Privacy Policy
Last Updated: February 16, 2025
Our Commitment to Your Privacy
Ethia handles sensitive health information. We take this responsibility seriously. This Privacy Policy explains what data we collect, how we protect it, and how we use it to serve you.
The short version: Your health information is stored under an anonymous token, separate from your identity, which is kept in an encrypted vault. We never sell your personal information, and we never share your records with researchers unless you choose to.
This policy is reviewed annually and upon any material changes to our data collection or processing practices. Last review completed: February 16, 2025.
1. Information We Collect
Account Information
When you create an account, we collect:
- Name and email address
- Password (stored encrypted, never in plain text)
- Primary autoimmune condition(s)
Health Information
To provide our services, we collect health information you choose to share:
- Lab results you upload (PDFs, images, or manual entry)
- Questionnaire responses about your symptoms, treatments, and health history
- Information about medications and biologics you've tried
- Your health goals and concerns
Usage Information
We automatically collect:
- How you interact with our platform (pages visited, features used)
- Device information (browser type, operating system)
- IP address and general location (city/region level)
2. How We Protect Your Data
🔒 HIPAA-Aligned Architecture
Ethia uses a split-database architecture built for healthcare data protection. Your directly-identifying information (name, email, date of birth) is encrypted and kept in a separate vault, apart from your health information, which is stored under an anonymous token rather than your name.
Our security measures include:
- Encrypted identity vault: Your directly-identifying information (name, email, date of birth) is encrypted at rest with AES-256 in a dedicated vault, separate from your health data
- Pseudonymized health data: Your health information is linked to an anonymous patient token, not your name, so it cannot be tied back to you without the separately-secured vault
- Encryption in transit: All data transmitted to and from Ethia uses TLS 1.2+
- Access logging: Access to identifying data is logged for audit purposes
- Regular security reviews: We regularly assess and improve our security practices
3. How We Use Your Information
To Provide Our Services
- Analyze your lab results using AI to provide educational insights
- Track your health markers over time and identify trends
- Personalize content and recommendations to your condition
- Show you news and recruiting studies shared by your patient organization (interest is always opt-in; your records are never shared with researchers)
To Improve Ethia
- Analyze usage patterns to improve our platform
- Train and improve our AI analysis systems (using de-identified data only)
- Fix bugs and technical issues
To Communicate With You
- Send important account notifications
- Alert you to new research opportunities that match your profile
- Respond to your questions and support requests
4. How We Share Your Information
We never sell your personal information. Period.
Research Opportunities (You Are Always in Control)
We do not sell or share your identifying information or your health records with pharmaceutical companies or research organizations.
If a patient advocacy organization you are connected with shares a research opportunity that may fit your profile, you will see it inside the app. Your information is shared only if you choose to express interest in that specific opportunity, and only then.
Any aggregate insights we provide to a patient organization are de-identified, cannot be traced to an individual, and are shared only with your explicit consent.
Service Providers
We work with trusted service providers who help us operate Ethia:
- Cloud hosting: Our infrastructure is hosted on secure, HIPAA-eligible cloud platforms
- AI processing: We use AI services to analyze lab results (data is processed securely and not retained by the AI provider)
- Email services: To send you account notifications
All service providers are contractually bound to protect your data and use it only for the services they provide to us.
Legal Requirements
We may disclose your information if required by law, such as in response to a valid court order or subpoena. We will notify you if legally permitted to do so.
5. Your Rights and Choices
Access Your Data
You can view all the health data you've uploaded and your profile information through your dashboard at any time.
Download Your Data
You can request a copy of all data we have about you. Contact us at george@ethia.io to request a data export.
Delete Your Data
You can request deletion of your account and all associated data. Upon deletion:
- Your personal information will be permanently removed from our identity vault
- Your health data and lab results will be deleted
- Your anonymous token will be deactivated
- Deletion is typically completed within 30 days
Note: We may retain certain anonymized, aggregated data that cannot be linked back to you for research and improvement purposes.
Communication Preferences
You can opt out of non-essential emails at any time. Essential account notifications (security alerts, terms changes) cannot be opted out of while you have an active account.
Research Participation
We never share your records with pharmaceutical companies or researchers. If your patient organization shares a research opportunity that fits your profile, you will see it in the app, and nothing is shared with anyone unless you choose to express interest. You can manage research-opportunity notifications in your account settings.
6. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you logged in to your account
- Remember your preferences
- Understand how you use our platform
- Improve our services
We do not use cookies for third-party advertising. You can disable cookies in your browser settings, but some features of Ethia may not work properly.
7. Data Retention
We retain your data for as long as you have an active account. After account deletion:
- Personal information is deleted within 30 days
- Backup copies are purged within 90 days
- Audit logs are retained for 7 years as required for HIPAA compliance
8. Children's Privacy
Ethia is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
9. International Users
Ethia is primarily operated from the United States. If you access our services from outside the US, your data will be transferred to and processed in the United States in accordance with the protections described in this policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email and/or a prominent notice on our platform. Your continued use of Ethia after changes take effect constitutes acceptance of the updated policy.
11. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of the sale of personal information.
As noted above, we do not sell personal information. To exercise your other rights, contact us at george@ethia.io.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Email: george@ethia.io
Company: Ethia / Investigate Health Publishing LLC