Consumer Health Data Privacy Notice

    Effective as of April 7, 2026

    This Consumer Health Data Privacy Notice explains how Casana Care, Inc. DBA Casana and our subsidiaries ("Casana," "we," "us," or "our") collect, use, share, and protect consumer health data when you use our Services. It also outlines your rights and choices regarding this data. This notice supplements our Privacy Policy, and terms used but not defined here are as defined in our Privacy Policy.

    What Consumer Health Data We Collect

    When you use our Services, we may collect the following types of consumer health data:

    Individual health conditions, treatment, diseases, or diagnosis.

    We collect information through our Services, including sensor data from Casana Devices and derived vital signs, as well as self-reported information about your health, lifestyle and wellbeing. Although we do not diagnose medical conditions, this information may reflect aspects of your health or perceived wellbeing and may be considered indicative of a health condition.

    Health-related surgeries or procedures.

    If you choose to voluntarily share information about past or planned medical procedures or surgeries, that information may be collected and stored as part of your account data.

    Bodily functions, vital signs, symptoms, or measurements of the information.

    We may collect information about your physical state through your use of the Service, including heart rate, respiration rate, blood pressure, blood oxygenation levels, and heart rate variability, as well as information you choose to provide, such as physical symptoms or other bodily measurements.

    Any inferences of the above categories of health data derived or extrapolated from non-health information.

    We may draw limited inferences about your wellbeing based on how you interact with our Services. While this information is not health data on its own, it may suggest wellness needs. These inferences are used only to personalize your experience and are not used or shared for advertising or promotional purposes.

    How We Collect Consumer Health Data

    We collect consumer health data in the following ways: (a) directly from you; (b) from your use of the Service; and (c) from third-party services that you choose to connect to our Service. Specifically, we collect consumer health data directly from you when you fill out questionnaires or assessments and when you interact with our Service, including via the means of collection we rely on in the Casana App, Casana Devices, and Casana Cloud.

    Why We Use Consumer Health Data

    We collect and use your consumer health data as necessary to provide you with the information and services you request through our Service to support your wellness, generate personalized insights, and conduct scientific research relating to our offerings. Where required by applicable law, we will obtain your consent before collecting or using your consumer health data for purposes beyond what is necessary to provide the products or services you have requested. This includes:

    • Provide, operate, and maintain the Service, including generating health insights from your data
    • Communicate with you, including sending service updates, security alerts, and support messages
    • Research and develop the Service and improve our algorithms and product performance
    • Respond to your inquiries and provide customer support
    • Comply with applicable legal obligations
    • Protect our rights and the rights and safety of our users and others

    When We Disclose Consumer Health Data

    We may disclose your consumer health data in the following circumstances:

    Affiliates.

    Our subsidiaries and corporate affiliates, for purposes consistent with this Policy.

    Other users.

    Our Service includes social and household account linking features. Depending on your privacy choices within the Service, we will share your personal information with other users.

    Service providers.

    Companies that provide services on our behalf, such as cloud hosting, payment processing, customer support, email delivery, and website analytics. Service providers are contractually bound to use personal information only for the purposes for which it was provided and are prohibited from selling or sharing it for their own purposes.

    Authorities and others.

    We may disclose information to law enforcement, government authorities, or other third parties when required by valid legal process, or when we believe in good faith that disclosure is necessary to protect rights, property, or safety. We will make reasonable efforts to notify you of any such request where legally permissible, and we will oppose requests that we believe are overbroad or not legally required.

    Business transferees.

    In connection with a merger, acquisition, reorganization, sale of assets, or similar transaction, your information may be transferred to the relevant parties as part of that transaction.

    Data Retention

    We retain consumer health information only for as long as is reasonably necessary to fulfill the purposes for which it was collected, or as required by applicable law. To determine the appropriate retention period for consumer health information, we consider the amount, nature, and sensitivity of the consumer health information, the potential risk of harm from unauthorized use or disclosure of consumer health information, the purposes for which we use personal information and whether we can achieve those purposes through other means, and the applicable legal and regulatory requirements.

    Your Rights and How to Exercise Them

    In addition to the rights described in the general Privacy Policy, depending on where you live, you may have the following rights with respect to your consumer health data:

    • Confirm whether we are collecting, sharing, or selling your consumer health data, and access your consumer health data.
    • Delete your consumer health data.
    • Withdraw your consent from our collection or sharing of your consumer health data.

    How to submit a request:

    Please email us at privacy@casanacare.com. You will not be discriminated against for exercising your rights.

    Appealing a denied request:

    If we deny your request, you can appeal by contacting us at privacy@casanacare.com. If your appeal is unsuccessful, you may file a complaint with your state's Attorney General. For Washington residents, visit www.atg.wa.gov/file-complaint.

    Changes to This Policy

    We may update this Consumer Health Data Privacy Notice from time to time. The most current version will be available within the Service and on our website. If we make material changes to how we treat your consumer health data, we will notify you through the Service, by email, or through another appropriate method. Updates will take effect once posted, unless otherwise stated.

    We use cookies

    We use Google Analytics to understand how visitors use our site so we can improve your experience. No personal data is sold. You can accept or decline analytics cookies; essential site functions always remain active.