Skip to content

Washington Consumer Health Data Privacy Policy

Effective date: August 5, 2026

Version: 2

This separate Policy provides the disclosures required by the Washington My Health My Data Act for Washington consumers and consumer health data collected in Washington. Bornly's general Privacy Policy provides additional information about other personal data.

1. Regulated entity and contact

Bornly ApS

C/O Mikkel Ulstrup, Traneholmen 45, 3460 Birkerød, Denmark

privacy@bornly.com

2. Consumer health data we collect and why

Depending on the app and features you choose, Bornly may collect the following categories of consumer health data for the listed purposes:

CategoryCollection and use purposes
Food, nutrition, meal, ingredient, allergy or tolerance information; meal and product-label photos; weight, body measurements, and goalsProvide food and nutrition journals, calculations, history, search, product information, requested AI features, sync, export, support, and service security
Symptoms, bowel movements, mood, stress, notes, scores, summaries, patterns, and other gut or well-being recordsProvide Gutly journaling, charts, summaries, requested AI features, sync, export, support, and service security
Pregnancy, due date, cycle, fetal-movement, contraction, pain, labour, hospital, maternity-contact, and partner-status informationProvide pregnancy and contraction journals, timers, reminders, partner features, sync, export, support, and service security
Sleep, rested scores, experiments, routines, wearable or HealthKit records, caffeine intake, bedtime, estimates, and remindersProvide Night Lab and Perkly journals, comparisons, calculations, reports, HealthKit features, sync, export, support, and service security
Health-related prompts, conversations, feedback, survey responses, attachments, AI inputs and outputs, and historical records from earlier featuresProvide the requested feature, maintain history, conduct authorised research or product improvement, provide support, investigate quality or safety, and secure the Services
Account, device, request, usage, IP-address, time-zone, consent, and relationship identifiers linked or reasonably linkable to the categories aboveAssociate data with the correct account, app, device, consent, partner or group; operate and secure the Services; fulfil requests; and comply with law
Health-related inferences, scores, patterns, summaries, or classifications derived from the categories aboveProvide the requested display, calculation, AI feature, support, research, service improvement, or security function

We do not collect a new category of consumer health data, or use an existing category for a materially different purpose, without updating this Policy and obtaining consent where the Act requires it.

3. Sources

Bornly collects consumer health data:

  • directly from you when you enter, upload, photograph, import, connect, or discuss it;
  • from your device, app use, and requests;
  • from HealthKit or another source you authorise;
  • from a partner or group participant who uses a directed sharing feature; and
  • by deriving a requested score, estimate, pattern, summary, classification, or AI output from those sources.

4. Consumer health data we share and recipients

The categories shared can include the health and wellness records, images, prompts, output, technical identifiers, and relationship data described in Section 2. The recipient and purpose depend on the feature you request:

Recipient or categoryConsumer health data and sharing purpose
Render Services, Inc.; Cloudflare, Inc.Hosting, database/cache, object storage, network security, content delivery, requests, logs, backups, and delivery of uploaded or generated assets
OpenAI Ireland Ltd. and its published subprocessorsContent and context needed for a selected AI feature or an authorised internal AI workflow, including relevant text, images, health-related records, feedback, survey material, catalogue data, identifiers needed to secure the request, and generated output
Resend, Inc.Health-related content you include in a transactional or support email and the delivery metadata needed to send it
RevenueCat, Inc.; Apple Inc.; Stripe entity applicable to the transactionSubscription, entitlement, platform, payment, device, and account identifiers; health content only if you place it in an identifier, support exchange, or platform feature you direct
Slack Technologies, LLC; GitHub, Inc.Restricted support, product, engineering, incident, and operational handling when a report or authorised workflow contains consumer health data
Waastly content service; Imgix, Inc.IP/request/device metadata, app or page context, and requested health-content or static-asset identifiers used to deliver articles, definitions, and images
USDA FoodData Central; Open Food FactsA requested product barcode or food-reference identifier and Bornly server request metadata; Bornly does not intentionally include an account identifier or health-log payload
A partner, family member, or group participant you invite or directThe profile, pregnancy, labour, contraction, hospital, baby-name, vote, status, or group information shown by the sharing feature
Professional advisers, incident responders, authorities, or transaction partiesLimited consumer health data where reasonably necessary and legally permitted for advice, security, legal claims, compliance, financing, reorganisation, or a business transaction

Processors can use their own subprocessors to provide the contracted service. Bornly has no corporate affiliates receiving consumer health data as of the effective date.

Bornly does not sell consumer health data for monetary or other valuable consideration. If that changes, Bornly will first obtain the separate, signed authorisation required by law.

5. Consent and withdrawal

Where the Act requires consent, Bornly must obtain a separate affirmative choice before collecting consumer health data for the purposes shown to you. Sharing that is not necessary to provide a product or service you requested requires a separate consent. A consent request must describe the categories, purpose, and relevant recipients and remain separate from general acceptance of the Terms.

You may withdraw consent for future collection or sharing through an available in-app control or by emailing privacy@bornly.com. Withdrawal does not automatically delete data already collected; deletion can be requested separately.

6. Your Washington rights

Subject to the Act and reasonable verification, you may:

  • confirm whether Bornly collects, shares, or sells your consumer health data;
  • access that data, including a list of third parties and affiliates with whom it was shared where required;
  • withdraw consent for future collection or sharing;
  • request deletion from Bornly and notification to processors and other recipients to delete where required; and
  • appeal Bornly's refusal of a request.

Submit a request through an available in-app privacy control or email privacy@bornly.com with the subject "Washington Consumer Health Data Request." An authorised agent may submit a request with proof of authority. We may request information reasonably needed to verify identity and authority.

To appeal, reply to the decision or email the same address with the subject "Washington Privacy Appeal." We will respond within the period required by law and explain any further complaint route. You may also contact the Washington Attorney General. Bornly will not discriminate against you for exercising a right.

7. Changes

We will publish changes with a new effective date. Before collecting an additional category of consumer health data or using data for a materially different purpose not disclosed here, Bornly will update this Policy and obtain consent where required.