Privacy
Privacy, in plain words.
A short summary first, then the full policy. Where they differ, the full policy governs.
Effective & last updated: July 29, 2026.
What we collect
Your email, which role you chose, which devices interest you, and anything you type in the note. Nothing else. No cookies, no ad trackers.
Why
To email you about Amaranth — early access, timelines, and questions we’re thinking through. Nothing else, ever.
Who sees it
The two founders. We don’t sell or share your information. Our infrastructure providers (hosting, database) process it on our behalf.
Your choices
Every email includes unsubscribe. Want your information deleted? Write to hello@amaranth.health and we’ll confirm within a week.
A note on sensitivity
We treat the fact that you’re interested in intimate health as private in itself. That’s the standard we’re building the whole product to.
The full policy
The Full Privacy Policy
27 sections · Effective July 29, 2026
1. Who we are, and what this Policy covers
Amaranth Health (“Amaranth,” “we,” “us”) is a pre-launch health-technology project operated by its two founders. As of the Effective Date, a separate incorporated legal entity has not been identified in this Policy. Until an incorporated entity assumes responsibility, the founders who operate Amaranth Health jointly determine why and how personal information covered by this Policy is processed. In European data-protection terminology, they act as joint controllers for that processing.
You can contact Amaranth Health about this Policy or exercise privacy rights by emailing hello@amaranth.health.
When Amaranth Health incorporates or another legal entity becomes responsible for the website, waitlist, or related records, that entity may assume the controller responsibilities described here. We will update this Policy with the entity’s legal name and contact information and provide any notice or renewed consent required by law before a material change applies to information already collected.
1.1 Services covered
This Policy covers:
- the website at amaranth.health and any page on that domain that links to this Policy;
- the Amaranth Health pre-launch waitlist and any preference, interest, or note fields displayed with it;
- emails or other communications you send directly to hello@amaranth.health about the website or waitlist;
- waitlist confirmations, product-development updates, surveys, early-access invitations, and similar email communications sent because you asked to hear from us; and
- privacy-rights requests and related correspondence.
1.2 Services not yet covered
This Policy does not govern any future Amaranth Health AI or voice companion, physical device, prototype, account, subscription, payment flow, clinical service, care-navigation service, telehealth service, research study, voice recording, conversation transcript, sensor data, or device telemetry. Those activities may involve materially different information and risks. Before any such product or service launches, we will provide product-specific terms and a product-specific privacy notice, complete any required privacy or safety assessments, and obtain any consent required for the relevant data and purpose.
This Policy also does not govern third-party websites, clinicians, laboratories, health systems, pharmacies, app stores, device platforms, or other services that may be linked from the Site. Their own policies apply to them.
1.3 A transparency notice, not a waiver
This Policy is intended to explain our practices clearly. It does not waive any right or remedy that applicable law gives you. It also does not create duties beyond the commitments expressly stated here or those imposed by applicable law.
2. Key definitions
For this Policy:
- “Consumer Health Data” means personal information that identifies or can reasonably be linked to a person and reveals or permits an inference about that person’s physical or mental health, health-related condition, treatment, bodily function, reproductive or sexual health, sex life, health-care activity, or interest in health-related products or services. This term is used broadly and includes information protected under Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar laws where applicable.
- “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked directly or indirectly to an individual or household. It includes “personal data” and similar terms used in privacy laws.
- “Process” or “Processing” means collecting, recording, organizing, storing, accessing, using, analyzing, disclosing, transmitting, deleting, or otherwise handling information.
- “Sensitive Information” includes Consumer Health Data and any information that reveals or permits an inference about health, sex life, sexual orientation, precise location, government identifiers, account credentials, or other categories treated as sensitive under applicable law.
- “Service Provider” or “Processor” means a vendor that processes information for us under instructions and contractual restrictions, rather than for its own independent marketing purposes.
- “Sell” and “Share” have the meanings assigned by applicable law. In particular, “share” can mean disclosure for cross-context behavioral advertising under California law, even when no money changes hands. Routine processing by a contractually restricted Service Provider is generally not a sale or advertising share, although we disclose it in this Policy for transparency.
- “Site” means the website, waitlist, and related pages or communications covered by Section 1.
3. Our privacy principles
We design the waitlist around the following rules:
- Collect less. We ask only for information needed to run the waitlist and understand interest in the planned service.
- Treat interest as sensitive. We do not wait for a person to provide a diagnosis before applying heightened safeguards. Interest in intimate-health services can itself be sensitive.
- Use information only for stated purposes. We do not quietly repurpose waitlist data for unrelated advertising, data brokerage, insurance, employment, credit, housing, or eligibility decisions.
- No behavioral advertising. We do not use advertising pixels, cross-site trackers, or data-broker profiles.
- No sale. We do not sell Personal Information or Consumer Health Data.
- No family outreach. We do not contact a family member, clinician, employer, insurer, or other person on your behalf merely because you joined the waitlist or mentioned that person.
- No model training with waitlist records. We do not use identifiable waitlist submissions, including notes, to train general-purpose or product machine-learning models.
- Limited access. Access is limited to people and providers who need it for the purposes described here.
- Delete when no longer needed. We use defined retention periods and honor verified deletion requests subject to narrow legal exceptions.
- Ask again before a material expansion. If we want to use sensitive information for a materially different purpose, collect a new sensitive category, or disclose it to a new category of recipient, we will provide notice first and obtain consent where required.
4. Information we collect
The tables below describe the complete categories the current Site is designed to collect. The actual fields shown to you may be fewer. We do not infer that you selected an optional preference when you did not.
4.1 Information you provide through the waitlist
Contact identifier
Examples: Email address. Required? Yes.
Why collected: Create and administer the waitlist; send requested updates; respond to you; verify rights requests.
Relationship or role
Examples: Exploring for myself; for a family member; clinician or researcher; building or investing in this area; or another option displayed on the form. Required? If displayed as required.
Why collected: Understand the audience; tailor a reply or invitation; analyze demand in aggregate.
Product or device interests
Examples: Optional interest in planned concepts such as the Lamp, Comfort Device, Trainer, Stimulation Device, voice companion, or other options displayed on the form. Required? No.
Why collected: Understand demand and potential pilot interest in aggregate.
Free-text note
Examples: Anything you choose to type into the optional note field. Required? No.
Why collected: Read and respond to relevant feedback; understand questions or interest; identify potential advisors or pilot partners.
Consent and age confirmations
Examples: Checkbox status, policy and terms version, date and time, and form source. Required? Yes where displayed.
Why collected: Document your request, consent, eligibility, and the notice presented to you.
Communications
Examples: Messages you send to us, survey responses, and our replies. Required? No, unless needed to answer you.
Why collected: Respond, keep an accurate support history, and administer the waitlist.
Your email address may contain your name or workplace even though we do not ask for those items separately.
4.2 Please do not put sensitive details in the note
The optional note is not a medical intake form, secure clinical message, or emergency channel. Please do not include:
- symptoms, diagnoses, medical records, laboratory or test results;
- medication lists or prescription information;
- detailed sexual history or descriptions of sexual activity;
- government identifiers, financial information, account credentials, or precise address;
- information about a child; or
- another person’s name, contact information, health information, or private circumstances.
If you nevertheless provide such information, we will treat it under this Policy. We may delete, redact, or decline to respond to it when it is not needed for the waitlist, when it concerns another person, or when keeping it would create unnecessary risk. We do not undertake to monitor notes for emergencies, and submitting a note does not create a clinician-patient, fiduciary, confidential professional, or other special relationship.
4.3 Information processed automatically when you visit
The Site is configured to keep automatic collection limited. Depending on your browser, network, and our provider settings, the following may be processed:
Request and security data
Examples: IP address, request time, requested page, HTTP headers, browser or user-agent information, error data, and signals associated with spam or abuse.
How used: Deliver the Site, troubleshoot errors, prevent attacks, rate-limit submissions, and maintain security.
Cookieless aggregate analytics
Examples: Page views, referral page, approximate country or region, device or browser category, and aggregate interaction counts.
How used: Understand whether the Site works and which pages are used, without building a cross-site profile.
Submission metadata
Examples: Date and time, form endpoint, success or failure status, and a limited anti-abuse signal.
How used: Operate the form, prevent duplicate or malicious submissions, and diagnose failures.
We do not intentionally attach your full IP address to your waitlist database record. Our hosting and network providers may retain standard logs for their own service-delivery, security, fraud-prevention, and legal-compliance periods under their contracts and policies. We configure our systems to avoid copying those logs into the waitlist record and to minimize access and retention where settings permit.
4.4 Cookies, pixels, fingerprinting, and cross-site tracking
As of the Effective Date and as currently configured:
- Amaranth Health does not set advertising cookies;
- we do not use advertising pixels or software development kits;
- we do not use browser fingerprinting;
- we do not use cross-site behavioral advertising or retargeting;
- we do not embed social-media “like” or sharing widgets;
- we do not purchase or append data from data brokers; and
- Vercel Web Analytics, if enabled, is used in its cookieless, aggregate configuration.
A third-party website may set its own cookies after you choose to follow an external link. That third party’s policy controls its site.
If we later add a technology that stores or accesses information on your device, we will update this Policy and, where required, present an appropriate choice before the technology operates.
4.5 Information we deliberately do not request for the waitlist
We do not intentionally request a legal name, date of birth, phone number, street address, payment card, government identifier, account password, precise geolocation, medical record, diagnosis, laboratory result, voice recording, conversation transcript, photo, contact list, or data from a wearable or device.
There are no Amaranth Health user accounts or payments under this waitlist Policy. If those features are introduced, they will be covered by a new or updated notice before collection begins.
4.6 Sources of information
We collect information from only these sources for the current Site:
- You, when you submit the waitlist, email us, answer a survey, or exercise a right.
- Your browser and network, when they send the technical information necessary to request a page or submit a form.
- Our Service Providers, when they return delivery, security, bounce, unsubscribe, or aggregate analytics information generated while providing services for us.
We do not obtain waitlist profiles from data brokers, advertising networks, social networks, family members, clinicians, insurers, employers, public records, or commercial enrichment services.
5. Sensitive Information and Consumer Health Data
5.1 Why the waitlist can reveal sensitive information
Amaranth Health concerns intimate and sexual health. The facts that a person visited a particular page, joined the waitlist, chose a relationship category, selected a device or service interest, or wrote a note may reveal or support an inference about health, sex life, sexual orientation, caregiving, age-related concerns, or interest in health care. We therefore treat the relevant waitlist record as Sensitive Information and, where applicable, Consumer Health Data even if it contains no diagnosis.
5.2 Consent for collection and use
Where consent is required, we request affirmative consent before collecting the waitlist record. For information that may reveal health or sex-life interests under the EU or UK GDPR, we rely on explicit consent under Article 9(2)(a), together with consent under Article 6(1)(a), for the specified waitlist and communication purposes.
Optional interest fields remain optional. You can join the general waitlist without selecting a device or service interest unless a clearly disclosed pilot requires a particular eligibility answer. We do not use a pre-checked box, silence, inactivity, or acceptance of unrelated terms as sensitive-data consent.
5.3 No sale, targeted advertising, or geofencing
We do not:
- sell or offer to sell Consumer Health Data;
- share Consumer Health Data for cross-context behavioral advertising;
- use Consumer Health Data to target advertising to you on another service;
- permit a third party to collect Consumer Health Data over time and across unrelated websites through our Site;
- use precise location or a geofence around a clinic, pharmacy, testing location, or other health-care facility to identify, track, collect information from, or message a person; or
- condition the waitlist on signing an authorization to sell Consumer Health Data.
If our practices ever changed in a way that legally constituted a sale of Consumer Health Data, we would not proceed without the separate, specific, signed authorization and other safeguards required by applicable law. Our present policy is not to engage in such a sale.
5.4 No high-impact decisions or discriminatory use
We do not use waitlist information to make decisions about insurance, credit, housing, employment, education, health-care eligibility, pricing based on a sensitive trait, or another decision that produces legal or similarly significant effects. We do not discriminate against a person for exercising privacy rights or declining an optional sensitive field.
5.5 No model training or unrelated research
We may count selections and summarize feedback after removing direct identifiers, but we do not use identifiable waitlist records to train a general-purpose AI model or a future Amaranth Health model. Joining the waitlist is not consent to participate in human-subject research, clinical research, product testing, or a research study. Any future study or prototype program will use separate materials and consent appropriate to that activity.
6. Why we process information and our legal bases
We process only information reasonably necessary and proportionate to the purposes below.
Receive and administer your waitlist request
Information involved: Email, role, optional interests, note, timestamp, consent record.
Typical legal basis in the EEA/UK: Consent, Article 6(1)(a); explicit consent, Article 9(2)(a), for health- or sex-life-revealing information.
Send the Amaranth Health updates you requested, including launch timing, early access, product-development questions, and surveys
Information involved: Email, role, communication preferences, limited segmentation based on an optional selection.
Typical legal basis: Consent, Article 6(1)(a); explicit consent, Article 9(2)(a), where segmentation uses sensitive interests.
Respond to your message or privacy request
Information involved: Email, message, verification information, request history.
Typical legal basis: Consent or steps taken at your request; legal obligation where a privacy law applies; legitimate interests in responding accurately.
Understand demand and improve the pre-launch plan
Information involved: Role, optional interests, note themes, aggregate counts.
Typical legal basis: Consent; explicit consent for sensitive information; legitimate interests only for truly anonymous statistics outside data-protection law.
Deliver, secure, debug, and protect the Site
Information involved: Request data, IP address, user-agent, error and anti-abuse signals, rate-limit data.
Typical legal basis: Legitimate interests, Article 6(1)(f), in providing a secure and functional Site; legal obligation where applicable.
Maintain unsubscribe and suppression choices
Information involved: Email address or a one-way hash/HMAC, unsubscribe date, communication status.
Typical legal basis: Legal obligation; legitimate interests in preventing unwanted email and proving compliance.
Keep consent and compliance records
Information involved: Policy version, consent text/version, timestamp, request and response history.
Typical legal basis: Legal obligation; legitimate interests in accountability and establishing, exercising, or defending legal claims.
Comply with law and protect rights, safety, and security
Information involved: Information strictly necessary for the request or incident.
Typical legal basis: Legal obligation, Article 6(1)(c); legitimate interests, Article 6(1)(f); vital interests only in a genuine emergency and where legally available.
Evaluate or complete an incorporation, financing, acquisition, reorganization, or transfer
Information involved: Relevant records subject to confidentiality and due diligence controls.
Typical legal basis: Legitimate interests in organizational continuity and a lawful transaction; consent if required for a materially new use.
Where we rely on legitimate interests, our interests are limited to operating a secure Site, answering requests, maintaining compliance, and protecting legal rights. We consider the sensitivity and limited context of the waitlist and do not rely on legitimate interests to override a required consent for sensitive-data collection or marketing.
7. Email and communication choices
7.1 What joining the waitlist requests
By voluntarily joining the waitlist through a form that clearly asks whether you want Amaranth Health updates, you request email about the pre-launch project, potential launch, early access, timelines, surveys, and questions we are exploring. We do not treat a message from one person as permission to email another person.
We do not send marketing text messages, automated calls, or prerecorded calls under this Policy. A phone number is not collected by the current form.
7.2 Discreet communications
Because the subject matter is sensitive, we aim to keep sender names, subject lines, and preview text reasonably discreet. Email itself is not a perfectly private medium. Anyone with access to your inbox, device, notification screen, employer system, or email provider may be able to see a message. Use an email account you control and review your device’s notification settings.
7.3 Unsubscribe
Every marketing email will provide an unsubscribe mechanism. We honor an unsubscribe promptly and no later than the period required by law. Unsubscribing stops marketing or waitlist-update messages but does not prevent a response to a privacy request, security notice, legal notice, or a message you specifically ask us to answer.
We may keep a minimal suppression record so that we do not accidentally add the address back to a marketing list. A suppression record is not used to continue marketing.
7.4 Consent records
We keep reasonable evidence of when, how, and for what purpose consent was obtained, including the form or policy version presented. This supports compliance with laws that require the sender to demonstrate consent, including laws applicable to recipients in Canada, the EEA, and the United Kingdom.
8. How we disclose information
We disclose information only as described below. A disclosure does not give the recipient permission to use information for unrelated advertising.
8.1 Founders and authorized personnel
The two founders may access waitlist records when needed to administer the list, read an optional note, respond, review aggregate interest, protect the Site, or handle a rights request. If authorized personnel are later added, access will be limited by role, need, confidentiality obligations, and this Policy.
8.2 Service Providers and processors
We use providers that process information for us under their service terms and, where available or required, data-processing terms. Current or planned categories are:
Vercel Inc.
Role: Website hosting, content delivery, request handling, security, logs, and cookieless web analytics if enabled.
Information it may process: Request data, IP address and headers, page and aggregate analytics data, and form traffic necessary to host and protect the Site.
Supabase, Inc. and/or its applicable contracting affiliate
Role: Hosted database and related infrastructure.
Information it may process: Waitlist fields, timestamps, consent records, communication status, and limited administrative metadata.
Resend / applicable email-delivery provider, if enabled
Role: Deliver waitlist confirmations and requested updates; process delivery, bounce, complaint, and unsubscribe events.
Information it may process: Email address, message content, delivery metadata, and communication status. We do not intentionally place sensitive device selections, diagnoses, or detailed notes in outbound email content.
Professional security, legal, compliance, accounting, or insurance advisers
Role: Advice, audits, incident response, legal compliance, or claims.
Information it may process: Only information reasonably necessary for the engagement, under duties of confidentiality or contractual restrictions.
We review provider configurations and contracts in light of the sensitivity of the information. A provider may use subprocessors to deliver its service, subject to its terms and data-processing commitments.
8.3 Affiliates
Amaranth Health has no separate corporate affiliates identified as of the Effective Date. If an affiliate is created and will receive Consumer Health Data, we will identify the affiliate or applicable category, explain the purpose, and obtain consent where required before the disclosure.
8.4 Legal process and protection of rights
We may preserve or disclose information if we reasonably believe disclosure is required by applicable law, a binding legal process, or a valid court or regulatory order; is necessary to establish, exercise, or defend legal claims; or is permitted and reasonably necessary to prevent fraud, abuse, a security incident, or an imminent risk of death or serious physical harm.
Given the sensitivity of the Site, we intend, where lawful and practicable, to:
- review a demand for legal sufficiency;
- seek to narrow an overbroad or disproportionate demand;
- disclose only information legally required;
- object or seek protective treatment where appropriate; and
- notify the affected person before disclosure unless prohibited by law, an emergency makes prior notice impracticable, or notice would compromise a lawful investigation.
These are good-faith process commitments, not a guarantee that every demand can be challenged or that notice will always be permitted.
8.5 Organizational changes and transactions
Information may be disclosed under confidentiality controls to evaluate or complete an incorporation, financing, merger, acquisition, restructuring, bankruptcy, sale of assets, or similar transaction. A successor that receives Personal Information must use it consistently with this Policy unless it provides advance notice and obtains any consent required for a materially different use. A change in ownership is not permission to use the waitlist for unrelated advertising.
8.6 At your direction
We may disclose information when you give a clear, specific direction or consent. We do not infer permission to contact a family member, clinician, or other person from the fact that you mentioned them in a note.
9. What we do not do
During the 12 months before the Effective Date, and as of the Effective Date:
- categories of Personal Information sold: none;
- categories of Personal Information shared for cross-context behavioral advertising: none;
- categories of Consumer Health Data sold: none;
- third parties receiving Personal Information for their own direct marketing: none;
- financial incentives or loyalty programs tied to Personal Information: none;
- targeted advertising based on waitlist information: none;
- automated decisions with legal or similarly significant effects: none; and
- data-broker enrichment or list rental: none.
We do disclose information to Service Providers for the business purposes described in Section 8.2. Those disclosures are limited to service delivery, security, analytics in the disclosed configuration, database hosting, email delivery, and compliance support.
10. Aggregate, de-identified, and anonymous information
We may create statistics such as the percentage of respondents who selected a role or optional product interest. Before treating information as de-identified or anonymous, we use measures appropriate to the context, such as removing direct identifiers, grouping results, suppressing very small cells, limiting access to source data, and prohibiting re-identification.
Where information remains reasonably linkable to a person, we continue to treat it as Personal Information. Where information is de-identified under applicable law, we commit to maintain it in de-identified form, not attempt to re-identify it except to test the effectiveness of de-identification where permitted, and require recipients to follow equivalent restrictions. Truly anonymous statistics may be retained and used indefinitely.
11. Retention and deletion schedule
We retain each category only as long as reasonably necessary for its disclosed purpose, security, legal compliance, and claims. The following schedule is our target and maximum unless a shorter period is required by law or a documented legal hold applies.
Active waitlist record
Until you withdraw, request deletion, or 24 months after your most recent affirmative interaction with Amaranth Health, whichever occurs first, unless you renew consent or a new product notice lawfully governs migration.
Optional free-text note
Reviewed for minimization and retained no longer than 12 months unless you ask us to keep an ongoing correspondence or a documented legal need applies; unnecessary medical or third-party details may be deleted sooner.
Email correspondence and survey replies
Up to 24 months after the conversation closes or your last interaction, unless needed for an active request, agreement, or legal matter.
Marketing delivery and preference data
While you are subscribed; delivery events are minimized according to provider settings; unsubscribe/suppression status is kept as needed to honor the choice.
Consent and policy-version records
While we rely on the consent and generally up to six years afterward where reasonably necessary to demonstrate compliance or address a claim, subject to applicable law.
Privacy-rights request records
Generally 24 months after closure, or longer if reasonably necessary to demonstrate compliance, resolve an appeal, or meet a legal requirement.
Rate-limit and anti-abuse data controlled by Amaranth
The shortest workable period, ordinarily no more than 30 days and often substantially less, unless associated with an active security incident.
Hosting and network logs controlled by a provider
According to the provider’s contracted retention and our available configuration; we seek to minimize retention and do not intentionally merge full IP logs with the waitlist record.
Aggregate or truly anonymous statistics
Indefinitely, because they no longer identify or reasonably link to you.
Backup copies
Removed or overwritten through the ordinary backup cycle. Where a verified Consumer Health Data deletion request applies, we target deletion from backups within six months or sooner and do not restore deleted data into active use except where necessary for security or disaster recovery, followed by re-deletion.
11.1 Migration at product launch
We will not silently convert a waitlist record into a product account, medical record, or conversation profile. Before migration to a launched product system, we will provide a fresh product notice and obtain any consent required for the new categories and purposes. If you do not take the requested action, we may leave the record on the waitlist until its retention period expires or delete it.
11.2 Legal holds and narrow exceptions
We may retain a limited record beyond the ordinary period when reasonably necessary to comply with law, preserve evidence, investigate security or fraud, enforce agreements, protect legal rights, or honor an unsubscribe. Information retained under an exception is restricted from unrelated use and deleted when the exception ends.
12. Security
We use administrative, technical, and organizational safeguards designed for a small pre-launch service handling sensitive interests. Measures described below must be understood as risk-reduction measures, not a promise of perfect security.
Our safeguards include, as applicable to the current configuration:
- encryption of Site traffic in transit using TLS;
- provider encryption of hosted database data and backups at rest;
- server-side handling of privileged database credentials, with secrets not intentionally exposed in browser code;
- row-level security or equivalent access controls and no public read access to waitlist records;
- server-side validation, input constraints, and rate limiting for form submissions;
- least-privilege access limited to the founders and authorized providers with a need to process the data;
- multi-factor authentication on administrative and provider accounts where available;
- unique accounts and strong password-manager-generated credentials;
- separation of production secrets from source code and public repositories;
- review of provider access, service keys, and administrative permissions;
- dependency, platform, and configuration updates;
- monitoring and response procedures for suspicious access, abuse, and provider notices;
- data minimization, short retention, and avoidance of unnecessary identifiers;
- contractual restrictions and data-processing terms with providers where available or required; and
- an incident-response process that includes containment, investigation, legal assessment, remediation, and required notices.
No internet transmission, email system, database, or security control is infallible. Do not submit information the form does not request. If you believe information submitted to Amaranth Health may have been accessed or used improperly, contact hello@amaranth.health promptly.
13. Security incidents and breach notification
If we become aware of a suspected incident, we will investigate its nature, scope, affected systems, categories of information, likely consequences, and available mitigation. We may engage providers, security specialists, insurers, and legal counsel under appropriate confidentiality protections.
Where notification is required, we will notify affected individuals and regulators without undue delay and within the period required by applicable law. Depending on the future service and information involved, relevant rules may include state breach-notification laws, the EU or UK GDPR, Washington or Nevada consumer health data obligations, and the Federal Trade Commission’s Health Breach Notification Rule for qualifying health apps, connected devices, or personal health records. A reference to a law does not mean that it necessarily applies to every incident or to the current waitlist.
We may delay a notice when a competent law-enforcement authority lawfully requires delay or when the facts are not yet sufficiently reliable, while still meeting applicable legal requirements.
14. International processing and transfers
The Site is operated from the United States. Our providers primarily process waitlist information in the United States, although provider support teams, corporate affiliates, or subprocessors may operate in other countries, including countries identified in the providers’ current subprocessor disclosures.
If information protected by the EEA GDPR, UK GDPR, or Swiss data-protection law is transferred to a country not recognized as providing adequate protection, we use an available lawful safeguard as required, such as:
- the European Commission’s Standard Contractual Clauses;
- the UK International Data Transfer Addendum or another UK-approved mechanism;
- a Swiss transfer addendum;
- an applicable adequacy decision;
- an applicable provider certification under the EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. Data Privacy Framework; or
- another mechanism permitted by applicable law.
Transfer mechanisms and provider certifications can change. We review the mechanism available for the relevant provider and may adopt supplementary safeguards appropriate to the limited waitlist data. You may request information about the applicable safeguard by contacting hello@amaranth.health. We may redact confidential commercial or security terms from a copy where law permits.
15. Your privacy rights — offered to everyone
Subject to verification, legal exceptions, and the nature of the record, Amaranth Health offers the following core choices to everyone on the waitlist, regardless of location:
- Access and confirmation. Ask whether we process information about you and receive a copy of the information we can reasonably link to you.
- Correction. Ask us to correct inaccurate or incomplete information.
- Deletion. Ask us to delete information, subject to narrow legal and security exceptions.
- Portability. Ask for information you provided in a structured, commonly used, machine-readable format where applicable.
- Withdraw consent. Withdraw consent for future collection, use, or email at any time. Withdrawal does not make earlier lawful processing unlawful.
- Object or restrict. Object to or request restriction of processing where applicable law provides that right.
- Know disclosures. Ask for categories of recipients and, for Consumer Health Data where required, the relevant third parties or affiliates to whom it was disclosed.
- Opt out of sale, targeted advertising, and significant profiling. We do not conduct these activities, but we will treat a valid request or recognized preference signal as an opt-out where applicable.
- Appeal. Appeal a denial of a rights request where applicable law provides an appeal.
- Non-discrimination. Receive no unlawful discrimination, retaliation, or materially different treatment for exercising a right or declining an optional sensitive field.
- Complaint. Contact an applicable supervisory authority, privacy regulator, or state Attorney General.
15.1 How to submit a request
Email hello@amaranth.health with a clear subject such as “Privacy Request”, “Consumer Health Data Request”, or “Privacy Appeal.” State the right you want to exercise and the email address used for the waitlist.
You may also write to the mailing address in Section 1 after it is completed.
15.2 Verification
For a waitlist record, our primary verification method is a confirmation sent to the email address in the record. If you write from a different address, we may ask you to confirm from the registered address or provide limited additional information reasonably necessary to match the record. We do not request a government ID for a simple waitlist request unless it is reasonably necessary, proportionate, and permitted by law.
We will not use verification information for another purpose and will not keep it longer than necessary for verification and compliance.
15.3 Timing
We aim to:
- acknowledge a request within seven calendar days;
- complete an authenticated deletion request within 30 days where feasible;
- complete other authenticated requests within 30 days where feasible; and
- never exceed the applicable statutory period without a legally permitted extension and timely notice.
Applicable laws may provide different periods, such as one month under the GDPR, up to 45 days under many U.S. state laws, 30 days for certain Nevada Consumer Health Data deletions, and an additional period for complex requests where permitted. Authentication does not excuse an avoidable delay.
15.4 Fees and repetitive requests
Requests are ordinarily free. Where law permits, we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, or repetitive. We bear the burden of justifying that decision and will explain the basis and available appeal.
15.5 Authorized agents
Where applicable law permits an authorized agent, the agent may submit a request with evidence of authority. We may still confirm the request directly with you or require proof of a valid power of attorney where permitted. An agent cannot expand the rights available to the consumer.
15.6 Appeals
If we deny all or part of a request, our response will explain the reason and how to appeal. To appeal, reply to the decision or email hello@amaranth.health with the subject “Privacy Appeal” within 60 days. We will respond within the period required by applicable law and ordinarily within 45 days. If an appeal is denied, we will identify the relevant regulator or complaint mechanism where required.
15.7 Deletion effects and exceptions
Deletion removes or de-identifies the information from active systems and directs applicable processors to do the same. Backup deletion follows Section 11. We may retain a minimal record to prove that a request was completed, preserve legal rights, investigate security, comply with law, or maintain an unsubscribe. Retained exception data is not used for marketing or product-interest analysis.
16. Consumer Health Data Privacy Notice for Washington and Nevada
This Section is intended to serve as Amaranth Health’s Consumer Health Data Privacy Notice under Washington’s My Health My Data Act and Nevada’s consumer health data law, to the extent either law applies. It supplements the rest of this Policy.
16.1 Categories of Consumer Health Data collected
We may collect:
- the fact that a person joined or attempted to join an intimate-health waitlist;
- the role or relationship selected in connection with the waitlist;
- optional interest in an intimate-health service, AI companion, device, or planned feature;
- health-, sex-life-, caregiving-, or age-related information voluntarily included in a note or communication;
- consent, withdrawal, and request records tied to the waitlist; and
- an inference that a person may be interested in intimate or sexual health information, services, or products.
We do not intentionally collect precise location, biometric identifiers, genetic data, medical records, diagnoses, prescriptions, or laboratory results through the current waitlist.
16.2 Sources
Sources are you directly; your browser and network for technical request data; and our processors for service-generated delivery, security, unsubscribe, and aggregate analytics events. We do not collect Consumer Health Data from data brokers, family members, clinicians, insurers, employers, or advertising networks.
16.3 Purposes and manner of processing
We collect and process Consumer Health Data only to:
- receive and administer your voluntary waitlist request;
- send the Amaranth Health updates you requested;
- respond to your note, question, or rights request;
- understand demand and feedback in aggregate;
- secure, debug, and protect the Site;
- honor withdrawal, deletion, and unsubscribe choices;
- comply with law and establish, exercise, or defend legal claims; and
- conduct a lawful organizational transition subject to Section 8.5.
Processing includes receipt, validation, encrypted transmission, storage in a restricted database, limited review by the founders, email delivery through a processor, aggregation, rights-request handling, and deletion.
16.4 Categories of Consumer Health Data shared
We do not share Consumer Health Data with an independent third party for that party’s advertising or unrelated use. Contractually restricted processors may process the categories necessary to provide hosting, database, security, email, and professional services as described in Section 8.2.
16.5 Categories of third parties and specific affiliates
- Independent advertising, data-broker, insurance, employer, credit, or marketing recipients: none.
- Corporate affiliates receiving Consumer Health Data: none as of the Effective Date.
- Processors: website-hosting and security provider; hosted-database provider; email-delivery provider if enabled; and professional advisers where necessary and subject to confidentiality.
16.6 Consent and withdrawal
We seek affirmative consent before collecting Consumer Health Data for the specified waitlist purposes. A consent to disclose Consumer Health Data to a recipient for an independent purpose would be separate from collection consent where required. You may withdraw consent for future collection or sharing by emailing hello@amaranth.health. Withdrawal may require us to remove you from the waitlist because the waitlist itself reveals the sensitive interest.
16.7 Rights
You may ask to confirm collection, access Consumer Health Data, obtain disclosure information required by law, withdraw consent, correct information where available, and delete Consumer Health Data. We will propagate a verified deletion request to applicable processors, contractors, and other recipients as required. We will not unlawfully discriminate against you for exercising a right.
Washington requests are handled without undue delay and within applicable statutory periods. Consumer Health Data in Washington backups will be deleted within the legally permitted backup period, targeted at no more than six months. Nevada Consumer Health Data deletion from active records is targeted within 30 days after authentication; any backup delay is limited by applicable law and our shorter operational target where feasible.
16.8 Appeal and complaints
Use the appeal process in Section 15.6. Washington residents may contact the Washington State Attorney General; Nevada residents may contact the Nevada Attorney General. We will provide the appropriate complaint mechanism in an appeal denial where required.
16.9 No sale and no geofence
We do not sell Consumer Health Data, seek a sale authorization, or use prohibited health-care geofencing.
17. California privacy disclosures and Notice at Collection
This Section applies to California residents to the extent the California Consumer Privacy Act, as amended, applies. We voluntarily provide the core rights in Section 15 even if Amaranth Health does not meet a statutory applicability threshold.
17.1 Categories collected or disclosed in the preceding 12 months
Identifiers
Examples: Email address, IP address in request logs.
Collected: Yes · Disclosed for a business purpose to Service Providers: Yes, as necessary · Sold or shared for cross-context advertising: No.
Customer-record information
Examples: Email and communications linked to the waitlist.
Collected: Yes · Disclosed to Service Providers: Yes, as necessary · Sold or shared: No.
Internet or electronic network activity
Examples: Page request, browser or device category, referral, aggregate page interaction.
Collected: Yes, limited · Disclosed to Service Providers: Yes, as necessary · Sold or shared: No.
Professional or employment-related information
Examples: A voluntary role such as clinician, researcher, builder, or investor.
Collected: If selected · Disclosed to Service Providers: Yes, as necessary · Sold or shared: No.
Inferences
Examples: Inference of interest in intimate-health information, services, or devices.
Collected: Yes · Disclosed to Service Providers: Yes, as necessary to host or administer · Sold or shared: No.
Sensitive Personal Information
Examples: Information that reveals or may reveal health, sex life, or sexual orientation; account-access credentials are not collected.
Collected: Yes, by consent or voluntary submission · Disclosed to Service Providers: Yes, as necessary to processors · Sold or shared: No.
Other information you submit
Examples: Optional note, survey answer, or message.
Collected: If submitted · Disclosed to Service Providers: Yes, as necessary · Sold or shared: No.
17.2 Purposes, sources, recipients, and retention
Purposes are in Section 6; sources are in Section 4.6; recipients are in Section 8; and category-specific retention is in Section 11. We do not collect, use, retain, or disclose more Personal Information than reasonably necessary and proportionate to the disclosed purposes.
17.3 California rights
To the extent applicable, California residents may request access to categories and specific pieces, correction, deletion, and portability; may opt out of sale or sharing; may limit certain uses of Sensitive Personal Information; and may not receive discriminatory treatment for exercising rights. We do not sell or share for cross-context behavioral advertising and do not use or disclose Sensitive Personal Information for purposes that require a “Limit the Use of My Sensitive Personal Information” link under current law.
We honor legally recognized opt-out preference signals such as Global Privacy Control where applicable. Because we do not sell or share, honoring the signal ordinarily confirms our existing practice.
17.4 No financial incentive
We do not offer a financial incentive, price difference, or loyalty program in exchange for Personal Information.
18. EEA, United Kingdom, and Switzerland
If the GDPR, UK GDPR, or Swiss data-protection law applies:
- the controller information is in Section 1;
- processing purposes and legal bases are in Section 6;
- categories and recipients are in Sections 4 and 8;
- retention is in Section 11;
- international safeguards are in Section 14; and
- rights and request methods are in Section 15.
You may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Where processing is based on consent, you may withdraw it at any time for the future. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; we do not conduct that processing for the waitlist.
You may complain to the supervisory authority in the country where you live or work or where an alleged infringement occurred. In the United Kingdom, the authority is the Information Commissioner’s Office. In Switzerland, it is the Federal Data Protection and Information Commissioner. We would appreciate the opportunity to address a concern directly, but contacting us first is not a condition of your right to complain.
19. Canada
If Canadian privacy or anti-spam law applies, we use consent appropriate to the sensitivity and purpose, maintain reasonable safeguards, and provide access and correction subject to lawful exceptions. Commercial electronic messages are sent only with a valid basis, identify the sender, provide required contact information, and include a working unsubscribe mechanism. We retain evidence of consent and honor withdrawal.
You may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy authority. Contact hello@amaranth.health first if you would like us to investigate and respond directly.
20. Other U.S. states and jurisdictions
Residents of jurisdictions with applicable comprehensive privacy laws may have rights to access, correct, delete, or obtain a portable copy of Personal Information and to opt out of sale, targeted advertising, or significant profiling. Some laws provide an appeal. We apply the universal process in Section 15 and the more protective requirement when applicable law differs.
Nothing in this Policy limits a mandatory consumer right, remedy, or regulator authority that cannot lawfully be limited.
21. HIPAA and clinical information
Amaranth Health is not currently representing that the waitlist is operated by a HIPAA covered health-care provider, health plan, health-care clearinghouse, or business associate. Information submitted directly to a consumer health website is not automatically protected health information under HIPAA merely because it relates to health.
That is one reason we apply the protections in this Policy and ask you not to submit medical records or detailed clinical information. The waitlist is not a patient portal, does not establish care, and should not be used by a clinician or organization to send protected health information. If Amaranth Health later acts for a covered entity or launches a regulated clinical service, it will assess HIPAA status, enter any required business associate agreements, and provide appropriate notices before receiving protected health information in that capacity.
22. Adults only
The Site and waitlist are intended for adults 18 years of age or older. They are not directed to children, and we do not knowingly collect Personal Information from a person under 18 through the waitlist.
If you believe a person under 18 submitted information, contact hello@amaranth.health. We may take reasonable steps to verify the report and will delete the record promptly where appropriate. A parent or caregiver should not submit a child’s health information through the note field.
23. Family members, caregivers, clinicians, and third-party information
You may join because you care about another adult, but join using your own email and describe your own interest. Do not provide another person’s email, name, diagnosis, sexual history, or other private information unless you have lawful authority and the disclosure is necessary. The waitlist does not authorize us to contact that person, disclose your interest to them, or treat you as their representative.
Clinicians and researchers must not submit patient information or protected health information. Organizations interested in a pilot or research relationship should contact us without patient-level data so that appropriate contracts, ethics review, consent, and security can be considered first.
24. Third-party links
The Site may link to public-health sources, research, surveys, or other websites. Following a link sends a request to the third party, which may collect IP address, browser data, and any information you submit there. We do not control the third party’s security, cookies, accessibility, accuracy, or privacy practices. Review its policy before providing information.
A link is not an endorsement, clinical referral, or representation that the third party is appropriate for your circumstances.
25. Do Not Track and Global Privacy Control
Some browsers send “Do Not Track” signals, but there is no universally accepted technical standard for responding. Our default configuration does not conduct cross-site tracking, so there is no behavioral-tracking profile to disable.
We recognize Global Privacy Control and other legally recognized opt-out preference signals where applicable. Because we do not sell or share Personal Information for cross-context behavioral advertising, the signal generally confirms our existing practice.
26. Changes to this Policy
We may update this Policy to reflect changes in law, providers, security practices, the waitlist, or the responsible entity. When we update it, we will:
- change the “Last updated” date;
- maintain a short change log below;
- post the current version at the same or a clearly linked location; and
- provide additional notice, and request renewed consent, before a material new use or disclosure applies to sensitive information already collected where law or our commitments require it.
Changes ordinarily apply prospectively. We will not use an update to retroactively authorize a sale, advertising disclosure, or materially incompatible use of Consumer Health Data without the authorization or consent required at that time.
Change log
- July 29, 2026: Initial full website and waitlist Privacy Policy.
27. Contact
For questions, privacy requests, consent withdrawal, deletion, complaints, or appeals:
Email: hello@amaranth.health