Consumer Health Privacy Policy
This Consumer Health Privacy Policy supplements our Privacy Policy and Terms of Service. It explains how MyEchoPath handles information that may be considered consumer health data under applicable state and federal laws, including the Washington My Health MY Data Act and similar legislation. If you are a Washington State resident, this policy is particularly important to you.
Overview & Our Commitment
MyEchoPath is a voice journaling and self-reflection tool. In the course of operating the Service, we may collect information that could be considered "consumer health data" under emerging state privacy laws — specifically, emotional states, mental wellness patterns, and mood data derived from your voice entries.
We do not sell your health data. We do not use your health data for advertising. We do not share your health data with insurers, employers, data brokers, law enforcement (except as legally required), or any entity that would use it to your detriment. Your emotional journey belongs to you alone.
This policy is designed to be transparent about the limited health-adjacent data we collect, exactly how it is used, and the robust protections we maintain. We honor these protections regardless of what state or country you live in.
What Is Consumer Health Data?
Laws like the Washington My Health MY Data Act define "consumer health data" broadly to include any personal information that identifies a consumer and is linked or reasonably linkable to the consumer's physical or mental health condition, including:
- Mental health conditions and diagnoses
- Emotional states and mood patterns
- Health-related behaviors (sleep, stress, exercise)
- Attempts to seek health information
- Data derived or inferred from other personal information that identifies health conditions
Within MyEchoPath, the following may qualify as consumer health data: emotion labels derived from your voice entries (e.g., "anxious," "hopeful"), mood valence scores, and AI-generated insights referencing your emotional state. We treat all of this data with the highest level of care.
Health-Related Data We Collect
The following table describes health-adjacent data collected through MyEchoPath:
| Data Type | Description | Source | Shared With |
|---|---|---|---|
| Voice Recordings | Audio of your spoken journal entries | You record directly | Transcription service (processing only); publicly if you opt into Collective Echo |
| Transcripts | Text of your spoken words | Auto-generated from audio | Anthropic Claude API (processing only; not retained for training) |
| Emotion Labels | AI-identified emotion (e.g., anxious, hopeful) | AI inference from transcript | No third parties (stored in your private account only) |
| Mood Valence Score | Numerical score from −1.0 to +1.0 indicating mood positivity | AI inference from transcript | No third parties |
| AI Insights | Personalized reflection text generated by AI | AI generation based on transcript | No third parties |
| Streak & Frequency | How often you journal; streak data | App activity | No third parties |
We do not collect: clinical diagnoses, medical records, prescription information, insurance data, genetic data, biometric identifiers (beyond your voice as described), or any data from health providers or wearable devices.
How We Use Health-Related Data
We use health-adjacent data exclusively for the following purposes, and no others:
- Providing the Service: Displaying your journal entries, insights, and growth data back to you
- Personalizing your experience: Generating AI coaching prompts, weekly insight summaries, and tailored daily challenges based on your patterns
- Collective Echo (with your consent only): If you explicitly share an entry, the audio and emotion label are published anonymously — with no other health data attached
- Technical operations: Storing, retrieving, and protecting your data; diagnosing technical errors (using aggregated, non-identifiable logs only)
We do not use your health-related data for: advertising or marketing; sale to any third party; employment screening; insurance underwriting; credit scoring; law enforcement purposes (except as required by law); or any purpose not listed above.
MyEchoPath Is Not a Medical Service
MYECHOPATH IS NOT A HEALTHCARE PROVIDER, MEDICAL DEVICE, MENTAL HEALTH TREATMENT, THERAPY SERVICE, CRISIS INTERVENTION SERVICE, OR CLINICAL TOOL OF ANY KIND. IT IS NOT REGULATED BY THE FDA OR ANY HEALTHCARE AUTHORITY. NOTHING IN THE SERVICE CONSTITUTES MEDICAL ADVICE, PSYCHIATRIC DIAGNOSIS, PSYCHOLOGICAL TREATMENT, OR CLINICAL GUIDANCE.
The emotion labels, mood scores, and AI-generated insights produced by MyEchoPath are generated by a general-purpose large language model. They are:
- Not clinical assessments — they are not produced by licensed healthcare professionals
- Not diagnostic — they do not diagnose any mental health or physical health condition
- Not therapeutic — they are not a form of therapy, counseling, or psychiatric treatment
- Potentially inaccurate — AI models can mischaracterize emotions; never rely on them for health decisions
- Not a substitute for professional care — if you have mental health concerns, please consult a licensed professional
MyEchoPath is not subject to HIPAA (Health Insurance Portability and Accountability Act) because we are not a covered entity or business associate as defined by HIPAA. However, we voluntarily apply privacy protections that go beyond what the law requires.
We Do Not Sell Your Health Data
MyEchoPath does not sell, rent, lease, or otherwise provide your consumer health data to any third party for compensation of any kind, including monetary payment, non-monetary compensation, or any form of value exchange.
We do not share your health-related data with:
- Data brokers or aggregators
- Advertisers or ad networks
- Health insurance companies
- Employers or background check companies
- Law enforcement (except when legally compelled by valid legal process)
- Any entity that would use your data to make decisions about your employment, creditworthiness, insurance eligibility, or housing
- Research institutions (unless you explicitly opt in to a specific research program)
Our only revenue model is direct consumer subscription. We are not in the business of monetizing your health data, and we never will be.
Security of Health Data
We apply heightened security measures to health-related data, consistent with the sensitivity of the information:
- All health data is encrypted in transit (TLS 1.2+) and at rest
- Access to health data is governed by Row-Level Security — only your account can retrieve your data
- No MyEchoPath employee can access your private recordings or emotional data in routine operations
- Third-party processors (Supabase, Anthropic, Whisper) are subject to data processing agreements that prohibit use of your data for their own purposes
- We conduct periodic reviews of our data handling practices
No security system is impenetrable. In the unlikely event of a data breach involving your health data, we will notify affected users within 72 hours of becoming aware of the breach, to the extent required by applicable law. We are not liable for breaches caused by circumstances beyond our reasonable control, including cyberattacks by third parties.
Your Rights Over Your Health Data
You have comprehensive rights over your consumer health data. We honor these rights for all users, regardless of location:
To exercise any of these rights, contact privacy@myechopath.com or use the in-app deletion tools. We will respond within 30 days and will not discriminate against you for exercising your rights.
State-Specific Privacy Rights
The following state laws may grant you additional rights regarding your consumer health data:
- Washington State (My Health MY Data Act): Grants broad rights over consumer health data. We comply fully. Washington residents may request a list of all third parties to whom we have disclosed health data (the answer is: none, for commercial purposes).
- California (CCPA/CPRA): California residents have the right to know, delete, correct, and opt out of the sale of personal information. We do not sell personal information. Submit requests to privacy@myechopath.com.
- Colorado, Connecticut, Virginia, and other US states: We honor the general consumer privacy rights granted by state privacy laws in effect, including rights to access, correct, delete, and portability.
- European Union (GDPR): EU residents have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Our lawful basis for processing is your consent (provided at account creation). Contact us to exercise any GDPR right.
- Other jurisdictions: We apply the strongest applicable standard globally, to the extent feasible.
To submit a privacy rights request, email privacy@myechopath.com with the subject line "Privacy Rights Request — [Your State/Country]."
Crisis Resources & Safety
MyEchoPath does not provide crisis services or real-time mental health support. If you or someone you know is experiencing a mental health emergency, suicidal thoughts, or a medical emergency, please use the resources below immediately. Do not rely on MyEchoPath in an emergency.
- Emergency Services: Call 911 (US) or your local emergency number
- 988 Suicide & Crisis Lifeline: Call or text 988 (US) — free, confidential, 24/7
- Crisis Text Line: Text HOME to 741741 (US) — free, confidential, 24/7
- International Association for Suicide Prevention: iasp.info/resources/Crisis_Centres
- SAMHSA National Helpline: 1-800-662-4357 — free mental health and substance use treatment referrals, 24/7
MyEchoPath is designed for reflective journaling in moments of stability. If you find that using MyEchoPath is causing significant distress, we encourage you to take a break from the app and seek support from a qualified mental health professional.
Limitation of Liability for Health-Related Use
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, MYECHOPATH LLC, ITS OWNERS, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AFFILIATES, AND SERVICE PROVIDERS ARE NOT LIABLE FOR ANY HARM — INCLUDING PHYSICAL INJURY, PSYCHOLOGICAL HARM, EMOTIONAL DISTRESS, MENTAL HEALTH DETERIORATION, SELF-HARM, DEATH, FINANCIAL LOSS, OR ANY OTHER DAMAGES — ARISING FROM OR RELATED TO:
- Your use of or reliance on any AI-generated emotional analysis, mood scores, coaching prompts, or insights from MyEchoPath
- Any decision you make — medical, psychological, personal, financial, or otherwise — based on content generated by the Service
- Your failure to seek professional medical or mental health care when needed
- Emotional distress, triggering, or psychological harm arising from journaling about past trauma or difficult emotions
- Secondary trauma or distress arising from listening to others' shared entries in the Collective Echo
- Any inaccuracy, error, or omission in AI-generated content
- Technical failures that result in loss of your journal data
- Unauthorized access to your account or data by third parties
- Any adverse outcome resulting from your self-reflection activities conducted through the Service
YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT: (1) you are solely responsible for your own mental, emotional, and physical wellbeing; (2) MyEchoPath is a journaling tool and not a healthcare service; (3) you use the Service voluntarily and at your own risk; and (4) our aggregate liability to you shall not exceed $50 USD under any circumstances.
Nothing in this limitation of liability affects any rights you may have under applicable mandatory consumer protection laws that cannot be waived by contract.
Contact Our Privacy Team
For all questions, concerns, or rights requests related to your consumer health data, please contact our dedicated privacy team:
MyEchoPath Privacy & Health Data
📧 Privacy: privacy@myechopath.com
📧 General: hello@myechopath.com
🌐 Website: myechopath.com
📮 MyEchoPath LLC, [Your Business Address]
Response time: within 30 days for all privacy requests. For health data breaches or urgent security matters, mark your email "URGENT: Health Privacy."