CONSUMER HEALTH DATA PRIVACY POLICY
Verendo Health LLC
Last updated: September 13, 2026
Effective date: October 1, 2026
1. WHAT THIS POLICY IS
This page explains what health information Verendo collects about you, where it comes from, why we have it, exactly who else can see it, how long we keep it, and how you can look at it, correct it, delete it, or shut the whole thing off. It is a separate page on purpose. Washington’s My Health My Data Act, Nevada’s SB 370, and California’s health privacy laws all require that a company handling consumer health data say these things plainly and in one place, rather than hiding them in the middle of a general privacy policy.
If anything on this page conflicts with our general Privacy Policy, this page wins for health data.
1.1 Who this policy is for
- Anyone who buys or uses Verendo’s lab panel analysis. Section 14.5 explains where it is available.
- Anyone who gives us health information through an intake form, an email, or a coaching session.
- We give every client the rights described here, in every state. Washington, Nevada, and California residents have specific statutory rights, and those are spelled out in Section 14, but we do not make you prove where you live before we honor a request.
Verendo Health LLC is a Florida limited liability company formed on May 11, 2026. Kevin McCall, MS, RDN, CSSD is the sole member and the only person who works here.
2. A PLAIN STATEMENT ABOUT HIPAA
Verendo is not a HIPAA covered entity, and we do not claim to be “HIPAA compliant.”
We are cash-pay. We do not bill insurance and we do not submit electronic health insurance claims, which is what would pull a business like ours under HIPAA. We are telling you this directly because plenty of wellness companies imply federal health privacy protection that they do not actually have.
What we do instead is apply HIPAA-informed safeguards. We protect your health data with many of the same kinds of controls a covered entity uses, because it is the right way to treat this information, not because a federal rule forces us to. Section 11 lists exactly which controls are in place.
Two practical consequences, so nobody is surprised later:
- Your rights over this data come from state consumer health privacy laws and from the promises we make on this page, not from HIPAA.
- If something ever goes wrong, the complaint path is your state attorney general, and in Washington and California also a private lawsuit, not the federal Office for Civil Rights.
3. WHAT WE TREAT AS CONSUMER HEALTH DATA
We treat all of the following as consumer health data, which means everything on this page applies to it.
3.1 Biomarker values from your lab panel
Every number on your panel. Blood, serum, and any other specimen result returned to us, including the values themselves, the units, the reference ranges, the collection date, and the ordering details attached to them.
3.2 What you tell us at intake
- Symptoms you report, including how long you have had them and how severe they are.
- Diagnosed conditions and past medical history.
- Medications you take, including dose and how long you have taken them.
- Supplements you take.
- Allergies and intolerances.
- Diet, training, sleep, stress, alcohol, and other lifestyle information.
- Menstrual cycle and reproductive information, if you provide it.
- Biological sex, age, height, and weight.
3.3 Your goals
What you told us you are trying to change. Goals count as health data because they reveal what you believe is wrong and what you are seeking care for.
3.4 What our engine concludes about you
Inferences our engine draws from your data are themselves consumer health data, and we protect them exactly like your lab results. This includes flagged biomarkers, suspected patterns, suggested root causes, ranked intervention recommendations, safety flags such as a possible medication interaction, and any score, tier, or category the engine assigns you. If a piece of output would let someone conclude something about your health, it is health data. We do not treat “it is only a derived score” as a loophole, because these statutes do not, either.
3.5 Your report
The finished report, in every form it exists: the data behind it, the rendered PDF, the copy we deliver to you, and the copy in your Verendo account once your account is set up.
3.6 Messages that touch on your health
Emails, other messages you send us, and coaching notes become health data the moment they discuss symptoms, results, or treatment.
3.7 Purchase information that reveals a health interest
The fact that you bought a Verendo lab panel, tied to you by name, tells someone something about your health. We treat that link as health data. When you buy a panel, Stripe processes the payment and holds that link, but never any clinical detail. Section 7.3 explains exactly what Stripe receives.
3.8 What is not consumer health data
Your name, email address, and billing details on their own, our website analytics, your email list signup, and our consent records are personal information but not health data. We list them here so you can see where the line is. Our consent records deliberately contain no health details, only your email address, the fact that you consented, when, to which document versions, and the IP address and browser you used.
4. WHERE THIS DATA COMES FROM
These are the only sources. We do not buy health data, and we do not append data from brokers.
| Source | What it gives us |
|---|---|
| You | Intake answers, goals, messages, and anything you volunteer. |
| Stripe | Confirmation that you bought a Verendo lab panel, which Section 3.7 treats as health data. Never your intake answers, results or report. |
| The lab system | Your biomarker results from Quest Diagnostics, which come back to us through Fullscript. You never upload your labs. We order the panel for you and the results come to us directly. |
| Our own engine | The inferences, flags, and rankings described in Section 3.4, generated by our own analysis software from the two sources above. |
| Your device, at a basic level | IP address and standard traffic data when you use our website, or our app once it launches. We do not use this to infer anything about your health. |
5. WHY WE COLLECT IT
We collect and use your health data for these purposes and no others.
- To order the right panel for you and to give the ordering clinician the information needed to review and sign the order.
- To analyze your results. Our engine compares your biomarkers against reference ranges and evidence-based targets, considers your intake answers, and produces assessments and ranked recommendations.
- To check your results for safety conflicts, such as an interaction between a suggested intervention and a medication you listed.
- To have a qualified person review your report before you get it. At launch, Kevin McCall, MS, RDN, CSSD reviews every report before it is delivered.
- To produce and deliver your report to you.
- To answer your questions about your results.
- To reach you about a critically abnormal value. If a result looks urgent, we will try to contact you promptly by email. This is not emergency care. See the Medical Disclaimer.
- To let you compare panels over time, if you test again.
- To deliver 1:1 coaching, if you buy it and you are located in a state where we offer it (see Section 14.5).
- To meet legal obligations and to keep the consent and transaction records the law expects us to keep.
5.1 Improving the service
We improve our analysis engine and our reference ranges using de-identified and aggregated data only. That work never uses data that identifies you, and it is never shared outside Verendo.
5.2 What we never do with it
- We never use your health data for advertising, and we never build advertising profiles.
- We never use it to train an outside company’s AI model. See Section 6.
- We never use it for a purpose you have not been told about here. If we ever want to, we will ask you first, in a separate request, and no is a complete answer.
6. YOUR HEALTH DATA IS NEVER SENT TO AN AI VENDOR
Our analysis engine is deterministic. It follows rules we wrote and can inspect. There is no large language model anywhere in the pipeline that produces your report.
Concretely: no part of your labs, your intake answers, your goals, your engine inferences, or your report is ever transmitted to Anthropic, OpenAI, or any other AI provider, or put into any AI model, including Google’s. Google does host our server and our email, as Section 7 explains. That is storage and email delivery, not AI analysis. We have no business associate agreement with any company for AI services, and we do not need one, because your data never goes to one. We use AI tools internally for writing software and documents, in a workspace that contains no client health data.
7. WHO ELSE SEES IT, BY NAME
We name every company that receives consumer health data. If a company is not on this list, it does not get your health data.
7.1 Companies that receive consumer health data
| Recipient | What they get | Why they get it |
|---|---|---|
| Fullscript | Your name, date of birth, biological sex, contact details, the panel ordered, the clinical information the reviewing clinician needs to approve it, and the lab results held in their system. | Fullscript is our lab ordering platform. Your order goes through the Fullscript Authorization Network, where a licensed network clinician reviews and signs it, because a lab order requires a clinician’s signature. That clinician is not your treating provider and does not interpret your results for you. Results return to us through Fullscript. Fullscript also fulfills supplement orders if you choose to buy them. |
| Quest Diagnostics | Your name, date of birth, biological sex, and your specimen. | Quest performs the blood draw at a Patient Service Center and runs the tests. Quest is contracted through Fullscript. |
| Getlabs | Your name, date of birth, address, phone number, appointment details, and your specimen. | Only if you choose the at-home draw. Getlabs performs the blood draw at your home. |
| Google Cloud | Everything stored on our server, including your intake answers, lab results, and reports. | Google provides the server that stores this information, in a database that we control. Google does not use your data and does not look at it. The server is covered by Google’s Business Associate Agreement, which is an extra layer of protection we chose to take even though we are not required to. |
| Google Workspace | Anything you email us, including health information you choose to include. | Google Workspace hosts our email inboxes, including [email protected] and [email protected]. It is covered by Google’s Business Associate Agreement. |
| Cloudflare | Traffic between your browser and our website, which can include information you send us through the website. | Cloudflare runs our website, provides its HTTPS connections, and protects it from attacks. Cloudflare Web Analytics and the proof-of-signup record for our email list also run on Cloudflare. Neither contains health data. |
| Resend | Your email address and the contents of the email we send you. | Resend delivers our email. If we email you about your report, the contents of that email pass through Resend. If you join our email list, Resend also stores your email address as a contact on that list. |
| Stripe | Your name, email, billing details, payment card data (which Stripe collects and holds directly), and the fact that you bought a Verendo lab panel. Never your intake answers, lab results, engine inferences, or report. | When you buy a panel, Stripe processes your payment. See Section 7.3. |
Rupa Health is now part of Fullscript and is not a separate recipient of your data.
7.2 Software we run ourselves, which is not a third party
These are not outside companies receiving your data. They are software we run ourselves.
| System | What it does |
|---|---|
| Supabase, self-hosted | Our database, our file storage, and the sign-in system for Verendo accounts once they launch. Postgres, GoTrue authentication, and storage, all running on our own server. Row Level Security is forced, which means the database itself refuses to let one account read another account’s records. |
| n8n, self-hosted | Workflow software on our own server that can move data between our own systems. |
| Our report software | Will produce your analysis and turn your report into a PDF once the service opens. Your report is never sent to an outside AI service or to an outside document service to be formatted. |
| Matomo, self-hosted | Analytics software that runs on our own server for internal use. It is not connected to this website and receives no health data. Our website analytics are described in Section 10. |
7.3 Stripe, and the wall between payment and health
Stripe processes your payment and receives no clinical data. When you buy a panel, Stripe gets your name, email, billing details, and card information, which Stripe collects and holds directly, and the fact that you bought a Verendo lab panel. Because Section 3.7 treats that purchase link as health data, Stripe is named in Section 7.1. Stripe does not receive your intake answers, your lab results, your engine inferences, or your report.
This separation is deliberate. Our payment system and our health data system are kept apart, so the company processing your card never sees your intake answers, results, or report.
7.4 Everything else
- When you ask us to. We will send your information to your doctor, a family member, or another professional if you ask us in writing. You control that, and you can cancel it.
- When the law requires it. We may disclose information in response to a subpoena, court order, or lawful government demand, or when it is necessary to protect someone’s safety. If we are legally allowed to tell you first, we will.
- If the business changes hands. If Verendo is merged, acquired, or sold, your health data may transfer to the new owner under the same protections described here. We will tell you before that happens whenever we reasonably can, and you can delete your data first.
We do not disclose your health data to anyone else. Not to data brokers, not to advertisers, not to researchers, not to insurers, and not to employers.
8. WHO INSIDE VERENDO CAN SEE IT
Kevin McCall, MS, RDN, CSSD is the only person at Verendo who can see your health data. Verendo has no other employees and no contractors with access. When you send a message, when your labs return, and when your report is reviewed before delivery, Kevin is the person on the other end.
If Verendo ever hires anyone, three things happen before that person gets access: they get access only to what their job actually requires, they sign a confidentiality agreement, and this page is updated to say so before it happens.
We back this up with technical controls, not just good intentions. Row-level security limits each account to its own records, server credentials never leave the server, and signing in to the server requires an SSH key.
9. AFFILIATES AND REFERRAL PARTNERS
Our affiliate program has not launched yet. When it does, these rules apply.
If a partner referred you to us, this section says exactly where that partner stands. The same rules apply to any affiliate or referral partner we work with.
Affiliates never receive your consumer health data. Not your lab results, not your intake answers, not your symptoms, medications, or conditions, not your goals, not the inferences our engine draws about you, and not your report. An affiliate would receive referral attribution only, which means a record that a purchase came from their referral link and the commission owed to them, with no health information attached and no clinical detail of any kind.
To be unambiguous about the edges of that promise:
- An affiliate can be told that a referral converted into a sale, and the commission amount. They cannot see what the panel found.
- An affiliate does not get a feed, an export, a dashboard view, or an API key that would reach any part of your health data.
- If a practitioner who is also an affiliate refers you and later wants to see your results, we will only send them your report if you tell us to in writing, under Section 7.4. That is your decision, made separately, and being an affiliate gives them no path to it.
- We do not sell, rent, or trade referral lists containing health information, because no such list exists.
Under Washington’s My Health My Data Act, the “affiliates” a company must name are corporate affiliates that share health data. Verendo has no parent company, no subsidiaries, and no corporate affiliates. Any referral partners we work with are independent marketing partners, and, as stated above, they receive no health data.
10. TRACKING, ADVERTISING, AND GEOFENCING
- We run no advertising or marketing trackers. No ad pixels, no third-party ad networks, and nothing of that kind anywhere near a page that contains your health data.
- Our website analytics. We use Cloudflare Web Analytics on every page of this website. It sets no cookies and stores nothing on your device, so the cookie banner does not control it. It counts page views and records the page you viewed, the page that referred you, your browser type and your approximate country. It does not identify you and does not follow you to other websites.
- Nothing else. We do not run any other analytics or advertising trackers on this website. Our website code includes an error-monitoring tool, Sentry, that is switched off; if we ever turn it on, we will update this page first. Matomo runs on our own server for internal use and is not connected to this website. Our website sets no cookies, other than one that remembers your cookie banner choice if you make one. Cloudflare may set a short-lived security cookie if it has to challenge traffic it thinks is automated. See our Cookie Policy.
- New analytics vendors. If we ever add another outside analytics vendor, we will name it in Section 7 before it runs. If that vendor would receive consumer health data, that is a material change and we will ask for your consent again rather than assume it.
- No analytics tool ever receives health data, and no analytics tool of any kind runs on a page that shows your lab results or your report.
- We do not use geofencing. We do not build a virtual boundary around any health care facility, pharmacy, lab, or clinic to identify people, send them ads, or collect their health data. Washington and Nevada both prohibit this, and we do not do it anywhere.
- About Global Privacy Control. A Global Privacy Control signal tells a site not to sell or share personal information. We do not sell or share it at all, so there is nothing for that signal to switch off. We have not yet built separate technical handling for a GPC or Do Not Track signal, and we will not claim we have. If you send one and want it treated as a withdrawal of consent, email [email protected] and we will do that in writing.
11. HOW WE PROTECT IT, STATED HONESTLY
We are a single-member company, not a hospital system. Here is what is actually in place.
What we do:
- Your information travels over encrypted HTTPS connections.
- Health information is stored in a database on a Google Cloud server that we control, covered by Google’s Business Associate Agreement. We took on that agreement as an extra contractual safeguard by choice. It is not a sign that HIPAA applies to us, because it does not.
- Row Level Security is forced at the database level, so one account cannot read another account’s records even if application code has a bug.
- Server credentials never leave the server.
- Changes to the database structure are logged, and signing in to the server requires an SSH key.
- Access limited to one person, Kevin McCall.
- A monitored privacy inbox and a written plan for what happens if there is a breach.
- Data minimization. We do not collect health information we do not need to produce your analysis.
What we do not claim:
- We are not HIPAA certified. No such certification exists for anyone.
- We have not completed a SOC 2 audit.
- We do not keep a log of each time someone reads the database.
- No system is perfectly secure. We use reasonable, current safeguards, and we cannot promise that no incident will ever happen.
If there is a breach. We will investigate promptly and notify you without unreasonable delay by email, and by mail if we cannot reach you by email. The notice will say what happened, what data was involved, what you can do, and what we are doing. We will notify state authorities where the law requires it. HIPAA’s federal breach process does not apply to us. State breach notification laws do, and we follow them.
12. YOUR RIGHTS, AND HOW TO USE THEM
12.1 How to make any request
Email [email protected] with what you want in the subject line, for example “Health Data Access Request,” “Health Data Deletion Request,” or “Withdraw Consent.”
You can also write to us at 7901 4th St N Ste 300, St. Petersburg, FL 33702.
We will verify your identity before we act, so that nobody else can reach your health data. Usually that means confirming you control the email address you use with us. We will never require a copy of a government ID for a routine request. You may name an authorized agent to act for you, and we will still verify that you actually authorized them.
12.2 The right to know, and to get a copy
You can ask us to confirm whether we hold health data about you, and to tell you what we collected, where it came from, why we have it, and every third party we shared it with. You can also ask for a copy of the data itself, including your biomarker values, your intake answers, the inferences our engine drew, and your report, in a format you can take somewhere else.
12.3 The right to correct
If something is wrong, tell us and we will fix it. This matters more here than in most places, because a wrong medication or a wrong date of birth changes what the engine concludes. If a lab value itself is disputed, we will note the dispute in your record and, where the lab allows it, pass the correction request to Fullscript or Quest, who hold their own copy.
12.4 The right to delete
You can ask us to delete your consumer health data, and we will delete it, including any copies we hold. Here is exactly what happens.
What gets deleted: your intake answers, your lab results as we hold them, every inference our engine drew, your reports, and any messages you sent us that discuss your health.
What we keep, and why:
| What we keep | Why |
|---|---|
| The consent record showing you consented, when, and to which document versions | To prove that we had permission to collect the data and that we honored your request. This record contains no health data. |
| The minimum billing and tax record of the transaction | Federal and state tax law requires it. This record shows that you bought a Verendo lab panel, which Section 3.7 treats as health data, but nothing about your intake answers, results, or report. |
| Coaching records, if you bought coaching | Kept for 5 years after your last coaching session, even if you ask us to delete your data sooner. If this applies to you, we will tell you exactly what we kept and why. |
What we cannot delete for you: Fullscript and Quest Diagnostics keep their own copies of your lab order and results under their own legal retention rules, and a laboratory is generally required by law to retain test records. If you chose an at-home draw, Getlabs may keep its own record of your appointment, and Stripe keeps its own record of your payment. We cannot delete their copies for you. When we confirm a deletion, we will give you their privacy contacts so you can make a request directly to them. We also notify our service providers of your deletion request and instruct them to delete your data, as Section 14.1 describes. Where a company keeps its own copy under its own legal obligations, as above, we will send a deletion request to it on your behalf if you ask.
Timeline: when we verify a deletion request, we delete your information within 30 days, including any copies we hold, and confirm in writing what was deleted and what we had to keep.
12.5 The right to withdraw consent
We ask for your separate, affirmative consent before we collect any health data. You can take that consent back at any time, for any reason, without explaining yourself, and without being charged for it.
Email [email protected] with “Withdraw Consent” in the subject line.
Withdrawal is prospective. It stops what happens next. It does not unmake a report we already delivered, and it does not reach into a copy of the report you already downloaded.
Say it plainly: withdrawing your health data consent ends the service. We cannot analyze labs we are not allowed to process. We tell you this before you consent, not after, because a consent is not a real choice if the consequence of saying no is hidden.
12.6 What withdrawal does to a lab order already in progress
This depends on where your order is when we get your request.
| Where your order is | What we do |
|---|---|
| Ordered, not yet drawn | We cancel the lab order through Fullscript, immediately where the order state still allows cancellation. |
| Blood already drawn, results not back | The draw cannot be undone, and results may still come back to us. Any results that arrive are set aside as soon as we see them. We do not analyze them or use them for anything, and we look at them only as far as needed to identify and delete them. They are deleted with everything else. |
| Results back, report not yet produced | We stop all work on your report and delete the results. |
| Report produced but not delivered | We do not deliver it, and we delete the report. |
| Report already delivered | We delete our copies. Your copy is yours to keep or delete. |
In every case we stop processing within 1 business day, notify you in writing about what we stopped and what we deleted, and finish deletion within 30 days.
About refunds: withdrawing consent does not by itself create a right to a refund. Refunds are governed entirely by the Terms of Service. In practice the stage matters, because lab and order-review fees paid on your behalf are not refundable once the order is submitted, and after the draw there is no refund except as the Terms describe. Read the refund section of the Terms before you withdraw if money is a factor in your decision.
12.7 The right to limit how we use sensitive information
Your lab results, health history, and biometric information are sensitive personal information under California law. We use them only to deliver the service you bought, which is the narrow purpose the law allows without a separate opt-in. We never use them to infer characteristics about you for advertising.
12.8 The right to opt out of sale, sharing, and profiling for ads
There is nothing to opt out of, because we do not sell your health data, we do not share it for cross-context behavioral advertising, and we do not profile you for advertising. We state the right anyway so you know it exists.
12.9 How fast we respond
| Step | Our commitment |
|---|---|
| We confirm we received your request | 5 business days |
| We stop processing after a withdrawal | Within 1 business day of receiving your request, by email or post |
| We complete an access or correction request | 45 days. If we genuinely need more time, we will tell you why and take up to 45 more days. |
| We complete a deletion request | 30 days from verifying it, as stated in Section 12.4 |
| We finish deleting after a withdrawal | 30 days |
| We confirm completion in writing | Within the same window |
We will never retaliate. We will not charge you more, give you a worse service, or refuse to serve you because you used a privacy right.
12.10 If we say no, you can appeal
If we deny a request, we will tell you why in writing, and we will tell you how to appeal. To appeal, reply to that denial or email [email protected] with “Appeal” in the subject line. We will review it and respond within 45 days with a written explanation of the outcome. If we still deny it, we will give you a link to submit a complaint to your state attorney general.
13. WE DO NOT SELL YOUR HEALTH DATA
Verendo does not sell your consumer health data, and never has. We do not exchange it, and we will not exchange it, for money or for anything else of value, to anyone, for any purpose. That is a sale under Washington’s My Health My Data Act, under Nevada’s SB 370, and under the California Consumer Privacy Act, and we do not do it under any of those definitions.
Because we do not sell health data, we never ask you to sign the separate written authorization that Washington and Nevada require before a sale. If you are ever presented with a document that looks like a health-data sale authorization from Verendo, do not sign it. Contact us, because it did not come from us.
We also do not sell any other personal information, and we do not share personal information for cross-context behavioral advertising as the CCPA defines sharing.
Using a service provider to do work for us is not a sale. The companies named in Section 7 provide services we use to deliver what you bought, and nobody pays us for access to your data. We do not authorize any of them to use your information for their own marketing.
One honest caveat, because it is yours to know: Fullscript and Quest, and Getlabs if you choose an at-home draw, also hold your information under their own privacy notices and their own legal obligations, including a laboratory’s duty to retain test records. You accept their terms directly with them when you create your Fullscript account and give your consent there. We can tell you what we do with your data and what we asked them to do. We cannot rewrite their notices, and we will not pretend otherwise. Their privacy notices are worth reading, and we will point you to them on request.
14. STATE-SPECIFIC RIGHTS
The rights in Section 12 are given to everyone. This section says where they come from and adds what is specific to each state.
14.1 Washington residents: My Health My Data Act
Washington law treats everything in Section 3 as consumer health data, including inferences. Under the Act you have the right to:
- Confirm whether we collect, share, or sell your consumer health data, and to access it, including a list of every third party and affiliate we shared it with, with contact information for each.
- Withdraw consent to collection and sharing.
- Delete your consumer health data, including any copies we hold. When you ask us to delete, we will notify our service providers of the deletion request and instruct them to delete it too, as the Act requires. As noted in Section 12.4, the lab’s own legally required test records are outside our control.
- Not be discriminated against for using any of these rights.
Verendo does not collect Washington consumer health data beyond what is necessary to provide the service you asked for, and we do not sell it. We do not use geofencing around health care facilities.
Washington’s law includes a private right of action, which means you can bring a claim under the state’s Consumer Protection Act. Before that, please email us at [email protected], because most problems are faster to fix directly. You may also contact the Washington State Attorney General.
14.2 Nevada residents: SB 370
Nevada residents have essentially the same rights: to know whether we collect, use, or share your consumer health data, to know who we share it with, to get a copy, to delete it, and to withdraw consent. We do not sell Nevada consumer health data, and we would need your separate written authorization to do so, which we will never request. We do not geofence health care facilities. Nevada’s law is enforced by the Nevada Attorney General, and you may file a complaint there.
14.3 California residents: CMIA and CCPA/CPRA
- CMIA. California’s Confidentiality of Medical Information Act treats lab results and the health information you give us as medical information. We do not disclose it without your written authorization, except as Section 7 describes. CMIA also gives you a private right of action.
- CCPA/CPRA. Your health data is sensitive personal information. You have the right to know, access, correct, delete, opt out of sale and sharing, limit the use of sensitive personal information, and be free from retaliation, all described in Section 12. We do not sell or share personal information as those terms are defined. We have not sold or shared personal information in the 12 months before the effective date of this policy, and we do not knowingly collect data from anyone under 18.
- You may also contact the California Privacy Protection Agency or the California Attorney General.
14.4 Everyone else
A growing number of states have passed comprehensive consumer privacy laws, and the common thread in them is that sensitive data, which includes health information, needs your opt-in consent before it can be processed. Texas and Colorado are two of them, and both matter to us because they are on the list of states where we plan to offer 1:1 coaching. Not every state has such a law, and the ones that exist differ in their details.
We did not try to work out the minimum each state requires. We ask everyone, everywhere, for the same explicit opt-in before we collect any health data, and we give everyone the same rights in Section 12, whether or not their state makes us. Wherever you live, use Section 12.
14.5 A note about availability and coaching
Our lab panel analysis is available in most of the United States. Our lab partner cannot currently serve people located in New York, New Jersey, Rhode Island, Hawaii or Puerto Rico. The analysis is informational and educational. It is not medical advice, not a diagnosis, and not treatment.
1:1 coaching is not yet available. When we offer it, it will be available only to clients located in Arizona, California, Colorado, Florida, Michigan, Texas and Wisconsin. Kevin is licensed in Florida (license ND15442); the other states on this list do not require a license for this kind of nutrition coaching. Coaching notes are health data and are covered by this policy, with the one retention difference noted in Section 15.
15. HOW LONG WE KEEP IT
| Data | How long |
|---|---|
| Intake answers, lab results, engine inferences, and reports | While your Verendo account is active, so you can compare panels over time. If your account is inactive for 24 months, we email you first and then delete your health information. |
| Messages that discuss your health | Same rule as the row above. |
| Coaching notes | Kept for 5 years after your last coaching session, even if you ask us to delete your data sooner. If we keep a coaching record after a deletion request, we will tell you exactly what we kept. |
| After you withdraw consent or ask for deletion | Deleted within 30 days of verifying your request, including any copies we hold. |
| Results that arrive after a withdrawal | Never analyzed, and deleted with the rest of your data within 30 days. |
| Consent records: your email address, date and time, IP address, browser type, and document versions | 7 years after the later of account closure or your last consent event. No health data in these. They exist to prove that collection was authorized and that we honored your requests. |
| Billing and payment records | 7 years from the transaction, for tax and business records. No clinical data in these. They show what you bought, never your intake answers, results, or report. |
| Website analytics | Held by Cloudflare under its own retention schedule. It does not identify you and is never linked to health data. |
| Email list | If you join our email list, your email address is stored as a contact by Resend, and you can unsubscribe at any time. Cloudflare’s proof-of-signup record, which holds only a scrambled one-way code made from your email address, a scrambled code made from your IP address, a shortened description of your browser, your approximate country, and the time you signed up, is kept for 5 years so we can show that you asked to join. No health data in these. |
| De-identified, aggregated data | Indefinitely, because it cannot be traced back to you. |
You can always ask us to delete sooner. See Section 12.4.
16. CHANGES TO THIS POLICY
If we change this policy in a way that materially affects your health data, we will email you and post notice at least 30 days before the change takes effect. If a change would extend how we use your health data beyond what you already agreed to, we will ask for your consent again rather than assume it. Not answering is not consent. The effective date at the top of this page always shows the current one, and we keep prior versions available on request.
17. CONTACT US
Verendo Health LLC
Kevin McCall, MS, RDN, CSSD, Privacy Contact
7901 4th St N Ste 300, St. Petersburg, FL 33702
Email: [email protected]
We read [email protected] and acknowledge every message within 5 business days.
Related documents:
- Privacy Policy, which covers information that is not health data
- Terms of Service
- Medical Disclaimer
- Cookie Policy
Verendo’s lab panel analysis is informational and educational. It is not medical advice, not a diagnosis, and not treatment. Always talk to your own clinician before changing anything about your care.