Arxova Consumer Health Data Policy

Effective: October 4, 2026

HealthKey Labs, LLC d/b/a Arxova ("Arxova," "we," "us," or "our") wrote this policy for people whose health data is covered by Washington's My Health My Data Act, Nevada's consumer health data law (SB 370), or the consumer health data provisions of Connecticut's Data Privacy Act. It sets out what consumer health data we collect, where it comes from, why we use it, who receives it, and how you can access it, delete it, and withdraw your consent.

This policy supplements the Arxova Privacy Policy at https://arxova.health/privacy-policy. Where the two policies describe the same practice, they use the same words. If they conflict on information covered by one of these laws, this policy controls.

1. What consumer health data means

Consumer health data is personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health. It includes information that is derived or inferred, such as a score or an AI-generated insight, and information that suggests you are seeking health care. Nearly everything Arxova holds about you is consumer health data, and we treat it that way.

2. Consumer health data we collect

CategoryExamples
Medical recordsConditions, medications, allergies, immunizations, procedures, visits, lab results, imaging reports, clinical notes, the names of your clinicians and health systems, and the demographic details your health system keeps, such as your name, date of birth, sex, address, and phone number
Wearable and device dataHeart rate, heart rate variability, resting heart rate, blood pressure, blood oxygen, respiration, temperature, weight, glucose, steps, activity, workouts, sleep, and energy expenditure
Information you enterSymptoms, manual vital signs, medications and doses, supplements, meals, check-ins, survey answers, goals, notes, and questions you ask ARIA
Reproductive and sexual healthCycle and reproductive health information you enter or connect
Genetic informationGenomic data files you upload, and the summary we produce from them
Documents and photosDocuments you upload, and photos of insurance or implant cards you choose to scan
Information we createSummaries, trends, scores, alerts, patterns, insights, ARIA's memory of earlier conversations, and research study matches
Health-related usageWhich health features you use, such as a glucose or cycle feature
Information about seeking careClinics you connect with, and research studies you are matched to, pre-screened for, or join
Circle messagesMessages to your Circle contacts that can describe how you are doing, and their replies

We do not collect your device's precise location. When you search for research studies, we use a coarse location, such as your state, taken from your profile.

3. Where it comes from

  • You, when you enter information, upload documents or genomic files, scan cards, or talk to ARIA.
  • Health systems, through their patient portals, when you connect them through Fasten Health.
  • Devices and health apps you connect: Apple Health, Android Health Connect, Samsung Health, Garmin (through ROOK), Oura, WHOOP, Withings, Polar, Strava, and Sensor Bio.
  • Clinics you give access to, which can add their own care records.
  • Your Circle contacts, when they reply to a message.
  • Arxova's own systems, which create scores, alerts, insights, and matches from the information above.

We do not buy consumer health data.

4. Why we collect and use it

We collect and use consumer health data to:

  • bring in, store, organize, and display your health information;
  • calculate scores, trends, and alerts, and send you notifications and reminders;
  • provide ARIA and the other AI features described in Section 8;
  • carry out sharing that you start: share links, clinic access, Circle messages, and research steps;
  • match you to research studies if you opt in, and count community insights if you opt in;
  • understand how the app is used and fix problems;
  • protect the Service, detect misuse, and keep security logs;
  • respond to your requests and support questions; and
  • comply with the law.

We do not use consumer health data for advertising. If we want to collect new categories of consumer health data, or use or share it for new purposes, we will update this policy and ask for your consent first where the law requires it.

5. Your consent: collecting and, separately, sharing

Consent to collect. Before setting up a new account, the app asks for your consent to collect and use your health data, and confirms you are 18 or older. Earlier accounts were not asked for specific health-data collection consent beyond the Privacy Policy acceptance. They are asked the next time they open the updated app; until they answer, collection continues, including wearable syncs and incoming records. If you decline or withdraw this consent, or tell us you are under 18, we stop all new collection: no new wearable data, no new records. The app stays locked until you consent again or delete your account.

Separate consent to share. Collection consent does not replace separate sharing consent where the law requires it. Sharing with people, clinics and research teams happens through your own actions, such as creating a share link, giving a clinic access, adding a Circle contact, or consenting to research. Each has its own step, and you can end each one. Service providers also receive information as described in Sections 7–9, including default-on analytics.

AI features. The app asks separately whether to allow AI features. Until you allow them, no AI features run for your account, including background features. Declining or withdrawing stops them, as explained in Section 8.

6. Who receives your consumer health data

People and organizations you choose. We share consumer health data with these recipients only after you take the step described.

RecipientCategories of consumer health dataWhen
A clinic you connect withThe records and data you allow the clinic to seeAfter you connect using a pairing code or invite; until you or the clinic end it
Anyone with a share link you createThe categories you choose for that linkUntil the expiry shown for that share or until revoked; some share types can remain open until revoked
Your Arxova Circle contactsYour first name and message text that can describe how you are doing, sent through Twilio by SMS to phone numbers in the United States and Canada and by WhatsApp to phone numbers in other countriesWhile Circle is on, until you remove the contact or turn it off
A clinical site pre-screening you for a studyYour eligibility result for that studyAfter you sign a HIPAA authorization for that study
Research organizations receiving matching statisticsRounded counts and broad characteristics of people waitingAfter you opt in to research matching
A study team for a study you joinYour name, contact details (email, phone, address, and date of birth), and the records relevant to the studyAfter study consent and any required privacy authorization
Apple Wallet or Google WalletThe device details on your implant cardWhen you ask us to add the card

Service providers. The companies in Section 7 receive consumer health data only to provide their service to Arxova.

Legal requirements. We may disclose consumer health data when the law requires it, such as in response to a valid court order or subpoena.

Affiliates. Arxova has no affiliates that receive consumer health data.

7. Service providers

These companies receive information from Arxova. For services involving clinic protected health information, we require the appropriate Business Associate Agreements and service configurations before processing that information.

Service providerWhat it does for ArxovaWhat it receivesHealth data?
Fly.ioHosts Arxova's servers and databasesEverything Arxova stores and processesYes
AnthropicAI features listed in Section 8A minimized snapshot of your health information; documents and card photos you upload; text you typeYes
Amazon Web Services (AWS)Holds the key that signs audit receiptsSigning requests containing short digital fingerprints (hashes)No
VercelHosts the web app, website, research portal, and clinic consoleWeb traffic and request logs. The web app sends your health data directly to Arxova's servers, not through Vercel. Research-portal requests that carry consent records and research review results pass through itResearch consent and review records only, in transit
Fasten HealthConnects to your health systems' patient portalsYour portal connection; it receives your medical records from your health system on our behalfYes
ROOKConnects Garmin devicesAn account reference that includes your wallet address; the Garmin data it receives on our behalfYes
Oura, WHOOP, Withings, Polar, Strava, Sensor BioConnections you choose to these devices and appsAuthorization requests, some including your wallet address; these services send your data to usThey send us health data
Apple Health, Android Health Connect, Samsung HealthHealth stores on your phone that you allow Arxova to readNothing; Arxova reads them on your phone with your permissionRead on your phone
TwilioArxova Circle messages: SMS to phone numbers in the United States and Canada, WhatsApp to phone numbers in other countriesYour contacts' phone numbers, your first name, message text that can describe how you are doing, and repliesYes
ExpoApp updates and push notification deliveryDevice and app version; push tokens and notification text, which contains no health readingsNotification text can show that a health update is ready
Apple Push Notification service, Google Firebase Cloud MessagingDeliver notifications to your phonePush tokens and notification text, which contains no health readingsNotification text can show that a health update is ready
PostHogProduct analyticsFeature-use events under a pseudonymous identifier; limited health details in events sent before September 30, 2026Feature use can suggest health interests
PrivySign-in and your account's Solana walletEmail address, sign-in identifiers, wallet signing requestsNo
Irys and ArweavePermanent encrypted storageEncrypted records; public labels on objects written before October 1, 2026Encrypted; older labels show the record type
Solana network, through HeliusAudit receiptsReceipts with a random reference; older receipts show a wallet address and event namePseudonymous receipts; older receipts may reveal health-related event types
Lit ProtocolKey protection for an optional encryption mode that is not on by defaultKey-protection requestsNo
RevenueCatApp store purchase records; no paid features are liveA random customer identifier, device and store informationNo
WalletConnectConnecting an outside wallet, if you choose toWallet address and signing requestsNo
Apple Wallet, Google WalletYour implant card, at your requestThe device details on the cardYes, at your request
ClinicalTrials.gov (NIH)Finding research studiesA condition term, an age, and a coarse location; no name or identifierNo name or account identifier attached
Europe PMCArticle citations for ARIASearch terms from your question; no identifierNo name or account identifier attached
RxNav (NIH)Medication name lookupMedication names; no identifierNo name or account identifier attached
UPCitemdbSupplement barcode lookupProduct barcodes; no identifierNo
AppsFlyer (OneLink links only)Marketing links to app storesThe click, including device type and IP address, when you tap a linkNo

Some services are connected in our code but not in use today: Stripe (payments), Persona (identity verification), MoonPay, and Jupiter. If we start using one, we will update this list.

We require service providers to use your information only to provide their service to Arxova.

8. ARIA and other AI features

ARIA and several other features use Claude, an AI service from Anthropic, PBC. We use Anthropic’s commercial AI services. We do not authorize Anthropic to use information sent through these services to train its models. A Business Associate Agreement is required before these services process protected health information on behalf of a clinic.

When your information is sent to Anthropic:

  • ARIA chat;
  • ARIA's memory of earlier conversations;
  • building a map of how your health information connects;
  • finding patterns in your data;
  • daily insights and proactive messages, which are prepared in the background even when you have not opened ARIA;
  • doctor and visit summaries;
  • tagging meals you log;
  • choosing search terms for article citations;
  • reading documents you upload; and
  • reading photos of insurance or implant cards.

What is sent. A capped, minimized snapshot of your information, not your whole history. Depending on the feature, it can include records, lab results, medications, supplements, symptoms, wearable data, notes, cycle information, a genomics summary, scores, alerts, ARIA's memory, and recent conversation. Your name is removed from the health record before ARIA sees it, and no account details, email, phone number, address, or device identifiers are attached. Card photos, documents, and the text you type are sent as they are and can include your name or other details. Because dates, clinicians, and clinical notes can remain, we treat everything sent to Anthropic as health information, not as de-identified data. Anthropic keeps information only as allowed by its retention terms with us.

Your choice. The app asks separately whether to allow these AI features. Until you allow them, no AI features run for your account, including background features such as morning insights. Older app versions cannot show this choice, so AI features do not work on them until you update the app and answer. If you decline or later withdraw in Settings, AI features stop. Earlier ARIA permissions have been retired; they are not treated as permission under the new choice.

ARIA’s answers, scores, and alerts are informational and may be inaccurate. They are not medical advice or final clinical decisions. Automated research matching can affect which studies you see; the study team makes final eligibility and enrollment decisions.

9. Product analytics

Security and technical logs help us run the Service, protect accounts and investigate errors. They are separate from the product analytics described below. The app’s analytics switch does not stop necessary security and operational logging.

Product analytics. We use PostHog to understand how the app is used. App analytics is on by default; we have not asked for a separate app-analytics permission. You can turn off analytics events sent by the app in Settings. Some usage events are sent from Arxova’s servers, and the setting does not stop those. This switch controls the app events described here; it does not stop necessary sign-in, security or operational logging.

Since September 30, 2026, events are limited to an approved list of feature-use events, contain no health values, and are tied to a pseudonymous identifier derived from your account, not to your name or email. Events sent before that date included limited health details, such as a symptom type or a daily step total, and some were tied to your wallet address. Which features you use can suggest something about your health, for example using a glucose feature, so we treat these events as consumer health data.

On our website, PostHog loading is controlled by the cookie-choice banner. The app’s analytics setting does not control website cookies. There are no advertising, attribution, or social media tracking tools in the app, and no AppsFlyer SDK. Some of our marketing links use AppsFlyer OneLink to send you to the right app store; when you tap one, AppsFlyer records the click.

10. Research and community insights

Research is optional. Arxova does not sell health data and does not pay participants. Clinics and research institutions pay Arxova for the matching infrastructure; that fee is not payment for your data.

Research matching. If you opt in, Arxova checks your clinical records against study criteria. Wearable data is not used. Matching is automated and happens inside Arxova. Before you agree to a study, researchers see only counts, which are rounded, and broad characteristics, such as top conditions and age bands, of the people waiting. They do not see who you are. Opting out stops matching immediately.

Pre-screening by a clinical site. A clinical site that pre-screens you sees your eligibility result only after you sign a HIPAA authorization for that study. You can revoke it.

Joining a study. After you complete a study’s consent and any required privacy authorization, that study team receives your name, contact details (email, phone, address, and date of birth), and the records relevant to the study so they can enroll you. From then on, the study's consent form and the study team's own policies also apply. Information already delivered to a study team cannot be pulled back by Arxova.

Finding studies. To find studies on ClinicalTrials.gov, we send a condition term, an age, and a coarse location. We do not attach your name or account identifier. The condition, age and coarse location are still health-related search information.

No re-identification. We do not try to re-identify de-identified data, and our researcher terms require researchers not to re-identify it either.

After you withdraw. Your data is removed from research datasets within 30 days.

Community insights. If you opt in, your conditions and symptom types are counted each month, without identifying you in the published counts. Nothing about a condition is shown until at least 50 people with that condition have joined. If you opt out, your counts are removed. Your opt-in or opt-out is recorded on-chain with a random reference.

11. We do not sell consumer health data

Arxova does not sell consumer health data. We do not sell it, rent it, or trade it, to advertisers, data brokers, insurers, employers, pharmaceutical companies, or anyone else. Fees that clinics and research institutions pay Arxova are for the matching infrastructure, not for your data, and we do not pay participants.

12. No targeted advertising and no geofencing

We do not use consumer health data for targeted advertising, and we do not allow third parties to collect it through Arxova to track you across other websites or apps. We do not set up geofences around health care facilities, and we do not use location to identify or track people seeking health care or to send them messages or ads.

13. Your rights

You have the right to:

  • confirm whether we collect, share, or sell your consumer health data;
  • access your consumer health data, and receive a list of every third party and affiliate we have shared it with, and an email address or other online way to contact each of them;
  • delete your consumer health data;
  • withdraw your consent to our collection and sharing of your consumer health data;
  • correct inaccurate consumer health data, where the law gives you that right;
  • appeal if we decline your request (Section 15); and
  • be free from discrimination for using these rights. We do not penalize you for exercising a privacy right. Some features cannot work without the information they need; withdrawing the general health-data consent currently locks the app as described in Section 5. You can still make requests by email.

14. How to use your rights

In the app:

  • Access: Settings, "Download a copy of my data."
  • Correct: on a document, imaging report, note, lab history, or prescription, use "Report a problem with this record." This opens an email to us naming the record type, date, and source, without the record's contents. We fix errors in how Arxova received, processed, or displayed a record. The original record can only be corrected by the health system that created it, and we will tell you how to ask them. Information you entered yourself, you can change or remove.
  • Withdraw consent: the health data consent, AI features, research, and community insights can be withdrawn in Settings. Connections can be disconnected in the app. Section 18 of the Privacy Policy lists what each withdrawal stops and what remains.
  • Delete: Settings, "Delete account."

By email: write to privacy@arxova.health with the subject "Consumer Health Data Request" and say which right you want to use. Use this route for anything you cannot do in the app, including the list of third parties and affiliates.

Verifying your request. If you write to us from outside the app, we verify that the request comes from the account holder, for example by confirming the email on your account or asking you to sign a message with your wallet. We ask only for what we need to verify you. Where the law allows, an authorized agent may make a request for you; we may ask for proof of their authority and confirm the request with you.

Timing and cost. We respond within 45 days of receiving your request, or within a shorter period required by law. Where applicable law permits an extension, we will notify you within the initial response period and explain the reason and permitted extension. We apply a shorter deadline where required. For deletion requests sent by email, we commit to a shorter time: we complete them within 30 days (Section 16). Requests are free.

15. Appeals and complaints

If we decline your request, in whole or in part, we will tell you why. You can appeal by emailing privacy@arxova.health with the subject "Consumer Health Data Appeal," including enough detail for us to find your original request. We will respond to your appeal in writing within 45 days and explain our decision.

If your appeal is denied, or you are not satisfied, you can file a complaint with your state attorney general:

You can also contact the U.S. Federal Trade Commission. The "Make a privacy complaint" option in Settings opens an email to us and points you to these authorities.

16. Deleting your consumer health data

How. In Settings, "Delete account." Deletion starts immediately and runs automatically, with retries until it finishes. You can also email privacy@arxova.health; we complete deletion requests sent by email within 30 days.

What is deleted automatically:

  • your account data in Arxova’s active databases, including imported records, shares, ARIA history and settings, subject to the specific retained records listed below;
  • the encryption keys we hold in active systems for your Arweave copies; backup copies of those keys expire within 5 days;
  • your Privy sign-in account;
  • your billing records at RevenueCat and Stripe, if any exist; and
  • Arxova's access to your Strava, Garmin (through ROOK), Oura, WHOOP, Polar, and Withings accounts.

What our team deletes by hand: your analytics profile at PostHog, and any records at Persona or Twilio.

What we cannot reach: Fasten Health and Sensor Bio do not offer a way for us to delete data or end the connection. Where available, revoke Arxova in the connected health system’s patient portal or your Sensor Bio account. If you cannot find that option, contact the provider or privacy@arxova.health for help. We do not send account-deletion notices to Anthropic, Fasten Health or Sensor Bio. Information previously sent to Anthropic is subject to its retention terms under our agreement, including our Business Associate Agreement. These describe current technical limits; they do not waive your deletion rights or excuse notices and cooperation required by applicable law. Email us if a provider-held copy needs attention.

What is kept:

  • records a clinic created in its care workspace stay with the clinic, no longer linked to your account;
  • consent records and security logs are kept without your identity;
  • database backups containing your data expire within 5 days;
  • encrypted copies on Arweave remain permanently; access depends on whether any usable key or plaintext copy remains;
  • public labels on Arweave objects and Solana receipts written before October 1, 2026 remain; and
  • We retain a one-way hashed reference derived from your account’s wallet address, together with the time and reason your sign-in sessions were ended, to keep sign-in tokens issued before deletion invalid. The original wallet address is not retained in this session-revocation record. This restricted security reference is not used for research, advertising, or analytics.

17. How long we keep it

InformationHow long
Your health data and accountUntil you delete your account
Database backups (daily snapshots)5 days
Push notification delivery receipts30 days
Arxova Circle repliesUp to 180 days; older replies are removed when a new reply arrives for your account
Research data after you withdrawRemoved from research datasets within 30 days
Security logsKept without an end date, for security purposes
A one-way hashed wallet reference and the time and reason your sign-in sessions were endedKept after you delete your account, so that any sign-in token issued before deletion stays invalid; nothing else is kept with it
Encrypted copies on ArweavePermanent; our active-system keys are removed on deletion and backup key copies expire within 5 days
Solana receiptsPermanent

Inactive accounts. We do not delete accounts for inactivity. An account and its data stay until you delete it.

18. Encryption, Arweave, and Solana

Encryption and who holds the keys

All Arxova databases are encrypted at rest at the storage layer. In addition, source documents, ARIA conversations, and raw device data are each encrypted individually with AES-256-GCM, using envelope encryption. Daily wearable totals, medication lists, symptoms, cycle data, and daily summaries are protected by storage-layer encryption only, so that features can read them. Information is encrypted in transit.

You decide who can see your records. Sharing, clinic access, and research all require your action, and you can revoke them. Arxova holds the encryption keys for most records so features like ARIA and scores can work; records encrypted with your wallet’s key require that key or an authorized decryption path. The keys Arxova holds are kept in secrets separate from the databases.

Arweave storage

Some records are also stored on Arweave, a permanent storage network, through the Irys service. Records are encrypted before upload. Copies on Arweave are permanent and cannot be deleted by anyone, including Arxova. When you delete your account, we remove the encryption keys we hold from active systems. Copies in our database backups expire within 5 days. After those retained key copies expire, encrypted files cannot be opened using Arxova’s retained keys. This does not erase plaintext or keys someone previously obtained, or the public labels described below.

Objects written before October 1, 2026 carry public, permanent labels showing a wallet address and the type of record, such as a lab observation, a medication, or a genomics file. Objects written since then do not.

We do not ask for a separate consent before storing encrypted copies on Arweave. It is part of how Arxova stores records.

Solana audit receipts

Arxova writes tamper-evident audit receipts to the Solana blockchain, so there is a record that cannot be quietly changed. A receipt is written when:

  • your account is created;
  • your medical records are accessed (at most once a day) or you download a copy of your data;
  • you share records, someone opens a share link, or you revoke a share;
  • data syncs from a device, or records are deleted;
  • you log medications or supplements (one receipt a day, without saying which);
  • a health alert is generated;
  • a clinic or study sends you a reminder, or Arxova asks you to review medications; and
  • you grant or revoke access: clinic access, research matching, a study's pre-screening authorization, and community insights.

A receipt is also written when you give or withdraw your AI consent, and when you add or remove an Arxova Circle contact.

Some choices are not recorded on-chain, including connecting or disconnecting a device or app, and your analytics setting.

Health records and health values are not written to Solana. Since October 1, 2026, receipts use a random reference instead of your wallet and a generic event name. A private reference held by Arxova connects a receipt to its account while that reference exists. Receipts written before then were linked to your wallet address and named the type of event (for example, a health alert or a device sync). Those older receipts are public and cannot be removed.

Arxova has no cryptocurrency token.

19. Security and HIPAA

We protect consumer health data with encryption at rest and in transit, access controls, separation of encryption keys from data, logging and monitoring, and vendor agreements. Arxova has a SOC 2 Type 1 report covering the Security criteria, as of August 31, 2026, issued by Percilchofe CPA LLC on September 23, 2026. An independent penetration test is underway. No system is perfectly secure. If a breach affects your information, we will notify you and the authorities as required by the FTC Health Breach Notification Rule, by HIPAA where Arxova acts for a clinic, and by state law.

Arxova is not a HIPAA covered entity. Consumer health data is protected by these state laws whether or not HIPAA applies. When a clinic uses Arxova's clinic console, Arxova acts as the clinic's business associate, and the clinic's own Notice of Privacy Practices applies to the records the clinic creates. We sign a Business Associate Agreement with each clinic before it uses Arxova. For services involving clinic protected health information, we require the appropriate Business Associate Agreements and service configurations before processing that information.

20. Children

Arxova is for adults 18 and older. We do not knowingly collect consumer health data from anyone under 18. If you tell us on the consent screen that you are under 18, we stop collecting health data for that account. If you believe a child is using Arxova, contact privacy@arxova.health and we will delete the account.

21. Changes to this policy

We will post any change here with a new effective date. When a change is material, the updated app tells you and asks you to accept the updated terms before you continue. Declining signs you out. Older app versions do not enforce this screen, and our servers currently do not block access solely because updated terms have not been accepted. While that screen is shown, you can accept, sign out, or open the Delete Account page to request deletion by email. For other requests, such as a copy of your data, email privacy@arxova.health.

22. Contact

HealthKey Labs, LLC's Founder and Chief Executive Officer is responsible for this policy and for Arxova's privacy program. You can reach the Founder and Chief Executive Officer at privacy@arxova.health.

Everyone at Arxova with access to personal data completes privacy and security training, and we review our privacy and security practices at least once a year.

HealthKey Labs, LLC d/b/a Arxova
382 NE 191st St PMB #924568
Miami, FL 33179
United States

Privacy email: privacy@arxova.health
Website: https://arxova.health
Privacy Policy: https://arxova.health/privacy-policy
Consumer Health Data Policy: https://arxova.health/consumer-health-data-policy

© 2026 HealthKey Labs, LLC d/b/a Arxova. All rights reserved.