Legal
Withya Consumer Health Data Privacy Policy
Last updated: September 13, 2026 · Version 1.0
1. Scope and organization
STH Technologies, LLC, 9206 Sunshine Pl, Downey, CA 90240, United States, operates Withya. Contact [email protected] for health-data requests. This separate policy explains our collection, use and sharing of consumer health data. It supplements the Privacy Policy, including for consumers protected by Washington’s My Health My Data Act, Nevada’s consumer-health-data law and applicable Connecticut protections. Applicable law controls the scope of each right.
2. Categories collected and sources
We collect health data supplied by you and other authorized adults: feeding and nursing records; pumping; sleep and bodily functions; symptoms, temperatures, recorded medicines and illness notes; weight, height/length, head circumference and growth-reference inputs; food introductions and reported reactions; developmental observations; gestational information; healthcare appointments, preparations, contacts and outcomes; and relevant free text, images or video you choose to provide.
Child birth date, reference sex, location and account/profile identifiers can become health data when linked to those records. Private assistant questions, relevant child context, responses and conversation history can reveal health concerns. Derived ages, growth displays and summaries may also be health data.
Technical events may reveal which health-related screen or function was used and when. Linked installation/account/child references, IP addresses and device metadata can make those events identifiable even if typed values are excluded. We treat information according to what it reveals, rather than assuming all analytics are nonsensitive.
Sources are the adult supplying information, other adults authorized for the same child, the app/device during use, and calculations or processing of the supplied records. Device location services can supply location information when you use the permitted location feature.
3. Purposes and permission
We use necessary health data to provide the specific functions you request: recordkeeping, family sharing, reminders, growth/reference displays, personalized guidance, private questions and authorized exports. Health-linked diagnostics and service-improvement analysis are separate purposes where they go beyond what is necessary for the requested function.
The app currently records screen and function use, including health-related activity, linked to an installation and, when applicable, your account and selected child. There is no separate in-app consent step or general switch for these usage events. Where applicable law requires consent that has not been obtained, this policy and your acceptance of the Terms do not authorize that collection. A service-necessity exception is limited to the data needed for your requested function; it does not cover unrelated improvement analytics.
Where law requires it, you have the right to give or refuse informed consent to collection and use, and separate consent to sharing. You may withdraw consent through the contact below. Refusing optional processing does not remove unrelated account or privacy rights. Required permission must be established before the affected processing; a notification permission or general Terms acceptance does not replace it.
4. Categories shared and recipients
| Recipient | Data and reason |
|---|---|
| Adults authorized for the selected child | Shared profile, care, plans, journal and media, including export and editing rights, when you authorize sharing |
| Amazon Web Services acting for Withya | Relevant health records for hosting, storage and the requested managed private-answer service; limited operational processing |
| Google/Firebase, RevenueCat and the relevant app store | Minimum identifiers and delivery/entitlement metadata needed for their function; this is not permission to send care histories to them |
| Community or message recipients you choose | Health information you intentionally include in a post, reply or message, visible to that audience |
| Authorized support or safety personnel | Information necessary for an access-authorized support request, security matter or report |
| Google, our support-mailbox provider | Email request contents and account/contact details you send; avoid unnecessary health history |
| A lawful authority or successor operator | Restricted information only where lawful, necessary and subject to applicable notice, consent and purpose restrictions |
We do not share consumer health data with affiliates. Shared service-provider accounts do not authorize another product’s use of Withya data. The main Privacy Policy identifies current provider services. If a recipient’s independent use constitutes sharing under applicable law, the required separate permission is necessary; calling it a processor is not enough.
Private assistant conversations are not automatically shared with other caregivers. Community posting and family sharing are distinct choices. We do not sell consumer health data, use it for targeted advertising, or offer an authorization to sell it as part of signup.
5. Rights and requests
Email [email protected] with the subject “Health data request.” Tell us whether you seek access, deletion, correction, withdrawal of collection or sharing consent, recipient information, or an appeal. A legal representative may act with verified authority.
Where applicable, you may obtain confirmation of processing, access your health data, withdraw collection or sharing consent, request deletion and receive the required list of third parties and affiliates with which the data was shared, including contact information where required. Washington requests are generally due within 45 days, with one additional 45-day extension when permitted and explained; appeals receive a decision within 45 days. Nevada requests generally use a 45-day response period with a permitted additional 45 days, and appeals within 45 days. Other applicable deadlines can differ and control the request concerned.
Nevada deletion has a separate, shorter rule: subject to its specific backup exception, we must delete covered data and notify applicable recipients within 30 days after authenticating the request; notified recipients have their own 30-day deletion duty. The general 45-day response period does not replace this rule. We do not use a longer backup exception to extend ordinary live-data retention.
We will explain a refusal and how to appeal by replying “Privacy appeal” to our contact. You may complain to the relevant regulator, including the Washington Attorney General or Nevada Attorney General. You retain any available court remedy.
Withdrawal stops consent-based processing prospectively; legally permitted retention or processing must have a separate basis. Deletion covers applicable live records, associated raw analytics and downstream instructions required by law. A routine seven-day account recovery period does not reset the statutory response clock or prevent an independent health-data deletion request.
Where Washington law permits delayed deletion from archived or backup systems, that delay is limited to six months after authentication of the request. This exception does not extend ordinary live-data retention. Other laws may require earlier handling. We must notify applicable processors/recipients as required rather than merely removing the on-screen record.