CopayRadar

Consumer Health Data Privacy Policy

v1.0 · in effect 1 August 2026

This page exists because Washington's My Health My Data Act requires it, and because you deserve a straight answer. It is written in the order the law asks the questions. Plain words, no lawyering.

Short version: we collect four things, we use them only to send you alerts, we never sell them, and you can delete everything with one button.

1. What health-related data we collect, and why

Only these four items, and only what you type in:

We use this only to check public coverage documents and email you when something changes for your medicine. Nothing else. We do not build a profile, score you, or infer anything about your health beyond the medicine you told us to watch.

We do not ask for and do not want: your name, date of birth, diagnosis, prescriber, pharmacy, member ID, or phone number.

2. Where we get it

From you, directly, when you set up your watch. That is the only source. We do not buy data, receive it from data brokers, or collect it from other websites you visit.

Separately, we read public documents that are not about you: government Medicare drug files and the coverage lists that pharmacy benefit managers publish. Those describe plans, not people.

3. What we share

Nothing. We do not share your consumer health data with anyone.

Some companies must run our software: Amazon Web Services stores our database and sends our email, and Stripe processes payments. They act on our instructions and may not use your data for their own purposes. Under the Act these are processors, not people we share data with.

4. Who we share it with, by category

There is no list to give, because the list is empty. To be explicit about the categories the law asks us to name:

If a link in an alert earns us a referral fee, we say so beside the link. Clicking it tells that company nothing about your medicine.

5. How to see, correct, delete, or withdraw

You can do all of these yourself, any time, from Settings → Privacy:

No account? Email privacy@copayradar.com and we will do it for you. We answer within 45 days, usually the same week, and we will not ask why. If we ever refuse a request we will tell you why, and you may appeal to the same address; if we get the appeal wrong you can complain to the Washington State Attorney General.

6. Deleting really means deleting

When you delete: your rows are removed from our live database immediately. Database backups roll off within 7 days, after which no copy remains. We keep no separate archive of your data.

One thing survives, and it is not about you: the public coverage documents we saved as evidence. Those are copies of Medicare files and insurer lists. They never contained anything about you.

We also keep a minimal record that a deletion happened — a date and the fact of it — so we can prove we honoured your request. It contains no health data.

7. We do not sell your data

We have never sold consumer health data and we do not intend to. Washington law would require a signed authorization from you first, and we are not going to ask for one. Our only revenue is the subscription fee.

8. No location tracking

We do not use geofencing. We do not collect precise location. The only location-ish thing we ever hold is a ZIP code you typed in yourself, used to find Medicare plans in your region.

9. Changes to this page

If we change it we will post the new version here with a new version number and date, and email you before it takes effect if the change materially affects your rights. We keep a record of which version you agreed to.

Who to contact

October Wolf LLC, Seattle, Washington — privacy@copayradar.com.

October Wolf LLC, Seattle WA · Consumer Health Data Privacy Policy · Privacy Policy · Terms