording, and never a name
- How many check-ins you have written since your last session — a count, never a date and never a time
What your provider never receives, whatever you turn on: anything you write in a journal entry, your voice recordings or their transcripts, your conversations with Daylogue, when you checked in, anything connected to a crisis or to distress we treat as crisis-adjacent, and anything at all about another person they work with.
Turning a signal on is not retroactive. It covers what you write from that moment forward. Entries you wrote before are not disclosed and cannot be reached by changing a setting later.
You can withdraw in one step, at Settings → Sharing, without asking your provider and without giving a reason. It takes effect immediately and stops all future disclosure. It does not undo a disclosure already made, which is why Daylogue keeps a record you can read of every signal that was disclosed and the week it covered.
This is a disclosure, not aggregation. In a workplace or team organization, figures are pooled across a group. A solo practice has no group to pool into, so nothing here is de-identified: it is information about you, going to someone who knows who you are. Even where something is not labeled with your name, they may still recognize it as yours. We do not claim otherwise.
Before any of this begins, you are shown a written authorization that names your provider, lists the exact signals you are releasing, and states what they may not do with them. You are entitled to a copy and can read or download it at any time.
Employer-context organizations are unchanged. Owners and administrators of a workplace, school, or team organization still never receive an individual person's mood, energy, or stress, and no setting makes that possible. Collab is a different arrangement, not a relaxation of that one.
If your provider is a licensed therapist (Collab Clinical)
A separate tier of Collab is open to licensed therapists, and only after they have signed a business associate agreement with us and attested to their license. Everything in the section above still applies: the same five signals, the same defaults, the same one-step withdrawal.
One of your rights is narrower there.California law requires a licensed therapist to keep client records for seven years after your last session — for marriage and family therapists, Bus. & Prof. Code §4980.49, with parallel rules for other license types. Entries you disclosed inside a Collab Clinical engagement are placed under a retention hold in your therapist's custody and kept until that date. They are not removed when you close your Daylogue account, and a deletion request will not remove them before the hold expires.
The hold reaches only the entries actually disclosed. The rest of your account — everything you never shared — is deleted on the normal schedule described under retention and deletion below. You can see what is held about you and until when. You are told all of this in the authorization before you share anything, because it is a real reduction in what you can delete and finding it later would be worse.
Your rights
- Access — request a copy of the consumer health data we hold about you.
- Deletion — request deletion of your consumer health data, including from any subprocessor. If you use Collab Clinical, entries you disclosed to your therapist are the one exception; see that section above.
- Withdraw consent— revoke any consent you gave to collection, processing, or sharing, at any time, with effect for the future. You can also disable individual health categories (Settings → Your Data), withdraw sharing with a provider (Settings → Sharing), delete health-derived patterns and reads, or reset your personal baseline without deleting your journal.
- Appeal — if we decline a request, you may appeal in writing; we will respond within 45 days.
- Authorized agent — Washington residents may designate an authorized agent to make a request on their behalf.
To exercise these rights, email privacy@daylogue.com or use the in-app data request flow at Settings → Data & Privacy.
Retention and deletion
Consumer health data is retained for as long as your account is active. On account deletion, active records are removed immediately and backups are purged within 30 days. Voice audio is never persisted. The transcript is persisted: spoken words become the text of the check-in or reflection they belong to and are then retained and stored on the same terms as anything you type, which are described under Security below.
Security
TLS 1.3 in transit, disk-level AES-256 at the hosting provider, row-level security scoping every query to the account that owns the row, audit logging, entry text kept out of application logs and error reports, and encryption-key management aligned to NIST SP 800-57. Stated plainly, because disk-level encryption is often read as more than it is: entry text is stored in readable form and Daylogue reads it to write your narratives and surface patterns. Daylogue is not end-to-end encrypted and no setting in the product provides it. Some accounts also hold an AES-256-GCM vault copy of journal content; that is an additional copy rather than a replacement, and it does not put the content beyond Daylogue’s reach. Full detail at /trust.
Contact
Daylogue LLC, Privacy Officer
privacy@daylogue.com
Washington residents may also contact the Washington State Attorney General. Nevada residents may contact the Nevada Attorney General. Connecticut residents may contact the Connecticut Attorney General.
Disclaimer
Daylogue is not therapy and is not a replacement for professional mental health care.