Skip to main content

What this policy covers

This policy covers consumer health data: information you enter here that identifies your past, present, or future physical or mental health. On Our System Sanctuary that means the health conditions, allergies, medications, symptoms, triggers, and related notes you choose to record, at the body level or for an individual member of your system.

It exists because Washington State’s My Health My Data Act, and similar laws in Nevada and Connecticut, require a separate policy covering only this. Everything else about your privacy here is on the Trust & Privacy page.

We are not a healthcare provider, a health plan, or a healthcare clearinghouse, so HIPAA does not apply to us. That is not a loophole we are relying on: it is why this policy exists instead.

What we collect, and where it comes from

All of it comes from you. We collect consumer health data only when you type it into a health record yourself. We do not buy it, infer it, receive it from another company, or derive it from anything else you do here.

We do not collect health data from your device, your location, your browsing, or any advertising identifier. There are no advertising identifiers here, because there is no advertising here.

Why we collect it

One purpose: to show it back to you, and to whoever in your system is fronting, inside your own account. That is the entire feature. It is a notebook that remembers.

We do not use it to personalize anything, to train any model, to target anything, or to make any decision about you.

Who we share it with

Nobody, unless you choose it. Specifically:

  • We do not sell consumer health data. We have never sold it and we will not, and the law requires us to say that a sale would need a separate signed authorisation from you, which we would not ask for.
  • We do not share it for advertising, and we run no advertising.
  • Supporters you invite see only the specific items you switch on for them, and nothing else.
  • Our hosting and database provider (Supabase) stores it on our behalf under contract. They do not use it for anything of their own.
  • We would disclose it if we were legally compelled to. If that ever happened and we were permitted to tell you, we would.

Nobody at Our System Sanctuary reads your health records as a matter of course. There is no support tool that opens them.

Your rights

You have the right to know what consumer health data we hold about you and who we have shared it with, the right to have it deleted, and the right to withdraw your consent at any time.

Most of this you can do yourself, immediately, without asking us: the records are in your account, you can read and delete them, and the sharing switches are yours. If you would rather ask us, write to hello@oursystemsanctuary.com and we will answer within 45 days. We will not charge you, and we will not make the experience worse for having asked.

If we ever refuse a request, we will tell you why and how to appeal it. If you are in Washington, you may also complain to the Washington State Attorney General.

How long we keep it, and how it is protected

We keep consumer health data for as long as your account exists, because it is yours and you may want it. Delete a record and it goes; delete your account and all of it goes.

It is encrypted in transit and at rest, access is restricted by database-level rules that apply to every request rather than by an application setting, and it is never included in analytics.

If your health data were ever exposed in a breach, the FTC Health Breach Notification Rule applies to us and we would notify you. That commitment is on the Trust & Privacy page.

Changes to this policy

If we change this policy in a way that affects what we collect, why, or who sees it, we will ask for your consent again rather than assume it. The version number and date at the top of this page always tell you which version is current.

Version 1.0 | Last updated August 4, 2026