Common questions
Frequently asked questions
Answers about how the trust works, how your data is protected, and how payouts are calculated.
A Patient-Owned Data Trust is a legal and technical structure where you retain ownership and control of your health data. Unlike a traditional health platform where you give up rights to your data by accepting terms of service, the trust structure means:
- You retain legal ownership of your data.
- You decide which research categories your data can be used for.
- You keep 80% of what a study pays when you opt in and your de-identified data is licensed.
- You can revoke consent and delete your data with a single technical action (not a support ticket).
Think of it as a co-op: members pool de-identified data to make it more valuable for research, but each member owns their individual contribution and shares in the revenue it generates.
You earn only from studies you choose to join. The 80/20 Payout™ is how that revenue is split:
- In The Vault, you opt in to the research categories you're willing to support -- nothing is shared until you do.
- When a study's criteria match your profile and you're accepted, your de-identified data is licensed to that study.
- You keep 80% of what the study pays for your participation. Xanadu keeps 20% to run the platform, security, and compliance.
- You're paid only for studies you opted into and were accepted for. Your data is never sold automatically.
Your Xanadu Score doesn't set your payout on its own. It reflects how complete and research-ready your data is, which makes you eligible for -- and more attractive to -- more studies over time. A stronger record means more potential matches, and more chances to be accepted and paid.
Example: you opt into sleep research. A university running a sleep study reviews de-identified profiles, accepts yours, and licenses it -- you receive 80% of what they pay for your participation.
The Xanadu Score™ reflects how complete and research-ready your data is. In general, your score goes up when you:
- Connect more verified data sources (wearables, provider records, labs, pharmacy data)
- Contribute consistent, gap-free records over time
- Keep your data accurate and up to date
- Maintain active consent
A higher score makes you eligible for -- and more attractive to -- more studies, because your record matches more research criteria. That means more chances to be accepted and paid over time. The score reflects how research-ready your data is; it does not, by itself, decide what any single study pays.
Importantly: the score is about data quality and completeness, not how healthy you are. A person managing a chronic condition with several connected sources will score higher than a healthy person with one.
Yes. Security is built into the architecture, not bolted on:
- Strong encryption: Your data is encrypted both when stored and when transmitted, using industry-standard methods.
- You hold the keys: Access is tied to you, not stored where someone else can reach it.
- No standing access: No system has open-ended access to your data; access is granted only when you allow it.
- One-tap kill-switch: When you revoke consent, access to your data is cut off and it can no longer be used.
- Audit log you can see: Every access event is recorded in a log you can review.
When data is shared with a study, it is de-identified before any external access. Researchers see only a general profile such as "Female, 35-44, Pacific NW, highly complete record." They never see your name, address, or any identifier.
Xanadu's controls are built to SOC 2 Type II and HITRUST readiness, the frameworks enterprise health and research partners audit against. Formal certification follows as we scale; the architecture is built for it from day one.
The Vault™ is your consent-controlled data store -- the interface through which you manage what happens to your data.
To delete your data:
- Open The Vault and select "Delete my data."
- Access is cut off immediately and your data can no longer be used.
- Backups and logs are purged on a 30-day schedule, consistent with WA MHMDA requirements.
This is a technical control, not an administrative one. There is no team that needs to process your request, and it takes effect right away.
Qualified licensees must agree to purpose-limitation contracts -- your data can only be used for the stated research purpose. They include:
- Universities and academic researchers
- Clinical trial sponsors
- Public health agencies
- Health insurance research divisions
You control this from The Vault: opt in to some research categories and out of others -- for example, consent to sleep research but opt out of insurance actuarial studies. Your granular consent preferences are honored before any study is assembled.
Xanadu connects the health data you already have:
- Provider records (via standard formats: FHIR APIs, C-CDA documents, and PDFs you upload)
- Your phone's health data
- Wearables and home devices
- Lab results
- Pharmacy data
- Payer & claims data (insurance claims, explanation-of-benefits, and coverage history, via patient-access APIs)
Coverage expands through the founding cohort.
Yes. Xanadu connects your data through the same open, federally defined interoperability standards that govern how health data moves in the U.S. That means records, including your insurance and claims data, flow in through standardized, patient-authorized channels instead of manual entry.
Where it applies to a patient-directed application, Xanadu is built to comply with:
- ONC 21st Century Cures Act Final Rule: your federal right to access your electronic health information through a certified, standardized FHIR API (ONC's (g)(10) Standardized API for Patient and Population Services), with information blocking prohibited under 45 CFR Part 171.
- ONC HTI-1 Final Rule (2024): the update to certified health IT, USCDI adoption, and information-sharing requirements.
- CMS Interoperability & Patient Access (CMS-9115-F): requires payers to make your claims, encounter, and coverage data available to the apps you choose. Xanadu connects through these patient-access APIs.
- CMS Interoperability & Prior Authorization (CMS-0057-F): expands payer data access, including prior-authorization information.
- USCDI data classes: the standardized set of health data elements, so what comes in is structured and consistent.
- CARIN Blue Button® and Da Vinci implementation guides: the industry FHIR profiles for consumer-directed payer data and provider-payer exchange.
- HIPAA individual right of access: where covered entities are involved.
The result: your provider, pharmacy, lab, and payer data can come together in one place you control, using national standards rather than closed, proprietary connections.
Every connection is validated with Your Data Health's own tooling before any real data is involved: the Technical Audit Protocol (TAP) and QA-in-a-Box synthetic datasets, alongside our data-privacy products. Each build is then graded on the same Sovereignty Scorecard™ we use to score other platforms, across three axes: individual consent, technical security, and interoperability.
Xanadu is designed to comply with and exceed the requirements of:
- WA MHMDA (My Health My Data Act): Washington State's comprehensive consumer health data privacy law, effective 2024.
- CA CCPA/CPRA (2026): California's consumer privacy rights framework.
- HIPAA: where applicable, when interfacing with covered entities.
Every design decision is held to the same Sovereignty Scorecard™ criteria we use to evaluate other platforms -- we score ourselves the way we score everyone else.
The founding cohort is the first group of Xanadu members. Joining the waitlist reserves your place in the founding cohort and locks in:
- Early access to The Vault before general availability
- Input into the trust's governance rules for research categories and payout structure
Joining the waitlist does not commit you to sharing any health data. That happens only after you join The Vault, with separate, explicit consent for each data type.
No. Specifically:
- No analytics, ad networks, or tracking scripts on any Xanadu property.
- We never profile you for advertising.
- We don't cooperate with data requests beyond what the law requires.
- We do not use your health data to train AI models without your explicit, separate, and compensated consent.
We practice what we audit others for violating.
Still have questions?
Reach out directly at terry@yourdata.health or join the waitlist to be notified when we open to the founding cohort.
Join the waitlist