Skip to content
Prime Years
HomeTreatmentsFAQMember login
Privacy

Privacy Policy.

This policy explains what health information Prime Years Medical collects, what we do with it, who else can see it, and the choices you have. It covers our website, our member app, and the data you choose to share with us from a connected device such as a WHOOP band.

Effective August 20, 2026  ·  Last updated August 20, 2026  ·  Version 2.0

Washington, Nevada and Connecticut residents: see our separate Consumer Health Data Privacy Policy →

On this page

  1. Notice at collection
  2. The short version
  3. Who this policy covers
  4. What we collect
  5. Where it comes from
  6. Connected devices and wearables
  7. How we use your information
  8. How we use artificial intelligence
  9. Who we share information with
  10. Selling your information
  11. Other sites and services
  12. How long we keep information
  13. How we protect information
  14. Where your information is processed
  15. Your rights and choices
  16. State privacy rights notice
  17. Cookies and tracking
  18. Children
  19. If there is a breach
  20. Changes to this policy
  21. How to reach us

1. Notice at collection

This box is the summary several state laws require us to give you at or before the moment we collect anything. The rest of the page is the detail.

The question the law asksOur answer
What do you collect?Account and contact details, health intake answers, clinical records and lab results, readings from a device you connect, information we derive from all of that, order and payment details, your messages to us, and technical information about your visit. Section 4 lists it in full
Is any of it sensitive?Yes. Health information, biometric and health-adjacent measurements, information about sex, and account credentials are all sensitive categories under state law
Why do you collect it?To provide and deliver your care, to show you your own results, to take payment, to keep the platform secure, and to meet legal obligations. Section 7 lists every purpose
Do you sell it or share it for advertising?Not today. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use health information for advertising. We are not promising never to sell data — Section 10 says exactly what would have to happen first, and your separate signed permission is part of it
Do you use it to profile me or make automated decisions?We compute health analytics from your data and show them to you and your clinician. We do not use automated decisionmaking to decide whether you get care, what you are charged, or whether a request is denied. A licensed clinician decides anything clinical. Section 8
How long do you keep it?For as long as clinical record-retention law requires, which is commonly six to ten years after your last visit, and longer for records of care given to a minor. Section 12 sets out the criteria
What are my rights, and how do I use them?Access, correct, delete, take a copy, appeal a refusal, and limit the use of sensitive information. Email privacy@primeyearsmedical.com. Sections 15 and 16

2. The short version

Your health information belongs to you. We hold it so that you and your care team can use it, and for no other reason.

We do not sell it, and we do not use it for advertising. We do not use your record to train anyone’s artificial intelligence models, including our own.

We are not promising never to sell data, because we would rather not make a promise we might one day want to change. What we will say is this: nothing that identifies you is sold without your separate, signed permission, and saying no changes nothing about your care. Section 10 sets out the whole position.

The rest of this page says the same thing in full. In brief:

  • We collect what care needs. Your account details, the answers you give in your health intake, your lab results, what you order, and — only if you connect one — readings from your wearable device.
  • We use artificial intelligence, and we tell you where. AI helps explain your results and shows you what is worth raising with your clinician. It never diagnoses you, never prescribes, never places an order, and never makes a decision about your care on its own. A licensed clinician decides anything clinical. Section 8 sets this out in full.
  • Your information stays inside a protected boundary. It is stored encrypted in the United States, and we do not send it to any company that has not signed a written agreement to protect it to the same standard. Data from which you cannot be identified is treated differently, and section 10 explains how.
  • You can see it, correct it, take it with you, and ask us to delete it. You can have a device disconnected at any time. You can ask to speak to a human being at any time. Sections 15 and 16 explain how.

Your use of this site is also governed by our Terms of Use. Where the two documents disagree about how we handle your personal information, this Privacy Policy controls.

3. Who this policy covers

Prime Years Medical (“Prime Years”, “we”, “us”) operates this website and the member app. Medical care is provided by licensed clinicians working through our affiliated professional entity and our clinician network. Prescriptions are written by those clinicians, not by Prime Years and not by any software we run.

Those clinicians are covered by the federal health privacy law known as HIPAA. Prime Years handles your health information on their behalf, under a written agreement that requires us to protect it the way HIPAA requires them to. The clinicians who treat you will also give you their own Notice of Privacy Practices, which is a separate document describing your rights under HIPAA. This policy does not replace it.

Some of the information we hold is not covered by HIPAA — for example, the readings from a fitness wearable before a clinician uses them, or the details you give us before you ever have a visit. We apply the same protections to all of it. We treat the whole record as health information, whichever law happens to reach a given field.

This policy applies to people in the United States. Prime Years does not offer services outside the United States, and it does not direct its services to the European Economic Area or the United Kingdom.

4. What we collect

Almost everything we hold, you gave us on purpose: you typed it into a form, uploaded it, bought something, or connected a device.

CategoryExamplesWhere it comes from
Account and contact detailsName, email address, phone number, date of birth, the state you live in, sign-in credentials, and how you prefer to be contactedYou, when you join the waitlist, create an account, or update your profile
Health intakeYour goals, sex assigned at birth, height and weight, conditions, medications, allergies, surgeries, family history, sleep, exercise, diet, alcohol and smoking, stress, symptoms and how long you have had them, and anything you write in a free-text boxYou, in the intake questionnaire
Clinical recordsLab results and reference ranges, documents you upload, visit outcomes, prescriptions written for you, clinician notes, follow-up plansYou, our clinician network, and the laboratories that run your tests
Device and wearable readingsSleep, recovery, heart rate, heart rate variability, respiratory rate, oxygen saturation, steps, workouts, body measurementsOnly from a device you connect yourself. See section 6
Information the platform derivesYour Prime ranges, trends over time, risk and readiness scores, suggested next steps, protocol draftsCalculated by us from the data above. See section 8
Orders and paymentWhat you bought, order status, amount, shipping address, and a payment tokenYou, at checkout. Card numbers go straight to our payment processor and are never stored by Prime Years
MessagesWhat you write to our assistant or to support, and our repliesYou, and us
Technical informationIP address, browser type and version, device type, sign-in times, pages you viewed and when, and security and audit logs recording who accessed whatCollected automatically when you use the site. See section 5

Some of this is sensitive by law — health data, biometric and health-adjacent measurements from a wearable, information about sex, and your account credentials. Several states give you extra rights over exactly these categories. Sections 15 and 16 explain what those rights are and how to use them.

What we deliberately do not collect. We do not ask for your Social Security number. We do not import location data from a connected device, even where the device makes it available. We do not collect precise geolocation from your browser or phone. We do not buy personal information from data brokers.

5. Where it comes from

There are four routes, and only four:

  • You give it to us. The waitlist form, your account, the intake questionnaire, documents you upload, what you buy, and what you write to us. This is the great majority of what we hold.
  • It is created in the course of your care. Laboratories return your results. Clinicians in our network write notes, protocols and prescriptions. Pharmacies confirm what shipped. All of it lands in your record.
  • A device you connected sends it. Only after you authorise it at the device company’s own sign-in screen, and only the categories you approved there. Section 6.
  • We log it automatically. When you use the site we record technical information — your IP address, browser and device type, the pages you viewed and when, sign-in and sign-out events, and an audit trail of who accessed which record. Some of this is a security control rather than a convenience: an access log that can be switched off is not an access log.

Information about other people. If you give us someone else’s details — a family member you want to share results with, an outside doctor, an emergency contact — please make sure you have their permission first. We use those details only for the purpose you gave them to us for.

Business transactions. If Prime Years is ever acquired, merges, or acquires another business, personal information may reach us or leave us as part of that transaction. Section 9 explains what we do about it.

6. Connected devices and wearables

Connecting a device is your choice, and it is never required. Nothing arrives from a device until you say so, and you can have it disconnected at any time. You connect a device yourself, with the Connect button on your wearables page. Disconnecting is not yet a button: you ask us, and we do it with you. The rest of this section explains both.

How the connection works

If you choose to connect a wearable — for example WHOOP, Oura, Garmin, Polar, Fitbit, or Apple Health — you go to that company’s own sign-in screen. You see exactly which categories of data you are agreeing to share, and you approve it there. We never ask for and never receive your password for that account. The device company gives us a token that lets us read the categories you approved, and nothing else.

You start that yourself. On your wearables page, choose Connect: your browser goes to the device company's own sign-in screen, and you approve — or decline — there. To disconnect, email support@primeyearsmedical.com and we will do it with you, or remove our access in the device company's own app. We are building a page where disconnecting is a button too; until it exists, this policy will keep saying so.

What we read, and what we do with it

We read the measurements the device produces — for example sleep stages and duration, recovery and strain scores, resting heart rate, heart rate variability, respiratory rate, oxygen saturation, workouts, steps, and body measurements such as height, weight and maximum heart rate. We use them for one purpose: to show you your own trends, and to give your care team a fuller picture when they review how a therapy is working.

Daily summaries of those readings are written into your clinical record so your clinician can see them alongside your labs. We deliberately do not import location data from a device, even where it is available, because your care does not need to know where you were.

What we never do with device data

  • We never write anything back to your device account. The connection is read-only.
  • We do not sell, license, lease or rent device data, and we do not share it with an advertiser or a data broker. This one is not ours to change: it is a condition of the agreements we hold with the device companies themselves, which is why it is stated more absolutely here than anything in section 10.
  • We never expose your device data to another user or to a third party without your explicit, separate opt-in — for example, if you choose to share your results with a family member or caregiver.
  • We never use device data to make a decision about you automatically. See section 8.

Disconnecting

You can have a device disconnected at any time. There are two ways to do it today, and neither is a button in the member app, because we have not built that page yet.

  • Tell the device company to stop. Sign in to that company’s own app or website and remove our access there. This takes effect straight away and does not depend on us.
  • Or ask us. Email privacy@primeyearsmedical.com and we will disconnect it for you.

Either way, new readings stop arriving. If you remove our access at the device company, that happens because the permission you gave them is gone. If you ask us, we also delete the token we hold. We would rather tell you which of those happened than say we delete something in a case where we may not.

Readings we already received stay in your clinical record either way, because they are part of the record your clinician used — that is the same rule that applies to a lab result you cannot un-take. If you want those readings removed as well, ask us and we will explain what we can delete and what we are required to keep. Section 15 covers this.

A note about the device company

WHOOP, Oura, Garmin and similar consumer device companies are not medical providers, and their handling of your data is governed by their privacy policy, not this one. Read theirs as well. This policy governs what happens to the data once it reaches Prime Years.

7. How we use your information

We use what we collect to:

  • Provide care. Give your clinician what they need to review your case, write a protocol, prescribe if appropriate, and follow up.
  • Show you your own data. Your results, your trends, your orders, and what has changed since last time.
  • Order and deliver what you buy. Send prescriptions to a pharmacy, requisitions to a laboratory, and products to your address.
  • Take payment, issue refunds, and keep the records the law requires us to keep.
  • Contact you about your care, your orders, and your account. Our emails never contain a result value, a diagnosis, a drug name or a treatment category — not in the message and not in the subject line. They tell you something is ready and give you a link to sign in and see it.
  • Keep the platform safe and working — security monitoring, fraud prevention, audit logging, debugging, and backups.
  • Improve the service. When we study how well a protocol works across many members, we work from a dataset with direct identifiers such as your name, email and address removed. We keep an internal member key, which means that dataset is pseudonymized, not de-identified — it never leaves our protected boundary and never goes to an outside company.
  • Build datasets that do not identify anyone. Separately from the above, we may produce properly de-identified and aggregated data — the eighteen categories of identifying detail removed, or a qualified expert’s written determination behind it — and we may use, publish, license or sell that. It is a different artifact from the pseudonymized set above and it is held to a stricter standard, precisely because it is the one that can leave. Section 10 explains it in full.
  • Meet legal obligations, respond to a lawful request, and defend our rights.

We do not use your health information for advertising, for lead generation, or to build a profile of you for anyone else. We do not use it to decide what to charge you.

We do not re-identify, and neither may anyone we give data to. Where we work from a pseudonymized or de-identified dataset, we do not attempt to reverse it back to a named person, except to test that our own stripping process works. Anyone who receives a de-identified dataset from us is contractually forbidden from attempting it, and from combining it with other data in a way that would achieve the same thing.

New purposes. If we ever want to use your information for something not described here, we will tell you first, and where the law requires your consent we will ask for it rather than assume it. Section 20.

8. How we use artificial intelligence

Prime Years uses artificial intelligence to help explain your health data and to suggest what to look at next. This section says exactly where it is used, what it can see, what it is never allowed to do, and how to opt out or reach a person instead.

The single most important line: AI does not decide anything about your care. A licensed clinician does.

8.0 What is switched on today

We are telling you this before it happens rather than after. The AI assistant described below is not live for members yet. It is built and it is switched off. Nothing you type on the Marcus page is sent to an AI model, and no member conversation has been sent to one. When that changes we will tell you directly, before it starts, and we will remove this paragraph on the same day — not before. Everything else in this section describes the rules the assistant will operate under from its first real conversation.

8.1 Where we use AI

  • Marcus, the member assistant. Marcus is an AI assistant inside the member app. It can read your record and answer questions about it, explain what a result means, connect something you mentioned months ago to a number today, and suggest what kind of question to bring to your clinician next. It does not choose products or doses for you — your clinician writes any plan. Marcus identifies itself as an AI education and navigation layer, not a clinician.
  • Turning what you say into a record. If you tell Marcus about a symptom, a condition, a medication you take or an allergy, it can offer to save that into your file so you do not have to fill in another form. Nothing is written to your record until you tap to confirm it. You see the exact wording before it is saved. It is stored as your own report — recorded in your name rather than as a clinician’s finding or a measurement, and never marked confirmed. A clinician confirms it or does not.
  • PYM Analysis. We calculate trends, Prime ranges, and readiness or risk indicators from your labs, your intake answers and your device readings. Some of this is ordinary arithmetic; some of it uses an AI model to interpret results in context.
  • Suggested next steps. The app ranks what to do next — for example, that a follow-up panel is due. These suggestions are prompts for you and your clinician, not instructions.
  • Proposing items for your cart. Marcus may propose adding a lab panel, a supplement, a consult or a medication to your cart. It cannot place the item there without your confirmation, and it cannot buy anything. See 8.4.
  • Internal operations. We may use AI to help draft summaries or route a support request. Anything AI drafts that reaches you about your clinical status is either reviewed by a person or labelled as AI-generated.

8.2 What the AI can see

When you use Marcus, it can look up your record: your profile, your intake answers, your lab results, your analysis, where you are in your care journey, and the sharing permissions you have granted. It fetches only what your question needs rather than loading your whole chart into every conversation.

It can only ever see your record. The identity of the member is taken from your signed-in session, and there is no way for the model — or for anything you or anyone else could type — to ask for another person’s data. That restriction is built into the software, not into the model’s instructions.

8.3 Where the AI runs, and who else sees your data

  • It runs inside our own protected cloud environment on Amazon Bedrock, under our agreement with Amazon Web Services covering protected health information. Your data is not sent to a separate AI company and is not sent to a consumer chatbot service.
  • It stays in the United States. We pin model processing to United States regions rather than letting requests route worldwide.
  • Your record is not used to train models. Not ours and not the model provider’s. Your conversations and your record are not added to any training set, and our agreements forbid our providers from doing so. The one boundary on this is data from which you cannot be identified, which is no longer your record — section 10 says so plainly rather than leaving you to work it out.
  • We restrict which models may touch your data. Only models that are contractually covered for protected health information may be used, the permitted model is fixed in one place in our code, and an automated test blocks any other model from being used.
  • Conversations are not kept in a separate pile. What Marcus saves, it saves into your clinical record where you can see it. There is no second store of your chart contents, and no search index built out of it.

8.4 What AI is never allowed to do

These are limits enforced by our software, not promises about behaviour:

  • It does not diagnose you. It explains what is on your file, connects it up, and shows you the routes open to you — it does not pick one for you.
  • It does not prescribe. Every prescription is a decision by a licensed clinician who reviews your case.
  • It cannot place an order, take a payment, or trigger a shipment. The most it can do is propose an item for your cart, which you then confirm. Your checkout is the only route to a purchase.
  • It cannot pay for a medication on its own. Where a medication is involved, your card is authorised but not charged until a clinician approves it. If the clinician declines, the authorisation is released.
  • It does not write to your record silently. Every write is shown to you and confirmed by you first.
  • It does not decide whether you get care, what you are charged, or whether a request is denied.
  • It does not contact you on its own. It responds to you; it does not send unprompted messages.
  • It does not present itself as a doctor. It carries no title, no credential and no wording implying it is a licensed professional.
  • It is not for emergencies. If you describe something urgent, you get a fixed, pre-written instruction to seek emergency care — not an AI-composed answer. If you think you are having an emergency, call 911.

8.5 A human is always available, and always the decider

Anything clinical is decided by a licensed clinician who reviews your record themselves. You can ask to speak to a person at any point, and Marcus will give you the route to do so. You never have to go through the AI to reach your care team: email support@primeyearsmedical.com and a person will answer.

8.6 Accuracy, and what AI gets wrong

AI can be confidently wrong. It can misread a number, miss context, or summarise something in a misleading way. We design around that — a clinician reviews clinical decisions, you confirm every record change, and the app shows you the underlying result rather than only the interpretation — but you should treat anything the assistant tells you as information to discuss with your clinician, not as medical advice you should act on alone. If something it says does not match what you know about yourself, tell us. We would rather hear it.

Where the record does not support an answer, the assistant is instructed to say so rather than guess.

8.7 Your choices about AI

  • You can choose not to use the assistant. The app is built to work completely without it. Your results, your orders, your care journey and your checkout are all ordinary screens.
  • You can ask us to turn AI-assisted analysis off for your account. Email us at the address in section 21. You will still get your results and your care; you will not get AI-generated interpretation or suggestions.
  • You can ask how a suggestion was reached, and what information it used. We will tell you.
  • You can ask for a human review of anything that affected you, and we will provide it.
  • Your data is not training data, and there is nothing to opt out of. Some companies let you opt out of having your data train their models. We do not offer that switch because we never do it in the first place. If that ever changes, it will be opt-in, not opt-out.

8.8 Your rights under AI-specific laws

A number of states now regulate AI in healthcare specifically. We follow these whether or not you live in the state concerned, because operating one honest standard is simpler than operating several:

  • Disclosure. Where a communication about your clinical status is generated by AI and has not been reviewed by a licensed clinician, it is labelled as AI-generated and tells you how to reach a human. In a continuous conversation, that label is shown throughout, not once at the start.
  • No false credentials. Our assistant never uses a title, credential, letters after a name, or any wording or design that suggests you are being cared for by a licensed professional when you are talking to software.
  • Notice that AI is used in your care. We tell you that AI systems are used in reviewing and interpreting your health data, in plain language, at or before the time of service — this policy is part of how we do that.
  • Automated decisions. We do not use AI to make significant decisions about you — about your care, your access to it, or its price — without a human making the decision. If that ever changes, we will give you notice beforehand, explain how it works, and give you the right to opt out and to have a person decide instead. California residents have specific rights here, described in section 16.

8.9 We log it

Every time the assistant reads part of your record or writes to it, that access is recorded in an audit log. You can ask us for an account of who and what has accessed your record. That includes the AI.

9. Who we share information with

We share the least that is needed, with the following categories of recipient, and each one is bound by a written contract requiring them to protect your information and forbidding them from using it for their own purposes:

WhoWhat they getWhy
Your clinicians and our clinician networkYour intake, labs, device summaries and historyTo review your case, prescribe and follow up
LaboratoriesThe details needed to run and return your testTo perform the tests you ordered
PharmaciesYour prescription and shipping detailsTo dispense and ship what your clinician prescribed
Our supplement partnerYour name, contact and shipping details, and what you orderedSupplements are bought from that partner, not from us. They are the seller of record, they take your payment, and their own privacy policy governs what they do with those details
Our payment processorAn amount, an order reference and your payment details. Never a diagnosis, a drug name or a treatment categoryTo take payment. A line item may say “Comprehensive Panel”; it never says why you are taking something
Our cloud and hosting providersEncrypted storage and processing of your recordTo run the platform, under agreements covering health information
Our email providerYour email address and a notification with no health content in itTo tell you something is ready. Our emails never carry health details, by design
People you chooseWhatever you decide to shareOnly if you set up sharing with a family member, a trainer, an outside doctor or a caregiver, and only until you turn it off
Professional advisersOnly what the specific matter requiresLawyers, accountants, auditors and insurers, in the course of the professional services they provide to us, under a duty of confidentiality
Legal and safetyWhat is specifically requiredTo comply with a law, a subpoena or a court order, to report as required by law, or to prevent serious harm
A future ownerYour record, under the same protectionsIf Prime Years is acquired or merges. We will tell you before your information moves, and this policy continues to apply until you are given notice of a change

We do not send your health information to any company that has not signed a written agreement to protect it — including a Business Associate Agreement where the law requires one. That rule is absolute, and it is why a small number of otherwise convenient tools are simply not used here.

Not on this list, deliberately: advertising networks, data brokers, analytics companies operating on pages that show health information, social media platforms, and any party that would receive your information for its own purposes rather than to do a job for you.

10. Selling your information

We do not sell your personal information today. We do not rent, license or trade it, we do not share it for cross-context behavioural advertising, and we do not send it to data brokers.

We are not going to promise that we never will. Companies change, and a promise made now that we might want to revisit is worth less to you than an honest account of the rules we would have to follow first. So here are the rules, and they are not ours — they are the law’s, and they are strict.

Information that identifies you

Your health record cannot be sold without your separate, signed permission. That is not a policy we could change by editing this page. Federal health privacy law requires an authorization that says, in terms, that the disclosure will result in payment to us. Washington, Nevada and Connecticut go further and require a specific signed authorization before consumer health data may be sold at all.

If we ever want to do this, here is what it looks like from where you sit:

  • We ask you, separately. Not buried in these terms, not a pre-ticked box, and not bundled into anything else you are signing.
  • We tell you who is buying it and what for before you decide.
  • Saying no changes nothing about your care. Not your treatment, not your price, not your place in the queue. Refusing is free, and we will never make it otherwise.
  • You can change your mind and withdraw permission afterwards, which stops any further disclosure.
  • It does not apply backwards. Information you gave us under this version of the policy is not swept into a later decision without you agreeing to it. See section 20.

Information that does not identify you

This is the part we are keeping open, so we would rather be plain about it than quiet. We may create datasets from which you cannot be identified — trends and patterns across many members, with the details that point to a person removed — and we may license, publish or sell those, including to researchers, health systems and commercial buyers. That is how health data is usually monetised, and it is a thing we may decide to do.

What that does and does not mean:

  • “Cannot be identified” has a legal definition and we use it. A dataset only leaves here if it meets the federal de-identification standard — either every one of the eighteen categories of identifying detail removed, or a qualified expert’s written determination that the risk of anyone being identified is very small.
  • We do not try to reverse it, except to test that our own process works, and any buyer is contractually forbidden from trying to identify you or to combine the data with anything that would.
  • Our internal analysis dataset is not this. When we study how a protocol performs across members, we work from a set that still carries an internal key back to you — which makes it pseudonymized, not de-identified. That one stays inside our protected boundary and is not sold: selling it would need exactly the signed permission described above, because with that key it is still your record. Section 7.
  • This is the one limit on our AI-training commitment, and we would rather you read it here than discover it. Your record is not used to train AI models, ours or anyone else’s, and section 8 explains how that is enforced. A properly de-identified dataset is no longer your record, and we do not undertake to control what a lawful buyer of one does with it.

Advertising

We do not use your health information to target advertising to you, we do not allow anyone else to use our site to do so, and we do not run advertising trackers on pages that show health information. If any of that changes we will tell you before it does, and where the law requires your consent we will ask for it rather than assume it.

If our position changes

You will not have to notice it for yourself. We will update this section, change the version at the top of the page, and tell you directly before it takes effect. Where a state requires an opt-out, we will publish one and honour the Global Privacy Control signal as a request to use it. Where a state requires opt-in consent for sensitive data — which is most of them, and health data is always sensitive — we will ask, and the default will be no.

As things stand today: we have not sold or shared personal information in the twelve months before the date at the top of this page, and we have no knowledge of selling or sharing the personal information of anyone under 16. Readings from a device you connect are covered by a stricter rule that we have agreed with the device companies and cannot change unilaterally — we do not sell, license, lease or rent them, full stop. Section 6.

11. Other sites and services

Our site links out to a small number of other services, and one of them takes your order directly: supplements are bought from our supplement partner, who is the seller of record and who collects your payment on its own systems. Our payment processor collects your card details on its own page, not on ours. Device companies such as WHOOP run their own sign-in screens.

Once you are on someone else’s site, their privacy policy applies, not this one. A link from our site is not an endorsement of that company and does not mean we control what it does. We choose these partners carefully and hold them to written contracts, but we cannot make promises on their behalf — so read their policies as well as ours.

12. How long we keep information

We keep personal information for as long as it takes to do the thing we collected it for, and then for as long as the law requires us to keep it. When we decide how long that is, we look at how sensitive the information is, how much harm its loss could do, whether we still need it for care, and what retention period the law sets. In practice:

  • Medical records are kept for as long as the law of your state requires a clinician to keep them, which is commonly six to ten years after your last visit and longer for records of care given to a minor.
  • Order and payment records are kept for as long as tax and financial rules require.
  • Device readings are kept as part of your clinical record. We keep daily summaries rather than every individual reading.
  • Access tokens for a connected device are deleted as soon as we disconnect a device. If instead you remove our access at the device company, the token stops working there and then.
  • Security and audit logs are kept for a limited period set by our security policy. They record who accessed what, and are themselves protected.
  • Waitlist details are kept until you join or ask us to remove them, whichever comes first.
  • Your account is kept until you close it, and then only the parts we are required to retain.

When we no longer need something and no law requires us to hold it, we delete it or strip it of identifiers so it can no longer be traced to you.

13. How we protect information

  • Encrypted in transit and at rest. Everything travels over an encrypted connection, and your record is stored encrypted with keys we control.
  • Stored in the United States. Your clinical record is held in United States data centres, and processing stays in the United States.
  • Access is limited and recorded. Staff access is restricted to what a role requires, staff accounts require multi-factor authentication, and access to member records is logged.
  • Your account can use multi-factor authentication. We recommend turning it on.
  • Health details are kept out of the plumbing. We do not put clinical values into web addresses, application logs, error reports, analytics, or email — a deliberate design rule that limits where your information can leak from.
  • Sessions time out. If you are signed in and step away, we sign you out. You will get a warning first, and anything you were part-way through filling in is not lost.

No system is perfectly secure, and we will not claim otherwise. Security risk is inherent in every internet service, and we cannot guarantee that your information will never be compromised. What we can tell you is what we do, and what we do when something goes wrong — see section 19. Keeping your own password private and your own device secure is the part we cannot do for you.

14. Where your information is processed

Prime Years is based in the United States, and your information is stored and processed here. We pin our cloud storage, our processing and our AI model calls to United States regions rather than allowing them to route worldwide, and we do not use offshore support or offshore development staff to handle member records.

We do not offer our services outside the United States. If you access the site from another country, understand that your information will be transferred to and held in the United States, where privacy law may differ from that of your own country.

15. Your rights and choices

To use any right on this page, email privacy@primeyearsmedical.com. We will confirm we received your request, verify who you are, and answer within the time the law allows — generally 45 days, and we will tell you if we need longer.

Rights under HIPAA, through your clinician

  • See and get a copy of your medical record, in an electronic format.
  • Ask for a correction if something in it is wrong or incomplete.
  • Get a list of disclosures — an account of where your information has been sent.
  • Ask us to restrict how your information is used or shared.
  • Ask us to contact you a particular way, or at a particular address.
  • Get a paper copy of the clinicians’ Notice of Privacy Practices.
  • Complain, without any consequence for your care. See section 21.

Rights under state privacy laws

Depending on where you live, you may also have the right to: know what we collect and who we share it with; access a copy; correct it; delete it; take it with you in a portable format; opt out of sale, of targeted advertising and of profiling (we do none of these); limit our use of sensitive information; and appeal if we refuse a request. We will not treat you differently, charge you more, or give you worse care for using any of them. Section 16 sets these out state by state, including how we verify who you are and how to appeal.

Choices you can make yourself, in the app

  • Turn sharing with a family member, trainer, outside doctor or caregiver on or off.
  • Update your profile.
  • Stop using the AI assistant, or ask us to turn AI-assisted analysis off for your account.

Choices you make by asking us

Connecting a wearable is a control in the app: the Connect button on your wearables page. Disconnecting is not yet — email privacy@primeyearsmedical.com and we will do it, or remove our access in the device company’s own app. Section 6 explains both.

Stopping non-essential email and changing how we contact you work the same way for now: there is no unsubscribe link or contact-preference setting in the app yet, so email that same address and we will make the change. We will still send messages about your care and your orders, because those are not marketing and you cannot be taken off them while you are a member.

If you decline to give us something

Some information we genuinely cannot work without — a clinician cannot review a case with no intake, and a pharmacy cannot ship to no address. If you leave out something we have marked as required, we may not be able to provide that part of the service. We will tell you which, rather than failing quietly.

16. State privacy rights notice

This section applies to residents of U.S. states whose privacy laws reach us and grant the rights below — including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah, Iowa, Indiana, Tennessee, Nevada, Washington and others as their laws take effect. Not every right is available in every state, and some rights are not absolute, so we may decline a request where the law allows it. If we do, we will tell you why and how to appeal.

How to make a request

Email privacy@primeyearsmedical.com and say what you want. Tell us the state you live in and the email address on your account. That is the whole process — there is no form to hunt for and no telephone tree.

How we verify who you are

We will not hand someone’s medical record to a stranger who asks for it, so we have to establish that you are you. For most requests, signing in to your account and making the request from the email address on it is enough. For a request to export or delete a clinical record, we will ask you to confirm details we already hold, and where the request is high-risk or the account cannot be signed into, we may ask for government identification or a signed declaration. We use anything you send for verification only, and we delete it afterwards.

Authorised agents

You can have someone make a request for you. We will need proof that you authorised them — a power of attorney, or written and signed permission from you — and we may still contact you directly to confirm it.

Appeals

If we refuse your request, you can appeal by replying to our refusal and saying you want it reviewed. A different person reviews it, and we answer within the time your state’s law allows. If we refuse again, we will tell you how to complain to your state Attorney General.

What we collect, and what we do with it, in the statutory categories

The table below restates sections 4, 7 and 9 in the categories the California Consumer Privacy Act uses, because the law requires that specific mapping. It describes our practices now and in the twelve months before the date at the top of this page.

What we collectCCPA categoryWhyDisclosed toSold or shared
Account and contact detailsIdentifiers; customer recordsTo run your account, contact you, and ship what you orderClinician network, pharmacies, laboratories, supplement partner, cloud and email providersNo
Date of birth, sex assigned at birth, state of residenceProtected classification characteristics; identifiersClinical eligibility, dosing, and which clinician licence appliesClinician network, laboratories, cloud providersNo
Health intake, clinical records, lab results, prescriptionsSensitive personal information (health)To provide care and to show you your own resultsClinician network, laboratories, pharmacies, cloud providersNo
Device and wearable readingsSensitive personal information (health); biometric-adjacentTo show you your trends and give your clinician contextClinician network, cloud providersNo
Analysis we derive — Prime ranges, scores, suggested next stepsInferences; sensitive personal information (health)Decision support for you and your clinicianClinician network, cloud providersNo
Orders, amounts, shipping address, payment tokenCommercial information; identifiersTo take payment, fulfil and shipPayment processor, pharmacies, laboratories, supplement partnerNo
Sign-in credentialsSensitive personal information (account log-in)To sign you in and keep the account secureCloud identity providerNo
Messages to the assistant and to supportCustomer records; sensitive personal information (health), where you write about your healthTo answer you and to record what you told usCloud providers; the AI model provider under our agreementNo
IP address, browser and device type, pages viewed, access logsInternet or other electronic network activity; identifiersSecurity, audit, fraud prevention and debuggingCloud and hosting providersNo

The “sold or shared” column above describes the twelve months before the date at the top of this page, which is what the law asks it to describe. It is a record, not an undertaking. If any entry in it ever becomes “yes”, the table changes, the version changes, and you are told before it takes effect — section 10.

We do not collect biometric identifiers in the legal sense (no fingerprints, faceprints or voiceprints), precise geolocation, education records, or professional or employment information. We do not collect a Social Security number or any other government identification number.

Sensitive personal information. We collect it — a health platform cannot avoid it — and we use it only to provide the service you asked for. We do not use or disclose sensitive personal information to infer characteristics about you, which is the specific use California lets you limit. There is therefore nothing for that limit to switch off, but you may still ask.

Selling, sharing, targeted advertising and profiling

  • We do not currently sell your personal information within the meaning of any state privacy law, for money or for anything else of value. This is a statement about our practices today rather than a promise about the future; section 10 sets out what would have to happen first, and the rest of this list tells you what your state gives you if it ever does.
  • We do not process personal information for targeted advertising or cross-context behavioural advertising, and we run no advertising trackers on pages that show health information.
  • Sensitive data needs your opt-in, and health data is always sensitive. Most states with a comprehensive privacy law require your affirmative consent before sensitive data may be processed for sale or targeted advertising. We would ask for it, separately, and the default would be no.
  • We do not profile you in a way that produces a legal or similarly significant effect. Our analytics inform you and your clinician; they do not decide whether you get care, what you pay, or whether you are refused.
  • Global Privacy Control. We honour it. Because we do not currently sell or share personal information there is nothing for it to switch off today, but we record and respect the signal now so that it takes effect from the first moment it would mean something, rather than being built after the fact.
  • An opt-out link, if it is ever needed. If we begin selling or sharing personal information we will publish a “Do Not Sell or Share My Personal Information” link and a “Limit the Use of My Sensitive Personal Information” link, in the places California requires them, before the first disclosure rather than after it.
  • Do Not Track. Browsers send a “Do Not Track” signal that the industry never agreed a meaning for, so we do not respond to it as such. What it would ask for, we already do: no tracking for advertising, anywhere on this site.

California

California residents have the rights above and, in addition, the right to know whether we use automated decisionmaking technology to make a significant decision about them, to opt out of it, and to access information about how it was used. As stated in section 8, we do not use AI to make significant decisions about your care without a human deciding. If that changes, we will give notice before it starts and offer the opt-out.

Shine the Light. California Civil Code §1798.83 lets California residents ask which personal information a business disclosed to third parties for those third parties’ own direct marketing in the previous calendar year. We do not disclose personal information for anyone else’s direct marketing, so the answer is none. To ask formally, email privacy@primeyearsmedical.com with the subject line “Shine the Light Request”, your name, your mailing address, and confirmation that you are a California resident.

Nevada

Nevada residents have the right under NRS Chapter 603A to tell us not to sell certain personal information for monetary consideration. We do not currently make such sales. You may register that direction now and we will honour it if we ever do — email privacy@primeyearsmedical.com. Nevada residents also have separate consumer health data rights — see below.

Texas

Texas residents: we do not currently sell personal data or sensitive data as the Texas Data Privacy and Security Act defines those terms, and we do not process personal data for targeted advertising. The Act requires a specific notice — “We may sell your sensitive personal data” — before any such sale, and we will post it before the first one rather than after, alongside the consent the Act requires.

Washington, Nevada and Connecticut consumer health data

These states regulate consumer health data specifically and give you extra rights over it, including the right to withdraw consent and the right to have consumer health data deleted. Those rights, and the separate notice those laws require, are in our Consumer Health Data Privacy Policy.

Other states

If your state passes a comprehensive privacy law that reaches us, its rights apply to you when it takes effect, whether or not this page has caught up with naming it. We would rather grant a right early than argue about a commencement date.

17. Cookies and tracking

A cookie is a small file a website stores in your browser. We use cookies that are necessary for the site to work: keeping you signed in, keeping your session secure, and remembering what is in your cart. You cannot turn these off and still use the member app, because they are how the app knows it is you.

We do not run third-party advertising trackers, session-replay tools, or advertising pixels on pages that show health information. We do not use health information for advertising anywhere.

Your browser lets you block or delete cookies, and lets you stop images loading in email, which is how invisible tracking pixels usually work. Blocking our necessary cookies will sign you out and keep you out. We do not use cookies to build an advertising profile of you, and no advertising network receives anything from this site.

18. Children

Prime Years is for adults. Our services are not offered to anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, contact us and we will delete it. We have no actual knowledge that we collect, sell or share the personal information of anyone under 16.

19. If there is a breach

If your unsecured health information is ever accessed, used or disclosed without authorisation, we will notify you without unreasonable delay and in any event within 60 days of discovering it, as federal law requires — both the HIPAA Breach Notification Rule and the Federal Trade Commission’s Health Breach Notification Rule, which covers health app and wearable data that HIPAA does not reach. We will tell you what happened, what information was involved, what we are doing about it, and what you can do. We will also notify the regulators and, where required, the media. If a company we work with suffers a breach affecting your data, they are contractually required to tell us promptly, and we will tell you.

20. Changes to this policy

If we change this policy we will update the date and version at the top. If the change materially affects how we use your health information — for example, a new way of using AI, or a new category of recipient — we will tell you directly before it takes effect, and where the law requires your consent, we will ask for it rather than assume it. We will not apply a new use retroactively to information you gave us under an older policy without your agreement.

Changes do not reach backwards. Information you gave us while this version was in force stays governed by this version until you agree otherwise. That matters most for section 10: if we later decide to sell data we do not sell today, that decision does not silently gather up everything you have already given us. It applies from the point you agree to it, and not before.

We keep the previous version of this policy and will send it to you on request, so you can see exactly what changed and when.

21. How to reach us

Privacy questions and requests: privacy@primeyearsmedical.com

Everything else: support@primeyearsmedical.com

Prime Years Medical, United States. We are an online service, so email reaches us fastest.

If you think your privacy rights have been violated, tell us first — we would rather fix it. You can also complain to the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints, to the Federal Trade Commission, or to your state Attorney General. Washington residents can complain to the Washington State Attorney General. We will never retaliate against you for making a complaint.

Prime Years Medical  ·  Est. MMXXVI
TermsConsumer Health DataFAQConfidential