Consumer Health Data Privacy Policy
This policy describes how Citaria, Inc. (“Citaria”, “we”, “us”) handles consumer health data as that term is defined in RCW 19.373.010. It covers only consumer health data. Our general Privacy Policy is published separately.
Our role. Citaria provides a research analysis workspace to organizations that conduct qualitative user research — research consultancies, agencies, and in-house research teams (each, a “Customer”). Citaria processes consumer health data on behalf of a Customer and on that Customer’s instructions, in the role RCW 19.373.060 gives to a processor. Our agreement with each Customer includes a Data Processing Addendum that sets out those instructions and limits. Citaria has no relationship with, and no account for, the individuals who take part in a Customer’s research.
1 Categories of consumer health data we process, and why
Citaria does not decide what material is submitted to the Services. A Customer may submit interview recordings, transcripts, notes, and research documents. Where a Customer’s research concerns health, that material may contain:
- individual health conditions, treatment, diseases, or diagnosis
- social, psychological, behavioral, or medical interventions
- health-related surgeries or procedures
- use or purchase of prescribed medication
- bodily functions, vital signs, symptoms, or measurements
- diagnoses or diagnostic testing, treatment, or medication
- gender-affirming care information
- reproductive or sexual health information
- information that identifies a consumer as one seeking health care services
- biometric data, in the form of the audio and video a Customer submits and the per-recording speaker separation applied to it
- information that our automated analysis derives or infers from any of the above, or from non-health information contained in the same material
Purpose, and how the data is used. We process this material for one purpose: to provide the Services to the Customer that submitted it. That means transcribing recordings, indexing the material so the Customer can search it, generating summaries, themes, citations, and other analytic outputs at the Customer’s request, and operating, securing, and supporting the Services.
Limits on our own use. Citaria does not use consumer health data for its own purposes. We do not use it to train, fine-tune, or improve any machine-learning model, whether our own or a third party’s. We do not use it to evaluate or benchmark our products. We do not use it in case studies, marketing materials, published research, or cross-customer benchmarks.
Service Data. Our Terms of Service describe a category of operational data called Service Data — logs, counts, timings, and structural signals such as whether a generated result was accepted, edited, or dismissed. We do not derive Service Data by analysing the substance of the material you submit.
Automated speaker separation. We use speaker separation only within a single recording: the speaker labels our transcription provider returns are applied to that recording alone. Our transcription provider states that speaker embeddings are created on a recording-by-recording basis and are not retained after the transcript is returned to us. Citaria does not store voice prints and does not match speakers across recordings. In our pipeline, participant names are resolved from the transcript text and from the named-entity list our transcription provider returns with it — not by matching voices.
2 Categories of sources
We receive consumer health data from our Customers and their authorized users, who upload material from research those organizations conduct. We also generate consumer health data by applying automated analysis to that material.
We do not collect consumer health data directly from consumers. We do not buy consumer health data, and we do not obtain it from data brokers or public records.
3 Sharing, and the service providers we use
Citaria does not sell consumer health data. We do not share consumer health data with any third party for that party’s own purposes.
Publication by a Customer. The Services let a Customer publish an analysis to a link that anyone holding the link can open without signing in. Where a Customer does this, the transcript of any recording cited in that analysis, and playback of that recording, become available to anyone holding the link. Citaria does not decide whether a Customer publishes. A published link stops working when the Customer un-publishes it or deletes the material, except that a media playback link already issued continues to work for a limited period after that.
We disclose consumer health data to the service providers we engage to operate the Services. Each row below states what that provider may receive and the data protection terms that apply to it.
The providers listed below are those we use as of the effective date of this policy.
| Service provider | What it may receive | Terms that apply |
|---|---|---|
| Google (Gemini API) | Transcript text and other Customer material submitted for analysis | Paid-tier terms exclude use of the material for model training; API request storage disabled at project level; DPA incorporated by reference |
| AssemblyAI | Audio and video submitted by a Customer, and the transcript returned from it | DPA with built-in standard contractual clauses; opted out of model training, benchmarking, and de-identified-data training; we issue a delete for the vendor-side transcript once ingestion completes |
| OpenAI | Text excerpts from Customer material, and the natural-language queries run against it, for building and querying the semantic search index (text embeddings) | DPA in place; no training on API data |
| Supabase | Database storage of Customer material and the outputs generated from it | DPA with a region-lock clause |
| Cloudflare | Object storage of audio and video files | DPA incorporated by reference |
| Railway | Application hosting and compute for the Services | DPA in place |
| Brave Search | Search queries generated by the Services when a Customer's users ask a question that calls for a web search. We do not send interview recordings, transcripts, or documents to this provider, but a query may reflect the subject matter of a Customer's material | DPA incorporated by reference; Brave's DPA excludes search queries sent through the API from its scope |
Categories of service providers we engage. Cloud hosting and compute providers; database providers; object storage providers; speech-to-text providers; AI model providers; and web search providers. These providers process consumer health data on our behalf under contract; they are not third parties as that term is defined in RCW 19.373.010.
Affiliates. Citaria, Inc. has no affiliates.
Citaria’s sub-processor list, including providers that do not receive consumer health data, is published at citaria.com/trust#sub-processors.
4 How to exercise your rights
RCW 19.373.040 gives a consumer rights against the regulated entity or small business that collected the data: to confirm whether consumer health data concerning them is being collected, shared, or sold; to access that data, together with a list of the third parties and affiliates it has been shared with or sold to and a way to contact them; to withdraw consent to its collection and sharing; to have it deleted; and to appeal a refusal to act.
Direct your request to the organization that conducted the research. Because Citaria processes consumer health data only on behalf of its Customers, the organization that ran the research you took part in — not Citaria — decides what data is collected and for what purpose, holds the relationship with you, and is the party that can act on these rights.
If you contact us instead:
- Write to privacy@citaria.com with enough detail for us to identify the research or the organization involved.
- Where we can identify the organization, we will pass your request to it and tell you that we have done so.
- We will assist that organization in responding to you, as RCW 19.373.060(1)(b) requires of a processor and as our agreement with that organization provides. Where it instructs us to delete consumer health data, we delete it from the active database and object storage that run the Services. Backup snapshots expire on their own schedules; we do not remove individual records from a backup.
- We act on messages sent to this address without undue delay.
What we cannot do. We have no account or other relationship with you, so we cannot authenticate a request from you, and we will not disclose consumer health data to you directly. Our role is to route your request to the organization that holds it and to act on that organization’s instructions.
5 Changes to this policy
If we begin to process categories of consumer health data, or to process consumer health data for purposes, not described in this policy, we will update this policy before we do so.
6 Contact
Citaria, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
privacy@citaria.com