Skip to main content

Consumer Health Data Privacy Notice

For Washington, Nevada, and (from July 1, 2026) Connecticut residents. This Notice is separate from, and supplements, our Privacy Policy.

Last Updated: September 1, 2026

Effective: Upon public launch of the Service

Work in Progress — Pre-Launch Draft

This Notice is a pre-launch draft and is not yet in effect. The canonical source of truth is CONSUMER_HEALTH_DATA_NOTICE.md in our repository.

About This Notice

This Consumer Health Data Privacy Notice ("CHD Notice") is a separate notice required by the Washington My Health My Data Act (RCW 19.373, "MHMDA"), Nevada SB 370 (NRS 603A.400 et seq.), and the Connecticut Data Privacy Act as amended by SB 1295 (effective July 1, 2026). It supplements, and does not replace, our Privacy Policy.

This Notice is linked directly from the footer of ophie.app, adjacent to — and distinct from — our Privacy Policy link, consistent with Washington Attorney General guidance.

1. Who This Notice Covers

  • Residents of Washington, regardless of the residence we have on file.
  • Consumers physically located in Washington when interacting with the Service.
  • Residents of Nevada.
  • Residents of Connecticut, for processing on or after July 1, 2026.

2. What "Consumer Health Data" Means for Ophie

MHMDA defines "consumer health data" broadly. For users covered by this Notice, Ophie treats the following as consumer health data:

  • voice audio (transient) and the text transcript derived from it;
  • message content of your conversations with Ophie;
  • memories and topics derived from your sessions;
  • emotional snapshots, sentiment, valence/arousal, and wellness trajectory inferences;
  • speech-emotion-recognition outputs (when persisted);
  • crisis-detection signals (category, confidence, action taken);
  • the fact of use (that you join the waitlist or use Ophie) and derived usage facts (frequency, duration, topical focus);
  • a health-related response entered before August 31, 2026 in the former optional waitlist free-text field. That field is retired, and new signups do not collect or persist a free-text response.

3. Categories of CHD and the Specific Sources

CategorySpecific Source
Voice audio (transient)Your microphone during a voice session, streamed via LiveKit WebRTC
TranscriptGenerated by AssemblyAI from your voice audio; stored in Supabase in Memory mode
Message contentTyped by you or transcribed from your voice
Session metadataGenerated by your use of the Service
Emotional inferencesOphie's local SER model and LLM stack
Memories, topics, constellations, continuity markersDerived by Ophie from your conversations
Crisis-detection signalsML safety classifier (GPT-OSS-Safeguard 20B)
Fact of useWaitlist signup, account creation, and session activity
Legacy optional waitlist responseProvided directly by you before the field was retired on August 31, 2026

4. Specific Purposes for Each Category

CategorySpecific Purposes
Voice audio (transient)Transcribe your speech; synthesize response voice; establish real-time voice connection
TranscriptContinuity within and across sessions; your review/edit/delete; operate RAG memory (Memory mode only)
Message contentGenerate the AI response; generate memories; operate safety classifier
Session metadataOperate/debug the Service; show you your own stats; bill paid tiers
Emotional inferencesAdapt tone in session; render your wellness timeline
Memories, topics, etc.Remember what you asked us to remember; your review/edit
Crisis-detection signalsSurface crisis resources; pause or redirect the session
Fact of useAdminister the waitlist; authenticate; render your stats
Legacy optional waitlist responseUnderstand prospective-user interest; never crisis monitoring, diagnosis, treatment, or automated health profiling

Ophie does not use CHD for targeted advertising, sale, training models, or profiling with significant effects. We instruct providers not to train on CHD, but provider protections vary. Together AI requires account-level ZDR activation that is not yet evidenced; its active voice-cognition path is a documented compliance blocker, not approved health-data processing.

5. Specific Third Parties We Share CHD With (by Name)

MHMDA requires named disclosure. The following is the complete list as of the date above:

  • Supabase, Inc. — managed Postgres database, authentication, file storage, and auth-flow email (account confirmation, password reset) (US).
  • LiveKit Incorporated — real-time WebRTC voice transport and LiveKit Cloud hosting of our voice agent runtime (US).
  • Speechify, Inc. — primary text-to-speech voice synthesis (the Simba 3.2 streaming model) — speaks Ophie's replies aloud (US).
  • AssemblyAI, Inc. — streaming speech-to-text transcription of your voice during sessions (Universal-3.5 Realtime Pro), plus batch transcription of session audio (US).
  • Deepgram, Inc. — last-resort text-to-speech fallback when the primary voice provider fails to initialize; formerly also the streaming speech-to-text provider (not selected while the AssemblyAI override is set) (US).
  • Hume AI, Inc. — text-to-speech voice synthesis (Octave 2) — selectable alternate; not selected under the current configuration (US).
  • Theai, Inc. (d/b/a Inworld AI) — text-to-speech voice synthesis (selectable alternate; not selected under the current configuration) (US).
  • Cartesia AI, Inc. — text-to-speech and speech-to-text (selectable alternate; not selected in production) (US).
  • OpenAI OpCo, LLC — primary inference provider for our conversational LLM (GPT-5.6) — generates the AI response. An optional batch speech-to-text path (Whisper) exists but is not enabled. (US).
  • Groq, Inc. — first automatic failover leg for the conversational LLM when the primary provider fails (an open-weight Qwen model); also inference for our crisis-detection safety classifier (the open-weight GPT-OSS-Safeguard 20B model), background reasoning models, and RAG summarization (US).
  • DeepInfra, Inc. — former primary inference provider for the conversational LLM (an open-weight Tencent Hy3 model); the integration and credentials remain but no production code path selects it (US).
  • SILICONFLOW TECHNOLOGY PTE. LTD. — former last-resort failover inference provider for the conversational LLM; the integration and credentials remain but no production code path selects it (Singapore).
  • Weights and Biases, LLC (W&B Inference) — former primary inference provider for the conversational LLM (an open-weight Qwen 3 model); the integration and credentials remain but no production code path selects it (US).
  • Together Computer, Inc. (Together AI) — inference for voice-session subconscious intuition and Guardian reasoning loops (North America).
  • Voyage AI Innovations, Inc. (a MongoDB, Inc. company) — text-embedding and reranking models used for memory retrieval (US).
  • Pinecone Systems, Inc. — former managed vector database retained as a disabled rollback integration while Supabase pgvector is active (US).
  • Amazon Web Services, Inc. (AWS Key Management Service) — key management for our application-layer envelope encryption (US).
  • Render Services, Inc. — backend API hosting (US).
  • Netlify, Inc. — frontend application hosting and CDN (US).
  • Functional Software, Inc. (d/b/a Sentry) — error monitoring and performance telemetry (backend and client apps) (US).
  • PostHog, Inc. — product analytics — only if you opt in; the default is off (US).
  • Stripe, Inc. — payment processing and subscription billing (not enabled during beta) (US).
  • Plus Five Five, Inc. (d/b/a Resend) — transactional email delivery (verification codes, receipts, policy notices) (US).

Ophie has no affiliates receiving CHD at the date above. We do not sell CHD to any person or entity.

7. Your Rights

  • Confirm whether we are processing your CHD.
  • Access the specific CHD we hold.
  • Access the list of third parties that have received your CHD, by name.
  • Delete your CHD, with propagation to our processors and downstream recipients.
  • Withdraw consent to further processing.

Response timing: 45 days, extendable once by 45 days when reasonably necessary. Appeal on denial; you may also complain to the Washington, Nevada, or Connecticut AG as applicable.

Submit requests at health-team@ophie.app or via in-product Privacy Controls.

8. No Geofencing

We do not use geofences to identify, track, target, collect data from, or send notifications or ads to consumers in relation to their CHD. We do not operate a geofence around any in-person healthcare facility.

9. Security

We protect CHD with the safeguards described in Section 10 of the Privacy Policy: transport and at-rest encryption; Postgres row-level security; scoped access; vendor due diligence; incident-response procedures. Production access to CHD is restricted and logged.

10. Breach Notification

In the event of unauthorized access, acquisition, or disclosure of CHD, we will notify affected users and regulators per the FTC Health Breach Notification Rule, MHMDA, Nevada breach law, and Connecticut breach law.

11. Private Right of Action (Washington)

Washington MHMDA is enforced by the Washington Attorney General and through the Washington Consumer Protection Act, which provides a private right of action. If you are a Washington resident and believe Ophie has violated MHMDA, you may have a claim in addition to filing with the Washington AG.

12. Retention

We retain CHD only as necessary for the purpose for which it was collected. Specific periods are in Section 9 of the Privacy Policy. Legacy optional waitlist responses are deleted 180 days after collection, or sooner when you exercise a deletion right under this Notice. Deletion flows propagate to our processors and, where feasible, to backups.

13. Contact

Consumer health data requests: health-team@ophie.app

General privacy: support@ophie.app

Regulator complaints:

  • Washington AG: https://www.atg.wa.gov/file-complaint
  • Nevada AG: https://ag.nv.gov/Complaints/CMPL_Main/
  • Connecticut AG: https://portal.ct.gov/ag/consumer-filing-a-complaint

14. Changes to This Notice

Material changes will be communicated by email and in-product notice at least 30 days before taking effect. If a change materially alters how we process CHD, we will solicit a refreshed opt-in consent before applying the change.