CONSUMER HEALTH DATA PRIVACY POLICY
This is the consumer health data privacy policy of AppClose, Inc. (the “Company,” “we,” “us,” or “our”), provided under the Washington My Health My Data Act. It applies only to consumer health data covered by that Act.
Who this policy covers. Under the Act, you are a “consumer” if you are a Washington resident, or if your consumer health data is collected in Washington — for example, because you were in Washington when you used AppClose. In either case you must be acting in an individual or household capacity. If you are a family law professional using AppClose Pro in the course of your work, you are acting in an employment capacity and the Act does not treat you as a consumer. If neither applies to you, this policy does not govern your information; our Privacy Policy does.
AppClose is a co-parenting communication platform. We do not ask you for health information, and no feature of AppClose requires it. Health information reaches us because you and your co-parent choose to communicate about your children’s care.
1. The Consumer Health Data We Collect, and Why
We collect the following categories of consumer health data, in each case only because you or another person in your circle chose to put it into AppClose:
Category of consumer health data | Why we collect it, and how it is used |
|---|---|
Health information you type into a message, calendar entry, note, expense description, or request — a child’s illness, symptoms, diagnosis, medication, therapy, or an appointment with a health care provider | To deliver it to the people in your circle you selected and display it to them; to create and preserve the unalterable record of your communications that is the service you signed up for; and to produce the records exports you or a professional you authorized request; and, if a family law professional you authorized uses the AI features in AppClose Pro, to be summarized or searched by those features as described in Section 4 |
Health information in a child’s profile or a user profile, including allergies, conditions, medications, and emergency contacts | To display it to the people in your circle you selected, so that a caregiver has it when the child is with them |
Health information in photos or documents you upload, such as a prescription, a bill, an insurance card, or a medical record | To deliver and display it to the people in your circle you selected, and to preserve it as part of your record |
Health information spoken during an audio or video call that every participant consented to record, and in the transcript of that call | To produce the recording and transcript that the participants requested, and to make them available to the participants for download. A recording and its transcript are deleted on the last day of the calendar month two (2) years after the calendar month in which the call was made or, if your account is closed or terminated, three hundred sixty-five (365) days after closure or termination, as described in Section 7. |
Health-related payment information, such as a transfer or expense entry described as a medical, dental, therapy, or pharmacy cost | To process the transfer you requested and to maintain the record of payments between you and your co-parent |
Precise location you generate through a check-in, which could indicate a visit to a health care facility | To create the time-and-place record you asked the app to create when you checked in |
Information about your status as a survivor of domestic violence, or a disability status, that you provide in a fee waiver application | To evaluate and administer the fee waiver you applied for |
We also use consumer health data to respond to a subpoena, court order, or other legally binding request; to respond to a support request in which you included health information; and to secure AppClose and prevent fraud and abuse.
We do not use consumer health data for marketing or advertising, to build profiles about you, or to train artificial intelligence models, and we do not permit any third party to use it for those purposes.
2. Where the Consumer Health Data Comes From
Every category above comes from one of two sources: from you, or from another person in your circle — your co-parent, or a family law professional whom you or your co-parent authorized. We do not buy consumer health data, we do not obtain it from data brokers or other third parties, and we do not infer it from your activity outside AppClose.
3. The Consumer Health Data We Share
We share every category listed in Section 1, in the circumstances described in Section 4. We do not share categories of consumer health data other than those listed in Section 1.
4. The Third Parties and Affiliates We Share It With
People you or your co-parent selected. Consumer health data you enter is delivered to the members of your circle you selected — typically your co-parent, and any family law professional whom you or your co-parent authorized. Each of those people can export their own records and share them outside AppClose, and we cannot control what they do with records they lawfully hold.
Service providers acting on our behalf. These providers process consumer health data only on our instructions, under written contracts, and may not use it for their own purposes — except Stripe, which as the merchant of record for subscriptions purchased through our website also processes payment and billing information for its own purposes (calculating and remitting transaction taxes, handling chargebacks, screening for fraud, and keeping the records financial law requires), as Section 7.3 of our Privacy Policy describes:
Third party | What it does |
|---|---|
Twilio Inc. | Audio and video calling, call recording, and transcription |
Dwolla, Inc. | Payment processing, where a transfer or expense description contains health information |
Plaid Inc. | Bank account linking, where you choose to use it |
Zendesk, Inc. | Customer support ticketing, where you include health information in a support request |
A language-model provider (unnamed), for the AI features in AppClose Pro | Processing of records that a family law professional you or your co-parent authorized has chosen to summarize or search using the AI features in AppClose Pro, as described in Section 4 |
Amazon Web Services, Inc. (AWS) | Cloud hosting, storage, backup, and security |
Link, owned by Stripe, Inc. | Processing of subscription payments made through our website |
The AI features available to family law professionals in AppClose Pro, described in Section 5 of our Privacy Policy, use a large language model operated by a third-party provider. Health information embedded in a record that you or your co-parent has shared with a family law professional is processed by that model, as written, when the professional uses those features; the provider processes that content only on our instructions and only to return the result within AppClose Pro, does not store it beyond the request, and does not use it to train models. Co-Parent Assist and the other AI features available to AppClose Users operate on models hosted on our own infrastructure, and no content is transmitted to any third-party AI provider for those features.
Affiliates. AppClose, Inc. has no affiliates with whom consumer health data is shared.
Courts, government agencies, and other recipients of legal process. We disclose consumer health data when required or authorized by a proper subpoena, court order, warrant, governmental order, or other legally binding request. Where we determine in good faith that the request was not initiated by you or your counsel, we may give you written notice so that you have an opportunity to seek a protective order, or we may confirm that your counsel has been notified. We give notice where the law requires it, and we do not give it where the law prohibits it; otherwise we are not obligated to notify you or to delay our response.
An acquiring party. If we are involved in a merger, acquisition, or sale of all or substantially all of our assets, consumer health data may transfer to the acquiring party, which will be required to honor this policy or a substantially similar one.
5. We Do Not Sell Consumer Health Data
We do not sell consumer health data, and we have never sold it. We do not exchange it for monetary or other valuable consideration with anyone. If that ever changes, we will update this policy and obtain your valid written authorization before any sale.
6. Your Rights, and How to Exercise Them
You have the right to:
- •Confirm whether we are collecting, sharing, or selling your consumer health data, and to access that data, including a list of all third parties and affiliates with whom we have shared it and an email address or other online means of contacting each of them
- •Withdraw your consent to our collection and sharing of your consumer health data
- •Have your consumer health data deleted
- •Appeal a decision by us to refuse to act on any of these requests
We will not deny you our services, charge you a different price, or provide you a different level of service because you exercised any of these rights.
A word about consent and withdrawal. We do not collect or share your consumer health data on the basis of your consent. We collect and share it because doing so is necessary to provide the service you asked us for — delivering what you wrote to the co-parent you selected, and keeping the record of it. Where we are not relying on consent, there is no consent to withdraw. If you want us to stop collecting and sharing your consumer health data, the way to do that is to stop putting it into AppClose and to close your account. Section 7 explains what happens then. This is different from the authorization you may give in the app for the disclosure of your records to a family law professional or a court; that authorization is revoked in the manner it describes, and revoking it does not delete any records.
How to submit a request. Email privacy@appclose.com with the subject line “Consumer Health Data Request,” or write to Attn: Office of the Data Protection Officer, AppClose, Inc., 5000 Plaza on the Lake, Suite 300, Austin, TX 78746. An authorized agent may submit a request on your behalf if you provide written authorization we can verify. A parent or legal guardian may submit a request on behalf of their child.
Verification. We verify your identity using the email address and mobile phone number associated with your account, and where necessary we may ask for additional information. If we cannot verify your identity, we will tell you and explain what we need.
Timing. We will respond without undue delay and in all cases within forty-five (45) days of receiving your request. Where reasonably necessary we may take one additional forty-five (45) day extension; if we do, we will tell you within the first forty-five days and explain why.
Appeals. If we refuse to act on a request, our response will tell you how to appeal. Send the appeal to privacy@appclose.com with the subject line “Consumer Health Data Appeal.” Within forty-five (45) days of receiving it we will tell you in writing what action we have taken or, if we deny the appeal, the reasons for the denial. If we deny your appeal, we will give you the contact information you need to submit a complaint to the Washington State Attorney General.
7. Deletion — What We Do and Do Not Do
We want to be straightforward about how deletion works here, because the design of AppClose shapes what a deletion request can reach.
Apart from the profile fields described below, health information is not stored in a separate, labeled field. It sits inside the messages, notes, calendar entries, expense descriptions, photos, and recordings that you and your co-parent created, and those records are encrypted. We do not read your records, and we do not search or review them to find health information. That is not because we are unable to decrypt them; it is because AppClose never reviews the content of a user’s communications to decide what to keep or remove. That rule is what allows both co-parents, and the courts that rely on AppClose records, to trust that no one at AppClose has read or edited them. Where a court order, other legal process, or your own request identifies a specific record, we can quarantine or delete that record, as Section 9 of our Privacy Policy describes; identifying a record that someone has specified is different from searching your records for their content.
What that means in practice. There are three kinds of consumer health data in AppClose, and a different answer for each:
- •Health information in a profile — yours or a child’s, such as allergies, conditions, medications, and emergency contacts. You can edit or remove it yourself at any time in the app, without a request to us. If you prefer, send us a request and we will remove it for you.
- •Health information in a specific record that you identify — a particular message, image, note, expense entry, or request. Tell us which record, with enough particularity for us to locate it without reading others. We decrypt the affected records only to locate that record, delete it, and enter a notation in the record sequence recording that a deletion occurred, when, and at whose request, as our Subpoena Policy describes. The content of a deleted record is not retained anywhere. Your account and the rest of your records are unaffected.
- •A general request — for example, “delete any health information in my chats.” We will not search your records to find it, for the reason explained above. A general request therefore reaches every record in your account, and those records are the service. We will tell you that, ask you to confirm that you want all of your records deleted and your account closed, and on your confirmation delete the records, enter the notation, and close your account. If you do not confirm, we will treat the request as withdrawn and tell you so. The confirmation step is for your protection and does not extend the time limits in Section 6.
- •Before we delete under any of these paths, we will determine whether the Act, or any other law, permits or requires us to retain the records — for example, because they are subject to a litigation hold, a preservation demand, a court order, a subpoena, or other legal process.
- •We will tell you in writing what we deleted, what we retained, and the specific basis for retaining anything. If we refuse to act on the request, you may appeal as described in Section 6.
If we delete, we delete the data from our records, including from all parts of our network and from archived and backup systems, and we notify the processors and third parties with whom we have shared it so that they can do the same.
Call recordings and transcripts are an exception. While your account is open or in read-only mode, a recording of a call, and any transcript of it, is deleted on the last day of the calendar month that is two (2) years after the calendar month in which the call was made, so the recordings of all calls made in the same calendar month are deleted on the same day. That period is measured from the calendar month of the call and does not restart or stop for entry into read-only mode or reactivation. If your account is closed or terminated, the recordings and transcripts held for your account are instead retained for three hundred sixty-five (365) days after closure or termination and are then deleted. Retention is determined for each participant by the status of that participant’s own account. A recording made before this version of this policy took effect is treated as if the call had been made in the calendar month in which this version took effect. We will notify each participant in the call whose account is open or in read-only mode at least thirty (30) days before a recording or transcript is deleted for that participant’s account. While your account is open or in read-only mode you can download the recording and the transcript in the app at any time before they are deleted. A closed or terminated account cannot be signed in to, so you can no longer download them after that. When the recording and the transcript are deleted for your account, they cannot be recovered for your account, and we retain a copy only if, and only for as long as, it remains within the retention period for the other participant’s account. Any health information spoken during that call is deleted along with them, without any request from you — unless we ourselves are required to preserve the recording or transcript under a litigation hold, a preservation demand, a court order, or another legal obligation that applies to us, in which case we retain it for as long as our obligation applies and delete it promptly once we learn that it has ended. A preservation obligation that applies to you or to another user, but not to us, does not suspend deletion. If you want to keep a recording or a transcript, download it before the period ends, and before you close your account.
What a deletion request does not reach. Your request covers your consumer health data. It does not by itself reach information that is your co-parent’s or your child’s consumer health data, whose rights are theirs to exercise and not yours. Because the records of a communication belong to both co-parents, a record deleted at your request is removed from your co-parent’s account as well, and the notation recording the deletion is visible to your co-parent and appears in any records export. A deletion also cannot recover records that your co-parent, or a professional either of you authorized, has already exported and now holds outside AppClose. We have no way to retrieve those.
8. New Categories and New Purposes
We will not collect, use, or share categories of consumer health data other than those disclosed in this policy, and we will not collect, use, or share consumer health data for purposes other than those disclosed in this policy, without first disclosing the new category or purpose and obtaining your affirmative consent. We prominently link this policy from our homepage, and we archive prior versions.
9. Contact Us
Questions about this policy may be directed to privacy@appclose.com, or by mail to Attn: Office of the Data Protection Officer, AppClose, Inc., 5000 Plaza on the Lake, Suite 300, Austin, TX 78746.