← Back to prismaIQ

Privacy Policy

Working draft · pending attorney review · Last updated for pilot alignment

Last Updated: 2026-09-02

1. Overview

This Privacy Policy describes how prismaIQ ("we," "us") collects, uses, and protects information when you use our platform. prismaIQ is HIPAA compliant. prismaIQ is HIPAA compliant. We have Business Associate Agreements in place with our associated vendors — including Xata for our database and OpenAI for the optional AI Assistant — so your health information stays protected when you use the Service.

By using our Service, you consent to the data practices described in this policy. If you do not agree, please do not use our Service.

2. Information We Collect

  • Account information: name, email, authentication data (via Google OAuth or similar), optional profile details.
  • Payment information: Payment processing is handled by Stripe. We do not store your full credit card numbers. Stripe collects and processes payment data under their privacy policy and PCI-DSS standards. See Stripe's Privacy Policy.
  • Health information you provide or connect: lab results (manual entry, PDF/CSV upload, or connected partners), medications, allergies, dietary restrictions, health conditions, logged health events, immunization records, care team contacts.
  • Health vault documents: lab reports, medication lists, visit summaries, discharge notes, immunization records, and imaging reports you choose to upload. Imaging uploads are stored as reference-only documents (viewable, downloadable, and attachable to a doctor-share summary). We may extract printed text for keyword quote search only. We do not run clinical AI interpretation of images (no radiology AI, no automatic diagnosis). Structured biomarker parse/confirm applies only to documents you classify as lab reports. We do not collect genetic testing results or mental health records at this time; those categories are blocked.
  • Wearable data: if you connect a supported wearable (e.g., WHOOP, Garmin), we receive recovery, HRV, sleep, and activity metrics as authorized by you. OAuth tokens are encrypted at rest with AES-256-GCM in application code.
  • Usage data: how you interact with the platform (e.g., which recommendations you keep or skip), device/browser information, and IP address for security and fraud prevention.
  • Shopping and grocery data: items added to cart, purchase confirmations, and related preferences, if you use shopping features.

3. How We Use Your Information

  • Provide core platform functionality (biomarker analysis, food and lifestyle guidance, drug–nutrient interaction checking, wearable integration)
  • Generate reports you explicitly request, such as a clinician-share summary
  • Improve and personalize the platform, including through disclosed, auditable statistical methods and, where enough personal data has accrued, machine learning for anomaly spotting — described in-product and in our Data Use Policy
  • Process subscriptions and payments
  • Communicate with you about your account and, where you opt in, send reminders or notifications
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your health information. We do not share your individual health information with advertisers.

4. Consumer Health Data — Additional Disclosures

Some jurisdictions (including Washington State's My Health My Data Act and similar laws) require specific disclosures regarding "consumer health data." In accordance with these requirements:

  • We collect the categories of consumer health data described in Section 2.
  • We use this data solely to provide and improve the platform as described in this Policy.
  • We do not sell consumer health data.
  • We do not share consumer health data with third parties except as described in Section 5 (Service Providers), for the purpose of providing the platform to you.
  • You may withdraw consent and request deletion of your consumer health data at any time (see Section 7).

5. Service Providers and Data Sharing

We share information with third-party service providers who help us operate the platform, under contractual obligations to protect your data:

  • Cloud hosting and database: Xata (Postgres). We have an executed Business Associate Agreement with Xata covering health information stored in our core database.
  • Application hosting and file storage: Vercel (hosting and private object storage / Vercel Blob for health vault files). Vault uploads use private Blob storage with product controls on real (non-synthetic) documents.
  • AI Assistant only: OpenAI powers the optional AI Assistant chat under an executed Business Associate Agreement as part of our HIPAA-compliant stack. The Assistant may use confirmed labs, medications, flagged findings, and related structured context (such as sex, height/weight, and conditions you have logged) so it can answer — without sending your name or date of birth by default. Anthropic may be used only as an optional fallback for the same Assistant under the same protections. Other platform features (labs, shopping, wearables, calendar, and so on) do not depend on the AI Assistant vendor.
  • Payments: Stripe (billing; not clinical charts).
  • Authentication: Google OAuth when you choose Google sign-in.
  • Error monitoring: Sentry (configured to avoid default PII; events are scrubbed). We also record operational counts when a lab file is uploaded and when results are returned to the app or site (document id, success/failure, row counts — not lab values, filenames, or your email). Failed deliveries can notify prismaIQ operations by email so we can fix the pipeline.
  • Transactional email: Resend (e.g., contribution or support requests you submit).
  • Wearable providers: WHOOP, Garmin (data only with your explicit connection).
  • Document processing: lab report parsing uses a self-hosted processing service. Matched markers with a collection date are saved to your results; unmatched rows still need your review. Imaging and other reference documents are not biomarker-parsed.
  • Grocery/shopping: Instacart (only for items you choose to add to a cart; we do not share your health conditions or biomarker data with Instacart).

A current list of our subprocessors is available at /subprocessors.

We may disclose information if required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users or others.

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

We do not sell your personal information to third parties for their own marketing purposes.

6. Data Security

  • Encryption in transit: HTTPS/TLS for application traffic
  • Encryption at rest: provider-managed encryption for database and private object storage; wearable OAuth tokens encrypted with AES-256-GCM in application code
  • Access controls: authenticated sessions and ownership checks on health APIs
  • Minimization: AI Assistant is HIPAA compliant under our OpenAI BAA and does not send your name or date of birth by default; health vault real uploads use private storage with product access controls

No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

7. Your Rights and Choices

  • Access and correction: view and edit your profile and health information in the platform
  • Deletion: request deletion of your account and associated data through account settings or by emailing legal@prismaiq.io
  • Data export: request a copy of your data (in-product export where available)
  • Withdrawal of consent: for features requiring opt-in (e.g., research data use, calendar notifications, health vault uploads), you may withdraw consent at any time

Email legal@prismaiq.io for privacy requests. We aim to respond within 30 days.

8. Data Retention

Active account data is retained while your account is active. After account deletion, we aim to purge associated health data from primary systems within a commercially reasonable period, except where retention is required by law, for security/fraud prevention, backups pending rotation, audit logs, or active dispute purposes. Exact backup retention windows will be finalized with counsel and published in a later update.

9. Research Use of Data (Optional Opt-In)

If you are offered the option to contribute de-identified or aggregated data to research purposes, this will always be presented as a separate, explicit, revocable opt-in, distinct from your consent to use the core platform. You will never be required to opt in to research use to access core platform features.

Material change from prior policy: earlier versions stated an absolute prohibition on research use of health data. This Policy replaces that with the optional opt-in framing above. Existing users will be notified of this material change.

10. Children's Privacy

prismaIQ is not directed to individuals under 18, and we do not knowingly collect information from anyone under 18. If you believe we have collected information from a child under 18, contact us immediately.

11. International Users

prismaIQ is currently designed for and offered to users in the United States. If and when international expansion occurs, this section will be updated to reflect applicable regional data protection requirements.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Service. See our Cookie Policy for details.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active users before they take effect (generally at least 30 days when practicable, including email where we have an address on file). The "Last Updated" date indicates the latest revision.

14. Contact

Questions about this Privacy Policy or your data: legal@prismaiq.io

By using prismaIQ, you acknowledge that you have read and understood this Privacy Policy.