Consumer Health Data Privacy Notice
Effective date: April 30, 2026
This Notice supplements our Privacy Policy and applies to personal information that constitutes “consumer health data” subject to the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (NRS 603A.400 et seq.), the Connecticut Data Privacy Act as amended for consumer health data, and similar U.S. state laws.
1. Categories of consumer health data we collect
- Information about your medical appointments, including notes, questions, and summaries.
- Medications, dosages, schedules, and adherence reminders you create.
- Symptoms, conditions, treatments, and other health-related content you submit.
- Audio recordings or transcripts you choose to upload for summarization.
- Information that could be used to infer a health status (e.g., the fact that you use a particular reminder).
2. Categories of sources
- Directly from you, when you create an account or submit content.
- From people you have authorized to share information with you (family sharing).
- Automatically from your device, limited to operational and security signals.
3. Purposes for collection and processing
- To provide the Service you have requested, including AI summarization and reminders.
- To enable family sharing that you initiate.
- To secure the Service and detect fraud or abuse.
- To comply with legal obligations.
We collect and process consumer health data only to the extent necessary to provide the Service or with your consent.
4. Categories of consumer health data we share
We share consumer health data only with the following categories of recipients, and only as needed for the purposes above:
- Processors acting on our behalf: cloud hosting and database providers; our AI providers (currently OpenAI, Anthropic, and/or Google Vertex AI); transactional email and customer-support providers; error-monitoring providers; and our payment processor (Stripe) for billing-related data.
- Recipients you choose via family sharing.
- Legal and safety recipients where required by law or legal process.
We do not sell consumer health data, do not share it with advertising networks or data brokers, and do not use it for targeted advertising.
5. Affiliates
VisitNotes is operated by 90 Day Plan Inc. We do not currently have affiliates that receive consumer health data. If that changes, we will update this Notice and identify each affiliate by name.
6. Your rights
You have the right to:
- Confirm whether we are processing your consumer health data and access that data.
- Withdraw consent to our collection or sharing of your consumer health data.
- Request deletion of your consumer health data. We will delete the data we hold and notify our processors and any affiliates to do the same, as required by law.
- Appeal a denial of a rights request.
To exercise these rights, email privacy@visitnotes.app or use the in-app privacy controls. We will not discriminate against you for exercising your rights.
7. Geofencing
We do not use geofences around healthcare facilities to identify, track, collect data from, or send notifications to consumers based on their proximity to such facilities.
8. Contact
Email: privacy@visitnotes.app
For Washington residents, you may also contact the Washington State Attorney General’s Office to file a complaint.