Consumer Health Data Privacy Policy
This policy explains how Meet Buddie L.L.C. handles consumer health data. It applies in addition to our Privacy Policy.
What consumer health data we collect
Buddie participates in group text conversations. While Buddie is active in a group, every message sent in that group is automatically analysed to identify possible expressions of suicidal ideation or self-harm.
That analysis produces inferred information about a person’s mental health status, which is consumer health data under Washington law, whether or not the analysis flags anything.
We collect the content of group messages at the moment they are analysed, the classification result, and a record that a crisis resource message was sent, without identifying who received it.
When this does not happen: Buddie stops generating replies, storing messages, building memory and running analytics when the group administrator’s account exhausts its message allowance, or when the service is paused or ended. The crisis-safety check continues in those states, so the text of an inbound message from a joined member is still transmitted for classification. Messages from members who have not joined are received by a third-party messaging infrastructure provider and transiently by Meet Buddie so we can identify the sender and recognize consent, opt-out, and identity-confirmation messages. The provider receives the message content, sender and participant identifiers, group and assigned-line information, and delivery metadata. Meet Buddie does not add the message content to its message database, send it to an AI provider, run crisis or reply-moderation classification on it, use it for memory or response generation, or include the content in analytics. We may keep content-free operational records tied to the member and group. Analysis also stops entirely for anyone we have clear reason to believe is under 13, as described in our Privacy Policy; those people are given crisis resources directly instead.
Where it comes from
Directly from the group conversation. We do not obtain consumer health data from any other source. We do not buy it and we do not receive it from third parties.
Why we collect it
To identify when someone in a group may be at risk of self-harm, and to send that person crisis resources privately.
California law requires operators of companion chatbots to maintain a crisis protocol and to report the number of referrals issued. That reporting obligation begins on 1 July 2027.
We do not use the crisis classification, or the record that a referral was sent, for any other purpose. We do not use either to build profiles, target advertising, or train AI models. A message that is not flagged remains an ordinary group message and is used to generate Buddie’s replies and, where the sender has opted in, to build memory notes, as described in our Privacy Policy.
We do not intentionally use consumer health data to personalise Buddie’s replies. Our memory system is instructed not to save health information, and each proposed memory is automatically screened before storage. These controls are automated and may fail, including when health context is removed as a message is summarised into a memory. If that happens, the saved memory may influence later replies. Text FORGET to delete saved memories and stop new ones.
Who else receives it
Anthropic. Message content is transmitted to Anthropic, an AI provider, to perform the analysis. Anthropic acts as our processor under commercial terms that incorporate a data processing addendum and prohibit training on customer content. Those terms also permit Anthropic to use content to enforce its usage policies, which is a use we do not direct. Anthropic’s retention periods are described in our Privacy Policy.
Third-party messaging infrastructure provider. The consumer health data disclosed to this provider consists of message content that may reveal or relate to mental health, suicidal ideation, or self-harm. Associated data includes sender and participant identifiers, group and assigned-line information, and delivery metadata. The purposes of the disclosure are to transmit and route messages, associate messages with the correct group and line, report delivery status, and provide messaging infrastructure. The provider’s public terms may also permit it to use customer data to improve its systems. We therefore do not describe this provider as processing the information strictly on our behalf.
Categories of other recipients: a cloud database provider stores our records, and an application hosting provider runs the service.
We do not share consumer health data with affiliates.
We do not sell consumer health data. We do not share it for advertising. We do not disclose the classification result, referral status, or the private referral to the group, the Admin, or any other member.
How long we keep it
The classification itself is transient and is not stored.
The message analysed is subject to the retention described in our Privacy Policy.
We keep a de-identified record of how often crisis resources were sent, containing the event timestamp, whether a referral was sent, the dispatch outcome, and the messaging provider’s acknowledgement. It does not contain the message, the phone number, the member, or the group.
Referral messages are normally limited to one per person in a rolling 60-minute period. A duplicate may be sent if we cannot confirm whether an earlier referral was accepted by the messaging provider, or if the temporary record used to suppress a repeat could not be written. It is a keyed hash of the phone number, expires automatically after 60 minutes, and is not available to Admins.
Your consent
We ask for your affirmative consent before Buddie participates in your group. The disclosure you receive states that messages are automatically checked for self-harm risk, that this check is performed by Anthropic, and that a flagged message results in a private crisis-resource message.
Replying YES, or YES NO MEMORY, requests Buddie’s participation, including the mandatory safety check. Where we have clear reason to believe a participant is under 13, we do not run the check on their messages regardless of any reply.
Messages from members who have not joined are received by a third-party messaging infrastructure provider and transiently by Meet Buddie so we can identify the sender and recognize consent, opt-out, and identity-confirmation messages. The provider receives the message content, sender and participant identifiers, group and assigned-line information, and delivery metadata. Meet Buddie does not add the message content to its message database, send it to an AI provider, run crisis or reply-moderation classification on it, use it for memory or response generation, or include the content in analytics. We may keep content-free operational records tied to the member and group.
Withdrawing consent
Text STOP at any time. We will stop analysing your messages and stop messaging you. You may also email support@meetbuddie.com.
Withdrawal takes effect on receipt. It does not affect processing that already occurred.
Your rights
You have the right to confirm whether we collect, share, or sell your consumer health data; to access it, including a list of third parties it has been shared with; to withdraw consent; and to have it deleted.
When you ask us to delete consumer health data, we will delete it from our records and notify each third-party recipient to which we disclosed it, and request deletion as required by applicable law. Deletion from backups may take up to six months.
Email support@meetbuddie.com with enough information to identify your phone number. We may take reasonable steps to verify you control it.
We respond within 45 days. Where the law permits additional time we will tell you and explain why.
If we refuse, we will tell you why and how to appeal. Reply to our response or write to support@meetbuddie.com with “appeal” in the subject. We respond within 45 days and will tell you how to contact your state attorney general.
Changes
We will post any updated version here with a new effective date.
Contact
Meet Buddie L.L.C.
support@meetbuddie.com
