Page notice — this is not part of the policy below
Gale is pre-commercial. No real patient record, clinical note, claim, or payment is in our system today. The clinical product runs on synthetic demonstration data.
That is not the whole truth, and the rest of it matters to you. Some real information about real people is processed today on our public surfaces: an email address you leave so we can reach you, a phone number you give us so a clinician's office can call you back, the questions you type into our chat, and the words you type into our care-finding front door. This policy describes how that information is handled — today, and when Gale serves real patients.
This policy is in force, effective July 13, 2026.
The Consumer Health Data Privacy Policy begins here.
The short version
- We will never use your health information for advertising or marketing. Not ours, not anyone else's. There is no advertising or analytics tracker of any kind on this site.
- We will never sell it. There is no form on this site that would let you authorize a sale, because we do not want one.
- We do not track your location, and we do not build a voiceprint, a faceprint, or any other biometric identifier of you.
- Before a chat message leaves your browser, we strip your name, phone number, email address, street address, dates, and record numbers out of it. Only the placeholdered text is sent onward. The key that turns the placeholders back into your real words never leaves your device.
- The health content of your chat question does go to Google, because that is what generates the answer. It goes to Google's Gemini model on Vertex AI, covered by the Google Cloud agreement we signed on 13 July 2026. Read § 5.3 before you type.
- You can ask us what we hold about you, and ask us to delete it. § 8. Today that is done by a person, by hand — we have not built the automated path yet, and we are not going to tell you we have.
- We are pre-commercial. There is no real patient record in our system yet.
The rest of this document is the detail behind those seven lines.
1. What this policy covers, and what it does not
This is Gale's Consumer Health Data Privacy Policy under Washington's My Health My Data Act, RCW chapter 19.373. It also serves as our consumer health data privacy policy for Nevada (Senate Bill 370 (2023), codified in NRS chapter 603A) — see § 10.
It is a separate document from Gale's general Privacy Policy, and from the Notice of Privacy Practices issued by a clinician's practice. It says nothing about anything other than consumer health data.
1.1 The HIPAA line — stated plainly
Which rules apply depends on what the information is, not on who you are. This is the part everyone gets wrong, including, in an earlier draft, us.
Gale does two different things.
Gale is software, and an administrative-services contractor to clinicians. Gale does not practice medicine. Licensed clinicians practice medicine, using their own judgment, through their own professional entities. Those practices own your medical record. Under the federal medical-privacy law (HIPAA, 45 CFR Parts 160 and 164), the practice is the party in charge of your record; Gale handles that record only on the practice's instructions, under a contract that binds Gale to the same rules. In HIPAA's vocabulary, the practice is the covered entity and Gale is its business associate.
Information in your medical record — your chart, your visit notes, your prescriptions, your claims, your payments — is protected health information. It is exempt from the My Health My Data Act (RCW 19.373.100), which excludes information that meets HIPAA's definition of protected health information, and information originating from and intermingled to be indistinguishable with it. So this policy does not cover your medical record. Your practice's Notice of Privacy Practices does. You have the right to see all of that record; Gale does not own it and does not decide who sees it.
Information you generate on our public surfaces — an article you read, a symptom you search, a screening questionnaire you take, a question you type into our chat, a request you make for us to find you care — is consumer health data under RCW 19.373.010. HIPAA does not cover it. This policy does — and it covers it even if you are also a patient of a practice that uses Gale.
Both kinds of information can belong to the same person. If you are a Gale patient, this policy still governs your chat, your searches, and your screeners.
1.2 The surfaces this policy covers
This policy applies to consumer health data Gale collects when you:
- read a health article in our library, or a condition, drug, or specialty page;
- search for a symptom, a condition, or a clinician;
- take a screening questionnaire — the PHQ-9, GAD-7, ACEs, PC-PTSD-5, or AUDIT-C;
- use Gale's chat — an AI that gives general health information, not medical advice, and that tells you so — to ask a health question, including a document you attach to it;
- ask us to find you care through our care-finding front door, without an account;
- ask Gale to telephone a clinician's office on your behalf (this feature is switched off today — see § 4.2);
- leave your email address so we can tell you when care is available in your area (a care-gap signup);
- leave your email and phone number so a clinician's office can be asked to call you back (a scheduling request).
If you can recognize yourself doing one of those things, this policy is about you.
2. The consumer health data we collect, why, how we use it, and how long we keep it
RCW 19.373.020(1)(a)(i) requires us to disclose the categories of consumer health data we collect, the purpose of collection, and how the data will be used. RCW 19.373.030(1)(a) permits collection only (i) with your consent for a specified purpose, or (ii) to the extent necessary to provide a product or service you have requested. The last column names which basis we rely on. Today we rely on (ii) for everything. We ask you for consent for nothing, because we collect nothing that is not needed to do the thing you asked us to do.
| Category | What it actually is | Why we collect it and how we use it | Basis — RCW 19.373.030(1)(a) | How long we keep it |
|---|---|---|---|---|
| Health questions you type into our chat | The free text of what you ask, the article you were reading, and text you attach from a document — after identifiers are removed from it in your browser (§ 4.1) | To generate an answer for you. Gale's chat is not a clinician; it gives general health information and does not diagnose or treat. What we store in your chat history is the placeholdered text, not what you typed — your browser puts your real words back when it shows the conversation to you. | (ii) necessary for the service you requested | 365 days — see § 2.4 |
| Screening questionnaire responses | Your answers, your score, and the range your score falls in, on the PHQ-9, GAD-7, ACEs, PC-PTSD-5, or AUDIT-C — including the PHQ-9 question about thoughts of self-harm | Your answers and your score are computed in your browser. Today they are not stored: saving a result to an account is part of our demonstration build and is switched off for real accounts (our database rules refuse the write). Nothing you answer on a screening questionnaire is transmitted to us. A score is not a diagnosis. We show you the published range your score falls in, we point you to a clinician, and we point you to 988 if your answers indicate a crisis. | (ii) necessary for the service you requested | Not stored today. See § 2.2 and § 4.3. |
| Symptom, condition, and clinician searches, and the words you type into the care front door | What you type into search, or your own description of your health problem in the care-finding flow | To route you to the right article, the right kind of care, or the right clinician. Deciding which kind of clinician you need is a deterministic keyword table. No model computes it. A separate, optional step that would send your words to Google to tidy up your logistics preferences (state, telehealth or in person, language, price ceiling) is switched off. | (ii) necessary for the service you requested | The words you type into the care front door travel in the web address of the request today, which means they land in our hosting providers' ordinary request logs. See § 3. |
| Care type and U.S. state | Coarse fields such as "behavioral health" and "Washington" | To tell you whether care of that kind is available where you are, and to route a scheduling request to a clinician licensed in your state | (ii) necessary for the service you requested | Up to 180 days — see § 2.4 |
| Contact information you give us so we can reach you about care | Email address (care-gap signup); email address and phone number (scheduling request), with the care type, your state, your preferred call window, and the clinician you picked | So we can contact you about the care you asked us to help you find. Today, we do not contact anyone. A scheduling request is stored with a permanent never-send marker and is transmitted to no one. Contacting a real person at all is behind a legal switch that is off. Do not leave a phone number expecting a call back until this policy says otherwise. | (ii) necessary for the service you requested | A scheduling request — and a care-gap signup — is deleted after 180 days by a Firestore TTL policy — see § 2.4 |
| What you read | The pages and articles you view | Our web hosting providers log the web address of every request, which reveals which page you were on. | (ii) necessary for the service you requested | We do not control our hosting providers' log-retention windows |
| Your IP address | The network address your browser connects from | We use it ourselves for exactly one purpose: to limit how many times the same address can submit a contact form, so those forms cannot be flooded. It is held in memory only, it is never written to our database, and it is never used to work out where you are or to target you. Our hosting providers separately receive it in their ordinary request logs. | (ii) necessary for the service you requested | Held in memory only, for one hour, then discarded |
2.1 What we will never use this data for
We will never use consumer health data for advertising or marketing. Not our own, not anyone else's.
That commitment is worth nothing unless we say where the line is, so here it is. The only messages we will ever send you are the ones you asked us to send. If you leave your email in a care-gap signup, we will send you exactly one kind of message: that the care you asked about is now available where you live, with a way to unsubscribe in one click. If you submit a scheduling request, we will send you logistics for that request. That is the complete list. We will never send you a promotional message, never upsell you, never send you another company's offer, never use your health data to decide what to show you or sell you, and never hand your address to anyone who will. We do not run advertising, so there is no advertising for your data to feed.
There is no third-party advertising or analytics code anywhere on this site. Our web application's entire dependency list is five packages — Firebase, Next.js, pdf.js, React, and React DOM. Not one of them is an analytics package. There is no Google Analytics, no Meta pixel, no Segment, no PostHog, no Amplitude, no Hotjar, no Mixpanel, no Clarity, no advertising SDK of any kind.
You do not have to take our word for it. Open your browser's network tab on any page of this site and watch where the requests go: to Gale and to Gale's own backend, and nowhere else. If you ever see a request to an advertising or an analytics host on a Gale page, tell us — that is a bug and we will treat it as one.
We will never sell consumer health data. See § 6.
We will never use consumer health data for cross-context behavioral advertising or targeted advertising, and we do not build advertising or marketing profiles about you.
Research, and what we do with your words. Gale does conduct research — it is how care gets better — but not with this data, and not without asking you. Today, nothing you type into our chat, no screening result of yours, and no search of yours is used by Gale to train a model or to run a study. If we ever want to, we will ask you first, in a separate request, in plain language, and you will be able to say no and keep using everything on this site exactly as before. Saying no will cost you nothing.
We must be precise about the one limit on that sentence, because it is a limit about someone else. That commitment is about what Gale does. When you use our chat, the health content of your question is sent to Google to generate the answer. That endpoint — Gemini on Vertex AI — is covered by the Google Cloud agreement we signed on 13 July 2026. Read § 5.3.
(Gale's clinical research — a different thing entirely, on a different body of data — runs on de-identified clinical data under 45 CFR 164.514. Where identifiable clinical data is needed, it requires a HIPAA Authorization under 45 CFR 164.508 that you sign separately, can revoke at any time, and never have to sign in order to get care. That is described in our general Privacy Policy and in our Authorization form. It is not consumer health data and it is not this document's subject.)
2.2 If you answer the question about thoughts of self-harm
The PHQ-9 asks whether you have had thoughts that you would be better off dead, or of hurting yourself. People do not answer that question honestly when they cannot tell what happens next. So:
Nobody at Gale is watching your screener in real time. Answering that question does not alert a clinician, a family member, an employer, an insurer, or an emergency service. No one is notified.
What happens is this: the moment you give that answer — not at the end, and not based on your total — we stop and show you the crisis lines. 988 (call or text), the Suicide & Crisis Lifeline. 741741 (text HOME), the Crisis Text Line. 911, if you are in immediate danger. Then you decide what to do next.
Your answers are scored in your browser and, today, are not stored anywhere. We would rather you answer honestly than manage what you tell us.
2.3 What we do not collect
- We do not collect precise geolocation on any of these surfaces. The only location information we hold is the U.S. state you tell us.
- We do not build biometric identifiers. We do not take voiceprints, faceprints, or fingerprints, and we do not run speaker identification or voice matching. If Gale is ever able to call a clinician's office for you (§ 4.2), your voice would be on that call and processed by our telephone and voice-AI vendors — but recording is off by default, it can only be turned on where every party to the call has consented under the law of the strictest state involved, and we would not derive a biometric template from your voice or use it to identify you anywhere else. That feature is switched off today.
- We do not collect your reading trail on these surfaces. The short list of articles you recently read (at most 20 topics, from the last 90 days) is kept in your browser's own storage. We never collect it, and nothing on these surfaces sends it anywhere. Clear your browser's site data and it is gone. One exception, and it is entirely yours to make: if you go on to book care and switch on the reading-trail toggle in the booking flow, the list of topics — not the web addresses — travels to Gale with your booking, appears in the visit brief for the clinician you named, and the topic titles are sent to Google's Gemini API to draft your pre-visit agenda. The switch is off unless you turn it on. That is a disclosure you make inside a care relationship, and it is described in Gale's general Privacy Policy, not here.
- Our usage counters carry nothing that identifies you. We count how many people move through the site: which page was viewed, which kind of care it concerned, which site you arrived from, and — if you begin a screening questionnaire — which questionnaire it was (for example,
phq9), never an answer and never a score. Those counters carry no user id, no email, no name, and no free text; our server throws away every field except a short, fixed list, so even a mistake in our own code cannot send us more than that list. The only identifier on them is a random number for the browser tab you are in, which is destroyed when you close the tab and is never linked to an account. Because that number can never be connected back to you, we do not treat these counters as consumer health data — and we also cannot find them to delete them. See § 8.2. - Gale sets exactly one cookie anywhere on this site, and it has nothing to do with you: a first-party token, lasting 90 days, that tells us which clinician-recruiting link a clinician arrived from. Nothing in this policy's scope ever sets it, it carries no health information, and it is deleted when a clinician signs up. We set no advertising identifier and no third-party cookie of any kind.
- No third party collects consumer health data over time, or across different websites or online services, through Gale. We carry no third-party trackers, so there is nothing for one to ride.
- We do not buy consumer health data, and we do not receive it from data brokers, advertising networks, or third-party trackers.
2.4 How long we keep it
Here is the schedule, and the database enforces it automatically.
We keep chat transcripts for 365 days, and care-gap signups and scheduling requests for 180 days, after which a Firestore time-to-live policy deletes them — not a script we remember to run, but a rule the database enforces (the scheduling-request expiresAt field is a real deletion trigger, not just an access cutoff). Our hosting providers' request logs cycle on their own schedules, which we do not control. We use this information only to provide the service you asked for — never for advertising, marketing, or sale — and you can have it deleted sooner at any time (see § 8.2).
3. Where we get it
RCW 19.373.020(1)(a)(ii). We collect consumer health data from two kinds of source.
- Directly from you. What you type, select, answer, attach, or submit. This is the great majority of what we hold.
- Automatically from your browser when you make a request to our site. Your IP address, which browser you are using, and the web address you requested — which reveals which page you were on. This is collected in the ordinary course of serving you a web page and is held by our hosting providers as request logs.
There is one thing you should know about source 2 that most policies would leave buried. When you use the care front door, the words you type travel as part of the web address of the request. That means your own description of your health problem — the sentence you wrote — appears in our hosting provider's ordinary request logs. We consider this a defect in our code, not a design choice; we are moving that text into the body of the request, where it does not appear in a log. Until we have, you should know it is there.
Apart from your identity provider at the moment you sign in — which tells us the email address on your account, and nothing about your health — that is all of them. We do not collect consumer health data from data brokers, from advertising networks, from third-party trackers, from public records, or from any other person.
3.1 What stays on your device, and never reaches us
Two things live in your browser's own storage and are never sent to us or to anyone else by anything in this policy's scope. They are not a source of collection, because we never collect them. We describe them because they are yours and you should know they exist.
The list of articles you recently read. A short list of page names, kept so your next step is easier. On these surfaces it never touches the network. It leaves your device only if you switch it on yourself when booking care — a step outside this policy, described in Gale's general Privacy Policy (§ 2.3).
The key to your own chat. When you use the chat, your browser removes your name, your phone number, your email address, your street address, dates, and record numbers from what you typed, and replaces each one with a placeholder like [NAME_1]. It then keeps a private key, on your device, that maps those placeholders back to your real words — which is how the chat reads back to you normally instead of in placeholders. That key is never sent to us and never sent to anyone.
Two consequences you are entitled to weigh. If you open the same chat on a different device, you will see the placeholders instead of your real words — that is the system working, not a bug. And if someone else uses your browser, they can read your chat back in plain form. Clear your browser's site data to destroy the key.
4. What we share, and with whom
RCW 19.373.020(1)(a)(iii).
"Share" is defined broadly in RCW 19.373.010 — to release, disclose, disseminate, divulge, make available, provide access to, license, or otherwise communicate consumer health data, by any means. It excludes disclosure to a processor, where the processor is handling the data for a purpose consistent with the purpose we collected it for. It does not exclude disclosure to an affiliate — which is why § 5.1 names ours.
4.1 Before anything leaves your browser
Gale de-identifies your chat message on your own device, before it is sent. Names, dates of birth, phone numbers, email addresses, street addresses, and record numbers are replaced with placeholders like [NAME_1]. Google receives the placeholdered text, not what you typed. The key that maps a placeholder back to your words never leaves your device (§ 3.1). A document you attach is read into text inside your browser and de-identified there too; the file itself is not uploaded.
This engine is measured, not perfect, and we will not describe it as perfect. Against our own benchmark it is required to hit 100% recall on direct identifiers (names, Social Security numbers, record numbers, phone numbers, email addresses, addresses, full dates, account and plan numbers), at least 95% recall across all eighteen HIPAA Safe-Harbor identifier classes, and at least 90% precision, and the build fails if it does not. But free text can still describe you in ways no engine can catch — "my son's school," "the clinic on my street." Do not treat the chat as anonymous.
And it removes identifiers, not content. The health content of your question still goes to Google. That is the only way the chat can answer it.
4.2 The categories we share
| What we share | With whom | Why | Basis — RCW 19.373.030(1)(b) |
|---|---|---|---|
| Your chat question, de-identified in your browser first (§ 4.1), plus the article you were reading, plus placeholdered text you attached from a document | Google (Gemini on Vertex AI) | To generate the answer you asked for. This is the only way the chat can work. | (ii) necessary for the service you requested — see § 5.3 for the honest limit on this |
| A search query derived from your chat question, where you have asked for a grounded answer | Google (Search, via Gemini's grounding tool) | To find current sources for the answer | (ii) necessary for the service you requested |
| Everything we store — chat transcripts, care-gap signups, scheduling requests, usage counters | Google (Firebase — Firestore, Authentication, Cloud Storage) | This is our database and our identity provider. It is where the data lives. | (ii) processor — this is our infrastructure |
| Your IP address, your browser, and the web address you requested — including, today, the words you type into the care front door (§ 3) | Vercel (web hosting); Google Cloud Run (backend hosting) | Ordinary request logs, generated by serving you a page | (ii) processor — this is our infrastructure |
| Your email address, and a message body containing only your name and a link or a code | Mailgun (email delivery) | Only if you have asked us to contact you. No message is sent to a real person today — see below. | (ii) necessary for the service you requested |
| Your phone number, and a message body containing only your name and a link or a code | Twilio (SMS delivery) | Only if you have asked us to contact you. No message is sent to a real person today — see below. | (ii) necessary for the service you requested |
| Your name, your date of birth, your callback number, insurance detail, the coarse kind of care you want, your preferred times — and the live audio of the call if you join it | Twilio (Programmable Voice / Conference) and OpenAI (Realtime API) | If you ask Gale to telephone a clinician's office on your behalf. This feature is switched off. It structurally cannot dial a real person's identity to either vendor until both vendors sign an agreement with us. See below. | (ii) necessary for the service you requested — not exercised today |
A scanned image or a photograph attached to the chat is a separate case. It is read by Google's vision model to lift the text out of it — but that path is part of our demonstration build and is refused for real accounts, and it will stay refused until we have a signed Business Associate Agreement with Google. A real account cannot send an image to Google through Gale today.
The voice call, honestly. Gale has built — but has not switched on — a feature that telephones a clinician's office on your behalf, with an AI voice agent on the line and you able to join. It is off. It requires two vendors we have no agreement with, and the code refuses to dial a real person's identity to either of them. We name it here, and name both vendors, so that nothing can arrive unannounced. If we ever turn it on: the call would not be recorded unless every party consented under the law of the strictest state involved; a fixed announcement would disclose the AI, the recording, and your presence on the line before any audio reached a vendor; and the vendors would receive only what you consented to send — your name, date of birth, callback number, insurance detail, coarse care type, and preferred times — never your chart and never your history. Afterwards, Gale would keep an identity-free record that a call happened and how it went, and an aggregate count of how a clinician's office answers calls, keyed to the clinician's public professional number. Neither carries your identity.
Two things are true of every message we ever send you, and they are enforced in the code: the body carries logistics only — a name and a link or a code — and never a diagnosis, a score, or a range; and we would rather send you nothing than send you the wrong thing — if we have not recorded your permission to contact you, the system refuses to send rather than sending by default, and logs the refusal.
But do not rely on that today, because today we do not contact anyone at all. A scheduling request is written with a permanent never-send marker and is transmitted to no one. No part of our code reads a care-gap signup or a scheduling request in order to send a message. And contacting a real person requires a legal switch that is off. Those are structural facts, not settings.
4.3 One path we are telling you about before it exists for you
If you save a screening result to an account and then ask Gale's chat to discuss it, or ask Gale to compose a summary of it to share with a clinician, your score, the range it falls in, the suggested talking points, and — for the PHQ-9 — whether you endorsed the question about thoughts of self-harm would be sent to Google (Gemini) to write that text. That is the only way a result would leave our database.
Today you cannot do this, because you cannot save a screening result at all — our database rules refuse the write for a real account (§ 2). This path exists only inside our demonstration build. We are disclosing it now, before it is switched on, because when it is switched on it will be the most sensitive thing on these surfaces and you should not learn about it on the day.
4.4 We share nothing else
We do not share consumer health data with advertisers, ad networks, data brokers, analytics vendors, or social platforms — because we do not use any of them. There is no such vendor in our code to share with.
5. Affiliates, and the third parties we share with
RCW 19.373.020(1)(a)(iv) is asymmetric. Third parties may be disclosed by category. Affiliates must be named specifically.
5.1 Affiliates
Today, Gale Care Inc. shares consumer health data with no affiliate.
The clinicians and clinician-owned professional entities that use Gale are independent practices. Gale is their administrative-services contractor and, under HIPAA, their business associate. We do not route consumer health data from these public surfaces to a practice unless you ask us to — for example, by submitting a scheduling request naming a clinician. Whether any of those entities is an "affiliate" as this statute defines the word is a live question that depends on facts about Gale's corporate structure that are not yet settled.
5.2 Third parties — named, not just categorized
| Category | Who | What they receive | BAA signed? | Data-processing terms |
|---|---|---|---|---|
| Generative AI provider | Google (Gemini on Vertex AI) | Your chat text, de-identified in your browser first; placeholdered text from attachments; a search query derived from your question; if the demonstration paths are ever opened to you, a screening score, its range, talking points, and PHQ-9 item-9 status (§ 4.3) | ✅ Yes (13 Jul 2026) | Covered by the Google Cloud terms + HIPAA BAA. See § 5.3. |
| Cloud infrastructure and identity | Google (Firebase — Firestore, Authentication, Cloud Storage) | Everything Gale stores | ✅ Yes (13 Jul 2026) | Google Cloud Data Processing Addendum (standard Cloud terms) |
| Web and application hosting | Vercel; Google Cloud Run | Request logs — IP address, browser, requested web address (including, today, care-front-door text — § 3) | No | Governed by Vercel's and Google Cloud's standard data-processing terms |
| Email delivery | Mailgun | Your email address; a logistics-only message body | No | Governed by Mailgun's standard data-processing terms |
| SMS delivery | Twilio | Your phone number; a logistics-only message body | No | Governed by Twilio's standard data-processing terms |
| Telephony for the care-finding call (switched off) | Twilio (Programmable Voice / Conference) | Phone numbers and live conference audio. Opaque identifiers only — never a name, a date of birth, or an insurance detail in a web address or a conference name | No | Governed by Twilio's standard data-processing terms |
| Voice AI for the care-finding call (switched off) | OpenAI (Realtime API) | Live call audio, and the session instructions built from the scope you consented to — your name, date of birth, callback number, insurance detail, coarse care type, preferred times. No chart. No history. | No | Governed by OpenAI's standard data-processing terms |
| Advertising, analytics, data brokers, social platforms | None. We use none of them. | Nothing | Not applicable | Not applicable |
Google signed the Google Cloud HIPAA Business Associate Addendum on 13 July 2026, covering its infrastructure and the Vertex AI model. The other subprocessors named here have not. None is required for these consumer surfaces today, because there is no protected health information in them. Each remaining vendor must sign one before Gale serves a real patient. That is a gate, not an aspiration.
5.3 The honest disclosure about Google — and what it means for you
Your chat text goes to Google's Gemini model on Vertex AI, which is covered by the Google Cloud HIPAA Business Associate Addendum Gale signed on 13 July 2026 — the version of the model a real agreement reaches. (Until that day it went to Google's consumer AI endpoint, which no such agreement covered; we moved it.) Your name, your phone number, your email address, your street address, and dates are removed in your browser before the message is sent (§ 4.1) — but the health content of the question is not, because removing it would leave nothing to answer.
The agreement governs what Google may do with the text; it does not stop the text being sent. Ask the chat what you are comfortable having Google process under that agreement. Every other part of this site works without it.
6. We do not sell consumer health data
RCW 19.373.010 defines "sell" as the exchange of consumer health data for monetary or other valuable consideration.
Gale does not sell consumer health data. Not for money. Not for anything else of value. Not in exchange for services, discounts, data, or access.
Because we do not sell it, we never seek — and you will never be shown — the valid authorization to sell that RCW 19.373.070 would require. There is no form on this site that would let you authorize us to sell your health information, because we do not want one and would not use one.
We also do not use consumer health data for targeted advertising, and we do not share it for cross-context behavioral advertising. As § 2.1 says: there is no advertising or analytics code on this site to do it with.
7. Geofencing
RCW 19.373.080 makes it unlawful to implement a geofence — a virtual boundary of 2,000 feet or less around a physical location — around an entity that provides in-person health care services, where the geofence is used to identify or track consumers seeking health care services, to collect consumer health data from them, or to send them notifications, messages, or advertisements related to their health data or health care services.
Gale does not implement a geofence around any location, for any purpose. We do not collect precise geolocation from you, we do not run location-triggered messaging, and we carry no third-party advertising or analytics code that could do it on our behalf.
Connecticut's parallel prohibition uses a 1,750-foot radius around mental health, reproductive health, and sexual health facilities. We satisfy both, because we operate no geofence at all.
8. Your rights, and how to exercise them
RCW 19.373.020(1)(a)(v) requires us to tell you how to exercise the rights in RCW 19.373.040. RCW 19.373.040(1)(d) separately requires that a request be makeable by a secure and reliable means established by us and described in this policy. § 8.3 is where we do that.
We grant these rights to every person who uses these surfaces, wherever you live. We do not ask what state you are in before honoring a request.
8.1 Your rights
You can confirm whether we are collecting, sharing, or selling your consumer health data, and get a copy of it — RCW 19.373.040(1)(a). Your request also entitles you to a list of every third party and affiliate we have shared or sold it to, with an active email address or other online way to contact each of them. We will provide that list, and those contacts, with our response. (We do not sell, so the "sold to" list will always be empty.)
You can ask us to review, and to change, your consumer health data. Tell us what is wrong at the address in § 8.3 and we will correct it or tell you why we cannot.
You can withdraw your consent to our collecting and sharing your consumer health data — RCW 19.373.040(1)(b). Today there is no consent to withdraw. We do not rely on your consent for anything described in § 2 — we collect only what is necessary to do the thing you asked us to do. If that ever changes, we will ask you for consent first, tell you at that moment how to withdraw it, and honor a withdrawal the same way we honor a deletion request.
You can ask us to delete your consumer health data — RCW 19.373.040(1)(c). On a verified request, the law requires us to delete it from our records, including from every part of our network and from archived and backup systems, and to notify every affiliate, processor, contractor, and third party we shared it with. Read § 8.2 before you rely on that, because we are going to tell you exactly what we can and cannot do today.
You cannot be discriminated against for exercising any of these rights — RCW 19.373.030(1)(d). Exercising a right will never change the care you are offered, the price you are quoted, or the quality of the service you get.
8.2 What we can actually do today
We are not going to describe a capability we do not have.
Gale has not yet built an automated way to delete what we hold. A deletion request today is carried out by a person, by hand, when you write to us.
- A saved screening result — you can delete yourself, from your account, at any time. (Today a real account cannot save one in the first place — § 2.)
- A chat transcript, a care-gap signup, a scheduling request — we will find and delete these by hand when you ask us at the address in § 8.3.
- Our usage counters — we cannot delete, and we are telling you rather than promising. They carry no name, no email, and no account: only a page name and a random number for a browser tab, destroyed when you close it. We cannot pick yours out, because we never knew they were yours.
- Copies in a backup — we cannot yet promise are gone. The law gives us up to six months from the day we verify your request to purge archived and backup systems (RCW 19.373.040(1)(c)(iii)). We will delete from our live systems first, and from backups as they cycle. We will never restore your data from a backup after you have asked us to delete it. But we have not yet built and verified a backup-purge path, and we are not going to tell you it is done when we cannot check it.
- Notifying everyone we shared it with — we will notify every vendor with whom we have a contract. Our agreement with Google covers the chat (§ 5.3), but there is still no channel by which to ask Google to recall a message already sent. That is one more reason § 5.3 is written the way it is.
What we cannot delete, and will not pretend to: your medical record, if you are a patient of a practice that uses Gale. That record is held for the practice as the party in charge of it. HIPAA grants no right to delete a treatment record, and state medical-record retention laws require the practice to keep it. It is also exempt from this Act under RCW 19.373.100 and outside this policy entirely. The deletion right above attaches to your consumer health data — your chat, your screeners, your searches, your signups.
8.3 How to submit a request
legal@gale.care Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA Bill Nguyen, CEO
You do not need to create a Gale account to make a request. If you already have one, we may ask you to use it. We have chosen these methods with regard to how people actually use Gale and to our ability to verify that a request is really yours — RCW 19.373.040(1)(d).
We will ask you for enough information to be confident the request is yours. We verify who the consumer is, not merely who is asking. Verification steps do not extend our deadline.
8.4 How we respond, and what it costs
We will respond without undue delay and in every case within 45 days of receiving your request — RCW 19.373.040(1)(g). We may extend that once, by 45 additional days, when reasonably necessary given the complexity and number of requests. If we extend, we will tell you within the first 45 days, and we will tell you why.
Our response is free. We will answer up to two requests from you per year at no charge. If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee to cover our administrative costs, or decline to act — and if we do, the burden is on us to show why — RCW 19.373.040(1)(f).
8.5 If we refuse — your right to appeal, and to complain about us
If we refuse to act on your request, we will tell you why, and we will tell you how to appeal — RCW 19.373.040(1)(h). The appeal is as easy to use as the original request: write to the same address in § 8.3, with "Appeal" in the subject line.
Within 45 days of receiving your appeal, we will tell you in writing what we did or did not do, with a written explanation of our reasons.
If we deny your appeal, we will give you a way to complain about us to the Washington Attorney General. We are required to give you this, and we will. The Washington Attorney General's consumer complaint system is at www.atg.wa.gov/file-complaint.
8.6 If you are a minor
These rights are yours, not your parent's.
A minor who uses these surfaces has full access to their own consumer health data and may delete it.
A parent or guardian who asks us for a minor's screening results, chat, or searches will not receive them where state law lets that minor consent to the care on their own — mental health, substance use, reproductive health, sexual health, and gender-identity categories. Every instrument named in this policy — the PHQ-9, the GAD-7, the ACEs, the PC-PTSD-5, the AUDIT-C — is squarely inside those categories.
That restriction is decided by a per-state, per-service, per-age consent engine, not by a static list, and not by whoever happens to ask.
9. How we will tell you if this policy changes
We may not collect, use, or share additional categories of consumer health data, or use it for additional purposes, beyond what is disclosed above, without first updating this policy and obtaining your affirmative consent before the new collection, use, or sharing begins — RCW 19.373.020(1)(c) and (1)(d).
That means this is not a document we can quietly revise. A new category or a new purpose requires a new disclosure and a new, freely given, specific, informed, opt-in agreement from you — and the consent request itself must tell you the categories collected or shared, the purpose and the specific ways the data will be used, the categories of entities it is shared with, and how to withdraw your consent, as RCW 19.373.030(1)(c) requires. Consent cannot be buried in terms of use, and it cannot be obtained through a dark pattern.
How we will notify you of a material change to this policy: We will notify you by email to the address on file for your account, update the effective date, and post the change on this page.
Version: 1.0 · Last updated: 2026-07-13 · Effective: July 13, 2026
10. Nevada
Nevada Senate Bill 370 (2023), codified in NRS chapter 603A, is structurally parallel to Washington's Act and requires a published consumer health data privacy policy of its own. Everything in this policy applies to consumers in Nevada, and specifically:
- We collect consumer health data only with your consent, or as necessary to provide a product or service you requested (§ 2).
- The categories we collect, the purposes, the categories of sources, the categories of third parties and affiliates we share with, and the categories we share are stated in §§ 2, 3, 4, and 5.
- You may review your consumer health data and request changes to it. Submit that request the same way as any other, at the address in § 8.3, and we will correct it or tell you why we cannot (§ 8.1).
- How we notify you of a material change to this policy is stated in § 9.
- No third party collects consumer health data over time, or across different websites or online services, through Gale (§ 2.3). We carry no third-party trackers.
- We do not sell consumer health data, and we therefore never seek the separate written authorization Nevada would require before a sale (§ 6).
- You have the same rights to confirm, access, delete, and withdraw consent, exercised the same way, at the address in § 8.3.
- We operate no geofence around any health care facility (§ 7).
- The effective date of this policy is July 13, 2026.
Nevada's law is enforced by the Nevada Attorney General. It does not create a private right of action.
11. Connecticut
Connecticut does not require a separate consumer health data privacy policy. Its health-data rules sit inside the Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., amended by Public Act 23-56, with the consumer-health-data provisions effective October 1, 2023). The notice Connecticut requires is a general controller privacy notice under Conn. Gen. Stat. § 42-520, and it is carried in Gale's general Privacy Policy, not here.
This section states only the health-data-specific commitments, which apply to you in Connecticut:
- Under the CTDPA, consumer health data is sensitive data, which requires your opt-in consent to process and separate consent for any sale.
- We do not sell, so the sale-consent question never arises (§ 6).
- Connecticut's geofence prohibition uses a 1,750-foot radius around mental health, reproductive health, and sexual health facilities. We operate no geofence (§ 7).
- Connecticut's law is enforced by the Connecticut Attorney General. It does not create a private right of action.
12. How to reach us
Gale Care Inc. Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA Delaware legal@gale.care Bill Nguyen, CEO