Consumer Health Data Privacy
The separate policy that Washington's My Health My Data Act requires, and that Nevada's law asks for too. Our general Privacy Policy — which covers everything, everywhere — is at heyblu.co/privacy.
HeyBlu is eight minutes on the phone with a real person. Your call is not recorded. No audio is stored and nobody can play it back.
We never sell your consumer health data and we never share it for advertising. We don't run geofences. Your employer never learns anything, even when they pay.
The one exception to all of it is safety, and section 5 says exactly what that means.
"We don't keep your conversations. The only exception is when someone's safety is at risk."
This policy is for people in Washington and Nevada, whose laws give consumer health data its own protections and require this to be a separate document. If you're elsewhere in the US, section 12 of our general Privacy Policy sets out your state rights. Reading this page costs you nothing and asks you to agree to nothing.
Section 1What counts as health data here
Washington's definition is broad on purpose, and we're going to read it broadly rather than argue about the edges.
The fact that you called HeyBlu at all is consumer health data — reaching out for mental-health support is itself information about your health. So is anything written down afterwards. We treat all of the following as consumer health data:
- That you have a HeyBlu account, and that you had a Connect
- Your Emotional Receipts and their tags
- Continuity copies — the short note a Blu Bud can read before a later call, kept only while you have continuity switched on
- Safety records, if the safety exception in section 5 ever applies to you
- Your check-in window — mornings, Sunday evenings, late nights — because when you tend to reach out says something
- Connect records — date, time, length, which Blu Bud
We do not hold a diagnosis, a clinical record, or a treatment plan, because HeyBlu is not health care and Blu Buds are not clinicians. HIPAA does not apply to us. Your protection here comes from this policy and from state law.
Section 2What we collect, why, and from where
| Category | Why we have it, and how it's used | Where it comes from |
|---|---|---|
| Account basics — first name, phone number, that you passed an 18+ check | To reach you, to let you reach a Blu Bud, and to keep the service adult-only | You, when you sign up |
| Connect records — date, time, length, which Bud | Billing, your own history, and paying Blu Buds fairly | Generated automatically when a call happens |
| Emotional Receipts and their tags | So the call leaves something behind for you. This is the product itself, written after every call | Written by software from the call, then shown to you |
| Continuity copies | So a Blu Bud can catch up and you don't retell a hard story. Only kept if you switch continuity on | The same automated step that writes your receipt |
| Check-in window | To know when not to bother you, and when a nudge might help. Uses call timestamps only, never content | You choose it; we look at when you call |
| Safety records | Only if section 5 applies — to help keep you or someone else safe | Your Blu Bud and the supervisor involved |
| Working text of a call | The transient text the summarising step needs. Deleted the moment your receipt is written; never stored, never read by a person | Produced automatically from call audio |
That's the whole list. We don't collect consumer health data from data brokers, from advertising networks, from your device's other apps, or from anywhere you didn't put it.
Section 3What we share, and with whom
"Share" here means what the law means by it: disclosing to someone else. It does not include selling, because we don't sell — see section 4.
| Who receives it | What they receive | Why, and on what terms |
|---|---|---|
| Your Blu Bud — our own people, not a third party | Your first name, check-in window, and — only while continuity is on — your past receipts and continuity copies | To talk to you. They may not record, screenshot, or keep private copies; breaking that is a disciplinary matter |
| An AI text-summarisation provider | The working text of a call, for the seconds it takes to write your receipt | Acts only on our instructions. Contractually barred from retaining it or training models on it. Named at heyblu.co/subprocessors |
| Telephony carriers | The call itself, as any phone network carries a call | Contractually barred from retaining audio or using it for their own purposes |
| Cloud hosting and error diagnostics | Data at rest, and crash diagnostics | Processors acting on our instructions only |
| Payment processors | Payment details and amounts — never anything about what you talked about | To charge you correctly and not twice |
| Emergency services, a crisis service, or a support person you name | Only the minimum in a safety record | Only under section 5, where there is a risk to life |
| Courts and regulators | Only what valid legal process compels | We'll tell you unless we're legally barred from doing so |
Your employer never receives any of it. If your employer pays for HeyBlu, they buy access — never visibility. They never learn whether you called, when, who you spoke to, what you said, or that a call was escalated. Not HR, not your manager, not through aggregate reporting. It is a condition of every enterprise contract.
No affiliate receives it. Consumer health data is not shared with any affiliated or group company of Unbroken Consulting Pte. Ltd.
Section 4What we never do
- We never sell consumer health data. Not to anyone, for any price. Because we don't sell, the separate written authorization that Washington and Nevada require before a sale simply never arises — there is nothing for you to sign, and we will never ask you to.
- We never share it for advertising. No targeted advertising, no cross-context behavioral advertising, no profiling, no ad networks, no advertising identifiers.
- We never geofence. We do not use, and will not implement, a geofence around any health care facility, clinic, hospital, pharmacy, or provider's office — for any purpose.
- We never let a provider train on you. No service provider may retain your data or use it to train an AI model.
- We never record your calls. There is no audio to release, subpoena, leak, or sell.
Section 5The safety exception
If your Blu Bud believes you or someone else is at risk of serious harm, they stay on the call for as long as it takes, nothing is charged, and we may create and keep a safety record — what the concern was, what was said about risk, any location or contact detail needed to get help to you, what was done, and the supervisor involved.
Where there's a risk to life we may share that record with emergency services, a crisis service, or a support person you name. Where the law requires it, we may report a risk to a child or a dependent adult.
Safety records are stored separately with restricted access, are never used for marketing or analytics, and are kept no longer than seven years, reviewed annually. This is the one place where your right to delete may not reach — and we'd rather say so here than surprise you later.
Section 6Consent, and taking it back
We collect and use the consumer health data in section 2 to provide the Connect you asked for. Anything beyond that needs your opt-in consent, given separately and never bundled into accepting our Terms.
| What | Starts as | How to change it |
|---|---|---|
| Your Emotional Receipt | Always written | It's the service you bought, so there's nothing to opt into. Ask us and we'll delete any of them |
| Continuity — a Blu Bud reading your past notes | Off | Let my Bud catch up first, in You → What we remember |
| Nudges and check-in calls | Off | You → Your check-in |
Withdrawing consent is as easy as giving it, takes effect immediately, and never costs you access to calls. You can do it in the app, or by emailing privacy@heyblu.co.
Section 7Your rights, and how to use them
| Right | What it means here |
|---|---|
| Confirm and access | Ask whether we collect, share or sell your consumer health data, and get a copy of it — together with a list of every third party and affiliate it has been shared with, and a working contact for each |
| Withdraw consent | From collection and from sharing, at any time, in the app or by email |
| Delete | Have your consumer health data deleted — see section 8 for exactly what that reaches |
| Appeal | If we refuse any of the above, we say why, and a different person reviews it |
| No retaliation | Your price and your service don't change because you asked for any of this |
How to ask. Email privacy@heyblu.co from the address on your account, or use You → Manage plan in the app. We'll verify it's you in a way proportionate to what you're asking for — usually a code to your registered number. We won't demand documents we don't need.
Someone acting for you. You can use an authorized agent. We'll ask them for written permission from you and may ask you to confirm directly — that check protects you, not us.
Timing. We acknowledge within 10 business days and answer within 45 calendar days, extendable once by a further 45 if we tell you why. Deletion of live records we complete within 30 days; section 8 says what that currently reaches.
Section 8Deletion, precisely
When you ask us to delete your consumer health data, we remove it from our live systems and instruct every processor and contractor holding it to do the same, and we confirm when that is done. We are honest about the limit: propagation to backups, archives and provider logs is not yet automatic, so copies can persist for a period after your request. We are building automated propagation and a deletion ledger, so that a restored backup re-applies your request. Until then we complete deletion manually.
The bare financial record that a payment happened — dates, amounts, invoices — which Singapore tax law requires us to keep for five years. It never includes anything about what you talked about.
A safety record under section 5, for as long as safety and law require and no longer than seven years. We'd rather tell you that here than have you discover it.
Everything else goes: receipts, continuity copies, tags, your name and number, your check-in window, diagnostics. There is no call audio to delete, because none was ever made.
Section 9Appeals and complaints
If we refuse a request, we'll tell you why in plain words and how to appeal. An appeal goes to someone who wasn't involved in the original decision, and we answer within 45 days. If we still say no, we'll tell you how to complain to your Attorney General.
You can complain to the Washington State Attorney General at atg.wa.gov, or the Nevada Attorney General at ag.nv.gov, at any time — you don't have to come to us first, though most things we can fix in a day.
Washington's law also gives you a private right of action under the Consumer Protection Act. We'd rather you never need it.
Section 10Contact
- Company
- Unbroken Consulting Pte. Ltd. · UEN 202511691N
68 Circular Road, #02-01, Singapore 049422 - Privacy
- privacy@heyblu.co
- Safety concerns
- safety@heyblu.co
- General
- hello@heyblu.co
- Full privacy policy
- heyblu.co/privacy
- Terms of service
- heyblu.co/terms
- Sub-processors
- heyblu.co/subprocessors
- In an emergency
- 911 · 988 Suicide & Crisis Lifeline
If we change this policy in a way that materially affects you, we'll tell you in-app and by message at least 30 days before it takes effect. We will never quietly weaken sections 3, 4 or 5.
It needs its own link on the homepage — the footer is the right place for it. Washington requires a prominent homepage link to this policy as a separate document. A normal footer link satisfies that, provided it is its own distinctly-labeled entry — Consumer Health Data Privacy, sitting beside Privacy Policy and Terms — rather than folded into "Privacy" or hidden inside a dropdown. What it cannot be is only a section inside the general privacy policy.
Confirm the affiliate statement in section 3. This policy states that no affiliate of Unbroken Consulting Pte. Ltd. receives consumer health data. That is the right position and matches the enterprise firewall — but it must be verified against the actual group structure and any reseller arrangement before publication.
Confirm the product matches. Continuity and check-ins must genuinely default to off, and deletion must genuinely reach backups and processors within 30 days. This page is a description of built behavior, not an aspiration.