Consumer Health Data Privacy Policy
Effective date: September 30, 2026
This Consumer Health Data Privacy Policy explains how CuraeAI Inc. ("CuraeAI," "we," "us" or "our") collects, uses, shares and protects consumer health data through the CuraeAI service (the "Service"), and how you can exercise your rights. It is written to meet the Washington My Health My Data Act (RCW 19.373), Nevada's consumer health data law (NRS 603A.400 to 603A.550) and the consumer health data provisions of the Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-526), and we apply it to every user in the United States. Our Privacy Policy describes all of our personal-information practices; where this policy is more protective of consumer health data, this policy controls.
Contact: privacy@curaeai.com. Don't include health information in an email to us.
1. What "consumer health data" means here
"Consumer health data" is personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status. Because CuraeAI is a personal health record, we treat almost everything in your record as consumer health data, together with information that shows you use the Service to seek or manage health care.
2. The consumer health data we collect, and why
| Category | Examples | Why we collect it and how we use it |
|---|---|---|
| Health records you import | Conditions and diagnoses, medications, allergies, test and lab results, vital signs, imaging, immunizations, procedures, visits, clinical notes and documents, care plans, family history, insurance claims and coverage, and identifiers in those records | To build and show your personal health record, to calculate the scores and estimates you see, to carry out the sharing you direct, and — where the features are switched on and you ask for them — to generate AI summaries |
| Information you provide | Uploaded documents and images; answers to health questionnaires, including mood and anxiety questionnaires; conditions and family health history you add; health-related profile details you choose to add, such as sexual orientation | The same purposes as above |
| Sensitive record types | Sexual and reproductive health, mental health, substance-use treatment (including records protected by 42 C.F.R. Part 2), genetic test results and other sensitive information that appears in your records | To show them to you, and to label them so that the Service applies extra protection when you share |
| Information we derive | Health Reserve and hereditary-risk information; labels for sensitive records; findings extracted from clinical notes and summaries produced by AI, where those features are switched on | To help you understand your records, as described in the AI Processing Disclosure |
| Information that you use a health service | That you have a CuraeAI account; which health systems you connect or search for; and which apps you connect through Curae Connect | To provide the Service and to secure it |
| Sharing and consent records | Who you shared with, what, until when, the authorization you signed, and each disclosure of your data to a person or app | To carry out and honor your choices, and to show you who received your data |
We also use consumer health data to keep the Service secure — for example, to detect and stop fraud, abuse and security incidents and to keep audit records of who accessed your records — and to comply with the law.
We collect consumer health data only with your consent, which you give separately from accepting our Terms of Service in the Consent to Collect Consumer Health Data, or to the extent necessary to provide the Service you request. We collect a new category of consumer health data, or use it for a new purpose, only after asking for your consent.
3. Where we get consumer health data
- From you, when you create your account, fill in your profile, upload documents, answer questionnaires or add information.
- From health systems you connect, when you sign in to a patient portal and approve the connection.
- From apps you use with Curae Connect, which tell us the identifier they use for you (and may give us your email address) when you choose to connect your records through them.
- From other people who share with you, such as a relative who shares family health history with you.
- From your use of the Service, in the security records of your requests.
- From our own processing, when we calculate scores, label records and — where the features are switched on — produce AI summaries and extracted findings.
4. How we process consumer health data
We store consumer health data on our systems at Amazon Web Services in the United States, encrypted at rest; it is encrypted in transit between your browser and our servers and between our servers and our databases. We organize it into your record, calculate scores from it, and show it to you and to the people and apps you choose. Where AI features are switched on, parts of your record are sent to AI models CuraeAI runs on its own servers in Microsoft Azure data centers in the United States to produce the output you asked for, as the AI Processing Disclosure describes. Access by our personnel is limited to those who need it to provide the Service you requested or for a purpose you consented to, and is recorded.
5. The consumer health data we share, and with whom
5.1. We share consumer health data only when you direct it, with the recipients you choose, in the ways the Service offers:
| Category of recipient | What they receive | How you control it |
|---|---|---|
| Third-party apps you connect through Curae Connect | The kinds of records, and the period of records, you approve on the authorization screen, until the end date shown there (at most one year) | You sign an authorization for each app, and you can stop each app's access at any time: in the Service under Consents, or, from an account made through Curae Connect, as Section 7.4 describes |
| People you choose: contacts you give access to, relatives you share family health history with, and a person you show a share code to | The parts of your record you select, until the end date you choose (at most one year); a relative's copy of your family health history leaves their record on that end date, or earlier if you stop sharing, except what they added to their own family history; a share code shows what you selected once, for up to 5 minutes | You sign an authorization for each share; you can end a person's access or stop sharing family history at any time, and a share code stops working when you close the screen that shows it |
| Health systems you connect | Your authorization and our requests to import your records | You can disconnect a health system at any time |
Each sharing action is a separate authorization you sign at the moment you share, under our Sharing Authorization. The screen where you sign it shows what is shared, with whom, why and until when; afterwards the Service shows you what you shared, lets you end it and lets you download the authorization. We do not share consumer health data with anyone else unless the law requires it (see Section 5.3).
5.2. Our processors. Companies that process consumer health data for us, only to provide the Service to you, receive it as processors, not as third parties: Amazon Web Services (hosting, storage and email), Microsoft (the servers our own AI models run on, where AI features are switched on) and MongoDB (the directory in which the health systems you search for are looked up). They are listed with what each receives in Section 6.2 of our Privacy Policy. Our email hosting provider receives the messages you send to our email addresses and our replies; it is not a channel for health information, so don't include health information in an email to us.
5.3. Required by law. We may disclose consumer health data when the law requires it, for example in response to a valid court order, and we tell you first unless the law or the circumstances forbid it.
5.4. No affiliates, no sale, no geofencing, no tracking across sites. CuraeAI Inc. has no affiliates, so no affiliate receives consumer health data. We do not sell consumer health data. We do not use geofences, and we do not collect precise location. We do not allow any third party to collect consumer health data about you over time and across different websites or online services when you use the Service.
6. Your rights
You have the right to:
- Confirm and access. Confirm whether we collect, share or sell your consumer health data, and access it. You can see your records in the Service at any time.
- Know who received it. Get a list of all third parties and affiliates with which we shared your consumer health data, with an email address or other online way to contact each. In the Service, under Consents, you can see each person and app you shared with and the authorization you signed for each, and the email address or other contact of each contact, share-code viewer and app that received your data; you can also ask us for the list by email.
- Withdraw consent. Withdraw your consent to our collection of consumer health data, or to any sharing. You can end any share in the Service under Consents, and disconnect a health system to stop collection from it. You can withdraw your consent to all collection in Settings or by emailing us; because the Service cannot keep a health record without collecting health data, withdrawing it closes your account when you confirm by the link we email you, and deletes your consumer health data as item 4 describes. Section 7.4 explains how to do this from an account made through Curae Connect.
- Delete. Have your consumer health data deleted. You can delete the records imported from a health system with Delete Records after disconnecting it, delete information you added yourself, such as family health history, or delete your account. When you delete your account, you and everyone you shared with lose access at once, and within 30 days of your request we permanently erase your consumer health data, including the records imported from your health systems, your documents, images and profile photos (every stored version of each), the information you entered yourself in your record and information derived from your records. We keep only what Section 9.3 of our Privacy Policy lists, including access and disclosure records with the key that links them to you destroyed, records of what you accepted and authorized and of each app connection you authorized, copies that expire from our backups, and the family tree you built, without the health history you recorded about the relatives in it. When you delete your account or use Delete Records, we tell the people who received that information, by email, and each app that received it. When you delete your account, an app you still share with is told by the end of its access, and any other app by a notice naming the records it received. When you use Delete Records, each app that received any of those records is sent a notice naming them, after the records are erased and a pause of at least an hour. Under our Developer Agreement, an app must delete what it received within 24 hours.
- Review and correct. Review your data in the Service and correct what you entered yourself. Records from a health system are corrected by that health system; its corrections reach the Service the next time the records are imported.
- Not be discriminated against for exercising any of these rights.
7. How to exercise your rights
7.1. Requests. Use the controls in the Service, or email privacy@curaeai.com from the email address on your account or, if you do not have an account, from the address we have for you. Don't include health information in an email to us: tell us what you want us to do, and sign in to the Service to see, share or delete your records. We verify requests to protect your data, normally by emailing a confirmation link to the address on your account or by asking you to sign in.
7.2. Timing. We respond within 45 days after we receive your request. If we need more time, we tell you so within those 45 days and take up to another 45 days. When you ask us to delete consumer health data, we delete it within 30 days of your request — for your account, you confirm the request by the link we email you; copies in backups expire within the following 30 days. Requests are free, up to twice in any 12 months.
7.3. Appeals. If we decline to act on your request, we tell you why. You can appeal by replying to our decision or by emailing privacy@curaeai.com with the subject line "Consumer Health Data Appeal." We tell you in writing, within 45 days after we receive your appeal, what we decided and why. If we deny your appeal, we tell you how to contact the attorney general of your state, including the attorney general's online complaint mechanism where one is available.
7.4. Accounts made through Curae Connect. If your account was made through Curae Connect and you have not finished setting up a full account, you cannot sign in to the Service. To stop sharing with the app, open Curae Connect from the app and choose Manage sharing, then Stop sharing; or use the app's own control for stopping sharing, which we require every app to provide. In Manage sharing you can also see and download each authorization you signed, and delete your account, which withdraws your consent and deletes your consumer health data as Section 6 describes; you confirm on that screen instead of by an emailed link. For any other right in Section 6, email privacy@curaeai.com and name the app you used; we verify the request by asking the app's developer to confirm the identifier the app uses for you, and the times in Section 7.2 run from the day we receive your email.
8. How we protect consumer health data
We protect consumer health data with the administrative, technical and physical safeguards described in Section 10 of our Privacy Policy, including encryption, strong sign-in, separation of each person's data, an authorization check on every access, and tamper-evident audit records.
9. Changes to this policy
We may update this policy. Each version is published with its effective date. When we make a material change, we tell you by email and in the Service before it takes effect. We collect a new category of consumer health data, use it for a new purpose, or share it with a new category of recipient only after updating this policy and asking for your consent where the law requires it.
10. Contact
Email privacy@curaeai.com. Don't include health information in an email to us. CuraeAI Inc. operates online and answers consumer health data requests by email.