Washington Consumer Health Data Privacy Policy
Effective date: August 5, 2026
Version: 2
This separate Policy provides the disclosures required by the Washington My Health My Data Act for Washington consumers and consumer health data collected in Washington. Bornly's general Privacy Policy provides additional information about other personal data.
1. Regulated entity and contact
Bornly ApS
C/O Mikkel Ulstrup, Traneholmen 45, 3460 Birkerød, Denmark
2. Consumer health data we collect and why
Depending on the app and features you choose, Bornly may collect the following categories of consumer health data for the listed purposes:
| Category | Collection and use purposes |
|---|---|
| Food, nutrition, meal, ingredient, allergy or tolerance information; meal and product-label photos; weight, body measurements, and goals | Provide food and nutrition journals, calculations, history, search, product information, requested AI features, sync, export, support, and service security |
| Symptoms, bowel movements, mood, stress, notes, scores, summaries, patterns, and other gut or well-being records | Provide Gutly journaling, charts, summaries, requested AI features, sync, export, support, and service security |
| Pregnancy, due date, cycle, fetal-movement, contraction, pain, labour, hospital, maternity-contact, and partner-status information | Provide pregnancy and contraction journals, timers, reminders, partner features, sync, export, support, and service security |
| Sleep, rested scores, experiments, routines, wearable or HealthKit records, caffeine intake, bedtime, estimates, and reminders | Provide Night Lab and Perkly journals, comparisons, calculations, reports, HealthKit features, sync, export, support, and service security |
| Health-related prompts, conversations, feedback, survey responses, attachments, AI inputs and outputs, and historical records from earlier features | Provide the requested feature, maintain history, conduct authorised research or product improvement, provide support, investigate quality or safety, and secure the Services |
| Account, device, request, usage, IP-address, time-zone, consent, and relationship identifiers linked or reasonably linkable to the categories above | Associate data with the correct account, app, device, consent, partner or group; operate and secure the Services; fulfil requests; and comply with law |
| Health-related inferences, scores, patterns, summaries, or classifications derived from the categories above | Provide the requested display, calculation, AI feature, support, research, service improvement, or security function |
We do not collect a new category of consumer health data, or use an existing category for a materially different purpose, without updating this Policy and obtaining consent where the Act requires it.
3. Sources
Bornly collects consumer health data:
- directly from you when you enter, upload, photograph, import, connect, or discuss it;
- from your device, app use, and requests;
- from HealthKit or another source you authorise;
- from a partner or group participant who uses a directed sharing feature; and
- by deriving a requested score, estimate, pattern, summary, classification, or AI output from those sources.
4. Consumer health data we share and recipients
The categories shared can include the health and wellness records, images, prompts, output, technical identifiers, and relationship data described in Section 2. The recipient and purpose depend on the feature you request:
| Recipient or category | Consumer health data and sharing purpose |
|---|---|
| Render Services, Inc.; Cloudflare, Inc. | Hosting, database/cache, object storage, network security, content delivery, requests, logs, backups, and delivery of uploaded or generated assets |
| OpenAI Ireland Ltd. and its published subprocessors | Content and context needed for a selected AI feature or an authorised internal AI workflow, including relevant text, images, health-related records, feedback, survey material, catalogue data, identifiers needed to secure the request, and generated output |
| Resend, Inc. | Health-related content you include in a transactional or support email and the delivery metadata needed to send it |
| RevenueCat, Inc.; Apple Inc.; Stripe entity applicable to the transaction | Subscription, entitlement, platform, payment, device, and account identifiers; health content only if you place it in an identifier, support exchange, or platform feature you direct |
| Slack Technologies, LLC; GitHub, Inc. | Restricted support, product, engineering, incident, and operational handling when a report or authorised workflow contains consumer health data |
| Waastly content service; Imgix, Inc. | IP/request/device metadata, app or page context, and requested health-content or static-asset identifiers used to deliver articles, definitions, and images |
| USDA FoodData Central; Open Food Facts | A requested product barcode or food-reference identifier and Bornly server request metadata; Bornly does not intentionally include an account identifier or health-log payload |
| A partner, family member, or group participant you invite or direct | The profile, pregnancy, labour, contraction, hospital, baby-name, vote, status, or group information shown by the sharing feature |
| Professional advisers, incident responders, authorities, or transaction parties | Limited consumer health data where reasonably necessary and legally permitted for advice, security, legal claims, compliance, financing, reorganisation, or a business transaction |
Processors can use their own subprocessors to provide the contracted service. Bornly has no corporate affiliates receiving consumer health data as of the effective date.
Bornly does not sell consumer health data for monetary or other valuable consideration. If that changes, Bornly will first obtain the separate, signed authorisation required by law.
5. Consent and withdrawal
Where the Act requires consent, Bornly must obtain a separate affirmative choice before collecting consumer health data for the purposes shown to you. Sharing that is not necessary to provide a product or service you requested requires a separate consent. A consent request must describe the categories, purpose, and relevant recipients and remain separate from general acceptance of the Terms.
You may withdraw consent for future collection or sharing through an available in-app control or by emailing privacy@bornly.com. Withdrawal does not automatically delete data already collected; deletion can be requested separately.
6. Your Washington rights
Subject to the Act and reasonable verification, you may:
- confirm whether Bornly collects, shares, or sells your consumer health data;
- access that data, including a list of third parties and affiliates with whom it was shared where required;
- withdraw consent for future collection or sharing;
- request deletion from Bornly and notification to processors and other recipients to delete where required; and
- appeal Bornly's refusal of a request.
Submit a request through an available in-app privacy control or email privacy@bornly.com with the subject "Washington Consumer Health Data Request." An authorised agent may submit a request with proof of authority. We may request information reasonably needed to verify identity and authority.
To appeal, reply to the decision or email the same address with the subject "Washington Privacy Appeal." We will respond within the period required by law and explain any further complaint route. You may also contact the Washington Attorney General. Bornly will not discriminate against you for exercising a right.
7. Changes
We will publish changes with a new effective date. Before collecting an additional category of consumer health data or using data for a materially different purpose not disclosed here, Bornly will update this Policy and obtain consent where required.