Consumer Health Data Privacy Policy
Last updated: May 11, 2026
This Consumer Health Data Privacy Policy ("CHDPP") describes how Pearl collects, uses, shares, and protects consumer health data as defined by the Washington My Health My Data Act (RCW 19.373) and analogous laws (Nevada SB 370; Connecticut PA 22-15 §6). It applies to all users regardless of jurisdiction.
This policy is separate from, and supplemental to, our general Privacy Policy. Where they conflict regarding consumer health data, this CHDPP controls.
1. Categories of Consumer Health Data We May Process
- Symptoms, conditions, diagnoses, and treatments you describe to Pearl.
- Medications, dosages, allergies, and side-effect descriptions you enter.
- Reproductive or sexual health information you choose to share.
- Mental or behavioral health information you choose to share.
- Biometric or measurement data (e.g. weight, blood pressure) you enter.
- Images you upload (e.g. test results, skin photos) — for PNG/JPEG images, EXIF and GPS metadata are stripped before transmission. Other file types (PDF, DOCX, etc.) are uploaded as provided; their internal document metadata is not modified.
- Inferences derived from any of the above, including AI-generated summaries.
- Precise location is not collected. Approximate timezone is recorded with each consent decision for audit only.
2. Sources We Collect From
- Directly from you (chat input, image uploads, profile fields).
- We do not buy, license, or otherwise acquire consumer health data from data brokers or any other third party.
3. How We Use Consumer Health Data
- To answer your questions by relaying your messages to an AI provider you selected.
- To generate summaries, appointment-preparation packets, and exports at your direction.
- To detect crisis signals (self-harm, medical emergency) and surface appropriate referrals.
- To run safety filters (PHI detection) before transmitting data to AI providers.
We do not use your consumer health data to train AI models, for targeted advertising, or for any purpose unrelated to providing the service you requested.
4. Sharing
4.1 Categories of third parties
- AI providers — Anthropic, OpenAI, Google — receive your messages to generate responses. They process data under their respective API terms, which do not train on API traffic by default.
- Infrastructure providers — Netlify (hosting), used only to deliver the web app. No conversation content is stored on our servers in normal operation.
- No advertising networks. No data brokers. No social-graph processors.
4.2 Affiliates
Pearl has no affiliates. If that changes, this policy will be updated and you will be re-prompted for consent.
4.3 Sale of consumer health data
We do not sell consumer health data. Any future sale would require a separate, written, signed authorization from you (RCW 19.373.030). The signed-authorization mechanism is not currently implemented because no sale occurs.
5. Consent
Before Pearl collects or processes consumer health data, we ask for opt-in consent. Each active category (health-data processing, AI processing, analytics, data sharing, age attestation) is consented to separately. Conversation cloud sync is disabled; health conversations stay on this device. Consent is recorded in a versioned local ledger; bumping the policy version forces a fresh prompt.
Pearl also collects a limited set of essential operational data — non-health signals about how the app is running (app opened, onboarding completed, errors and performance) — to operate and improve the service. This data is pseudonymous, never includes consumer health data or any content, and is therefore not consumer health data under this policy. It runs by default on a necessary-operations basis, honors your browser's Do Not Track setting, and can be turned off entirely in Privacy Settings. The separate analytics opt-in above governs feature-level behavioral analytics, which stays off unless you choose it.
6. Your Rights
You have the right to:
- Confirm whether we are processing your consumer health data.
- Access the data we hold about you.
- Delete your consumer health data. The in-app "Delete my data" action wipes local storage on this browser. Use Help & Feedback to request deletion of any operator intake records or vendor records associated with your submissions.
- Withdraw consent for any processing category. The in-app Privacy Settings screen exposes per-category toggles.
- Appeal a denial of a rights request.
6.1 How to make a request
Submit requests via the in-app Help & Feedback form. Include enough information for us to verify the request without requesting additional sensitive data. If Pearl provides a dedicated privacy email in your beta invitation, you may use that address too.
6.2 Response timing
We respond within 45 days. We may extend once by 45 days for complex requests, with notice.
6.3 Appeal
If we deny a request, you may appeal by replying to our denial notice. We will respond to the appeal within 45 days. If denied on appeal, you may submit a complaint to the Washington State Attorney General at atg.wa.gov/file-complaint, or to your state's analogous authority.
7. Security
- Conversation history is encrypted at rest on your device (AES-GCM-256, PBKDF2 200k iterations).
- Health conversations are stored on your device only; Pearl does not store them in cloud conversation storage.
- Network traffic is TLS-protected; HSTS is enforced.
- For PNG/JPEG images, EXIF and GPS metadata are removed before any upload. PDFs and other document uploads are transmitted as provided.
- PHI detection runs before each external AI call to surface and block likely identifiers.
- Audit logs record metadata only (event type, timestamp, consent state, vendor) — never raw chat content.
8. Retention
- Local conversation data: until you delete it, or you clear browser storage.
- Consent ledger entries: retained locally for audit; you can wipe them via "Delete my data."
- Server-side audit logs: 13 months, then purged.
9. Age
Pearl is for users 18 and older. We require an age-range attestation before collecting any consumer health data. If we learn we have collected data from a user under 18, we will delete it.
10. Changes to This Policy
Material changes bump the policy version. The next time you open Pearl, you will be re-prompted for consent on the affected categories. The version history is recorded in the consent ledger.
11. Contact
Pearl privacy requests
Use the in-app Help & Feedback form for fastest response.