Consumer Health Data Privacy Policy
Effective 24 August 2026.
This policy is required by the Washington My Health My Data Act (RCW 19.373). It exists because a small part of what BlinkWrite reads from your screen can, in some cases, be consumer health data under that law — information that identifies your own physical or mental health status. This policy tells you, specifically, what happens to that category of information. It supplements, and does not replace, our Privacy Policy, which covers everything BlinkWrite does with your data in full.
If you are not a Washington resident, most of this document still describes our practices accurately, but the specific rights in Section 6 are the rights Washington law gives you. See our Privacy Policy §12 for the rights that apply where you live.
1. What counts as consumer health data here
BlinkWrite does not ask what you're writing about, does not classify it, and does not tag it. It reads the text in the window you're working in and masks identifiers before anything leaves your Mac, exactly as described in our Privacy Policy §2.
Occasionally, that text includes a statement about your own health — for example, a sentence like "I'm out sick with the flu" in a draft email. When it does, and when it can still be linked to your account after masking, it is consumer health data for the purposes of this policy and Washington law. Most of what BlinkWrite reads is not this, and this policy does not apply to the rest of it — that's covered by our regular Privacy Policy.
2. Categories of consumer health data we collect, and why
| Category | Example | Why we collect it |
|---|---|---|
| Statements about your own physical or mental health status, appearing incidentally in text you're writing | "I'm dealing with a migraine today," "I've been diagnosed with X," "out sick," a reference to a therapy appointment | Solely to generate the writing suggestion you asked for in that moment |
We do not seek this category out, do not detect it, and do not treat it any differently from any other text on your screen. It reaches us only because it was present in a window you were actively working in when you asked for a suggestion, in the same way any other sentence would.
We do not infer, derive, or guess at your health status from anything you write. There is no classifier, health-topic tagger, or model in BlinkWrite that does this — see our Privacy Policy §2.6 and the engineering findings referenced in Section 9.
3. Where this data comes from
The only source is you — specifically, the text visible in the application window you are actively using BlinkWrite in, read through the macOS Accessibility interface or, where that isn't available, extracted on your Mac from a screen capture under macOS Screen Recording. We do not obtain consumer health data from any other source: not from data brokers, not from partners, not from public records.
Full detail on how this reading works is in our Privacy Policy §2.1–2.4.
4. Categories of consumer health data we share, and with whom
We do not share consumer health data with any third party, and we do not sell it, in any form, under any circumstances.
Two companies touch this data besides you, and neither receives it for its own purposes. Amazon Web Services, Inc. runs the servers that generate your suggestion. Cloudflare, Inc. sits in front of that endpoint, so the request passes through it on the way. Both act under a written agreement that lets them process data only on our instructions, and neither is a party we "share" data with in the ordinary sense of that word — see Privacy Policy §9 for the complete list of everyone who touches any BlinkWrite data, health-related or not.
We do not use consumer health data to train any model, run any advertising, or build any profile.
5. Consent
When you first sign in, and before BlinkWrite has read your screen at all, you are asked to separately and affirmatively consent to that, in a tick of its own — never pre-ticked, and never the same tick that accepts our Terms of Service and Privacy Policy. BlinkWrite does not turn on until you give it. That consent covers the categories of data described in Section 2, the purpose described there, and the fact that we do not share or sell it. You can withdraw that consent at any time — see Section 6.
6. Your rights, and how to exercise them
If you are a Washington resident, RCW 19.373.040 gives you the right to:
- Confirm whether we are collecting, sharing, or selling consumer health data about you, and to access it;
- Withdraw your consent to our collection or sharing of it, at any time, without affecting anything already generated;
- Request deletion of consumer health data we hold about you, including from any third party we've shared it with — though because nothing is retained (Section 7), there is in practice nothing to locate or delete once a suggestion has been returned;
- Appeal if we refuse a request under this section.
To withdraw your consent, you do not need to contact us and you do not need to wait for us. You can stop BlinkWrite reading your screen yourself, at any time, and it takes effect immediately:
- pause BlinkWrite for one application or one website, for an hour, for the day, or until you turn it back on;
- pause it everywhere, or quit it;
- withdraw the Accessibility permission in macOS System Settings, which stops it reading altogether.
Any of these ends the collection described in this policy. We built the consent as a single tick, and withdrawing it should be no harder than giving it was.
To exercise any of these rights — including telling us in writing that you have withdrawn consent, so there is a record of it — email [email protected] with the subject line "Washington Consumer Health Data Request." We will confirm receipt and respond within a reasonable time.
To appeal a refusal, reply to our response noting you wish to appeal. A member of our team not involved in the original decision will review it and respond within 45 days. If we uphold the refusal, we'll explain why and give you a way to submit a complaint to the Washington Attorney General.
These rights sit alongside, and don't replace, the rights in our Privacy Policy §12.
7. How long we keep it
We don't. Consumer health data is handled exactly like every other category of text BlinkWrite reads: held in server memory for the second or two it takes to generate your suggestion, then discarded. It is not written to disk, not logged, and not stored in any database. See Privacy Policy §2.5 and §11 for the full retention schedule covering every category of data we hold.
8. Security
Consumer health data is protected the same way as everything else BlinkWrite handles in transit and in memory — see Privacy Policy §13. Because nothing is retained, there is no stored consumer health data to protect against unauthorized access after the fact.
9. How we can say this with confidence
The claims in Sections 4, 6, and 7 aren't just policy — they're backed by code we can walk through: no call path that could emit request content is reachable in production, our model server logs nothing about the requests it handles, and neither our database nor our cache schema has a column or field that could hold message text.
We would rather be precise than impressive, so one qualification. The gateway in front of our model servers keeps an ordinary web access log — the time a request arrived, whether it succeeded, and how large it was. It records that a request happened. It does not record what was in it, and there is no setting anywhere in that path that would write the text of a request to disk.
We're glad to answer specific questions about any of this at [email protected].
10. Changes to this policy
We will update this policy if what's described above changes. Material changes — a new category of consumer health data, a new purpose, or a new recipient — will not take effect until we've disclosed them here and, where required, obtained your renewed consent, per RCW 19.373.020(1)(c)–(d). Everything in Privacy Policy §17 about versioning and notice applies here too.