Why this is a separate page. Washington State’s My Health My Data Act (RCW 19.373) requires a stand-alone consumer health data privacy policy containing only the information the Act specifies, linked prominently from the homepage. Washington Attorney General guidance is that mixing this content into a general privacy policy, or adding extra material to it, does not satisfy the requirement. Nevada SB 370 (NRS 603A.400–.360) imposes a closely similar obligation. This page is therefore deliberately narrow. Everything else about how we handle data is in our main Privacy Policy.
This policy applies to residents of Washington State and Nevada. We apply the same practices to everyone, everywhere.
1. The central disclosure
[CADENCE LEGAL ENTITY NAME], as a business entity, does not receive, gather, access, retain, share or sell consumer health data.
The precision of that sentence is deliberate, and it matters. RCW 19.373.010 defines “collect” expansively — to “buy, rent, access, retain, receive, acquire, infer, derive, or otherwise process consumer health data in any manner.” Under a definition that broad, the honest description is not a flat “we collect nothing”, but this:
- The Cadence application, running on your own device, processes consumer health data locally. It records what you enter, retains it in the app’s private storage on your phone, and derives summary measures from it. All of this happens on your terminal device, under your control.
- Cadence the company does not. We operate no server, database, endpoint or API capable of receiving, storing or accessing that data. It is never transmitted to us. We hold no copy and have no technical means of obtaining one.
We are therefore not a recipient, holder or seller of your consumer health data, and there is no centralised infrastructure on which it exists.
The disclosures that follow are made in the form the Acts require, and describe (a) the consumer health data the application processes locally under your control, and (b) the small amount of non-health personal data we do receive.
2. Categories of consumer health data collected, and the purpose of collection
2.1 Data generated and stored on your device only
Collected by the app, at your direction, and stored solely in the app’s private storage on your device:
| Category | Examples | Purpose of collection | How it is used |
|---|---|---|---|
| Bodily functions | Bowel movement date and time; Bristol Stool Scale type; completeness of evacuation; straining; urgency; leakage; time spent | To maintain your personal bowel diary | Displayed to you; summarised in reports you generate |
| Symptoms | Abdominal pain rating; bloating; presence of blood; unusual stool colour | To record symptoms alongside movements | Displayed to you; used by on-device flag rules |
| Medications and interventions | Medication names, doses, start and stop dates; laxative use; supplements | To record what you are taking and when it changed | Displayed to you; used to distinguish spontaneous from aided movements |
| Diet | Foods and drinks you type in | To let you look for food–symptom associations | Used by the on-device correlation engine |
| Bodily images | Photographs, only if you enable this feature, which is off by default | To record an observation visually | Displayed to you; stored locally |
| Reproductive and perinatal status | Pregnancy mode indicators, if you enable that mode | To adjust the diary for pregnancy | Displayed to you |
| Data about a person in your care | The categories above, recorded about an infant or another person in caregiver or infancy mode | To let you keep a diary on their behalf | Displayed to you; see the Caregiver Addendum |
| Derived health information | Frequency, SBM and CSBM rates, typical Bristol range, correlation results, red flags | To summarise your record and highlight patterns to raise with a clinician | Computed on your device; displayed to you; printed in reports you choose to generate |
None of the above is collected by us. All of it is collected by the application onto your device, at your instruction.
2.2 Data we do receive
| Category | Purpose of collection | How it is used |
|---|---|---|
| Email address, if you join the waitlist | To notify you at launch and apply the promised Plus unlock | One email; then deleted per our retention schedule |
| Email address and message content, if you write to us | To answer your question | Support response only |
| Purchase records from Google Play, if you buy Plus | To validate your entitlement, process refunds, and keep required accounting records | Entitlement and accounting only |
| Website server log data, including IP address | To deliver and secure the website | Not analysed, not profiled |
We do not treat any of the above as consumer health data, and we do not infer health status from any of it. We do not, for example, treat the fact that you joined a bowel-health waitlist as an indication that you have a bowel condition, and we do not use it to segment, target, profile or enrich.
3. Categories of sources from which consumer health data is collected
| Source | What comes from it |
|---|---|
| You, directly | Every item in §2.1. All of it is typed, tapped or photographed by you into your own device. |
| On-device computation | Derived measures in §2.1 are calculated by the app from the entries you made. No external source contributes to them. |
We collect consumer health data from no other source. Specifically, and for the avoidance of doubt, we do not obtain consumer health data from:
- data brokers, list vendors or lead generators;
- advertising networks, ad exchanges, or advertising identifiers;
- social media platforms, or any pixel, SDK or tag on our website or in our app;
- health systems, insurers, pharmacies, laboratories or electronic health record vendors;
- Health Connect, Google Fit, Apple Health, wearables, or any other application on your device;
- public records, or inference from any of the above.
4. Categories of consumer health data that is shared
None.
We share no consumer health data, in any category, with any third party, for any purpose. We have never done so.
This is not a policy commitment layered over a system that could do it. There is no transmission path: the data does not leave your device.
You may of course share your own data yourself — by exporting a CSV, generating a PDF report and giving it to your doctor, or taking a screenshot. When you do, you are the one sharing it, to a recipient you chose, and this policy does not govern what happens to it afterwards.
5. Categories of third parties and specific affiliates with whom consumer health data is shared
None. There are no such third parties and no such affiliates.
For completeness, the following parties process the non-health personal data described in §2.2. They receive no consumer health data:
| Party | What they receive | Relationship |
|---|---|---|
| Cloudflare, Inc. | Website hosting and delivery (request logs); waitlist email addresses (stored in Cloudflare KV) | Service provider under contract |
| [EMAIL INBOX PROVIDER] | Support correspondence | Service provider under contract |
| Google LLC | Play Store and Play Billing transaction data | Independent third party under its own policy |
No email-sending provider is appointed yet, because no email has ever been sent. One will be named here before the launch email goes out.
Affiliates: We have no affiliates.
6. Sale of consumer health data
We do not sell consumer health data, and we never have.
We have not obtained, and will not seek, the valid authorization that RCW 19.373.100 and NRS 603A require before any such sale. If that position ever changed, the law requires a separate signed authorization from you containing specified terms — it could not be effected by updating this policy, by bundling it into terms of service, or by treating your continued use of the app as agreement.
7. How to exercise your rights
Washington residents have the rights set out in RCW 19.373.030. Nevada residents have equivalent rights under NRS 603A. We extend all of them to everyone, regardless of residence.
7.1 Right to confirm and access
You may ask us to confirm whether we collect, share or sell your consumer health data, and to give you access to it, including a list of all third parties and affiliates with whom we have shared it and an active contact for each.
Our answer will be that we hold none. Your health data is on your device, and you already have complete access to it: open the app, or export the full history as CSV from Settings → Export, free, at any time, without asking us.
7.2 Right to withdraw consent
You may withdraw consent to the collection and sharing of your consumer health data.
In the app, this means turning off any feature you no longer want — photographs, correlation, flagging, or a whole tracking mode — in Settings. Because nothing is shared, there is no sharing consent to withdraw. Withdrawal takes effect immediately and does not require contacting us.
7.3 Right to delete
You may ask us to delete your consumer health data.
- On your device: delete an individual entry, use Settings → Erase all data for a one-tap wipe, or uninstall the app. Deletion is immediate and permanent, subject to any Android backup you have enabled (see §5.4 of the main Privacy Policy).
- From us: there is nothing to delete, because we hold nothing. If you send us a deletion request anyway, we will confirm that in writing, and we will delete any waitlist entry and support correspondence we hold about you at the same time.
- Where a request is directed to us, we will also notify any service provider or third party that received the relevant data — which, for consumer health data, is nobody.
7.4 How to submit a request
| [email protected] | |
| Post | [FULL REGISTERED ADDRESS] |
| Response time | Within 45 days. We may extend once by a further 45 days where reasonably necessary, and will tell you within the first 45 days if we do, with reasons. |
| Cost | Free. |
| Identity verification | Proportionate to the request. For a request about a waitlist address, replying from that address is sufficient. We will not require identity documents where they are not necessary. |
| Authorised agents | Accepted, with evidence of authority. |
7.5 Right to appeal
If we refuse a request, you may appeal by replying to our decision or writing to [email protected] with “Appeal” in the subject line.
We will respond in writing within 45 days, explaining the reasons for our decision.
If we deny your appeal, you may contact:
- Washington: Office of the Attorney General, Consumer Protection Division — https://www.atg.wa.gov/file-complaint
- Nevada: Office of the Attorney General, Bureau of Consumer Protection — https://ag.nv.gov/Complaints/File_Complaint/
Washington residents: the My Health My Data Act carries a private right of action under the Consumer Protection Act (RCW 19.86). Nothing in this policy limits that right.
7.6 No retaliation
We will not deny you the app, charge you a different price, provide a different quality of service, or penalise you in any way for exercising any right described here.
8. Geofencing
RCW 19.373.080 makes it unlawful for any person to implement a geofence around an entity that provides in-person health care services, where the geofence is used to identify or track consumers seeking health care services, collect consumer health data, or send consumers notifications, messages or advertisements relating to their consumer health data or health care services. Nevada imposes a materially equivalent prohibition.
This is one of the few provisions of the Act that applies to any person, not only to regulated entities, and it carries the private right of action.
Cadence contains no geofencing capability and collects no location data of any kind — not GPS, not network location, not Bluetooth or Wi-Fi derived location, not IP-derived location, and not location inferred from any other signal. We do not serve advertising of any kind, health-related or otherwise.
9. Contact
| Entity | [CADENCE LEGAL ENTITY NAME] |
| Address | [FULL REGISTERED ADDRESS] |
| Health data privacy contact | [email protected] |
10. Changes
We will update this policy if our practices change, and we will not apply a material change retroactively to consumer health data already collected without first obtaining your consent. The version number and effective date above always reflect the current text. Changes are recorded at [/privacy/changelog].