Legal
Consumer Health Data Privacy Notice
A supplement to the Privacy Policy covering the state laws that treat health-adjacent information differently.
Last updated September 16, 2026
Important: This standalone notice supplements the Privacy Policy for consumer health data and related U.S. state-law frameworks, including Washington's My Health My Data Act, Nevada SB 370, and similar statutes. It is not a substitute for HIPAA BAAs or clinical disclosures where those apply.
1. Who We Are
Momeaze, LLC (Texas)
Privacy contact: privacy@momeazeapp.com
Postal address: 5900 Balcones Drive, Suite 100, Austin TX 78731
Primary policy: Privacy Policy
2. Scope of This Notice
This notice applies when we process information that certain U.S. state laws treat as consumer health data or sensitive health-adjacent personal information in connection with the Momeaze mobile app and related U.S.-market services described in the Privacy Policy.
United States-only phase: This notice applies to users in the United States. It does not implement GDPR, UK GDPR, or other non-U.S. frameworks.
Not HIPAA PHI by default: For how HIPAA and PHI relate to the consumer app, see Section 6 of the Privacy Policy.
3. Categories of Consumer Health Data We May Collect
| Category | Examples | Source |
|---|---|---|
| Wellness check-ins | Mood, stress, sleep-related responses you enter | You |
| Goals and habits | Routines tied to wellbeing or parenting load | You |
| Free text | Notes that may mention health, pregnancy, or mental health | You |
| Media | Photos that could imply health status | You |
| Inferences | AI or rules-based outputs about wellbeing | Derived |
4. Purposes of Processing
We process consumer health data only for purposes permitted by law and consistent with your in-app disclosures and consents, such as:
- Providing and improving the features you request;
- Safety, fraud prevention, and abuse detection;
- Legal compliance and responding to lawful requests;
- First-party, pseudonymous analytics that do not use consumer health data for advertising and do not conflict with your opt-in / opt-out choices.
We do not sell consumer health data for money, and we do not share consumer health data in exchange for cross-context behavioral advertising or other valuable consideration.
5. Disclosure and Sharing
We disclose consumer health data only as described in the Privacy Policy and at /legal/sub-processors (and in §9.1 of the Privacy Policy), including:
- Hosting, security, and infrastructure vendors in the United States only (AWS U.S. regions);
- AI / OCR / model providers as listed in §9.1 of the Privacy Policy (including, currently, Momeaze Agent, AWS Textract, and the other sub-processors named there) — each engaged under written terms that prohibit using your content to train their own models;
- Authorities when required by law.
Affiliates / advertising: The Momeaze app does not contain advertising SDKs. Momeaze does not share consumer health data with advertising networks, ad-tech vendors, or data brokers, and does not use consumer health data for cross-context behavioral or targeted advertising. Our marketing website uses the Meta Pixel to measure and show Momeaze ads, as described in Section 8 of the Privacy Policy. The pixel never receives information from the app, does not receive anything typed into website forms, and does not load on our blog (which covers health and wellbeing topics), our legal and privacy pages, or our contact page. You can opt out at Your Privacy Choices, and we honor Global Privacy Control signals. No consumer health data is used for advertising.
6. Your Rights (State-Dependent)
Depending on your state of residence, you may have rights to access, delete, correct, withdraw consent, obtain a list of disclosures, or opt out of certain processing under your state's consumer-health-data law — for example, Washington's My Health My Data Act (MHMDA), Nevada SB 370, Connecticut's SB 3, and equivalent state regimes as enacted. Where your state grants a stronger right than this Notice describes, the stronger right controls.
How to exercise rights:
- Privacy / DSAR hub: /privacy/rights
- Email: privacy@momeazeapp.com
We will respond within the timelines required by applicable law — generally within 45 days of receipt, extendable by an additional 45 days where state law allows; we will notify you in writing of any extension and the reason for it.
Authorized agents: You may designate an authorized agent to submit a request on your behalf where your state's law allows. We will require written authorization from you and identity verification of both you and the agent before acting on an agent-submitted request.
7. Retention
We retain consumer health data only as long as necessary for the purposes above and as stated in the Privacy Policy Section 12 (retention). At v1 the operational retention posture is:
- Account-tied data is retained for the duration of your account plus a 30-day grace period for account-deletion recovery.
- After grace expiration we purge from production systems within 60 days and from encrypted backups within 180 days.
- Specific category overrides (for example, payment records held by Stripe under PCI-DSS requirements, or legal-hold carve-outs) are described in Privacy §12.
8. Security
We use technical and organizational measures appropriate to the sensitivity of the data. Details at /trust (and see §13 (Security) of the Privacy Policy).
9. Changes
We may update this notice. Material changes will be reflected by an updated effective date and, where required, additional notice in the app or by email.
10. Contact
privacy@momeazeapp.com · 5900 Balcones Drive, Suite 100, Austin TX 78731
Related documents