Bondura logo

Washington Consumer Health Data

Consumer Health Data Privacy Policy

Effective date: May 22, 2026. Applicable to Washington residents under RCW 19.373 (My Health My Data Act).

1. Scope and Application

This Consumer Health Data Privacy Policy is provided by Bondura, Inc. ("Bondura") to comply with the Washington My Health My Data Act, RCW 19.373 ("MHMDA"). It supplements, and does not replace, Bondura's general Privacy Policy.

It applies to "consumer health data" that Bondura collects about Washington residents and about other consumers whose data is processed in Washington. "Consumer health data" includes personal information that identifies a consumer's past, present, or future physical or mental health status, including information that Bondura derives or infers from other data.

2. Categories of Consumer Health Data We Collect

Bondura collects the following categories of consumer health data directly from you or generates them from your use of the Services:

  • Mental and emotional health information you share in chats, journal entries, surveys, daily check-ins, or partner simulations
  • Information about diagnoses, conditions, symptoms, or treatments you choose to share
  • Information that identifies you as seeking or receiving health-related services, including pairing with a licensed therapist through Bondura
  • Session notes, focus areas, and homework that a Therapist you have paired with publishes to you through the Bondura app, which Bondura's AI may reference when generating responses in your personal and partner chats
  • Biometric data, only to the extent you provide it (Bondura does not currently collect biometric identifiers such as facial scans or voiceprints, and will update this policy before it does)
  • Information that Bondura infers about your mental, emotional, behavioral, or relational state from your use of the Services, including AI-generated insights and personality profile outputs

3. Sources of Consumer Health Data

Bondura collects consumer health data from the following sources:

  • Directly from you when you create an account, complete a survey, write a journal entry, send a message, or interact with the Services
  • Automatically from your device when you use the Services (for example, the app version and event timestamps associated with your activity)
  • Generated by Bondura from your activity inside the Services (for example, AI-generated summaries, inferred traits, and memory records)
  • From your paired Therapist, to the extent your Therapist sends data back to your Bondura account in connection with your care

4. How We Use Consumer Health Data

Bondura uses consumer health data only for the following purposes:

  • To deliver the features of the Services that you have requested (chats, simulations, journal, insights, partner pairing, therapist pairing)
  • To generate AI summaries, personality outputs, and other content for your use and, where you have authorized it, for your Therapist
  • To maintain the security, reliability, and integrity of the Services and detect fraud or abuse
  • To comply with legal obligations and respond to lawful requests
  • To communicate with you about your account and the Services

Bondura does not use consumer health data for advertising, profiling for advertising, or sale. Bondura does not use consumer health data to train, fine-tune, or evaluate any third-party foundation model or any Bondura proprietary machine learning model.

5. How We Share Consumer Health Data

Bondura shares consumer health data only with the following categories of recipients, and only as described below:

  • With subprocessors that operate the Services on Bondura's behalf, under written contracts requiring confidentiality and use only for Bondura's instructions. The current subprocessors are Amazon Web Services, Inc. (hosting, database, authentication, file storage, email, AI inference, push notification delivery, and operational logging), Apple Inc. (App Store distribution, In-App Purchase, Apple Push Notification service), and Cloudflare, Inc. (DNS resolution only)
  • With your paired Therapist, only to the extent of your active HIPAA Authorization and your in-app sharing settings
  • With other Bondura users (a partner, group member) you explicitly pair or share content with inside the app
  • When required by valid legal process or to protect rights, property, or safety as permitted by RCW 19.373

Bondura does not sell consumer health data. Bondura has not sold consumer health data in the prior 12 months and will not do so without first obtaining your separate written authorization that meets the requirements of RCW 19.373.110.

6. Your Rights Under the Washington My Health My Data Act

If you are a Washington resident, you have the following rights with respect to your consumer health data:

  • The right to confirm whether Bondura is collecting, sharing, or selling your consumer health data, and to access that data
  • The right to a list of all third parties and affiliates with whom Bondura has shared or sold your consumer health data, along with active contact information for those third parties
  • The right to withdraw your consent to Bondura's collection and sharing of your consumer health data
  • The right to have Bondura delete your consumer health data, including from all subprocessors. Bondura honors valid deletion requests within the timeframes required by RCW 19.373.060
  • The right not to be discriminated against for exercising any of these rights

To exercise any of these rights, contact contact@bondura.app. You will not be required to create an account to submit a request, but Bondura may need to verify your identity or, for sensitive requests, ask you to provide additional information. Bondura will respond within 45 days of receiving a verified request and will explain in writing if more time (up to an additional 45 days) is required.

If Bondura denies a request, you have the right to appeal. To appeal, reply to the denial email or write to contact@bondura.app with the subject line "MHMDA Appeal." Bondura will respond within 45 days of an appeal. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/file-complaint.

7. Consent and Authorization

Bondura obtains your consent before collecting, using, or sharing your consumer health data for any purpose that is not strictly necessary to provide a feature you have requested. That consent is obtained through a separate, plain-language consent flow at signup, before any consumer health data is collected for non-necessary purposes. You may withdraw consent at any time inside the app or by contacting contact@bondura.app.

Bondura does not sell consumer health data. If Bondura ever proposes to sell consumer health data, Bondura will obtain your separate written authorization meeting all requirements of RCW 19.373.110 before doing so, and will provide you a copy of that authorization.

8. Retention

Bondura retains consumer health data only as long as necessary for the purposes described in this policy, and in accordance with the retention periods stated in Bondura's general Privacy Policy. When you delete your account or withdraw consent, Bondura deletes the associated consumer health data on a synchronous schedule, with automated database backups expiring within 7 days.

9. Security

Bondura maintains administrative, technical, and physical safeguards designed to protect consumer health data, including encryption in transit and at rest, role-based access controls, row-level database security, network isolation in a private virtual cloud, audit logging of access to client data, and routine security review. Bondura limits employee access to consumer health data to those who need it to operate the Services.

10. Contact

Bondura's Privacy Officer for purposes of this Consumer Health Data Privacy Policy is Cole Meyer. To contact Bondura about consumer health data, email contact@bondura.app.

Have a Washington consumer health data request?

Email contact@bondura.app with the subject line "MHMDA Request." See also our general Privacy Policy.