Skip to main content
Everyday Works — practical apps, planners and printables

Consumer Health Data Privacy Notice

Effective date: August 25, 2026

This Consumer Health Data Privacy Notice supplements the Everyday Works Privacy Policy. It applies to “consumer health data” as defined by applicable consumer health privacy laws, including Washington’s My Health My Data Act, when Everyday Works controls that data. Consumer health data generally includes personal information that identifies or can reasonably be linked to a consumer and identifies the consumer’s past, present, or future physical or mental health status.

This Notice is especially relevant to Moody Meals and Forget Me Not. Those apps are personal organization tools, not health-care providers. Everyday Works is generally not a HIPAA-covered entity, and consumer app information should not be assumed to be protected by HIPAA. Other privacy, consumer-protection, security, and breach-notification laws may still apply.

1. Categories of consumer health data we may collect

Depending on the app, platform, version, feature, and information you choose to provide, the categories may include:

Food, nutrition, mood, and wellness entries

  • foods, meals, drinks, timing, portions, notes, or dietary choices;
  • moods, emotions, energy, mental clarity, symptoms, reactions, and observations;
  • patterns, correlations, goals, preferences, or inferences generated from the entries; and
  • questions or notes prepared for discussion with a professional.

Medical and care-organization entries

  • medical history, conditions, allergies, intolerances, medications, supplements, doses, schedules, procedures, and side effects;
  • health-care providers, pharmacies, emergency contacts, appointments, care notes, questions, and instructions entered by the user;
  • insurance, benefit, claim, or coverage information connected to health care;
  • photographs, documents, identifiers, or other user content that reveals health information; and
  • information about a family member or person in the user’s care when the user chooses to enter it.

Health-linked account and technical information

  • name, email, account or user identifier, device or app identifier, and authentication information linked to health entries;
  • purchase or subscription status needed to provide a health-related feature;
  • location information when a user enables a relevant location feature and the location can reveal or be linked to health status or care; and
  • app-use, support, diagnostic, or security information when it reveals use of a health-related feature or is linked to health entries.

We do not intentionally collect genetic sequence data, biometric identity templates, precise measurements from a medical device, or information from an electronic health record unless a clearly disclosed future feature requests it. We will update this Notice and obtain consent first if a new category or purpose requires consent.

2. Sources of consumer health data

We may obtain consumer health data from:

  • you, when you type, select, upload, import, photograph, or otherwise provide it;
  • your device, but only through a feature and permission you choose to enable;
  • another user who is authorized to share family or caregiver information with you or enter information on your behalf;
  • a service provider that stores, synchronizes, authenticates, or supports the feature; and
  • a third-party integration you deliberately connect, if a future feature clearly identifies the integration before connection.

Some information may remain only on your device, while account, synchronization, backup, purchase, support, and shared-feature data may be transmitted. Forget Me Not stores medical records through a MongoDB-backed service, may store uploaded documents in configured AWS S3 or local file storage, and may send user-selected prescription images or medication names to Google Gemini through an Emergent-managed integration when you invoke OCR, text-extraction, or medication-interaction assistance. Moody Meals uses account and cloud services for meal, mood, health, subscription, and related app data. Exact behavior depends on the released version, selected feature, and production configuration.

3. Why we collect and use consumer health data

We collect and use consumer health data only as reasonably necessary to:

  • provide the feature you request, such as saving, displaying, organizing, searching, synchronizing, exporting, or sharing entries;
  • generate user-requested summaries, patterns, reminders, or organizational views;
  • maintain an account and recognize access to subscription features;
  • respond to support, correction, access, consent-withdrawal, or deletion requests;
  • secure the apps, detect abuse, troubleshoot errors, and maintain reliability;
  • comply with law and protect the rights, safety, and integrity of users and the Services; and
  • carry out another purpose clearly disclosed at collection with any consent required by law.

Everyday Works does not use consumer health data to make decisions about eligibility for employment, housing, credit, insurance, education, or another essential service. We do not use consumer health data for targeted advertising or create advertising profiles from health entries.

4. Categories of consumer health data we share

“Share” can have a special legal meaning and may include making data available to a third party other than as a processor performing services for us. Everyday Works does not sell consumer health data. We do not share consumer health data for targeted advertising.

We may disclose or make consumer health data available in these limited circumstances:

  • User-directed sharing. The data and fields you select may be provided to a family member, caregiver, professional, travel companion, or other recipient you choose. The recipient controls copies they save.
  • Feature processors. Depending on the released app and selected feature, Amazon Web Services, MongoDB, hosting providers, authentication services, or storage services may process consumer health data needed to provide the requested function. When a user deliberately invokes an applicable Forget Me Not prescription OCR/text-extraction or medication-interaction feature, Google Gemini through an Emergent-managed integration may process the prescription image or medication name needed to return the requested result.
  • Support and security processors. A support, logging, or security provider may process limited health-linked information when necessary to resolve a user-requested issue, investigate an incident, or protect the Service. We limit access to what is reasonably necessary.
  • Legal and safety disclosures. We may disclose information when required by law or valid legal process, or when reasonably necessary to protect rights or safety, investigate unlawful activity, or establish or defend a legal claim.
  • Business transaction. Information may be reviewed or transferred in a merger, financing, reorganization, sale, or similar transaction, subject to applicable consent, authorization, notice, and contractual requirements.

Apple, Google, and RevenueCat process purchase, platform, account, or entitlement information for app subscriptions. They are not intended to receive the substance of meal, mood, medical-history, medication, or care entries through subscription processing. A separate, user-invoked Forget Me Not AI-assisted feature may send the limited health content described above to its feature processor.

5. Categories of third parties and specific affiliates

The categories of third parties that may receive consumer health data are:

  • a person or service you direct us to share with;
  • cloud hosting, database, storage, authentication, support, security, and user-requested AI-assisted feature processors used to provide the selected function;
  • professional advisers and authorities when a legally permitted disclosure is necessary; and
  • a buyer, successor, or transaction adviser subject to appropriate confidentiality and applicable legal requirements.

Specific corporate affiliates that receive consumer health data: none as of the effective date of this Notice. Everyday Works is currently described in this Notice as a brand operated by Sadie Gordon, not as a group of affiliated companies. If that structure or sharing changes, we will update this Notice and obtain consent or authorization when required before sharing.

If you request access under an applicable law, we will provide the additional details required by that law, which may include a list of third parties and affiliates with whom your consumer health data was shared and an active contact mechanism for them.

6. Sale of consumer health data

Everyday Works does not sell consumer health data. We will not begin selling it without first updating this Notice and obtaining a separate, valid authorization that meets applicable legal requirements. Consent to use an app is not consent to a sale.

7. Your consumer health data rights

Subject to applicable law and limited exceptions, you may have the right to:

  • confirm whether Everyday Works is collecting, sharing, or selling consumer health data about you;
  • access that data and receive required information about recipients;
  • withdraw consent to future collection or sharing;
  • request deletion of consumer health data; and
  • appeal a refusal or limitation of your request.

Submit a request through https://everydayworkstoday.com/contact and write “Consumer Health Data Request.” Identify the app and account email or identifier, describe the right you want to exercise, and use a secure method if we ask for additional information. Do not place detailed health entries or passwords in the first message.

We may take commercially reasonable steps to authenticate you and protect the account. You do not have to create a new account. An authorized agent may act where law permits, subject to proof of authority and identity verification.

We provide responses free of charge to the extent required by law. Manifestly unfounded, excessive, or repetitive requests may be handled as the law allows. We do not discriminate against you for exercising a right.

Timing

For requests covered by Washington’s consumer health data law, we act without undue delay and within 45 days of receiving the request. We may extend the period once by up to 45 additional days when reasonably necessary based on complexity or volume, provided we notify you during the initial period and explain the reason.

Deletion and processors

When a valid deletion request applies, we delete the covered data from systems within our control and notify affiliates, processors, contractors, and other third parties as required so they can honor the request. Permitted deletion from archived or backup systems may be delayed until restoration or the normal deletion process, but for Washington-covered data the delay will not exceed six months after authentication.

Deletion does not require a third party to delete information it received directly from you outside the Everyday Works Services, and it cannot retrieve copies you independently exported, printed, or gave to another person. Limited information may be retained when an applicable exception permits it, such as to protect security, comply with law, or document the request.

Appeals

If we deny or limit a request, we will explain the reason and how to appeal where required. Submit an appeal through the same contact form with “Consumer Health Data Appeal.” We will respond within the period required by law. If an appeal is denied, we will identify any regulator or attorney-general complaint process that applicable law requires us to provide.

8. Consent and withdrawal

Where law requires consent, we request a clear affirmative action before collecting or sharing consumer health data for the disclosed purpose. Consent for collection is separate from any authorization required for sale, and Everyday Works does not sell this data.

You may withdraw consent through available app controls or the contact process above. Withdrawal applies prospectively and may make a feature unavailable if the data is necessary to provide it. Withdrawal does not affect processing that was lawful before withdrawal or retention that the law permits.

We will not collect, use, or share an additional category of consumer health data, or use existing data for a materially new purpose, without first updating the disclosure and obtaining affirmative consent when required.

9. Retention

We retain consumer health data only as long as reasonably necessary to provide the chosen feature and for permitted security, support, legal, or request-documentation purposes. Account content may remain while the account is active and until deletion is completed. Retention can differ when information stays only on a device, is synchronized to a cloud feature, appears in a support request, or is included in a protected backup.

We aim to minimize retention and access. Data that has been deidentified so it cannot reasonably be linked to you may be retained for reliability or aggregate analysis, subject to legal limits and commitments not to reidentify it.

10. Security and breach response

We use safeguards appropriate to the sensitivity of consumer health data and the size and nature of the Services, which may include access controls, authentication, encryption where supported, secure transmission, vendor restrictions, monitoring, backups, and incident procedures. No safeguard is perfect. Protect your device and account, limit shared access, and keep a separate secure copy of urgent information.

If a security incident affects consumer health data, we investigate and provide notices required by applicable law. The Federal Trade Commission’s Health Breach Notification Rule may require notice to affected people, the FTC, and in some cases the media for certain breaches of unsecured individually identifiable health information.

11. Geofencing and health facilities

Everyday Works does not use a geofence around an entity that provides in-person health-care services to identify, track, collect data from, or send messages or advertising to a person based on that person’s presence at the location.

12. Children and information about others

Children under 13 may not independently create an Everyday Works account or directly submit consumer health data to Everyday Works. An adult may choose to organize information about a child, family member, or person in the adult’s care only when the adult has appropriate authority or permission. Enter only what is reasonably necessary and share it only with people who need it.

13. Changes to this Notice

We may update this Notice to reflect changes in features, vendors, law, or data practices. The revised Notice will show a new effective date. We will provide additional notice and obtain consent or authorization before a change when required by law.

14. Contact

Everyday Works is operated by Sadie Gordon in Utah, United States. For a consumer health data question, request, or appeal, use the secure contact form at https://everydayworkstoday.com/contact and identify the app involved. Do not use the form for a medical or safety emergency.

We use necessary technologies to run the site (security, checkout, downloads, and remembering this choice). With your permission we also use optional analytics (Google Analytics and PostHog) to understand how the site is used. We never use advertising trackers. Read our Cookie Policy.