Consumer Health Data Privacy Policy
Version 1.2.1—Last updated: 2026-08-06
Published
1. Who We Are; Scope
This Consumer Health Data Privacy Policy is published by Qpher LLC ("Qpher", "we", "us") under the Washington My Health My Data Act and Nevada Senate Bill 370. It applies to Washington and Nevada consumers' "consumer health data" handled by Qpher Legacy and Qpher Vault.
This policy supplements our Privacy Policy at qpher.ai/legal/privacy. For consumer health data of Washington and Nevada consumers, where this policy and the Privacy Policy differ, this policy governs.
2. What We Can and Cannot See
Your documents are encrypted on your device; Qpher stores only ciphertext and does not read document contents or (for Legacy Vault documents) file names in normal service operation. The unlock keys are held in Qpher's access-controlled key-management service and are used only to provide the service you configure — your own access, and release to your designated recipients when your release policy completes. Like any provider that holds unlock keys, Qpher could be compelled to use them under a valid legal order; Section 6.5 of our Privacy Policy describes the full trust model and our transparency commitments. We believe this means we do not collect readable health information from your documents in the ordinary course. To the extent any data we hold is consumer health data, this policy governs it.
3. Categories of Consumer Health Data Collected
To the extent the following constitute consumer health data, we collect:
(a) Encrypted documents you store, which may contain health information we cannot read; and, for Qpher Legacy Vault documents, the encrypted document and folder names (for standard, non-Legacy Qpher Vault documents, file names are stored unencrypted — see Section 3 of our Privacy Policy — so do not put health information in a standard Qpher Vault file name if this matters to you);
(b) A death certificate, only if a claimant submits one in the manual claim-review lane of the Qpher Legacy claim process (a copy of a death certificate may state a cause of death);
(c) Claim attestations regarding a death — the sworn statement, typed legal name, and date a claimant provides when opening a claim on a Legacy Vault.
We do not collect biometric data, precise location data, health-status inferences, or any other category of consumer health data.
4. Sources
We collect the data described in Section 3 from: (a) you, when you store documents; and (b) your designated heirs and confirmers, for claim-lane submissions only (attestations and, in the manual review lane, a death certificate).
5. Purposes
We collect and use the data described in Section 3 only to: (a) provide the storage and legacy-release service you configure; (b) verify claims on a Legacy Vault; (c) maintain the security of the service; and (d) comply with legal obligations. No other purpose.
6. No Sale; No Advertising Use
We do not sell consumer health data and do not use it for advertising. No data is shared for these purposes. Because we do not sell consumer health data, we do not need — and do not ask for — the separate signed authorization Washington law requires before any sale.
7. Sharing
We share the data described in Section 3 only:
(a) with recipients you designate, when your release policy completes (release is controlled by your policy — a claim, your confirmers, the delay period, and your right to veto);
(b) with processors acting under binding contracts that limit processing to our documented instructions — currently Google Cloud (infrastructure and storage), Cloudflare (encrypted object storage), and Twilio SendGrid (transactional email); the current list is maintained in this section and in Section 6 of our Privacy Policy;
(c) as required by law — see the legal-process transparency provisions of our Terms of Service; law-enforcement requests are documented and never, by themselves, release documents; and
(d) with the confirmers a vault owner designated, and only once a claim has been opened on that owner's Legacy Vault and enough of those confirmers are available to decide it: the legal name the claimant typed into their attestation (Section 3(c)). We show that name beside a partly hidden form of the contact address the owner gave us for that person, so that the confirmers can judge whether the claim makes sense — the address itself is ordinary contact data the owner supplied, not Section 3 data, and Section 3.1 of our Privacy Policy governs it. Confirmers are never shown any document. If a claim is opened on a policy that does not have enough available confirmers to decide it, no confirmer is contacted and nothing is shared under this paragraph.
8. Your Rights
If you are a Washington resident (or a Nevada resident, with equivalent rights under Nevada law), you have the right to:
- **Access** the consumer health data we hold about you, including the categories of third parties and processors it has been shared with;
- **Withdraw consent** you previously gave for the collection or sharing of your consumer health data;
- **Delete** your consumer health data, including from backups, on the timelines the statutes set, except records we are permitted or required by law to retain — for example the append-only legacy policy ledger entry recording a claim attestation, and a death certificate held as part of a claim record, both of which we keep as evidence of the basis for a claim on the retention timelines described in our Privacy Policy. Where we retain such data, we tell you what we kept and why in our response. Deleting your Legacy Vault disarms your legacy policy.
Submit a request to privacy@qpher.ai. We verify each request, respond within the statutory deadlines (for most requests, within 45 days of verification, extendable once by a further 45 days where the law allows and we notify you), and never discriminate against you for exercising your rights.
**Appeals**: if we decline a request, you may appeal by replying to our decision; we will respond to the appeal within the statutory appeal deadline. If your appeal is unresolved, you may raise it with the Washington Attorney General or the Nevada Attorney General, as applicable.
9. Processors
Every processor that handles consumer health data on our behalf is bound by a contract limiting its processing to our documented instructions and requiring it to assist us in honoring the rights in Section 8. Our current processors for this data are listed in Section 7.
10. Changes to This Policy
We may update this policy as our practices or the law change. Material changes will be announced on this page before taking effect, and where the law requires renewed consent for a new collection or sharing purpose, we will ask for it — we will not apply a material change to previously collected consumer health data without the consent the law demands.
Our archive of prior versions has two parts. The first is the revision history at the end of this page: it records every version of this policy, its date, and what changed in it, and it is published here so you can read it without asking us. The second is our source-control history — the record our engineering systems keep of every change to this page — which preserves the complete text of every version exactly as it was published. If you want the full text of an earlier version rather than a summary of what changed, ask privacy@qpher.ai for it by version number or date and we will send it to you within 10 business days.
11. Contact
For questions about this policy or to exercise your rights: privacy@qpher.ai.
Qpher LLC, 8401 Mayland Dr Ste A, Richmond, VA 23294, USA.
This Consumer Health Data Privacy Policy first took effect on July 7, 2026 (version 1.0.0). The version shown at the top of this page is the one now in effect; the revision history below records every version and what changed in it.