Page notice — this is not part of the policy below
Gale is pre-commercial. No real patient record, clinical note, claim, or payment is in our system today. The clinical product runs on synthetic demonstration data.
That is not the whole truth, and the rest of it matters to you. Some real information about real people is processed today on our public surfaces: an email address you leave so we can reach you, a phone number you give us so a clinician's office can call you back, the questions you type into our chat, and the words you type into our care-finding front door. This policy describes how that information is handled — today, and when Gale serves real patients.
This policy is in force, effective July 13, 2026.
The Consumer Health Data Privacy Policy begins here.
The short version
- We will never use your health information for advertising or marketing. Not ours, not anyone else's. There is no advertising or analytics tracker of any kind on this site.
- We will never sell it. There is no form on this site that would let you authorize a sale, because we do not want one.
- This website never reads your location. The Gale Care iPhone app can — on the phone, and only if you turn it on. Three switches, each off until you flip it, let the app work out the kind of place you have arrived at so it can say one useful thing. No coordinate of yours ever reaches Gale. § 2.5 says what the app reads and where it goes; § 7 describes the one boundary it can draw.
- We do not build a voiceprint, a faceprint, or any other biometric identifier of you — not on the site, not in the app, not anywhere.
- Before a chat message leaves your browser, we strip your name, phone number, email address, street address, dates, and record numbers out of it. Only the placeholdered text is sent onward. The key that turns the placeholders back into your real words never leaves your device.
- The health content of your chat question does go to Google, because that is what generates the answer. It goes to Google's Gemini model on Vertex AI, covered by the Google Cloud agreement we signed on 13 July 2026. Read § 5.3 before you type.
- In the iPhone app, a few whole numbers from your own tracking go with the question — steps, sleep, meditation minutes, two counts, and any counters you named yourself — while the switch in You marked "Let Gale's AI use my saved details and numbers" is on. It is on unless you turn it off. An earlier version of this policy said those numbers stayed on the phone. That was wrong, and § 2.5 is the correction. Two things ride with those numbers and are not numbers: the name you gave a counter you made yourself, which travels as you wrote it, and — only if you ask about your food diary — that day's entries. § 2.5 and § 4.2.
- You can ask us what we hold about you, and ask us to delete it. § 8. Today that is done by a person, by hand — we have not built the automated path yet, and we are not going to tell you we have.
- We are pre-commercial. There is no real patient record in our system yet.
The rest of this document is the detail behind those seven lines.
1. What this policy covers, and what it does not
This is Gale's Consumer Health Data Privacy Policy under Washington's My Health My Data Act, RCW chapter 19.373. It also serves as our consumer health data privacy policy for Nevada (Senate Bill 370 (2023), codified in NRS chapter 603A) — see § 10.
It is a separate document from Gale's general Privacy Policy, and from the Notice of Privacy Practices issued by a clinician's practice. It says nothing about anything other than consumer health data.
1.1 The HIPAA line — stated plainly
Which rules apply depends on what the information is, not on who you are. This is the part everyone gets wrong, including, in an earlier draft, us.
Gale does two different things.
Gale is software, and an administrative-services contractor to clinicians. Gale does not practice medicine. Licensed clinicians practice medicine, using their own judgment, through their own professional entities. Those practices own your medical record. Under the federal medical-privacy law (HIPAA, 45 CFR Parts 160 and 164), the practice is the party in charge of your record; Gale handles that record only on the practice's instructions, under a contract that binds Gale to the same rules. In HIPAA's vocabulary, the practice is the covered entity and Gale is its business associate.
Information in your medical record — your chart, your visit notes, your prescriptions, your claims, your payments — is protected health information. It is exempt from the My Health My Data Act (RCW 19.373.100), which excludes information that meets HIPAA's definition of protected health information, and information originating from and intermingled to be indistinguishable with it. So this policy does not cover your medical record. Your practice's Notice of Privacy Practices does. You have the right to see all of that record; Gale does not own it and does not decide who sees it.
Information you generate on our public surfaces — an article you read, a symptom you search, a screening questionnaire you take, a question you type into our chat, a request you make for us to find you care — is consumer health data under RCW 19.373.010. HIPAA does not cover it. This policy does — and it covers it even if you are also a patient of a practice that uses Gale.
Both kinds of information can belong to the same person. If you are a Gale patient, this policy still governs your chat, your searches, and your screeners.
1.2 The surfaces this policy covers
This policy applies to consumer health data Gale collects when you:
- read a health article in our library, or a condition, drug, or specialty page;
- search for a symptom, a condition, or a clinician;
- take a screening questionnaire — the PHQ-9, GAD-7, ACEs, PC-PTSD-5, or AUDIT-C;
- use Gale's chat — an AI that gives general health information, not medical advice, and that tells you so — to ask a health question, including a document you attach to it;
- ask us to find you care through our care-finding front door, without an account;
- ask Gale to telephone a clinician's office on your behalf (this feature is switched off today — see § 4.2);
- leave your email address so we can tell you when care is available in your area (a care-gap signup);
- leave your email and phone number so a clinician's office can be asked to call you back (a scheduling request).
It also applies to the Gale Care iPhone app, where you:
- turn on "Suggestions in the moment," which reads signals your phone already holds — the shape of your day, whether you are moving, how you slept, and the kind of place you are at — and occasionally says one thing;
- turn on "Meals in your calendar," which reads the name, time, and address of calendar events that look like a meal out, and nothing else about your calendar;
- turn on "A note when you arrive," which lets that one suggestion reach your lock screen when you get there;
- tap "Use my current location" while booking, which reads your location once to fill in your state, and does nothing else with it;
- ask Gale's chat a question in the app, which can attach a few whole numbers from your own tracking to that question — and, if you ask about your food diary, a day of what you logged in it — § 2.5;
- turn on "My nightly sleep hours" or "My daily step count", which lets the app keep that one reading beside the day it belongs to, for one hundred and eighty days — the only thing in this app that keeps a reading, and both are off until you turn them on — § 2.5 and § 9.1.
Every one of the first four is off until you turn it on, and your phone asks you for its own permission on top of ours. The two keeping switches in the last line are off until you turn them on too. The chat line is the one that is different, and we are not going to bury the difference: the switch that lets those numbers travel is on unless you turn it off. § 2.5 says what each one reads and where it goes; § 7 describes the one boundary any of it draws.
If you can recognize yourself doing one of those things, this policy is about you.
2. The consumer health data we collect, why, how we use it, and how long we keep it
RCW 19.373.020(1)(a)(i) requires us to disclose the categories of consumer health data we collect, the purpose of collection, and how the data will be used. RCW 19.373.030(1)(a) permits collection only (i) with your consent for a specified purpose, or (ii) to the extent necessary to provide a product or service you have requested. The last column names which basis we rely on. Today we rely on (ii) for everything we actually collect. We collect nothing that is not needed to do the thing you asked us to do. Two rows below name categories nothing is being collected under: the row of four the app is built to attach says "none yet," and the row for a kept sleep or step reading names basis (i), your consent — because that row could only ever run on your consent, and § 9.1 says what has to happen before it runs at all. Basis (ii) does not stretch to cover a new kind of information, and a switch existing in the app is not consent having been asked for.
| Category | What it actually is | Why we collect it and how we use it | Basis — RCW 19.373.030(1)(a) | How long we keep it |
|---|---|---|---|---|
| Health questions you type into our chat | The free text of what you ask, the article you were reading, and text you attach from a document — after identifiers are removed from it in your browser (§ 4.1) | To generate an answer for you. Gale's chat is not a clinician; it gives general health information and does not diagnose or treat. What we store in your chat history is the placeholdered text, not what you typed — your browser puts your real words back when it shows the conversation to you. | (ii) necessary for the service you requested | 365 days — see § 2.4 |
| Numbers from your own tracking in the iPhone app, attached to a chat question | Whole numbers — steps today, how long you slept last night, meditation minutes this week, how many of your own medicines you ticked off today, how many people you noted connecting with this week — plus, for each of up to eight counters you made yourself, the short name you gave it and today's number. That name is your own words, not a number | So the answer can be about you rather than about people in general. Sent only while the switch in the app's You tab — "Let Gale's AI use my saved details and numbers" — is on, and it is on unless you turn it off. Turn it off and none of them travel. The app attaches no other field, our server refuses any field it does not recognise, and it drops any counter you named after a menstrual cycle before the question is answered — there is no cycle field, by design. The server is also built to carry the further categories in § 9.1; the app does not send them | (ii) necessary for the service you requested | Not kept as part of this flow. They ride along with the question and are never written to a record about you here. What is kept is the conversation itself — 365 days, § 2.4. The one exception is the row below, which is a different act you turn on yourself |
| A sleep or step reading kept as a record (iPhone app) | The hours you slept on a night your phone recorded, or the steps it recorded for a day, written beside that day. Nothing derived from it | So a surface in the app can count what you logged and compare a day of yours with another day of yours. Kept only after you turn that category on — "My nightly sleep hours" or "My daily step count", each its own switch, each off until you turn it on. Nothing is worked out from these rows: no usual, no score, no band, no share of a target — there is no field in the record for a total to be a share of | (i) your consent, per category, RCW 19.373.030(1)(a)(i) | One hundred and eighty days, then a Firestore time-to-live policy deletes it. Turning the switch off deletes the rows |
| A day of the food diary you keep in the iPhone app, when you ask the chat about it | The foods you logged that day — what you called each one, the portion you gave it, the calories where we know them, and the day's total. Only the day your question is about | So a question about what you ate is answered from what you actually logged rather than from a guess. The diary is kept in your Gale account (that is how the app shows it back to you). When your question is about it, our server looks up that one day and hands it to Google's Gemini on Vertex AI with your question — only while the same "Let Gale's AI use my saved details and numbers" switch is on. The summary states what you logged; it never scores, grades, or sets a target for your day | (ii) necessary for the service you requested | The diary entries stay in your account — no schedule deletes them today, and they go when you ask us to delete them or delete your account (§ 8.2). The day's summary that rides with your question is not separately kept; what is kept is the conversation, 365 days, § 2.4 |
| The situation behind a suggestion you tapped "Ask Gale about this" on | One line: the restaurant name from your own calendar, what Gale suggested there, and coarse words for the shape of your day ("her calendar today is much fuller than her usual") — never the measurements those words came from, never a coordinate, never any other calendar entry | So a question about a suggestion is answered against the evening you are actually in. Gated by the same switch, and de-identified in the app before it is sent | (ii) necessary for the service you requested | Not kept. It rides with the question and is never written to a record about you — there is no keeping switch for it and none is planned |
| Four further kinds of information the app is built to attach — none of it attached today, each behind its own switch that starts off (§ 9.1) | Your medication list in your own words; weekly movement minutes; a one-line, categorical summary of where you are in a plan you follow (food, movement, meditation, or the connection intentions you wrote for yourself); daily protein, fat and carbohydrate totals from your food diary | We are disclosing these before they exist for you, not after — the § 4.3 practice. Nothing in this row is being collected, used, or shared today, and none of it begins until we have asked you for that specific kind of information and you have agreed — § 9.1 | None yet. Not (i) and not (ii): a new category needs your affirmative consent under RCW 19.373.020(1)(c)–(d) first | Not applicable — nothing is being collected |
| Screening questionnaire responses | Your answers, your score, and the range your score falls in, on the PHQ-9, GAD-7, ACEs, PC-PTSD-5, or AUDIT-C — including the PHQ-9 question about thoughts of self-harm | Your answers and your score are computed in your browser. Today they are not stored: saving a result to an account is part of our demonstration build and is switched off for real accounts (our database rules refuse the write). Nothing you answer on a screening questionnaire is transmitted to us. A score is not a diagnosis. We show you the published range your score falls in, we point you to a clinician, and we point you to 988 if your answers indicate a crisis. | (ii) necessary for the service you requested | Not stored today. See § 2.2 and § 4.3. |
| Symptom, condition, and clinician searches, and the words you type into the care front door | What you type into search, or your own description of your health problem in the care-finding flow | To route you to the right article, the right kind of care, or the right clinician. Deciding which kind of clinician you need is a deterministic keyword table. No model computes it. A separate, optional step that would send your words to Google to tidy up your logistics preferences (state, telehealth or in person, language, price ceiling) is switched off. | (ii) necessary for the service you requested | The words you type into the care front door travel in the web address of the request today, which means they land in our hosting providers' ordinary request logs. See § 3. |
| Care type and U.S. state | Coarse fields such as "behavioral health" and "Washington" | To tell you whether care of that kind is available where you are, and to route a scheduling request to a clinician licensed in your state | (ii) necessary for the service you requested | Up to 180 days — see § 2.4 |
| Contact information you give us so we can reach you about care | Email address (care-gap signup); email address and phone number (scheduling request), with the care type, your state, your preferred call window, and the clinician you picked | So we can contact you about the care you asked us to help you find. Today, we do not contact anyone. A scheduling request is stored with a permanent never-send marker and is transmitted to no one. Contacting a real person at all is behind a legal switch that is off. Do not leave a phone number expecting a call back until this policy says otherwise. | (ii) necessary for the service you requested | A scheduling request — and a care-gap signup — is deleted after 180 days by a Firestore TTL policy — see § 2.4 |
| What you read | The pages and articles you view | Our web hosting providers log the web address of every request, which reveals which page you were on. | (ii) necessary for the service you requested | We do not control our hosting providers' log-retention windows |
| Your IP address | The network address your browser connects from | We use it ourselves for exactly one purpose: to limit how many times the same address can submit a contact form, so those forms cannot be flooded. It is held in memory only, it is never written to our database, and it is never used to work out where you are or to target you. Our hosting providers separately receive it in their ordinary request logs. | (ii) necessary for the service you requested | Held in memory only, for one hour, then discarded |
2.1 What we will never use this data for
We will never use consumer health data for advertising or marketing. Not our own, not anyone else's.
That commitment is worth nothing unless we say where the line is, so here it is. The only messages we will ever send you are the ones you asked us to send. If you leave your email in a care-gap signup, we will send you exactly one kind of message: that the care you asked about is now available where you live, with a way to unsubscribe in one click. If you submit a scheduling request, we will send you logistics for that request. That is the complete list. We will never send you a promotional message, never upsell you, never send you another company's offer, never use your health data to decide what to show you or sell you, and never hand your address to anyone who will. We do not run advertising, so there is no advertising for your data to feed.
There is no third-party advertising or analytics code anywhere on this site. Our web application's entire dependency list is five packages — Firebase, Next.js, pdf.js, React, and React DOM. Not one of them is an analytics package. There is no Google Analytics, no Meta pixel, no Segment, no PostHog, no Amplitude, no Hotjar, no Mixpanel, no Clarity, no advertising SDK of any kind.
You do not have to take our word for it. Open your browser's network tab on any page of this site and watch where the requests go: to Gale and to Gale's own backend, and nowhere else. If you ever see a request to an advertising or an analytics host on a Gale page, tell us — that is a bug and we will treat it as one.
We will never sell consumer health data. See § 6.
We will never use consumer health data for cross-context behavioral advertising or targeted advertising, and we do not build advertising or marketing profiles about you.
Research, and what we do with your words. Gale does conduct research — it is how care gets better — but not with this data, and not without asking you. Today, nothing you type into our chat, no screening result of yours, and no search of yours is used by Gale to train a model or to run a study. If we ever want to, we will ask you first, in a separate request, in plain language, and you will be able to say no and keep using everything on this site exactly as before. Saying no will cost you nothing.
We must be precise about the one limit on that sentence, because it is a limit about someone else. That commitment is about what Gale does. When you use our chat, the health content of your question is sent to Google to generate the answer. That endpoint — Gemini on Vertex AI — is covered by the Google Cloud agreement we signed on 13 July 2026. Read § 5.3.
(Gale's clinical research — a different thing entirely, on a different body of data — runs on de-identified clinical data under 45 CFR 164.514. Where identifiable clinical data is needed, it requires a HIPAA Authorization under 45 CFR 164.508 that you sign separately, can revoke at any time, and never have to sign in order to get care. That is described in our general Privacy Policy and in our Authorization form. It is not consumer health data and it is not this document's subject.)
2.2 If you answer the question about thoughts of self-harm
The PHQ-9 asks whether you have had thoughts that you would be better off dead, or of hurting yourself. People do not answer that question honestly when they cannot tell what happens next. So:
Nobody at Gale is watching your screener in real time. Answering that question does not alert a clinician, a family member, an employer, an insurer, or an emergency service. No one is notified.
What happens is this: the moment you give that answer — not at the end, and not based on your total — we stop and show you the crisis lines. 988 (call or text), the Suicide & Crisis Lifeline. 741741 (text HOME), the Crisis Text Line. 911, if you are in immediate danger. Then you decide what to do next.
Your answers are scored in your browser and, today, are not stored anywhere. We would rather you answer honestly than manage what you tell us.
2.3 What we do not collect
- Gale's servers collect no geolocation — precise or coarse. The only location information we hold about you is the U.S. state you type or select yourself.
- The iPhone app can read your location, on the phone, and only if you switch it on. What it reads stays there. Your sleep and your steps are different now, and only if you ask for it: with that category switched on, the reading is kept for one hundred and eighty days — § 2.5 and § 9.1. The app turns a position into a word — home, work, a café, a gym, the shops, on the way somewhere — and keeps the word. No latitude or longitude is ever sent to Gale, written to your record, or stored on our servers. § 2.5 says what the app reads; § 7 describes the one boundary it can draw.
- We do not build biometric identifiers. We do not take voiceprints, faceprints, or fingerprints, and we do not run speaker identification or voice matching. If Gale is ever able to call a clinician's office for you (§ 4.2), your voice would be on that call and processed by our telephone and voice-AI vendors — but recording is off by default, it can only be turned on where every party to the call has consented under the law of the strictest state involved, and we would not derive a biometric template from your voice or use it to identify you anywhere else. That feature is switched off today.
- We do not collect your reading trail on these surfaces. The short list of articles you recently read (at most 20 topics, from the last 90 days) is kept in your browser's own storage. We never collect it, and nothing on these surfaces sends it anywhere. Clear your browser's site data and it is gone. One exception, and it is entirely yours to make: if you go on to book care and switch on the reading-trail toggle in the booking flow, the list of topics — not the web addresses — travels to Gale with your booking, appears in the visit brief for the clinician you named, and the topic titles are sent to Google's Gemini API to draft your pre-visit agenda. The switch is off unless you turn it on. That is a disclosure you make inside a care relationship, and it is described in Gale's general Privacy Policy, not here.
- Our usage counters carry nothing that identifies you. We count how many people move through the site: which page was viewed, which kind of care it concerned, which site you arrived from, and — if you begin a screening questionnaire — which questionnaire it was (for example,
phq9), never an answer and never a score. Those counters carry no user id, no email, no name, and no free text; our server throws away every field except a short, fixed list, so even a mistake in our own code cannot send us more than that list. The only identifier on them is a random number for the browser tab you are in, which is destroyed when you close the tab and is never linked to an account. Because that number can never be connected back to you, we do not treat these counters as consumer health data — and we also cannot find them to delete them. See § 8.2. - Gale sets exactly one cookie anywhere on this site, and it has nothing to do with you: a first-party token, lasting 90 days, that tells us which clinician-recruiting link a clinician arrived from. Nothing in this policy's scope ever sets it, it carries no health information, and it is deleted when a clinician signs up. We set no advertising identifier and no third-party cookie of any kind.
- No third party collects consumer health data over time, or across different websites or online services, through Gale. We carry no third-party trackers, so there is nothing for one to ride.
- We do not buy consumer health data, and we do not receive it from data brokers, advertising networks, or third-party trackers.
2.4 How long we keep it
Here is the schedule, and the database enforces it automatically.
We keep chat transcripts for 365 days, care-gap signups and scheduling requests for 180 days, and a sleep or step reading you asked us to keep for 180 days, after which a Firestore time-to-live policy deletes them — not a script we remember to run, but a rule the database enforces (the scheduling-request expiresAt field is a real deletion trigger, not just an access cutoff). Our hosting providers' request logs cycle on their own schedules, which we do not control. We use this information only to provide the service you asked for — never for advertising, marketing, or sale — and you can have it deleted sooner at any time (see § 8.2).
2.5 The iPhone app — what it reads on the phone, and the little that leaves it
This section was wrong, and this is the correction, not a quiet edit. Until 7 August 2026 it was headed "the things it reads on the phone without sending them to us" and it ended with the sentence "None of this becomes a record about you at Gale." The heading was not true. When you ask Gale's chat a question from the iPhone app, the app can attach a few whole numbers from your own tracking to that question, and they go to Google's Gemini model on Vertex AI with it. That has been true of the shipped app; the policy had not caught up. We would rather print the correction than repair the sentence and say nothing.
The rest of the section is what it always said, because the rest of it is accurate: the phone reads a great deal more than it sends.
If you turn on "Suggestions in the moment," the Gale Care app reads, on your phone: how full your day looks from your calendar (how many things are booked, for how long, and where the gaps are — never what any of them are called), whether you are moving or sitting still, what your phone's Health data already holds about your steps and your sleep, and — if you allow location — the kind of place you are at: home, work, a café, a gym, the shops, or on the way somewhere.
Here is what happens to that, and it is short.
- It is used on the device, by a table that ships inside the app, to decide whether there is one useful thing to say. Most of the time there is not, and the app says nothing.
- Your coordinates are never sent to Gale. Not once, not summarized, not in a log. For this feature the app never asks your phone for a continuous position: it uses what iOS calls visit monitoring, which reports that you arrived somewhere and that you left, and never the path between the two.
- What stays on the phone is a neighbourhood, not an address. From how much time you spend where, the app learns the rough area you sleep in and the rough area you work in, rounded to about a hundred metres — a block, not a doorway. That lives in the app's own storage on your device, is never uploaded, and is erased when you sign out.
- Two lookups do send a coordinate off your phone, and both go to Apple rather than to us. When you arrive somewhere the app has not learned yet, it asks Apple's Maps service what kind of place is there, keeps the category — café, restaurant, shop, gym — and drops the rest; this does not happen at all for the places you are usually at. Separately, if you tap "Use my current location" while booking, the app asks Apple to turn that one position into a state name, and keeps only the state. Both are the same lookups any maps app makes, and both are governed by Apple's privacy terms rather than ours.
- If you turn on "Meals in your calendar," one more thing leaves the phone: the name of the restaurant. Not the time, not the address, not who is coming, not your other events — the venue name alone, sent to Gale so we can look up what that place serves. We ask once per restaurant and remember the answer on your device.
- That venue name reaches Google. Our server asks Google's Gemini model on Vertex AI what kind of place it is and to name one thing on its menu. It is the same agreement described in § 5.3. What we send is the name of a restaurant, with nothing about you attached to it.
- Almost none of this becomes a stored record about you at Gale, and one part now can. There is no location history in your Gale account and no file of your counters — there is nothing to put in one. Your sleep and your steps are the exception, and only if you turn that category on. With the switch on, the reading a surface in the app already shows you is written down beside the day it belongs to, kept for one hundred and eighty days, and then deleted by the database itself. Turn the switch off and those rows are deleted, not hidden. Nothing is worked out from them: no usual, no score, no band, no share of a target. This paragraph is new because the app can now do it — the code and this page are landing together. Not stored was never the same as not sent, and now there is a third thing to keep separate from both: kept, because you asked.
Turning "Suggestions in the moment" off stops all of it, and removes what the app had learned.
What leaves the phone when you use the chat in the app
Ask Gale's chat a question in the iPhone app and the app can attach, to that one question, a short list of whole numbers from your own tracking. This is the complete list of what the app attaches — there is no other field in it, and our server refuses any field it does not recognise:
- steps today and how long you slept last night, from what your phone's Health data already holds;
- minutes of meditation you have listened to this week;
- how many of your own medicines you ticked off today — the count, never their names;
- how many people you noted connecting with this week — the count, never who;
- any counters you made yourself: the name you gave each one and today's number, at most eight of them.
And one thing built ahead of the ask, said rather than left to be found. Since 7 August 2026 the server is able to receive the § 9.1 categories (six of them since 10 August 2026, and since 24 August 2026 it can also keep the two that are kept rather than sent) — it has to be built before it can be asked for — and the app now carries a switch for each one it could compose, every one of them off until you turn it on (§ 9.1 names them). The app sends none of the sending categories for you, and it keeps neither of the kept ones until you turn that category on; § 9.1 says what has to happen — this policy first, then we ask you about that category by itself, then your yes on its own switch — before any of them begins. Until you have been asked and have said yes, the list above is the whole of what the app attaches to a question.
Seven things are true of that list, and each of them is built rather than promised.
- They go where your question goes — to Google's Gemini model on Vertex AI, under the agreement described in § 5.3, so that an answer about your sleep can be about your sleep. They go nowhere else.
- One switch governs all of it. In the app's You tab, "Let Gale's AI use my saved details and numbers" — on unless you turn it off. Turn it off and none of these numbers travel, and neither does anything else the app would have attached; the chat then works from what you type and nothing more.
- They are numbers, not sentences — with one exception, and it is the one you write yourself. No date, no place, no coordinate, and nothing you typed into the chat or into a diary rides in this list. The exception is the name of a counter you made yourself: that is short text you wrote (at most 40 characters), and it travels exactly as you wrote it. A counter called "walks" sends the word "walks" — and a counter you name after a person, or after a medicine, sends that too. Name your own counters with that in mind. Three things do get taken out of a counter name before your question moves on: one that reads as cycle tracking is dropped entirely, one that trips our banned-phrases list is dropped entirely, and a structured identifier inside it — a phone number, an email address, a record number, an address — is stripped by the same server sweep described in § 4.1. A person's name has no such shape, so no sweep can find it. That is why this bullet says what it says instead of promising you a filter.
- There is no cycle field, and there is no back door to one. A counter you named after a period or a cycle is dropped before your question is answered — you keep it on your phone, and it does not travel.
- Gale keeps none of them by default, and keeps two of them if you say so. The numbers ride along with your question and are never written into a record about you — unless you have turned on "My nightly sleep hours" or "My daily step count," in which case that reading is written down for one hundred and eighty days and deleted when you turn the switch off. What is kept otherwise is the conversation — your question and Gale's answer — for 365 days (§ 2.4). So if the answer says a number back to you, that sentence is in your transcript, and you can delete it (§ 8).
- This is the app only. The website's chat has none of this — it has no access to your phone's Health data and sends no numbers.
- And one thing the app does not attach, because it does not have to. If your question is about your food diary, our server looks that day up in the diary you keep in the app and sends the foods themselves — what you called each one, the portion, the calories where we know them, and the day's total — to Google with your question. It is your own record read back to you, it happens only when you ask about it, and the same switch governs it. § 2 and § 4.2 carry the row.
One more thing travels the same way, and only if you tap it. When a suggestion card offers "Ask Gale about this," tapping it sends one line of situation with your question: the restaurant name from your own calendar and what Gale suggested there, plus coarse words for the shape of your day — "her calendar today is much fuller than her usual," "she has moved less than she usually has by now," "last night was shorter than her usual." Those are categories, never the measurements behind them, never a coordinate, and never any calendar entry other than the venue you already chose to share. The same switch governs it, and the app de-identifies the line before it is sent.
Four things the app is built to send, and is not sending
We are describing these before they reach you, the way § 4.3 describes the screening path — because the day to learn about a change is not the day it happens.
- your medication list, in your own words — the names, and the dose and schedule text exactly as you typed them, never re-written by us into a dose we compute;
- weekly movement minutes;
- a one-line summary of where you are in a plan you follow — food, movement, meditation, or the connection intentions you wrote for yourself. Categorical only: never the intentions themselves, never a person's name;
- daily protein, fat and carbohydrate totals from what you logged in the food diary.
One flow that is NOT in that list, because it is already happening. When you ask the chat about your food diary, Gale's server fetches that day from your diary and hands the foods themselves — what you called each one, the portion, the calories where we know them, and the day's total — to Google with your question. That is not one of the four pending categories; it is a disclosure this policy owed you now, and it is in the § 2 and § 4.2 tables. The pending row above is the day's protein, fat and carbohydrate totals, which are not sent.
None of that is travelling today, and the order is a commitment, not a sequence we hope to follow. Since 7 August 2026 the app carries a switch for each of the first three, in You — every one off until you turn it on; § 9.1 names them and says why a switch existing is not the ask happening. Each one begins only after we have asked you about that specific kind of information and you have said yes — § 9.1, which also says why the master switch above is not that permission and cannot be made to serve as it.
And a limit on our own promise, printed rather than left for you to discover. If your medication list ever does travel, it travels with every question you ask while its switch and the master switch are both on — not only questions about medication — and Gale's answer can say those names back to you; that answer is kept in your transcript for 365 days, exactly as a medicine you type yourself already is. That is a consequence of asking about them, we cannot make it otherwise, and § 9.1 asks you about it before it can happen.
3. Where we get it
RCW 19.373.020(1)(a)(ii). We collect consumer health data from two kinds of source.
- Directly from you. What you type, select, answer, attach, or submit. This is the great majority of what we hold.
- Automatically from your browser when you make a request to our site. Your IP address, which browser you are using, and the web address you requested — which reveals which page you were on. This is collected in the ordinary course of serving you a web page and is held by our hosting providers as request logs.
There is one thing you should know about source 2 that most policies would leave buried. When you use the care front door, the words you type travel as part of the web address of the request. That means your own description of your health problem — the sentence you wrote — appears in our hosting provider's ordinary request logs. We consider this a defect in our code, not a design choice; we are moving that text into the body of the request, where it does not appear in a log. Until we have, you should know it is there.
Apart from your identity provider at the moment you sign in — which tells us the email address on your account, and nothing about your health — that is all of them. We do not collect consumer health data from data brokers, from advertising networks, from third-party trackers, from public records, or from any other person.
3.1 What stays on your device, and never reaches us
Two things live in your browser's own storage and are never sent to us or to anyone else by anything in this policy's scope. They are not a source of collection, because we never collect them. We describe them because they are yours and you should know they exist.
The list of articles you recently read. A short list of page names, kept so your next step is easier. On these surfaces it never touches the network. It leaves your device only if you switch it on yourself when booking care — a step outside this policy, described in Gale's general Privacy Policy (§ 2.3).
The key to your own chat. When you use the chat, your browser removes your name, your phone number, your email address, your street address, dates, and record numbers from what you typed, and replaces each one with a placeholder like [NAME_1]. It then keeps a private key, on your device, that maps those placeholders back to your real words — which is how the chat reads back to you normally instead of in placeholders. That key is never sent to us and never sent to anyone.
Two consequences you are entitled to weigh. If you open the same chat on a different device, you will see the placeholders instead of your real words — that is the system working, not a bug. And if someone else uses your browser, they can read your chat back in plain form. Clear your browser's site data to destroy the key.
4. What we share, and with whom
RCW 19.373.020(1)(a)(iii).
"Share" is defined broadly in RCW 19.373.010 — to release, disclose, disseminate, divulge, make available, provide access to, license, or otherwise communicate consumer health data, by any means. It excludes disclosure to a processor, where the processor is handling the data for a purpose consistent with the purpose we collected it for. It does not exclude disclosure to an affiliate — which is why § 5.1 names ours.
4.1 Before anything leaves your browser
Gale de-identifies your chat message on your own device, before it is sent. Names, dates of birth, phone numbers, email addresses, street addresses, and record numbers are replaced with placeholders like [NAME_1]. Google receives the placeholdered text, not what you typed. The key that maps a placeholder back to your words never leaves your device (§ 3.1). A document you attach is read into text inside your browser and de-identified there too; the file itself is not uploaded.
This engine is measured, not perfect, and we will not describe it as perfect. Against our own benchmark it is required to hit 100% recall on direct identifiers (names, Social Security numbers, record numbers, phone numbers, email addresses, addresses, full dates, account and plan numbers), at least 95% recall across all eighteen HIPAA Safe-Harbor identifier classes, and at least 90% precision, and the build fails if it does not. But free text can still describe you in ways no engine can catch — "my son's school," "the clinic on my street." Do not treat the chat as anonymous.
And it removes identifiers, not content. The health content of your question still goes to Google. That is the only way the chat can answer it.
Since 7 August 2026 a second pass runs on our own server for chat in the iPhone app, and it is a net, not a replacement. Before the text of one of those turns is handed to Google, our server sweeps it once more for identifiers that have a recognisable shape — Social Security numbers, record and chart numbers, phone and fax numbers, email addresses, street addresses and PO boxes, ZIP codes behind a cue, dates of birth, and account, health-plan and license numbers — and replaces each one with a tag like [PHONE]. It sweeps what you typed, your earlier messages in the conversation, the names of your own counters, and the medication text the app is being built to send. It is deliberately not clever: it finds shapes, so a bare name ("Sam called me") goes straight through it, and it is the de-identification on your own device (above) that is the real protection. We log only how many it replaced and of which kind — never the text, and never the values.
The same de-identification runs in the iPhone app, on your phone, before your question leaves it — and it runs whether or not the switch in § 2.5 is on, because it is not a setting. The numbers that switch governs are a different thing and it would be misleading to say they are "de-identified": they are whole numbers with no date, place, or coordinate in them to remove. What makes them safe to send is that there is nothing in them but the number, and § 2.5 lists every one there is. One item alongside them is not a number and we will not describe it as one: the name you gave a counter you made yourself is your own text and travels as you wrote it — the second pass above strips a phone number or a record number out of it, and nothing can strip a name out of it. § 2.5 says so in full.
4.2 The categories we share
| What we share | With whom | Why | Basis — RCW 19.373.030(1)(b) |
|---|---|---|---|
| Your chat question, de-identified in your browser first (§ 4.1), plus the article you were reading, plus placeholdered text you attached from a document | Google (Gemini on Vertex AI) | To generate the answer you asked for. This is the only way the chat can work. | (ii) necessary for the service you requested — see § 5.3 for the honest limit on this |
| In the iPhone app: a few whole numbers from your own tracking, attached to that question — steps today, last night's sleep, meditation minutes this week, the count of medicines you ticked off today, the count of connections you noted this week, and up to eight counters you made yourself. Never a medicine name and never a name from your contacts — but the short name you gave a counter is your own text and goes as you wrote it (§ 2.5) | Google (Gemini on Vertex AI) | So the answer can be about you rather than about people in general | (ii) necessary for the service you requested — and only while the "Let Gale's AI use my saved details and numbers" switch is on (§ 2.5) |
| In the iPhone app: one day of your food diary, when your question is about it — the foods you logged, the portions you gave them, the calories where we know them, and the day's total. Fetched by our server from your own diary, not sent up from the phone | Google (Gemini on Vertex AI) | So a question about what you ate is answered from what you actually logged | (ii) necessary for the service you requested — same switch (§ 2.5) |
| In the iPhone app: the one-line situation behind a suggestion you tapped "Ask Gale about this" on — the restaurant name from your own calendar, what Gale suggested there, and coarse words for the shape of your day | Google (Gemini on Vertex AI) | So a question about a suggestion is answered against the evening you are actually in | (ii) necessary for the service you requested — same switch |
| Not shared today — six categories the app is built to attach, each behind its own off-by-default switch (§ 9.1, its first six rows; the last two rows there are about keeping a reading, not about sharing one): your medication list in your own words; weekly movement minutes; a categorical one-line plan summary (food, movement, meditation, or the connection intentions you wrote); daily protein/fat/carbohydrate totals; your sleep for the last two weeks; your age as a range | Google (Gemini on Vertex AI), when and if it begins | The same purpose — an answer about you. Disclosed here before it exists for you, as § 4.3 does | Neither (i) nor (ii) today. Each is a new category, so RCW 19.373.020(1)(c)–(d) requires this policy updated and your affirmative, per-category consent before the first send — § 9.1. Nothing in this row is being shared |
| A search query derived from your chat question, where you have asked for a grounded answer | Google (Search, via Gemini's grounding tool) | To find current sources for the answer | (ii) necessary for the service you requested |
| Everything we store — chat transcripts, care-gap signups, scheduling requests, usage counters | Google (Firebase — Firestore, Authentication, Cloud Storage) | This is our database and our identity provider. It is where the data lives. | (ii) processor — this is our infrastructure |
| Your IP address, your browser, and the web address you requested — including, today, the words you type into the care front door (§ 3) | Vercel (web hosting); Google Cloud Run (backend hosting) | Ordinary request logs, generated by serving you a page | (ii) processor — this is our infrastructure |
| Your email address, and a message body containing only your name and a link or a code | Mailgun (email delivery) | Only if you have asked us to contact you. No message is sent to a real person today — see below. | (ii) necessary for the service you requested |
| Your phone number, and a message body containing only your name and a link or a code | Twilio (SMS delivery) | Only if you have asked us to contact you. No message is sent to a real person today — see below. | (ii) necessary for the service you requested |
| Your name, your date of birth, your callback number, insurance detail, the coarse kind of care you want, your preferred times — and the live audio of the call if you join it | Twilio (Programmable Voice / Conference) and OpenAI (Realtime API) | If you ask Gale to telephone a clinician's office on your behalf. This feature is switched off. It structurally cannot dial a real person's identity to either vendor until both vendors sign an agreement with us. See below. | (ii) necessary for the service you requested — not exercised today |
A scanned image or a photograph attached to the chat is a separate case. It is read by Google's vision model to lift the text out of it — but that path is part of our demonstration build and is refused for real accounts, and it will stay refused until we have a signed Business Associate Agreement with Google. A real account cannot send an image to Google through Gale today.
The voice call, honestly. Gale has built — but has not switched on — a feature that telephones a clinician's office on your behalf, with an AI voice agent on the line and you able to join. It is off. It requires two vendors we have no agreement with, and the code refuses to dial a real person's identity to either of them. We name it here, and name both vendors, so that nothing can arrive unannounced. If we ever turn it on: the call would not be recorded unless every party consented under the law of the strictest state involved; a fixed announcement would disclose the AI, the recording, and your presence on the line before any audio reached a vendor; and the vendors would receive only what you consented to send — your name, date of birth, callback number, insurance detail, coarse care type, and preferred times — never your chart and never your history. Afterwards, Gale would keep an identity-free record that a call happened and how it went, and an aggregate count of how a clinician's office answers calls, keyed to the clinician's public professional number. Neither carries your identity.
Two things are true of every message we ever send you, and they are enforced in the code: the body carries logistics only — a name and a link or a code — and never a diagnosis, a score, or a range; and we would rather send you nothing than send you the wrong thing — if we have not recorded your permission to contact you, the system refuses to send rather than sending by default, and logs the refusal.
But do not rely on that today, because today we do not contact anyone at all. A scheduling request is written with a permanent never-send marker and is transmitted to no one. No part of our code reads a care-gap signup or a scheduling request in order to send a message. And contacting a real person requires a legal switch that is off. Those are structural facts, not settings.
4.3 One path we are telling you about before it exists for you
If you save a screening result to an account and then ask Gale's chat to discuss it, or ask Gale to compose a summary of it to share with a clinician, your score, the range it falls in, the suggested talking points, and — for the PHQ-9 — whether you endorsed the question about thoughts of self-harm would be sent to Google (Gemini) to write that text. That is the only way a result would leave our database.
Today you cannot do this, because you cannot save a screening result at all — our database rules refuse the write for a real account (§ 2). This path exists only inside our demonstration build. We are disclosing it now, before it is switched on, because when it is switched on it will be the most sensitive thing on these surfaces and you should not learn about it on the day.
4.4 We share nothing else
We do not share consumer health data with advertisers, ad networks, data brokers, analytics vendors, or social platforms — because we do not use any of them. There is no such vendor in our code to share with.
5. Affiliates, and the third parties we share with
RCW 19.373.020(1)(a)(iv) is asymmetric. Third parties may be disclosed by category. Affiliates must be named specifically.
5.1 Affiliates
Today, Gale Care Inc. shares consumer health data with no affiliate.
The clinicians and clinician-owned professional entities that use Gale are independent practices. Gale is their administrative-services contractor and, under HIPAA, their business associate. We do not route consumer health data from these public surfaces to a practice unless you ask us to — for example, by submitting a scheduling request naming a clinician. Whether any of those entities is an "affiliate" as this statute defines the word is a live question that depends on facts about Gale's corporate structure that are not yet settled.
5.2 Third parties — named, not just categorized
| Category | Who | What they receive | BAA signed? | Data-processing terms |
|---|---|---|---|---|
| Generative AI provider | Google (Gemini on Vertex AI) | Your chat text, de-identified in your browser first; placeholdered text from attachments; a search query derived from your question; if the demonstration paths are ever opened to you, a screening score, its range, talking points, and PHQ-9 item-9 status (§ 4.3) | ✅ Yes (13 Jul 2026) | Covered by the Google Cloud terms + HIPAA BAA. See § 5.3. |
| Cloud infrastructure and identity | Google (Firebase — Firestore, Authentication, Cloud Storage) | Everything Gale stores | ✅ Yes (13 Jul 2026) | Google Cloud Data Processing Addendum (standard Cloud terms) |
| Web and application hosting | Vercel; Google Cloud Run | Request logs — IP address, browser, requested web address (including, today, care-front-door text — § 3) | No | Governed by Vercel's and Google Cloud's standard data-processing terms |
| Email delivery | Mailgun | Your email address; a logistics-only message body | No | Governed by Mailgun's standard data-processing terms |
| SMS delivery | Twilio | Your phone number; a logistics-only message body | No | Governed by Twilio's standard data-processing terms |
| Telephony for the care-finding call (switched off) | Twilio (Programmable Voice / Conference) | Phone numbers and live conference audio. Opaque identifiers only — never a name, a date of birth, or an insurance detail in a web address or a conference name | No | Governed by Twilio's standard data-processing terms |
| Voice AI for the care-finding call (switched off) | OpenAI (Realtime API) | Live call audio, and the session instructions built from the scope you consented to — your name, date of birth, callback number, insurance detail, coarse care type, preferred times. No chart. No history. | No | Governed by OpenAI's standard data-processing terms |
| The FDA label of a medicine you name | openFDA — api.fda.gov (U.S. Food and Drug Administration) | The name of one medicine, and nothing else. When you ask the chat whether medicines can be taken together and you name a drug, we send that drug's generic name — drawn from a fixed list of 140 — so the answer can quote what the manufacturer's own FDA-approved label says. Nothing of yours goes with it: not your question, not your medication list, not your name, account, or any identifier. Two people asking about the same medicine send exactly the same request | Not required — nothing that reaches it is health information about you. That is built, not promised: one file in our code can reach it, it refuses to send anything that is not one of those 140 names, and a build check fails if that changes | Public U.S. government open data (open.fda.gov/license) |
| Advertising, analytics, data brokers, social platforms | None. We use none of them. | Nothing | Not applicable | Not applicable |
Google signed the Google Cloud HIPAA Business Associate Addendum on 13 July 2026, covering its infrastructure and the Vertex AI model. The other subprocessors named here have not. None is required for these consumer surfaces today, because there is no protected health information in them. Each remaining vendor must sign one before Gale serves a real patient. That is a gate, not an aspiration.
openFDA is the one row where "no agreement" is a permanent answer rather than a pending one, and it is worth separating from the rest. Every other vendor above will need an agreement before Gale serves a real patient, because sooner or later something of yours could reach it. openFDA is different in kind: what we send is a drug's name from a fixed list, and there is no configuration of the product in which anything about you can be added to it. Nothing of yours can reach it, so nothing about you needs to be governed there. This did not add a new category of your information — it added a place we look something up.
5.3 The honest disclosure about Google — and what it means for you
Your chat text goes to Google's Gemini model on Vertex AI, which is covered by the Google Cloud HIPAA Business Associate Addendum Gale signed on 13 July 2026 — the version of the model a real agreement reaches. (Until that day it went to Google's consumer AI endpoint, which no such agreement covered; we moved it.) Your name, your phone number, your email address, your street address, and dates are removed in your browser before the message is sent (§ 4.1) — but the health content of the question is not, because removing it would leave nothing to answer.
The agreement governs what Google may do with the text; it does not stop the text being sent. Ask the chat what you are comfortable having Google process under that agreement. Every other part of this site works without it.
6. We do not sell consumer health data
RCW 19.373.010 defines "sell" as the exchange of consumer health data for monetary or other valuable consideration.
Gale does not sell consumer health data. Not for money. Not for anything else of value. Not in exchange for services, discounts, data, or access.
Because we do not sell it, we never seek — and you will never be shown — the valid authorization to sell that RCW 19.373.070 would require. There is no form on this site that would let you authorize us to sell your health information, because we do not want one and would not use one.
We also do not use consumer health data for targeted advertising, and we do not share it for cross-context behavioral advertising. As § 2.1 says: there is no advertising or analytics code on this site to do it with.
7. Geofencing
RCW 19.373.080 makes it unlawful to implement a geofence — a virtual boundary of 2,000 feet or less around a physical location — around an entity that provides in-person health care services, where the geofence is used to identify or track consumers seeking health care services, to collect consumer health data from them, or to send them notifications, messages, or advertisements related to their health data or health care services.
Gale draws no boundary around any health care facility, and none around any place you did not choose yourself. We are going to describe the one boundary the software can draw, in full, because a policy that says "no geofence" while an app draws one is not a policy you can rely on.
On this website: none. No page of gale.care reads your location, precise or coarse. There is no boundary, no beacon, and no third-party advertising or analytics code that could draw one on our behalf.
In the Gale Care iPhone app: one, and you create it. If you turn on "Suggestions in the moment," and then turn on "Meals in your calendar," the app looks at your own calendar for an event in the next eight hours that reads like a meal out. If that event carries an address, the app asks iOS to tell it when you arrive there — a circle of about 1,000 feet around the restaurant on your own calendar. That is the entire mechanism. These are its edges:
- The centre is an address from your own calendar, on an event you created. Gale never picks it, and Gale keeps no list of places to watch. There is no boundary around any address Gale chose — not a clinic, not a hospital, not a pharmacy, not anyone's office.
- One at a time, and only while that meal is pending. The circle is removed the moment the meal passes, the event is cancelled, or you turn either switch off. There is no standing set of boundaries.
- Your phone holds the boundary. Gale never learns it. The circle is registered with iOS; arriving inside it wakes the app on the device. No coordinate, no address, and no arrival is transmitted to Gale, and none is stored on our servers.
- What it can do when it fires is show you the line the app was already showing — a suggestion about the meal, worked out on the phone. Only if you also turn on the third switch, "A note when you arrive," does that same line reach your lock screen. It is never new words, never at night, and never a second time without an answer from you.
- It is not used to identify you, to track you, to work out that you are seeking health care, or to collect health data from you. It reads one fact — you arrived at the restaurant on your calendar — and lets go of it when the meal is over.
We are not going to claim a check we have not built. The app tests whether a calendar event reads like a meal; it does not test whether the address on it belongs to a health care facility. If you put a clinic's address on an event called "coffee," the software would not know the difference. We would rather tell you that than describe a safeguard that is not in the code.
If you want none of this, do nothing. All three switches are off until you turn them on, and iOS asks you separately for permission before any of them can run. Turning "Suggestions in the moment" off removes the boundary immediately.
Connecticut's parallel prohibition uses a 1,750-foot radius around mental health, reproductive health, and sexual health facilities. The same answer holds for both statutes: the only boundary Gale draws is around a restaurant on your own calendar, at your request, with nothing leaving your phone — and none around a health care facility of any kind.
8. Your rights, and how to exercise them
RCW 19.373.020(1)(a)(v) requires us to tell you how to exercise the rights in RCW 19.373.040. RCW 19.373.040(1)(d) separately requires that a request be makeable by a secure and reliable means established by us and described in this policy. § 8.3 is where we do that.
We grant these rights to every person who uses these surfaces, wherever you live. We do not ask what state you are in before honoring a request.
8.1 Your rights
You can confirm whether we are collecting, sharing, or selling your consumer health data, and get a copy of it — RCW 19.373.040(1)(a). Your request also entitles you to a list of every third party and affiliate we have shared or sold it to, with an active email address or other online way to contact each of them. We will provide that list, and those contacts, with our response. (We do not sell, so the "sold to" list will always be empty.)
You can ask us to review, and to change, your consumer health data. Tell us what is wrong at the address in § 8.3 and we will correct it or tell you why we cannot.
You can withdraw your consent to our collecting and sharing your consumer health data — RCW 19.373.040(1)(b). Until now there was no consent to withdraw. There is one now, for as many of the § 9.1 categories as you have switched on: outside those, we still rely on your consent for nothing described in § 2, because we collect only what is necessary to do the thing you asked us to do. § 9.1 says what we ask and how to withdraw it, category by category and as easily as you gave it — and for a kept reading, withdrawing deletes what was kept. We honor a withdrawal the same way we honor a deletion request. (The switch described in § 2.5 is a control over what already ships, not a consent under this Act — § 9.1 says why the difference matters.)
You can ask us to delete your consumer health data — RCW 19.373.040(1)(c). On a verified request, the law requires us to delete it from our records, including from every part of our network and from archived and backup systems, and to notify every affiliate, processor, contractor, and third party we shared it with. Read § 8.2 before you rely on that, because we are going to tell you exactly what we can and cannot do today.
You cannot be discriminated against for exercising any of these rights — RCW 19.373.030(1)(d). Exercising a right will never change the care you are offered, the price you are quoted, or the quality of the service you get.
8.2 What we can actually do today
We are not going to describe a capability we do not have.
Gale has not yet built an automated way to delete what we hold. A deletion request today is carried out by a person, by hand, when you write to us.
- A saved screening result — you can delete yourself, from your account, at any time. (Today a real account cannot save one in the first place — § 2.)
- A chat transcript, a care-gap signup, a scheduling request — we will find and delete these by hand when you ask us at the address in § 8.3.
- A sleep or step reading you asked us to keep — you delete yourself, by turning that category off in the app. The rows go; they are not hidden. You can also ask us at the address in § 8.3, and if you delete your account they go with it.
- Our usage counters — we cannot delete, and we are telling you rather than promising. They carry no name, no email, and no account: only a page name and a random number for a browser tab, destroyed when you close it. We cannot pick yours out, because we never knew they were yours.
- Copies in a backup — we cannot yet promise are gone. The law gives us up to six months from the day we verify your request to purge archived and backup systems (RCW 19.373.040(1)(c)(iii)). We will delete from our live systems first, and from backups as they cycle. We will never restore your data from a backup after you have asked us to delete it. But we have not yet built and verified a backup-purge path, and we are not going to tell you it is done when we cannot check it.
- Notifying everyone we shared it with — we will notify every vendor with whom we have a contract. Our agreement with Google covers the chat (§ 5.3), but there is still no channel by which to ask Google to recall a message already sent. That is one more reason § 5.3 is written the way it is.
What we cannot delete, and will not pretend to: your medical record, if you are a patient of a practice that uses Gale. That record is held for the practice as the party in charge of it. HIPAA grants no right to delete a treatment record, and state medical-record retention laws require the practice to keep it. It is also exempt from this Act under RCW 19.373.100 and outside this policy entirely. The deletion right above attaches to your consumer health data — your chat, your screeners, your searches, your signups.
8.3 How to submit a request
legal@gale.care Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA Bill Nguyen, CEO
You do not need to create a Gale account to make a request. If you already have one, we may ask you to use it. We have chosen these methods with regard to how people actually use Gale and to our ability to verify that a request is really yours — RCW 19.373.040(1)(d).
We will ask you for enough information to be confident the request is yours. We verify who the consumer is, not merely who is asking. Verification steps do not extend our deadline.
8.4 How we respond, and what it costs
We will respond without undue delay and in every case within 45 days of receiving your request — RCW 19.373.040(1)(g). We may extend that once, by 45 additional days, when reasonably necessary given the complexity and number of requests. If we extend, we will tell you within the first 45 days, and we will tell you why.
Our response is free. We will answer up to two requests from you per year at no charge. If requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee to cover our administrative costs, or decline to act — and if we do, the burden is on us to show why — RCW 19.373.040(1)(f).
8.5 If we refuse — your right to appeal, and to complain about us
If we refuse to act on your request, we will tell you why, and we will tell you how to appeal — RCW 19.373.040(1)(h). The appeal is as easy to use as the original request: write to the same address in § 8.3, with "Appeal" in the subject line.
Within 45 days of receiving your appeal, we will tell you in writing what we did or did not do, with a written explanation of our reasons.
If we deny your appeal, we will give you a way to complain about us to the Washington Attorney General. We are required to give you this, and we will. The Washington Attorney General's consumer complaint system is at www.atg.wa.gov/file-complaint.
8.6 If you are a minor
These rights are yours, not your parent's.
A minor who uses these surfaces has full access to their own consumer health data and may delete it.
A parent or guardian who asks us for a minor's screening results, chat, or searches will not receive them where state law lets that minor consent to the care on their own — mental health, substance use, reproductive health, sexual health, and gender-identity categories. Every instrument named in this policy — the PHQ-9, the GAD-7, the ACEs, the PC-PTSD-5, the AUDIT-C — is squarely inside those categories.
That restriction is decided by a per-state, per-service, per-age consent engine, not by a static list, and not by whoever happens to ask.
9. How we will tell you if this policy changes
We may not collect, use, or share additional categories of consumer health data, or use it for additional purposes, beyond what is disclosed above, without first updating this policy and obtaining your affirmative consent before the new collection, use, or sharing begins — RCW 19.373.020(1)(c) and (1)(d).
That means this is not a document we can quietly revise. A new category or a new purpose requires a new disclosure and a new, freely given, specific, informed, opt-in agreement from you — and the consent request itself must tell you the categories collected or shared, the purpose and the specific ways the data will be used, the categories of entities it is shared with, and how to withdraw your consent, as RCW 19.373.030(1)(c) requires. Consent cannot be buried in terms of use, and it cannot be obtained through a dark pattern.
How we will notify you of a material change to this policy: We will notify you by email to the address on file for your account, update the effective date, and post the change on this page.
9.1 The eight categories we are asking about — six before we send them, two before we keep them
§ 2.5 and § 4.2 name six kinds of information the iPhone app is built to attach to a chat question, and say that none of it is being attached. The last two rows are a different act and the table says which: they are not sent with a question, they are kept — the reading a surface already shows you, written beside the day it belongs to. Sending and keeping are separate asks and neither one grants the other. This is the part that says what has to be true first, in the order it has to be true.
| The category | What it would be | Where it is today |
|---|---|---|
| Your medication list, in your own words | The names, and the dose and schedule text exactly as you typed them — never normalized by us into a dose we computed | Not sent. The list is on your phone |
| Weekly movement minutes | One whole number, like the meditation minutes already described in § 2.5 | Not sent |
| A plan summary | One categorical line about where you are in a plan you follow — food, movement, meditation, or the connection intentions you wrote for yourself. Never the intentions themselves, and never a person's name | Not sent |
| Daily protein, fat and carbohydrate totals | Day totals from what you logged in the food diary. When you ask about your food log, the foods themselves already go — that flow is disclosed in § 2 and § 4.2 and is not pending; these are the macronutrient totals alongside them | Not sent |
| Your sleep for the last two weeks | How long you slept on each of the last 14 nights you recorded, and the usual your phone works out from them. Nights you did not record are simply not there — there is no zero standing in for a night you did not wear the watch. Not the stages, not the times you went to bed | Not sent. The switch exists; it is off |
| Your age, as a range | One of seven ranges, like 40-49, worked out on your phone from the birth year you gave when you set the app up. Never your birthday, and never the year itself — a range cannot be turned back into a date | Not sent. The switch exists; it is off |
| Your sleep, kept as a record | The hours you slept on a night your phone recorded, written down beside the day it belongs to — nothing worked out from it, no usual, no rating of the night | Not kept until you turn it on. The switch is off until you do — and with it on, the reading is kept |
| Your steps, kept as a record | The step count your phone recorded for a day, written down beside that day — the number only, never a place, never a time of day, and never a share of a target | Not kept until you turn it on. The switch is off until you do — and with it on, the reading is kept |
Since 7 August 2026 the app carries the switches themselves — and a switch existing is not the ask happening. In the app's You tab, under "What Gale's AI may see," there is now one switch for each of these, named for the data rather than for a benefit: "My medication list"; "My movement minutes this week"; "My sleep for the last two weeks"; "My age, as a range"; and, for the plan summary, one per plan you might follow — "Where I am in my food program," "Where I am in my movement program," "Where I am in my meditation program," and "The shape of my connection plan." (The fourth row — the protein, fat and carbohydrate totals — has no switch, because the app cannot send them at all yet.) Every one of them starts off. Each is its own act: there is deliberately no control that turns them all on, because a single switch that grants six categories is exactly the bundling RCW 19.373.030(1)(c) forbids. Turning one off stops that category on the very next question you ask. And all of them sit under the "Let Gale's AI use my saved details and numbers" switch from § 2.5 — turning that master switch on turns none of these on, and turning it off stops everything at once. The app records your choice with your account; on a build our server does not yet understand, it keeps the record on your phone and tells you so on the spot, and signing out then clears it.
Since 24 August 2026 the app carries the two keeping switches, in their own section, and they are not under the master switch. In the same You tab, under a separate heading — "What Gale keeps" — there is one switch for each of the last two rows: "My nightly sleep hours" and "My daily step count." Both start off, each is its own act, and there is no control that turns both on. Three differences from the switches above, and you should not have to find any of them. First, these are about keeping, not about sending: what they govern is a reading being written down beside a day, not a number riding a question. Second, the master switch does not govern them — "Let Gale's AI use my saved details and numbers" is about what Gale's AI may look at, and turning it off does not stop a reading being kept; only that category's own switch does. We put them under their own heading for exactly that reason, because dimming them with the master switch would tell you something untrue. Third, turning one off deletes the rows that category kept. It does not stop new ones and leave the old ones sitting there.
What turning the medications switch on does, stated precisely — because this is the row to read twice. While "My medication list" and the master switch are both on, your medication list — your own words: each name, and the dose and timing text as you typed them — travels with every question you ask. Not only questions about medication: there is no filter in the app that decides whether a question "needs" your list, and the app's medications page tells you the same thing in as many words. And if Gale's answer says your medication names back to you, that answer — with those names in it — is kept in your stored conversation for its 365 days (§ 2.4), exactly as a medicine you type into the chat yourself already is. You can delete the conversation at any time (§ 8.2); you cannot have the answer without the sentence it is in.
For each of them, in this order:
- This policy says so first — that is this page, and this is the version that says it.
- We ask you, for that category by itself. The request will name the category, why we want it, and how to withdraw — and, for the six that are sent, that they go to Google's Gemini model on Vertex AI; for the two that are kept, how long they are kept and that turning the switch off deletes them — RCW 19.373.030(1)(c). One ask per category. Agreeing to your movement minutes is not agreeing to your medication list, agreeing that your sleep may be sent with a question is not agreeing that it may be kept, and we will not offer you a single box that means all eight.
- You say yes, and only then does it begin. No sooner. If you say nothing, nothing is sent and nothing is kept; if you say no, nothing is sent, nothing is kept, and nothing else about Gale changes.
- You can withdraw, category by category, the same way and as easily — § 8.1.
The switch in § 2.5 is not that consent, and we are not going to treat it as though it were. "Let Gale's AI use my saved details and numbers" is on by default and it covers everything at once. RCW 19.373.030(1)(c) requires consent that is freely given, specific, informed, and opt-in, and RCW 19.373.030(1)(d) forbids obtaining it through a dark pattern. A default-on switch is none of those things for a category you have never been told about. It is a control we give you over what already ships; it cannot double as permission for what does not.
Two things we owe are outstanding right now, and both are ours to do, not yours — and neither of them is what holds a category shut. Counsel has not re-reviewed this version. That review runs on its own track, it is not claimed here as done, and this page will keep saying so until it is. And the § 9 email notice — outstanding since version 1.1 — has not been sent. It is a notice owed to account holders, and the accounts on this lane today are synthetic and demonstration accounts; the obligation therefore attaches when a real account holder first has a reading kept. It is not discharged, not waived, and not claimed to have gone out.
What holds a category shut is your own switch, and always was. It is off until you turn it on, it is one act per category with no control that grants several at once, you can turn it off again as easily as you turned it on, and for a kept reading turning it off deletes what that category kept. Until you turn one on, the eight rows above stay exactly where they are.
An earlier version of this section said something different, and this replaces it. It said no category begins for anyone until counsel has re-reviewed and the notice has gone out. That was an overreach by the author of that text: it turned two things Gale owes into gates on shipping code, which is not what either of them is for. The founder corrected it. Counsel's review continues, on its own track, and what is written above is the whole of what stands between a category and you.
And one thing that is new with the last two rows, said here rather than left for you to work out. Until now, a switch we had shipped early was inert — the app carried the control, but the part that would have written anything did not exist, and on top of that our server refused the write whatever the switch said. Neither is true of the two keeping switches any more: the code that writes a reading down exists, it is running, and the server accepts it. So your switch is doing the work now rather than standing in for it. Turn one on and a reading is kept from that point; turn it off and the rows that category kept are deleted. We are writing that down because the previous version of this paragraph told you the safeguard was that we would not put the build in front of you, and that is no longer the arrangement — the safeguard is the switch, and it is yours.
Version: 1.8 · Last updated: 2026-08-24 · Effective: August 24, 2026 — a revision takes effect on the day it is posted here. The policy itself has been in force since July 13, 2026 (§ 10).
What changed in 1.8 (2026-08-24). This version changes nothing about what is kept, for how long, or what turning a switch off does. It replaces the sentences that said who may begin a category, and when.
What the last version said, and why it was wrong. Version 1.7 said no category begins for anyone until counsel has re-reviewed this instrument and the § 9 email notice has gone out. Two things Gale owes were written into this page as preconditions on shipping code. That is not what either of them is. Counsel reviews the published instrument, on its own track, and a review that has not happened is a debt rather than a gate; the § 9 notice is a notice owed to account holders. Making them gates was an overreach by the author of that text. The founder corrected it, and counsel's review continues on its own track.
Neither is claimed to have happened, and neither is waived. Counsel has not re-reviewed any version since 1.1 (2026-08-06). The § 9 email notice has not been sent and has been outstanding since version 1.1 — and it is here re-scoped rather than discharged: it is owed to account holders, the accounts on this lane today are synthetic and demonstration accounts, and so the obligation attaches when a real account holder first has a reading kept. Both stay recorded as outstanding on this page until each is done.
What gates a category is your own switch. Off until you turn it on, one act per category with no bundle control, revocable as easily as it was given — and for a kept reading, turning it off deletes what was kept rather than hiding it. That was always the clause that mattered and it is unchanged.
What is new in the code, and it is the whole of the change. Until today our server refused to write a kept reading regardless of what your switch said. That refusal is lifted. A category you turn on now actually keeps a reading — which is what a granted category is supposed to do, and what makes your switch a real one rather than a preference we recorded.
On ordering, plainly. Version 1.7 recorded that the page and the code landed in the same commit. Today's server change lands ahead of counsel's re-read of any version since 1.1. That is written here rather than left standing as a claim this page can no longer make. § 2.5, § 9.1 and the § 9.1 table are the sections rewritten.
What changed in 1.7 (2026-08-24). § 9.1 gains two categories, and these are kept rather than sent: your sleep, kept as a record and your steps, kept as a record — the reading a surface already shows you, written beside the day it belongs to, held for one hundred and eighty days, and deleted by the database itself. Nothing is derived from either: no usual, no score, no band, no proportion. Turning a category off deletes what was kept; it does not hide it. § 2 gains its row, and § 1.2, § 2.3, § 2.4, § 2.5, § 8.1 and § 8.2 are corrected — several of them said in print that no store of your steps or your sleep exists on our servers, and that is the sentence this version replaces. § 9.1 also records that the two keeping switches sit outside the master switch from § 2.5, because that switch is about what Gale's AI may look at and turning it off does not stop a reading being kept. On the day it was posted, the page and the code landed in the same commit. Version 1.6 had recorded two switches shipping in the morning and the page being written in the afternoon, and that was not repeated. That is not a claim this page can go on making, and 1.8 above says so: a server change landed the same day, ahead of counsel's re-read. Superseded by 1.8 on one point. This entry ended by saying no category begins until counsel has re-reviewed and the § 9 notice has gone out. That sentence no longer states the gate — read 1.8. Counsel's re-review and the § 9 notice both remain outstanding.
What changed in 1.6 (2026-08-10). § 9.1 gains two categories, and this entry records that they arrived in the wrong order. The two: your sleep for the last two weeks — how long you slept on each of the last 14 nights you recorded, plus the usual your own phone works out from them, with nights you did not record simply absent rather than written down as zero — and your age, as a range, one of seven bands like 40-49, worked out on your phone from the birth year you gave at setup and never the birthday or the year itself. Both switches are off, both are their own act, and nothing of either has been sent. The order was wrong. This policy's own promise is that it says a category first and the app carries it second; on 10 August 2026 the app's two switches were committed in the morning and this page was written in the afternoon. Nothing began in the interval — the switches default off and the § 9 preconditions are unmet, so no category could have begun regardless — but the sequence is the promise, and it was not kept. It is recorded here instead of being quietly repaired, for the same reason every other correction on this page is. This version starts nothing: counsel has still not re-reviewed, the § 9 notice has still not been sent, and no category begins until both are done and you turn that category on yourself. (Superseded on that last clause by 1.8: counsel's re-review and the § 9 notice are no longer stated as preconditions on a category beginning. Both remain outstanding; your own switch is the gate.)
What changed in 1.4 (2026-08-07). The iPhone app now carries the switches for the § 9.1 categories, and this version says so before any of them can be used: one per category, named in § 9.1 as the app names them, every one off until you turn it on, each its own act with no all-at-once control, all under — never inside — the master switch from § 2.5. Three of the four § 9.1 rows have a switch (the plan summary has one per plan, four in all); the macronutrient totals have none, because the app cannot send them at all yet. § 9.1 also now states precisely what the medications switch does when it is on: your list — your own words — travels with every question you ask, not only medication questions, and an answer that says your medication names back to you is kept in your conversation for its 365 days. This version starts nothing: no category is being sent, and none may begin until counsel re-reviews, the § 9 notice goes out, and you turn that category on yourself — the same order § 9.1 has required since v1.2, restated here because shipping the switch is not asking the question. (Superseded on that last clause by 1.8: counsel's re-review and the § 9 notice are no longer stated as preconditions on a category beginning. Both remain outstanding; your own switch is the gate.)
What changed in 1.3 (2026-08-07). Three corrections to version 1.2, made the same day it was posted, because a correction that overstates is still an untruth. First: 1.2 said the list was "numbers, not sentences" with "no name … and nothing you wrote in free text." That is not true of the name you gave a counter you made yourself — it is your own text, it crosses as you wrote it, and no filter can take a person's or a medicine's name out of it. § 2, § 2.5, § 4.1 and § 4.2 now say so, and § 2.5 tells you to name your counters accordingly. Second: 1.2 said "our server accepts nothing but those integers." Since 7 August 2026 the server is built to receive the § 9.1 categories as well; the app sends none of them, so those sentences now say what the app attaches and § 2.5 states what the server can hold and cannot be asked for. Third: when you ask the chat about your food diary, our server already fetches that day and hands the foods, portions, calories and day total to Google. That flow had only a subordinate clause in § 9.1; it now has its own row in § 2 and § 4.2. § 4.1 also describes the server-side identifier sweep that shipped the same day. All three are corrections about what already ships; none of them starts anything new.
What changed in 1.2 (2026-08-07). § 2.5 was corrected: it had said the app read your steps and sleep on the phone "without sending them to us," and that none of it became a record at Gale. The first was untrue of the shipped app — those numbers, and four others, are attached to a chat question you ask in the app. § 2.5 now lists every number there is, names the switch that governs them, and says what is and is not kept. § 2 and § 4.2 gained the rows that flow was missing. § 4.1 says plainly that the numbers are not "de-identified" — there is nothing in them to remove. § 9.1 is new: the four categories the app is being built to carry, and the per-category consent that has to come first. This version corrects the record about what already ships; it starts nothing new.
10. Nevada
Nevada Senate Bill 370 (2023), codified in NRS chapter 603A, is structurally parallel to Washington's Act and requires a published consumer health data privacy policy of its own. Everything in this policy applies to consumers in Nevada, and specifically:
- We collect consumer health data only with your consent, or as necessary to provide a product or service you requested (§ 2).
- The categories we collect, the purposes, the categories of sources, the categories of third parties and affiliates we share with, and the categories we share are stated in §§ 2, 3, 4, and 5.
- You may review your consumer health data and request changes to it. Submit that request the same way as any other, at the address in § 8.3, and we will correct it or tell you why we cannot (§ 8.1).
- How we notify you of a material change to this policy is stated in § 9.
- No third party collects consumer health data over time, or across different websites or online services, through Gale (§ 2.3). We carry no third-party trackers.
- We do not sell consumer health data, and we therefore never seek the separate written authorization Nevada would require before a sale (§ 6).
- You have the same rights to confirm, access, delete, and withdraw consent, exercised the same way, at the address in § 8.3.
- We operate no geofence around any health care facility. The one boundary the iPhone app can draw is around a restaurant on your own calendar, at your request, and nothing about it leaves your phone (§ 7).
- The effective date of this policy is July 13, 2026.
Nevada's law is enforced by the Nevada Attorney General. It does not create a private right of action.
11. Connecticut
Connecticut does not require a separate consumer health data privacy policy. Its health-data rules sit inside the Connecticut Data Privacy Act (Conn. Gen. Stat. § 42-515 et seq., amended by Public Act 23-56, with the consumer-health-data provisions effective October 1, 2023). The notice Connecticut requires is a general controller privacy notice under Conn. Gen. Stat. § 42-520, and it is carried in Gale's general Privacy Policy, not here.
This section states only the health-data-specific commitments, which apply to you in Connecticut:
- Under the CTDPA, consumer health data is sensitive data, which requires your opt-in consent to process and separate consent for any sale.
- We do not sell, so the sale-consent question never arises (§ 6).
- Connecticut's geofence prohibition uses a 1,750-foot radius around mental health, reproductive health, and sexual health facilities. We draw no boundary around any such facility — the only one the iPhone app can draw is around a restaurant on your own calendar, at your request, with nothing leaving the phone (§ 7).
- Connecticut's law is enforced by the Connecticut Attorney General. It does not create a private right of action.
12. How to reach us
Gale Care Inc. Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA Delaware legal@gale.care Bill Nguyen, CEO