Back to EMBRACE

Consumer Health Data Privacy Policy

Last updated: July 31, 2026

This policy is required by the Washington My Health My Data Act and applies to consumer health data as that law defines it. It is deliberately limited to what that law requires. Everything else about how EMBRACE handles your information is in our Privacy Policy.

EMBRACE is made by SWN Consulting LLC. Contact: swoo@swnconsultingllc.com.

What we treat as consumer health data

EMBRACE is a self-regulation exercise app. It is not a medical service and does not diagnose or treat anything. But some of what it records could indicate something about your mental or emotional state, so we treat the following as consumer health data:

  • How activated you feel before and after a reset — two numbers you choose on a 0–10 scale, and the difference between them.
  • Which pre-written option you tapped at each step of a reset, recorded as a fixed code rather than as text.
  • Which topic you chose for a reset, such as work deadlines or a personal relationship, recorded as a fixed code.
  • AI-written debrief content, if you turn on AI Insights: the short conversation an AI writes about your recent practice, its week-to-week summary, and which of its pre-written answers you tapped. These are the AI's words, not yours, but they can reflect your practice patterns, so we treat them the same way.
  • A random identifier created on your device, which groups the analytics stream above. It contains no name, email, account, or device identifier, and it is never attached to an AI request.

How we collect it

Only from you, and only inside the app, when you choose to share it.

None of it is collected unless you turn on analytics. That setting is off when you install EMBRACE and stays off until you turn it on in More → Privacy. We do not collect consumer health data from any other source — not from other companies, not from advertising networks, not from public records, and not from any device sensor.

Anything you type, and the signature you draw, stay on your device and are never collected.

Why we collect it

One purpose: to understand, across everyone who opts in, whether the reset actually helps and where the app is failing people. We look at it in aggregate.

We do not use it to advertise to you, to build a profile about you, to make any decision about you, or to infer anything about your health beyond what you chose to record.

Who we share it with

We do not sell consumer health data. We have never sold it and we do not have a process to sell it. Washington law requires separate written authorization before any such sale, and we have never sought one.

We share it with two categories of recipient, both of them service providers working on our behalf under written contracts, neither of them partners:

  • Our hosting provider, Supabase, Inc., which stores the analytics data on our behalf under a contract that forbids using it for its own purposes.
  • Our AI provider, Anthropic, PBC, but only if you turn on AI Insights — a separate, paid, off-by-default feature. About once a week it receives your recent before/after numbers, coded patterns, the reviewed wording of selected pre-written reset and profile-card choices, and short AI-written pieces of your previous debrief (the AI's own lines, questions, your tapped pre-written option, and its week summary — text the AI wrote, which may reflect your practice patterns and which we treat as consumer health data too). It writes a labeled debrief conversation that a second AI model and the app both check before it is shown; a debrief built on-device replaces it whenever any check fails. It never receives text you typed, drawings, or signatures.

The AI request carries no identifier of any kind — no random ID, no device ID, nothing that could tie it to you or to your other data. Our server keeps no record of it and has no user table. Anthropic may hold the request for up to 30 days for abuse monitoring under its commercial terms, and does not use it to train its models. If you never turn AI Insights on, nothing is sent to Anthropic at all.

We have no affiliates. We do not share consumer health data with advertisers, data brokers, analytics networks, or any other third party.

If we are ever legally compelled to disclose data, we will do so only to the extent required.

Where it is stored and how long we keep it

On servers in the United States. We keep the analytics data for up to 12 months, after which it is deleted automatically. We keep nothing at all from the AI Insights requests; Anthropic may hold those for up to 30 days as described above.

If you turn analytics off, we delete the data we already received at that moment — you do not have to ask us separately. If that deletion cannot reach our servers, the app tells you so and shows you your identifier so you can email us.

Your rights

Under the My Health My Data Act you have the right to:

  • Confirm whether we are collecting, sharing, or selling your consumer health data, and to access it, including a list of everyone we shared it with.
  • Withdraw your consent to our collection and sharing of it.
  • Have it deleted.

To exercise any of these, email swoo@swnconsultingllc.com.

Because we hold no name, email, or account, we cannot connect a request to your data unless you give us the identifier the app shows in More → Privacy. Open that screen and copy the Analytics ID before turning analytics off, and include it in your email. If you have already turned analytics off, your data was deleted at that moment.

You can also withdraw consent yourself at any time, without contacting us, by turning analytics off in More → Privacy. That both stops collection and deletes what we already have.

We will respond within 45 days of receiving your request. If we need more time we will tell you within that period, and may take up to 45 additional days. If we deny a request we will tell you why and how to appeal. If we deny your appeal, you may complain to the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.

We will not charge you for exercising these rights, and we will not deny you service, charge you a different price, or give you a lesser experience because you did.

When we delete your data, we will also direct anyone we shared it with to delete it.

How we protect it

Access to consumer health data is restricted to the people who need it to run EMBRACE. Our database is configured so that the app itself can only add records — it cannot read them back — and deletion runs through a separate restricted process. Data is encrypted in transit and at rest.

Changes to this policy

If we materially change how we handle consumer health data, we will update this page and change the date at the top before the change takes effect.