Bramwell · Privacy

Consumer Health Data Privacy Policy

bramwell.app/privacy/consumer-health-data
Effective 2026-05-02 · Last reviewed 2026-05-02

This is a separate policy required by Washington's My Health My Data Act (MHMDA, RCW 19.373) and Maryland's Online Data Privacy Act (MODPA, Md. Code Ann. Comm. Law §14-4601 et seq.). It is linked from the Bramwell homepage and surfaced inline before any health-context field is collected — not buried in the main privacy policy.

This policy applies only to the optional medical-context field on the $20 Cloud Pro tier. If you have not opted in to that field, this policy is not relevant to you and Bramwell holds no consumer health data about you.

Status, August 2026: the Cloud Pro tier is not yet available for purchase, so no one has been able to opt in to the medical-context field and Bramwell currently holds no consumer health data about anyone.

What "consumer health data" means here

Under WA MHMDA §19.373.010(8) and Maryland MODPA §14-4601(g), "consumer health data" includes data that identifies a consumer's past, present, or future physical or mental health status. Practically, in Bramwell, this is the medical-context field — a free-text field where you can describe relevant health conditions, ongoing treatments, allergies, medications, accessibility considerations, or any other health information that helps Alfred run errands well.

Bramwell is not a HIPAA covered entity, business associate, or healthcare provider. We are a personal-assistant SaaS, and the medical-context field is collected from you (not from a healthcare provider) on a voluntary opt-in basis at the $20 tier. WA MHMDA and MODPA apply to our handling of this data regardless — both statutes are deliberately broader than HIPAA on the consumer side.

Opt-in consent

The medical-context field is gated behind an explicit consent screen on Screen 6 of the Cloud Pro onboarding wizard. The consent screen presents:

  1. The exact wording of this policy (or a link to it on the same page)
  2. A clear "I consent" checkbox — unchecked by default
  3. A clear "Skip — Alfred will ask in chat when he needs this" alternative
  4. A timestamp + IP address + user-agent record stored alongside the consent flag, kept for the lifetime of the account

You can revoke consent at any time in account settings. Revocation triggers immediate hard-delete of the medical-context field across all storage layers (profile rows + Alfred's memory + any errand notes that reference it). The 1-year audit-log retention applies to the fact that an errand ran (per the Profile Data Privacy Notice) but the medical-context content itself is purged.

If you skip the field at onboarding, Alfred will ask once in chat at the moment of need (e.g., "When are you next available for a dental appointment?" — without surfacing health context). The field never gets written without your explicit consent gesture in that exact session.

What we do NOT do with consumer health data

These are the affirmative commitments specific to consumer health data, beyond the general profile-data commitments:

Storage

Consumer health data is encrypted at rest using AES-256-GCM via the existing CredentialEncryption path (the same mechanism that protects user passwords for third-party services). The key is per-installation in self-hosted Local Pro deployments, and per-tenant in the Cloud Pro deployment. The medical-context field is never stored in plaintext, never logged, never included in error reports, and never sent to any system other than the ZDR-only inference endpoint described above when an errand actually requires it.

Storage location:

Your rights

Per WA MHMDA, MODPA, and CCPA/CPRA, you have the right to:

  1. Confirm we hold consumer health data about you — visible in your account settings page; the medical-context field is shown verbatim
  2. Receive a copy of your consumer health data — exportable from account settings as JSON, with all metadata
  3. Delete your consumer health data — one-click, in account settings; hard-delete within 7 days operational target across all layers; deletion certificate (PDF) confirms the purge
  4. Withdraw consent for collection of consumer health data — same control as above; revocation purges the field
  5. Appeal a denied request[email protected], response within 45 days per CCPA timing

Disclosure when consumer health data is shared

WA MHMDA §19.373.040(2) requires that any sharing of consumer health data with a processor be disclosed. Bramwell uses these processors for consumer health data specifically:

Consumer health data processors
ProcessorPurposeData scope
AWS RDS (us-east-1)Database storageEncrypted at rest only
Postgres encryption-at-rest layerStorageBytes-only, no plaintext access
The ZDR-only inference endpoint of (Anthropic / OpenAI / Google / AWS, depending on errand routing)Per-errand inference when medical-context is relevant to the taskSingle-prompt only, no retention, no training

We do not share consumer health data with anyone else. We do not sell it. We do not allow third-party advertising tags or analytics on any page that surfaces consumer health data.

How to revoke consent

  1. Open Bramwell account settings → Privacy
  2. Click "Revoke medical-context consent"
  3. Confirm
  4. Receive deletion certificate (PDF) within 7 days

Contact

Health-data privacy questions: [email protected] (subject line: "MHMDA")

Maryland-specific requests: same address

Washington-specific requests: same address; cc the WA AG consumer-protection division if you want a regulator copy

Disputes

If we cannot resolve a consumer health data complaint, you may file with:

This policy is a Phase 1 launch document. Material changes are notified to consenting users by email and via in-app banner with a 30-day comment window before they take effect.