Consumer Health Data Privacy Policy
This policy describes how Pippa LLC ("Pippa," "we") collects, uses, and shares consumer health data, and the rights you have over it. It supplements our Privacy Policy and is provided for all users, including as required by Washington's My Health My Data Act and Nevada's consumer health data law. If this policy and the Privacy Policy ever conflict, the one giving you stronger protection controls.
1. What consumer health data we collect
Pippa is an eating-disorder recovery support app, so almost everything you put into it is consumer health data: information that identifies your physical or mental health status, or from which it could be inferred. Specifically:
- Meal photos, food descriptions, calorie estimates, and meal times
- Post-meal check-in answers, including urges and behaviors you choose to report
- Weight, height, and blind weight check-ins
- Mood entries, notes, and daily check-in answers
- Chat messages with the Pippa AI companion, a rolling summary of them, and automated crisis-safety flags
- Messages between you and clinicians you've approved
- Responses to questionnaires your clinician assigns
- Meal plans and grocery lists
- The fact that you use an eating-disorder recovery app at all, together with your account details (email, date of birth, gender) and device information (device identifier, push token, time zone) when linked to the above
- Records of your consents, such as guardian consent and clinician data-sharing agreements
We collect no precise location data and use no biometric processing. Journal entries never leave your device.
2. Where it comes from
- You: what you enter, photograph, or say in the app.
- Generated from your content: food and calorie estimates from your meal photos, chat responses and summaries, and automated safety flags.
- Clinicians you approve: goals, plans, questions, and notes they set for you.
- Your device: device identifier, push token, and time zone.
3. Why we collect and use it
We collect and use consumer health data only to provide and support the service you asked for:
- Logging meals and generating food and calorie estimates
- Mood support, check-ins, and the Pippa chat companion
- Sharing your progress with clinicians you approve, and their care features (plans, questionnaires, messages, reminders)
- Crisis-safety detection and escalation, as described on the Safety page
- Sync across your devices, notifications, and account security
- Keeping legally required consent and audit records
We do not collect or use consumer health data for advertising, marketing to third parties, AI model training, or any purpose beyond operating the service, and we collect no more than the service needs.
4. Who receives it
We do not sell consumer health data, and we have never sold it. Selling it would require your separate, signed authorization under laws like Washington's, and we do not seek one. We also share it with no affiliates; Pippa LLC has none.
Consumer health data is disclosed only to:
- Clinicians you approve through a signed data-sharing agreement you can sever at any time in Settings.
- Service providers processing data solely on our instructions: OpenAI (chat responses, meal-photo estimates, safety moderation; API content is not used to train their models), Amazon Web Services (database, sign-in, transactional email), Cloudflare (application server, photo storage), Apple and Google (push notifications and sign-in), and Stripe (clinic billing only; Stripe never receives patient health data).
- Authorities, if validly required by law, limited to what is required.
5. Your rights
You may, at any time and for free:
- Confirm and access the consumer health data we have about you, including a list of the third parties and service providers it has been shared with and how to contact them.
- Withdraw consent for collection or sharing, including severing any clinician's access instantly in Settings.
- Delete your consumer health data. Deletion covers our systems and is passed along to our service providers; backup copies are erased as backups rotate. See Delete Your Account.
To exercise any right, use the in-app controls or email pippa.app.general@gmail.com from the address on your account. We authenticate requests, respond within 45 days (extendable once by 45 days with notice), and never discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our response; we answer appeals within 45 days. If your appeal is denied, you may contact your state Attorney General (for Washington residents: atg.wa.gov).
6. A note on HIPAA
When you are enrolled through a participating treatment provider, your records held for that provider are protected health information governed by HIPAA and the provider's Notice of Privacy Practices, with Pippa acting as the provider's business associate. This policy covers the consumer health data we hold outside that relationship.
7. Changes and contact
Material changes to this policy will be announced in the app and take effect only going forward; new uses of already-collected health data require your fresh consent. Questions or requests: pippa.app.general@gmail.com. Pippa LLC.