Legal
Consumer Health Data Privacy Policy
Effective October 6, 2026
1. About This Policy
This Consumer Health Data Privacy Policy describes how BlockHaven Inc. (“BlockHaven,” “we,” “us,” or “our”) collects, uses, shares, and protects consumer health data in connection with our websites, the HealthMemory applications, the Haven assistant, the Genesis service, and related features and services (collectively, the “Services”). It is provided under the Washington My Health My Data Act (RCW 19.373), Nevada law on consumer health data (NRS Chapter 603A), and the Connecticut Data Privacy Act, and applies to consumers protected by those and similar laws.
“Consumer health data” means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. This Policy supplements our Privacy Notice at www.blockhaven.ai/privacy, which describes our handling of personal information generally.
The health information you keep in HealthMemory is stored in an encrypted vault (your “Vault”). Your Vault is encrypted on your device with a key generated on your device. To support account recovery, we store copies of that key that are themselves encrypted with keys we do not have, so we cannot open them or recreate your key on our own. We cannot read the contents of your Vault, including any encrypted copy we store for you. Information you choose to send through a feature that processes it outside your Vault, such as Genesis or the artificial intelligence features described in Section 5, is handled as this Policy describes for that feature.
2. Consumer Health Data We Collect
We collect the following categories of consumer health data:
- information about your physical or mental health that you enter, import, or authorize us to collect, including health conditions, symptoms, treatments, procedures, medications, allergies, test results, and vital signs;
- health and fitness measurements from sources you connect, such as Apple Health;
- health records and documents you choose to import, including records retrieved at your direction from a third-party source of health records;
- your conversations with Haven, and summaries and other information the Services derive from your health information; and
- information that shows you have purchased or sought a health-related service from us, such as your email address together with a record of the purchase.
Where the Services offer a face scan, the video of your face is analyzed on your device to estimate measurements such as heart rate, is not sent to us, and is not used to identify you. Only the resulting measurements are kept, in your HealthMemory. We do not create a faceprint or any other template that could identify you, and we do not collect biometric identifiers. Precise location, where you permit it, is used only on your device and is not collected by us.
3. Sources
We collect consumer health data from you; from your device, with your permission; from the sources of health records and health data you connect at your direction; and from our payment processor, which confirms purchases, refunds, and dispute outcomes.
4. Purposes
We collect and use consumer health data to provide the Services you request, including to store and organize your health information, to answer your questions through Haven, to prepare information you ask for, and to process records through Genesis. We also use it, to the extent necessary, to authenticate you, to protect the security and integrity of your account and the Services, to process purchases, refunds, and related transactions, and to comply with legal obligations.
We do not use consumer health data for advertising, sell it, or use it to train artificial intelligence models.
5. How We Obtain Your Consent
Haven chat, Genesis, and visit preparation rely on artificial intelligence services provided by third parties. When you use one of those features, the provider receives only a minimized excerpt of your consumer health data, limited to what the request requires, after removal of the direct identifiers our software detects, such as your name, dates, and identification numbers. Identifier removal is automated and cannot be guaranteed to remove every identifier.
Two separate consents apply. When you finish setting up HealthMemory, you give us permission to collect and keep the consumer health data you add. HealthMemory keeps new information you add only while that permission is in effect, and asks for it again on a device where it is not. When you create your account, we ask for your consent to share consumer health data with artificial intelligence service providers for these features. That consent is given by ticking a box that is not ticked for you, separate from your agreement to our Terms of Service and your acknowledgment of our Privacy Notice, and an account cannot be created without it.
You may withdraw your consent to sharing at any time in the app’s settings, under Privacy. Withdrawal stops any further sharing with these providers and turns off Haven chat, Genesis, and visit preparation until you consent again. Your account and your consumer health data remain, and nothing is deleted.
We will ask for your separate consent before we collect, use, or share consumer health data for any purpose not described in this Policy.
6. Sharing
We share consumer health data only as follows:
- Service providers. We share consumer health data with service providers that act on our instructions to provide services to us, in these categories: cloud hosting, artificial intelligence services for the features described in Section 5, payment processing, and email delivery. The consumer health data these providers receive is: for artificial intelligence services, the questions, measurements, medications, test results, and document text that a feature requires, after identifier removal; for cloud hosting, your encrypted Vault and records being processed by Genesis; for payment processing and email delivery, your email address and the record of a purchase or code.
- Recipients you choose. When you share information through the Services, we transmit it as you direct. Shared information is encrypted on your device before it is sent, so that only someone who has the link or code you share can open it, and we cannot read it. A file you save or copy out of the Services yourself is not encrypted by us and is under your control.
- Legal requirements. We may disclose consumer health data where the law requires it, such as in response to valid legal process. Because we cannot open your Vault, we cannot disclose its contents.
- Business transfers. In connection with a merger, acquisition, or sale of assets, consumer health data may be transferred to a successor, which must handle it as this Policy describes.
We have no affiliates that receive consumer health data. You may request a list of the specific third parties with whom we have shared your consumer health data.
7. No Sale and No Geofencing
We do not sell consumer health data. We do not set up or use a geofence around any location where health care services are provided. We do not allow third parties to collect consumer health data about your activities over time and across websites or online services through the Services.
8. Your Rights
Subject to applicable law, you have the right to:
- confirm whether we collect, share, or sell your consumer health data, and access that data;
- obtain a list of the third parties and affiliates with whom we have shared or sold your consumer health data, with a way to contact them;
- correct inaccurate consumer health data;
- withdraw your consent to the collection or sharing of your consumer health data;
- have your consumer health data deleted; and
- appeal our decision on any request.
9. How to Exercise Your Rights
You can view and correct the information in your Vault directly in the Services, withdraw your consent in the app’s settings, and delete your account in the app’s settings where that option is available. If that option is not available to you, you may ask us to delete your account by writing to [email protected]. To make any other request, write to [email protected]. You may designate an authorized agent to make a request on your behalf.
We will verify your request before acting on it, using information associated with your account. Because we cannot read the contents of your Vault, we fulfill requests about that information through the tools in the Services, which let you view, correct, and delete it yourself. We will respond within 45 days of receiving your request. Where reasonably necessary, we may extend that period once by a further 45 days, and we will tell you of the extension and the reason for it within the first 45 days. We do not charge for requests, except as the law allows for requests that are manifestly unfounded, excessive, or repetitive. We will not discriminate against you for exercising your rights.
When we delete consumer health data at your request, we delete it from our systems, and copies in backups are deleted when those backups expire, within six months after we authenticate your request. Health records that Genesis processes are deleted from our systems within one day after we receive them, whether the run finishes, fails, or is abandoned, and they are not kept in backups. A finished Genesis record waiting for you to collect it is stored encrypted, in a form we cannot open, for up to 30 days. We will notify the processors and other third parties with whom we shared the data, as the law requires.
10. Appeals
If we decline to act on your request, in whole or in part, you may appeal by replying to our response. We will inform you in writing of the outcome of your appeal, with an explanation, within the time the law requires. If we deny your appeal, we will tell you how to contact your state attorney general to submit a complaint.
11. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new effective date. If we make a material change, including any change to how we collect, use, or share consumer health data, we will notify you in advance through the Services or by other appropriate means and, where required by law, obtain your consent.
12. Contact Us
BlockHaven Inc.
16192 Coastal Highway
Lewes, Delaware 19958
[email protected]