Futurion LLC, doing business as Alova · Last updated: August 4, 2026
This Consumer Health Data Privacy Policy is separate from Alova's general Privacy Policy. It applies to "Consumer Health Data" covered by the Washington My Health My Data Act and similar laws. It is available through a distinct, prominent link at https://alova.dev/health-data and in the Alova app.
Contact: support@alova.dev · Futurion LLC, 522 W Riverside Ave, Ste N, Spokane, WA 99201, United States.
Alova collects or derives the following Consumer Health Data when you consent or when collection is otherwise permitted by law:
Alova does not diagnose a condition, create a medical record, provide treatment, or claim that a Safety Signal is clinically accurate. Automated inferences may be incorrect.
We do not use Consumer Health Data for targeted advertising, sale, data brokerage, credit, employment, insurance, housing, or unrelated profiling.
Before Alova analyzes your messages for Safety Signals, we ask for a separate affirmative consent. Consent is not obtained through acceptance of general Terms alone. You may decline, but Alova cannot safely or lawfully provide companion chats without this processing.
You may withdraw consent at any time through Profile → Privacy → Health Data or by contacting support@alova.dev. Withdrawal stops future collection after we process the request. Because safety processing is integral to the chat service, withdrawal may require disabling companion chats or closing the account. Withdrawal does not affect processing already completed lawfully and does not require deletion of data that law permits or requires us to retain; you may separately request deletion.
The following contracted processors may access Consumer Health Data only to perform services for Alova under our instructions:
| Processor category / provider | Purpose | |---|---| | AI and safety processing — Anthropic | Generate responses and apply model-level safety processing to relevant message content and output. | | Hosting and database — Supabase | Store and transmit account, conversation, Safety Signal, response, and deletion data. | | Security, legal, and incident-response providers | Limited access when reasonably necessary for a specific security event, legal obligation, or claim. |
We do not send private messages or Safety Signals to PostHog for analytics, RevenueCat for subscription management, Resend for ordinary email delivery, or Apple for payment processing, except if you intentionally include health information in a support communication delivered through a service provider.
We do not "share" Consumer Health Data for an independent third-party purpose. If we propose to share Consumer Health Data in a way that requires separate authorization, we will identify the data, recipient, purpose, and method of revocation and obtain legally valid authorization before sharing.
At launch, Alova does not share Consumer Health Data with third parties for their own purposes. Contracted processor access under Alova's instructions is described above. We may disclose information when required by valid legal process or necessary to prevent or respond to a serious security or safety incident, subject to applicable law.
Submit a request through https://alova.dev/privacy, Profile → Help & Support, or support@alova.dev. We may authenticate the request using information already associated with your account. We will respond within the period required by law, generally 45 days, subject to a permitted extension with notice.
To appeal, email support@alova.dev with "Consumer Health Data Appeal" in the subject line. We will provide a written explanation and information about contacting the Washington Attorney General when required.
Identifiable Consumer Health Data is retained only as long as reasonably necessary for the purposes above. Message content and associated Safety Signals are deleted when you delete the relevant conversation or account, subject to short operational delays, backup schedules, active security investigations, legal holds, and other permitted exceptions.
After deletion, Alova may retain deidentified or aggregated safety statistics if they cannot reasonably be linked to you. Alova maintains reasonable measures to prevent reidentification, publicly commits not to reidentify the information, and contractually requires recipients to comply with the same restriction where applicable.
Alova uses reasonable safeguards appropriate to Consumer Health Data, including access controls, encryption in transit, logging, processor restrictions, data minimization, and incident-response procedures. No security measure eliminates all risk.
We will update this policy before collecting, using, or sharing additional categories of Consumer Health Data and will obtain affirmative consent when required. Material changes will be communicated through the app, email, or another legally appropriate method.
Futurion LLC (dba Alova) 522 W Riverside Ave, Ste N Spokane, WA 99201 United States support@alova.dev