Legal

Consumer Health Data Privacy Policy

Last Updated: July 6, 2026

This Consumer Health Data Privacy Policy (this “CHD Policy”) supplements the Lowkey Enterprises, Inc. (“LOWKEY,” “we,” “us,” or “our”) Privacy Policy (the “Privacy Policy”) and applies to personal data defined as “consumer health data” (“CHD”) by: (i) the Washington State My Health My Data Act (“MHMDA”); (ii) Nevada’s Consumer Health Data Privacy Law (“Nevada CHD Law”); (iii) Connecticut’s Data Privacy Act (“CTDPA”); (iv) the Colorado Privacy Act, including its sensitive data provisions (“CPA”); and (v) other applicable state comprehensive data privacy laws and consumer health data statutes across the United States (collectively, the “CHD Laws”). We refer to the LOWKEY mobile application and all related services provided by LOWKEY together in this CHD Policy as the “Services.” This CHD Policy is incorporated into our Terms of Service and Privacy Policy. Undefined capitalized terms shall have the meaning set forth in the Privacy Policy and the Terms of Service.

Categories of CHD Collected

As described further in our Privacy Policy, and depending on how you interact with the Services and applicable law, we may collect the following categories of CHD, as broadly defined under the applicable CHD Laws:

  • Bodily functions, vital signs, and measurements: e.g., resting heart rate, heart rate variability (HRV), step count, active calories burned, exercise minutes, distance traveled, flights climbed, and other biometric and physiological signals collected passively through Apple HealthKit and connected devices you authorize.
  • Sleep information: e.g., sleep duration, sleep timing, and sleep pattern data collected through Apple HealthKit from your device or connected wearable.
  • Physical activity and movement patterns: e.g., data reflecting your activity levels, movement routines, and physical engagement trends collected through Apple HealthKit and iOS motion sensors.
  • Location pattern data: e.g., data reflecting when you enter or leave user-defined locations (geofenced areas such as your home). GPS coordinates are processed entirely on your device and are never transmitted to or stored on our servers; we store only anonymized location pattern identifiers (e.g., “Home”).
  • Phone and device engagement patterns: e.g., phone pickup frequency and engagement patterns collected through iOS motion sensors, used to identify deviations in your routine.
  • Data that identifies a consumer seeking health care or wellness services: e.g., information that, in context, identifies you as a person using a behavioral wellness and pattern-detection service, including your account information (name, email address, phone number, date of birth, and zip code).
  • Information about your designated support network (Constellation): e.g., contact information (name, email, and/or phone number) of persons you invite as Supporters into your Constellation, which is processed on your behalf to facilitate opt-in notification sharing.
  • Algorithmic outputs and derived insights: e.g., Baseline Deviation Scores, contextual insights, and alert-level outputs derived or inferred from the behavioral and biometric signals described above, which may constitute derived or inferred CHD under applicable CHD Laws.
  • Other information that may be used to infer, derive, or extrapolate data related to the above or other health or wellness information.

Sources of CHD

As described further in our Privacy Policy, we collect information which may include CHD from the following sources: (1) directly from you (e.g., account registration information, Supporter contact information, notification preferences, and in-app feedback you provide); (2) automatically and passively through your use of the Services and your device (e.g., Apple HealthKit data, iOS motion sensor data, and geofencing-based location pattern data that you authorize); (3) third-party health and fitness services and connected devices linked to Apple HealthKit that you authorize; and (4) the behavioral baseline analysis and algorithmic processing performed by our Services on the data you authorize us to collect.

Purposes for Collection of CHD

We describe the purposes for collection and use of CHD in our Privacy Policy. As further described there and subject to applicable law and your consent, we collect and use CHD: (1) to provide and operate the Services, including to establish your personal behavioral baseline, detect deviations from that baseline, and generate tiered notifications to you and, where you have provided separate affirmative consent, to Supporters you designate in your Constellation; (2) to analyze and improve the accuracy of our pattern-detection algorithms and app functionality, using de-identified and aggregated data; (3) to respond to your support requests and technical inquiries; (4) for safety and fraud prevention purposes; and (5) for legal purposes, such as to comply with applicable laws or to establish, exercise, or defend our legal rights. We do not use your CHD for targeted advertising or cross-context behavioral advertising. We do not sell your CHD.

How and Why We Share CHD

We may share categories of CHD described above only as set forth below and as further described in our Privacy Policy. We share CHD only: (1) at your direction and with your separate, affirmative, opt-in consent; (2) to the extent necessary to provide the Services you have requested; or (3) as required or permitted by applicable law.

We may share CHD for the following purposes:

  • to deliver the Services to you, including to generate and transmit notifications to Supporters in your Constellation that you have authorized and invited to receive alerts;
  • to maintain and improve the Services and the accuracy of pattern-detection algorithms, using de-identified and aggregated data only;
  • to protect LOWKEY and others, including to enforce our Terms of Service or other agreements, and for fraud prevention; and
  • to comply with our legal obligations or in response to valid legal process.

We do not use CHD for advertising, marketing, or cross-context behavioral advertising, and we do not sell CHD.

Subject to applicable law and your consent where required, we may share CHD with the following categories of third parties:

  • Supporters in your Constellation: When you separately and affirmatively consent and invite specific individuals to join your Constellation, those Supporters may receive contextual insights and alert notifications derived from your behavioral baseline data. Supporters never receive your raw health data, high-frequency biometric sensor readings, or precise GPS coordinates. You may withdraw this consent and remove Supporters at any time through in-app Settings.
  • Service Providers: We use third-party service providers, including Supabase (database and authentication infrastructure) and Firebase Cloud Messaging (push notification delivery), that process data on our behalf subject to binding data protection agreements. These providers may not use your CHD for their own purposes.
  • For Legal Purposes: We may disclose CHD to governmental or regulatory authorities in response to valid legal process or to protect safety in emergency situations.
  • For Business Transfers: In connection with a merger, acquisition, or sale of business assets, CHD may be transferred subject to continued protections consistent with this CHD Policy.
  • At Your Direction or With Your Consent: We may share CHD with other parties at your specific direction or with your separate, affirmative consent.

We reserve the right to create and use de-identified or aggregated data derived from CHD, and such data is not subject to this CHD Policy. We may use de-identified and aggregated population trends for research, product improvement, and algorithm refinement.

How To Exercise Your MHMDA, Nevada CHD Law, CTDPA, CPA, and Other State Rights

Subject to exceptions, the applicable CHD Laws extend certain rights with respect to CHD. Depending on your jurisdiction, these rights may include requests: (1) to confirm whether LOWKEY is collecting, sharing, or selling your CHD; (2) to access your CHD and receive a list of all third parties and affiliates with whom LOWKEY has shared or sold your CHD; (3) to delete your CHD; (4) to withdraw your consent to the collection or sharing of your CHD; and (5) to correct inaccuracies in your CHD.

You can seek to exercise these rights by emailing support@lowkeyprotection.com or by using the in-app data controls available in Settings. Depending on the nature of your request, we may contact you for further information to authenticate your identity. LOWKEY will never ask you for sensitive financial information when authenticating your identity.

Sensitive Data and Biometric Information

Health, biometric, activity, behavioral pattern, and precise location information collected by LOWKEY may constitute “sensitive personal information,” “sensitive data,” or “consumer health data” under applicable state privacy laws, including the MHMDA, Nevada CHD Law, CTDPA, CPA, and comprehensive state privacy laws in Virginia, Texas, Oregon, Montana, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Rhode Island, Tennessee, Utah, and Florida. We process such information only for the purposes you have authorized and consistent with your consent. Where required by applicable law, we obtain your separate, affirmative, opt-in consent before collecting or sharing such sensitive data. You may limit our use of sensitive data through in-app Settings controls.

If we deny your request in whole or in part, you may appeal that decision by contacting us at support@lowkeyprotection.com. If your appeal is denied, you may contact your applicable state attorney general:

We will respond to verifiable consumer requests within 45 days of receipt. Where permitted by law, we may extend this period by an additional 45 days when reasonably necessary, with notice to you.

Geofencing Notice: In compliance with the MHMDA and Nevada CHD Law, LOWKEY does not engage in geofencing for advertising, tracking, or marketing purposes around any in-person health care facilities. The geofencing features within the LOWKEY app are used solely for your personal location-pattern detection at locations you define, and only at your direction and with your consent.

Updates to this CHD Policy

We reserve the right to change this CHD Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. We will make the revised CHD Policy accessible through the Services, so you should review it periodically. The date this CHD Policy was last revised is identified at the top of the document. You are responsible for periodically monitoring and reviewing any updates to the CHD Policy. If we make a material change to the CHD Policy, we will provide you with appropriate notice in accordance with legal requirements. Your continued use of our Services after such amendments (and notice, where applicable) will be deemed your acknowledgment of these changes to this CHD Policy.

Automated Decision-Making and Profiling

LOWKEY uses automated statistical processing — including a Baseline Deviation Score (“BDS”) algorithm — to detect meaningful deviations from your personal behavioral baseline and generate tiered notifications. This automated processing analyzes behavioral and biometric data (including steps, sleep, heart rate, HRV, location pattern changes, and phone engagement) to identify pattern changes. Outputs are informational wellness signals and are not clinical diagnoses, medical advice, or treatment recommendations. You may provide feedback on notifications through the app to improve accuracy for your unique patterns, and you may adjust or disable sharing of algorithmic insights with Supporters at any time in Settings. As required by applicable law (including the Colorado Privacy Act and other state laws requiring automated decision-making transparency), we disclose that no solely automated processing produces decisions with legal or similarly significant effects on you.

Contact Us

If you have any questions about this CHD Policy or LOWKEY’s privacy practices, please contact us at: support@lowkeyprotection.com or Lowkey Enterprises, Inc., 2525 Arapahoe St Unit E4 #715, Boulder, CO 80302.