SessionGauge Consumer Health Data Privacy Policy
This policy explains how SessionGauge handles personal information that identifies, or can reasonably be linked to, your physical or mental health, medication use, substance-related experiences, or efforts to understand your well-being. It supplements our general Privacy Policy at https://sessiongauge.com/privacy/.
It covers SessionGauge Personal Mode and related account, support, and website interactions when they involve consumer health data. It does not automatically cover future Liquid Lojic apps or a future Professional Mode. Opening this policy does not constitute consent to collection, sharing, or sale of health data.
1. Health data we collect and why
Session records. We process the session information you enter, including session names, substance selections and recorded amounts where provided, timestamps, status, check-ins, markers, and notes. We also process session timing information, including active duration. We use these records to provide the tracking, timeline, and history functions you request. Names and notes can themselves contain sensitive information.
Medications and profile information. We process medication names, recorded strengths, active or stopped status, and ingredient or product selections you save. We use these details to maintain your medication list and identify the catalog entry you selected. We also process the profile information and optional photo you provide. Account identifiers link these records to your account. Please avoid adding other people’s health information unless you are authorized to do so.
Reflections and derived information. Optional reflections can include overall experience, mood, energy, sleep categories, and written observations. We use these answers for your reflection history and, where available in your version, ratings, charts, and comparisons. Calculated ratings summarize answered overall-experience, mood, and energy fields; sleep and free text are not scored. These summaries can reveal health-related patterns but are not diagnoses or determinations that an experience was safe.
2. Other information and sources
Contacts and communications. We store emergency-contact details you choose to provide for your contact list. Support or privacy messages may contain health data if you include it. We use those messages to respond to you and handle requests. Transactional messages include account communications and deletion receipts; deletion receipts do not include session or reflection details.
Technical information. Account, security, and service records may become consumer health data when linked to your use of SessionGauge. [CONFIRM AND LIST actual technical fields, such as IP addresses, device or app version, request timestamps, error details, and authentication or delivery events; identify their sources and purposes. Confirm whether logs capture URLs, medication searches, record contents, or identifiers.]
Sources. Our sources include information you enter or upload; your interaction with app functions, such as starting or ending a session; calculations from those records; your communications with us; and authentication information supplied when you choose Google sign-in. Public medication and substance reference catalogs supply reference information, not your personal health history. [CONFIRM provider-returned fields and any additional sources.]
Device authentication and permissions. Optional biometric unlock uses the device’s authentication system. SessionGauge does not receive your fingerprint template through that unlock flow. A profile photo is a separate upload, not a fingerprint record. Camera or photo access supports images you choose to add. [VERIFY all shipped device permissions and disclose any location, sensor, wearable, or health-platform collection before publication.]
3. How we use and process this information
We use the information described above to provide your requested account and tracking functions, maintain and display records, produce requested exports and comparisons, answer support and privacy requests, secure the service, and complete account-deletion operations. Stored account data is processed through our backend; the app also retrieves and displays it and performs calculations or creates files on your device.
Personal medication lists are not sent to RxNav, DailyMed, or DrugBank by the currently described app. Medication-interaction lookup remains disabled. This policy does not represent future clinical review, professional sharing, AI features, or automated safety monitoring as current features.
[CONFIRM actual practices for analytics, advertising, research, AI training, model providers, and cross-service tracking. State explicitly which occur and which do not; do not publish an unverified “we never” claim.]
4. Recipients and disclosures
The following identifies the currently described service functions and data flows. Service providers may legally be processors rather than third parties. Their classification does not remove the need to disclose the data flow accurately.
Hosting and account services. Supabase provides the backend database, authentication, file storage, and server functions used to handle account-linked session records, medications, reflections, contacts, profile information, and deletion operations. Cloudflare provides website and authentication-page hosting and network delivery for those pages. [CONFIRM each vendor’s contracting entity, subprocessors, logging, and any additional access to health data.]
Email and support services. Resend delivers account and deletion-receipt emails and processes recipient addresses, message contents, and delivery information. Google Workspace handles support and privacy correspondence, including any health data you choose to send us. Google sign-in involves identity information for authentication; that does not mean your session journal is sent to Google through the sign-in flow.
Recipients you choose. When you export and share a file, the selected app, storage service, or recipient receives the exported information. Screenshots and recordings can also contain health data. We cannot recall copies you save or give to other people. Merely saving an emergency contact does not automatically send your session records to that person. Urgent-help calling uses the phone app; it does not establish that emergency services received your health records.
Other third parties and affiliates. [LIST any additional recipient categories and the health-data categories and purposes for each, or confirm there are none. LIST specific affiliates receiving health data, or state none after verifying the legal operator structure. Do not list Liquid Lojic and SessionGauge as separate affiliates merely because they have different brand names.]
[CONFIRM any legally required disclosures and their narrow legal basis. Do not insert a broad disclosure permission that overrides consumer-health protections.]
5. Consent and sale of health data
Where applicable law requires consent, collection and sharing require the relevant affirmative consent before they occur. Sharing consent must be separate where required. Processing necessary to provide a product or service you requested may be permitted without separate consent under applicable law. This policy and the Terms of Use do not replace any required consent or sale authorization.
[CONFIRM whether consumer health data is sold or exchanged for other valuable consideration. If none, state: “We do not sell consumer health data.” Confirm advertising disclosures separately. Any proposed sale requires legal review and the specific authorization required by applicable law, not a general checkbox accepting this policy.]
6. Your choices and privacy requests
You may leave optional fields unanswered. Depending on applicable law, you may request confirmation of collection, sharing, or sale; access to your health data; information about recipients, including recipient contact details where required; correction; withdrawal of consent or cessation of processing; and deletion. You may also appeal a denied request. Available rights and exceptions depend on the law that applies to you.
Send requests to privacy@sessiongauge.com. A suggested subject is “Consumer health data request,” but no particular wording is required. Identify the account and what you want us to do. Do not send your password, authentication codes, or an entire health journal. We may request only the additional information reasonably needed to verify your identity and authority through an appropriate channel. You do not need to create a new account to submit a request.
You can review records and edit fields where the app provides those controls. The app’s personal-data export can help you obtain records, but an export is not necessarily the complete response to a statutory access or recipient-list request. Email us if a record cannot be corrected through the app or the export reports unavailable collections.
To withdraw consent or request that collection or sharing stop, email the same address and identify the processing concerned. A feature may become unavailable if it cannot operate without the information involved. Withdrawal does not itself erase existing records; you may request deletion as well. [CONFIRM the operational withdrawal process and any additional in-app controls.]
Response times and appeals. We will handle verified requests within the deadlines required by applicable law. Where Washington’s My Health My Data Act applies, requests generally require a response within 45 days of receipt; one additional 45-day extension is permitted when justified and timely explained. Nevada generally allows 45 days after authentication for a response, but requires covered deletion within 30 days after authentication, subject to its backup provisions.
If we decline your request, email privacy@sessiongauge.com to appeal, with the decision reference and why you disagree. “Privacy appeal” is a suggested subject. For requests covered by the Washington or Nevada consumer-health law, we will provide a written appeal decision within 45 days. If denied, we will provide the applicable Attorney General complaint method. We will not unlawfully discriminate against you for exercising applicable privacy rights. [CONFIRM staffing, request tracking, identity verification, and appeal review before publication.]
Complaint resources: Washington Attorney General — https://www.atg.wa.gov/file-complaint; Nevada Attorney General — https://ag.nv.gov/Complaints/File_Complaint/; Minnesota Attorney General — https://www.ag.state.mn.us/Data-Privacy/Complaint/.
7. Deletion and retention
Eligible email/password accounts can request account deletion through settings → Privacy & Security → Delete account. The flow requires typed confirmation and fresh password sign-in. Google-only accounts, people unable to use that flow, and people requesting deletion of particular health data can contact privacy@sessiongauge.com. An email request does not instantly delete an account.
The in-app process removes the login and SessionGauge-controlled personal records and profile-photo storage records through the deletion workflow. Success is shown only after that workflow reports completion. A receipt email is separate from completion; delivery failure does not undo deletion. Deletion jobs and receipt or request records can remain for follow-up operations. [SPECIFY their retained fields, purpose, retention, and treatment under health-data deletion requests.]
Signing out, uninstalling the app, or hiding a session from History does not constitute account deletion. Removing a reflection removes that reflection, not the entire session. App deletion does not erase exports, screenshots, or files you have saved or shared outside the app.
A completed account workflow does not prove immediate erasure from every backup, log, or delivery cache. This limitation does not waive our legal deletion obligations. Applicable requests must also be handled across our controlled systems and recipients as required. Washington limits its permitted archived/backup deletion delay to six months after authentication; Nevada permits a delay of up to two years only as its law allows. These are legal limits, not SessionGauge’s chosen retention schedule.
[INSERT verified retention periods or specific criteria for active records, soft-deleted sessions, support messages, logs, backups, deletion jobs, receipts, and processor/CDN copies. Describe recipient notification and restoration handling. Do not carry forward unapproved five-year or two-year placeholders as actual practice.]
8. Security and your device
SessionGauge uses account-scoped access controls and optional device biometric saved-login protection. It does not provide end-to-end encryption. Device unlock protection does not mean every displayed record or exported file is encrypted by the app.
Exports are readable files. App-owned temporary-file cleanup is best effort; export files may remain for a post-sharing cleanup period and longer if cleanup fails. Screenshots and recordings are allowed, and the in-app privacy cover does not guarantee that Android Recents hides a preview. Please protect copies you keep or share.
9. Policy changes and contact
Contact privacy@sessiongauge.com with questions. [APPROVE the method for notifying users of material changes, such as an in-app notice and email.] We will update the effective date when a finalized revision takes effect and obtain any legally required consent before adding data categories, recipients, or purposes. Posting a revised policy alone does not supply that consent.
Minimum age: [OWNER DECISION REQUIRED; align this policy, the general Privacy Policy, Terms of Use, and account controls]. Processing locations: [VERIFY app, website, support, email, backup, and vendor locations; do not assume one database region describes every service].