Privacy Policy

Last updated 2026-07-14

This Privacy Policy explains how SelfAssay (“SelfAssay,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use selfassay.com and our related applications and services (the “Service”). It forms part of, and should be read with, our Terms of Service.

1. The short version

Your Vault (your stack, dosing, daily check-ins, symptoms, goals, experiments, decoded labs, saved protocols, and your questions to our assistant) is encrypted at rest under a key envelope-wrapped per member. We do not sell your personal information, we do not show it to advertisers, and we do not use it to train third-party AI models. You can export or permanently delete your account and Vault at any time from Settings. Anything that contributes to our aggregate community or measured-outcomes data is strictly opt-in and de-identified.

2. Who we are (data controller)

The controller responsible for your personal information is SelfAssay. You can reach us at hi@selfassay.com.

3. Information we collect

Information you provide

Information collected automatically

Payment information

Subscription payments are processed by our payment processor, Dodo Payments, under their own terms and privacy policy. We do not receive or store your full card number; we receive subscription status and limited transaction metadata needed to provide and manage your plan.

4. How and why we use your information

We use personal information to:

Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service you sign up for); our legitimate interests (to secure, improve, and protect the Service, balanced against your rights); your consent (for processing health/sensitive data, optional cohort contributions, and any non-essential cookies, which you may withdraw at any time); and compliance with legal obligations.

5. Health and other sensitive data

Some information you choose to provide (the compounds and medications you take, symptoms, goals, and lab markers) may relate to your physical or mental health or wellness. We treat this as sensitive information and apply heightened protections.

We are not a healthcare provider, and SelfAssay is not a covered entity or business associate under HIPAA. The Service is a personal-research and decision-support tool, not a medical record. See our Terms of Service for the wellness/not-medical-advice disclaimer.

Consumer health data.Where laws such as the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Law, and similar state laws apply, certain information you provide may be “consumer health data.” We collect it only to provide features you request; we rely on your consent (given when you create an account and by your continued use under this Policy, and a separate, specific opt-in before any sharing into our aggregate datasets); we do not sell consumer health data; and we share it only with the service providers in Section 9 to operate the Service. You may withdraw consent and delete this data at any time (Sections 7, 11, and 12).

Where the GDPR/UK GDPR applies, we process special-category (health) data on the basis of your explicit consent, which you can withdraw at any time without affecting prior processing.

6. How your data is stored and secured

Each Vault section is encrypted at rest with a per-member data key, which is itself wrapped under a server-managed master key (envelope encryption). Embeddings derived from your free-text entries (used for your own semantic search, e.g. “when else have I felt like this?”) are stored separately, tagged to your member id, and are not shared with other members.

How access works. SelfAssay is not a zero-knowledge service. To deliver server-side features (search, AI assistance, lab decoding, and opt-in aggregation), our systems process your Vault contents to perform the operations you request. That access is restricted, logged, and limited to what those features require and to what the law requires of us; we do not access your content for any other purpose.

We use administrative, technical, and organizational safeguards appropriate to the risk. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.

7. Opt-in community and measured-outcomes data

By default, your entries are not contributed to any shared dataset. Two separate, optional contributions exist, each off by default and each independently withdrawable:

Community signal

If you opt in, the classified content of certain entries (e.g. effects and side-effects mentioned in your notes) is routed into aggregate, de-identified community counts and patterns. We never present verbatim user text or attribute it to you. Because these contributions are de-identified on entry, aggregate rows already contributed may not be individually retrievable after opt-out.

Measured-outcomes ledger

If you opt in, when you conclude an n-of-1 experiment we add a de-identified, structured outcome (the compound, what you tracked, the result and effect size, your adherence, and how long you tracked) to an aggregate “people like you, measured” dataset. It is keyed by a salted, one-way hash rather than your account id; aggregate results are only shown above a minimum group size (k-anonymity); and we never include your name, free-text notes, or raw lab values. Turning this off purges the rows you contributed.

You can change either choice at any time in Settings.

8. AI processing

To answer your questions, decode lab reports, and optionally select emphasis for an Assay explanation, we send the specific request and minimum necessary context to our AI processors. For a scored Assay, that limited context can include compound names, the headline purpose and report count, the fixed score, and allowed fact identifiers. It excludes your identity, doses, medication history, and free-text Vault content; the processor selects identifiers only and does not calculate or write the score. A provenance gate is designed to send only the relevant request, never your entire Vault. We do not permit our AI processors to use your content to train their general models, and we do not use your Vault to train third-party models. AI outputs are generated automatically and may be incomplete or inaccurate; they are decision support, not a determination with legal or similarly significant effect, and a human (you) remains in control of all decisions.

9. How we share information (sub-processors)

We do not sell your personal information. We share it only with service providers who process it on our behalf under contract, and only as needed to run the Service:

Information you choose to publish.Stack Assays are private by default. If you select “Create share card,” we create an unlisted public link containing the compound names and Assay result. It excludes your account identity, doses, source-health diagnostics, and private explanation. You can remove that public snapshot with “Make private,” and owned Assay cards are deleted with your account.

Formulary protocol links are also opt-in, unlisted public links. A protocol link contains your goal exactly as entered plus the compound names, roles, doses, and units in the shared composition. It does not include your account identity, saved client fields, or private rationale, but free text or an unusual composition may still identify you or another person. After creating a link, you can make it private while its current page session remains open. We do not currently keep a persistent in-product registry of protocol links; if you lose the link after leaving or reloading, contact SelfAssay for removal. Owned protocol links are deleted when you delete your account.

We may also disclose information to comply with law or valid legal process, to enforce our Terms, to protect the rights, safety, and security of users or the public, or in connection with a merger, acquisition, or sale of assets (with notice as required by law).

10. International data transfers

We and our service providers may process your information in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism.

11. Data retention

We retain your account and Vault for as long as your account is active. When you delete your account, we permanently delete your encrypted records and the derived embeddings, and purge your opt-in measured-outcomes rows, within 365 days, except where we must retain limited records to comply with law, resolve disputes, or enforce our agreements. Backups are cycled out on our normal rotation schedule. De-identified aggregate data that no longer identifies you may be retained.

12. Your rights and choices

From Settings you can, at any time, view and export your Vault and permanently delete your account. Depending on where you live, you may also have rights to:

EEA/UK (GDPR/UK GDPR): you have the rights above and may lodge a complaint with your supervisory authority (in the UK, the ICO). California (CCPA/CPRA): you have rights to know, delete, correct, and limit the use of sensitive personal information; we have not sold personal information in the preceding 12 months. Washington, Nevada, and similar consumer-health-data laws: you may withdraw consent, delete consumer health data, and (where provided by law) appeal a decision. To exercise any right, contact hi@selfassay.com; we will verify and respond within the time required by applicable law. You may use an authorized agent where the law permits.

13. Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, remember preferences, and secure the Service. We do not use third-party advertising or cross-site tracking cookies. Where required, we will request consent for any non-essential cookies and honor recognized opt-out signals (such as Global Privacy Control).

14. Children

The Service is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here, revise the “last updated” date, and, for material changes, provide additional notice (e.g. in-app or by email) before they take effect where required.

16. Contact us

Questions or requests about this Policy or your data: hi@selfassay.com.