Washington Consumer Health Data — Privacy Notice
Astronero Ltd (operator of Me Journal) — published 2026-05-26 Public URL: https://me-journal.com/legal/washington-health-data Last reviewed: 2026-07-07
This notice supplements the main Privacy Policy and applies only to Washington State residents under the My Health My Data Act (Wash. Rev. Code ch. 19.373 — "MHMDA").
The MHMDA defines consumer health data broadly and grants Washington consumers specific rights independent of Me Journal's general privacy practices. If you live anywhere else, the main Privacy Policy (which includes UK, EU-EEA and California sections) and, for Nevada residents, the Nevada Consumer Health Data notice apply; this page does not change those rights.
1. Categories of consumer health data we collect
When you choose to use Me Journal, the following data is treated as consumer health data under MHMDA:
-
Body Compass daily entries — menstrual cycle data, fertility signals, pregnancy / postpartum tracking, mood level, sleep duration + quality, stress level, symptom + trigger logs, free-text notes. These entries are stored end-to-end encrypted — see §3.
-
Body Compass related records that are NOT end-to-end encrypted (they are encrypted at rest on our servers, and our systems can read them because the feature needs it): EPDS screening responses and scores (kept server-readable so screening reminders and the safety flag can run); your medication register — drug name, dose and schedule (kept server-readable so missed-dose reminders can run; the free-text reason and notes you attach to a medication ARE end-to-end encrypted); and calendar events you add (birthdays, appointments, celebrations).
-
Journal and gratitude entries — free-text reflections you write. Stored E2EE.
-
Mood check-ins — the standalone mood tracker's mood level (one of five one-word levels, e.g. "sad", "happy") and its timestamp are stored server-side (encrypted at rest, not end-to-end); a note attached to a check-in IS end-to-end encrypted. Recent mood levels power the optional AI wellness suggestions described in §2.
-
Health profile (optional) — allergies, insurance information, blood type. Stored E2EE.
-
Inferences about mood patterns, cycle predictions, fertility windows — generated client-side from the data above. These inference outputs carry the methodology + contraceptive disclaimer at the point of display (predictions are statistical estimates, not medical advice, and must not be relied on for contraception or conception).
-
Precise location — only when you trigger an SOS safety alert. Me Journal does not collect location for tracking, profiling, advertising, or in the background. The single exception is the personal-safety (SOS) feature: when you actively trigger an SOS alert and choose to share your location, the app captures one location fix (latitude, longitude, accuracy) at that moment. It is stored only while the alert is live, shared with the emergency contacts you chose (as a Google Maps link in the alert email), and deleted when you stand the alert down. It is never used for any other purpose.
We do NOT collect:
- Biometric identifiers (fingerprints, face geometry, retina scans).
- Genetic data.
- Precise geolocation for tracking, profiling, advertising, or any routine or background purpose. (The only location we ever collect is the single, user-triggered SOS fix described directly above.)
- Pharmacy or prescription-fill records (we have no NHS Spine / EHR integration).
2. Purposes of collection
We use consumer health data solely to provide the features you have requested:
- Display your data back to you (your dashboard, cycle calendar, doctor's PDF, etc.).
- Generate inferences within the app (cycle prediction, fertility windows, mood patterns). These are computed on your device; in the current version Body Compass health data is not sent to any AI/LLM for processing.
- Generate the optional AI wellness suggestions shown on the mood tracker screen. When you use the mood tracker, your recent mood levels and logging-streak count (the one-word mood levels only — never your name, email, account identifier, journal content or Body Compass data) are sent to OpenAI, Inc. (USA), acting as our processor, to generate two short wellness suggestions. This is the only AI processing of consumer health data in the current version. All other AI features (gratitude insight, monthly synthesis, cycle insights) are switched off across the app and make no AI calls; if we enable them, they will run only with your explicit opt-in.
- Operate the service — billing, error logs, abuse prevention. Health data is not used for any of these; only metadata (timestamps, counters, error IDs).
In the current version of Me Journal (private Body Compass scope — see ADR-2026-06-15), we do not share your Body Compass health data with anyone, including a partner. Partner cycle-data sharing is disabled by default. The partner-share feature (a one-time cycle code that previously let you share cycle data with another Me Journal user you invited) is turned off and retained only as dormant, configurable functionality. It would become available again only if explicitly re-enabled under a future configuration, which is subject to updated authorisation, a refreshed data-protection impact assessment, advance notice to you, and the authorisations described in §5. While the feature is disabled, your Body Compass entries stay end-to-end encrypted on your device and are not written to any server-readable column.
We do NOT:
- Share your Body Compass health data with any other user, including a partner — sharing is disabled by default in the current version.
- Sell consumer health data — full stop. No exceptions, no anonymised- selling, no aggregated-selling.
- Send consumer health data to any AI/LLM for processing, other than the mood-tracker wellness suggestions described above (recent mood levels only, with no name, email or account identifier attached).
- Use consumer health data to train models we own.
- Use consumer health data to serve advertising.
- Share consumer health data with advertisers, data brokers, or third- party analytics platforms.
- Use consumer health data for any secondary purpose without your separate, specific, opt-in consent.
3. How your health data is protected
- End-to-end encryption (AES-256-GCM, key derived from your vault password via PBKDF2-SHA-256 with 600,000 iterations + a fresh salt). This means Me Journal staff cannot read your journal, Body Compass entries, or health profile — only you can decrypt them on your devices. We are publishing this as a technical fact, not marketing. See our Security Statement for the full cryptographic description.
- Data that is NOT end-to-end encrypted (entry dates and tracker settings, EPDS screening responses, the medication register, calendar events, and mood check-in levels — see §1) is stored by Convex, Inc. in the United States, encrypted at rest (AES-256), with access controls aligned to ISO/IEC 27001:2022 Annex A. See our sub-processor list for the international data-transfer safeguards.
- Doctor's PDF export is rendered entirely in your browser — the PDF bytes never traverse our servers.
4. Your rights under MHMDA
Washington residents have the following rights, exercisable free of charge with reasonable response time:
| Right | How to exercise | |-------|-----------------| | Confirm whether we process your consumer health data | In-app — Account (settings) → Privacy & Security → "Export my data" | | Access your consumer health data | Same — downloads a JSON archive prepared in your browser; end-to-end-encrypted content is decrypted locally on your device (unlock your vault first) and never reaches our servers in readable form | | Withdraw consent for any specific processing | In-app — Account (settings) → Body Compass to disable the tracker or individual modules at any time; Account → Privacy & Security → "AI-powered insights" toggle. Partner sharing is disabled in this version, so there is no sharing consent to withdraw. You can also email privacy@me-journal.com | | Delete consumer health data | In-app — Account (settings) → Body Compass lets you delete all Body Compass data (or just pregnancy data) without closing your account; Account → Danger Zone → "Delete Account" permanently and irreversibly erases your entire account and data immediately | | Appeal a denied request | Email privacy@me-journal.com. We respond within 45 days |
If we deny a request, we will tell you why in writing and how to appeal to us (see the table above). If we deny your appeal, we will give you a way to raise a complaint with the Washington State Attorney General at atg.wa.gov.
5. Consent required for sharing; authorisation required for selling
Under RCW 19.373.030, we will not collect or share consumer health data beyond what is necessary to provide the features you have requested without your separate, specific opt-in consent. Going further, under RCW 19.373.070 we will never sell consumer health data — and a sale would in any case require a valid written authorisation that (among the other statutory elements):
- Identifies the consumer (you).
- Identifies the specific recipient(s).
- Describes the specific data being shared.
- Describes the purpose.
- Has a fixed expiration date (not to exceed one year).
- Includes your signature (typed or hand-written equivalent).
In the current version of Me Journal there is no routine sharing of consumer health data. Body Compass partner sharing is disabled by default (ADR-2026-06-15): we do not share your cycle/fertility/pregnancy or other Body Compass health data with any other user, including a partner. The previous partner-share feature (a one-time cycle code) is turned off.
If we ever re-enable partner sharing under a future configuration, we will not do so by relying on this notice alone. Any such sharing would first require your separate, specific opt-in consent under RCW 19.373.030, a refreshed legal review and data-protection impact assessment, and advance notice to affected users — and the in-app share creation, gated by your own action (you generating a code and choosing the scopes), would record that consent, revocable at any time.
6. Geofencing prohibition
Per RCW 19.373.080, we do not maintain or operate any "geofence" within 2,000 feet of a healthcare facility for the purpose of identifying or tracking visitors, advertising, or building data profiles. Outside the single user-triggered SOS location fix described in Section 1, Me Journal collects no precise geolocation at all — and even that SOS fix is never used for geofencing, tracking, advertising, or profiling.
7. Children
Me Journal is 18+ only. The Body Compass "Simplified mode" toggle is a UI feature that, when switched on by the account holder (an adult), simplifies certain copy and hides the fertility-related modules — it is not a mode for minors to use the service. Anyone under 18 attempting to sign up will be refused, and we do not retain a date of birth for anyone under 18.
8. Contact
Astronero Ltd (operator) Companies House 15024376, England & Wales Email: privacy@me-journal.com Subject for MHMDA requests: "Washington MHMDA request — [Access / Confirm / Withdraw / Delete / Appeal]"
We will acknowledge receipt within 7 days and respond within 45 days of receipt (extensible by an additional 45 days where reasonably necessary, with notice).
Changelog
- 2026-05-26 — Initial draft published. Triggered by the Body Compass V2.x rollout and the corresponding pre-launch decision (SEC-005) to publish an MHMDA-specific notice ahead of any US marketing.