Back

Consumer Health Data Privacy Policy

Last updated September 25, 2026

This notice is required by Washington's My Health My Data Act and describes, specifically and separately from our general Privacy Policy, how Meloa LLC ("we," "us," "our") collects, uses, and shares your consumer health data — information that identifies your past, present, or future physical or mental health status. If anything here conflicts with the general Privacy Policy on how health data specifically is handled, this notice controls.

Categories of consumer health data we collect, and why

Distress ratings (SUDS logs)

0–100 anxiety scores, and optional somatic/cognitive/anticipatory/autonomic breakdowns, tied to specific events or logged ad hoc.

Purpose: Compute your baseline anxiety trend and detect patterns like the Anticipation Gap shown on your Record page.

Baseline mental health assessments

General anxiety, social anxiety and depression self-report scores: check-ins adapted from the GAD-7 and PHQ-9, plus a short social-anxiety check-in written for Meloa.

Purpose: Track how your baseline anxiety and mood shift over weeks or months, shown as longitudinal trend lines on your Record page.

Daily anxiety logs

One whole-day 0–100 rating and optional notes, per day.

Purpose: Shade calendar day cells and provide a coarse day-level view distinct from individual event ratings.

Medications & adherence logs

Medication name, dosage, frequency, schedule, and whether each scheduled dose was taken, skipped, or partial.

Purpose: Power daily adherence check-ins and the medication adherence trend line on your Record page.

Event anxiety ratings & cognitive profile

Per-event 1–10 anxiety ratings; time-blindness level, rejection sensitivity, and checking-compulsion score you provide during onboarding or intake.

Purpose: Drive pre-event lockout timing, post-event decompression buffers, and OCD-safeguard schedule locking defaults.

Breathing & guided relax session history

Session type, duration, and completion status for breathing exercises and guided relax audio.

Purpose: Show your own session history; not used for anything beyond your own account.

Intake questionnaire responses

Executive-function, schedule-preference, and baseline-anxiety answers from onboarding.

Purpose: Set your initial app defaults (spoon budget, buffer lengths, category defaults); retaken any time to re-tune them.

Period start dates (optional)

The first day of each period, only if you turn on period tracking and log it yourself. Never inferred from your mood or anything else. Plus one setting: how many days before an estimated period you'd like more room.

Purpose: Let your own record show what the days before and during your period do to your anxiety numbers, using the same statistics as every other pattern. The estimate of your next period, from your own logged dates, is used only to honor the room setting you chose — never to tell you how a week will go.

Facts Meloa has worked out about you (your working profile)

One-sentence conclusions with a pointer to their source: "anticipation runs hottest around work things," "you finish focus tasks in the morning," "you told us phone calls are a trigger." Never a predicted score, a diagnosis, or a risk level.

Purpose: Size buffers, pick calmer windows, and let Talu refer to things you have actually done. Every fact is visible on your facts page, where you can hide, correct, or delete it. See the section below.

What Meloa learns about you

Meloa keeps a working profile: a set of facts it has worked out from what you log, so it can size buffers, pick calmer windows, and let Talu refer to things you have actually done. Every fact has a source you can see — the check-ins, ratings, events, tasks, or answers it came from. Facts come from three places:

  • Computed from your numbers and dates. This is arithmetic over your own record and involves no outside service.
  • Distilled from things you wrote: the notes beside a rating, prep notes on an event, notes on a task or a day, and any journal entry you asked Talu to reflect on. Distilling uses Google Gemini, runs only if you have turned on AI-assisted features, and is part of the Premium plan.
  • Stated by you, on the “What Meloa knows about you” page.

Your journal is not read to build this profile. An entry is read once, only when you press “Ask Talu to reflect” on it. Entries you have not asked about are never sent anywhere and never used to learn about you. Chats with Talu are never stored, with two exceptions you choose: a reply you save to your journal, and a reply you report, which sends that reply and your message just before it to the Meloa team.

The profile never contains a predicted score, a diagnosis, or a risk level. Meloa’s whole approach depends on your own before-and-after numbers, and a number a model made up would poison that record.

You can see every fact, hide any fact so nothing uses it, correct it, or delete it, at Record → What Meloa knows about you. Deleting your account deletes the profile with everything else, and your data export includes it.

Who we share it with, and why

We do not share your consumer health data with anyone beyond what's listed below, and never for advertising or to build profiles about you for other companies.

Supabase

Database hosting and authentication — stores every category above.

Shared: Always, as our infrastructure provider, to operate the Service you asked for. Not optional and not a consent choice — the app cannot function without a database.

Google Gemini (Google Cloud AI)

Talu's AI features are provided by Google's Gemini, a third-party AI service: task breakdown, planning from a description, paste and photo import, chat, weekly reflections, journal reflections you request, and (on Premium) distilling the notes you write into facts on your working profile. What is sent: text you type, paste or dictate; task and event details, including the anxiety ratings you give them; photos you choose; and your distress (0–100) and daily anxiety ratings, with the notes beside them when you chat with Talu, or as weekly averages when you ask for a weekly reflection. Text is run through PII redaction before it is sent.

Shared: Only while "AI-assisted features" is on in Settings → Privacy, and only on accounts belonging to someone 18 or over. It is off by default at every age, nothing is sent while it is off, and you can turn it off there at any time. Meloa itself is available from age 13, but Gemini's own terms require adult users, so on an account whose date of birth is under 18 the switch cannot be turned on and nothing is ever sent — buying a paid plan does not change that. Task Breakdown still works without it via a non-AI heuristic fallback.

OpenAI (text-to-speech)

Talu's spoken voice. What is sent: the replies Talu writes to you in chat, which can mention your events, tasks and how you've been feeling. Your own messages are never sent. The reply is turned into audio and returned to your device; Meloa stores none of it, and OpenAI does not use it to train its models.

Shared: Only after you turn on Talu's voice in a chat and agree on the screen that names OpenAI, only while "AI-assisted features" is also on, and only on accounts belonging to someone 18 or over. It is off by default, is never used for a crisis reply, and you can withdraw it anytime in Settings → Privacy.

PostHog

Product analytics — named, deliberate events (e.g. "onboarding_completed") with your account ID, never free-text health data, never autocapture of form inputs.

Shared: Only when you've turned on "Product analytics" in Settings → Privacy. Off by default, and never sent if your browser sends a Global Privacy Control signal.

Stripe

Billing — payment and subscription-tier information only. Never receives health data.

Shared: Only if you subscribe to Premium or Pro.

Resend

Transactional email delivery (account confirmation, notifications you opt into).

Shared: Only your email address and the notification content itself — never your logged health data.

Vercel

Application hosting — every request to Meloa passes through it in transit.

Shared: In transit only, encrypted; Vercel does not store your health data.

Sentry

Error reports when something in the app breaks.

Shared: Technical details of the failure. Form contents and logged values are not attached to a report.

We do not sell your consumer health data

Meloa does not sell consumer health data, and has never sold it, to any third party — not to data brokers, advertisers, or anyone else. If that were ever to change, the law requires (and we would provide) a separate, signed authorization naming the buyer, the specific purpose, and an expiration date — not a routine consent pop-up. We have no plans to introduce this.

No location-based tracking near healthcare facilities

Meloa does not use device geolocation, and does not establish geofences around hospitals, clinics, reproductive health facilities, or any other healthcare facility to track your visits, collect data, or trigger notifications or advertising. The only location-related features in the app work from addresses you type in yourself: a text-based address autocomplete for event locations, saved places you choose to add (like Home), and optional travel-time estimates between them. None of these read your device's GPS, and the addresses you save are visible only to you and deletable at any time in Settings.

Your consent and how to withdraw it

Collecting your consumer health data requires your affirmative, opt-in consent, given at signup (or, for accounts created before this notice existed, the first time you sign back in). Sharing it with Google Gemini or PostHog requires a second, separate opt-in — both are off until you turn them on.

You can withdraw the sharing opt-ins at any time from Settings → Privacy, with immediate effect. Because the collection of this data is what the core product does, withdrawing consent to collection itself means closing your account — see Delete Account in the same section. Deletion cascades through our database, backups, and the third-party processors above within 30 days, with no retention exceptions.

You can also download a full, machine-readable copy of everything listed above at any time from the same section of your profile settings.

Contact

Questions about this notice, or requests to access, correct, or delete your consumer health data, can be sent to support@meloa.io.