Health Aevum AI Inc. (Delaware)
Aevum Privacy Notice
Last updated July 29, 2026 · Version engineering-draft-2026-07-29
1. Scope and launch status
This notice describes the personal and health information the Aevum website and mobile applications are designed to process. Services that collect identity, health, payment-linked, lab, appointment, medication, wearable, or consultation information must remain unavailable until the applicable privacy, security, contractual, consent, and state-licensure controls are enabled.
This engineering draft does not replace an attorney-approved Privacy Policy or, where applicable, a separate Notice of Privacy Practices.
2. Information we may collect
Depending on the features you choose and the permissions you grant, we may collect account and contact information; authentication and consent records; health assessments; medication and supplement information; allergies; lab and biomarker information; wearable data; appointment and support communications; shipping information; transaction records; and technical security data.
Payment card details are handled by the applicable payment processor. Health information must not be placed in payment descriptions, metadata, receipts, or processor dashboards.
We collect health, wearable, location, camera, notification, and similar permission-based information only through the consent controls applicable to that data source and feature.
3. How we use information
We may use information to operate accounts and authentication; provide requested wellness features; perform medication and contraindication safety screening; coordinate permitted orders and services; respond to support requests; prevent fraud and abuse; maintain audit records; and comply with legal obligations.
Health and wellness outputs describe trends, baselines, uncertainty, and safety limitations. Automated outputs are not diagnoses, treatment plans, or affirmative medication clearance.
4. AI and automated processing
AI features remain disabled unless the required privacy configuration, contract evidence, and separate user choices for collection and external sharing are satisfied. When an approved external model path is used, direct identifiers are removed or replaced before provider submission and model output is screened before release.
We do not represent automated output as review by a licensed professional. A pharmacist-reviewed or human-reviewed label is shown only when the server records the verified reviewer identity, review time, and immutable audit evidence. Otherwise the service identifies the result as automated safety screening.
You may decline optional AI processing or external sharing. Declining an optional feature does not authorize a hidden legacy or less-protective fallback.
5. Disclosure and service providers
We disclose information only as needed for an enabled service, at your direction, for security and legal obligations, or to service providers whose contractual and technical requirements have been satisfied. A provider remains disabled when the required agreement or configuration is absent.
Order-fulfillment partners receive only the minimum information required for fulfillment. Payment processors receive transaction information without health data. Licensed-professional and direct-to-consumer lab services are available only when patient-state and licensure restrictions are satisfied.
We do not sell personal health information. Advertising pixels and advertising SDKs are not permitted on authenticated or health-data routes. Separate choices apply to collecting information and sharing it with another party.
6. Retention and deletion
Retention periods vary by data category and legal purpose. Account, health, consent, audit, security, billing, support, and backup records do not all use one retention period.
When you request deletion, we delete or de-identify eligible information and retain only information that must remain for a documented legal, security, fraud-prevention, billing, dispute, or audit purpose. Backup and log deletion follows their documented lifecycle rather than an unsupported universal deadline.
De-identified information is retained only when the de-identification and approved-use requirements are satisfied.
7. Your choices and rights
Subject to applicable law and identity verification, you may request access, correction, export, or deletion of your information and may withdraw optional collection or sharing choices. You may also disconnect wearable integrations and change device permissions.
State-specific health-data, privacy, telehealth, pharmacist, and lab rights and restrictions apply based on your verified location. Exercising a privacy right will not result in prohibited discrimination.
8. Security and incidents
Enabled services use administrative, technical, and physical safeguards appropriate to the information involved, including least-privilege access, encrypted transport, protected storage, audit logging, and fail-closed runtime controls. No security measure eliminates all risk.
A feature remains unavailable when its required authentication, authorization, consent, encryption, audit, backup, recovery, contractual, or incident-response control is not ready.
9. Children
The general consumer service is not intended for children under 18. Any future pediatric workflow requires verified guardian authority, applicable consent, state-law review, and mandatory human escalation before activation.
10. Contact and policy changes
Questions and privacy requests may be sent to privacy@healthaevumai.com. Support requests may be sent to support@healthaevumai.com. Do not include unnecessary health details in an unencrypted email.
Material policy changes require a new version, an updated effective date, required notice or consent, and legal approval before the changed practice is enabled.