DeepSensi™ Cognitive EngineBuilt for licensed physicians.Request access

LEGAL // CONSUMER HEALTH DATA

DeepSensi Consumer Health Data Privacy Policy

Version 2.1, dated 27 September 2026 and effective 28 September 2026, replaces every earlier version of this policy.

This policy applies to consumers in the United States and is published under its own title, linked from our home page. It adds to our Privacy Policy: the two say the same thing where both apply, this policy governs where it is stricter, and a Privacy Policy section cited here applies to your consumer health data. Our forms are closed in the territories listed in section 2 of our Privacy Policy.

Consumer health data means personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status, including information that can be used to infer that status. Where your state's law defines it more broadly, we apply the broader definition.

1. Who we are

DeepSensi Public Benefit Corporation, incorporated in the State of Delaware on 23 March 2026 under file number 10560161, collects the data. Requests and appeals go to [email protected] or to [email protected], our second monitored address; every period in this policy runs against both, and both are answered by our sole director, Tomasz Jan Gomoła, the person in charge of the protection of personal information. Security reports go to [email protected]. As at 27 September 2026 no entity under common control with us receives consumer health data from us, processes it for us or decides anything about it with us; before one does, we update this policy, name it and say what it receives.

2. What we collect, and from where

Category Source Required
Clinical documentation for an analysis, which may include diagnoses, medications, laboratory and imaging reports, clinical notes and the dates of those events you, or the parent or legal guardian of the person concerned, through the application yes, to run an order
Genetic and genomic content in a report you submit you no; processed only on the separate consent in section 7
The area of care or Precision Suite you select you, in the form optional
Health information you describe in a message you, by contact form or email no; our contact form offers no topic inviting it, and we ask you not to send documents or results this way
Name and practice of the physician you name, and the fact of delivery you, when you order yes, to deliver the analysis
Record of your consents and authorizations generated by us yes

The application accepts only report text and its values, not medical images, raw analyzer or sequencer files, medical device exports or wearable data, and its software enforces that limit. We do not buy consumer health data, obtain it from data brokers or collect it about you from public or commercial sources. At the date of this version we accept no clinical documentation. Our Privacy Policy states which forms and fields do not yet accept submissions (section 2), the condition before any clinical documentation is accepted (section 4) and how the Elite tiers are handled (section 1); for Elite Human Performance we act on the instructions of the purchasing organization and receive health and performance records only under an identifier it assigns, with direct identifiers removed on the purchaser's device (Zero-PHI).

3. Why we collect it

Purpose What it covers
Preparing the analysis you ordered reading your documentation against the medical literature and preparing an analysis for the physician you name
Delivering it verifying the physician's license, making the dossier and analysis available to that physician, and recording receipt
Running your order asking for payment under section 7 of our Privacy Policy, answering you and keeping records tax law requires
Telling you when a service is available where you live using your email address and country, and the area of care or Suite once that field opens and you give one
Security detecting and stopping abuse, and recording access to our systems
Showing compliance keeping the consent wording you were shown and the record of your requests

We never use consumer health data for advertising of any kind or to target you, never sell it, and never use it to train a general purpose model. We run no geofence around any hospital, clinic, pharmacy, laboratory, counseling center or other facility providing health services, and we do not use location to infer anything about your health.

4. Zero-PHI

Zero-PHI is DeepSensi's Patent Pending architecture: direct identifiers are removed on your own device, in your browser or in the My DeepSensi application, before anything reaches us, and the key that maps them back to you stays there; we never receive it. On our side a case is connected to your order only by an order number, held in our order records apart from the clinical content, and a result from a laboratory or hospital node is coded there before it reaches us. Section 4 of our Privacy Policy lists the identifiers removed and the safeguards that apply, and we call the data coded, not de-identified or anonymous.

5. Who may send us records

Section 5 of our Privacy Policy states who may send us records, including the rule for children. If you send us clinical information about another adult, you confirm that you are that person's legal representative or have their authorization. Clinical information about a third person sent without our asking is not used and is deleted within seven days, mailbox copies included.

6. Who receives it

Category of recipient Specific recipient What they receive
Hosting and database provider Cloudflare, Inc., a corporation registered in the State of Delaware, United States hosting, the databases behind our forms, and coded cases and analyses; clinical content in coded form only
Transactional email provider Plus Five Five, Inc., the company that operates the Resend service, United States the messages we send you and their addresses, with no clinical content
Mailbox provider MyDevil.net, a hosting service operated by a company registered in Poland, acting under a written processing instrument, on its servers in Poland the correspondence you send us and our replies; we ask you not to describe a health situation there
Payment provider Stripe, Inc., a corporation registered in the State of Delaware, United States once checkout opens, the payment details you enter with it and the order and payment records, with no clinical content
The physician you name the physician identified in your order your dossier and the analysis, only with your separate written authorization under section 7
Professional advisers our legal and accounting advisers in the United States and the European Union only what a specific matter requires
Public authorities and courts as applicable only what the law requires, in the case at hand
Companies under common control with us none, as section 1 states nothing

We name each provider and its country of registration. Each provider processes consumer health data on our instructions, holds it no longer than we instruct and receives no key that would restore the identifiers, and a disclosure to such a provider is not sharing within the meaning of the Washington My Health My Data Act. Sections 8 and 13 of our Privacy Policy cover subprocessors, contractual safeguards and what our emails may contain, and its section 7 the physician's independent role and our position under the Health Insurance Portability and Accountability Act.

7. Consent

We ask for your consent to collect consumer health data and, separately, for your consent to disclose it, in a second request you can refuse while keeping the service. The two are never joined in one tick box, and neither is a condition of using the service for anything it is not needed for.

Act What we ask for
Collection your consent before collection, in wording naming what we collect and why, recorded with its version identifier and the time
Recording the area of care or Suite explicit consent by a separate tick box on submission, as section 5A of our Privacy Policy describes
Genetic or genomic content in a report a separate consent naming that content and the purpose. If you refuse, we run the order on the rest of the documentation. If you withdraw, we remove that content from your coded case within seven days, tell you when it is done and never use it again, though an analysis already delivered stays in your physician's records, beyond our reach
Disclosure to the physician you name your separate written authorization naming that physician, the data, the purpose and an expiry date, signed and dated by you in the form section 11 describes; without it, wherever you live in the United States, we disclose nothing
Disclosure to anyone else none; we disclose only what the law compels us to give a court or an authority
Sale would require your signed authorization, which we do not seek; we have never sold consumer health data and do not intend to
Coded data in work for a commercial organization a further authorization, as section 10 of our Privacy Policy describes; refusing it changes nothing about your order, and nothing is processed on the wording of an earlier version

We never sell, disclose or use genetic or genomic content for advertising, underwriting, employment or research, or pass it to an insurer, employer or data broker; it serves only the analysis you ordered. You may withdraw a consent or revoke an authorization at any time at either address in section 1 or through the link in any message we send. We stop the processing it covered without delay and at the latest the same day, without affecting earlier lawful processing, and withdrawing a consent an order depends on ends the order.

8. How long we keep it

Section 5B of our Privacy Policy sets the retention periods, and where two could apply the earlier governs. A coded case and its analysis are kept 12 months after delivery, genetic or genomic content is removed within 7 days of your withdrawing its consent, and consumer health data you ask us to delete is deleted within 30 days.

9. Your rights

You may ask us to confirm whether we collect, share or sell your consumer health data, to list everyone we have disclosed it to with an active contact for each, to give you a copy of it, to withdraw a consent or revoke an authorization, and to delete it. Write to either address in section 1; requests are free and never held against you.

Request Our deadline
Any request under this policy 30 days, extendable once by 45 days where the law allows, with notice and reasons within the first 30 days
Deleting consumer health data 30 days, never extended, covering live systems, archives and the copies our providers hold for restoration
Deleting an interest registration or reservation, requested by email 7 days

Deadlines run from the day your request arrives at either address. Every restoration is filtered through a list of deleted records, so a deletion is not undone; section 11 of our Privacy Policy states what a deletion covers and the one record that survives it. If we refuse, we tell you why, and you may appeal to either address with the word appeal in the subject line; we answer within thirty days, and if we refuse again you may complain to the attorney general of your state. Residents of Washington may also bring a claim under the state Consumer Protection Act, and we do not ask you to waive it. Security, the review due on 31 March 2027 and breach notification, including under the Health Breach Notification Rule of the Federal Trade Commission, are in section 9 of our Privacy Policy.

10. Where it is stored

Sections 8 and 13 of our Privacy Policy state where data are held and how transfers are safeguarded. Consumer health data sits with our hosting provider in its European Union region, apart from our order records.

11. State specific provisions

State What applies in addition
Washington this policy is our notice under the My Health My Data Act. Collection requires your consent, disclosure your separate signed authorization, and a sale your signed authorization, which we do not seek
Nevada we do not sell consumer health data and would not without your written authorization, and we do not use it for targeted advertising
Connecticut consumer health data is sensitive data, processed only with your consent, and we have assessed this processing, relying where the law permits on an assessment prepared for another law that covers it
California consumer health data is sensitive personal information: you may limit our use of it, ask what we hold, and ask for a copy, correction or deletion, and we neither sell it nor share it for cross-context behavioral advertising. Genetic information is processed only on the separate consent in section 7. Under Civil Code section 56.06(b) we treat the Confidentiality of Medical Information Act as applying to us, so an authorization we ask you to sign meets every requirement of Civil Code section 56.11: handwritten by you or in at least fourteen point type, clearly separate from other language, signed and dated by you, and stating the uses and limitations of the medical information disclosed and of the recipient's use, the discloser and the recipient, an expiry date and your right to a copy. Section 56.36 gives you a right of action for a violation of that Act, and we do not ask you to waive it
Maryland and every other state we treat consumer health data as sensitive data requiring your consent wherever you live, and section 13D of our Privacy Policy applies

12. Changes

We change this policy when the facts change, publish each version on this page with its date and a summary of what changed, and provide superseded text on request. Compared with the version published before 28 September 2026, this version deletes consumer health data within 30 days across live systems, archives and restoration copies, calls case data coded rather than de-identified, requires your written authorization before any disclosure to your physician, adds a separate consent for genetic content and keeps fields that can carry health information closed until tested. Section 14 of our Privacy Policy, on a change of provider, a late review and a takeover, applies here too.

13. Contact

Our registered address is DeepSensi Public Benefit Corporation, 8 The Green STE A, Dover, DE 19901, United States. This policy is published in English, which is binding; where local law requires a notice in another language, we publish it before offering a service there.