Consumer Health Data Privacy Policy
Last updated: August 20, 2026
Holakare is a place to write down your family's care — the medicines, the doses, the sick days. Almost everything you put in it is health information about someone you love, so it deserves its own page rather than a paragraph inside a longer document.
This policy covers consumer health data: information that is linked to you and that describes someone's physical or mental health. It sits alongside our general Privacy Policy, which still applies to everything else. Where the two overlap, this page is the more specific one.
It exists because of Washington State's My Health My Data Act, and Washington residents have the rights described in Your rights below. We apply this policy to everyone who uses Holakare, wherever they live, because writing one set of rules and following it everywhere is simpler than sorting people by address — and because the answer we would give a Washington resident is the answer we want to give you.
What we collect, and why
We collect this because it is the service you asked us for: without it there is no record to keep, nothing to remind you about, and nothing to show the rest of your household. We do not use it to advertise to you, to build a profile of you, or to infer anything about you beyond what you wrote down.
About the people in your household
- Names, dates of birth, and any notes or conditions you choose to record
- Photos you attach to a person, if you add one
Medicines and treatments
- Medicine names, dose types, categories, quantities, expiry and opening dates
- Treatment schedules — what is taken, how much, how often, and for how long
- Every dose recorded as taken, skipped, or missed, with its time; and, for an injection, the site you recorded
Sick days and observations
- Care Episodes — an illness you are tracking, its category, and when it began
- Quick Log observations — symptoms, temperatures, notes, and optional photos
Care providers
- Doctors, health centers, and the visits you record against them
Your account
- Your email address and name, and which household you belong to
- When your account was last active, so dormant households can be cleaned up
Where it comes from
All of it comes from you, or from another member of your household. You type it, photograph it, or tap it in the app or the web portal. We do not buy consumer health data, and we do not receive it from data brokers, advertising networks, public records, or any other outside source.
A household is shared on purpose: what one caregiver records, the others can see. That is the point of the product, and it is not a disclosure to a third party — it is the household you chose to join.
What we share, and with whom
We do not sell your consumer health data. We never have. Selling it would require a signed authorization from you under Washington law, and we do not ask for one.
We do not share your consumer health data with anyone for their own purposes — not with advertisers, data brokers, insurers, employers, or analytics companies. The only companies that touch it are the service providers that run Holakare for us, under contract, and only so the app works:
- Supabase — the database and photo storage where your household's records live.
- Railway — hosting for the Holakare API.
- Netlify — hosting for this website and the web portal.
- Resend — sending sign-in links, household invitations, and account emails. Resend receives your email address. It does not receive health data.
- Apple — subscription processing. Apple receives no health data from us.
These providers act on our behalf and may not use your data for anything else. We share no consumer health data with affiliates, because we have none.
Two things that leave the app without going to us
Medicine name lookup. When you search for a medicine while adding one, your device asks the U.S. National Library of Medicine's public RxNorm and DailyMed services directly. The only thing sent is the drug name you typed. No account, session, or device identifier goes with it, the request carries nothing about who you are or who the medicine is for, and neither the query nor its result is stored. The lookup is optional — you can type a name yourself and skip it.
Photos. Photos you attach are encrypted on your device before they are uploaded, so we hold only ciphertext and cannot read them. We also strip location and camera metadata and keep only a resized copy and a small thumbnail.
One exception, stated plainly: photos added before we introduced on-device encryption were stored unencrypted, and not all of them have been replaced.
- Patient photos — the picture on a person's profile — are re-uploaded in encrypted form the first time the app opens one. Until that happens, that photo is still readable by us.
- Quick Log photos — the pictures attached to an observation during an illness — are not migrated. A legacy one stays readable by us for as long as it exists. Deleting the Quick Log deletes the photo with it, and any photo added since encryption arrived is sealed on your device as described above.
Those legacy photos are protected the same way the rest of your record is — scoped to your household, access-controlled, and never shared — but that is access control, not encryption, and the two are not the same promise. We would rather name the gap than let "we cannot read them" cover photos it does not.
Analytics
We use goodday, our own analytics, which we host ourselves — the numbers do not go to an outside analytics company. It sets no cookies and reads no identifiers: no advertising ID, no device ID, nothing from HealthKit, contacts, or location.
The app counts generic actions so we can tell whether features are working — for example that a dose was recorded, or that an item of some kind was added. These counts carry no identifier of any sort, so they cannot be connected back to you, to your household, or to any person in it, and they never include a medicine name, a symptom, a note, or a photo. You can turn analytics off in the app's settings.
Your rights
You can ask us to:
- Confirm and access. Tell you whether we collect, share, or sell your consumer health data, give you a copy of it, and give you the list of every third party we have shared it with.
- Withdraw consent. Stop collecting it, stop sharing it, or both.
- Delete. Delete it from our live systems and from the service providers that hold it for us. Backups are the one place we cannot reach on request — see below.
You can do most of this yourself, immediately, without asking us. Your records are visible and editable in the app at any time, and Settings → Delete Account deletes your account and its data. Your sign-in stops working straight away. When the last member of a household deletes their account, the shared household record is scheduled for deletion and permanently purged after a 30-day recovery window, during which it is inaccessible but can be restored if the deletion was a mistake.
About backups. Deleting your record removes it from the systems that serve the app. It does not reach into our backups, and we would rather say so than imply otherwise. Backups exist so a failure or an attack cannot destroy a household's medical history, and to do that job they are deliberately immutable — nobody can edit or selectively remove anything from them, including us. They age out instead, on a fixed schedule: the daily database backups within seven days, and the separate encrypted archive within ninety. After that no copy of your record remains anywhere.
About photo files. Photo files live in storage separate from the database and are removed straight after the record itself. If that step fails, the leftover files are reconciled by a sweep rather than left indefinitely. We record the outcome either way, so a deletion is never reported as complete when it was not.
To make a request in writing, or to ask for something the app cannot do for you, email [email protected]. We will respond within 45 days. If we need more time we will tell you why within those 45 days and take up to 45 more.
If we refuse a request, we will explain why and how to appeal. To appeal, reply to that message or write to [email protected] with "appeal" in the subject line; we will answer within 45 days. If we deny your appeal, you may complain to the Washington State Attorney General.
Geofencing
We do not use geofencing. Holakare does not track your location, and we do not build virtual boundaries around hospitals, clinics, pharmacies, or any other health facility to identify you, advertise to you, or collect data about you.
Children
Holakare is for adults organizing their family's care. Children do not have their own accounts. An adult account holder enters and controls everything in a household, including details about the children in it.
Changes
If we start collecting a new category of consumer health data, or using it for a new purpose, we will update this page and ask for your consent before doing so — not after.
Contact
Holakare is operated by Metric Ton LLC. Write to [email protected] with any question about this policy, or anything on this page you would like explained.

