Last updated: June 30, 2026
This Privacy Policy explains how Health Question Architect AI ("we", "us", the "Service") collects, uses, and protects information. The Service is designed to collect and retain as little personal data as reasonably possible.
1. Who we are
Health Question Architect AI is a consumer health-literacy and medical-visit preparation tool. It is not a healthcare provider, health plan, healthcare clearinghouse, HIPAA covered entity, or intended HIPAA business associate, and it does not provide medical advice, diagnosis, or treatment.
2. Information we collect
- Account data: email address and authentication data managed by Supabase.
- Subscription data: plan status, billing state, Stripe customer/subscription identifiers, and related payment status. Stripe processes card payments; we do not see or store your full card number.
- Limited technical data: IP address and request metadata used for security, abuse prevention, rate limiting, and service operation.
- Conversation text: health-related text you choose to type is processed transiently to generate an AI response.
3. Conversation content
We do not save conversation content in our server database and do not write conversation content to our server logs. Conversation content is sent to the configured AI model provider to generate the response. We do not intentionally send your account email or billing data to the AI model provider, but the health text you type is processed by that provider.
4. Cookies and Local Storage
We use cookies and browser storage for functional purposes needed to operate the Service. We do not use advertising cookies, behavioral advertising pixels, or cross-site tracking tools in the current version of the Service.
- Session cookies: used to keep the application session secure while you use the Service.
- Language cookie: used to remember your selected language preference.
- Authentication storage: Supabase may use browser storage to keep you signed in and manage secure authentication flows.
- Chat local storage: your browser may store recent conversation content locally on your device so the chat can be restored.
You can remove local conversation content by restarting the conversation, clearing browser storage, or deleting your account. You can also control cookies and local storage through your browser settings, but disabling essential storage may prevent login, language selection, or chat features from working correctly.
5. How we use information
- To create and secure your account.
- To provide the Service, including free usage limits and Premium subscription access.
- To process payments, renewals, cancellations, and account deletion requests.
- To prevent abuse, fraud, security incidents, and unauthorized access.
- To comply with applicable legal obligations.
6. Service providers
We use service providers only as needed to operate the Service:
- Supabase - authentication and database services.
- Stripe - payment processing, subscription billing, and related payment records.
- AI model provider - response generation from the conversation text you submit.
7. Health information and AI
The assistant may discuss health topics, but it does not diagnose, prescribe, provide treatment, or replace a licensed professional. AI responses may be inaccurate or incomplete. Always verify important information with a qualified healthcare professional. In an emergency, contact local emergency services immediately.
8. Retention and deletion
We keep account and subscription data while your account is active or as needed for legal, security, tax, billing, or dispute purposes. Conversation content is not retained in our server database. You can delete your account from the app; this removes account/subscription data under our control and cancels any active subscription, subject to records that providers or law may require us to retain.
9. Your choices
Depending on where you live, you may have rights to access, correct, delete, or receive information about personal data. Contact us at support@example.com to exercise available rights.
10. Security
We use HTTPS/TLS in transit, provider-side encryption at rest where available, secure cookies, least-privilege access controls, rate limiting, and secret keys stored server-side. No system is perfectly secure, and we do not promise absolute security.
11. Children
The Service is intended for adults 18 and older and is not directed to children. We do not knowingly collect data from children.
12. Breach notification
If we discover a breach involving unsecured identifiable health information or other personal information, we will investigate promptly and notify affected users, the FTC, media outlets, or other authorities when required by applicable law, including the FTC Health Breach Notification Rule. When that rule applies, notices will be made without unreasonable delay and no later than the legally required deadline after discovery.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new "Last updated" date.
14. Contact
Questions about privacy? Contact us at support@example.com.