Consumer Health Data Privacy Policy
Effective Date: July 23, 2026
This Consumer Health Data Privacy Policy supplements our General Privacy Policy and applies specifically to "consumer health data" as defined by applicable state health privacy laws.
1. Categories of Consumer Health Data We Collect
Through your use of SoulAnthem, we may collect information linked or reasonably linkable to your physical or mental health status, including:
Goals, feelings, and check-in inputs. We may collect the goals you select or write, including preset goal selections and custom goal text, the feelings or voice-style preferences you select, and any check-in inputs you provide.
Optional free-text entries. We may collect words you enter to personalize your experience, such as goal descriptions, mental-block text, or other reflections you choose to provide.
Generated content and saved activity. We may collect and store affirmations, anthem scripts, generated audio references, ratings, rituals, journeys, and other content or activity created through your use of SoulAnthem.
- Safety-related classifications. Information generated by automated content-safety screening that evaluates whether text you submit may contain language associated with severe distress, self-harm, or potential harm to others so SoulAnthem can provide a safer response or display crisis resources. This screening is not a medical or mental-health assessment and may not identify every safety concern.
2. Sources of Consumer Health Data
We collect Consumer Health Data directly from you through your choices, entries, and activity in SoulAnthem, and generate certain content and safety inferences through operation of the service.
3. Why We Collect and Use Consumer Health Data
We process your consumer health data based strictly on your affirmative opt-in consent for the following purposes:
We require Consumer Health Data consent before generation because SoulAnthem's generation experience uses the goals, feelings, check-in inputs, free-text entries, and generated content associated with your account.
We use this information to generate affirmations, anthem scripts and audio, personalize your SoulAnthem experience, support safety and distress handling, save content you choose to keep, operate and secure the service, respond to privacy and support requests, and provide the features described in this Consumer Health Data Privacy Policy.
4. How We Process and Disclose Consumer Health Data
We do not sell your consumer health data, nor do we share it with third parties for their own independent commercial or marketing purposes.
We use carefully selected service providers that assist us in delivering SoulAnthem's functionality, including AI text generation, safety analysis, hosting, storage, audio generation, and diagnostics/error-monitoring services. Where user content is processed by these providers, we require contractual and technical safeguards designed to protect the confidentiality and security of the information.
Before transmitting user-generated content to certain service providers, we remove or minimize direct identifying information where reasonably possible. Depending on the service being used, these providers may receive user-generated content without associated account identifiers such as email addresses, user IDs, device identifiers, IP addresses, or similar direct identifying information. This safeguard is designed to reduce the extent to which information processed by those providers can be associated with a particular user. Some service providers, such as our hosting, authentication, database, security, payment, or account-management providers, may process information that remains associated with a user where necessary to operate SoulAnthem, maintain user accounts, process subscriptions, provide security, comply with legal obligations, or deliver requested services.
When Consumer Health Data or similar wellness-related content is processed by a service provider on our behalf, the provider is authorized to use the information only for the purpose of providing services to SoulAnthem, maintaining the security and integrity of its systems, satisfying legal obligations, or as otherwise permitted by applicable law and contractual commitments.
We use limited analytics and performance-monitoring tools to understand product usage, reliability, and performance. We do not send emotional free-text entries, mental-block text, affirmation text, anthem script text, goal names, believability ratings, account email addresses, or Consumer Health Data content to analytics. Analytics events are limited to pseudonymous product usage and performance information, including standard app, device, session, page/route, and non-user-authored route identifier information, and are not used for advertising targeting.
Error and crash monitoring. We use analytics and error-monitoring tools to help us detect crashes, failed network requests, app hangs, and performance issues. These tools may receive pseudonymous technical information such as device type, operating system, app version, timestamp, screen or route information, and error stack traces. We configure them to exclude or scrub user-authored content and other text that may contain Consumer Health Data before transmission.
5. Your Rights Regarding Consumer Health Data
You have the right to confirm whether we collect your consumer health data and access a copy of it, withdraw your consent to our future collection and processing of your data at any time, and request the deletion of your consumer health data as described below.
You may exercise these rights by contacting us at privacy@pyrigen.com or through the in-app privacy menu. If you contact support@pyrigen.com with a privacy or data-rights request, we will route your request to our privacy process. We will authenticate your request before acting on it. If we deny a request, you will be provided with written justification and instructions on how to appeal our decision.
Our response timeframes, deletion process, backup-system treatment, and service-provider retention limitations are described in Section 6.
6. Retention, Deletion, and Protection of Consumer Health Data
We retain Consumer Health Data only for as long as reasonably necessary to provide SoulAnthem, maintain user accounts and saved content, comply with legal obligations, resolve disputes, enforce agreements, protect the security and integrity of our platform, and support the purposes described in this Consumer Health Data Privacy Policy.
When you submit a verified request to access, confirm, withdraw consent for, or delete Consumer Health Data, we will respond without undue delay and within the timeframes required by applicable law. For Washington Consumer Health Data requests, we generally respond within 45 days of receiving the request. Where permitted by law and reasonably necessary due to the complexity or number of requests, we may extend that period once by an additional 45 days and will notify you of the extension and the reason for it.
When we verify a deletion request, we will delete or de-identify applicable Consumer Health Data from our active systems in accordance with applicable law, except where retention is legally required or otherwise permitted. Information stored in archived, backup, disaster-recovery, security, or similar systems may take longer to remove. Where Washington's My Health My Data Act applies, deletion from archived or backup systems will not be delayed longer than permitted by that law.
Certain authorized service providers that process data on our behalf may retain limited categories of information for backup, security, fraud prevention, auditing, disaster recovery, legal compliance, or similar operational purposes where permitted by applicable law and contractual commitments. Where such retention occurs, those providers remain subject to contractual, administrative, technical, and organizational safeguards designed to protect the information, restrict its use, and preserve its confidentiality. Our audio-generation provider may retain non-account-linked generated script text under its applicable terms and data controls; this provider does not receive raw user free-text or account identifiers from SoulAnthem.
We do not promise immediate deletion from every processor environment in all circumstances. Instead, we delete or de-identify Consumer Health Data from our systems as required by law and require our service providers to protect retained information and delete, dispose of, or limit further use of that information in accordance with their contractual obligations and applicable legal requirements.
7. De-identification Commitment
When we de-identify Consumer Health Data, we do so using reasonable technical and organizational measures designed to remove or obscure direct identifiers and reduce the risk that the information can be linked to a particular person. We may retain and use de-identified information only in de-identified form.
Pyrigen Incorporated will not attempt to re-identify de-identified Consumer Health Data, and we will not knowingly permit our service providers, contractors, or other recipients to re-identify de-identified Consumer Health Data on our behalf.
We require service providers and other authorized recipients to use de-identified Consumer Health Data only in de-identified form, to maintain it in that form, and to refrain from combining it with other information for the purpose of re-identifying a person, except where applicable law expressly permits or requires otherwise.
If we disclose de-identified information to a service provider or other recipient, we require that recipient to maintain the information as de-identified and to use it only for the limited purpose for which it was disclosed.
We may review de-identified data for quality, safety, analytics, research, security, or service improvement purposes, provided that the data remains de-identified and is not used to identify a person.