Privacy Policy
Pre-launch draft · last updated August 8, 2026 · Your Data Health, Inc. / Xanadu · privacy@yourdata.health
Contents
- The Short Version
- Who We Are and What This Covers
- This Website and the Waitlist
- The Xanadu App: What It Handles
- Where Your Health Data Lives
- How Records Are Retrieved
- What We Never Do
- Sharing You Direct
- How We Protect Your Data
- HIPAA and Where It Applies
- If Something Goes Wrong
- Washington Consumer Health Data
- Other Privacy Laws
- Your Rights and How to Use Them
- Government and Legal Requests
- Children
- Retention and Deletion
- Changes to This Policy
- Contact
1. The Short Version
Your health data belongs to you. It is stored encrypted, under keys you control, and we cannot read it. We do not sell your data. We do not run ads, analytics, or trackers. Nothing is shared with anyone unless you explicitly direct it, and anything you share you can revoke. You can see, correct, export, or delete everything we hold about you at any time, for free, by emailing privacy@yourdata.health. The rest of this document is the detail behind those sentences.
2. Who We Are and What This Covers
Xanadu Health is a product of Your Data Health, Inc., a Delaware corporation operating in Washington State ("we," "us"). This policy covers two things:
- This website (xanadu.yourdata.health), including the waitlist, in effect now.
- The Xanadu app, our patient-facing personal health record application, effective when the app launches.
This policy is incorporated by reference into our Terms of Service. Where this policy and the Terms overlap, the more protective statement for you controls.
3. This Website and the Waitlist
When you join the waitlist, we collect the email address you give us, and any optional details you choose to add: your name, what kind of person or organization you are, what you are hoping Xanadu does for you, and how you heard about us.
That is all. This website does not collect any health data. We use waitlist information for two things: to contact you about Xanadu's launch and the founding cohort, and to understand who is interested so we build the right product. Nothing else. This site sets no cookies and runs no advertising networks, no tracking pixels, and no analytics. Beyond what you explicitly submit to the waitlist, we collect no data about you or your visit.
4. The Xanadu App: What It Handles
When the app launches, it will handle the following categories of information:
- Account information: the profile details you provide when you create an account (such as name and contact email).
- Health records you retrieve: the clinical records you direct the app to fetch from your healthcare providers, such as medications, lab results, vital signs, conditions, immunizations, allergies, procedures, care plans, goals, and clinical documents.
- Health data you add: observations, documents, or device data you choose to import or record yourself.
- App operations data: the minimum technical information needed to run the service securely, such as authentication events and error diagnostics. Diagnostics never include the contents of your health records.
5. Where Your Health Data Lives
Your health records are stored in an encrypted vault. The encryption keys are controlled by you, not by us. In plain terms: we operate the safe-deposit boxes, and you hold the key. Our systems and our staff cannot read the health records in your vault.
You choose where your encrypted vault is stored, on your device or in storage you designate. Whatever you choose, the same rule holds: contents are encrypted before they leave your device, and we cannot read them.
6. How Records Are Retrieved
The app retrieves your records using patient-directed access under the SMART on FHIR standard, the same mechanism required of health systems by federal information-blocking and patient-access rules. You log in to your own provider or portal account, you approve the connection, and the records flow directly into your vault. We request read-only access. The app does not write to, modify, or delete anything in your providers' systems.
7. What We Never Do
- We never sell your data. Not personal information, not health records, not "anonymized" derivatives sold as data products.
- We never share your data with advertisers, data brokers, or analytics companies.
- We never set cookies and never run advertising networks, tracking pixels, or third-party analytics in the app or on this site.
- We never use your identifiable health data to train artificial intelligence models.
- We never condition access to your own data on payment, participation in research, or waiving your rights.
8. Sharing You Direct
Sharing only happens when you initiate it, and every grant is visible and revocable in the app:
- People and apps you choose: if you direct the app to share records with a caregiver, clinician, or another application, we transmit exactly what you selected, to the recipient you selected, and nothing more.
- Research participation: participation in research is off by default. If you opt in to a specific research lease, the named organization receives de-identified data for the stated purpose, under terms shown to you before you accept, as described in our Terms of Service. You can revoke any lease at any time.
- Service providers: a small number of vendors help us operate the service (for example, hosting infrastructure). They handle only encrypted content or the minimum operational data needed, are bound by contract to use it solely to provide the service to us, and are prohibited from selling it or using it for their own purposes.
9. How We Protect Your Data
- Encryption in transit and at rest, everywhere, with vault contents encrypted end to end under keys you control.
- Privacy by design: data minimization, purpose limitation, and privacy risk assessment before any new data practice, following the principles of the IAPP privacy engineering discipline.
- Access controls and audit logging on every administrative system we operate.
- Our security and compliance program is designed and operated in line with the SOC 2 Trust Services Criteria and the HITRUST CSF control framework. We are not yet certified against these frameworks; independent audits are on our roadmap, and we will update this page as they complete rather than claim them early.
10. HIPAA and Where It Applies
Honest scoping, because this is widely misunderstood:
- Your healthcare providers are covered by HIPAA. Records held in their systems are protected by HIPAA there.
- When you direct a copy of your records into your own vault, that copy is under your control and is generally no longer governed by HIPAA. It is protected instead by this policy, by our contracts with you, and by the consumer health privacy laws described below, several of which are in important ways stronger.
- The Xanadu consumer app is a personal health record service, not a HIPAA covered entity. Where Your Data Health, Inc. separately provides services to HIPAA-covered organizations, we sign business associate agreements and comply with HIPAA in those engagements.
11. If Something Goes Wrong
As a personal health record vendor, we are subject to the FTC Health Breach Notification Rule. If a breach of identifiable health data ever occurs, we will notify you, the Federal Trade Commission, and where required the media, within the timelines the rule sets. Because vault contents are encrypted under keys we do not hold, a breach of our infrastructure does not by itself expose your health records; we commit to notifying you honestly about what was and was not affected.
12. Washington Consumer Health Data (My Health My Data Act)
This section serves as our consumer health data privacy policy under Washington's My Health My Data Act (MHMDA) and applies to Washington consumers, alongside similar laws in other states.
Categories of consumer health data
The app handles the health record categories listed in Section 4, solely as directed by you. The website and waitlist collect no consumer health data.
Sources
Your healthcare providers (at your direction), and you.
Purposes
To provide the service you asked for: retrieving, organizing, securing, and displaying your own health records, and carrying out sharing you explicitly direct. We do not collect, use, or share consumer health data for any other purpose.
Sharing and sale
We do not sell consumer health data, and we do not share it except as you direct (Section 8). No third parties or affiliates receive consumer health data from us for their own purposes.
Your MHMDA rights
You have the right to confirm whether we collect, share, or sell consumer health data about you; to access it, including a list of third parties and affiliates with whom we have shared it; to withdraw consent; and to have it deleted. Exercise any of these by emailing privacy@yourdata.health. We will respond within the statutory timelines. If we decline a request, you may appeal by replying to our decision with the word "appeal," and we will have the appeal reviewed by someone other than the original decision-maker. If your appeal is unsuccessful, you may contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.
13. Other Privacy Laws
Depending on where you live, you may have rights under laws such as the California Consumer Privacy Act, other state privacy laws, or the EU/UK General Data Protection Regulation. We honor the strongest applicable version of these rights for everyone rather than gating them by geography: access, correction, deletion, portability, and freedom from discrimination for exercising them, as described in Section 14. For GDPR purposes, Your Data Health, Inc. is the controller for account and waitlist data, and processes health records solely on your instructions; where GDPR applies, our lawful bases are performance of our contract with you and your explicit consent for health data.
14. Your Rights and How to Use Them
Every right below is free, available at any time, and never results in worse treatment:
- Access: ask what we hold about you and get a copy.
- Export: take your data with you in portable, standard formats, including FHIR for clinical records.
- Correction: fix anything that is wrong in the data we hold about you.
- Deletion: delete your account and data, from within the app or by email. We complete deletion within 30 days.
- Withdraw consent: revoke any sharing grant or research lease at any time, effective from that date.
- Authorized agents: you may designate someone to exercise these rights for you; we will verify the designation to protect you.
Send any request to privacy@yourdata.health. We will verify your identity (to protect you, using the minimum information necessary), respond within 30 days or the shorter period a law requires, and explain ourselves plainly if any part of a request cannot be fulfilled. See also Your Rights for the member-facing summary of the guarantees built into the product itself.
15. Government and Legal Requests
Our position follows the Electronic Frontier Foundation's guidance on protecting user data:
- We disclose data only when legally compelled by valid process, and only the minimum the process actually requires.
- We challenge requests that are overbroad, improper, or lack valid legal basis.
- We notify you of any request for your data before complying, unless a court order legally prohibits notice, in which case we notify you as soon as the prohibition lifts.
- Because vault contents are encrypted under keys you control, in most cases we are technically incapable of producing readable health records, and we will say exactly that to any requester.
16. Children
The service is for adults 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact privacy@yourdata.health and we will delete it.
17. Retention and Deletion
Waitlist data is kept until launch outreach completes or you ask us to delete it, whichever comes first. Account data is kept while your account is active. When you delete your account, we delete your data within 30 days, and any active sharing grants and research leases terminate immediately. Encrypted vault contents you stored in your own designated storage are yours and remain wherever you put them.
18. Changes to This Policy
We will give at least 30 days' notice before material changes take effect, by email and by a notice in the app and on this page. We will never use a policy change to retroactively claim rights over data collected under an earlier promise.
19. Contact
Privacy questions and rights requests: privacy@yourdata.health
Legal: legal@yourdata.health
Your Data Health, Inc., a Delaware corporation operating in Washington State.
Pre-launch draft · last updated August 8, 2026 · Your Data Health, Inc. · Terms of Service · Your Data Rights