Consumer Health Data Privacy Policy
Status: draft — legal-owner-inputs development fixture; not for release
Effective date: {{owner:effective_date}}
Version: 2026-10-05.1
This policy explains how {{owner:company_legal_name}} ("Gemnd", "we", "us") collects, uses and shares consumer health data in the Gemnd app and on our website.
Consumer health data is personal information that is linked, or can reasonably be linked, to you and that identifies your past, present or future physical or mental health. It includes what we infer or derive about your health, including by algorithms or machine learning.
Washington's My Health My Data Act (RCW 19.373) requires this policy. We follow it for every Gemnd user, wherever you live, and we give everyone the rights in section 5.
Our Privacy Policy covers the other personal information we handle, including what Nevada's consumer health data law asks us to tell you.
In the app, this policy is at Settings → Your data and devices → Consumer health data privacy policy.
1. Consumer health data we collect and how we use it
Gemnd is an AI companion that you talk to by text and voice, and that remembers you. You decide what to tell your companions. When you talk about your health, we collect it.
What you tell your companions about your health
What it is. Anything you type, dictate or say in a call about your physical or mental health. For example:
- conditions, illnesses, injuries, disabilities and symptoms;
- mood and emotional wellbeing, such as depression, anxiety or loneliness;
- medications, treatment, therapy, surgeries and procedures;
- sexual or reproductive health, such as contraception, pregnancy, fertility, sexual function or sexually transmitted infections;
- gender-affirming care.
It also includes your companion's replies and your conversation titles when they repeat or refer to what you said. It also includes anything about your health you write into a selfie request or a custom look.
How we use it.
- To write your companion's replies, in chat and in calls.
- To speak your companion's replies aloud, in calls and when you have a reply read aloud.
- To search the web when your companion needs current information to answer you. The search words your companion writes can reflect what you told it.
- To keep your conversation history, so you can read it and your companion can pick up where you left off.
- To form memories, as described below.
- To create your companion's pictures and videos when your selfie or look request mentions your health, and to check them against our content rules.
- To run automated safety checks on messages, replies and requests, so that companions stay within our content rules and Gemnd can show you crisis resources when you may be at risk.
Memories, notes and summaries about you
What it is. Health facts and summaries that Gemnd's AI creates from your conversations, such as "takes medication for anxiety" or "had knee surgery in March". This includes:
- memories you ask your companion to keep or correct;
- notes your companion saves about you, including a short profile with your name, your work and an "about you" description;
- summaries of earlier conversations;
- a search index of your memories that our own systems compute.
How we use it. So your companions remember what you have shared, stay consistent with you, and can bring it up when it matters. That includes the replies, spoken replies and web searches described above.
You can see, edit, stop using or forget each saved memory in Memory. Your profile notes, conversation summaries and the search index are not shown there. They are deleted when you delete your account, or sooner if you ask us (section 5).
Health details in your companion settings
What it is. Anything about your health that you write into a companion's settings, such as how you would like to be supported on a hard day, or a topic to avoid. It also includes changes your companion makes to its own settings because of something you said, together with the words that prompted the change.
How we use it. To shape how your companion talks with you.
Safety signals
What it is.
- A record that Gemnd showed you crisis resources, such as the 988 Suicide & Crisis Lifeline, after one of your messages.
- A record that an automated safety check found signs of distress or a risk of self-harm in a message. This record keeps a one-way fingerprint (a hash) of what the check looked at, never its text.
- Entries in our operational logs for each automated safety check, including the score it gave for signs of self-harm, and a note when a safety response was given. They carry coded identifiers and no message text.
How we use it. Only to show you crisis resources, to keep Gemnd safe, and to meet laws that require us to detect and respond to signs of suicidal thoughts or self-harm.
If the law requires us to report how often we showed crisis resources, we will report only totals that cannot be linked to you, and we will not try to re-identify them.
Reports you send
What it is. If you report a companion's reply, selfie or custom look, we keep what you reported and any note you add. Either may contain health information.
How we use it. So a person can review the report, and so we can improve our safety rules.
Your voice, when your iPhone can't transcribe it
What it is. Gemnd turns your speech into text on your iPhone whenever your iPhone can. When it can't, your voice is streamed over an encrypted connection to our speech-recognition provider, which turns it into text. In a call, the audio passes through our call service on the way.
How we use it. Only to turn your speech into text.
- We keep the text as part of your conversation. We do not keep the audio, and we do not record calls.
- Our speech provider is set not to keep the audio after transcribing it, and not to use it to improve its models.
- Washington law can treat some voice recordings as biometric data. Gemnd does not create voiceprints or any other template of your voice, and never uses your voice to identify you.
Messages you send us
What it is. Anything about your health in an email or letter you send us, including a privacy request.
How we use it. To answer you and to handle your request.
Only these uses
We use consumer health data only for the purposes in this section.
- We do not use it for advertising or marketing.
- We do not sell it.
- We do not use it to set your price or your plan.
Any new purpose, such as training AI models, would first need an updated policy and your consent.
2. Where we get it
- From you: what you type, say and choose in Gemnd, and what you send us.
- From your iPhone's microphone: only while you dictate a message or are in a call.
- From our systems and our processors' AI models: they create memories, notes, summaries and safety signals from what you share.
We do not buy consumer health data or receive it from other companies.
3. Who we share it with
Third parties and affiliates
We do not sell consumer health data, and we do not share it with any affiliate or with any company for its own use. The only third parties that may receive it are:
- Courts, law enforcement and other government agencies, only when the law compels us, such as a valid court order, search warrant or subpoena, and only the consumer health data it requires. We review every request first and, unless the law forbids it, we tell you before we disclose. [counsel: the Washington My Health My Data Act has no express exception for legal process (RCW 19.373.100(3)); confirm this bullet before publication.]
- Others who help us respond to security incidents and illegal activity, such as law enforcement, a person or company harmed by fraud or illegal activity, or a security firm. We disclose consumer health data to them only to prevent, detect, protect against or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activity, or activity that is illegal under Washington or federal law; to keep our systems secure; or to investigate, report or help prosecute those responsible. We disclose only what that purpose needs.
We do not disclose consumer health data to enforce our Terms of Use or to defend legal claims without your consent.
If Gemnd is merged with or sold to another company, a company that takes over consumer health data must comply with Washington's My Health My Data Act and this policy.
Processors
Our service providers ("processors") process consumer health data on our behalf, only to provide Gemnd to you. They do so under binding contracts that set our instructions and forbid any other use. Washington law does not treat processors as third parties.
These are the kinds of processors we use, and the consumer health data each one receives:
- AI model hosting and routing: your conversations, memories, notes and companion settings, to write replies, memories and summaries.
- Text content-safety checks: your messages, your companion's replies, your companion settings, and the words of selfie and look requests you write.
- Speech recognition and voice synthesis: your voice when your iPhone can't transcribe it, and the text of replies your companion speaks aloud.
- Call audio service: the audio of a call while it is active. That is your companion's voice, and your voice when your iPhone can't transcribe it.
- Image and video generation and image safety checks: the words of a selfie or look request you write, when they include anything about your health, and the images and videos made from them. Our image and video generation providers, listed on the Subprocessors page, keep request data and generated files for [pending: media provider retention].
- Web search for companion answers: search queries your companion writes, which can reflect what you have told it.
- Cloud hosting, databases and storage: all of the consumer health data in section 1.
- Operational logging and monitoring: the safety log entries described in section 1, including self-harm scores, with coded identifiers and no message text.
- Support mailbox: messages you send us.
Our Subprocessors page names our current processors and says what each one does. In the app, it is at Settings → Your data and devices → Subprocessors.
4. Your consent
Before we collect it
Before your first conversation, Gemnd asks for your consent to collect and use consumer health data as this policy describes. It asks on the Allow AI processing screen. That screen is separate from our Terms of Use and Privacy Policy.
The screen tells you:
- why we send what you write and say to AI providers: to reply to you, speak, remember you and create your companion's look;
- who receives it: each AI provider that writes, checks, voices or illustrates your companion and what it does, with a "Who processes your data" link to our Subprocessors page, which names every processor, including our web search provider. They process it only on our instructions;
- how to withdraw your consent: Settings → AI processing → Turn off.
You agree by tapping Allow. We record that you agreed and when.
[counsel: the AI processing screen does not name the consumer health data categories, has no checkbox and does not link this policy; confirm whether it meets RCW 19.373.030(1)(b) consent before publication. Same open question as the Privacy Policy's sensitive-data note.]
If you do not agree, you can keep your account, download your data or delete it. Your companions cannot reply to you, though, because they need to process what you say.
We collect consumer health data only with that consent, or where collecting it is necessary to provide something you asked for, such as answering an email or letter you send us.
Sharing
Apart from the disclosures in section 3, we do not share consumer health data with third parties or affiliates. If that ever changed, we would ask for your separate consent first.
Selling
We do not sell consumer health data, and we do not ask anyone to authorize a sale.
Withdrawing consent
Go to Settings → AI processing → Turn off.
- We stop using AI to process what you write and say, stop forming memories and safety signals from it, and stop sending your conversations to our processors, right away. We still keep anything you send us yourself, such as an email.
- Chat, calls, memory updates and avatar creation pause until you turn AI processing back on.
- Anything already sent to a processor before you turned it off cannot be recalled.
- Your conversations and memories stay until you forget memories, delete your account or ask us to delete them. You can still download or delete your data.
To stop only new memories, turn off Remember new conversations in Memory.
5. Your rights and how to use them
Your rights
- Confirm and access. You can find out whether we collect, share or sell your consumer health data, and get a copy of it. In the app: Settings → Your data and devices → Download my data. The download includes your conversations, memories, notes, companion settings, safety records and reports. It does not include the safety entries in our operational logs or what you wrote in an email to us. For a copy of those, email {{owner:privacy_email}} and we will send it to you.
- Get the list of third parties and affiliates. If we have ever disclosed your consumer health data to a third party under section 3, we tell you which one and how to contact it. On request, we also send you our list of processors and how to contact each one.
- Withdraw consent and stop collection. See section 4.
- Delete.
- One memory: Memory → open the memory → Forget this. This removes the memory and its earlier versions. The messages it came from stay in your conversation history. To delete those too, email us.
- Everything: Settings → Delete account.
- Anything else, such as specific messages, your profile notes or conversation summaries: email us.
How deletion works. We delete your consumer health data from our live systems within 30 days after we confirm that the request comes from you, and in every case within 45 days after we receive it (60 days if we extend the deadline as explained under "When we answer"). That includes the safety entries in our operational logs, which are deleted automatically within {{owner:log_retention_days}} days. We notify every processor and any other recipient we disclosed it to, so they delete their copies too. OpenAI's abuse-monitoring logs expire on their own within 30 days, and our image and video generation providers keep request data and generated files for [pending: media provider retention]. Our Privacy Policy explains when backup copies expire. We keep a record of your request and our answer for 24 months, and it holds only what you wrote to us and what we replied.
How to make a request
- Use the in-app controls above.
- Email {{owner:privacy_email}} from the email address on your Gemnd account.
- Write to {{owner:company_legal_name}}, {{owner:mailing_address}}.
To protect your data, we confirm that a request comes from you before we act on it, for example by sending a code to your account's email address.
- You do not need to create an account to make a request. If you already have one, we may ask you to use it.
- If we cannot confirm that a request comes from you, we will ask you for more information.
- Someone you authorize can make a request for you. We will confirm it with you directly.
When we answer
We respond within 45 days after we receive your request. If we need more time because a request is complex, or because you have sent several, we will tell you why within those 45 days, and we will take no more than 15 more days.
Requests are free. We may decline a request that is manifestly unfounded, excessive or repetitive, and if we do, we will tell you why.
Appeals
If we decline a request, in whole or in part, you can appeal:
- reply to our decision email with the word "Appeal" in the subject line; or
- email {{owner:privacy_email}} with "Appeal" in the subject line.
We will tell you in writing, within 45 days, what we did and why.
If we deny your appeal, you can complain to your state attorney general:
- Washington: Office of the Attorney General, file a complaint online.
- Anywhere else: the attorney general of the state where you live.
6. Contact us
{{owner:company_legal_name}}
{{owner:mailing_address}}
Email: {{owner:privacy_email}}