Consumer Health Data Privacy
Last updated: August 22, 2026
What this covers
LevelHeadedApp is a self-guided emotional regulation and reflection tool. Some of what you choose to enter — mood, stress levels, emotional reactions, reflections and similar entries — may be considered “consumer health data” under certain state laws (for example Washington's My Health My Data Act) and may be treated as health-related information by the FTC. This page explains, in one place, how that data is handled.
LevelHeadedApp is not therapy, medical care, psychiatric treatment, diagnosis, or an emergency or crisis-monitoring service, and it is not a HIPAA covered entity. Nothing here is legal or medical advice.
What we collect
- Daily check-ins you submit (mood, stress, urge levels, and notes you choose to write).
- Entries in the Vent Room, Emotion Translator, Rewrite My Text, Trigger Tracker and reflections.
- Crash-Out Quiz answers you submit (only after confirming you are 18 or over).
- Account details (email, display name) and subscription status.
What we do with it
- Provide the tools: analysis, rewrites, streaks and history inside your own account.
- Operate safety routing: certain content may receive a safety-oriented response or resources.
- Run the subscription, prevent abuse, and meet legal obligations.
What we never do
- We do not sell your personal or health-related data.
- We do not share it for advertising or cross-context behavioral advertising.
- We do not use your private entries for marketing.
- We do not send your name, email, account ID, card or billing data to AI providers — AI requests contain only the text of your current request.
- We do not claim end-to-end encryption, HIPAA compliance, or “clinical-grade” security. Data is encrypted in transit and at rest; no online service can promise that no one could ever access it.
AI processing and minimization
When you use an AI feature, only the text of that specific request is sent to the AI provider, through a payload-minimization layer that strips identity and billing fields. A metadata-only log records which categories of data were sent — never the raw emotional content.
Processors
We use a small number of service providers to run the app: cloud hosting and database (our backend platform), payment processing (Stripe — card details go to Stripe, never to us), email delivery, and an AI gateway for the AI features. Each receives only what it needs to provide its service.
Retention
- Your content (check-ins, vents, rewrites, triggers): kept while your account exists; deleted when you delete your account.
- AI request payloads: not stored by the safety router; transient for the request.
- Security logs: up to 12 months.
- Consent records: life of the account plus up to 6 years (legal proof of consent).
- Billing records: up to 7 years (tax and financial obligations).
- Encrypted backups: rotate out within about 30 days.
Your rights and how to exercise them
Depending on where you live, you may have the right to access, correct, export, or delete your consumer health data, and to withdraw consent to its collection or use.
- Export: Settings → Export my data (JSON or CSV), any time.
- Delete: Settings → Delete account. Active-system deletion completes within 30 days; encrypted backups rotate out within about 30 more. Financial and legal-hold records are retained only as the law requires.
- Access, correction, consent withdrawal or questions: email privacy@levelheadedapp.com. We respond within 30 days.
Withdrawing consent or deleting your data is free and does not require a reason.
Crisis positioning
LevelHeadedApp is not an emergency or crisis-monitoring service. Automated safety systems may provide safety-oriented responses or resources when certain content is detected, but no one is monitoring your entries. If you are in crisis, use the resources on our crisis page or contact emergency services.
Contact
Privacy: privacy@levelheadedapp.com
Support: support@levelheadedapp.com
See also: Privacy Policy, Security & Privacy Center, Terms.