Washington My Health My Data Act (SB 1155) — Consumer Health Data Privacy Policy
Consumer Health Data Privacy

Your Health Data,
Your Control

This Consumer Health Data Privacy Policy describes how TheraSignal collects, uses, and shares your health and biometric data. It is required under the Washington My Health My Data Act (MHMDA) and the Illinois Biometric Information Privacy Act (BIPA) and is separate from our HIPAA Privacy Policy.

Effective Date: March 29, 2026  ·  Version 1.0  ·  Questions? privacy@therasignal.com

🏛️
Washington MHMDA Coverage

The Washington My Health My Data Act (SB 1155, eff. March 31, 2024) gives Washington residents the right to opt-in before any consumer health data is collected or shared, the right to access and delete that data, and the right to sue if these rights are violated. TheraSignal will not collect or share your health data without your explicit opt-in consent.

Contents

1 What Is Consumer Health Data

"Consumer health data" under Washington MHMDA and similar laws means any personal information that identifies or could identify your physical or mental health condition, treatment, or prognosis — even if that information is not covered by HIPAA.

TheraSignal's product involves the following categories that qualify as consumer health data:

Category Examples Applies To
Mental health inferences Affect scores, emotional state labels (distress, insight, etc.), arousal patterns All users with Live Session enabled
Facial geometry / biometric identifiers Facial geometry measurements extracted from webcam frames during affect detection Users who enable facial analysis
Voice biometrics Voiceprint characteristics — pitch, energy, speech rate — extracted during live sessions Users who enable audio analysis
Physiological inferences Estimated heart rate, GSR (galvanic skin response), engagement scores derived from signal fusion All Live Session users
Session analytics Aggregated scores per session (overall affect, key moment counts, risk level) All users

2 Data We Collect

TheraSignal collects consumer health data only with your explicit opt-in consent. The following data is collected during Live Sessions when you have consented:

🔒
Privacy-First Architecture

Raw webcam frames and raw audio buffers are never transmitted to our servers. All signal processing happens in your browser (client-side). Only the resulting numerical scores are sent over an encrypted connection.

3 How We Use Your Data

We use your consumer health data for the following purposes:

Purpose Data Used Requires Consent
Real-time session analysis All biometric scores during live session ✅ Yes — opt-in required
Clinical session records Aggregated session scores (non-raw biometric) ✅ Yes — collection consent
Intervention recommendations Key moment types and affect patterns ✅ Yes — collection consent
Product improvement Anonymized, aggregated analytics only ✅ Yes — separate analytics consent
Marketing or advertising N/A — We do not use health data for marketing N/A — prohibited

We do not use your health data to infer conditions you have not disclosed, to make employment or insurance decisions, or for any purpose not listed above.

4 Data Sharing & Third Parties

🚫
We Do Not Sell Your Health Data

TheraSignal does not sell, rent, trade, or otherwise transfer your consumer health data to any third party for their own use. Period.

We share your health data only in these limited circumstances — all of which require your consent where indicated:

Recipient Purpose Data Shared Your Consent Required
Infrastructure providers Hosting, database storage (Render, Neon PostgreSQL) Encrypted session scores in secure database Collection consent covers this (BAA in place)
Your designated clinician If you share a session report with your therapist/supervisor Session summary only ✅ Explicit share action by you
Law enforcement / legal process If legally required by court order or subpoena Minimum necessary N/A — legal requirement
Analytics providers None — we do not use third-party analytics on health data N/A

6 Retention & Deletion

We retain your consumer health data only as long as necessary for the purpose it was collected.

Data Type Retention Period Deletion Method
Raw biometric signals (facial geometry measurements, voiceprint data per frame) 90 days from session date — then automatically deleted Automated nightly cleanup job
Processed session scores (affect valence, arousal, engagement averages) Duration of your account, or until you request deletion Account deletion or explicit request
Key moments (flagged clinical events with timestamps) Duration of your account Account deletion or explicit request
Consent records (proof of your consent) 7 years (legal compliance) Not deletable — required for legal audit trail
Compliance audit log 7 years (legal compliance) Not deletable — required for legal compliance
⏱️
BIPA 90-Day Biometric Retention

Under Illinois BIPA (740 ILCS 14/15(a)), biometric identifiers must be destroyed within 3 years of collection or when the purpose is fulfilled, whichever is earlier. TheraSignal uses a 90-day window as a best practice, which is more protective than the 3-year BIPA maximum. Raw sensor readings are automatically purged after 90 days.

7 Your Rights

Depending on your jurisdiction, you have the following rights regarding your consumer health data. Washington MHMDA, Illinois BIPA, and California CCPA each grant specific rights — we honor all of them regardless of where you are located.

👁️
Right to Access
Request a copy of all consumer health data we hold about you, including what was collected and when.
🗑️
Right to Delete
Request deletion of your biometric and health data. Processed scores may be retained for clinical records; consent logs are retained for legal compliance.
🚫
Right to Withdraw Consent
Revoke your consent at any time. Future collection stops immediately. Data already collected is unaffected unless you also request deletion.
⚖️
Right to Sue (Private Right of Action)
Under Washington MHMDA and Illinois BIPA, you may bring a private civil action if we violate these rights. No class action waiver applies to BIPA claims.
📋
Right to Audit Log
View a full audit log of all access events for your health data, including when consent was granted or revoked.
🔄
Right to Correct
Request correction of inaccurate health data. For biometric data derived from sensor readings, deletion and re-collection is the available remedy.

To exercise any of these rights, contact us at privacy@therasignal.com or use the controls in your account settings.

We will respond to verified requests within 30 days (Washington MHMDA) or 45 days (CCPA) of receipt.

8 Biometric Data & Illinois BIPA

TheraSignal's BIPA compliance program includes:

Retention & Destruction Policy

Biometric identifiers are destroyed:

This schedule is more protective than BIPA's 3-year maximum. The policy is enforced programmatically via an automated daily cleanup job, not just a policy document.

9 Security

We implement technical and organizational safeguards appropriate for the sensitivity of health data:

10 Contact Us

For questions, access requests, deletion requests, or to exercise any of your privacy rights:

Privacy Contact

Subject: Health Data Privacy Request — [your name]
Response: Within 30 days for MHMDA requests; within 45 days for CCPA requests
BIPA: Illinois BIPA requests: include "BIPA Request" in subject line

If you are a Washington resident and believe we have violated the MHMDA, you may also file a complaint with the Washington State Attorney General's Office.

If you are an Illinois resident and believe we have violated BIPA, you may bring a private civil action in state court under 740 ILCS 14/20.