Last revised on: July 18, 2026
This Privacy Policy describes how Take Helm Health, LLC ("TakeHelm," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website at takehelm.io (the "Site") and our related mobile applications, services, and features (collectively, the "Services").
For Washington Residents and Consumer Health Data: We have a separate Consumer Health Data Privacy Policy that describes our practices specifically for "consumer health data" under the Washington My Health My Data Act (MHMDA) and similar state laws. Please review that policy in addition to this one.
HIPAA Notice: TakeHelm is not a "covered entity" under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). When TakeHelm provides Services in connection with a healthcare provider under a Clinic-Tier Service Agreement, TakeHelm acts as a "Business Associate" under HIPAA, and the handling of Protected Health Information is governed by a Business Associate Agreement between TakeHelm and the healthcare provider. When TakeHelm provides Services directly to individual consumers, HIPAA does not apply, and your data is protected under this Privacy Policy, our Consumer Health Data Privacy Policy, and applicable state laws.
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
We collect information in several ways: directly from you, automatically when you use our Services, and from third-party sources you choose to connect.
Account Information: Name, email address, password (stored in hashed form), and billing/payment information (processed by Stripe; we do not store full payment card numbers).
Profile Information: Age, sex, height, weight, health goals and preferences, lifestyle information (activity level, sleep habits, dietary preferences).
Health Information: Health history and conditions, current medications and supplements, laboratory test results you upload, genetic testing reports you upload, and medical records you choose to share (all user-provided).
Communications: Messages you send to our support team, feedback and survey responses, and any other information you choose to provide.
Device and Usage Information: IP address, browser type and version, operating system, device identifiers, pages viewed and features used, time spent on pages, referring and exit pages, and date and time of visits.
Location Information: We do NOT collect precise GPS location. We may infer general location (city/region) from IP address for analytics and compliance purposes.
When you choose to connect third-party services, we receive data from those sources:
Wearable Devices and Health Platforms:
You initiate all third-party connections and can revoke access at any time through your account settings or through the third-party platform directly.
Laboratory Services: Lab results from providers like Function Health, Quest, LabCorp (when you upload).
Genetic Testing Services: Genetic reports from 23andMe, 3x4 Genetics, and similar providers (when you upload).
We only access data from third-party services that you explicitly authorize. We do not purchase data about you from data brokers.
If you are enrolled in TakeHelm through a healthcare practice ("Your Practice"), we may receive health information about you from Your Practice's electronic health record (EHR) system. This data is transmitted by Your Practice pursuant to Your Practice's privacy policies and your consent.
Data we may receive from Your Practice:
| Category | Examples |
|---|---|
| Laboratory Results | Blood panels, metabolic panels, hormone levels, genetic tests |
| Supplements & Medications | Current prescriptions, supplement protocols, dosage changes |
| Vitals | Blood pressure, weight, glucose readings |
| Visit Summaries | Clinical notes, provider assessments, care plans |
| Demographics | Name, date of birth, email, phone number |
Important:
We use your data in connection with the Services to generate personalized health insights and recommendations, trend analyses and pattern recognition, AI-generated wellness guidance, and progress tracking and goal monitoring. This derived information is considered part of your data and is subject to this Privacy Policy and our Consumer Health Data Privacy Policy.
Not Medical Advice: TakeHelm is a wellness advisory service, NOT a healthcare provider. Nothing provided through our Services constitutes medical advice, diagnosis, or treatment. Always consult qualified healthcare professionals before making health-related decisions. See our Terms of Service for full disclaimer.
AI-Generated Content: Our Services use artificial intelligence (including large language models provided by Anthropic) to generate personalized health insights, recommendations, and trend analyses. Key commitments regarding AI processing:
All AI processing is performed in accordance with this Privacy Policy and our Consumer Health Data Privacy Policy.
We process your information based on the following legal grounds:
Creating and managing your account, delivering personalized health insights and recommendations, generating weekly wellness plans and daily guidance, analyzing trends in your health data, and providing customer support.
Understanding how users interact with the Services, identifying and fixing bugs, developing new features, and improving our recommendation algorithms using de-identified and aggregated data.
Sending service-related announcements and updates, responding to your inquiries, and sending promotional communications (with your consent, where required).
Detecting and preventing fraud, abuse, and security threats, enforcing our Terms of Service, and protecting the rights and safety of TakeHelm and our users.
Complying with applicable laws and regulations, responding to legal requests and court orders, and establishing, exercising, or defending legal claims.
Conducting health and wellness research using de-identified and aggregated data. Publishing research findings (never with individual identification).
If you are enrolled through a healthcare practice, we also use your information for:
How we protect clinical data during AI processing: Before health information received from Your Practice is used in AI-powered features, we remove identifying information (your name, contact details, record numbers, and exact dates) as a reasonable de-identification measure under HIPAA. The AI services that generate your coaching content never receive your identity; your name and dates are re-attached only within our HIPAA-protected systems when content is displayed to you or delivered to Your Practice.
We do NOT use your information for:
We do not sell your personal information. We share your information only as described below:
We share information with third-party service providers who perform services on our behalf (as of July 16, 2026):
| Category | Purpose | Providers | Receives identifying health data? |
|---|---|---|---|
| Cloud Infrastructure | Data storage and processing | Supabase, Vercel | Yes — under Business Associate Agreement |
| De-Identification & Document Processing | Removing identifiers from clinical data; secure processing of provider records | Google Cloud (Vertex AI, Cloud Run, Cloud Storage) | Yes — under Business Associate Agreement |
| AI/Machine Learning | Generating personalized recommendations | Anthropic | No — de-identified data only |
| Pipeline Compute | Automated data processing | Modal | No — de-identified data only |
| Patient Notifications | iMessage/SMS coaching notifications | Sendblue | No — notifications contain no provider-sourced health information |
| Transactional Email | Service emails | Resend | No provider-sourced health information — content is limited to data you provide directly or from devices you connect |
| Secure Health Email | Emails containing provider-sourced health information (e.g., laboratory result interpretations) | Paubox | Yes — under Business Associate Agreement |
| Payment Processing | Processing subscription payments | Stripe | No — payment data only |
All service providers are bound by contractual obligations to process data only as we instruct, maintain appropriate security measures, and not use data for their own purposes. Service providers that handle Protected Health Information are bound by Business Associate Agreements; providers marked "de-identified data only" never receive your identity alongside your health information.
If you are enrolled through a healthcare practice, we may share information with Your Practice:
We do not share your data with healthcare providers other than Your Practice without your explicit consent.
We may share your information with third parties you explicitly authorize, when you use features that involve sharing, or when you request data export.
We may disclose your information to comply with applicable law, respond to lawful requests from government authorities, enforce our Terms of Service, or protect the rights, property, or safety of TakeHelm, our users, or others.
If TakeHelm is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice and the opportunity to opt out where required by law.
We may share de-identified and aggregated data that cannot reasonably be linked to you for research, analytics, and business purposes.
We use cookies and similar technologies to remember your preferences and settings, keep you logged in, understand how you use the Services, and improve performance and functionality.
We do not use advertising cookies, tracking pixels, retargeting tags, or share browsing data with ad networks. We do not engage in interest-based or cross-site advertising.
Most browsers allow you to block or delete cookies. However, blocking essential cookies may prevent the Services from functioning properly. We recognize and honor Global Privacy Control (GPC) signals as required by California law (CPRA).
The Services integrate with third-party platforms (Apple Health, Oura, Withings, etc.). When you connect these services, you authorize us to receive data from them, and your use of those services is governed by their own privacy policies. The Services may also contain links to third-party websites whose privacy practices we do not control.
We implement administrative, technical, and physical security measures to protect your information, including:
No system is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law, including the FTC Health Breach Notification Rule where applicable.
Account Data: Retained while your account is active and for up to 90 days afterward to facilitate account recovery, after which it is deleted.
Health Data: Retained while your account is active. Deleted or de-identified within 45 days of account deletion request. Some data may persist in encrypted backups for up to an additional 90 days, after which it is automatically purged.
Usage Data: Retained in identifiable form for up to 24 months, then de-identified or deleted.
When you delete your account or request data deletion, we will delete your personal information from our active systems within 45 days, instruct our service providers to delete your data, and may retain de-identified and aggregated data that cannot reasonably be linked to you, or data required by law.
You can:
You have additional rights under the Washington My Health My Data Act (MHMDA), including the right to confirm, access, delete, and withdraw consent for your consumer health data. See our Consumer Health Data Privacy Policy for full details. We do not sell consumer health data.
You may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. We do not sell personal information. Contact privacy@takehelm.io to exercise your rights.
Residents of states with comprehensive privacy laws (Colorado, Connecticut, Virginia, Utah, and others) may have similar rights to access, delete, and correct their personal information. Contact privacy@takehelm.io to exercise these rights.
Our Services are currently available only to users in the United States. Your information is stored and processed in the United States. If you access the Services from outside the United States, you do so at your own risk and consent to the transfer of your information to the United States.
The Services are intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 18. If we learn that we have collected such information, we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated Policy on the Site, update the "Last Updated" date, notify you by email, and material changes will be effective 30 days after posting unless we indicate otherwise.
For changes affecting consumer health data: Material changes to how we collect, use, or share consumer health data require your affirmative re-consent. See our Consumer Health Data Privacy Policy for details.
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Take Helm Health, LLC
Email: privacy@takehelm.io
Mail:
Take Helm Health, LLC
Attn: Privacy
1522 Western Ave STE 24699
Seattle WA 98101
United States