Consumer Health Data Privacy Policy
Last updated: July 14, 2026
Policy version: 2026-07-14
This policy is separate from, and more specific than, our general Privacy Policy. It exists because Check My Burnout collects information that Washington law and other regulations treat as consumer health data, and you're entitled to a clear, standalone explanation of what that means.
1. What consumer health data we collect
We collect the following categories of data in order to compute your personal burnout-risk score:
- Check-in responses: self-reported sleep hours and stress level, entered by you.
- Calendar density: meeting/event start and end times from Google Calendar, if you connect it. We read scheduling density only — we never store event titles, descriptions, attendee lists, or locations.
- Screen-time check-ins: self-reported or extension-submitted screen-time totals.
- Computed burnout scores: a 0–100 score and its four component sub-scores, derived from the above.
- Reset-suggestion interaction history: which personalized suggestions you've been shown and dismissed, used only to avoid repeating the same suggestion.
We do not collect: precise location, biometric identifiers, genetic data, or any data from a third party data broker.
2. Why we collect it
Solely to compute your burnout-risk score and power the personalized reset suggestions you see in the app. We do not use this data for advertising, profiling for marketing purposes, or any purpose you have not consented to.
3. Consent
We collect your health data only after you affirmatively opt in at signup. This consent is separate and independent from:
- your consent (or non-consent) to have your data shared or sold, which defaults to off and must be separately and affirmatively turned on in Settings, and
- your decision to subscribe or pay — you can use the app under a free trial and manage your consent choices regardless of billing status.
Every grant, and every later change, is recorded with a timestamp and the policy version in effect at the time, so we can show you (or a regulator, if ever required) exactly what you agreed to and when. You can review and change your data-sharing consent at any time in Settings → Account.
4. We do not sell your data
We do not sell consumer health data. If this ever changes, we will seek your separate, affirmative authorization before any sale — not bundled with any other consent or with your continued use of the app.
5. Who we share it with
We share data only with the service providers necessary to operate the app, and only the minimum data each one needs:
- Supabase — database hosting and authentication. Stores your check-in data, computed scores, and consent records.
- Cloudflare — application hosting.
- Polar — payment processing. Receives your email and payment details; never receives health data (sleep, stress, calendar, or score data).
- Google— if you connect Google Calendar, we exchange an authorization code with Google's OAuth service to read your calendar's event timing only.
We do not send health-derived fields (sleep hours, stress levels, burnout scores, calendar density) to any analytics or advertising service. If we use analytics in the future, only anonymized, aggregate, non-health events will be sent.
6. Geofencing
We do not use your location to determine your proximity to any health care facility, and we do not geofence around such facilities.
7. Your rights
You have the right to:
- Access a copy of the data we hold on you, available for download as JSON from Settings → Account → Export.
- Withdraw consent to data sharing at any time (see Section 3) — this does not require deleting your account.
- Delete your account and data. Requesting deletion in Settings starts a 30-day grace period, during which you can cancel the request and keep your account. After 30 days, we permanently delete your check-in data, calendar connections (including revoking our access with Google), screen-time data, burnout scores, and account credentials.
- One exception: our record that you granted (and later withdrew, by deleting your account) consent is retained in an anonymized form, so we can continue to demonstrate MHMDA compliance without retaining any way to link that record back to you. This anonymization uses a one-way cryptographic transformation — we cannot reverse it to identify you.
- Submit a request related to any of the above by support@checkmyburnout.com.
We will respond to rights requests within 45 days, as required by Washington law.
8. Security
Data is encrypted in transit (TLS) for all connections. Your Google Calendar refresh token is encrypted at rest using a dedicated encryption key that never leaves our server environment. Database access is restricted by row-level security policies so that, outside of automated account-deletion processing, only you can read your own records.
9. Data retention
We retain your health data for as long as your account is active. If you request deletion, data is retained only through the 30-day grace period described in Section 7, after which it is permanently and irreversibly deleted, with the narrow exception of the anonymized consent record described above.
10. Breach notification
If a breach affecting your consumer health data occurs, we will notify affected users and, where legally required, the FTC and/or Washington State regulators, within the legally required timeframe.
11. Changes to this policy
If we materially change what data we collect, why, or who we share it with, we will update the "policy version" recorded with your consent and notify you before the change takes effect, giving you the opportunity to review your consent choices again.
12. Contact
support@checkmyburnout.com
This policy is linked from our homepage and from Settings, and is distinct from our general Terms of Service and Privacy Policy, which cover non-health data practices (e.g., account credentials, payment records), and our disclaimer, which explains that this app is not a medical device.