Consumer Health Data Privacy Notice
This notice explains how MindCheck Tools handles information that may be treated as consumer health data under laws such as Washington's My Health My Data Act. It supplements our Privacy Policy.
Last updated: (provider-status clarification)
The most important distinction
Questionnaire answers, scores, journal entries, safety plans, and locally saved tool data are processed in your browser and are not intentionally sent to MindCheck Tools. Tools that intentionally save entries in your browser say so before use. Ordinary page requests are separate and can create hosting records.
Visiting a mental-health or substance-use page can itself suggest an interest in a health topic. Ordinary hosting requests therefore deserve careful treatment even though they do not contain your answers or score. This notice describes that limited request and service data conservatively.
Categories collected and why
- Website request data: requested path, IP address, user-agent or browser information, time, response status, and security events. Vercel processes this information to deliver the page, prevent abuse, diagnose failures, and protect the service. A health-topic path may indicate an interest in that topic.
- Cookie-free aggregate measurement: When enabled for the production project, Vercel Web Analytics counts visitors and page views only on a positive allowlist of topic-neutral and professional pages. Its documented data-point fields can include event time, allowlisted page path and route, browser-supplied referrer, coarse city/region/country, operating system and version, browser and version, device type, and analytics-script version. Query strings and fragments are removed from the event URL, custom events are not sent, and Global Privacy Control suppresses events. Assessment, result, crisis, condition-specific, blog-detail, and interactive-tool routes do not send Web Analytics events.
- Messages you send: we receive the contents of messages you choose to send. Please do not email screening answers, diagnoses, or other sensitive health details.
Sources
Request data comes from your browser, device, and network when you visit the site. If analytics is enabled, analytics data comes from the same sources on allowlisted pages. Contact information comes directly from you when you choose to send it. We do not buy health data, enrich visitor profiles with broker data, or infer a diagnosis from site activity.
Sharing and service providers
We do not sell consumer health data. Limited information is processed by:
- Vercel: website request and security information, including the requested path, for hosting, delivery, reliability, and abuse prevention. Vercel also processes cookie-free aggregate events from the narrow non-sensitive route allowlist when Vercel Web Analytics is enabled. Its documented visitor hash resets after 24 hours.
- Email delivery providers: message contents and routing metadata when you choose to contact us by email.
No MindCheck Tools corporate affiliate receives consumer health data. Disclosed affiliate links use a no-referrer policy and do not append answers or scores. An external destination may collect information after you choose to visit it under its own privacy policy.
No display advertising
MindCheck Tools does not display ads or load advertising networks on any page. We do not use screening activity, answers, scores, or other consumer health information for advertising, retargeting, or commercial profiling. Disclosed affiliate links and professional services remain separate from sensitive tool journeys. Hosting, any enabled allowlisted aggregate analytics, contact messages, and local copies retain the boundaries described in this notice.
Your choices and requests
- Use browser controls to clear local storage and cookies. MindCheck Tools does not use Google Analytics or display advertising. Global Privacy Control suppresses any enabled Vercel Web Analytics events.
- Clear or reset browser-local tool data on the device where it is stored. MindCheck Tools cannot retrieve or delete data that remains only in your browser.
- Email privacy@mindchecktools.com with the subject "Consumer Health Data Request" to ask whether we hold covered data about you, request access or deletion, request a list of the third parties and affiliates with which covered data has been shared or sold, or withdraw consent. You do not need to create an account. We may request limited information needed to authenticate the request.
We will respond without undue delay and within the period required by applicable law. If we deny a request, you may appeal by replying with the subject "Consumer Health Data Appeal." We will explain the outcome and, when required, how to contact the appropriate regulator.
Retention and security
Browser-local health entries remain on your device until you reset the tool, clear site data, or the browser removes them. Hosting/security log retention follows Vercel's configured service limits and legitimate security or legal needs. When Web Analytics is enabled, Vercel documents that its visitor hash resets after 24 hours; aggregate reporting retention follows the project and plan settings.
Sensitive routes use no-store and no-referrer response controls and bypass optional analytics, advertising, affiliate calls to action, and service-worker caching. When browser JavaScript loads successfully, the sensitive-route lifecycle also replaces a query-bearing or fragmented address with the clean path after the initial request. A query can still reach hosting infrastructure in that initial request, and cleanup cannot be guaranteed if JavaScript or hydration fails; do not place sensitive information in a URL.
Changes and contact
We will update this notice before collecting, using, or sharing an additional category of consumer health data or using it for a materially different purpose when notice or consent is required. Questions and requests can be sent to privacy@mindchecktools.com.
For official information, see the Washington Legislature's My Health My Data Act and the Washington Attorney General's guidance.