August 1st, 2025
August 1st, 2025
August 1st, 2025
Privacy Policy
Yari Care, Inc.
Short Summary:
We temporarily process your health data through our HIPAA-compliant Firebase and Vertex AI backend under Google's Business Associate Agreement. We have disabled data caching to achieve zero data retention - your data is immediately deleted after processing. We don't store your health data. We only collect anonymous usage logs with no health data or personal identifiers. Your health information is processed securely under HIPAA protections and then immediately deleted.
Longer Legal Version:
We have the highest regard for your privacy and personal information and realize that the success of our services depends on the trust that you have in the way we handle your personal information. By entrusting us with your information, we would like to assure you of our commitment to keep such information private and to process it only temporarily as needed to provide our Service. We have taken considerable steps to protect the confidentiality, security and integrity of this information. We encourage you to review the following information carefully.
This Privacy Policy applies to your use of Yari Timeline mobile device application (the "App") owned by Yari Care, Inc. ("Company," "we" or "us"). "You" refers to any user of the App.
This policy sets out our commitments and explains the rights that you have with respect to your personal information. We may update this Privacy Policy from time to time. Any changes will be effective immediately upon the posting of the revised Privacy Policy. We encourage you to periodically review this Privacy Policy for the latest information on our privacy practices. If you do not agree to the terms of this Privacy Policy, please do not use the App.
ZERO DATA STORAGE PHILOSOPHY
We have intentionally designed this App to NOT collect or store your personal information long-term. Unlike most apps that collect your data, our App is built specifically to be a minimal-data-collection app with temporary processing only. We believe your health information belongs to you alone and should not be permanently stored by us.
GROUNDS FOR DATA PROCESSING
When you use our App, you consent to the temporary processing of portions of your health information as described in this Privacy Policy solely for the purpose of providing you with our Service. This processing is necessary for the performance of our contractual obligations towards you and providing you with our Service.
For purposes of this Privacy Policy, "Personal Information" means any information which may potentially allow your identification with reasonable means. "Health Information" means data from Apple's HealthKit that you choose to share with the App.
HOW OUR APP WORKS WITH YOUR INFORMATION
No Long-Term Data Storage: Our App does not collect or retain any of your Personal Information or Health Information for long-term storage. All processing is temporary and data is deleted after processing is complete.
Temporary Processing Only: When you use HealthKit features:
Your Health Information is temporarily sent to our HIPAA-compliant Firebase backend for processing
Data is processed through Google's Vertex AI service under HIPAA Business Associate Agreement
Zero Data Retention: We have disabled data caching to ensure immediate deletion after processing
No Health Information is stored on our servers after processing is complete
The App itself does not store HealthKit data locally - when closed, it must request data from HealthKit again
HIPAA Compliance: We maintain a Business Associate Agreement (BAA) with Google to ensure HIPAA compliance for all health data processing.
No Registration Required: The App has no login feature because we don't want or need to track who you are.
WHAT INFORMATION IS PROCESSED (BUT NOT STORED)
Health Information: If you choose to use HealthKit features, this data is:
Temporarily sent to our HIPAA-compliant Firebase backend for processing
Processed to provide you with the requested service
Immediately deleted from our servers after processing
Never stored long-term on our servers
Never used for any purpose other than providing the immediate service you requested
Anonymous Technical Logs: We may collect only minimal anonymous technical logs such as:
Anonymous crash reports to fix App functionality issues
Anonymous logs of API calls for service capacity and security auditing
These logs contain no personal identifiers and cannot be traced back to you personally
We do not collect device identifiers, IP addresses, or detailed analytics
Support Communications: If you email us for support, that communication will contain whatever information you choose to share.
HOW WE USE HEALTH INFORMATION
In accordance with Apple's requirements and HIPAA compliance:
We temporarily process your Health Information through our HIPAA-compliant Firebase backend
Processing occurs through Google's Vertex AI service under HIPAA Business Associate Agreement
Zero Data Retention: We have disabled data caching to ensure immediate deletion after processing
We do not store your Health Information on our servers
Your data is never used for marketing, research, or any other purpose
We maintain strict HIPAA compliance through our Business Associate Agreement with Google
DATA SHARING POLICY
Limited Sharing: Since we don't store your personal or health information long-term, our ability to share data is extremely limited:
HIPAA-Compliant Service Providers: We share Health Information only with:
Google Cloud Platform/Firebase and Vertex AI (under HIPAA Business Associate Agreement) for temporary processing with immediate deletion
We have disabled data caching to ensure zero data retention
No other third parties have access to your Health Information
No Marketing or Commercial Sharing: We do not share Personal Information or Health Information with:
Research partners (unless you provide explicit consent)
Marketing companies
Data brokers
Advertising platforms
Any other third parties
Support Communications: If you contact us for support, we may retain that communication to provide assistance.
SERVICE PROVIDERS
We use the following service providers who may have access to limited information:
Google Cloud Platform/Firebase: Processes Health Information temporarily under HIPAA Business Associate Agreement
Apple App Store: App distribution
Anonymous Crash Reporting: Basic crash logs with no personal identifiers
Customer Support Systems: Only if you contact us directly
These providers do not have access to your Health Information except for Google Cloud Platform under HIPAA protections.
USER RIGHTS
Depending on your jurisdiction, you have various rights regarding your personal information:
General Rights (All Users):
Access: Request information about data processing (though we don't store data long-term)
Deletion: Request deletion of any data, though most data is automatically deleted after processing
Correction: Maintain control over your data through HealthKit settings
Opt-Out: Revoke HealthKit permissions at any time through your device settings
US Users (CCPA): See "CCPA-Related Information" section below
UK Users (UK GDPR): See "UK GDPR Compliance" section below
Canadian Users (PIPEDA): See "Canadian Privacy Law Compliance" section below
Exercising Your Rights: To exercise any of these rights, contact us at timeline-privacy@yari.care
. We will respond within the timeframes required by applicable law.
No Discrimination: We will not discriminate against you for exercising your privacy rights.
COMPLIANCE WITH LEGAL REQUIREMENTS
We may be required to provide information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. However, since we don't store Personal Information or Health Information long-term, we have extremely limited information to provide.
RETENTION
Health Information:
Zero Data Retention: We have disabled data caching for immediate deletion after processing
No Health Information is stored on our servers after processing is complete
Upon termination of our Google BAA, all PHI will be returned or destroyed as required by HIPAA
Anonymous Technical Data: Retained only as necessary for service improvement and security
Support Communications: Retained only as necessary to provide assistance and comply with legal obligations
INTERNATIONAL TRANSFERS
Health Information may be temporarily processed on servers located outside of your jurisdiction as part of our Firebase backend processing:
US Users: Processing occurs within Google Cloud Platform under HIPAA Business Associate Agreement protections.
UK Users: Data may be transferred to Google Cloud Platform servers. We ensure adequate protection through:
Google's adequacy decision status where applicable
Standard Contractual Clauses approved by UK authorities
HIPAA-level security protections
Canadian Users: Cross-border processing occurs under:
Google's security safeguards and contractual protections
HIPAA Business Associate Agreement standards
Appropriate technical and organizational measures
All transfers are temporary (data is immediately deleted after processing) and occur under strict security protections.
LINKS TO OTHER WEBSITES OR APPS
Our App may link to third-party websites or services that we do not own or control. Any Personal Information you provide is provided directly to such third party and is subject to such third party's privacy policy. This Privacy Policy does not apply to such other websites or services.
HOW WE PROTECT YOUR INFORMATION
HIPAA Compliance: All Health Information processing occurs under HIPAA Business Associate Agreement with Google Encryption: Data is encrypted in transit and during processing Immediate Deletion: Health Information is deleted immediately after processing Limited Access: Only authorized systems have access to data during the brief processing period No Long-Term Storage: The strongest protection is that we don't store your data long-term
CHILDREN
Our App is intended for use by persons over the age of majority. We will not knowingly process Personal Information from any person under the age of majority without valid parental consent. If you discover that a child has been using the App without your consent, please contact us and we will take reasonable steps to address the situation.
CCPA-RELATED INFORMATION
For California residents, this section provides information required under the California Consumer Privacy Act (CCPA):
Personal Information Collection: In the preceding twelve months, we have collected only:
Temporary Health Information for immediate processing (immediately deleted)
Anonymous technical logs (crash reports, API usage logs that contain no personal identifiers)
No Sale or Sharing: We do not "sell" or "share" personal information as defined under the CCPA.
Processing Disclosure: Health Information is temporarily disclosed to Google Cloud Platform/Firebase under HIPAA Business Associate Agreement for processing purposes only.
Your Rights: You have the right to request information about our data practices. Since we don't store Personal Information long-term, there is limited stored data to access, delete, or correct.
MY HEALTH MY DATA ACT (WASHINGTON STATE)
We comply with Washington State's My Health My Data Act by:
Not storing consumer health data long-term
Processing health data only temporarily under HIPAA protections
Immediately deleting health data after processing
Obtaining consent before processing health data
UK GDPR COMPLIANCE
For users in the United Kingdom, we comply with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018:
Legal Basis for Processing: Our processing of your Health Information (special category data under Article 9 UK GDPR) is based on:
Your explicit consent when you grant HealthKit permissions
Processing necessary for preventive medicine, medical diagnosis, or health/social care (Article 9(2)(h))
Your Rights Under UK GDPR:
Right of Access: Request information about how we process your data
Right to Rectification: Request correction of inaccurate data
Right to Erasure: Request deletion of your data (though we don't store it long-term)
Right to Restrict Processing: Request limitation of processing
Right to Data Portability: Receive your data in a portable format
Right to Object: Object to processing based on legitimate interests
Right to Withdraw Consent: Withdraw consent at any time through HealthKit settings
Data Protection Officer: Given our minimal data processing, we have not appointed a DPO, but you can contact us with any data protection concerns.
International Transfers: Temporary processing through Google Cloud occurs under adequate safeguards and Standard Contractual Clauses.
Complaints: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
CANADIAN PRIVACY LAW COMPLIANCE
For users in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:
Consent: We obtain your meaningful consent before collecting or processing Health Information through HealthKit permissions.
Purpose Limitation: We process Health Information only for the specific purpose of providing our App's functionality.
Minimal Collection: We collect only the Health Information necessary to provide the requested service.
Retention Limitation: We do not retain Health Information - it is deleted immediately after processing.
Safeguards: We maintain appropriate technical and organizational safeguards, including HIPAA-compliant processing.
Your Rights Under Canadian Privacy Law:
Right to access your personal information (though we don't store it long-term)
Right to request correction of inaccurate information
Right to withdraw consent at any time
Right to file a complaint with the Privacy Commissioner of Canada or relevant provincial privacy commissioner
Provincial Health Privacy Laws: Where applicable, we also comply with provincial health information privacy legislation such as:
Personal Health Information Protection Act (Ontario)
Health Information Act (Alberta)
Personal Information Protection Act (British Columbia)
Cross-Border Disclosure: Health Information is temporarily processed through Google Cloud Platform under HIPAA Business Associate Agreement protections.
POLICY AMENDMENTS
We may update this Privacy Policy from time to time. The updated date will be reflected in the "Last Updated" heading. We will notify users of material changes through the App or other appropriate means.
HOW TO CONTACT US
If you have any questions, comments, requests, or concerns related to this Privacy Policy or the privacy practices of our App, please contact us at timeline-privacy@yari.care
Privacy Complaints:
US Users: Contact us first, or file complaints with relevant state authorities
UK Users: Contact the Information Commissioner's Office (ICO) at ico.org.uk
Canadian Users: Contact the Privacy Commissioner of Canada at priv.gc.ca or your relevant provincial privacy commissioner
We are committed to resolving any privacy concerns you may have.
Yari Care, Inc.
Short Summary:
We temporarily process your health data through our HIPAA-compliant Firebase and Vertex AI backend under Google's Business Associate Agreement. We have disabled data caching to achieve zero data retention - your data is immediately deleted after processing. We don't store your health data. We only collect anonymous usage logs with no health data or personal identifiers. Your health information is processed securely under HIPAA protections and then immediately deleted.
Longer Legal Version:
We have the highest regard for your privacy and personal information and realize that the success of our services depends on the trust that you have in the way we handle your personal information. By entrusting us with your information, we would like to assure you of our commitment to keep such information private and to process it only temporarily as needed to provide our Service. We have taken considerable steps to protect the confidentiality, security and integrity of this information. We encourage you to review the following information carefully.
This Privacy Policy applies to your use of Yari Timeline mobile device application (the "App") owned by Yari Care, Inc. ("Company," "we" or "us"). "You" refers to any user of the App.
This policy sets out our commitments and explains the rights that you have with respect to your personal information. We may update this Privacy Policy from time to time. Any changes will be effective immediately upon the posting of the revised Privacy Policy. We encourage you to periodically review this Privacy Policy for the latest information on our privacy practices. If you do not agree to the terms of this Privacy Policy, please do not use the App.
ZERO DATA STORAGE PHILOSOPHY
We have intentionally designed this App to NOT collect or store your personal information long-term. Unlike most apps that collect your data, our App is built specifically to be a minimal-data-collection app with temporary processing only. We believe your health information belongs to you alone and should not be permanently stored by us.
GROUNDS FOR DATA PROCESSING
When you use our App, you consent to the temporary processing of portions of your health information as described in this Privacy Policy solely for the purpose of providing you with our Service. This processing is necessary for the performance of our contractual obligations towards you and providing you with our Service.
For purposes of this Privacy Policy, "Personal Information" means any information which may potentially allow your identification with reasonable means. "Health Information" means data from Apple's HealthKit that you choose to share with the App.
HOW OUR APP WORKS WITH YOUR INFORMATION
No Long-Term Data Storage: Our App does not collect or retain any of your Personal Information or Health Information for long-term storage. All processing is temporary and data is deleted after processing is complete.
Temporary Processing Only: When you use HealthKit features:
Your Health Information is temporarily sent to our HIPAA-compliant Firebase backend for processing
Data is processed through Google's Vertex AI service under HIPAA Business Associate Agreement
Zero Data Retention: We have disabled data caching to ensure immediate deletion after processing
No Health Information is stored on our servers after processing is complete
The App itself does not store HealthKit data locally - when closed, it must request data from HealthKit again
HIPAA Compliance: We maintain a Business Associate Agreement (BAA) with Google to ensure HIPAA compliance for all health data processing.
No Registration Required: The App has no login feature because we don't want or need to track who you are.
WHAT INFORMATION IS PROCESSED (BUT NOT STORED)
Health Information: If you choose to use HealthKit features, this data is:
Temporarily sent to our HIPAA-compliant Firebase backend for processing
Processed to provide you with the requested service
Immediately deleted from our servers after processing
Never stored long-term on our servers
Never used for any purpose other than providing the immediate service you requested
Anonymous Technical Logs: We may collect only minimal anonymous technical logs such as:
Anonymous crash reports to fix App functionality issues
Anonymous logs of API calls for service capacity and security auditing
These logs contain no personal identifiers and cannot be traced back to you personally
We do not collect device identifiers, IP addresses, or detailed analytics
Support Communications: If you email us for support, that communication will contain whatever information you choose to share.
HOW WE USE HEALTH INFORMATION
In accordance with Apple's requirements and HIPAA compliance:
We temporarily process your Health Information through our HIPAA-compliant Firebase backend
Processing occurs through Google's Vertex AI service under HIPAA Business Associate Agreement
Zero Data Retention: We have disabled data caching to ensure immediate deletion after processing
We do not store your Health Information on our servers
Your data is never used for marketing, research, or any other purpose
We maintain strict HIPAA compliance through our Business Associate Agreement with Google
DATA SHARING POLICY
Limited Sharing: Since we don't store your personal or health information long-term, our ability to share data is extremely limited:
HIPAA-Compliant Service Providers: We share Health Information only with:
Google Cloud Platform/Firebase and Vertex AI (under HIPAA Business Associate Agreement) for temporary processing with immediate deletion
We have disabled data caching to ensure zero data retention
No other third parties have access to your Health Information
No Marketing or Commercial Sharing: We do not share Personal Information or Health Information with:
Research partners (unless you provide explicit consent)
Marketing companies
Data brokers
Advertising platforms
Any other third parties
Support Communications: If you contact us for support, we may retain that communication to provide assistance.
SERVICE PROVIDERS
We use the following service providers who may have access to limited information:
Google Cloud Platform/Firebase: Processes Health Information temporarily under HIPAA Business Associate Agreement
Apple App Store: App distribution
Anonymous Crash Reporting: Basic crash logs with no personal identifiers
Customer Support Systems: Only if you contact us directly
These providers do not have access to your Health Information except for Google Cloud Platform under HIPAA protections.
USER RIGHTS
Depending on your jurisdiction, you have various rights regarding your personal information:
General Rights (All Users):
Access: Request information about data processing (though we don't store data long-term)
Deletion: Request deletion of any data, though most data is automatically deleted after processing
Correction: Maintain control over your data through HealthKit settings
Opt-Out: Revoke HealthKit permissions at any time through your device settings
US Users (CCPA): See "CCPA-Related Information" section below
UK Users (UK GDPR): See "UK GDPR Compliance" section below
Canadian Users (PIPEDA): See "Canadian Privacy Law Compliance" section below
Exercising Your Rights: To exercise any of these rights, contact us at timeline-privacy@yari.care
. We will respond within the timeframes required by applicable law.
No Discrimination: We will not discriminate against you for exercising your privacy rights.
COMPLIANCE WITH LEGAL REQUIREMENTS
We may be required to provide information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. However, since we don't store Personal Information or Health Information long-term, we have extremely limited information to provide.
RETENTION
Health Information:
Zero Data Retention: We have disabled data caching for immediate deletion after processing
No Health Information is stored on our servers after processing is complete
Upon termination of our Google BAA, all PHI will be returned or destroyed as required by HIPAA
Anonymous Technical Data: Retained only as necessary for service improvement and security
Support Communications: Retained only as necessary to provide assistance and comply with legal obligations
INTERNATIONAL TRANSFERS
Health Information may be temporarily processed on servers located outside of your jurisdiction as part of our Firebase backend processing:
US Users: Processing occurs within Google Cloud Platform under HIPAA Business Associate Agreement protections.
UK Users: Data may be transferred to Google Cloud Platform servers. We ensure adequate protection through:
Google's adequacy decision status where applicable
Standard Contractual Clauses approved by UK authorities
HIPAA-level security protections
Canadian Users: Cross-border processing occurs under:
Google's security safeguards and contractual protections
HIPAA Business Associate Agreement standards
Appropriate technical and organizational measures
All transfers are temporary (data is immediately deleted after processing) and occur under strict security protections.
LINKS TO OTHER WEBSITES OR APPS
Our App may link to third-party websites or services that we do not own or control. Any Personal Information you provide is provided directly to such third party and is subject to such third party's privacy policy. This Privacy Policy does not apply to such other websites or services.
HOW WE PROTECT YOUR INFORMATION
HIPAA Compliance: All Health Information processing occurs under HIPAA Business Associate Agreement with Google Encryption: Data is encrypted in transit and during processing Immediate Deletion: Health Information is deleted immediately after processing Limited Access: Only authorized systems have access to data during the brief processing period No Long-Term Storage: The strongest protection is that we don't store your data long-term
CHILDREN
Our App is intended for use by persons over the age of majority. We will not knowingly process Personal Information from any person under the age of majority without valid parental consent. If you discover that a child has been using the App without your consent, please contact us and we will take reasonable steps to address the situation.
CCPA-RELATED INFORMATION
For California residents, this section provides information required under the California Consumer Privacy Act (CCPA):
Personal Information Collection: In the preceding twelve months, we have collected only:
Temporary Health Information for immediate processing (immediately deleted)
Anonymous technical logs (crash reports, API usage logs that contain no personal identifiers)
No Sale or Sharing: We do not "sell" or "share" personal information as defined under the CCPA.
Processing Disclosure: Health Information is temporarily disclosed to Google Cloud Platform/Firebase under HIPAA Business Associate Agreement for processing purposes only.
Your Rights: You have the right to request information about our data practices. Since we don't store Personal Information long-term, there is limited stored data to access, delete, or correct.
MY HEALTH MY DATA ACT (WASHINGTON STATE)
We comply with Washington State's My Health My Data Act by:
Not storing consumer health data long-term
Processing health data only temporarily under HIPAA protections
Immediately deleting health data after processing
Obtaining consent before processing health data
UK GDPR COMPLIANCE
For users in the United Kingdom, we comply with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018:
Legal Basis for Processing: Our processing of your Health Information (special category data under Article 9 UK GDPR) is based on:
Your explicit consent when you grant HealthKit permissions
Processing necessary for preventive medicine, medical diagnosis, or health/social care (Article 9(2)(h))
Your Rights Under UK GDPR:
Right of Access: Request information about how we process your data
Right to Rectification: Request correction of inaccurate data
Right to Erasure: Request deletion of your data (though we don't store it long-term)
Right to Restrict Processing: Request limitation of processing
Right to Data Portability: Receive your data in a portable format
Right to Object: Object to processing based on legitimate interests
Right to Withdraw Consent: Withdraw consent at any time through HealthKit settings
Data Protection Officer: Given our minimal data processing, we have not appointed a DPO, but you can contact us with any data protection concerns.
International Transfers: Temporary processing through Google Cloud occurs under adequate safeguards and Standard Contractual Clauses.
Complaints: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
CANADIAN PRIVACY LAW COMPLIANCE
For users in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws:
Consent: We obtain your meaningful consent before collecting or processing Health Information through HealthKit permissions.
Purpose Limitation: We process Health Information only for the specific purpose of providing our App's functionality.
Minimal Collection: We collect only the Health Information necessary to provide the requested service.
Retention Limitation: We do not retain Health Information - it is deleted immediately after processing.
Safeguards: We maintain appropriate technical and organizational safeguards, including HIPAA-compliant processing.
Your Rights Under Canadian Privacy Law:
Right to access your personal information (though we don't store it long-term)
Right to request correction of inaccurate information
Right to withdraw consent at any time
Right to file a complaint with the Privacy Commissioner of Canada or relevant provincial privacy commissioner
Provincial Health Privacy Laws: Where applicable, we also comply with provincial health information privacy legislation such as:
Personal Health Information Protection Act (Ontario)
Health Information Act (Alberta)
Personal Information Protection Act (British Columbia)
Cross-Border Disclosure: Health Information is temporarily processed through Google Cloud Platform under HIPAA Business Associate Agreement protections.
POLICY AMENDMENTS
We may update this Privacy Policy from time to time. The updated date will be reflected in the "Last Updated" heading. We will notify users of material changes through the App or other appropriate means.
HOW TO CONTACT US
If you have any questions, comments, requests, or concerns related to this Privacy Policy or the privacy practices of our App, please contact us at timeline-privacy@yari.care
Privacy Complaints:
US Users: Contact us first, or file complaints with relevant state authorities
UK Users: Contact the Information Commissioner's Office (ICO) at ico.org.uk
Canadian Users: Contact the Privacy Commissioner of Canada at priv.gc.ca or your relevant provincial privacy commissioner
We are committed to resolving any privacy concerns you may have.