Legal
Consumer Health Data Privacy Notice
Language: English · Polski
Version: 1.0 — prepared 5 September 2026
Effective date: 01.10.2026
This separate notice supplements the Privacy Policy for consumer health data covered by Washington’s My Health My Data Act or Nevada’s consumer health data law. It also explains our approach if you accidentally include health information in Crumely. Your GDPR and other applicable rights remain available; where an earlier deadline or stronger protection applies, we follow it.
The responsible business is Adrian Gaik, trading as Adrian Gaik Software, ul. Armeńska 5/8, 52-121 Wrocław, Poland; NIP 8992914427; REGON 520853243. Contact privacy@crumely.com for questions and requests.
1. What health data means here
Crumely is a recipe and baking app, not a medical-record or healthcare service. We do not ask for your medical history or intentionally create health profiles from your recipe choices. Nevertheless, content linked or reasonably linkable to a person can reveal health information: for example, a recipe note naming someone’s allergy, a photograph of medical dietary instructions, or a support message about a diagnosed condition. A generic “gluten-free” recipe is not, by that label alone, a statement about your health.
The categories that may be present are health conditions, allergies or intolerances, health-related dietary restrictions, and information about health services or treatment voluntarily included in text or images. Account identifiers, contact details, source links, and activity associated with such content may also be consumer health data where the law’s definition is met. We do not collect precise location for health-related purposes, use geofences around healthcare facilities, or perform biometric identification.
Sources are information you submit or ask us to import, the source material used for that import, and information another person includes in content or correspondence. Please do not include another person’s health information. If someone has included yours, you can request removal without having a Crumely account.
2. Purposes and collection limits
Where lawful, we process this information only to provide the particular feature you request—such as storing and synchronising your selected content, extracting a recipe from submitted material, or answering your request—and to comply with applicable legal obligations.
We collect or share consumer health data only with the consent required by applicable law, or to the extent a specific exception permits processing necessary to provide a product or service you requested. A service request does not override GDPR requirements for special-category data. Accepting the Terms or acknowledging a privacy notice is not health-data consent. Where consent is required, consent to sharing is obtained separately from consent to collection. We do not use health data for advertising, general product analytics, or inferring health characteristics from ordinary recipe activity.
Keep health information out of public recipes, reviews, biographies, and other public contributions. Publishing content can reveal it to other users and create saved copies. An ordinary publish action is not a substitute for any separately required health-data consent.
3. Who may receive it
Access is limited to people and providers that need the information for the permitted purpose, subject to applicable restrictions:
- Hosting and storage processors: Convex stores account content and uploaded files.
- AI extraction processor: OpenAI receives material you select for an AI import. Content already saved in your library is not routinely sent for AI processing.
- Support and communications providers: providers handling the particular message or attachment you send us; Resend delivers operational emails. We do not intentionally include health content in routine verification or entitlement emails.
- Legal, security, or professional recipients: only when permitted or required by the applicable law, with information limited to the particular matter.
We do not sell consumer health data, share it for targeted advertising, or disclose it to affiliates for their independent use. We do not authorise processors to use it for their own unrelated purposes. The Privacy Policy explains international transfers and the limits of provider retention. Those disclosures do not create permission for otherwise prohibited health-data sharing.
4. Your rights and how to use them
Email privacy@crumely.com, identifying the information or content involved if you can. You may request confirmation and access, withdraw consent, or request deletion. Where required, access includes a list of third parties and affiliates with whom we shared or to whom we sold your consumer health data, together with contact details. We do not sell it. You may also use the correction and other rights described in the Privacy Policy. We will not discriminate against you for using these rights.
We verify identity in a proportionate way and request only information needed to protect against unauthorised disclosure or deletion. No account creation or paid plan is required. We respond without undue delay and within 45 days of receiving a request, or sooner where another applicable law requires it. Verification does not restart the Washington deadline. If a legally permitted extension is necessary, we explain why and give its duration before the original deadline; under Washington law, it may be extended once by up to 45 days. GDPR’s one-month response requirement continues to apply where relevant.
For Nevada health-data deletion requests, we delete within 30 days after authenticating the request, subject only to applicable statutory exceptions. Washington deletion includes archived and backup systems as required by its law. We notify processors and other recipients where required and direct deletion as the applicable law requires. Ordinary backup cycles do not displace a stricter health-data obligation.
Withdrawing consent stops the processing that depends on it. Settings retains a withdrawal option for sensitive-image consent recorded by earlier versions. It records your withdrawal but does not itself erase existing files or copies; ordinary recipe photos do not require this consent. Contact us to identify existing sensitive information so we can complete the necessary action. Continued restricted retention requires an applicable legal exception, not merely a previous consent.
If we decline a request, reply to our decision with “Privacy appeal”. We provide a reasoned response within 45 days of receiving the appeal, or earlier where required. You can also complain to the Washington Attorney General or Nevada Attorney General, as applicable, and use other remedies provided by law. GDPR complaints can be made to the Polish supervisory authority or another competent EU authority as explained in the Privacy Policy.
5. Changes
We keep this notice separately accessible from our website’s home page and from the main Privacy Policy. Before collecting a new category of consumer health data or using it for a new purpose, we update the notice and obtain any consent required by law. Posting an update does not itself supply that consent.
