Consumer Health Data Privacy Policy
Last updated: September 26, 2026
Holakare is a place to write down your family's care: the medicines, the doses, the sick days. Almost everything you put in it is health information about someone you love, so it deserves its own page rather than a paragraph inside a longer document.
This policy covers consumer health data: information that is linked to you and that describes someone's physical or mental health. It sits alongside our general Privacy Policy, which still applies to everything else. Where the two overlap, this page is the more specific one.
It exists because of Washington State's My Health My Data Act, and Washington residents have the rights described in Your rights below. We apply this policy to everyone who uses Holakare, wherever they live, because writing one set of rules and following it everywhere is simpler than sorting people by address, and because the answer we would give a Washington resident is the answer we want to give you.
What we collect, and why
We collect this because it is the service you asked us for: without it there is no record to keep, nothing to remind you about, and nothing to show the rest of your household. We do not use it to advertise to you, to build a profile of you, or to infer anything about you beyond what you wrote down.
One thing we collect is not consumer health data, and we mention it here so the picture is complete: the waitlist button on our home page opens a sign-up page hosted by Mailchimp, and whatever you enter there (an email address, an optional name, and whether you ticked the optional beta box) reaches us. That is a marketing contact, not a health record; it is stored separately from any household, it is never joined to one, and it is used only to tell you when Holakare is available.
About the people in your household
- Names, dates of birth, and any notes or conditions you choose to record
- Photos you attach to a person, if you add one
Medicines and treatments
- Medicine names, dose types, categories, quantities, expiry and opening dates
- Treatment schedules: what is taken, how much, how often, and for how long
- Every dose recorded as taken, skipped, or missed, with its time; and, for an injection, the site you recorded
Sick days and observations
- Care Episodes: an illness you are tracking, its category, and when it began
- Quick Log observations: symptoms, temperatures, notes, and optional photos
Care providers
- Doctors, health centers, and the visits you record against them
Your account
- Your email address and name, and which household you belong to
- When your account was last active, so dormant households can be cleaned up
Where it comes from
All of it comes from you, or from another member of your household. You type it, photograph it, or tap it in the app or from a signed-in browser session. We do not buy consumer health data, and we do not receive it from data brokers, advertising networks, public records, or any other outside source.
A household is shared on purpose: what one caregiver records, the others can see. That is the point of the product, and it is not a disclosure to a third party; it is the household you chose to join.
What we share, and with whom
We do not sell your consumer health data. We never have. Selling it would require a signed authorization from you under Washington law, and we do not ask for one.
We do not share your consumer health data with anyone for their own purposes, not with advertisers, data brokers, insurers, employers, or analytics companies. The only companies that touch it are the service providers that run Holakare for us, under contract, and only so the app works:
- Supabase: the database and photo storage where your household's records live.
- Railway: hosting for the Holakare API.
- Cloudflare: the network in front of the Holakare API and this website. Requests from the app and from a browser, including those that carry household records, pass through it on their way to us.
- Netlify: hosting for this website. When Holakare is used from a browser, API requests that carry household records also pass through Netlify.
- Resend: sending sign-in links, household invitations, and account emails. Resend receives your email address. It does not receive health data.
- Apple: subscription processing. Apple receives no health data from us.
- Mailchimp (Intuit): sending the launch note, and a beta invitation if you asked for one, to people who joined the waitlist. You sign up on Mailchimp’s own page, so it receives what you enter there plus the technical request data any web request carries (your IP address and browser user-agent). It receives no consumer health data, and no waitlist address is ever joined to a household record.
These providers act on our behalf and may not use your data for anything else. We share no consumer health data with affiliates, because we have none.
Two things that leave the app without going to us
Medicine name lookup. The lookup is off until you turn it on: the first time you type a medicine's name, the app asks whether to use it, and you can change your answer in Settings at any time. While it is on, your device asks the U.S. National Library of Medicine's public RxNorm and DailyMed services directly. RxNorm receives the drug name you typed, and DailyMed the RxNorm identifier of the result you pick. As with any web request, the Library also sees your IP address and routine technical details: the app's name and version, and your preferred language. No account, session, or device identifier goes with either request, and neither names you or the person the medicine is for. We do not store your search. If you pick a result, its RxNorm identifier and a link to its official DailyMed page are saved with that medicine, like the rest of your household's record. With the lookup off, nothing goes to the Library; you type the name yourself.
Photos. Photos you attach are encrypted on your device before they are uploaded, so we hold only ciphertext and cannot read them. We also strip location and camera metadata and keep only a resized copy and a small thumbnail.
One exception, stated plainly: photos added before we introduced on-device encryption were stored unencrypted, and not all of them have been replaced.
- Patient photos, the picture on a person's profile, are re-uploaded in encrypted form the first time the app opens one. Until that happens, that photo is still readable by us.
- Quick Log photos, the pictures attached to an observation during an illness, are re-uploaded in encrypted form the first time the app opens one, the same way as patient photos. Until that happens, that photo is still readable by us. Removing the photo from an observation deletes it. Marking the observation itself as a mistake hides it from everyone in your household but does not erase the picture. That happens when the record it belongs to is deleted: right away if you delete the person it is about, 90 days after you delete the illness it was filed under, or at the end of the 30-day recovery window described under Your rights once the last member of your household deletes their account. From then on Holakare can no longer reach the photo, and we delete its stored file. If that deletion fails, the leftover file can stay in storage, still unreachable from Holakare, until it is cleaned up. Any photo added since encryption arrived is sealed on your device as described above.
Those legacy photos are protected the same way the rest of your record is (scoped to your household, access-controlled, and never shared), but that is access control, not encryption, and the two are not the same promise. We would rather name the gap than let "we cannot read them" cover photos it does not.
Analytics
The app uses GoodDay, our own analytics, which we host ourselves; the numbers do not go to an outside analytics company. GoodDay sets no cookies and reads no identifiers: no advertising ID, no device ID, nothing from HealthKit, contacts, or location. That describes our analytics rather than the whole site; joining the waitlist sends you to Mailchimp’s sign-up page, where you type an email address.
The app counts generic actions so we can tell whether features are working, for example that a dose was recorded, or that an item of some kind was added. These counts carry no identifier of any sort, so they cannot be connected back to you, to your household, or to any person in it, and they never include a medicine name, a symptom, a note, or a photo. You can turn analytics off in the app's settings.
Separately, the iPhone and iPad app can send GoodDay Diagnostics: coded reports of non-fatal failures (for example that a sync or a save failed). Those reports carry only fixed labels (an error type, an operation name, and recent screen names) plus the app's version and build and the major iOS version. They never include stack traces, names, notes, doses, identifiers, or the text of an error. You can turn diagnostics off in the app's settings, independently of analytics.
Your rights
You can ask us to:
- Confirm and access. Tell you whether we collect, share, or sell your consumer health data, give you a copy of it, and give you the list of every third party we have shared it with.
- Withdraw consent. Stop collecting it, stop sharing it, or both.
- Delete. Delete it from our live systems and from the service providers that hold it for us. Backups are the one place we cannot reach on request; see below.
You can do most of this yourself, immediately, without asking us. Your records are visible and editable in the app at any time, and Settings → Delete Account deletes your account and its data. Your sign-in stops working straight away. When the last member of a household deletes their account, the shared household record is scheduled for deletion and permanently purged after a 30-day recovery window, during which it is inaccessible but can be restored if the deletion was a mistake. We keep your information only as long as you use Holakare: a household with no active subscription whose members have all been inactive for an extended period (at least 12 months, plus a grace period) may also be permanently deleted.
When the last member of a household deletes their account, we keep that person's email address for that same window, solely so we can confirm in writing once the deletion has actually completed. The confirmation is sent after the household record has been permanently deleted rather than when the request is made, which is why the address has to outlast the sign-in. It is destroyed the moment the deletion completes, before the confirmation is even sent; so if that message fails to reach you, your address is still gone. It is used for nothing else, and if the deletion is canceled or does not go ahead it is destroyed then instead.
Two details about that deletion we would rather state than gloss. First, most of what goes, patient profile photos included, is held inside the household record itself and is removed in the same operation, checked before the deletion is recorded as complete. Where photos are instead kept as separate files, those files are removed immediately afterwards; if that removal fails they are already unreachable, nothing in the app can find or serve a photo once its record is gone, but the underlying bytes can remain in our private storage until a later clean-up removes them. Second, we keep one thing permanently: a record that the deletion happened, which includes a one-way fingerprint of the email address that asked for it. It cannot be turned back into your address, it is never used to contact you or to recognize you if you sign up again, and it exists so that if you ever ask us to confirm the deletion we can show it took place.
About backups. Deleting your record removes it from the systems that serve the app. It does not reach into our backups, and we would rather say so than imply otherwise. Backups exist so a failure or an attack cannot destroy a household's medical history, and to do that job they are deliberately immutable; nobody can edit or selectively remove anything from them, including us. They age out instead, on a fixed schedule: the daily database backups within seven days. We are not publishing a specific timetable for any other backup layer until it has been proven in a live restore drill.
About photo files. Photo files live in storage separate from the database and are removed straight after the record itself. If that step fails, the leftover files are already unreachable, nothing can find or serve them, and a periodic sweep can reclaim them, though we do not promise a fixed timetable for that. The written confirmation refers to the household record: it is sent once that record is permanently deleted, and it does not claim more than that.
To make a request in writing, or to ask for something the app cannot do for you, email [email protected]. We will respond within 45 days. If we need more time we will tell you why within those 45 days and take up to 45 more.
If we refuse a request, we will explain why and how to appeal. To appeal, reply to that message or write to [email protected] with "appeal" in the subject line; we will answer within 45 days. If we deny your appeal, you may complain to the Washington State Attorney General.
Geofencing
We do not use geofencing. Holakare does not track your location, and we do not build virtual boundaries around hospitals, clinics, pharmacies, or any other health facility to identify you, advertise to you, or collect data about you.
Children
Holakare is for adults organizing their family's care. Children do not have their own accounts. An adult account holder enters and controls everything in a household, including details about the children in it.
Changes
If we start collecting a new category of consumer health data, or using it for a new purpose, we will update this page and ask for your consent before doing so, not after.
Contact
Holakare is operated by Metric Ton LLC. Write to [email protected] with any question about this policy, or anything on this page you would like explained.