Cardiki
Open the app
Draft — under legal review. Not yet in force.

Consumer Health Data Privacy Policy

Last updated: 8 October 2026

This policy applies to consumers in Washington State, Nevada and other places with consumer health data laws. It explains how Cardiki collects, uses and shares "consumer health data", which these laws define broadly enough to include some of what you might write in a reflection app. It supplements our Privacy Policy.

What consumer health data we collect

Cardiki does not ask for medical information. However, some features can capture information that these laws treat as consumer health data:

  • Mood tags you choose after a reading, such as "calm" or "anxious".
  • Journal entries you write, which may mention your physical or mental health, how you are feeling, or care you are receiving.
  • Questions you ask the cards, if they touch on your health.
  • Pattern insights we derive from your mood tags and journal, such as how your mood has trended over recent weeks.
  • Safety event codes: when a question suggests someone may be in crisis, we record a category code and a response code, never the text.

Where we collect it from

Directly from you, when you tag a mood, write in your journal or ask a question. We derive pattern insights from that same information. We do not buy health data or collect it from other sources.

We store mood tags and use your journal for readings and insights only after you tick the unticked "Personalise with my journal" box, which explains in plain language what it allows. You can withdraw that consent in Settings at any time; processing stops immediately and we offer to delete the insights derived from your journal. Without consent, you can still write journal entries that are stored only for you to read, and Cardiki still works.

How we use it

  • to keep your journal and show it back to you;
  • to personalise interpretations with recent moods and journal excerpts, if you have consented;
  • to calculate pattern insights such as mood trends, if you have consented;
  • to show support resources instead of a reading when a question suggests someone may be at risk;
  • to measure whether our safety protocol is working, using codes only.

We do not use consumer health data for advertising, and we never use it to train or fine-tune AI models.

Who we share it with

We share consumer health data only with service providers that process it for us under contract and may not use it for their own purposes:

  • our AI provider, which receives mood tags and short journal excerpts, without your name, email or account identifiers, only to write an interpretation you asked for, and keeps nothing or keeps it for at most 7 days;
  • our cloud hosting and database provider, which stores it encrypted.

We do not sell consumer health data. We do not share it with advertisers, data brokers or anyone else, and we do not use geofencing around health care facilities. We would disclose it only if the law compelled us to, and we would tell you unless the law prohibits that.

How we protect it

Journal entries and questions are encrypted at the application layer with a key unique to your account. They are decrypted only for the moment needed to show them to you or write a reading, and they never appear in notifications, analytics or crash reports.

Your rights

You have the right to:

  • confirm whether we collect, share or sell your consumer health data, and access it, including a list of the third parties and affiliates we have shared it with;
  • withdraw consent to its collection and sharing;
  • delete it, which also deletes it from our processors' systems.

You can export your data and delete entries or your whole account in the app, or on the web. You can also email privacy@cardiki.com. We respond within 45 days, and may extend that by a further 45 days where necessary, telling you why. If we decline your request, you can appeal by replying to our decision; we respond to appeals within 45 days, and if you are still unhappy you may contact the Washington State Attorney General at atg.wa.gov or the Nevada Attorney General at ag.nv.gov.

Retention

Mood tags, journal entries and derived insights are kept until you delete them, withdraw consent and ask us to delete derived insights, or delete your account. Deleted accounts are erased within 30 days and removed from backups within 90 days. Safety event codes are kept for 13 months.

Contact

[to be confirmed by counsel], [to be confirmed by counsel]. Email: privacy@cardiki.com