← Back to home

Consumer Health Data Privacy Policy

For people in the United States. Last updated: October 4, 2026. This page is in English only; our general Privacy Policy is available in German and English.

In short: We collect only the health information you enter, import or switch on, to show it to you and to prepare your doctor’s report. We do not sell it, we do not share it with anyone else, we do not use it for advertising, and we use no tracking technologies, location data or geofences. You can access, withdraw consent for and delete your data at any time.

1. About this policy

Emivita (operated by Florian Hubert, Biburg-Durnhart, Germany) lets adults record and view their own health information, for example thyroid lab values, symptoms and medication. This policy explains how we handle consumer health data of consumers in the United States, in particular under the Washington My Health My Data Act (RCW 19.373), Nevada Senate Bill 370 and the Connecticut Data Privacy Act. It supplements our Privacy Policy, which also covers the EU General Data Protection Regulation (GDPR); because we are established in the EU, the GDPR applies to all users, wherever they live. Emivita is intended for people aged 18 and over.

2. What consumer health data we collect and why

If you allow it, the iPhone app also reads heart, breathing, sleep and activity values and workouts from Apple Health, to show them to you. These stay on your device; we neither receive nor store them. The one exception is body weight, if you switch on the weight sync.

We use consumer health data only to provide the features you request, to keep the service secure and to meet legal obligations. We do not use it for advertising. We will not collect other categories of consumer health data or use it for other purposes without telling you first and asking for your consent.

3. Where the data comes from

From you (what you type, tap, import or switch on); from Apple Health, only if you switch the sync on and allow it in iOS; and from the lab report files you choose to import. Sign-in with Apple or Google gives us your email address and, from Apple, your name the first time; neither provider sends us health data.

4. Who processes your data; no sale, no sharing

We do not sell consumer health data, and we do not share it with third parties or affiliates (we have no affiliates). We use the following service providers, who process data only on our behalf and under written data processing terms:

We disclose consumer health data to no one else, except where the law requires it. If this ever changes, we will update this policy and ask for your separate consent before any sharing.

5. Consent

When you create an account, in the app and on our website, we ask for your consent with a required checkbox that names the kind of data, the purposes, the recipients and how to withdraw. Importing from other sources (lab report import, Apple Health, Apple Watch) is something you switch on or trigger yourself. Because we do not share consumer health data, there is no separate sharing consent; if we ever planned to share it, we would ask for one, separate from this consent.

6. Your rights and how to use them

You can:

How: in the app under Account (delete account and all data, export), on the website in your profile, or by email to kontakt@emivita.de. You do not need an account to send a request; we may ask you to confirm it from the email address of your account. We respond within 45 days; if necessary, we may extend this once by another 45 days and will tell you why. You can make up to two requests a year free of charge. We do not treat you differently for using your rights.

Appeal: if we refuse or only partly grant a request, you can appeal by writing to kontakt@emivita.de with the subject “Appeal”. We will answer in writing within 45 days of receiving your appeal and explain our decision. If we deny the appeal, you can contact the Washington Attorney General at atg.wa.gov/file-complaint, the Connecticut Attorney General at portal.ct.gov/ag, or the attorney general of your state.

7. What we do not do

8. Security and breaches

Each account’s data is kept in its own database on encrypted storage in Germany; connections are encrypted; backups are encrypted; access is limited to the operator and to service providers who need it. If a breach of security affects unsecured health information we hold, we will notify you and, as the law requires, the U.S. Federal Trade Commission, the media and state authorities, without unreasonable delay and within 60 days of discovery (FTC Health Breach Notification Rule, 16 CFR Part 318, and state laws).

9. Where your data is processed

Account data is stored and processed in Germany. If you use Emivita from the United States, your data is therefore transferred to Germany, where the GDPR applies. If you import a lab report, the file also goes to Anthropic in the United States, as described above.

10. Changes and contact

If we change this policy, we post the new version here and, for material changes, inform registered users by email. The date of the last update is shown at the top.

Florian Hubert
Ortsstrasse 27a
93354 Biburg-Durnhart, Germany
Email: kontakt@emivita.de