Consumer health data privacy policy

Effective date: August 28, 2026 · Last updated: September 5, 2026

Nevada’s SB 370 and California law each define a category of “consumer health data” that is broader than most people expect. It covers not only medical records but information about the health care services and coverage a person seeks or pays for, which includes health insurance. Because LifQ organizes your household’s coverage, some of what you give us falls into that category. This page explains exactly what, and what you can do about it. It supplements our privacy policy. For consumer health data, this page controls wherever it is stricter.

What we treat as consumer health data

In the LifQ application. Health plan summaries and policies; Explanation of Benefits statements, including the claims, services, and payment information they contain; HSA and FSA records; health-benefit eligibility and cost-sharing information; any health-related information contained in documents you upload; and the plain-language summaries LifQ’s AI produces from them.

Inferences count too. If AI processing derives something health-related that you never typed, for example a summary of a specialized medical travel rider implies something about a condition, we treat that derived information as consumer health data, with the same consent, access, sharing, retention, and deletion rules as the document it came from.

What we do not collect

We never ask for diagnoses, conditions, treatments, medications, test results, or anything about your care. The benefits checklist in our free tools runs entirely in your browser. Nothing you enter is transmitted to us or stored, and it disappears when you close the tab. We do not attempt to infer health information from your browsing, and no third party collects consumer health data about you across other websites through our service.

Where it comes from

Three sources, all of them yours: documents and information you upload or enter directly; documents added for your household by another member with the authority to do so, see Consent below; and the summaries LifQ’s processing extracts from those documents. We do not buy, license, or acquire health data from anyone.

Why we collect it, and how it is processed

We collect consumer health data for exactly these purposes: storing your documents securely; producing plain-language summaries; showing your coverage side by side; sending reminders you enable; sharing within your household at your direction; and security and support. It is never used for advertising, profiling, scoring, or eligibility decisions of any kind.

Processing works like this. A PDF that already carries readable text is parsed on our own systems. A photo you take goes to Google Cloud Vision to have its text extracted, and so does a PDF that turns out to be a scan rather than text, or that our own parser cannot read. The extracted text is then processed by Anthropic and OpenAI to produce your summary, which is stored in your account. We treat what we extract, and everything derived from it, as consumer health data. We do not claim anything is de-identified unless it meets the law’s strict de-identification standard.

Consent, and how it actually works

Consent to collect your health data and consent to share it are separate, distinct choices. The law requires that, and we build it that way. Before LifQ first processes a health-related document of yours, we ask you plainly, in a standalone step: no pre-ticked boxes, no consent bundled into terms acceptance, no design tricks. Sharing with your household is a second, separate choice you make through your sharing settings.

Consent belongs to the person the data is about. You consent for yourself. An invited adult household member consents for themselves, accepting the invitation and these terms, before documents about them are read or shared. One adult cannot consent for another adult, even a spouse. Parents and legal guardians may act for their dependents where the law permits. You can withdraw any consent at any time, and withdrawal stops further processing.

Once you have granted sharing access, individual document views by the people you chose do not require fresh consent each time. Instead, sharing stays transparent and revocable: access logs show who viewed what, and you can revoke any member’s access at any moment. If we ever want to collect a new category of health data or use it for a new purpose, we will ask for your affirmative consent first. Notice alone is not enough, and we hold ourselves to that.

We do not sell it

LifQ does not sell consumer health data and never has. We do not share it with insurers, brokers, agents, quote services, data brokers, advertisers, or anyone else for their own purposes. Because we do not sell it, we will never ask you to sign a sale authorization. No analytics or advertising vendor receives it. Our website analytics never run on the beta application, the tools pages, or inside the product.

Who receives it

Only the service providers needed to operate LifQ, each acting on our instructions, bound by contract to the commitments in this policy, and prohibited from using your data for their own purposes: Supabase (encrypted storage), Vercel (hosting), and our AI processing providers (Anthropic, OpenAI and Google Cloud Vision). That list is kept current in section 6 of the privacy policy and updated before any new provider touches customer content. We share consumer health data with no affiliates and no one else, except when legally compelled, in which case we notify you first unless the law prohibits it.

How long we keep it

  • Application health data. Kept while your account and documents are active. When you delete a document, close your account, or withdraw consent, the documents and everything extracted or derived from them are deleted within 30 days, our processors are instructed to delete concurrently, and backup copies age out fully within 90 days at most.

Your rights

Everyone who uses LifQ gets these, regardless of where they live: confirm whether we hold consumer health data about you and see it; get a list of every third party it has been shared with, and their contact information; withdraw consent to our collection and use of it; and have it deleted, including from our service providers and our backups. Email privacy@lifq.ai. We will verify your identity, enough to be sure the request is really yours and no more, then respond within 45 days, extending once if we genuinely need longer and telling you if we do. You may use an authorized agent, whose authority we will verify. There is no charge, and asking will never affect your account or your place on the waitlist.

If we deny a request, we will tell you why and how to appeal: reply to our denial and a different reviewer will decide within 45 days. If your appeal is denied, Nevada residents may contact the Nevada Attorney General, and residents of other states may contact their own attorney general. We will include the link with our answer.

No geofencing

We do not use geofences around health care facilities, or anywhere else, and we do not track your location.

Security and breach notification

Consumer health data gets every protection described in our privacy policy: row-level security scoping each record to its household, encryption in transit and at rest, and access limited and logged. If a security incident affects your consumer health data, we will notify you without unreasonable delay, consistent with applicable law.

A note on HIPAA

LifQ is not a HIPAA-covered entity or business associate, and we will never tell you otherwise. HIPAA governs healthcare providers, health plans, and their business associates. It does not cover a tool you use on your own information. What protects your data here is this policy, the state laws above, and the security described in our privacy policy.

Changes to this policy

For material changes, a new category of health data, a new purpose, a new kind of recipient, or a change to your rights, we will give you at least 30 days’ notice by email and prominently in the app before the change takes effect. During that window you can withdraw consent and delete your data. And where a change means collecting new health data or using existing data in a new way, notice is not enough: we will ask for your affirmative consent before it starts. The effective date at the top always tells you which version you are reading.

Contact

LifQ is operated by Pakal Systems LLC. privacy@lifq.ai

Pakal Systems LLC9101 W Sahara Ave, Suite 105 PMB 1513Las Vegas, NV 89117United States