Privacy Policy
Privacy Policy
Effective date: July 10, 2026·Last updated: July 10, 2026
This Privacy Policy explains how Rapha Health, LLC ("Rapha Health," "we," "us," or "our") collects, uses, stores, and shares information when you use the Rapha Health web application and website at raphahealthco.com (the "Service").
Rapha Health is a direct-to-consumer self-tracking and informational tool for adults tracking symptoms, supplements, recovery practices, and related health and wellness information in connection with chronic inflammatory, mold-related, or similar recovery journeys. Rapha Health is not a healthcare provider, is not a HIPAA covered entity, does not bill insurance, and is not a medical device.
We recognize that the information you enter into the Service may be sensitive. This policy describes our practices in plain language.
1. Who this Service is for
The Service is intended for individuals who are:
- at least 18 years old;
- using the Service for personal self-tracking and informational purposes; and
- primarily located in the United States or otherwise accessing a United States-operated service.
We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us at griffin@raphahealthco.com, and we will take reasonable steps to delete it.
The Service is operated from the United States and intended primarily for users in the United States.
2. Information we collect
We collect only the types of information needed to operate the Service, support your account, process subscriptions, and provide the self-tracking features you choose to use.
A. Account information. When you create an account, we collect your email address; your password, stored only in hashed form through our authentication provider; and account creation date and related authentication records. We do not see or store your plaintext password.
B. Profile information. You may provide profile information, including first name, age, biological sex, optional weight, symptom duration, recovery stage, and protocol start date.
C. Health and wellness information you log. You may choose to log sensitive health and wellness information, including symptoms; supplements and supplement start dates; daily energy rating; environment or exposure notes; recovery practices; and optional last-menstrual-period date for cycle context. This information is voluntary, but some features of the Service may not work as intended unless you provide relevant information.
D. Subscription and billing information. Payments are processed by Stripe. We do not receive or store your full credit card number. We may receive limited billing information from Stripe, such as subscription status, trial status, billing period, payment status, limited card details (such as card brand and last four digits, where made available by Stripe), and customer or subscription identifiers.
E. Technical and security information. We collect basic technical and security information needed to operate and protect the Service, including IP address, timestamps, login and session activity, browser or device information, and error and security logs.
F. Communications. If you contact us, we may collect the information you include in your message, such as your email address, message content, and support request details.
3. Sensitive health and consumer health data
Some information you provide to Rapha Health may be considered sensitive health information, consumer health data, or similar protected data under certain state or federal laws.
For purposes of this policy, "health data" means the information you choose to enter into the Service about your symptoms, supplements, energy, recovery practices, environment or exposure notes, cycle context, and related recovery information.
We use your health data only to provide the Service to you; display your logs, snapshots, trends, and informational insights; help you manage your account; maintain, secure, debug, and improve the Service; respond to your requests; and comply with legal obligations.
We do not sell your health data. We do not use your health data for third-party advertising. We do not use third-party advertising trackers. We do not share your health data with advertisers, data brokers, or social media advertising platforms.
4. How we use your information
We use your information to create and maintain your account; authenticate your login; provide, operate, maintain, secure, and improve the Service; store and display the data you log; generate self-tracking snapshots, trends, and informational insight cards based on the data you enter; send transactional and account-related emails (such as password resets, account notices, trial notices, billing notices, and service updates); manage subscriptions, trials, promotional access, and billing through Stripe; respond to support requests; detect, prevent, and investigate abuse, security incidents, or technical issues; and comply with legal, tax, accounting, and regulatory obligations.
Your individual health data is used to power your experience in the Service. We do not use it to make decisions about you outside the Service.
5. Informational insights and logged data
The Service may display trends, patterns, reminders, rule-based insight cards, or other informational outputs based on the information you enter.
These outputs are for self-tracking and informational purposes only. They are not medical advice, diagnoses, treatment recommendations, clinical findings, or emergency alerts. Correlation does not mean causation.
6. How we share information
We do not sell your personal information or health data. We share information only in limited circumstances described below.
A. Service providers and subprocessors. We use service providers to operate the Service. These providers process information only as needed to provide services to us:
| Provider | Purpose | Information handled |
|---|---|---|
| Supabase | Database, authentication, and hosting | Account information, profile information, health and wellness logs, technical/security data |
| Stripe | Payment processing and subscription management | Billing status, subscription information, payment-related information |
| Resend | Transactional and account emails | Email address, transactional email content |
B. Legal compliance and safety. We may disclose information if we believe it is reasonably necessary to comply with applicable law, regulation, legal process, or government request; protect the rights, property, or safety of Rapha Health, our users, or others; investigate fraud, abuse, security incidents, or technical issues; or enforce our Terms of Service.
C. Business transfers. If Rapha Health is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, information may be transferred as part of that transaction. If that happens, we will require the recipient to handle your information in a manner consistent with this Privacy Policy or provide notice where required by law.
7. No sale of health data and no advertising use
We do not sell your health data. We do not share your health data for cross-context behavioral advertising, targeted advertising, or third-party advertising purposes. We do not use third-party advertising trackers, pixels, or behavioral advertising cookies in the Service.
8. Cookies and local storage
We use only essential cookies and local storage needed to keep you signed in, maintain secure sessions, operate the Service, and remember necessary account or app state. We do not use third-party advertising cookies or advertising trackers.
9. Data retention
We keep your information for as long as your account is active or as reasonably necessary to provide the Service.
You may delete your account and data from Settings. When you delete your account, we will delete or de-identify your personal and health data within a commercially reasonable period, except where we need to retain limited information to comply with legal, tax, accounting, or payment obligations; prevent fraud or abuse; resolve disputes; enforce agreements; or maintain security logs for a limited period.
Backup copies may persist for a limited time before being overwritten or deleted according to our backup practices.
10. Your choices and rights
You can access and update certain profile and logged information in the Service; delete your account and data from Settings; cancel your subscription through the Stripe customer portal available from Settings; opt out of non-essential emails, where applicable; and contact us to request access, correction, deletion, or other assistance with your information.
We may need to verify your identity before responding to certain requests. To make a privacy request, contact us at griffin@raphahealthco.com.
11. California privacy rights
If you are a California resident, you may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, if the law applies to Rapha Health. These rights may include the right to know what personal information we collect, use, disclose, sell, or share; access personal information we have collected about you; delete personal information, subject to certain exceptions; correct inaccurate personal information; limit certain uses and disclosures of sensitive personal information; opt out of the sale or sharing of personal information; and not be discriminated against for exercising privacy rights.
We do not sell personal information or health data. We do not share health data for cross-context behavioral advertising.
To exercise California privacy rights, contact us at griffin@raphahealthco.com. We may need to verify your identity before completing your request.
12. Washington My Health My Data Act
Washington's My Health My Data Act may apply to certain companies that collect, use, or share consumer health data, including some health and wellness apps that are not covered by HIPAA.
Rapha Health collects health and wellness information that users voluntarily enter into the Service. We use that information to provide the Service to the user and for the limited purposes described in this Privacy Policy.
We do not sell consumer health data. We do not share consumer health data for advertising. We do not use geofencing around healthcare facilities. We do not collect precise location data for the purpose of identifying visits to healthcare facilities.
If Washington's My Health My Data Act applies to Rapha Health or to any user, you may have rights to confirm whether we collect, share, or sell consumer health data; access consumer health data; withdraw consent where consent is required; request deletion of consumer health data; and receive a list of certain third parties or affiliates with whom consumer health data has been shared, where required by law.
To exercise these rights, contact us at griffin@raphahealthco.com.
13. FTC Health Breach Notification Rule
Rapha Health is not a HIPAA covered entity. However, certain non-HIPAA health apps and services may be subject to the FTC Health Breach Notification Rule.
If Rapha Health experiences a breach of unsecured personal health information that triggers the FTC Health Breach Notification Rule or another applicable breach-notification law, we will provide notices to affected users, regulators, and other required parties in the manner and timeframe required by applicable law.
We also require service providers to notify us of security incidents affecting information they process for us, where required by contract or law, so we can evaluate and meet our notification obligations.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including encryption in transit; authentication controls; row-level security and access controls intended to limit users to their own records; limited administrative access; security logging and monitoring; and use of reputable infrastructure and payment providers.
No system is perfectly secure. We cannot guarantee absolute security, but we work to protect your information and to respond appropriately to security incidents.
15. HIPAA status
Rapha Health is not a healthcare provider, health plan, healthcare clearinghouse, or business associate acting on behalf of one of those entities.
The Service is a direct-to-consumer self-tracking and informational tool. Rapha Health does not bill insurance and is not providing medical care.
Because of this, information you provide to Rapha Health generally is not governed by HIPAA. It may, however, be protected by other federal or state privacy, consumer protection, health data, or breach-notification laws.
16. Users outside the United States
Rapha Health is operated from the United States and is intended primarily for users in the United States.
If you access the Service from outside the United States, you understand and consent that your information will be transferred to, stored, and processed in the United States, which may have data-protection laws different from those in your country.
Because Rapha Health is operated from the United States and is not currently designed for international compliance, you are responsible for determining whether your use of the Service complies with laws that apply to you in your location.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and, where appropriate, notify you by email or in the Service. Your continued use of the Service after the updated policy becomes effective means you accept the updated policy.
18. Contact us
Questions about this Privacy Policy or your data may be directed to:
Rapha Health, LLC
Email: griffin@raphahealthco.com