Who this applies to
This notice applies to consumers in Washington, Nevada, Connecticut, and any other U.S. jurisdiction with a comparable consumer-health-data law. Where the protections in those laws exceed the protections in our general Privacy Policy, this notice and the underlying law control. Where the general Privacy Policy provides stronger protections, the general Policy controls.
Categories of consumer health data we collect
The Services are in a limited beta. The list below describes the categories we actually hold today, not a planned end-state.
- Individual health conditions, diagnoses, treatments, medications, and procedures (past, present, or future).
- Reproductive- and sexual-health information, where it appears in a record you provide or connect.
- Mental-health information, where it appears in a record you provide or connect.
- Substance-use information, where it appears in a record you provide or connect. Read Section 12 of the Terms of Service first: we do not have the machinery that 42 C.F.R. Part 2 requires and we do not hold ourselves out as a Part 2 compliant recipient.
- Genetic information, which reaches us only as a file you upload (a 23andMe or AncestryDNA raw export). There is no genetics account connection, and nothing genetic enters your record unless you put it there.
- Bodily functions, vital signs, symptoms, and measurements (heart rate, heart-rate variability, sleep stages, respiratory rate, temperature, blood pressure, blood oxygen, weight, activity, and similar).
- Laboratory results, allergies, immunizations, pregnancy records, social history, practitioner details, and visit records received through Android Health Connect’s Medical Records FHIR R4 feed or entered by you or a clinician you authorize.
- Coarse location captured at each sign-in, and continuous precise location where you grant that permission. The setting that enables continuous location and travel detection is on by default for new accounts and can be turned off at any time. Precise location can indicate an attempt to acquire or receive health services or supplies, and we treat it accordingly.
- Health-appointment and travel information derived from your calendar, including events that Google itself generated from your email and placed in your calendar. We hold no mail permission, but those events are visible to us through the calendar connection.
- The inventory of health applications installed on your device, which the operating system reports when you connect a health platform.
- Biometric identifiers are not collected. If a future feature collects them, we will obtain a separate written release first.
Sources we collect from
We collect consumer health data directly from you, from the sources you authorize, from clinicians you authorize, and automatically from your interaction with the Services. A source not named here is not connected.
- Wearables and recovery platforms: Whoop, Oura, Withings, Polar, Wahoo, and devices such as Fitbit that report through Google Health.
- Apple Health on iOS and watchOS, and Android Health Connect, including its Medical Records FHIR R4 feed.
- Google Calendar, on read access plus a dedicated Aler calendar we write to.
- Files you upload, including genetics raw exports, lab PDFs, and photographs of documents.
- Messages and documents you send into your vault by email.
- Clinicians you have authorized to contribute to your record.
What is not a source. Direct hospital EHR connections, pharmacy systems, and claims feeds are not built. Laboratory connections exist in the code but are credentialing-gated and are not enabled. No Sponsor program is live, so we receive no data from a sponsoring organization today. An earlier version of this notice named lab vendors, pharmacies, and genetics services as connected sources. That described an intended architecture and has been corrected. See the general Privacy Policy for details.
Purposes and uses
We use consumer health data only to (i) provide the Services you have requested and to build your personal-baseline model, (ii) communicate with you about the Services, (iii) operate, secure, and develop the Services, (iv) comply with law, and (v) generate de-identified or aggregated information consistent with the de-identified data terms in the general Privacy Policy. We do not use consumer health data for cross-context behavioral advertising and do not provide consumer health data to insurers, employers, or marketers in identifiable form.
Two uses worth stating explicitly. First, producing a reply to a question you ask requires transmitting the context assembled for that question, which can include your conditions, medications, laboratory values, and recent metrics, to a third-party inference provider. Second, your baseline is computed inside your own account from your own history, while the shared models that read it are trained on de-identified data, including de-identified data derived from your account. Data that could identify you never enters training.
What we do not do. We do not run product analytics, session recording, or behavioral tracking, we do not send consumer health data to an analytics or attribution vendor, and we do not run advertising in the Services.
Your rights
You may at any time:
- Confirm whether Aler is collecting, sharing, or selling your consumer health data and access that data.
- Withdraw consent, including consent to processing of consumer health data and to inclusion in de-identified data licensing.
- Request deletion of your consumer health data, subject to limited exceptions required by law.
- Appeal a denial of a rights request as described in the general Privacy Policy.
- Lodge a complaint with the Washington Attorney General (atg.wa.gov), the Nevada Attorney General, the Connecticut Attorney General, or any other applicable state authority.
To exercise these rights, contact [email protected]. We respond within thirty (30) days, with extensions only where the law permits.
Retention
We retain consumer health data only as long as necessary to provide the Services, comply with legal obligations, and resolve disputes. The retention windows in the general Privacy Policy apply.
How deletion works today, stated plainly. You can delete individual records at any time, and closing your account schedules the whole record for deletion with a thirty-day window. The automated purge worker that erases the marked record at the end of that window is not built yet, so that final erasure is currently performed manually. Turning off continuous location stops new location from being recorded but does not by itself delete the history already recorded; deleting that history is a separate action you can take.
Security
We protect consumer health data with the safeguards described in the general Privacy Policy and at /trust/security. Both split honestly between the controls in place today and the ones on our pre-launch roadmap, and you should read them as written rather than assuming a mature security program. In place today: column-level encryption on encrypted volumes, TLS in transit, role-based access on least privilege, mandatory two-factor authentication for clinicians, device-bound revocable sessions, row-level isolation of each account inside a shared database, an append-only audit log, and health content stripped from logs and error reports. Not in place today: a retained security-event pipeline, anomaly detection, an annual third-party penetration test, multi-zone redundancy, and vendor Business Associate Agreements. We are HIPAA-aware. We are not HIPAA-certified, no such certification exists, we hold no SOC 2 report, and we do not claim HITRUST.
Changes
We will announce material changes to this notice in the product, by email to active users, and on this page at least thirty (30) days before they take effect, except where a faster change is required by law.
Contact
Privacy Officer · Aler Health, Inc.
Email: [email protected]
Notice address: 1209 Orange Street, Wilmington, DE 19801, USA
