Consumer Health Data Privacy Policy

Effective date: August 16, 2026 Last revised: September 10, 2026

This Consumer Health Data Privacy Policy applies to consumer health data collected by the symptom-tracking app "Seren" (the "Service"), provided by Daiki Yamaguchi ("we," "us," or "our"). It is provided for consumers in the United States and describes our practices under U.S. state consumer health data laws, including the Washington My Health My Data Act and Nevada's consumer health data law (SB 370).

This policy supplements our Privacy Policy. Where this policy addresses consumer health data, this policy governs.

Categories of Consumer Health Data We Collect

The purpose of the Service is to help you record and review your own symptoms. We collect the following categories of consumer health data, only with your consent or as necessary to provide the Service you have requested:

We collect approximate location (rounded to a coarse area of about 11km) only to retrieve the weather and barometric pressure for your area, and only if you grant the OS location permission. We do not collect precise location information, biometric data, or genetic data. We do not use geofencing of any kind.

How We Use Consumer Health Data (Purposes of Collection)

We collect and use consumer health data solely to provide and improve the Service you request:

We do not use consumer health data for advertising, and we do not sell consumer health data. We do not permit any third party to collect your consumer health data through the Service for advertising or marketing purposes (see "Categories of Consumer Health Data We Share" below for how the service providers we use handle your data).

How We Process Consumer Health Data

Consumer health data is stored on our cloud infrastructure (Google Firebase; stored in Japan), encrypted in transit, and processed automatically to provide the features described above — storing and displaying your records, generating AI responses, maintaining AI memory if you have enabled it, relating your records to the weather in your area, generating Insights (patterns found in your records by an automated nightly process), and generating a summary's events, summary-specific Insights, and suggested talking points for your doctor (performed when you create a summary and when you answer additional questions on its screen). Access on our side is limited to the operator and only for the purposes described in this policy. When AI memory is enabled, this includes using descriptions of usual patterns and what you have told us matters to you to personalize chat responses and the events selected for summaries. We do not process consumer health data for any purpose other than those described in this policy.

Categories of Sources

When AI memory is enabled, we also derive descriptions of usual patterns from the records you provide. We distinguish these observations and their evidence periods from information you tell us about what matters to you. Recent correction and deletion history helps later generation take your changes into account; it is used and retained as described in Section 7 of the Privacy Policy. Turning AI memory off stops new automatic storage and use in both chat and summaries, while saved entries remain available for you to review, edit, and delete.

The source records for these features come from you: the information you enter or dictate in the app (records, AI chat messages, feedback). Weather information is retrieved for your approximate area (see above) from a public weather API (Open-Meteo), which receives only coordinates rounded to a coarse area and no information that identifies you. We store the weather code and daily minimum pressure for each day linked to your account, and include roughly the last 7 days of it (AI chat), about 90 days of it (Insights), or the selected period of it (Summary) in the data sent to OpenAI as described below.

Categories of Consumer Health Data We Share, and With Whom

We do not sell consumer health data, and we do not share it for advertising or marketing. We share (transmit) consumer health data only with the service providers below, as necessary to provide the Service:

Category of data shared Category of recipient Recipient
Health condition records, AI conversations, AI memory Cloud infrastructure provider (storage and server processing) Google LLC (Firebase)
Your AI chat input, the records and AI memory the AI references, and the weather and air pressure of roughly the last 7 days; the immediately preceding exchange used for the safety check on the AI's response; for the Insights feature, a daily summary of roughly the last 90 days of your records (pain level, sleep hours, and whether activity, medication, or menstruation was recorded) with the weather and air pressure for the days in that period on which weather was retrieved, sent automatically on a schedule without any action on your part; and, when you create a summary with the Summary feature or answer additional questions on its screen, the daily numerical records in the chosen period (pain level, sleep hours, and whether activity, medication, or menstruation was recorded) with the weather and air pressure, the worded parts of your records (note text, medication names, activity descriptions, and pain locations and types), the period's statistics, anything you entered as something to check at your appointment, the context, questions, and options for additional questions (including unanswered questions), and your additional-question answers; context, questions, and options may be sent again for translation, while questions and answers may be sent again for follow-up questions and final generation, and unanswered question text is used to avoid repetition AI analysis service provider (chat generation, response safety check, insight generation, and summary generation) OpenAI, L.L.C. — by default, data sent via its API is not used to train AI models and is deleted after a limited retention period
The text of your in-app feedback (for automatic categorization) AI analysis service provider (feedback categorization) Anthropic, PBC — by default, data sent via its API is not used to train AI models and is deleted after a limited retention period
Voice audio when you use voice input Operating-system speech-recognition service Apple Inc. (iOS) / Google (Android)
In-app feedback (text, category, submission date, and the like, together with your user ID; deleted from the analytics store when you delete your account) Cloud analytics provider Google LLC (BigQuery)

When AI memory is enabled, Google Firebase also stores correction and deletion history. Chat and summary generation send saved memories, their evidence periods, and recent correction and deletion history to OpenAI. An automated nightly process, and summary creation when comparison material is missing, send the worded parts of roughly the preceding 90 days of records, saved memories, and recent correction and deletion history to OpenAI to describe usual patterns. Candidate text and its source context are sent for safety checks. Record-derived memories that pass the safety check are saved automatically without individual approval. AI action permission settings apply to actions within chat. Turning AI memory off stops new automatic storage and use in both chat and summaries.

The cloud and AI providers above (Google LLC, OpenAI, L.L.C., Anthropic, PBC) handle this data to provide their services to us, under their service terms and data-processing conditions. The speech-recognition services are different in kind: they are features of your device's operating system, and when you use voice input, audio is sent by the OS to its vendor and handled under that vendor's own privacy policy (see "Notes on voice input" in the Privacy Policy). If you do not want this, you can type instead of using voice input.

We do not permit any third party to collect your consumer health data through the Service for advertising or marketing purposes. No third party collects consumer health data about you over time and across different websites or online services through your use of the Service.

Diagnostic and usage analytics (Firebase Crashlytics / Analytics) and subscription purchase management (RevenueCat, Inc.) do not receive your health condition records or conversations. Diagnostic and usage analytics run only with your separate, optional opt-in consent, which you can change or withdraw at any time from the app's settings screen.

If a court or other public authority makes a legally binding demand, we disclose data only to the extent of our legal obligations, as described in the Privacy Policy.

How We Obtain Your Consent

When you sign up — before any consumer health data is collected — we ask for your affirmative, opt-in consent through separate checkboxes: one for the collection and storage of your health information, and one for the transmission to the U.S.-based providers described above. These are independent of your acceptance of the Terms of Service (consent is not bundled into the terms). We do not collect consumer health data before you have consented. If we materially change what we collect or share, we ask for your renewed consent before the change applies to you.

Your Rights

Under applicable state law (including the Washington My Health My Data Act), you have the right to:

How to exercise your rights

We respond to requests without delay and within the timeframes required by applicable law (for Washington residents, within 45 days, extendable once by 45 days where reasonably necessary). No fee is charged.

Appeals

If we decline to act on your request, we will explain why. You may appeal our decision by replying to our response or contacting support.seren@gmail.com with the subject line "Appeal." If your appeal is unsuccessful, you may contact the Attorney General of your state (for Washington residents: www.atg.wa.gov).

Changes to This Policy

We may revise this policy as necessary. For material changes, we will announce the change on the Service and, where required, ask for your renewed consent.

Contact