Consumer Health Data Privacy Policy
Effective 2026-08-05
Washington and Nevada require this to be its own page, separate from our general privacy policy. It covers the health-related data Drop collects, why each piece is collected, who processes it, and how to get it back or have it deleted.
Why this is a separate document
Washington's My Health My Data Act (RCW ch. 19.373) and Nevada SB 370 (NRS 603A.400–.550) each require a consumer-health-data privacy policy that is distinct from a general privacy policy, reachable by its own prominent link, and — per the Washington Attorney General's reported position — containing only the content the statutes require. No marketing copy, no brand voice, no material that belongs in PRIVACY_POLICY.md.
Two facts drive the whole posture:
- There is no size threshold. Unlike the CCPA/VCDPA family, MHMD's "regulated entity" definition has no revenue floor and no minimum record count. The "small business" tier is a subset of regulated entity, not an exemption — its only benefit was a later compliance date of 2024-06-30, which has passed. A pre-launch app in 2026 has no runway.
- Washington has a private right of action. RCW 19.373.090 declares a violation a per se Consumer Protection Act violation, which carries the RCW 19.86.090 private action (injunctive relief, actual damages, capped treble damages, attorney's fees). It is the only US consumer-health-data statute with one. Nevada is AG-enforced only.
This draft is built to the stricter of the two on every axis, so one document serves both. Nevada-only elements are marked [NV].
Scope and effective date [NV]
Effective date: (to be set at publication) Applies to: the Drop Skincare mobile application and drop-skincare.com.
1. Consumer health data we collect
Drop treats the entire user health profile as consumer health data. This is deliberate and conservative: RCW 19.373.010(8)(b)(xiii) reaches "proxy, derivative, inferred, or emergent data… including algorithms or machine learning," which means the moment Drop's engine derives a skin condition from a product list, the product list is in scope too. Field-level scoping is not available to a product that infers.
| Category | Examples |
|---|---|
| Reproductive health status | Pregnancy status; breastfeeding/chestfeeding status |
| Declared skin conditions | Eczema flare, active rosacea, compromised barrier, fungal acne, perioral dermatitis, seborrheic dermatitis |
| Declared sensitivities | Named fragrance allergens; free-text sensitivities; fragrance-free / alcohol-free preferences |
| Care status | Whether a dermatologist manages your care |
| Age band | Collected as a safety input (some ingredients carry under-18 contraindications) |
| Skin attributes | Skin type, skin tone, concerns, sun exposure, acne severity |
| Product inventory | The skincare products you tell us you own, have used, or have finished |
| Routine and adherence | Your routine, the steps you complete, and when |
| Journal and reactions | Journal entries, reaction reports, and the chips you select |
| Photos | None at V1. Progress photos are not a V1 feature (D-036 deferred them to V1.5). Shelf and product photos you take to add items are sent for ingredient extraction and are not retained after the response — they are never stored, never linked to your profile, and never used to identify you. The "is a skin photo biometric data" question therefore does not arise at V1, and cannot arise without amending this page first. |
Purposes. We collect this data to (a) build and adjust your routine, (b) apply ingredient safety rules — the contraindication checks that hold back products your profile flags, (c) show you cited explanations for what we flag, and (d) let you keep a record of your own skin over time.
We do not collect or use consumer health data to improve, train, tune, or evaluate our models or product.
Everything in the table above is collected because a feature you asked for needs it, which is the boundary the statutes draw. We hold ourselves to it concretely: on 2026-08-05 we stopped collecting skin tone and acne severity (D-379) because no part of the product read them. They were collected for a feature we had not built yet, and intending to use something later is not the same as needing it now. If a field is not doing a job for you, we should not be holding it.
2. Sources of consumer health data
- Directly from you — onboarding answers, the skin & safety profile editor, journal entries, reaction reports, photos, and products you add.
- From your use of the app — which routine steps you complete and when.
- We do not buy consumer health data, and we do not receive it from data brokers, advertising networks, or other third parties.
3. Consumer health data we share, and with whom
We share consumer health data with two categories of recipient, both of them service providers processing on our instructions under contract — never for their own purposes:
| Recipient | What it receives | Why |
|---|---|---|
| Anthropic PBC (AI provider) | Pregnancy status, age band, declared conditions, and derm-care status — only when you have turned on personalized AI features | To generate and personalize your routine. Configured for zero retention; per Anthropic's API terms your data is not used to train their models. |
| Supabase (hosting/database) | All stored profile data | To host the application database and storage |
| PostHog (analytics, EU region) | Product-usage events, under a data processing agreement | To understand how the app is used. Opt-out available in Settings. |
Anthropic acts as our processor: it works on our documented instructions, does not retain the inputs, and does not train on them. It is not free to use what it receives for its own purposes, which is what separates processing from sharing. Regardless of that characterisation, this transmission has its own separate opt-in — it is off unless you turn it on, enforced on our servers rather than in the app, and you can withdraw it at any time in Settings → Privacy. Withdrawing it stops the transmission; the app keeps working without personalised routine generation.
Specific affiliates. Washington requires naming specific affiliates. Drop has no corporate affiliates and shares consumer health data with none.
4. Third-party collection across sites and applications [NV]
Drop does not permit third parties to collect consumer health data across our website and application over time. We use no advertising SDKs and no cross-context behavioural advertising trackers.
5. Sale of consumer health data
Drop does not sell consumer health data. We earn affiliate commission when you choose to buy through a retailer link, and we are explicit about that elsewhere — but the commission is paid for a purchase, not for data, and the retailer learns nothing about you from us.
That is guaranteed by construction rather than by promise: no health attribute, condition code, or profile-derived parameter is transmitted in any outbound affiliate link or postback. The stronger and more accurate statement, verified against the code on 2026-07-28: no Drop-originated identifier of any kind is present in the outbound URL — not an opaque one, not a hashed one, none. The URL is the static per-product string, byte-identical for every user.
6. Your rights
You may:
- Confirm and access the consumer health data we hold about you, including a list of every third party and affiliate we have shared or sold it to.
- Withdraw consent to our collection of your consumer health data, and separately to our sharing of it.
- Delete your consumer health data, including from backups and archived systems.
Exercising these rights never costs you service or price.
How. In the app: Settings → Privacy → View & manage your data. Or email privacy@drop-skincare.com.
Timeline. We respond within 45 days, the window both statutes allow, applied to everyone rather than branched by state — and in practice usually much sooner. If we need more time we will tell you why and how much before the 45 days are up.
(This said 30 days until 2026-08-05. That was a promise we invented: neither statute requires it, and a self-imposed deadline we might miss is itself actionable under Washington's Consumer Protection Act. Committing to the real window and beating it is the honest version.)
Deletion reach. We delete from production immediately and from backups within the restoration cycle, and we notify every processor that received your data so they delete it too.
Appeals. If we deny a request you may appeal by replying to the denial. If we deny the appeal, you may complain to:
- Washington Attorney General — Consumer Protection Division, https://www.atg.wa.gov/file-complaint
- Nevada Attorney General — Bureau of Consumer Protection, https://ag.nv.gov/Complaints/File_Complaint/
7. Security
We restrict access to consumer health data to what is needed to run the service. Access is row-scoped per user at the database layer, and processor access is bounded by contract.
8. How we notify you of material changes [NV]
Because this policy defines the limits of what we may collect and why, a material change requires new disclosure and fresh affirmative consent — we will not quietly widen it. We will notify you in the app before a material change takes effect, and every published version is retained with its effective date.
9. Contact
Drop Skincare LLC 8735 Dunwoody Place, Ste R, Atlanta, GA 30350, USA privacy@drop-skincare.com
This is the same entity named in the Terms of Service.
---
Questions, or to exercise any right above: privacy@drop-skincare.com