Skip to main content

Privacy Policy

Pre-launch draft · last updated August 8, 2026 · Your Data Health, Inc. / Xanadu · privacy@yourdata.health

Pre-launch draft. The Xanadu app is not yet open to the public. This policy is published for transparency. The sections covering the app take effect when the app launches; the sections covering this website and the waitlist are in effect now. This document is undergoing legal review and may change before launch. Last updated August 8, 2026.

1. The Short Version

Your health data belongs to you. It is stored encrypted, under keys you control, and we cannot read it. We do not sell your data. We do not run ads, analytics, or trackers. Nothing is shared with anyone unless you explicitly direct it, and anything you share you can revoke. You can see, correct, export, or delete everything we hold about you at any time, for free, by emailing privacy@yourdata.health. The rest of this document is the detail behind those sentences.

2. Who We Are and What This Covers

Xanadu Health is a product of Your Data Health, Inc., a Delaware corporation operating in Washington State ("we," "us"). This policy covers two things:

This policy is incorporated by reference into our Terms of Service. Where this policy and the Terms overlap, the more protective statement for you controls.

3. This Website and the Waitlist

When you join the waitlist, we collect the email address you give us, and any optional details you choose to add: your name, what kind of person or organization you are, what you are hoping Xanadu does for you, and how you heard about us.

That is all. This website does not collect any health data. We use waitlist information for two things: to contact you about Xanadu's launch and the founding cohort, and to understand who is interested so we build the right product. Nothing else. This site sets no cookies and runs no advertising networks, no tracking pixels, and no analytics. Beyond what you explicitly submit to the waitlist, we collect no data about you or your visit.

4. The Xanadu App: What It Handles

When the app launches, it will handle the following categories of information:

5. Where Your Health Data Lives

Your health records are stored in an encrypted vault. The encryption keys are controlled by you, not by us. In plain terms: we operate the safe-deposit boxes, and you hold the key. Our systems and our staff cannot read the health records in your vault.

You choose where your encrypted vault is stored, on your device or in storage you designate. Whatever you choose, the same rule holds: contents are encrypted before they leave your device, and we cannot read them.

6. How Records Are Retrieved

The app retrieves your records using patient-directed access under the SMART on FHIR standard, the same mechanism required of health systems by federal information-blocking and patient-access rules. You log in to your own provider or portal account, you approve the connection, and the records flow directly into your vault. We request read-only access. The app does not write to, modify, or delete anything in your providers' systems.

7. What We Never Do

8. Sharing You Direct

Sharing only happens when you initiate it, and every grant is visible and revocable in the app:

9. How We Protect Your Data

10. HIPAA and Where It Applies

Honest scoping, because this is widely misunderstood:

11. If Something Goes Wrong

As a personal health record vendor, we are subject to the FTC Health Breach Notification Rule. If a breach of identifiable health data ever occurs, we will notify you, the Federal Trade Commission, and where required the media, within the timelines the rule sets. Because vault contents are encrypted under keys we do not hold, a breach of our infrastructure does not by itself expose your health records; we commit to notifying you honestly about what was and was not affected.

12. Washington Consumer Health Data (My Health My Data Act)

This section serves as our consumer health data privacy policy under Washington's My Health My Data Act (MHMDA) and applies to Washington consumers, alongside similar laws in other states.

Categories of consumer health data

The app handles the health record categories listed in Section 4, solely as directed by you. The website and waitlist collect no consumer health data.

Sources

Your healthcare providers (at your direction), and you.

Purposes

To provide the service you asked for: retrieving, organizing, securing, and displaying your own health records, and carrying out sharing you explicitly direct. We do not collect, use, or share consumer health data for any other purpose.

Sharing and sale

We do not sell consumer health data, and we do not share it except as you direct (Section 8). No third parties or affiliates receive consumer health data from us for their own purposes.

Your MHMDA rights

You have the right to confirm whether we collect, share, or sell consumer health data about you; to access it, including a list of third parties and affiliates with whom we have shared it; to withdraw consent; and to have it deleted. Exercise any of these by emailing privacy@yourdata.health. We will respond within the statutory timelines. If we decline a request, you may appeal by replying to our decision with the word "appeal," and we will have the appeal reviewed by someone other than the original decision-maker. If your appeal is unsuccessful, you may contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.

13. Other Privacy Laws

Depending on where you live, you may have rights under laws such as the California Consumer Privacy Act, other state privacy laws, or the EU/UK General Data Protection Regulation. We honor the strongest applicable version of these rights for everyone rather than gating them by geography: access, correction, deletion, portability, and freedom from discrimination for exercising them, as described in Section 14. For GDPR purposes, Your Data Health, Inc. is the controller for account and waitlist data, and processes health records solely on your instructions; where GDPR applies, our lawful bases are performance of our contract with you and your explicit consent for health data.

14. Your Rights and How to Use Them

Every right below is free, available at any time, and never results in worse treatment:

Send any request to privacy@yourdata.health. We will verify your identity (to protect you, using the minimum information necessary), respond within 30 days or the shorter period a law requires, and explain ourselves plainly if any part of a request cannot be fulfilled. See also Your Rights for the member-facing summary of the guarantees built into the product itself.

15. Government and Legal Requests

Our position follows the Electronic Frontier Foundation's guidance on protecting user data:

16. Children

The service is for adults 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact privacy@yourdata.health and we will delete it.

17. Retention and Deletion

Waitlist data is kept until launch outreach completes or you ask us to delete it, whichever comes first. Account data is kept while your account is active. When you delete your account, we delete your data within 30 days, and any active sharing grants and research leases terminate immediately. Encrypted vault contents you stored in your own designated storage are yours and remain wherever you put them.

18. Changes to This Policy

We will give at least 30 days' notice before material changes take effect, by email and by a notice in the app and on this page. We will never use a policy change to retroactively claim rights over data collected under an earlier promise.

19. Contact

Privacy questions and rights requests: privacy@yourdata.health
Legal: legal@yourdata.health
Your Data Health, Inc., a Delaware corporation operating in Washington State.

Pre-launch draft · last updated August 8, 2026 · Your Data Health, Inc. · Terms of Service · Your Data Rights