Intake & reference tool for qualified Ayurvedic practitioners · Not a medical device · Not for diagnosis or treatment · Intended use →
MyDosha ← mydosha.org
Consumer Health Data · United States

Consumer Health Data Privacy Policy

Effective 2026-05-13. Applies to U.S. residents whose consumer health data is collected, used, or shared through MyDosha.

Read this first. This page sits alongside our general Privacy Policy. It exists to comply with U.S. consumer-health-data laws — primarily the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (SB 370), the Connecticut consumer-health-data amendments to the CTDPA, and the sensitive-personal-information provisions of California's CPRA. If you are a U.S. resident and any of those laws apply to you, this policy governs how MyDosha handles your consumer health data. Where this policy and the general Privacy Policy differ for U.S. consumer health data, this policy controls.

1. Who we are and how to reach us

MyDosha (operating brand of MyTrueDosha) is operated by Thomas Thijs, Frazione Ammazzavecchia 12, 58010 Sorano (GR), Italy. Privacy and consumer-health-data requests: privacy@mydosha.org. Security: security@mydosha.org. Public security policy: /.well-known/security.txt. We respond to verified consumer health data requests within 45 days; we may extend by 45 days when reasonably necessary, in which case we will tell you why.

2. What is "consumer health data"

Under the Washington My Health My Data Act and analogous state laws, "consumer health data" is personal information that identifies a consumer and that is linked or reasonably linkable to past, present, or future physical or mental health status. We treat the following MyDosha data as consumer health data:

CategoryWhat it is
IdentificationName, email address, age, gender, language, IP address used at intake.
Self-reported intakeAnswers given to the chatbot intake covering constitution indicators (Phase 1), lifestyle (Phase 2), and the patient's own description of their health concern.
Dosha assessmentThe computed Vata / Pitta / Kapha scores and the dominant-dosha classification derived from intake answers.
AI-generated dossierThe 19-section practitioner-facing summary written by Claude (Anthropic) from the intake answers, including prakriti, vikriti, agni, srotas and manas reorganisations of patient self-report.
Practitioner notesThe ashtavidha pariksha exam fields (nadi, jihva, netra, sparsha, akriti, agni, ama, mala, mutra, manas) and the practitioner's own care-plan notes (aushadha, ahara, vihara, panchakarma).
PhotosClinical photos uploaded by the practitioner (for example, tongue, eyes, skin) and stored base64-encoded in the patient's clinical record.
Journal entriesDaily self-reported energy, digestion, sleep and mood scores and free-text notes.
Communication metadataMagic-link delivery records, audit log entries, support correspondence.

3. Why we collect it — the specific purposes

We collect each category of consumer health data only for the purposes listed below. We do not collect consumer health data for other purposes without first obtaining your separate, affirmative consent.

We do not use consumer health data for advertising, behavioural profiling, targeted marketing, training general-purpose AI models, or for the sale or rental of data to any third party.

4. Sources — where we get it from

Almost all of your consumer health data comes from you, entered directly into the intake or the journal. Practitioner-note fields, photos, and AI-generated dossier sections are produced by your practitioner or by Claude (Anthropic) on the basis of your own intake answers. We do not buy, scrape, or otherwise acquire consumer health data from third parties.

5. Consent — collection

Before we collect your consumer health data, we ask you to give explicit, opt-in consent on the first screen of the intake. Consent is recorded with a timestamp, the version of this policy you saw, and your IP address. You can withdraw consent for further collection at any time by emailing privacy@mydosha.org or by deleting your record via the patient portal. Withdrawing consent for collection does not retroactively make prior collection unlawful, but it stops further collection going forward.

6. Consent — sharing with your practitioner

Sharing your consumer health data with your practitioner is the core purpose of MyDosha and is therefore subject to a separate, affirmative consent gate during intake. By giving this second consent you authorise MyDosha to share your intake data, dosha assessment, and AI-generated dossier with the practitioner who invited you to use the service (and with the clinic that practitioner operates). This consent is also recorded with timestamp, policy version, and IP address.

We do not share your consumer health data with anyone outside that practitioner relationship except as set out in §8 (sub-processors) and §9 (legal-compliance disclosures), and except where you ask us to.

7. We do not sell consumer health data

MyDosha does not sell consumer health data within the meaning of any U.S. state privacy or consumer-health-data law. "Sale" in those laws includes the exchange of data for "valuable consideration", and we do not engage in that practice for consumer health data. We will not start selling consumer health data without first asking you for separate, affirmative consent.

8. Sub-processors — service providers and processors we share data with

We share your consumer health data with the following processors only to the extent necessary for them to perform a function on our behalf, under written data-processing agreements:

ProcessorWhat they do for usWhere data is processed
Supabase Inc.Database hosting (PostgreSQL).EU (Frankfurt, AWS eu-central-1).
Vercel Inc.Serverless function and static hosting.Edge / multi-region; primary functions in EU.
Anthropic, PBCAI inference for intake summarisation and dossier generation (Claude). Contractually bound not to train on customer data.United States.
Resend Inc.Transactional email delivery (magic links, care plan).United States.
Stripe, Inc.Payment processing for paid practitioner plans. Patient data not shared.United States.
GitHub Inc.Source-code hosting. Production data not stored in source code.United States.

We do not share consumer health data with any other category of recipient. We do not share it with advertising networks, data brokers, analytics vendors, or affiliated brands. We do not transfer consumer health data to entities owned by the same parent company because MyDosha has none.

9. Legal disclosures

We will disclose consumer health data when required by law (for example, a valid subpoena or court order), when necessary to comply with regulator inquiries, when necessary to investigate or prevent fraud or abuse, or when necessary to protect the safety of any person. We will, where lawfully possible, notify you of any compelled disclosure of your data.

10. Your rights

You have the following rights with respect to your consumer health data. To exercise any of them, email privacy@mydosha.org with the subject "Consumer health data request" or use the in-product controls described below. We verify identity through your access email and, where necessary, the magic-link flow.

11. Geofencing

MyDosha does not implement geofences around any health-care facility, mental-health facility, or reproductive- or sexual-health facility, and we do not use any technology that would alert, identify, advertise to, or notify a consumer based on the consumer being within or near such a facility. This commitment matches the prohibition in RCW 19.373.030 and analogous state provisions.

12. Children

MyDosha is intended for adults. We do not knowingly collect consumer health data from anyone under 13, consistent with the Children's Online Privacy Protection Act. Practitioners must not use MyDosha with patients under 18.

13. Retention

Patient records are retained for as long as the practitioner who manages them keeps them on the platform, subject to your deletion right under §10. Audit-log entries derived from your data are retained for the period required by our security and regulatory obligations (currently a minimum of 12 months). Backups are retained for up to 90 days; deleted records age out of backup within that window.

14. Security

We apply healthcare-grade safeguards regardless of whether HIPAA applies to your practitioner: encryption in transit (TLS) and at rest (AES-256 on Supabase), service-role separation, append-only audit logging with database-level triggers preventing UPDATE / DELETE / TRUNCATE on audit rows, magic-link authentication for the patient portal, and rate-limiting on sensitive endpoints. Our security incident response runbook commits us to a 60-day individual-notification clock and a 10-business-day FTC-notification clock for breaches affecting 500 or more individuals, consistent with the FTC Health Breach Notification Rule. Vulnerability reports go to security@mydosha.org; the canonical policy lives at /.well-known/security.txt.

15. Private right of action

The Washington My Health My Data Act creates a private right of action through the Washington Consumer Protection Act (RCW 19.86). Other states' consumer-health-data laws provide for enforcement by the state Attorney General. MyDosha accepts these exposures as part of its responsibility for handling consumer health data and does not, by this policy or by any contract, attempt to waive consumer rights of action under those statutes. If you believe MyDosha has violated this policy or the underlying statutes, please contact privacy@mydosha.org first so we can investigate and respond.

16. Changes to this policy

We will revise this policy as the underlying statutes evolve and as we add or change processors. When a change materially affects how we collect, use or share consumer health data, we will give you advance notice and, where the change requires it, request fresh consent before applying it to your data.


Questions, concerns, or rights requests: privacy@mydosha.org. We respond within 45 days. Read alongside the general Privacy Policy, the Intended Use statement, and the Imprint.

Last updated: 2026-05-13.