Legal
A standalone explanation of how Menthra collects, uses, shares, and protects consumer health data — separate from our general Privacy Policy and our HIPAA Notice — written to meet Washington, Nevada, and comparable state requirements.
In plain English
Menthra collects mental-wellness conversation data, mood signals, and similar information that qualifies as consumer health data under Washington (MHMDA) and Nevada (NHDPA) law. We do not sell consumer health data. We do not share it with advertisers. We do not use it to train foundation AI models. You can access, delete, withdraw consent, and appeal — at any time, from one place, without contacting support. This notice tells you exactly how.
This Consumer Health Data Privacy Notice explains how Menthra Inc. ("Menthra," "we") collects, uses, shares, and protects information that qualifies as consumer health data under laws including:
Consumer health data under these laws is broader than "Protected Health Information" under HIPAA. It includes information that identifies your past, present, or future physical or mental health status — including information you provide to an AI wellness companion, mood signals you log, and inferences derived from those interactions — regardless of whether Menthra is acting as a HIPAA-covered entity at the time.
This notice is in addition to, and does not replace:
Where this notice and the Privacy Policy describe overlapping practices, the protections in this notice apply to consumer health data specifically.
The categories of consumer health data Menthra may collect include:
We do not purchase consumer health data from data brokers, marketing lists, or third-party advertising networks.
We use consumer health data only for the purposes you would reasonably expect from a wellness companion platform, and only as described below:
To be explicit, Menthra does not:
If we ever propose a use of consumer health data that falls outside the categories above, we will obtain your specific, separate, prior consent — and for sales of consumer health data, the signed authorization MHMDA § 7 and NHDPA equivalent require. Standing consent to this notice is not sufficient for any of those uses.
We share consumer health data only with the following categories of recipients, only as needed, and only under written agreements that bind them to the same protections in this notice:
Under MHMDA, NHDPA, and comparable laws, you have the following rights with respect to your consumer health data. You can exercise every right below from your account, without contacting support. If you do not have an account, see Section 8 for how to request access.
Request a copy of the consumer health data Menthra holds about you, including categories collected, sources, recipients with whom it has been shared, and the purposes for which it has been used.
Request deletion of your consumer health data. We honor deletion requests within the statutory timeframe (no later than 30 days for MHMDA; sooner where possible). We will also direct any service provider that received the data on our behalf to delete it. Note that records we are legally required to retain (for example, records of a crisis intervention, or records subject to a litigation hold) may be retained for the minimum period required by law and remain protected under this notice.
Withdraw any consent you have previously given for the collection or sharing of your consumer health data, with prospective effect. Withdrawal is as easy as the original opt-in and is available from your account at any time. Withdrawing consent does not invalidate processing carried out lawfully before the withdrawal.
We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a right under this notice. The only exception is where consumer health data is reasonably necessary to deliver the feature you are requesting — for example, you cannot have an AI Companion conversation while simultaneously refusing the collection of that conversation as consumer health data. Where that necessary relationship exists, we will explain it transparently before you act.
If we decline a rights request, you may appeal in writing to privacy@menthra.ai. We will respond within 45 days with our reasoning and, if our decision stands, your options for further escalation, including to your state Attorney General.
Consumer health data is encrypted at rest and in transit. Our broader security posture is documented in our Security overview.
Staff access to consumer health data is governed by a documented internal policy with role-based controls, trigger requirements, immutable access logging retained for at least seven years, quarterly cross-officer review, and explicit prohibitions on uses such as model training, demos, or external AI tools. No Menthra staff member has standing access to consumer health data; every read requires a specific documented trigger and a reason code. Emergency ("break-glass") access is permitted only for active life-safety situations and is reviewed within 24 hours.
Menthra maintains demonstrable role-based access controls over user content, as required by the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Act, and similar consumer health data laws. The full Staff Access to User Content Policy — including the role-based access matrix, the trigger list that justifies access, the access logging requirement, the break-glass procedure for emergencies, and the absolute limits binding every Menthra staff member — is published at menthra.ai/downloads/staff-access-to-user-content.md.
We retain consumer health data only as long as needed to provide the service, comply with our legal obligations (including duty of care for crisis events), and resolve disputes. When the retention purpose is satisfied, we delete or de-identify the data per our retention schedule.
If a breach of consumer health data occurs, we will notify affected individuals and applicable regulators within the timeframes required by law — including the 60-day requirement under MHMDA and equivalent timelines under NHDPA and HIPAA where applicable.
If you believe Menthra holds consumer health data about you and you do not have an account from which to exercise rights, write to privacy@menthra.ai with enough information for us to identify you (typically: name, email associated with any prior account, and a description of when you used Menthra). We may need to verify your identity before acting on a request.
A note about crisis
Crisis intervention is the one area where rights to withdraw or delete can be limited — not because we devalue your privacy, but because abandoning a person in active crisis violates a stronger obligation. Where this trade-off applies, we will tell you transparently, retain only the minimum data needed for the duty of care, and resume the standard rights as soon as the crisis is resolved.
Crisis resources at menthra.ai/crisis are always available with no account, no login, and no data collection beyond what is technically necessary to deliver the page.
Material changes to this notice are recorded in our Legal Changelog and, where they affect the rights described above, communicated to you directly. The current version is shown at the top of this page.
Contact