Why this policy exists
The Washington My Health My Data Act and Nevada's consumer health data law (SB 370) give you specific rights over "consumer health data", which means personal information that identifies your past, present or future physical or mental health status, including data from wearables and inferences drawn from it. Auracare Health Ltd ("Auracare", "we", "us") is the regulated entity for the purposes of these laws.
The consumer health data we collect
With your consent, Auratwin may collect:
- Health and wellness measurements from sources you connect: sleep, activity, heart rate, recovery, body composition and continuous glucose readings;
- Things you tell Aura in conversation about how you feel, what you ate, and your habits, and the wellness inferences the twin draws from them (for example, your sleep baseline);
- Precise location, only if you separately opt in, used to give your guidance context such as time zones and travel;
- Account and delivery information (name, email, the messaging identity you use) needed to run the service.
Voice notes are transcribed and the audio is then discarded. We do not create voiceprints and we do not use biometric identification.
Where it comes from
Only from you: the sources you explicitly connect through each provider's own authorisation screen (for example Apple Health, Oura, Garmin or Dexcom), and the messages you send Aura. We do not buy health data, and we do not collect it from data brokers, advertisers or public sources.
Why we collect it
To build and maintain your personal digital twin, learn your baselines, notice meaningful changes, and send you the check-ins you asked for. We also use it to keep the service secure and reliable. We do not use your consumer health data for advertising.
Who we share it with
We do not sell your consumer health data. Selling it would require your separate, signed authorisation under Washington law, and we do not seek one. We share it only with service providers (such as cloud hosting and message delivery) that process it on our instructions under contract, and with no one else unless you direct us to or the law requires it. We never use your location to infer visits to healthcare facilities, and we do not use geofencing around health services.
Information that we have aggregated or de-identified so that it no longer identifies you, and cannot reasonably be linked back to you, is not consumer health data, and it never includes your precise location. We take reasonable measures to ensure it cannot be associated with you, we publicly commit to using and sharing it only in de-identified form and never attempting to re-identify it, and we contractually require anyone who receives it to commit to the same. Subject to those commitments, this policy does not restrict our use or sharing of that de-identified information.
Your rights
- Know and access the consumer health data we hold about you, including the third parties and affiliates it has been shared with;
- Withdraw consent to our collection or sharing of your consumer health data;
- Delete your consumer health data, including from our backups and from our processors;
- Appeal a decision we make about any of these requests.
To exercise any of these rights, email privacy@auracare.org.uk. We will confirm receipt, respond within the time the law allows, and never discriminate against you for exercising a right. If we deny a request, our response explains why and how to appeal; if your appeal is unsuccessful, you may contact the Washington State Attorney General or the Nevada Attorney General.
Changes
If we materially change how we handle consumer health data, we will update this policy, change the date above, and tell you in-app or by email before the change takes effect. New uses of your consumer health data will always ask for your consent first.
Contact
Questions about this policy? Write to us at privacy@auracare.org.uk.