Health Data Privacy Policy

How FreeRxApp collects, protects, and uses your health information — and your rights under CCPA/CPRA, the Washington My Health My Data Act, and other applicable laws.

CCPA/CPRA Compliant AES-256 Encrypted De-Identified Data Right to Delete

Effective: April 16, 2026  ·  Version 1.0

Table of Contents

  1. Data We Collect
  2. How We De-Identify Data
  3. How We Use Your Data
  4. Who We Share Data With
  5. Data Architecture & Security
  6. Consent & Your Choices
  7. CCPA/CPRA Rights (California)
  8. Washington My Health My Data Act
  9. Connecticut Health Data Law
  10. Data Retention
  11. Security Measures
  12. FTC Health Breach Notification
  13. Cookies & Tracking
  14. Contact & Requests

1. Data We Collect

When you complete the FreeRxApp Health Assessment, we collect the following information:

Page 1 — Demographics

FieldTypePurpose
Age rangeNon-identifying category (e.g., "35–44")Risk scoring algorithm
GenderCategoryRisk scoring
ZIP codeGeographic area (not precise location)Regional health context
Height (inches)NumericBMI calculation
Weight (lbs)NumericBMI calculation
BMICalculated numericRisk scoring
Insurance typeCategoryResource matching
Household sizeCategoryResource matching

Page 2 — Lifestyle Factors

FieldTypePurpose
Exercise frequencyCategoryRisk scoring
Sleep quality1–5 scaleRisk scoring
Smoking statusCategory (Current/Former/Never)Risk scoring
Alcohol useCategoryRisk scoring
Diet typeCategoryRisk scoring
Stress level1–5 scaleRisk scoring

Page 3 — Current Health Conditions

FieldTypePurpose
Health conditionsMulti-select (e.g., Diabetes, Hypertension, Asthma)Risk scoring; audience segmentation
Condition detailsPer-condition: medication, specialist, durationRisk scoring
Seen a specialistBooleanRisk scoring
Treatment satisfaction1–5 scaleSwitch-readiness indicator (internal)
Last doctor visitCategory (e.g., "Within 6 months")Risk scoring

Page 4 — Family Health History

FieldTypePurpose
Parent conditionsMulti-selectGenetic risk flags
Sibling conditionsMulti-selectGenetic risk flags
Family early-onsetBooleanGenetic risk scoring
Early-onset conditionsMulti-selectGenetic risk scoring

Page 5 — Email Gate & Consent

FieldStoragePurpose
Email addressAES-256-GCM encrypted; stored separately from health dataDelivering your results; identity resolution for deletion requests
Consent recordTimestamp, consent version, text shownProof of affirmative consent
IP address (hashed)SHA-256 hash only — never stored in plaintextConsent proof; fraud prevention
No name collected. We do not ask for your first or last name. Your email address and health assessment responses are stored in separate database tables and are only joined for authorized operations such as honoring deletion requests.

2. How We De-Identify Data

Before your health information is used for advertising or research purposes, it is de-identified using the following methods:

3. How We Use Your Data

We do not use your data for: Employment decisions, insurance underwriting, credit decisions, or any purpose not described in this policy.

4. Who We Share Data With

Pharmaceutical companies, healthcare agencies, and demand-side advertising platforms receive only aggregate, de-identified audience segments — never individual health records.

Recipient TypeWhat They ReceiveWhat They Never Receive
Pharmaceutical advertisers Aggregate audience segments (e.g., "12,400 users with diabetes interest, age 45–64") Individual records, emails, names, raw health responses
Healthcare advertising agencies Aggregate segment data for campaign targeting Individual records
Demand-side platforms (DSPs) Anonymized segment identifiers for ad targeting Individual health records or personal identifiers
Analytics providers Page-level analytics (page views, events) without health data Health assessment responses
Service providers (hosting, database) Encrypted data at rest; no ability to read plaintext PII without encryption key Decrypted email addresses
We do not sell individual health records. If you opt out of the sale of your personal information (using the link below), your data will not be included in any audience segments shared with third parties.

5. Data Architecture & Security

Two-Table Architecture

Health data is physically separated from your email address in our database:

Encryption

7. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the following rights:

🔍

Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected about you.

🗑️

Right to Delete

Request deletion of your personal information. We will delete your email and anonymize your health assessment records.

🚫

Right to Opt-Out of Sale

Opt out of the sale of your personal information to third parties. Use the "Do Not Sell My Personal Information" link in our footer.

✏️

Right to Correct

Request correction of inaccurate personal information. Contact us at the address below.

⚖️

Right to Non-Discrimination

We will not discriminate against you for exercising any of these rights.

🎚️

Right to Limit Sensitive Data

Health information is "sensitive personal information" under CPRA. You may direct us to limit its use to providing the requested service.

To exercise these rights, email info@summitaudiencesegments.com or use the Do Not Sell page.

We will respond to verifiable consumer requests within 45 days (extendable to 90 days with notice). We do not charge a fee for reasonable requests.

Global Privacy Control (GPC)

We honor the GPC browser signal (Sec-GPC: 1). When we detect this signal, we automatically treat your visit as an opt-out of the sale of your personal information.

8. Washington My Health My Data Act

If you are a Washington State resident, the My Health My Data Act (effective July 2023) provides additional protections for health data:

9. Connecticut Health Data Law (SB 3 / PA 23-16)

Connecticut residents have the following rights under SB 3 (effective July 1, 2023):

To submit a request, email info@summitaudiencesegments.com with the subject line "Connecticut Privacy Request."

10. Data Retention

Data TypeRetention PeriodDeletion Process
Email address (encrypted)2 years from collection, or until deletion requestPermanently deleted from consents table
Health assessment responses2 years from completion, or until deletion requestAll fields set to NULL; session UUID retained for audit log only
Risk scores (health age, category risks)2 yearsDeleted with assessment record
Consent records5 years (required for legal proof of consent)Email removed; anonymized consent record retained per legal requirement
Deletion request records5 yearsRetained to demonstrate CCPA compliance; no health data retained in these records

11. Security Measures

12. FTC Health Breach Notification Compliance

FreeRxApp is operated by Summit Audience Segments, Inc. We are a personal health record (PHR) related entity as defined under the FTC Health Breach Notification Rule (16 CFR Part 318).

In the event of a breach of unsecured personally identifiable health information, we will:

Our security incident response plan is reviewed annually. Contact info@summitaudiencesegments.com to report a suspected security incident.

13. Cookies & Tracking

FreeRxApp uses the following cookies and tracking technologies:

NameTypePurposeConsent Required?
_sc_vidFirst-party, 1 yearAnonymous visitor ID for analytics (no health data attached)No — essential analytics
Session storageBrowser session onlyHealth assessment in-progress stateNo — essential functionality
Google Analytics (GA4)Third-partyPage-level analytics — does not track health responsesNo — no health data transmitted
Google AdSenseThird-partyDisplay advertising (non-targeted, not based on health data)No
Health pages are not cross-tracked. We do not attach health assessment responses to any advertising tracking pixel or third-party analytics event. Google Analytics receives only standard page view data (URL, referrer, device) — never your health quiz answers.

14. Contact & Data Requests

For all privacy requests, contact our data privacy team:

Subject line options to help us route your request quickly:

Exercise Your Privacy Rights

Delete your data, opt out of data sharing, or submit a right-to-know request.

Do Not Sell My Info Request Data Deletion

Contact: info@summitaudiencesegments.com