Consumer Health Data Privacy Policy
Hanzo's posture on consumer health data under Washington's My Health My Data Act and similar laws — what we do not collect, and the safeguards that apply if a feature ever does.
Draft, pending counsel review — not yet effective. Version 2026-07-22, last updated 2026-07-22.
This Policy addresses "consumer health data" as defined by Washington's My Health My Data Act (MHMDA) and comparable laws (for example, Nevada SB 370 and Connecticut's health-data provisions). It supplements the Privacy Policy.
1. Our default: we do not seek consumer health data
The general Hanzo Services are not designed to collect consumer health data, and our Privacy Policy instructs you not to submit health or other regulated data unless a feature and your agreement expressly support it. We do not use inputs to infer a health condition, diagnosis, treatment, or health-status characteristic, and we do not build health profiles for advertising.
Because Hanzo is a general AI platform, a user could nonetheless place health-related content into a prompt. Such content is processed as ordinary Customer Content to provide the requested Service under the Privacy Policy and, for business customers, the DPA — not collected by Hanzo as a health-data product — and it is not used for generalized training absent a separate election.
2. If a feature ever processes consumer health data
Should Hanzo offer a feature whose purpose involves consumer health data, the following apply before it launches:
- Separate consent to collect, and a separate consent to share. MHMDA requires distinct, unbundled consents; we will not bundle them or pre-check them.
- No sale without valid authorization. We will not sell consumer health data, and any "sale" as defined by the applicable statute requires the separate signed authorization the law specifies.
- Purpose limitation and minimization. Data is used only for the disclosed health-related purpose and retained only as long as necessary.
- Deletion rights. You may request deletion of consumer health data, and we will delete it across our systems and instruct processors to do the same, subject to legal holds.
- Processor bindings. Any vendor involved is listed in the Subprocessor Register and bound to equivalent restrictions.
3. No geofence around health facilities
We do not implement geofences around any facility that provides in-person health care or services to identify, track, collect data from, or send notifications to consumers about their health data — a practice MHMDA prohibits.
4. Your rights and contact
You may exercise access, deletion, and withdrawal-of-consent rights for consumer health data by contacting [email protected]. We honor the rights and timelines described in the Privacy Policy and applicable health-data law, and we do not discriminate against you for exercising them.
Publication gate: If any consumer-health feature is contemplated, obtain MHMDA / Nevada / Connecticut counsel review, stand up the separate collect and share consents, and confirm processor bindings before launch. Absent such a feature, this Policy documents the default no-collection posture.