Effective 2026-05-13. Applies to U.S. residents whose consumer health data is collected, used, or shared through MyDosha.
MyDosha (operating brand of MyTrueDosha) is operated by Thomas Thijs, Frazione Ammazzavecchia 12, 58010 Sorano (GR), Italy. Privacy and consumer-health-data requests: privacy@mydosha.org. Security: security@mydosha.org. Public security policy: /.well-known/security.txt. We respond to verified consumer health data requests within 45 days; we may extend by 45 days when reasonably necessary, in which case we will tell you why.
Under the Washington My Health My Data Act and analogous state laws, "consumer health data" is personal information that identifies a consumer and that is linked or reasonably linkable to past, present, or future physical or mental health status. We treat the following MyDosha data as consumer health data:
| Category | What it is |
|---|---|
| Identification | Name, email address, age, gender, language, IP address used at intake. |
| Self-reported intake | Answers given to the chatbot intake covering constitution indicators (Phase 1), lifestyle (Phase 2), and the patient's own description of their health concern. |
| Dosha assessment | The computed Vata / Pitta / Kapha scores and the dominant-dosha classification derived from intake answers. |
| AI-generated dossier | The 19-section practitioner-facing summary written by Claude (Anthropic) from the intake answers, including prakriti, vikriti, agni, srotas and manas reorganisations of patient self-report. |
| Practitioner notes | The ashtavidha pariksha exam fields (nadi, jihva, netra, sparsha, akriti, agni, ama, mala, mutra, manas) and the practitioner's own care-plan notes (aushadha, ahara, vihara, panchakarma). |
| Photos | Clinical photos uploaded by the practitioner (for example, tongue, eyes, skin) and stored base64-encoded in the patient's clinical record. |
| Journal entries | Daily self-reported energy, digestion, sleep and mood scores and free-text notes. |
| Communication metadata | Magic-link delivery records, audit log entries, support correspondence. |
We collect each category of consumer health data only for the purposes listed below. We do not collect consumer health data for other purposes without first obtaining your separate, affirmative consent.
We do not use consumer health data for advertising, behavioural profiling, targeted marketing, training general-purpose AI models, or for the sale or rental of data to any third party.
Almost all of your consumer health data comes from you, entered directly into the intake or the journal. Practitioner-note fields, photos, and AI-generated dossier sections are produced by your practitioner or by Claude (Anthropic) on the basis of your own intake answers. We do not buy, scrape, or otherwise acquire consumer health data from third parties.
Before we collect your consumer health data, we ask you to give explicit, opt-in consent on the first screen of the intake. Consent is recorded with a timestamp, the version of this policy you saw, and your IP address. You can withdraw consent for further collection at any time by emailing privacy@mydosha.org or by deleting your record via the patient portal. Withdrawing consent for collection does not retroactively make prior collection unlawful, but it stops further collection going forward.
Sharing your consumer health data with your practitioner is the core purpose of MyDosha and is therefore subject to a separate, affirmative consent gate during intake. By giving this second consent you authorise MyDosha to share your intake data, dosha assessment, and AI-generated dossier with the practitioner who invited you to use the service (and with the clinic that practitioner operates). This consent is also recorded with timestamp, policy version, and IP address.
We do not share your consumer health data with anyone outside that practitioner relationship except as set out in §8 (sub-processors) and §9 (legal-compliance disclosures), and except where you ask us to.
MyDosha does not sell consumer health data within the meaning of any U.S. state privacy or consumer-health-data law. "Sale" in those laws includes the exchange of data for "valuable consideration", and we do not engage in that practice for consumer health data. We will not start selling consumer health data without first asking you for separate, affirmative consent.
We share your consumer health data with the following processors only to the extent necessary for them to perform a function on our behalf, under written data-processing agreements:
| Processor | What they do for us | Where data is processed |
|---|---|---|
| Supabase Inc. | Database hosting (PostgreSQL). | EU (Frankfurt, AWS eu-central-1). |
| Vercel Inc. | Serverless function and static hosting. | Edge / multi-region; primary functions in EU. |
| Anthropic, PBC | AI inference for intake summarisation and dossier generation (Claude). Contractually bound not to train on customer data. | United States. |
| Resend Inc. | Transactional email delivery (magic links, care plan). | United States. |
| Stripe, Inc. | Payment processing for paid practitioner plans. Patient data not shared. | United States. |
| GitHub Inc. | Source-code hosting. Production data not stored in source code. | United States. |
We do not share consumer health data with any other category of recipient. We do not share it with advertising networks, data brokers, analytics vendors, or affiliated brands. We do not transfer consumer health data to entities owned by the same parent company because MyDosha has none.
We will disclose consumer health data when required by law (for example, a valid subpoena or court order), when necessary to comply with regulator inquiries, when necessary to investigate or prevent fraud or abuse, or when necessary to protect the safety of any person. We will, where lawfully possible, notify you of any compelled disclosure of your data.
You have the following rights with respect to your consumer health data. To exercise any of them, email privacy@mydosha.org with the subject "Consumer health data request" or use the in-product controls described below. We verify identity through your access email and, where necessary, the magic-link flow.
delete_patient_safe database function, which snapshots the record to the audit log before deletion and refuses obviously-too-large bulk operations.MyDosha does not implement geofences around any health-care facility, mental-health facility, or reproductive- or sexual-health facility, and we do not use any technology that would alert, identify, advertise to, or notify a consumer based on the consumer being within or near such a facility. This commitment matches the prohibition in RCW 19.373.030 and analogous state provisions.
MyDosha is intended for adults. We do not knowingly collect consumer health data from anyone under 13, consistent with the Children's Online Privacy Protection Act. Practitioners must not use MyDosha with patients under 18.
Patient records are retained for as long as the practitioner who manages them keeps them on the platform, subject to your deletion right under §10. Audit-log entries derived from your data are retained for the period required by our security and regulatory obligations (currently a minimum of 12 months). Backups are retained for up to 90 days; deleted records age out of backup within that window.
We apply healthcare-grade safeguards regardless of whether HIPAA applies to your practitioner: encryption in transit (TLS) and at rest (AES-256 on Supabase), service-role separation, append-only audit logging with database-level triggers preventing UPDATE / DELETE / TRUNCATE on audit rows, magic-link authentication for the patient portal, and rate-limiting on sensitive endpoints. Our security incident response runbook commits us to a 60-day individual-notification clock and a 10-business-day FTC-notification clock for breaches affecting 500 or more individuals, consistent with the FTC Health Breach Notification Rule. Vulnerability reports go to security@mydosha.org; the canonical policy lives at /.well-known/security.txt.
The Washington My Health My Data Act creates a private right of action through the Washington Consumer Protection Act (RCW 19.86). Other states' consumer-health-data laws provide for enforcement by the state Attorney General. MyDosha accepts these exposures as part of its responsibility for handling consumer health data and does not, by this policy or by any contract, attempt to waive consumer rights of action under those statutes. If you believe MyDosha has violated this policy or the underlying statutes, please contact privacy@mydosha.org first so we can investigate and respond.
We will revise this policy as the underlying statutes evolve and as we add or change processors. When a change materially affects how we collect, use or share consumer health data, we will give you advance notice and, where the change requires it, request fresh consent before applying it to your data.
Questions, concerns, or rights requests: privacy@mydosha.org. We respond within 45 days. Read alongside the general Privacy Policy, the Intended Use statement, and the Imprint.
Last updated: 2026-05-13.