Consumer Health Data Privacy Policy
Effective date: August 12, 2026
Developer: Primealpha Research
Privacy contact: [email protected]
This policy supplements Aeviva's general Privacy Policy. It is intended to describe Aeviva's current practices for information that may qualify as consumer health data under applicable U.S. state law, including laws that can define collection broadly enough to include local access, processing, derivation, or inference. This policy does not limit rights provided by applicable law.
1. Age policy
The current U.S. web launch is intended for adults age 18 and older.
2. Categories of consumer health data Aeviva may collect or process
Depending on the features available and the features you choose, categories may include:
- Heart rate, resting heart rate, sleep, steps, activity, and related health-platform records you authorize;
- Camera-derived pulse spot checks, signal quality, and related derived features;
- Wellness, nutrition, supplement, activity, sleep, and user-entered notes;
- Laboratory-document information or derived biomarker information when you choose an available laboratory-document feature;
- Derived or inferred wellness information such as trends, biological-age estimates, recovery-related scores, or similar non-diagnostic metrics;
- Permission, consent, provenance, quality, audit, and integrity information connected to health features.
3. Sources
Sources may include information you enter, device sensors you activate, Apple Health or Health Connect records you authorize, files or documents you choose, and information Aeviva derives locally from those sources.
4. Purposes
Aeviva processes consumer health data to provide features you request, display local wellness trends and non-diagnostic estimates, perform quality and safety checks, maintain local integrity evidence, support deletion and consent controls, and perform user-directed export or sharing when you choose it. Aeviva does not use consumer health data for behavioral advertising or data brokerage.
5. Local-first architecture and remote systems
The current health-intelligence runtime is designed so that the health dataset remains on the user's device. Aeviva Commerce Edge is designed not to accept health measurements, camera or audio telemetry, Apple Health or Health Connect records, wellness logs, N-of-1 observations, or Personal Response Graph data.
Local-first architecture does not by itself determine whether applicable law considers local access, processing, derivation, or inference to be collection. Aeviva therefore describes these practices in this policy.
6. Sharing, sale, and third parties
- Aeviva does not sell consumer health data.
- The current health-intelligence runtime does not automatically share the health dataset with Aeviva Commerce Edge, advertising networks, data brokers, or external AI providers.
- Apple Health and Health Connect may be sources of data you authorize and remain governed separately by their platform rules.
- If you explicitly export or share information, the recipient you choose receives the information under the recipient's own practices.
- If you voluntarily include health information in a support message, Aeviva may receive the information you chose to send. Do not send health information unless an approved process specifically requires it.
7. Consent and withdrawal
Where applicable law requires affirmative consent, Aeviva should obtain that consent before the relevant collection, use, or sharing. You may withdraw device and health-platform permissions in system settings and may stop using a feature. A future feature that introduces a new category, purpose, recipient, or transfer must be disclosed and consented to where required before the new practice occurs.
8. Your rights
Depending on applicable law, you may have rights to request confirmation about consumer health data Aeviva possesses, obtain information about third parties with whom Aeviva has shared or sold such data, request cessation of certain collection or sharing, withdraw consent, request deletion, or appeal a refusal.
For the current local-only health dataset, Aeviva generally cannot inspect or remotely delete data it does not possess. Use Aeviva's local deletion and permission controls for that dataset. For information Aeviva actually possesses because you transferred it to Aeviva or because another permitted remote process created it, initiate a request at [email protected]. Do not include raw health data in the initial request. Aeviva may use a separate verification process before acting.
9. Appeals
If applicable law gives you a right to appeal a refusal, send an email with the subject "Consumer Health Data Appeal" to [email protected] and identify the prior request without attaching raw health information. Aeviva will respond within the time required by applicable law.
10. Deletion
Local records can be deleted using Aeviva's Delete Account & Data control, app-storage controls, or uninstall. Apple Health or Health Connect records must be managed separately. For consumer health data Aeviva actually possesses remotely, Aeviva will process authenticated deletion requests as required by applicable law, subject to lawful exceptions and third-party retention rules.
11. Security
Aeviva applies administrative, technical, and product controls appropriate to the nature of the data and the local-first architecture. No security measure can guarantee absolute protection.
12. Geofencing and health targeting
Aeviva does not use geofencing around health-care facilities to identify, track, collect consumer health data from, or send health-related messages or advertising to consumers.
13. Changes
If Aeviva materially changes the categories, purposes, sharing practices, or other practices described here, it will update this policy and obtain consent where applicable law requires consent before the new practice begins.
14. Contact
Primealpha Research
Email: [email protected]