Policies
Health data notice
健康信息
- Last updated
- 8 September 2026
- Version
- 2026-09-08
- Written for
- WA MHMDA · NV SB 370 · UK & EU GDPR
- Photograph kept
- 30 days after delivery
- Answers kept
- 24 months, or until you ask
Your thirty answers, anything you write in your own words, one photograph of your tongue and your email address are held for a limited time so that a physician can read them and write your report. They are stored encrypted, read by two people, never sold, and deleted when you ask. No advertising or analytics code runs on those pages.
What this notice covers, and why it is a separate document
Everything you send us in the intake is health information. Not only the answer about your sleep, but the whole of it: the pattern of the answers, the words you chose in the free-text boxes, and the photograph. Washington’s My Health My Data Act defines consumer health data broadly enough to include inferences drawn from any of that, and it is right to.
So this is its own notice, not a paragraph inside the privacy policy. Washington and Nevada both require a distinct consumer health data notice, linked from the homepage, and both require consent to collect that data to be asked for separately from acceptance of the terms of service. On the intake page there are three tick boxes, none of them ticked for you.
The privacy policy covers everything else — logs, cookies, payment, email. Where the two overlap, this document governs.
Exactly what we collect
- Your answers to the thirty fixed-choice intake questions.
- Anything you type in your own words in the free-text boxes.
- One photograph of your tongue.
- Your email address, so the report has somewhere to go.
- A Stripe payment reference. Never a card number — card details are entered on Stripe’s own page and never reach our servers.
- Timestamps: when you submitted, when we delivered, when we corresponded.
- A salted hash of the IP address you consented from. Never the address itself.
That is the complete list. No device fingerprint, no location, no advertising identifier, no contacts, no browsing history, and no question about anything you did not volunteer. We do not buy information about you from anyone, and we do not combine what you tell us with anything bought elsewhere.
Nothing you send is used to train a machine-learning model, ours or anyone else’s. Your answers and your photograph are never sent to a third-party model for any purpose.
What allows us to hold it
Consent, given before collection, separately, and revocable. Not consent inferred from your having continued to scroll.
- United Kingdom and European Economic Area. Article 9(2)(a) UK and EU GDPR — your explicit consent to processing data concerning health — together with Article 6(1)(b) for the ordinary parts of doing what you paid for.
- Washington. Consent under the My Health My Data Act, asked for before collection, in a request that is not bundled with anything else.
- Nevada. Affirmative, voluntary consent under SB 370, on the same terms.
- Everywhere else. The same standard. It is easier to hold one bar than to work out which one applies to you.
We record the version and a SHA-256 hash of the consent wording you were shown, so that later we can say what you agreed to rather than what the page says today. You can withdraw consent at any time, and withdrawing it does not make what we did before unlawful — it stops what happens next.
The photograph, and the metadata we throw away
A photograph carries more than a picture. The file your phone makes usually holds EXIF metadata: GPS coordinates accurate to a few metres, the camera’s serial number, the exact second, sometimes the name you gave the device.
On upload the file is decoded and re-encoded on our server before it reaches storage. Everything that is not pixels is discarded — EXIF, XMP, IPTC, embedded thumbnails, colour profiles beyond the one needed to render it correctly. The original bytes are never written to disk. What is kept is an image of a tongue, at most 1,600 pixels on the long edge, filed under a random identifier with no relationship to your name or your email address.
We ask for the tongue and the mouth around it, not your face. If your face is in the frame, crop it before you send it. If it arrives anyway, we crop it and keep only the crop.
Where it is stored
Records sit in a managed PostgreSQL database in the European Union, encrypted at rest with AES-256 and in transit with TLS 1.3. Photographs sit in a private object store in the same region. Neither is publicly addressable: the links our physicians open are signed and expire after fifteen minutes.
The companies we rely on to run that, and what each one sees:
| Provider | Role | Sees your health information |
|---|---|---|
| Supabase | Database and file storage, EU region | Encrypted at rest; no human access on their side |
| Vercel | Hosting and edge routing | No. Nothing is stored there |
| Stripe | Payment | No. Only an amount, a date and an email |
| Email delivery provider | Carries the report to your inbox | Yes — the report itself, in transit and in their log |
The last row is the honest weak point of any emailed report, and it is worth saying out loud: once a report is in an inbox, it lives under your email provider’s rules, not ours. If you would rather collect it from a link that expires instead, say so before you pay and we will send it that way.
Who reads it
Two people. The physician who writes your report, and one editor who checks the English before it is sent. Both are named on request, and the physician is named on the report itself.
Access is by individual account, never a shared login. A physician sees the intakes assigned to them and not the rest. Every read is logged with the account and the time, and those logs are kept for two years so that a question about who opened what has an answer.
Nobody else reads it. Not a contractor, not an advertiser, not an analytics company, not an insurer, and not an artificial-intelligence vendor. We have never received a government request for a reader’s records; if we ever do, and we are allowed to tell you, we will.
The transfer to China, stated plainly
The physician who reads your intake is in Hangzhou. When they open your record, your information is accessed from the People’s Republic of China. That is an international transfer, and for readers in the United Kingdom and the European Economic Area it is the part of this notice that deserves the most attention.
China has no adequacy decision from the European Commission or from the United Kingdom government. There is no enforceable local equivalent of your rights there, and no supervisory authority you could complain to. Chinese law can oblige a company established in China to give information to state authorities in circumstances wider than European law allows, and it is possible you would not be told that it happened.
We do not paper over that with standard contractual clauses that would not survive the transfer risk assessment behind them. We rely on your explicit consent under Article 49(1)(a) of the UK and EU GDPR, given after being shown the paragraph above, in its own tick box on the intake page.
You can withdraw that consent at any moment. Withdraw it before your report is delivered and we stop work and refund you in full. If you would prefer that your information never leaves Europe, then we cannot write your report, and that is the honest answer rather than a workaround.
How long each thing is kept
| Record | Kept for | Why that long |
|---|---|---|
| Tongue photograph | 30 days after delivery | Long enough to answer a question about the report |
| Intake answers and free text | 24 months | So a second reading can see what changed |
| The report we sent you | 24 months | So we can send it again if you lose it |
| Email correspondence | 24 months | Complaint history |
| Consent record: version, hash, timestamp, hashed IP | 6 years | The only evidence that we asked properly |
| Payment record: amount, date, Stripe reference | 7 years | Tax law. Contains no health information |
Twenty-four months is not an accident. It is there so that if you come back, the physician can read what you said the first time and see what moved. If you would rather they could not, tell us and we delete the earlier record.
No advertising or analytics code, enforced by a header
There is no advertising pixel and no analytics script anywhere on this site. On the routes that touch health information there is additionally no way for one to be added by mistake.
Those routes are:
/assessment/intake/report/admin/api/intake/api/report/api/upload
On every one of them the Content-Security-Policy header sent by our edge proxy blocks third-party script, connect, image and frame sources outright. If someone here pasted a tag manager into the page tomorrow, your browser would refuse to load it. This is not a statement about our discipline. It is a response header, and you can read it in your browser’s network panel.
Nearly every case actually brought under Washington’s My Health My Data Act so far has been about the same thing: a third-party tracking pixel on a health page. We would rather make that impossible than remember not to do it.
Deleting it — the actual route
Email privacy@bencaohouse.com from the address you used, with the word delete in the subject line. That is the whole process. There is no form, and nobody will call you to ask you to reconsider.
- We reply within 72 hours. If the address does not match our record, we ask you one question from your own intake rather than ask for identity documents.
- The photograph is deleted within 24 hours of that reply.
- Everything else goes within 30 days, backups included. Backups roll on a 30-day cycle, which is the only reason it is 30 days and not immediate.
- We write to you when it is done, and tell you what survived.
What survives: the payment record, which tax law requires us to keep for seven years and which holds no health information, and the consent record, which is the evidence that we asked you properly. Ask and we will delete as much of those as the law allows.
You can also ask for less than everything — delete the photograph, keep the report; or delete the answers and keep nothing else. Say which and that is what happens.
Washington, Nevada and the other state laws
Washington — My Health My Data Act
If you live in Washington, or your information was collected there, you may confirm whether we hold consumer health data about you, see the list of parties it has been shared with, withdraw your consent to its collection and sharing, and have it deleted from our systems and our backups. The list of parties is short: the providers named in clause 05, and nobody else.
We do not sell consumer health data and never have. We have never operated a geofence around any healthcare facility, and we have no advertising business that would give us a reason to. We answer requests within 45 days and tell you if we need the one extension the Act permits. If we refuse a request, we tell you how to appeal it. The Act also gives you a private right of action through the state Consumer Protection Act, which does not depend on our co-operation.
Nevada — SB 370
The same rights on the same timetable: confirm, access, delete, and withdraw consent. We do not sell consumer health data, so there is nothing for a Nevada resident to opt out of.
California, Colorado, Connecticut, Virginia, Texas, Oregon and the rest
These laws classify health information as sensitive personal information and require opt-in consent before it is collected. We collect on opt-in consent everywhere, so those requirements are simply how the intake already works. Send requests to the same address, and say which state you are writing from.
Rights under the UK and EU GDPR
You have the right to:
- a copy of everything we hold about you;
- have anything wrong in it corrected;
- have it erased;
- restrict what we do with it while a question is open;
- receive it in a portable, machine-readable form;
- object to processing;
- withdraw a consent you have given, without that withdrawal affecting what was lawful beforehand.
Write to privacy@bencaohouse.com. We answer within one calendar month and do not charge. We ask for nothing beyond the email address you used.
No decision about you is made by an automated system. A person reads every intake and writes every report; there is no profiling and no scoring.
You may complain to a supervisory authority without coming to us first: the Information Commissioner’s Office in the United Kingdom, or the data protection authority of the country you live in within the European Economic Area. We are not required to appoint a Data Protection Officer and have not appointed one; the person who answers signs their reply with their name.
Changes, and who to write to
This notice is versioned. If we change what we collect, how long we keep it, or who can see it, the version moves and we email everyone who has bought a report in the previous twelve months at least fourteen days beforehand. A change that broadens what we do with information already collected requires fresh consent; it does not happen by announcement.
Questions, requests and complaints about any of the above: privacy@bencaohouse.com. Anything else: care@bencaohouse.com. Both are read by a person.
The reading
Nothing here is a condition you have to accept.
The intake asks three separate questions before it asks anything about your body: may we hold this, may it be read in China, and may we email you. None of the boxes are ticked in advance.