Trust
Consumer Health Data Privacy Notice
For Washington and Nevada residents. Effective 8 August 2026.
Consumer Health Data Privacy Notice
For Washington and Nevada residents. Effective 8 August 2026.
https://super.ai/trust/consumer-health-data
1. Who this notice is for
This notice describes how super.AI handles health-related information for the purposes of Washington's My Health My Data Act (RCW 19.373) and Nevada's parallel statute (NRS 603A.400 to 603A.420). It is written for residents of those states, and we apply the same handling to everyone.
It is a separate notice, not a section of our general policy. Everything else about how we handle personal data is in our Privacy Policy.
We publish this notice because the duty to publish attaches as soon as consumer health data is collected, and the Act defines collection to include simply receiving it. Publishing it is not an acknowledgement that the Act's other obligations apply to us or that any particular person using our service is a consumer within its meaning.
2. What we do and do not do with health information
super.AI processes business documents. We do not ask for health information, we do not buy it, and we do not obtain it from data brokers or public sources.
We do not operate any feature that infers health conditions, diagnoses or health status about anyone. If that ever changes we will update this notice before it does.
We also do not use health-related information for advertising, we do not sell it, and we do not disclose it for targeted advertising or for any purpose other than providing the service a user asked for.
What can happen is this: a user chooses to upload a document, or paste text, that happens to contain health information. When that happens we receive that information as part of the material the user asked us to process, and we treat it the same way we treat the rest of that document.
3. Categories of consumer health data we collect, and why
Any health-related information contained in documents, files or text that a user chooses to submit to the service. That can include diagnoses, treatments, test results, medications, health-insurance and claim information, and bodily measurements, wherever they appear inside submitted material.
We collect it only because it is inside material submitted for processing, and we use it only to provide the document processing the user requested, to operate and secure the service, and to keep the records the law requires us to keep. That is collection to the extent necessary to provide a service the consumer has requested, under RCW 19.373.030(1)(a)(ii), rather than collection for a purpose of our own.
We do not collect biometric identifiers, precise location data, or health information from any source other than what a user submits.
4. Where it comes from
Directly from the user, by their own submission. There is no other source. We do not enrich, append or purchase health-related information, and we do not derive it from browsing behaviour or advertising identifiers.
5. Who we disclose it to
Only to the sub-processors that operate the service on our instructions: the cloud infrastructure that stores submitted content and the cloud-hosted AI models that process it. Each one is named, with its function, location and transfer mechanism, on our sub-processor page.
Those disclosures are made to processors acting on our instructions, which the Act excludes from what it calls sharing (RCW 19.373.010(27)(b)), and they are in any event necessary to provide the service the user requested (RCW 19.373.030(1)(b)(ii)).
The categories of consumer health data disclosed to them are the same categories described in section 3: whatever health-related information the submitted document contains. There is no subset we single out and no separate health-data feed.
We do not disclose consumer health data to advertising networks, data brokers or analytics providers. We do not sell consumer health data, so we do not seek the written authorization a sale would require.
Affiliates: super.AI has none, so no affiliate receives consumer health data. There is one company behind this service and no group around it. If that ever changes we will name the affiliate here before it does.
We may disclose information where we are legally compelled to do so, and we treat any such demand as narrowly as the law allows.
6. Your rights, and how to use them
You may ask us to confirm whether we collect, share or sell health-related information about you, and to identify the third parties it has been disclosed to. You may withdraw consent to our collection or sharing of it. And you may ask us to delete it.
Email us and say which right you want to use. We will respond without undue delay and in any event within 45 days, and if we need more time we will tell you within that period and take at most a further 45 days.
On deletion, here is what actually happens, stated plainly rather than promised more broadly than we can deliver. We delete it from our live systems when we act on your request. We delete it from our backups when those backups next expire or are restored, and in any event within six months of us authenticating your request, which is the period the Act allows where the data sits on archived or backup systems. Some providers that process content for us keep short-lived copies for security and abuse monitoring; those expire on that provider's own schedule, and the schedules are described on our sub-processor page.
Deleting the health-related information inside a document usually means deleting the document. We will tell you if that is the case before we act.
If we deny your request you may appeal by replying to our decision. We will tell you the outcome in writing with our reasons. If we deny your appeal we will give you a way to submit a complaint to the Washington State Attorney General, or to the Nevada Attorney General if you are a Nevada resident.
7. Changes to this notice
We will update this page when our handling changes, and the effective date above will change with it. We review it at least once a year.
To use any of the rights above, or to ask us a question about this notice, email security@super.ai. Our sub-processors are listed on the sub-processor page, and everything else about how we handle personal data is in our Privacy Policy.