CONSUMER HEALTH DATA

Consumer Health Data Privacy Notice

How future RTH health-data workflows will handle sensitive health, wearable, biometric, symptom, clinical, and inferred information even when HIPAA does not apply.

Effective: September 9, 2026  ·  Last reviewed: September 9, 2026  ·  Architecture: RTH Governance 2.0

Status: Prelaunch governance standard. The public RestartingTheHeart.com website does not currently accept external health records or wearable-health feeds through these future product workflows. This notice defines controls that must be in place before the described capability is activated.

1. Supplemental health-data notice

This Consumer Health Data Privacy Notice supplements the RTH Privacy Policy and the SuperstarIQ Privacy Notice. It is designed for consumer health information that may be regulated under U.S. state consumer-health laws or other privacy laws even when HIPAA does not apply.

2. Consumer health data categories

Depending on an activated feature and user choice, consumer health data may include symptoms, diagnoses or health-history information, wearable measurements, sleep/activity/recovery information, heart rate or HRV, ECG-related files, reproductive-health information, laboratory information, medication information, clinical documents, disability-related information, or health inferences derived from information a user elects to provide or connect.

3. Sources

Sources may include the user, user-authorized devices and applications, user-authorized healthcare or records sources, authorized caregivers or organizations, and information derived by the product from those inputs. Every connected or derived health datum should retain source and provenance information sufficient to distinguish original measurement, user report, transformation, inference, and generated explanation.

4. Purposes

Permitted purposes may include providing a user-requested feature, organizing longitudinal information, generating a review-ready summary, security, support, quality assurance, legally required recordkeeping, and separately consented research or model-development activity. RTH will not treat one purpose as blanket authorization for unrelated purposes.

5. Consent and authorization

RTH will request consent or authorization where required before collecting or processing consumer health data. Permissions should be granular enough to distinguish account operation, connected-source access, optional sharing, research participation, and model-development use.

6. No sale or targeted advertising with health data

RTH's baseline is not to sell consumer health data and not to use personal health data for cross-context behavioral advertising. If law defines "sale," "sharing," or "targeted advertising" more broadly than ordinary language, RTH will evaluate the applicable definition and provide required controls before enabling the activity.

7. AI and health data

Consumer health data may be processed by AI only for an approved product purpose under the AI & Model Governance Standard. Personal health data is not automatically eligible for model training. Identifiable health data is prohibited from general-purpose RTH model training unless a separately approved program establishes lawful rights, explicit scope, source permissions, security, retention, and governance; general-purpose foundation-model training should preferentially use data for which RTH has clear training rights, synthetic data, and appropriately governed non-identifiable data.

8. Disclosure and processors

Health data may be disclosed only to approved service providers acting for RTH, to a recipient the user directs RTH to share with, to authorized institutional/research participants under appropriate agreements, or where required or permitted by law. A product subprocessor list will identify material processors before external health-data collection begins. See Service Providers & Subprocessors.

9. Rights

Depending on applicable law, a user may have rights to confirm processing, access, obtain a copy, correct, delete, withdraw consent, restrict certain uses, obtain portability, or appeal a denied request. RTH will not discriminate against a person for exercising a legally protected privacy right. See Data Rights & Requests.

10. Retention

Health-data retention must be tied to the feature, user expectation, law, research protocol, contractual obligation, and security need. RTH will publish product-specific retention information before launch. Deletion will address active systems and scheduled backup expiration, subject to lawful preservation requirements. See Data Retention & Deletion.

11. Security and health-breach response

Consumer health data requires heightened access, logging, encryption, segregation where appropriate, incident detection, and breach assessment. If RTH experiences a breach covered by the FTC Health Breach Notification Rule, state consumer-health law, HIPAA, or another applicable rule, RTH will follow the notification requirements that apply to the affected data and workflow.

12. Revoking a connected source

Disconnecting a wearable or records source stops future collection from that connection after the revocation is processed; it does not necessarily delete information already lawfully imported. Users may separately request deletion where applicable. A third party may retain information previously sent to it at the user's direction under that third party's policies.

Privacy and data requests: privacy@restartingtheheart.com. Do not send medical records, passwords, authentication codes, government identifiers, or other unnecessary sensitive information by ordinary email.

Security reports: security@restartingtheheart.com. See the Vulnerability Disclosure Policy before performing security testing.

General questions may use the RTH contact page.