Bramwell · Privacy
Consumer Health Data Privacy Policy
This is a separate policy required by Washington's My Health My Data Act (MHMDA, RCW 19.373) and Maryland's Online Data Privacy Act (MODPA, Md. Code Ann. Comm. Law §14-4601 et seq.). It is linked from the Bramwell homepage and surfaced inline before any health-context field is collected — not buried in the main privacy policy.
This policy applies only to the optional medical-context field on the $20 Cloud Pro tier. If you have not opted in to that field, this policy is not relevant to you and Bramwell holds no consumer health data about you.
Status, August 2026: the Cloud Pro tier is not yet available for purchase, so no one has been able to opt in to the medical-context field and Bramwell currently holds no consumer health data about anyone.
What "consumer health data" means here
Under WA MHMDA §19.373.010(8) and Maryland MODPA §14-4601(g), "consumer health data" includes data that identifies a consumer's past, present, or future physical or mental health status. Practically, in Bramwell, this is the medical-context field — a free-text field where you can describe relevant health conditions, ongoing treatments, allergies, medications, accessibility considerations, or any other health information that helps Alfred run errands well.
Bramwell is not a HIPAA covered entity, business associate, or healthcare provider. We are a personal-assistant SaaS, and the medical-context field is collected from you (not from a healthcare provider) on a voluntary opt-in basis at the $20 tier. WA MHMDA and MODPA apply to our handling of this data regardless — both statutes are deliberately broader than HIPAA on the consumer side.
Opt-in consent
The medical-context field is gated behind an explicit consent screen on Screen 6 of the Cloud Pro onboarding wizard. The consent screen presents:
- The exact wording of this policy (or a link to it on the same page)
- A clear "I consent" checkbox — unchecked by default
- A clear "Skip — Alfred will ask in chat when he needs this" alternative
- A timestamp + IP address + user-agent record stored alongside the consent flag, kept for the lifetime of the account
You can revoke consent at any time in account settings. Revocation triggers immediate hard-delete of the medical-context field across all storage layers (profile rows + Alfred's memory + any errand notes that reference it). The 1-year audit-log retention applies to the fact that an errand ran (per the Profile Data Privacy Notice) but the medical-context content itself is purged.
If you skip the field at onboarding, Alfred will ask once in chat at the moment of need (e.g., "When are you next available for a dental appointment?" — without surfacing health context). The field never gets written without your explicit consent gesture in that exact session.
What we do NOT do with consumer health data
These are the affirmative commitments specific to consumer health data, beyond the general profile-data commitments:
- We do not sell consumer health data. Maryland MODPA bans this outright; we extend the ban to all states.
- We do not share consumer health data with advertisers, data brokers, or any third party for marketing purposes. Period.
- We do not derive health inferences from non-health data (e.g., we don't infer "this user is pregnant" from shopping patterns and store that as health data). The medical-context field is the only place consumer health data is created.
- We do not geofence health-related locations (clinics, abortion-care providers, mental-health services). Bramwell holds no precise GPS location data — period — and would not implement geofencing if we did.
- We do not transmit consumer health data to LLM providers under any data-retention terms. Even our zero-data-retention contracts with Anthropic, OpenAI, Google, and AWS are not used for medical-context queries — those queries route to a separate ZDR-only inference endpoint with audit logging that proves the prompt was not retained.
- We do not share consumer health data with law enforcement absent a valid subpoena, search warrant, or court order, and we will challenge overbroad requests in court when there's a credible legal basis to do so. We notify you of any law-enforcement request affecting your data unless we are legally barred from doing so.
Storage
Consumer health data is encrypted at rest using AES-256-GCM via the existing CredentialEncryption path (the same mechanism that protects user passwords for third-party services). The key is per-installation in self-hosted Local Pro deployments, and per-tenant in the Cloud Pro deployment. The medical-context field is never stored in plaintext, never logged, never included in error reports, and never sent to any system other than the ZDR-only inference endpoint described above when an errand actually requires it.
Storage location:
- Cloud Pro (us-east-1): AWS RDS Postgres in a private VPC, AES-256 at rest, TLS 1.3 in transit, restricted IAM
- Local Pro: the user's own Postgres on the user's own machine, our scope ends at the encryption envelope
Your rights
Per WA MHMDA, MODPA, and CCPA/CPRA, you have the right to:
- Confirm we hold consumer health data about you — visible in your account settings page; the medical-context field is shown verbatim
- Receive a copy of your consumer health data — exportable from account settings as JSON, with all metadata
- Delete your consumer health data — one-click, in account settings; hard-delete within 7 days operational target across all layers; deletion certificate (PDF) confirms the purge
- Withdraw consent for collection of consumer health data — same control as above; revocation purges the field
- Appeal a denied request — [email protected], response within 45 days per CCPA timing
Disclosure when consumer health data is shared
WA MHMDA §19.373.040(2) requires that any sharing of consumer health data with a processor be disclosed. Bramwell uses these processors for consumer health data specifically:
| Processor | Purpose | Data scope |
|---|---|---|
| AWS RDS (us-east-1) | Database storage | Encrypted at rest only |
| Postgres encryption-at-rest layer | Storage | Bytes-only, no plaintext access |
| The ZDR-only inference endpoint of (Anthropic / OpenAI / Google / AWS, depending on errand routing) | Per-errand inference when medical-context is relevant to the task | Single-prompt only, no retention, no training |
We do not share consumer health data with anyone else. We do not sell it. We do not allow third-party advertising tags or analytics on any page that surfaces consumer health data.
How to revoke consent
- Open Bramwell account settings → Privacy
- Click "Revoke medical-context consent"
- Confirm
- Receive deletion certificate (PDF) within 7 days
Contact
Health-data privacy questions: [email protected] (subject line: "MHMDA")
Maryland-specific requests: same address
Washington-specific requests: same address; cc the WA AG consumer-protection division if you want a regulator copy
Disputes
If we cannot resolve a consumer health data complaint, you may file with:
- Washington Attorney General's Office — atg.wa.gov/file-complaint (MHMDA private right of action attaches via WA Consumer Protection Act)
- Maryland Attorney General's Office — marylandattorneygeneral.gov (MODPA enforcement)
- Your state attorney general's office for any state with an applicable comprehensive privacy law
This policy is a Phase 1 launch document. Material changes are notified to consenting users by email and via in-app banner with a 30-day comment window before they take effect.