This Consumer Health Data Privacy Policy is a standalone notice required by certain U.S. state laws that regulate "consumer health data," including Washington's My Health My Data Act ("MHMDA"), Nevada's Consumer Health Data Privacy Law, and Connecticut's Data Privacy Act as amended (collectively, "Consumer Health Data Laws"). It applies regardless of where you are located if you are a resident of, or your consumer health data is collected in, a state covered by these laws. This document contains only the disclosures these laws require; our general ResetDay Privacy Policy covers our broader data practices and applies alongside this one.
This Consumer Health Data Privacy Policy supplements our general Privacy Policy. In the event of a conflict between our Privacy Policy and this Consumer Health Data Privacy Policy, this Consumer Health Data Privacy Policy controls to the extent required by applicable state law.
This Consumer Health Data Privacy Policy describes how we process Consumer Health Data that we collect through our digital properties (including our mobile application) and related marketing activities (collectively, the "Service").
Because ResetDay helps you understand and change your relationship with alcohol, some of what you tell us - your drinking patterns, goals, triggers, and reflections - is "Consumer Health Data" under these laws, even though ResetDay is not a healthcare provider and this is not a medical record.
Consumer Health Data We Collect, and Why
| Category | Examples | Why We Collect It |
|---|---|---|
| Alcohol-related data | Self-reported drinking frequency and amount, triggers, cravings, drinking goals, check-in responses, reflections you share | To build and continuously personalize your plan |
| Inferred health data | Patterns, progress trends, or plan adjustments we derive from the data above | To personalize your plan and improve the Service |
| Contact data | Email address | To create your account and communicate with you |
| Account/profile data | Login credentials, any biographical information you add | To operate your account |
| Device and usage data | Device model, OS version, IP address, in-app screens/features used, session activity | To operate, secure, and improve the Service |
We do not collect any Consumer Health Data beyond what is listed above, and we do not infer or derive additional categories of health information (such as a specific diagnosis) from what you share.
Sources of Consumer Health Data
We collect Consumer Health Data:
- directly from you through onboarding questions, check-ins, and anything you type into the app;
- automatically through your device and your use of the app; and
- from our service providers and the Apple App Store limited to account authentication and subscription status.
We do not purchase Consumer Health Data about you from data brokers or other third parties.
Consumer Health Data We Share, and With Whom
We do not share Consumer Health Data except as described below:
- Service providers, acting under contract on our behalf, for hosting, analytics necessary to operate the Service, or customer support but never for their own independent purposes.
- Apple, limited to what is necessary to authenticate your account and process your subscription.
- Law enforcement or other parties, only where required by valid legal process, or where necessary to protect someone's life or physical safety.
Affiliates: we do not currently share Consumer Health Data with any parent, subsidiary, or corporate affiliate. If this changes, we will update this Policy to name the specific affiliate(s) before any such sharing occurs, and we will obtain your consent where required.
We do not share Consumer Health Data for the purpose of advertising to you, and we do not use it for cross-context behavioral advertising.
How We Obtain Your Consent
We only collect Consumer Health Data beyond what is strictly necessary to provide a feature you've requested with your prior, affirmative, opt-in consent. Consent to collect Consumer Health Data is separate and distinct from any consent you give us to share it, we ask for these separately, and neither is bundled into a general terms-of-use acceptance or obtained through pre-checked boxes, hovering, or similar dark-pattern designs.
You may withdraw your consent at any time (see Your Rights Section below). Withdrawing consent will not affect any collection or sharing that already occurred, but it will stop future collection or sharing and trigger deletion as described below.
We Do Not Sell Consumer Health Data
We do not sell your Consumer Health Data, and we have no plans to. If this were ever to change, we would first obtain your valid, signed authorization specific to that sale and separate from any other consent, and would retain a record of that authorization for at least six years, as required by law.
No Geofencing Around Health Care Facilities
We do not, and will not, implement geofences around in-person healthcare facilities (including mental health, reproductive health, or substance-use treatment facilities) to identify, track, or send messages to consumers, or to infer or collect their consumer health data.
Your Rights
Subject to certain exceptions under applicable law, you have the right to:
- Confirm whether we are collecting, sharing, or selling your Consumer Health Data.
- Access your Consumer Health Data, including a list of all third parties and affiliates (if any) with whom we have shared or sold it, along with an active email address for each.
- Withdraw consent for our future collection or sharing of your Consumer Health Data.
- Delete your Consumer Health Data including from archived or backup systems, and including instructing our service providers, processors, and contractors to do the same.
- Appeal if we deny your request (see next Section).
You will not be charged different prices or receive a different level of service for exercising any of these rights.
To exercise any right above, email us at support@resetday.io. We will not require you to create an account to submit a request, though we may need to verify your identity using information already associated with your account.
How We Respond to Requests
We will respond to your request within 45 days of receipt (with one 45-day extension where reasonably necessary, and notice to you if we need it). We provide these rights free of charge up to twice per calendar year. Backup-system deletions may take up to six months to complete due to the nature of backup architecture.
If we deny your request in whole or in part, we will explain why in writing and provide you instructions for appealing that decision by emailing support@resetday.io with the subject line "Consumer Health Data Appeal." We will respond to your appeal within 45 days (with one permitted 45-day extension).
How We Restrict Access to and Secure Consumer Health Data
We restrict internal access to Consumer Health Data to the employees, processors, and contractors who need it to provide the Service or fulfill the purposes for which you provided consent. We maintain administrative, technical, and physical safeguards appropriate to the volume and nature of the Consumer Health Data we process, consistent with a reasonable standard of care. Any processor that handles Consumer Health Data on our behalf does so under a binding contract that limits its processing to purposes consistent with this Policy.
Consistent with the Federal Trade Commission's guidance for developers of health and wellness apps, we also:
- minimize data: we collect only what the App needs to build and personalize your plan, and nothing more (see our general Privacy Policy's "Information We Do Not Collect" section);
- limit access and permissions: both for our own staff and for the device permissions the app requests;
- build in authentication: securing your account through email verification or your Apple ID, rather than relying on weak or optional authentication;
- vet our mobile ecosystem: reviewing the analytics and infrastructure vendors and SDKs we integrate for their own data-handling and security practices; and
- design for security from the start rather than treating it as an afterthought.
Breach Notification
If we experience a breach of security involving unsecured Consumer Health Data, we will notify affected individuals, and where applicable the Federal Trade Commission and other regulators, in accordance with the FTC's Health Breach Notification Rule (16 C.F.R. Part 318) and any applicable state breach notification law.
Additional State-Specific Notes
- If you are a Nevada resident, the rights and protections above apply to you under Nevada's Consumer Health Data Privacy Law, which is narrower in scope than the MHMDA and does not carry a private right of action.
- If you are a Connecticut resident, your consumer health data is treated as "sensitive data" under the Connecticut Data Privacy Act, entitling you to the rights described above as well as those in our general Privacy Policy.
- If your state adopts a similar consumer health data law, we intend to extend the same protections and rights described in this Policy to you, regardless of your specific state of residence.
Changes to This Policy
We will not make material changes to the categories of Consumer Health Data we collect, use, or share, or the purposes for which we do so, without updating this Policy and, where required, obtaining your renewed consent before the change takes effect. We will post the updated effective date at the top of this Policy.
Contact Us
Email: support@resetday.io
Devellux Inc
8 The Green, STE A
Dover, DE 19901, USA