Consumer Health Data Privacy Policy
What we collect: almost nothing, on purpose.
What we collect, and why
When you ask Substrate a question, we answer it and forget it. The question is processed in memory and never written to disk. We don't have a record of what you asked.
We count questions in aggregate — that "magnesium + sleep" was asked 1,400 times last month — so we know which evidence to review next. Those counts contain no identifier of any kind, and our database physically refuses to store any question asked by fewer than 25 people, because a rare enough question is a person. This is a schema constraint, not a policy promise — see independence for the technical detail.
If you save supplements to a stack or watchlist, or create an action plan, personal experiment, or check-ins, that's data about you and we store it. A plan may contain the goal, protocol, monitoring, adherence, experiment protocol and periods, consent and eligibility inputs, measurements, side effects, product/batch, cost, other changes and reason for stopping that you provide. This is the consumer health data we hold about a named person.
Sources of this data
Directly from you: the supplements/outcomes you save to a stack or watchlist and the plan, experiment, or check-in details you choose to record. Nothing is purchased, inferred from third-party data brokers, or derived from tracking.
Categories shared, and with whom
We share consumer health data with no one. There is no third party. We run no advertising pixels, no session replay, and no ad-tech tags on any page where you're asking about your health.
Your rights (real endpoints, not just policy prose)
You can confirm, access, withdraw consent for, and delete your consumer health data.
- Confirm + access: signed in? GET /api/v1/me/health-data — returns every row of consumer health data we hold about you, in JSON, no hidden fields.
- Withdraw + delete: signed in? Send DELETE to the same URL. Cascading delete across every table (experiments, periods, plans, check-ins, stacks, watchlist, credentials, submissions, contributor row itself). We keep no backup — after that call, we can't restore your data even if you ask us to.
- Not signed in / prefer email: email the founder and the request is honored the same way, same SLA.
- Response SLA: 45 days per MHMDA. Typical response: same day. The API path is synchronous.
We can't sell your health data because we never collected it.