BeMiVe

Consumer Health Data Privacy Notice

Washington My Health My Data Act and similar state laws • Version 1.0 • Last updated: August 10, 2026

Português|English|Español|Français

This notice is a separate statement about consumer health data, required by the Washington My Health My Data Act (MHMDA) and comparable state laws (such as Nevada SB 370). It supplements our Privacy Policy; if the two conflict on consumer health data, this notice prevails.

BeMiVe is not a HIPAA-covered entity: it is a personal health-management tool you use directly, and the data you record in it is generally not covered by HIPAA.

1. What we treat as consumer health data

Consumer health data is any information linked to you that identifies your past, present or future physical or mental health status. In BeMiVe, that includes:

  • health indicators you record: weight, body measurements, blood pressure, blood glucose, heart rate, oxygen saturation, temperature, hydration and sleep;
  • lab and imaging results, medical reports and prescriptions, including files you upload;
  • medications, dosages and schedules — including GLP-1 treatments — vaccines, allergies, symptoms and chronic conditions;
  • family health history you record;
  • data imported from smartwatches and wearables through Apple HealthKit or Android Health Connect;
  • appointments, preventive-care plans and health goals;
  • inferences we generate from the above, such as your wellness score and AI-generated summaries.

It does not include data that is deidentified in a way that cannot reasonably be linked back to you.

2. Where it comes from

  • From you: everything you type, upload or record in the app.
  • From devices you connect: smartwatches and wearables, only after you authorize the health integration.
  • From your family circle: a legal guardian may record data for dependants they manage.
  • Generated by us: scores, trends and summaries derived from the data above.

We do not buy consumer health data, and we do not obtain it from data brokers.

3. Why we collect it

  • to store, organize and display your health history to you;
  • to send the reminders and alerts you configure (medications, appointments, vaccines);
  • to generate explanations, summaries and insights through the AI features you explicitly enable;
  • to let you share your record with people you choose, through a link you generate;
  • to keep the service secure and to comply with legal obligations.

We collect and use consumer health data only with your consent or as strictly necessary to provide a service you requested. Each purpose is presented separately, and consent to the optional ones can be withheld or withdrawn without losing access to the rest of the app.

4. Who receives it

We share consumer health data only with processors that support the service, under contracts requiring confidentiality and equivalent protection:

  • Infrastructure and storage: Amazon Web Services (EC2, RDS PostgreSQL, S3).
  • AI features you enable: DeepSeek (explanations, summaries and assistant answers) and Google Cloud Vision (OCR of exam files); OpenAI only if you connect BeMiVe to ChatGPT. Sending happens through our backend gateway — your device never talks to these providers directly — and is limited to the context of the request.
  • Voice assistant: Amazon Alexa, if you link the Skill.
  • People you authorize: family members inside your family profile, and anyone holding a shared-record link or emergency card you generate.

We do not sell consumer health data, and we do not share it for advertising. Advertising in the free plan never uses health data for targeting — it relies only on advertising identifiers and signals unrelated to health. We do not use geofencing around health care facilities, hospitals, pharmacies or clinics.

Employers who offer BeMiVe as a corporate benefit never receive individual health data — only aggregated, anonymized statistics with a minimum group size.

5. Your rights

  • Access: obtain a list of the consumer health data we hold about you and of the third parties with whom it has been shared, including how to contact them.
  • Withdraw consent: revoke consent for collection or sharing at any time, for each purpose independently, in Settings › Privacy › My Consents.
  • Deletion: request deletion of your consumer health data. We honor it and pass the request on to the processors listed above.
  • No discrimination: exercising these rights never degrades the service or changes the price you pay.

How to exercise: write to support@bemive.com or use "Support > Privacy" in the app; account deletion is also available directly in Settings > Privacy and Data. We may ask for information to verify your identity. We respond within 45 days, extendable once by another 45 days where the law allows, and we tell you if we extend. If we deny a request, you may appeal by replying to our decision; if the appeal is denied, you may contact the Washington State Attorney General at atg.wa.gov/file-complaint.

6. How long we keep it

We keep consumer health data while your account is active. After you request account deletion, the account is blocked immediately across all channels, personal data is anonymized after a 7-day grace period during which the deletion can be cancelled, and health records are permanently erased within the 180-day window described in section 9 of the Privacy Policy.

7. Contact

  • Controller: W N P DE MATOS SOLUCOES EM INFORMATICA - ME (BeMiVe)
  • Data Protection Officer: Weverly Matos
  • E-mail: support@bemive.com
  • In-app: "Support > Privacy"

Changes to this notice are announced by e-mail, push or in-app message, and material changes take effect 30 days after the notice.

Related documents