Consumer Health Data Privacy Policy

Last updated: May 11, 2026

This Consumer Health Data Privacy Policy ("CHDPP") describes how Pearl collects, uses, shares, and protects consumer health data as defined by the Washington My Health My Data Act (RCW 19.373) and analogous laws (Nevada SB 370; Connecticut PA 22-15 §6). It applies to all users regardless of jurisdiction.

This policy is separate from, and supplemental to, our general Privacy Policy. Where they conflict regarding consumer health data, this CHDPP controls.

1. Categories of Consumer Health Data We May Process

2. Sources We Collect From

3. How We Use Consumer Health Data

We do not use your consumer health data to train AI models, for targeted advertising, or for any purpose unrelated to providing the service you requested.

4. Sharing

4.1 Categories of third parties

4.2 Affiliates

Pearl has no affiliates. If that changes, this policy will be updated and you will be re-prompted for consent.

4.3 Sale of consumer health data

We do not sell consumer health data. Any future sale would require a separate, written, signed authorization from you (RCW 19.373.030). The signed-authorization mechanism is not currently implemented because no sale occurs.

5. Consent

Before Pearl collects or processes consumer health data, we ask for opt-in consent. Each active category (health-data processing, AI processing, analytics, data sharing, age attestation) is consented to separately. Conversation cloud sync is disabled; health conversations stay on this device. Consent is recorded in a versioned local ledger; bumping the policy version forces a fresh prompt.

Pearl also collects a limited set of essential operational data — non-health signals about how the app is running (app opened, onboarding completed, errors and performance) — to operate and improve the service. This data is pseudonymous, never includes consumer health data or any content, and is therefore not consumer health data under this policy. It runs by default on a necessary-operations basis, honors your browser's Do Not Track setting, and can be turned off entirely in Privacy Settings. The separate analytics opt-in above governs feature-level behavioral analytics, which stays off unless you choose it.

6. Your Rights

You have the right to:

6.1 How to make a request

Submit requests via the in-app Help & Feedback form. Include enough information for us to verify the request without requesting additional sensitive data. If Pearl provides a dedicated privacy email in your beta invitation, you may use that address too.

6.2 Response timing

We respond within 45 days. We may extend once by 45 days for complex requests, with notice.

6.3 Appeal

If we deny a request, you may appeal by replying to our denial notice. We will respond to the appeal within 45 days. If denied on appeal, you may submit a complaint to the Washington State Attorney General at atg.wa.gov/file-complaint, or to your state's analogous authority.

7. Security

8. Retention

9. Age

Pearl is for users 18 and older. We require an age-range attestation before collecting any consumer health data. If we learn we have collected data from a user under 18, we will delete it.

10. Changes to This Policy

Material changes bump the policy version. The next time you open Pearl, you will be re-prompted for consent on the affected categories. The version history is recorded in the consent ledger.

11. Contact

Pearl privacy requests
Use the in-app Help & Feedback form for fastest response.