Version 2.1, dated 27 September 2026 and effective 28 September 2026, replaces every earlier version of this policy.
This policy applies to consumers in the United States and is published under its own title, linked from our home page. It adds to our Privacy Policy: the two say the same thing where both apply, this policy governs where it is stricter, and a Privacy Policy section cited here applies to your consumer health data. Our forms are closed in the territories listed in section 2 of our Privacy Policy.
Consumer health data means personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status, including information that can be used to infer that status. Where your state's law defines it more broadly, we apply the broader definition.
1. Who we are
DeepSensi Public Benefit Corporation, incorporated in the State of Delaware on 23 March 2026 under file number 10560161, collects the data. Requests and appeals go to [email protected] or to [email protected], our second monitored address; every period in this policy runs against both, and both are answered by our sole director, Tomasz Jan Gomoła, the person in charge of the protection of personal information. Security reports go to [email protected]. As at 27 September 2026 no entity under common control with us receives consumer health data from us, processes it for us or decides anything about it with us; before one does, we update this policy, name it and say what it receives.
2. What we collect, and from where
| Category | Source | Required |
|---|---|---|
| Clinical documentation for an analysis, which may include diagnoses, medications, laboratory and imaging reports, clinical notes and the dates of those events | you, or the parent or legal guardian of the person concerned, through the application | yes, to run an order |
| Genetic and genomic content in a report you submit | you | no; processed only on the separate consent in section 7 |
| The area of care or Precision Suite you select | you, in the form | optional |
| Health information you describe in a message | you, by contact form or email | no; our contact form offers no topic inviting it, and we ask you not to send documents or results this way |
| Name and practice of the physician you name, and the fact of delivery | you, when you order | yes, to deliver the analysis |
| Record of your consents and authorizations | generated by us | yes |
The application accepts only report text and its values, not medical images, raw analyzer or sequencer files, medical device exports or wearable data, and its software enforces that limit. We do not buy consumer health data, obtain it from data brokers or collect it about you from public or commercial sources. At the date of this version we accept no clinical documentation. Our Privacy Policy states which forms and fields do not yet accept submissions (section 2), the condition before any clinical documentation is accepted (section 4) and how the Elite tiers are handled (section 1); for Elite Human Performance we act on the instructions of the purchasing organization and receive health and performance records only under an identifier it assigns, with direct identifiers removed on the purchaser's device (Zero-PHI).
3. Why we collect it
| Purpose | What it covers |
|---|---|
| Preparing the analysis you ordered | reading your documentation against the medical literature and preparing an analysis for the physician you name |
| Delivering it | verifying the physician's license, making the dossier and analysis available to that physician, and recording receipt |
| Running your order | asking for payment under section 7 of our Privacy Policy, answering you and keeping records tax law requires |
| Telling you when a service is available where you live | using your email address and country, and the area of care or Suite once that field opens and you give one |
| Security | detecting and stopping abuse, and recording access to our systems |
| Showing compliance | keeping the consent wording you were shown and the record of your requests |
We never use consumer health data for advertising of any kind or to target you, never sell it, and never use it to train a general purpose model. We run no geofence around any hospital, clinic, pharmacy, laboratory, counseling center or other facility providing health services, and we do not use location to infer anything about your health.
4. Zero-PHI
Zero-PHI is DeepSensi's Patent Pending architecture: direct identifiers are removed on your own device, in your browser or in the My DeepSensi application, before anything reaches us, and the key that maps them back to you stays there; we never receive it. On our side a case is connected to your order only by an order number, held in our order records apart from the clinical content, and a result from a laboratory or hospital node is coded there before it reaches us. Section 4 of our Privacy Policy lists the identifiers removed and the safeguards that apply, and we call the data coded, not de-identified or anonymous.
5. Who may send us records
Section 5 of our Privacy Policy states who may send us records, including the rule for children. If you send us clinical information about another adult, you confirm that you are that person's legal representative or have their authorization. Clinical information about a third person sent without our asking is not used and is deleted within seven days, mailbox copies included.
6. Who receives it
| Category of recipient | Specific recipient | What they receive |
|---|---|---|
| Hosting and database provider | Cloudflare, Inc., a corporation registered in the State of Delaware, United States | hosting, the databases behind our forms, and coded cases and analyses; clinical content in coded form only |
| Transactional email provider | Plus Five Five, Inc., the company that operates the Resend service, United States | the messages we send you and their addresses, with no clinical content |
| Mailbox provider | MyDevil.net, a hosting service operated by a company registered in Poland, acting under a written processing instrument, on its servers in Poland | the correspondence you send us and our replies; we ask you not to describe a health situation there |
| Payment provider | Stripe, Inc., a corporation registered in the State of Delaware, United States | once checkout opens, the payment details you enter with it and the order and payment records, with no clinical content |
| The physician you name | the physician identified in your order | your dossier and the analysis, only with your separate written authorization under section 7 |
| Professional advisers | our legal and accounting advisers in the United States and the European Union | only what a specific matter requires |
| Public authorities and courts | as applicable | only what the law requires, in the case at hand |
| Companies under common control with us | none, as section 1 states | nothing |
We name each provider and its country of registration. Each provider processes consumer health data on our instructions, holds it no longer than we instruct and receives no key that would restore the identifiers, and a disclosure to such a provider is not sharing within the meaning of the Washington My Health My Data Act. Sections 8 and 13 of our Privacy Policy cover subprocessors, contractual safeguards and what our emails may contain, and its section 7 the physician's independent role and our position under the Health Insurance Portability and Accountability Act.
7. Consent
We ask for your consent to collect consumer health data and, separately, for your consent to disclose it, in a second request you can refuse while keeping the service. The two are never joined in one tick box, and neither is a condition of using the service for anything it is not needed for.
| Act | What we ask for |
|---|---|
| Collection | your consent before collection, in wording naming what we collect and why, recorded with its version identifier and the time |
| Recording the area of care or Suite | explicit consent by a separate tick box on submission, as section 5A of our Privacy Policy describes |
| Genetic or genomic content in a report | a separate consent naming that content and the purpose. If you refuse, we run the order on the rest of the documentation. If you withdraw, we remove that content from your coded case within seven days, tell you when it is done and never use it again, though an analysis already delivered stays in your physician's records, beyond our reach |
| Disclosure to the physician you name | your separate written authorization naming that physician, the data, the purpose and an expiry date, signed and dated by you in the form section 11 describes; without it, wherever you live in the United States, we disclose nothing |
| Disclosure to anyone else | none; we disclose only what the law compels us to give a court or an authority |
| Sale | would require your signed authorization, which we do not seek; we have never sold consumer health data and do not intend to |
| Coded data in work for a commercial organization | a further authorization, as section 10 of our Privacy Policy describes; refusing it changes nothing about your order, and nothing is processed on the wording of an earlier version |
We never sell, disclose or use genetic or genomic content for advertising, underwriting, employment or research, or pass it to an insurer, employer or data broker; it serves only the analysis you ordered. You may withdraw a consent or revoke an authorization at any time at either address in section 1 or through the link in any message we send. We stop the processing it covered without delay and at the latest the same day, without affecting earlier lawful processing, and withdrawing a consent an order depends on ends the order.
8. How long we keep it
Section 5B of our Privacy Policy sets the retention periods, and where two could apply the earlier governs. A coded case and its analysis are kept 12 months after delivery, genetic or genomic content is removed within 7 days of your withdrawing its consent, and consumer health data you ask us to delete is deleted within 30 days.
9. Your rights
You may ask us to confirm whether we collect, share or sell your consumer health data, to list everyone we have disclosed it to with an active contact for each, to give you a copy of it, to withdraw a consent or revoke an authorization, and to delete it. Write to either address in section 1; requests are free and never held against you.
| Request | Our deadline |
|---|---|
| Any request under this policy | 30 days, extendable once by 45 days where the law allows, with notice and reasons within the first 30 days |
| Deleting consumer health data | 30 days, never extended, covering live systems, archives and the copies our providers hold for restoration |
| Deleting an interest registration or reservation, requested by email | 7 days |
Deadlines run from the day your request arrives at either address. Every restoration is filtered through a list of deleted records, so a deletion is not undone; section 11 of our Privacy Policy states what a deletion covers and the one record that survives it. If we refuse, we tell you why, and you may appeal to either address with the word appeal in the subject line; we answer within thirty days, and if we refuse again you may complain to the attorney general of your state. Residents of Washington may also bring a claim under the state Consumer Protection Act, and we do not ask you to waive it. Security, the review due on 31 March 2027 and breach notification, including under the Health Breach Notification Rule of the Federal Trade Commission, are in section 9 of our Privacy Policy.
10. Where it is stored
Sections 8 and 13 of our Privacy Policy state where data are held and how transfers are safeguarded. Consumer health data sits with our hosting provider in its European Union region, apart from our order records.
11. State specific provisions
| State | What applies in addition |
|---|---|
| Washington | this policy is our notice under the My Health My Data Act. Collection requires your consent, disclosure your separate signed authorization, and a sale your signed authorization, which we do not seek |
| Nevada | we do not sell consumer health data and would not without your written authorization, and we do not use it for targeted advertising |
| Connecticut | consumer health data is sensitive data, processed only with your consent, and we have assessed this processing, relying where the law permits on an assessment prepared for another law that covers it |
| California | consumer health data is sensitive personal information: you may limit our use of it, ask what we hold, and ask for a copy, correction or deletion, and we neither sell it nor share it for cross-context behavioral advertising. Genetic information is processed only on the separate consent in section 7. Under Civil Code section 56.06(b) we treat the Confidentiality of Medical Information Act as applying to us, so an authorization we ask you to sign meets every requirement of Civil Code section 56.11: handwritten by you or in at least fourteen point type, clearly separate from other language, signed and dated by you, and stating the uses and limitations of the medical information disclosed and of the recipient's use, the discloser and the recipient, an expiry date and your right to a copy. Section 56.36 gives you a right of action for a violation of that Act, and we do not ask you to waive it |
| Maryland and every other state | we treat consumer health data as sensitive data requiring your consent wherever you live, and section 13D of our Privacy Policy applies |
12. Changes
We change this policy when the facts change, publish each version on this page with its date and a summary of what changed, and provide superseded text on request. Compared with the version published before 28 September 2026, this version deletes consumer health data within 30 days across live systems, archives and restoration copies, calls case data coded rather than de-identified, requires your written authorization before any disclosure to your physician, adds a separate consent for genetic content and keeps fields that can carry health information closed until tested. Section 14 of our Privacy Policy, on a change of provider, a late review and a takeover, applies here too.
13. Contact
Our registered address is DeepSensi Public Benefit Corporation, 8 The Green STE A, Dover, DE 19901, United States. This policy is published in English, which is binding; where local law requires a notice in another language, we publish it before offering a service there.