Washington Consumer Health Data Privacy Policy
Effective date: August 14, 2026
This policy applies to Washington consumers and individuals whose consumer health data is collected in Washington, to the extent the Washington My Health My Data Act (RCW Chapter 19.373) applies. For information about AvoPet’s other personal information practices, see the “AvoPet Privacy Policy.” AvoPet is not a medical provider and does not claim to be a HIPAA-covered entity.
1. Purpose of This Policy
This notice explains how AvoPet collects, uses, shares, stores, and deletes consumer health data under Washington’s My Health My Data Act. It applies only where Washington law applies and does not mean Washington law governs every user worldwide.
2. Categories of Consumer Health Data
AvoPet may process the following categories of consumer health data. Because Washington’s definition of consumer health data can broadly include information processed to associate or identify health information, linking and administrative information is also listed below.
Profile, body, and diet information
- Gender
- Age range
- Diet goal
- Optional target weight
- Optional current weight
Meal information
- Meal image data taken with the camera
- Meal type
- Meal date
- Post-meal mood
- Setback factors
- Meal diary notes
Analysis and inferences
- AI meal determinations
- Nutritional-balance feedback
- Analysis of meal and weight changes
- Health- or diet-related inferences generated from the information above
Linking and administrative information
- Health data consent status
- Health data request and processing history
- Account identifiers such as the Supabase user UUID used to associate health data with a specific user record
AvoPet does not send meal photos, health profile information, current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters. Separately, identifiers used to link or administer consumer health data are included in this category for transparency.
AvoPet does not collect the following:
- Photos selected from your gallery
- Medical diagnosis records
- Prescription records
- Genetic information
- Biometric information
- Precise location data used to identify visits to healthcare facilities
3. Sources of Collection
- Information you enter in your profile and meal diary
- Meal images you take directly with the in-app camera
- Information generated during meal verification and app use
- AI determinations and feedback generated through OpenAI meal analysis
- Linking and administrative information created during Supabase authentication, storage, and request handling
AvoPet does not collect consumer health data from AdMob, Apple account linking, or Google account linking.
4. Purposes of Collection and Use
AvoPet collects and uses consumer health data for the following purposes:
- Providing health profile features
- Meal verification
- AI meal analysis and feedback
- Providing the meal diary
- Analyzing weight and meal changes
- Providing AvoPet feeding and health features
- Managing health data consent status
- Processing access, deletion, and appeal requests for health data
- Security, troubleshooting, and complying with legal obligations
AvoPet does not use consumer health data for the following purposes:
- Personalized advertising targeting
- Providing data to data brokers
- Independent third-party marketing
- Selling consumer health data
5. Shared Data and Recipients
The external services that process the app’s health content—such as meal photos, health profile information, and meal records—are Supabase and OpenAI. AvoPet has no affiliates with which it shares consumer health data, and AvoPet does not sell consumer health data.
| Recipient | Purpose | Categories that may be processed |
|---|---|---|
| Supabase Inc. | Anonymous authentication, database, private meal photo storage, Edge Functions, and health data request handling | User UUID, profile health information, meal records, meal images, AI determinations and feedback, weight and meal diary data, and consent and request records |
| OpenAI, L.L.C. | AI meal analysis you request | Meal image data, gender, age range, and diet goal |
AvoPet does not send Supabase user UUIDs, signed URLs, Storage paths, nicknames, email addresses, pet or gameplay information, or full meal diary histories to OpenAI. AvoPet sends OpenAI API requests with store set to false and does not separately retain an OpenAI response ID. Setting store to false does not constitute Zero Data Retention. OpenAI may retain limited information for safety, abuse prevention, or legal obligations for the periods described in its applicable policies. Supabase and OpenAI process data only as needed to provide the services AvoPet requests.
- AvoPet does not send meal photos, health profile information (gender, age range, or diet goal), current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters.
- For its initial iOS release, AvoPet does not request ATT authorization or access to the IDFA, and configures AdMob requests for non-personalized ads only. Before requesting ads, the app updates UMP consent information and checks canRequestAds.
- Even when ads are requested as non-personalized, the Google Mobile Ads SDK may process an IP address, approximate location, app- or device-scoped identifiers, advertising and app interactions, and performance or diagnostic information for ad delivery, measurement, frequency capping, and fraud prevention.
- AvoPet does not disclose health profile or meal content to Apple or Google account linking.
6. Consent and Withdrawal
- Before you enter a profile, AvoPet shows a health data consent screen.
- Health profile, meal verification, AI analysis, meal diary, and analysis features are provided only if you consent.
- If you do not consent, you can still adopt a pet and use general gameplay features that do not rely on health features.
- You can withdraw consent or consent again in Settings.
- If you withdraw consent, AvoPet stops future collection of consumer health data and stops AI analysis.
- Withdrawing consent does not automatically delete existing data.
- Deleting existing data requires a separate health data deletion request or account deletion.
Processing by Supabase and OpenAI occurs only as needed to provide the health features you request. AvoPet does not claim that a separate sharing-consent screen exists beyond what is currently implemented.
7. Rights of Washington Consumers
Where applicable, consumers may have the right to:
- Confirm whether AvoPet collects, shares, or sells consumer health data
- Access consumer health data
- Obtain a list of third parties and affiliates with which health data has been shared or sold, and how to contact them
- Withdraw consent to future collection or sharing of health data
- Request deletion of consumer health data
- Appeal a refused request
- Not be unlawfully discriminated against for exercising these rights
Because AvoPet does not sell consumer health data, there are no sale recipients. The external services that currently process the app’s health content for requested services are Supabase and OpenAI.
8. How to Submit a Request
The primary authenticated request method is the health data request feature in AvoPet app Settings. That feature authenticates you with your current Supabase session. AvoPet does not require you to create a new account to exercise these rights, and your existing app session may be used for authentication.
Supported in-app requests include:
- Access your health data
- Delete health data
- Appeal a refused request
Supplemental contact methods are email at avopet.support@gmail.com and phone at +82 10-4491-7410. If you lose access to your app session, you may contact us by email or another available method. If we cannot authenticate a request, we may ask only for additional information reasonably necessary to verify it. AvoPet does not promise to provide sensitive health data by email alone.
For instructions on submitting a request and managing your privacy choices, see Privacy Choices.
9. Response Timeframes, Fees, and Appeals
The timeframes below apply only to requests covered by this Washington consumer health data notice. They do not mean the same 45-day standard applies to the entire United States or to other countries.
- AvoPet responds to rights requests without undue delay and no later than 45 days after receipt.
- If reasonably necessary because of the complexity and number of requests, AvoPet may extend the period once by up to 45 days.
- If extended, AvoPet will notify you of the extension and the reason within the first 45 days.
- Identity-verification steps do not automatically extend the 45-day response timeframe.
- Providing information is free up to twice per consumer per year.
- For requests that are manifestly unfounded, excessive, or repetitive, AvoPet may charge a reasonable fee or refuse the request and will explain the basis for doing so.
- AvoPet provides an appeal process for refused requests.
- Appeals receive a written response within 45 days of receipt.
- If an appeal is denied, you may file a complaint with the Washington Attorney General. Official guidance is available at https://www.atg.wa.gov/file-complaint.
10. Deletion and Backups
When an authenticated deletion request is processed, a health-data deletion Edge Function deletes the requested consumer health data directly from AvoPet’s operational Supabase database and Storage, and the request is marked completed only after that deletion succeeds. Where required by applicable law, AvoPet may notify OpenAI through OpenAI’s official support or privacy-request channels and may keep limited operational records of that notice or related handling. AvoPet does not represent that such notice automatically results in the immediate deletion of records that OpenAI may retain for security, abuse-prevention, or legal purposes. Data remaining in backup or archival systems may take longer to delete because of restore cycles and similar operational constraints, but under this Washington standard AvoPet does not retain such residual data for more than six months after an authenticated deletion request.
Scope of Health Data Deletion
Health data deletion is separate from full account deletion. The health data covered by the request—including any results previously provided in response to a data access request—is deleted from AvoPet’s operational database and Supabase Storage. The items deleted or reset include:
- Meal photos
- Meal records
- Meal diary entries
- Verification attempts
- Gender
- Age range
- Diet goal
- Target weight
- Current weight
- Health data results previously provided through an access request
- Any other health data payloads or attachments covered by the deletion request
- Existing health-data processing consent history (upon successful deletion)
While a health-data deletion request is being processed, the existing consent status remains in effect. Once the requested health data has been successfully deleted and the request is completed, AvoPet also deletes the existing health-data processing consent history and resets the health-data consent status to not consented. AvoPet does not create a new withdrawn or declined consent record solely to record the deletion. If the user later opens a health feature, the consent screen is shown, and a new consent record is created only if the user consents again.
The following items are retained:
- Auth account
- Nickname
- Pet
- Collection entries
- Adoption rights
- Items and general gameplay information
- Limited request-processing information, such as request ID, request type, submission and completion times, and processing status
To document the handling of privacy-rights requests and comply with legal obligations, AvoPet may retain limited request-processing information, such as the request ID, request type, submission and completion times, and processing status. This record does not contain deleted health data, access results, attachments, Storage paths, signed URLs, OpenAI response IDs, or the previous health-data processing consent history. It is retained only to confirm how requests were handled and to respond to appeals, and it is not used to infer health status, provide health features, advertise, or market to the user.
11. Contact
- Data Controller: WonGyu Jang
- Privacy Officer / Data Protection Officer: WonGyu Jang
- Location: Republic of Korea
- Email: avopet.support@gmail.com
- Phone: +82 10-4491-7410
12. Changes to This Policy
AvoPet may update this policy if the law, app features, or processing practices change. If material changes are made, notice may be provided in the app or on the website, and the updated effective date will appear on this page.
13. Effective Date
Effective date: August 14, 2026
