Legal
Consumer Health Data Privacy Notice
Flourish Daily Ltd
Effective Date: July 2, 2026
This Consumer Health Data Privacy Notice supplements our Privacy Policy and applies to "consumer health data" about residents of U.S. states with consumer health data laws, including Washington's My Health My Data Act (MHMDA) and Nevada's SB 370. Where this Notice and our Privacy Policy conflict as to consumer health data, this Notice controls.
"Consumer health data" means personal information that is linked or reasonably could be linked to you and that identifies your past, present, or future physical or mental health status, as defined by applicable state laws. For Flourish, this can include the fitness, activity, sleep, and wellness data you connect or enter, and health-related information you share in conversations and journal entries, as well as inferences we draw from that data.
Flourish is a wellness product, not a healthcare provider. We are not a HIPAA covered entity or business associate, and we do not provide medical advice, diagnosis, or treatment.
1. Categories of Consumer Health Data We Collect & Why
We collect the following categories of consumer health data to power your AI wellness guide, track your progress, and personalize your coaching:
- Bodily functions & physiological measurements: heart rate and heart-rate variability, breathing rate, blood oxygen, skin temperature, VO₂ max, and similar metrics.
- Physical activity & fitness: steps, distance, workouts and activity types, calories, and the precise location of a workout when it is recorded with GPS.
- Sleep: sleep stages, duration, and sleep quality metrics.
- Recovery & wellness scores provided by connected devices (e.g., stress, recovery, readiness).
- Nutrition you log or that a connected service provides.
- Mental and emotional wellness inputs you share in conversations, voice notes, and journal entries (e.g., mood, mindfulness, reflections).
- Inferences we derive from the above to personalize your guidance.
2. Sources of Consumer Health Data
- You: information you enter, speak, or upload (goals, journal entries, voice notes, self-reported notes).
- Connected health platforms and devices you choose to link, such as Apple Health, Android Health Connect, Samsung Health, Strava, Garmin, WHOOP, Oura, Fitbit, and similar, connected through our health-data aggregator, Spike.
- Your device: sensors and, with permission, location.
3. How We Share Consumer Health Data
We share consumer health data only with service providers and processors who act on our behalf to deliver the Services, under contract, and only for that purpose. We share the following categories of consumer health data with the following categories of third parties:
- AI providers that power your guide and process your conversations and context: OpenAI, Anthropic, Google, Deepgram, and ElevenLabs.
- AI memory providers that maintain continuity of your context: Mem0, Honcho, and Hindsight.
- Secure AI compute: E2B, an isolated cloud sandbox where our AI agent runs computations on your data.
- Real-time voice infrastructure: LiveKit.
- Health-data aggregation: Spike, which connects your chosen health platforms and devices.
- Hosting & storage: Supabase.
- Product analytics & diagnostics that help us operate and improve the app: PostHog and Sentry.
A full, up-to-date list of the specific providers and affiliates with whom we share consumer health data is available on request at privacy@flourishdaily.io.
4. We Do Not Sell Your Consumer Health Data
We do not sell your consumer health data. We do not use it for advertising, and we do not share it with advertising networks or data brokers for their own purposes.
We collect and share consumer health data only where it is necessary to provide the Services you have requested, or with your consent. You may withdraw your consent at any time by disconnecting the relevant source in App Settings or by contacting us (see Section 5).
5. Your Rights & How to Exercise Them
If you are a resident of a state with a consumer health data law, you have the right to:
- Access the consumer health data we have collected about you, including a list of the third parties and affiliates with whom we have shared it.
- Delete your consumer health data.
- Withdraw consent to our collection and sharing of your consumer health data.
- Not be discriminated against for exercising these rights.
To exercise any of these rights, use the controls in App Settings (to disconnect sources or delete your account) or email us at privacy@flourishdaily.io. We will verify and respond to your request as required by law. If we deny your request, you may appeal by replying to our decision or contacting the same email; if you have concerns about our response, you may contact your state Attorney General.
Washington residents: Washington State Office of the Attorney General: atg.wa.gov/file-complaint
Nevada residents: Office of the Nevada Attorney General: ag.nv.gov
6. Retention
We retain consumer health data for as long as reasonably necessary to provide the Services and for the purposes described in this Notice, and then delete or de-identify it. When you delete your account, we delete your consumer health data and instruct our processors to do the same, within 30 days.
7. Contact Us
Flourish Daily Ltd
Email: privacy@flourishdaily.io
Address: 15 Penzance Pl, London, W11 4PG, United Kingdom