Consumer Health Data Privacy Policy
This policy is for people in Washington and Nevada. Their laws — Washington's My Health My Data Act and Nevada's SB 370 — cover data that relates to your health, treat mental health as part of that, and require this policy to be published on its own rather than folded into a general privacy notice. So here it is on its own.
Start here: most of it never reaches us
Runeka runs on your Windows computer, and your workspace — Diary entries, mood and energy check-ins, reflections, focus history — lives in a database file on that machine. We do not have a copy. There is no background sync, no upload you did not ask for, and no server-side mirror of your journal.
The rest of this policy describes the narrow cases where consumer health data does reach us, because you switched a cloud feature on and used it. If you never turn one on, we hold no consumer health data about you at all.
What we collect, and why
Only these categories, and only through a deliberate action you take:
- Diary text you send for a cloud reflection. Exactly the entries and context shown in the scope receipt before you send — nothing else from your workspace travels with it. Purpose: to generate the reflection you asked for, and nothing else.
- Wellbeing values you confirmed — mood, energy, stress, or sleep — when they are part of that same scope receipt. Purpose: context for the reflection. The AI never fills these in for you; only values you entered or explicitly confirmed exist at all.
- Memories you individually approved, where they are part of the scope you send. Purpose: continuity between reflections.
- Encrypted backups, if you turn backup on. These are encrypted on your device before upload. We hold ciphertext and its size, timestamps, and quota metadata. We never receive your passphrase and cannot read the contents. Purpose: so you can restore your own data.
We do not infer health conditions, we do not diagnose, and we do not build a health profile from anything you write. Reflections are not clinical findings — see the AI & wellbeing disclaimer.
Where it comes from
One source: you, directly, through the Runeka app on your own device. We do not buy consumer health data, we do not receive it from data brokers, advertising networks, health providers, or other apps, and we do not derive it from tracking you across the web. There are no third-party trackers or ad pixels on our website.
What we share, and with whom
We share the narrowest thing that makes a feature work, with these categories of recipients:
- AI providers — Anthropic or OpenAI, selected by our server — receive the exact Diary text and context you approved in the scope receipt, in order to generate that one response. Our own API processes the request in memory and does not write your Diary text or the AI response into its logs, analytics, or usage records.
- Infrastructure and storage providers hold encrypted backup blobs and run the service. They cannot read backup contents, because the encryption happens on your device.
That is the complete list for consumer health data. We do not share it with advertisers, data brokers, analytics vendors, insurers, employers, or social networks. Our crash-reporting and analytics tools are configured to exclude Diary and note text, task titles, AI prompts and responses, and anything you type. If you ask, we will give you the specific companies and their contact details, not just the categories.
We do not sell it
Runeka has never sold consumer health data and does not intend to. Selling it would require your separate written authorization under Washington law — a specific, signed document, distinct from the consent that lets a feature run. We do not ask for one, because we are not asking to sell your data. If that ever changed, it would take a new authorization from you, freely refusable, and refusing it would not cost you the product.
Consent, and taking it back
Cloud processing of Diary content is off until you turn it on. Turning it on is a separate choice from accepting the terms, from telemetry, and from every other switch in the product — we do not bundle them, and refusing keeps the rest of Runeka working. Each use then needs its own action, with the scope shown to you first.
You can withdraw that consent at any time in the app. Withdrawal stops future collection and sharing. It does not by itself erase what was already stored — the deletion right below does that.
Your rights
Under Washington and Nevada law you can ask us to:
- Confirm whether we collect, share, or sell your consumer health data, and give you access to it;
- List every third party and affiliate we have shared it with, including how to contact them;
- Withdraw your consent to our collecting and sharing it; and
- Delete it. Deletion reaches our live systems and our backups and archives — we remove it from backups on their next cycle rather than leaving a quiet copy behind. We will tell all our providers to delete it too.
We answer within 45 days. If a request is genuinely complex we may take one further 45 days, and we will tell you why before we do. It is free. If we turn a request down, we will explain why and give you a way to appeal to a person; if the appeal fails you can contact the Washington State Attorney General or, in Nevada, the Nevada Attorney General.
How to make a request
Email support@runeka.com and say what you want and that you are in Washington or Nevada. We may need to check the request really comes from you — usually by writing back to the email address on your account — and we will not ask for more than that check needs. You can delete local data yourself at any time in the app, without asking us.
No geofencing
We operate no geofence around any health-care facility, and Runeka does not collect your location at all. There is no location permission, no background positioning, and nothing that notices where you happen to be writing from.
HIPAA does not apply
Worth repeating here, because these laws exist precisely to cover the gap: Runeka is not a healthcare provider, health plan, or clearinghouse, and not a business associate of one, so HIPAA does not protect what you write in the app. That is exactly why Washington and Nevada wrote these statutes, and why this policy exists.
Changes and related documents
If we change the categories of consumer health data we collect, use, or share, we will update this policy and ask for your consent before the new processing starts — not after. Read this alongside the Privacy Notice, the regional privacy supplement, the Terms of Use, and the AI & wellbeing disclaimer.
This policy is published by RUNEKA, Grega Nerat s.p., Razvanjska cesta 109, 2000 Maribor, Slovenia.
Last updated: August 18, 2026.
