Privacy Policy
Effective September 2, 2026 · Your Data Health, Inc., a Delaware corporation operating in Washington State · Questions: privacy@yourdata.health
The short version
This website sets no cookies. It runs no advertising networks, no tracking pixels, and no third-party analytics that identify you. Fonts are served from this domain, so loading a page here does not announce your visit to anyone else. If you send us something through the intake form, it arrives as an email to us and goes nowhere else.
We publish this because we audit other companies and their privacy practices for a living. It would be indefensible to hold clients to a standard we do not meet ourselves.
Who we are
Your Data Health, Inc. is a Delaware corporation operating in Washington State. This policy covers yourdata.health and its pages. Our Xanadu product at xanadu.yourdata.health has its own separate privacy policy governing health data; this policy does not cover it.
What this site collects
Nothing automatic that identifies you. We do not set cookies, and we do not use
localStorage or sessionStorage. There is no login, no account, and no user profile.
Aggregate traffic measurement. We use Cloudflare Web Analytics, which is cookieless. It reports page counts, referrers and performance. It uses no client identifier, does not fingerprint your device, and cannot follow you to other sites.
What you choose to send us. The intake form asks for your name, email, company, role, organization type, what is driving your enquiry, optional FHIR endpoint details, optional links, and free-text notes. That form has no server behind it: submitting it opens an email addressed to us. We receive only what you type and send.
Who else can see it
We do not sell, rent, trade or share your information for anyone else and their marketing. We never have.
Two providers necessarily process technical data to make the site work:
- Google Firebase Hosting serves these pages and processes the connection data any web host must, including your IP address.
- Cloudflare provides the cookieless analytics described above.
Email you send us is handled by our business email provider. That is the whole list.
Retention
Because the site stores nothing, there is nothing here to retain. Correspondence you send us is kept in our email system for as long as the conversation and our business records require, and you can ask us to delete it at any time.
Your rights
Depending on where you live you may have rights to know what we hold, obtain a copy, correct it, delete it, opt out of sale or sharing (we do neither), and appeal a decision. We honour these requests regardless of whether a particular law technically reaches us, because arguing about thresholds is not the business we want to be in.
Email privacy@yourdata.health. We acknowledge promptly and respond within 45 days. If we need more time we will say so, with the reason, before that deadline passes. If we decline, we will explain why and how to appeal.
We recognise the Global Privacy Control signal. Since we do not sell or share personal information and run no targeted advertising, there is nothing here for it to switch off, but we will not ignore it.
Specific laws
Washington My Health My Data Act. This site is marketing and educational content and does not collect consumer health data. Our Xanadu product does handle health data, under its own policy.
California (CCPA/CPRA). We do not sell or share personal information, and we do not use or disclose sensitive personal information beyond providing what you asked for.
GDPR and UK GDPR. Where these apply, our lawful basis for responding to an enquiry is taking steps at your request before entering a contract. Our basis for aggregate traffic measurement is our legitimate interest in knowing whether the site works, balanced by using a method that cannot identify you.
Children
This is a business site, not directed to children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us information, email us and we will delete it.
Security
The site is static and served over HTTPS. It has no database and no login, which removes most of the ways a website leaks personal data. Our engineering pipeline scans every change for committed secrets, vulnerable dependencies and insecure configuration before it ships.
Changes
If we change this policy we will change the effective date above and describe what changed. We keep prior versions so you can see what we said and when.