Moku Consumer Health Data Privacy Policy
Document version: chd-v3 Effective date: 2026-09-22 Last updated: 2026-09-22
1. Scope
This Consumer Health Data Privacy Policy applies to "consumer health data" as defined under Washington's My Health My Data Act (RCW 19.373). It supplements, and does not replace, our Privacy Policy, which governs all of your information; this policy addresses only the consumer health data of Washington residents and consumers whose consumer health data is collected in Washington.
Moku is operated by Arbor Ray, Inc. (dba "Moku," "we," "our," or "us"). We are a consumer health-education app: you bring in your medical records — by uploading them or by connecting a health system at your direction — and we read, organize, and generate educational explanations of them for you.
2. Categories of consumer health data we collect, and the purpose
We collect the following categories of consumer health data to provide the service you request — reading, organizing, and generating educational explanations and suggested questions from your records — and, as Section 4 of our Privacy Policy describes, to improve Moku's accuracy, evaluate quality, and develop new features using de-identified data:
- Medical records you provide — documents you upload, such as lab reports, imaging reports, discharge summaries, and visit notes.
- Medical records from a connected health system — records retrieved, at your direction, from a hospital, clinic, or other healthcare organization you choose to connect.
- Clinical information we extract from those records — for example, conditions and diagnoses, medications, lab and test results, procedures, and the dates of medical events.
- Health information in your profile, questions, and notes — what you tell us about the person whose records you are organizing, and any health-related questions or notes you enter.
- Educational outputs we generate — summaries, explanations, and suggested topics to discuss with a clinician, derived from your records.
We do not use your consumer health data for advertising, and we do not collect it for any purpose not described in this policy or our Privacy Policy.
3. Categories of sources we collect from
- Directly from you — the records you upload and the profile information, questions, and notes you enter.
- From a connected health system, at your direction — when you choose to connect a healthcare organization, your records are retrieved by our record-retrieval vendor and delivered to Moku.
4. Categories of consumer health data we share
We share the following categories, only as needed to operate the service for you:
- The medical records you bring in.
- The clinical information we extract from them.
- The educational outputs we generate.
5. Categories of third parties and affiliates we share with
We share consumer health data only as needed to operate the product. The service providers that process consumer health data on our behalf each do so under a Business Associate Agreement, and only to perform their service for us:
- Cloud hosting and storage providers — currently Amazon Web Services (secure U.S. storage and hosting).
- AI and model providers — currently Google Cloud (Vertex AI / Gemini), which receives the record as-is to perform optical character recognition and the related document-preparation steps (checking the OCR output, and classifying and splitting the pages of a multi-page file); and OpenAI, which receives de-identified text for reasoning and summarization and, for the identifier-finding step only, the recognized text of a record before de-identification so that the identifiers can be located and replaced. OpenAI additionally operates under Zero Data Retention.
- Electronic health record connectivity providers — currently Fasten Health, Inc., which retrieves your records from a connected health system at your direction.
- Error and security monitoring providers — to detect and diagnose bugs, crashes, and security events.
- Customer support tooling — to respond to your support requests.
- Your enrolling healthcare organization and its provider — only if you join through it and separately authorize the share — read-only access to the organized information in your account under the separate Healthcare Organization Data-Sharing Authorization; never another organization, employer, health plan, or insurer.
We may also disclose consumer health data to legal and compliance recipients — for example, in response to a valid subpoena or court order, or where necessary to protect rights, safety, or the integrity of the product. These disclosures are required by law or necessary for safety; they are not sales or commercial sharing.
Specific affiliates: we have no affiliates with whom we share consumer health data.
We do not sell your consumer health data. We do not share it with advertising platforms, data brokers, or information resellers, and we do not use it for targeted advertising.
6. How to exercise your rights
You have the right to confirm whether we are collecting, sharing, or selling your consumer health data; to access it; to withdraw your consent to its collection and sharing; and to have it deleted, including by any of our processors (a deletion request covers the vault copy of a record as well — see below). To exercise these rights:
- In the app — review what we have extracted, disconnect a connected health system, delete a profile, or delete your account at any time.
- By email — contact us at info@mokuhealth.ai.
We will respond to a rights request within 45 days of receipt. When reasonably necessary, we may extend that period once by an additional 45 days, and we will notify you of the extension and the reason within the first 45 days.
If we decline your request, you may appeal by replying to our response or emailing info@mokuhealth.ai. The appeal process mirrors the request process, and we will respond in writing within 45 days of receipt, explaining the action we have taken or declined to take. If we deny your appeal, you may submit a complaint to the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.
When you delete consumer health data, we delete it from our active systems within a reasonable period; deleted data may persist in encrypted backups for up to six months before it is overwritten on backup rotation. For records added after you accept Privacy Policy v1.3 or later, a copy of each original record is also kept in a separately secured vault (see Sections 2 and 6 of the Privacy Policy); the vault copy is kept until you delete the profile or your account (if you ask us to delete specific records under the rights above, we delete their vault copies as well), and when you do, we destroy the encryption key for that profile's vault copies, which makes every copy, including copies in backups, unreadable — irreversibly so once the backup window above has passed — although the unreadable encrypted remnants may persist in storage.
7. Changes and affirmative consent
We will not collect, use, or share additional categories of consumer health data not disclosed in this policy, or use your consumer health data for purposes not disclosed here, without first disclosing the change and obtaining your affirmative consent. Where a change would let us keep your consumer health data longer, collect a new category of it, use it for a new purpose, or introduce a feature that needs your identifying details, we will ask for your affirmative consent in the app before it applies to you; until you accept, the previous version keeps governing your data. Where we ask for that consent in the app, you will need to accept before continuing to use Moku; if you prefer not to, you can delete your account instead, and everything you have already added stays under the previous version until then. Every processor that handles your consumer health data on our behalf is contractually required to process it consistently with this policy. If we make a material change to this policy, we will update the version and the effective date above.
8. Contact us
To exercise any right described above, or for any question about your consumer health data, contact:
Moku (Arbor Ray, Inc.) Email: info@mokuhealth.ai
Version History
- chd-v3 — 2026-09-22 — Aligns the purpose statement with Section 4 of the Privacy Policy (Section 2), and corrects and completes the recipient disclosures in Section 5 (what Google Cloud and OpenAI each receive, including the identifier-finding step; customer support tooling; the enrolling healthcare organization you separately authorize). Adds the vault copy of original records to the deletion description, including that a deletion request under your rights covers the vault copy (Section 6) and commits to asking for your affirmative consent in the app before any change that would keep your consumer health data longer, collect a new category of it, use it for a new purpose, or introduce a feature that needs your identifying details (Section 7). Updates the Privacy Policy reference to v1.3.
- chd-v2 — 2026-08-26 — Corrects the Zero Data Retention statement (only OpenAI operates under Zero Data Retention; Google Cloud operates under a Business Associate Agreement) and fixes the Privacy Policy link.
- chd-v1 — 2026-06-22 — Initial Consumer Health Data Privacy Policy under Washington's My Health My Data Act.