CONSUMER HEALTH DATA PRIVACY POLICY - That One Tech Company, LLC
Last Updated: July 23, 2026
This Consumer Health Data Privacy Policy ("Health Data Policy") supplements our general Privacy Policy. It applies specifically to "consumer health data" as that term is defined under the Washington My Health My Data Act (RCW 19.373), Nevada Senate Bill 370 (NRS 603A), and the Connecticut Data Privacy Act.
It describes what consumer health data That One Assistant ("Toa") may process, why, who receives it, and how you can exercise your rights.
Where this Health Data Policy and our general Privacy Policy address the same subject, this Health Data Policy controls for consumer health data.
Questions or requests: support@thatoneassistant.com.
Who This Policy Covers
This Health Data Policy applies to you if you are:
A resident of Washington State, or a natural person whose consumer health data is collected in Washington
A resident of Nevada
A resident of Connecticut
It applies whether you are a Toa account holder or a person whose information appears in an account holder's connected mailbox, calendar, contacts, or files.What Toa Is, and Why That Matters Here
Toa is a business productivity tool. It helps professionals manage email, calendar, and task workflows. It is not a health application, a wellness tracker, a symptom checker, or a medical service.
Three points follow from that, and they shape everything else in this policy:
We do not seek consumer health data. No feature of Toa asks for it, infers it, categorizes it, or acts on it as health information.
We restrict who can sign up. Toa's registration process does not permit selection of healthcare, medical, or health-insurance industry classifications, and our terms prohibit use by businesses operating in those sectors.
We prohibit entering it. Account holders are contractually prohibited from entering health or medical information into Toa's free-text profile fields.
Nonetheless, because Toa reads and acts on the contents of a mailbox and calendar an account holder connects, health-related information may be present in that content. This policy explains what happens when it is.What Counts as Consumer Health Data
Under the laws listed above, consumer health data means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status. It can include, among other things, health conditions, diagnoses, treatments, procedures, medications, symptoms, bodily functions, reproductive or sexual health information, gender-affirming care information, biometric or genetic data, precise location that could indicate an attempt to obtain health services, and any information used to infer any of the above.Categories of Consumer Health Data We May Collect, and Why
Categories. We do not collect consumer health data as a distinct category, and we do not maintain a health data file, profile, or classification for any person. Consumer health data may nonetheless reach our systems in the following forms:
Email and message content. The body, subject line, and metadata of messages in a connected mailbox, where those messages happen to discuss a health condition, appointment, treatment, accommodation, or similar subject.
Attachment and connected file content. The contents of an attachment or a Google Drive or OneDrive file that an account holder asks Toa to read or attach.
Calendar entries. Event titles, descriptions, times, locations, and attendees, where an entry happens to relate to a medical appointment or similar.
Task and note content. Where an account holder or Toa saves any of the above into a task or note.
Free-text profile information. Where an account holder enters such information contrary to our terms.
Purpose, and how it is used. We process this content for one purpose only: to perform the specific action the account holder requested, such as drafting a reply, summarizing a message, scheduling an event, or extracting a task.
We do not use it to determine, infer, or record health status. We do not use it for advertising, targeted advertising, profiling, product development, or model training. We do not use it to build audiences or segments. We do not use it to make decisions about any person.Categories of Sources
We collect the information described above from:
The account holder, when they enter text into Toa or save content into a task, note, or profile field.
Connected third-party accounts, namely Google (Gmail, Google Calendar, Google Contacts, Google Drive) and Microsoft (Outlook, Exchange, Calendar, OneDrive), where the account holder has authorized that connection.
We do not purchase consumer health data, obtain it from data brokers, derive it from advertising networks, or collect it from any source other than those listed above.Sharing: We Do Not Share Consumer Health Data
We do not share consumer health data with any third party or affiliate, as "share" is defined under the Washington My Health My Data Act and Nevada Senate Bill 370. We have not done so, and we do not do so.
Disclosure to our processors. Where an account holder asks Toa to act on a message, calendar entry, or file, the content needed to perform that action is disclosed to processors acting on our behalf under binding written contracts. If health-related information is present in that content, it is disclosed along with it.
Washington law excludes disclosure to a processor from the definition of "share" where that disclosure is made to provide the goods or services the consumer requested, in a manner consistent with the purpose for which the data was collected. Our disclosures to processors meet that condition: content is disclosed only to carry out the action the account holder requested, and for no other purpose.
Our processors are:
Anthropic, PBC. Operates the Claude models Toa uses and generates the requested output, under its Commercial Terms of Service and Data Processing Addendum.
Microsoft Corporation. Provides the Microsoft Azure AI Foundry access layer, authentication, and billing through which we reach those models. Microsoft receives billing, usage, and transaction metadata.
Google LLC and Microsoft Corporation. In their capacity as the provider of the account an account holder has connected, and only to deliver the email, calendar, contact, and file features requested.
Each processor is bound by a written contract that instructs how it may process data on our behalf, limits the actions it may take, prohibits the use of any content to train generalized artificial intelligence or machine learning models, and requires it to assist us in meeting our obligations under this policy and applicable law.
Affiliates. We do not disclose consumer health data to any affiliate.
Advertising and data brokers. We do not disclose consumer health data to advertisers, data brokers, ad networks, or analytics providers. Google Analytics runs only on our public marketing website and has no access to any content processed by Toa.
Legal process. We may disclose information where required by law, in response to lawful process, or to establish or defend legal claims. We will not disclose consumer health data to law enforcement or any government authority in response to a request that is not legally binding, and we will seek to notify the affected person where we are permitted to do so.
What this means for your rights request. Because we do not share consumer health data, a request under Section 10 for a list of third parties and affiliates that have received your consumer health data will return no entries. In place of that list, we will identify the processors above and confirm what was disclosed to them and why. A deletion request is still passed through to each processor, as described in Section 10.1.We Do Not Sell Consumer Health Data
We have never sold consumer health data, and we do not sell it. We do not exchange it for monetary consideration or for any other valuable consideration.
Because we do not sell consumer health data, we do not seek or maintain the valid authorization that Washington and Nevada law would require before any such sale.Our Legal Basis for Processing
Washington and Nevada law permit the collection of consumer health data in two circumstances: with the consumer's consent, or to the extent necessary to provide a product or service that the consumer has requested.
We rely on the second. Where health-related information reaches our systems, it does so because it is contained in a mailbox, calendar, or file that an account holder has connected and asked Toa to act on. Processing it is necessary to deliver the action requested, and we do not process it for any purpose beyond that action.
As described in Section 6, we do not share consumer health data, so the separate consent those laws require before sharing does not arise. We do not collect consumer health data for any secondary purpose. If either of those things ever changes, we will update this policy first and obtain separate consent for collection and separate consent for sharing before proceeding.
Connecticut. Under the Connecticut Data Privacy Act, consumer health data is sensitive data and processing requires consent. We do not knowingly process consumer health data for any purpose other than delivering the requested feature, and we do not use it for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects.Retention
Consumer health data is not retained as a separate category. It is retained only as part of the content described in Section 4, under the schedule in our Privacy Policy:
AI conversation records are automatically deleted once older than 30 days, by a pruning job that runs daily.
Session data, including email and attachment context, is released as the working session closes and cleared by a scheduled purge.
Task, note, contact, and profile data is retained until the account holder deletes it or deletes the account.
Content transmitted to our AI provider is retained by that provider under its own published terms rather than under our control. Under Anthropic's current published policies, inputs and outputs for commercial API traffic are deleted within 30 days, subject to exceptions. Content flagged by Anthropic's automated trust and safety systems as a potential Usage Policy violation may be retained for up to 2 years, with related classification scores retained for up to 7 years.
When an account is deleted, all content associated with it is permanently destroyed and cannot be recovered.Your Rights
10.1 Washington Residents
Under the My Health My Data Act, you have the right to:
Confirm whether we are collecting, sharing, or selling your consumer health data, and to access that data
Obtain a list of all third parties and affiliates with whom we have shared or sold your consumer health data, together with an active means of contacting each one
Withdraw consent to our collection and sharing of your consumer health data
Have your consumer health data deleted from our systems, including archived and backup systems
Where you request deletion, we will delete your consumer health data from our own systems and will notify each of our processors and third parties of the request and direct them to delete it as well.
10.2 Nevada Residents
Under Nevada Senate Bill 370, you have the right to:
Confirm whether we are collecting or sharing your consumer health data, and to access that data
Obtain a list of the third parties with whom we have shared your consumer health data
Withdraw consent to our collection and sharing of your consumer health data
Have your consumer health data deleted
10.3 Connecticut Residents
Under the Connecticut Data Privacy Act, you have the right to:
Confirm whether we process your personal data, and to access it
Correct inaccuracies
Delete personal data we hold about you
Obtain a portable copy of data you provided to us
Opt out of targeted advertising, sale of personal data, and certain profiling. We do not engage in any of these.
Withdraw consent to the processing of sensitive data, including consumer health dataHow to Exercise Your Rights
Submitting a request. Email support@thatoneassistant.com with the subject line "Consumer Health Data Request." Tell us which right you are exercising and which state you reside in.
Verification. We will verify your identity before acting on a request. If you hold a Toa account, verification normally means confirming control of the email address associated with that account. If you do not hold an account and believe your information appears in an account holder's mailbox or calendar, tell us the email address or identifying detail we should search for, and we will verify you to the extent we reasonably can before acting.
Response times. We will respond to Washington and Connecticut requests within 45 days, and to Nevada requests within 60 days. Where reasonably necessary, we may extend those periods as permitted by the applicable law and will tell you before we do.
Cost. We will not charge you for exercising these rights, and you will not receive different pricing, service quality, or treatment for having done so.
Authorized agents. You may use an authorized agent. We may require proof of the agent's authority and may require you to verify your identity directly.
Appeals. If we decline your request, we will tell you why in writing. You may appeal by replying to our response or writing to us at the address in Section 15 and stating that you wish to appeal. We will inform you in writing of our decision on appeal and the reasons for it, within the period required by applicable law. If your appeal is denied, you may contact your state Attorney General:
Washington: atg.wa.gov/file-complaint
Nevada: ag.nv.gov/Complaints
Connecticut: portal.ct.gov/AGLimits on What We Can Provide
We want to be straightforward about two constraints.
Deleted content cannot be recovered or produced. When an account is deleted, or when content passes the retention periods in Section 9, it is permanently destroyed. If you request access to content that has already been deleted, we cannot produce it.
We do not control our AI provider's retention. Where content has been transmitted to our AI provider, we will notify that provider of a deletion request and direct it to delete the associated data. We cannot independently confirm deletion within that provider's systems, and we cannot compel deletion of content the provider has retained under a legal obligation or under its trust and safety processes.Geofencing
We do not use geofencing. We do not establish a virtual boundary around any healthcare facility, mental health facility, reproductive health facility, or any other location, and we do not use location data to identify or track any person seeking health care services, to collect consumer health data, or to send notifications or advertisements relating to consumer health data.
Approximate location from website analytics. Google Analytics, which runs only on our public marketing website, derives an approximate location from a visitor's IP address at the country, state or region, and city level. This is not precise location information as those laws define it, it is not collected within the Toa application, and it is not associated with any content Toa processes. We use it only to understand aggregate website traffic. We do not use it to infer health status, to identify anyone seeking health services, or for advertising.Employee and Processor Access
Access to account content within our systems is restricted to personnel who need it to operate the service, and is limited to (a) access an account holder specifically requests or authorizes, such as when they ask us for support, (b) access necessary for security purposes such as investigating abuse, (c) access required to comply with applicable law, and (d) access to aggregated or de-identified data.
Each processor we engage is bound by written terms requiring confidentiality, limiting use to providing the service to us, and prohibiting the use of any content to train generalized artificial intelligence or machine learning models.Changes to This Policy
We may update this Health Data Policy. The "Last Updated" date reflects the effective revision date. We will not collect, use, or share any category of consumer health data not disclosed in this policy at the time of collection without first updating this policy and obtaining consent where required.Contact Us
That One Tech Company, LLC
14800 Quorum Dr, Suite 415
Addison, TX 75254
United States
Email: support@thatoneassistant.com
