Effective Date: June 22, 2026 · Version 1.0
This Consumer Health Data Privacy Policy is required by the Washington My Health My Data Act (“MHMDA”) and applies to “consumer health data” as that law defines it. It supplements our general Privacy Policy; where this policy and the Privacy Policy differ on consumer health data, this policy controls. Although MHMDA is a Washington law (and Nevada has a similar law), we apply the protections described here to all Labcoat users, wherever you live.
Labcoat is a direct-to-consumer service and is not subject to HIPAA. We are not a healthcare provider, health plan, or business associate of one.
We collect the following categories of consumer health data, and only to provide our service to you:
We collect consumer health data from a single source: directly from you, when you create your health profile and upload or enter information. We do not receive your consumer health data from healthcare providers, labs, insurers, data brokers, or any other third party.
We use consumer health data only to:
We do not use consumer health data for advertising, marketing, or any purpose beyond providing the service to you.
We share consumer health data only with the service providers (“processors”) required to operate Labcoat. We share it for processing on our behalf, under contract, and not for their own purposes.
Categories shared: your uploaded lab files, relevant health profile data, and your chat questions are shared for AI analysis; your full profile, reports, chat history, and consent records are shared for storage.
Categories of third parties (and specific entities) we share with:
Our payment processor, Stripe, receives your email and purchase details only — it never receives consumer health data. We have no corporate affiliates with whom we share consumer health data, and we do not share it with advertisers, data brokers, or analytics providers. We may disclose data if required by valid legal process, and will notify you unless legally prohibited.
We have never sold, and will never sell, your consumer health data. MHMDA prohibits the sale of consumer health data without a separate, valid authorization; we simply do not engage in any sale, so no such authorization is sought or needed.
With respect to your consumer health data, you have the right to:
You can access and delete your data directly from your dashboard, or exercise any of these rights by emailing privacy@labcoat.net. Because every consent is necessary to provide the service, withdrawing consent means you will no longer be able to use Labcoat. We respond to verified requests within 30 days. If we decline a request, you may appeal by replying to our response; if we deny your appeal, you may contact the Washington State Attorney General. We will never discriminate against you for exercising these rights.
We do not use geofences around any healthcare facility, and we do not use location data to identify, track, collect data from, or send notifications to consumers related to their consumer health data.
For any question about this policy or to exercise your rights: privacy@labcoat.net.
Questions? Contact us at privacy@labcoat.net