GivePeace Consumer Health Data Privacy Policy
Version 1.0 — Effective July 30, 2026
This policy exists because two state laws — Washington's My Health My Data Act and Nevada's consumer health data law — ask companies to explain, in one dedicated place, exactly what health-related data they handle and why. This is that place. It is published by Give Peace Inc., a Delaware corporation ("Give Peace," "we," "us"), and covers the GivePeace iOS app and the givepeace.co website (together, the "Service").
GivePeace is not a health app. It is a service that delivers sealed video messages to the people you love after you pass away. But doing that job carefully means handling a small amount of data these laws call "consumer health data" — chiefly, your answers when we ask whether you are still alive. This policy describes that data completely: what we collect, where it comes from, why we have it, who touches it, and the rights you have over it.
This policy is deliberately limited to what these laws require. Everything else about how we handle personal data — including retention and deletion in full detail — lives in our Privacy Policy.
1. Who This Policy Applies To
1.1 This policy applies to consumer health data, as Washington's My Health My Data Act (RCW chapter 19.373) and Nevada's consumer health data law (Senate Bill 370 of 2023, codified in chapter 603A of the Nevada Revised Statutes) define it, belonging to the consumers those laws protect.
1.2 You do not need a GivePeace account to have rights under this policy. Trustees, recipients, and people named in verification documents are covered too. We honor the requests in Section 8 from any Washington or Nevada consumer, member or not.
2. The Consumer Health Data We Collect, and Why We Collect It
We collect consumer health data only as necessary to provide the service you request from us: verifying, carefully, that a person has passed away, and delivering the messages they sealed. Here is each category, with its purpose and how it is used.
2.1 Proof-of-life check-in responses, and their timing. When our verification process needs to hear from you — inactivity check-ins, countdown notices, and the 48-hour final call before any release — we ask you directly — by push notification, by email, and by text message if you have added a phone number — to confirm you are alive. We record whether and when you respond, every "I'm alive" confirmation, and, if you armed the optional inactivity switch, the ordinary signs of account activity that tell us the switch should stay quiet. Under these laws, data showing you are alive is data about your present physical health status. We collect and use it for exactly one purpose: to make sure we never release a living person's messages.
2.2 Death-verification records. When a trustee reports that a member has passed away, we record the report, any confirmations or contests by other trustees, the state of the resulting countdown, and any response to the final call. These records speak to a person's vital status. We collect and use them only to run the verification process that member set up.
2.3 Death certificates and verification documents. A trustee may upload a death certificate. A certificate typically states a cause of death, and it can name living people — the informant, the deceased person's parents. We collect certificates for one purpose: manual review by our own trained reviewers to help corroborate that a person has passed away. Reviewer access is limited to the people who need it, opens through time-limited links, and is logged. A death certificate is never shown to recipients and never appears on any memorial or feed.
2.4 Memorial words that may reveal health information. Tributes, prayers, comments, and tombstone videos on public memorial surfaces may mention an illness or a cause of death, because grieving people speak plainly about what happened. We do not ask for this information; members choose what to say. We collect and use these words only to display them on the memorial surfaces the member posted them to.
2.5 Health information you volunteer inside your messages. A sealed video message may contain anything you choose to say, including things about your health. We store your sealed messages solely to deliver them to the recipients you chose after you pass away. Sealed private messages are not reviewed by moderation and are accessed only where the law requires.
2.6 That is the complete list. We collect no consumer health data for any other purpose — not for advertising, not for profiling, not to draw inferences about you, and not to build any product beyond the one you asked for.
3. Where This Data Comes From
3.1 From you — your check-in responses, your sealed messages, and the words you post on memorial surfaces.
3.2 From trustees you appointed — death reports, confirmations, contests, and uploaded death certificates.
3.3 From other members — words they post on public memorial surfaces, which may mention the health of someone they loved.
3.4 From our own systems — timestamps, countdown state, and the verification records generated as the process runs.
3.5 We never buy consumer health data, never obtain it from data brokers, and never collect it from any outside source.
4. How Consumer Health Data Is Shared
4.1 Never sold. We do not sell consumer health data. We never will. Because we never sell it, we will never ask you to sign the authorization these laws require before a sale.
4.2 Never for advertising. There is no advertising on GivePeace. No consumer health data goes to advertisers, advertising networks, or anyone else for advertising or marketing purposes.
4.3 No affiliates. Give Peace Inc. has no affiliates. The list of specific affiliates with whom we share consumer health data is: none.
4.4 The disclosures that do happen, by category. (a) The words and videos in your sealed messages go to the recipients you chose — delivering them is the service you asked us for, and it happens only after verification completes. (b) The words members post on public memorial surfaces are visible to anyone who can see that memorial, because posting them there is what the member chose. (c) Check-in responses, verification records, death certificates, and stored messages are processed by the service providers in Section 5, acting on our instructions. (d) Any category may be disclosed where valid legal process compels it, as our Legal Process & Estate Requests Policy describes. Death certificates and verification records are disclosed to no one outside (c) and (d).
5. The Processors That Touch Consumer Health Data
5.1 These service providers process consumer health data on our behalf, under contracts that limit them to our documented instructions and forbid them from using the data for their own purposes:
- Google LLC (Firebase) — the database and server functions that store check-in responses and verification records, and the push-notification service that carries check-in prompts to your device.
- Apple Inc. — delivery of push notifications to iOS devices.
- Amazon Web Services, Inc. — encryption-key management, protected storage of sealed videos and death certificates, the email and text-message channels that carry check-ins and notices, video processing, and message delivery.
- Functional Software, Inc. (Sentry) — error monitoring. When a check-in, verification, or delivery step fails, the error report includes an account identifier and the name of the step that failed, so we can find and fix the failure before it matters. These reports never include message contents, health details, or contact information.
5.2 Our other service providers — for payments, analytics, search, and infrastructure, each named in our Privacy Policy — are not sent consumer health data.
6. Biometric Data: Our Position
6.1 Your videos contain faces and voices. Under Washington's law, biometric data is a category of consumer health data, so we will be exact: we never extract, generate, derive, store, or transmit a biometric identifier or biometric template — a scan of face geometry, a voiceprint, or anything similar — from any video, image, or audio recording on the Service. We do not use face recognition or face matching. We do not permit any processor to perform biometric extraction on your data; our contracts limit every processor to our documented instructions, and biometric extraction is not among them. A video of your face is, to us, exactly what it is to the person you made it for: a message, not a measurement.
6.2 If you use Face ID to lock the app, that check happens entirely on your device through Apple's own systems. We never receive Face ID data.
7. Geofencing
7.1 We do not use geofencing. The Service collects no GPS or other precise location — the only place information you give us is the city, region, or country you choose to share on your profile — and we never create a geofence around any place, including any facility that provides in-person health care services.
8. Your Rights, and How to Exercise Them
8.1 Your rights. You have the right to: (a) confirm whether we collect, share, or sell consumer health data about you, and to access that data, including a list of all third parties with whom we have shared it and an email address you can use to contact each of them; (b) withdraw any consent you have given to our collection or sharing of your consumer health data; and (c) have your consumer health data deleted.
8.2 How to ask. Email support@givepeace.co with the subject line "Health Data Request". Tell us what you are asking for and that you are a Washington or Nevada consumer. You may also use an authorized agent; we will confirm the request with you directly.
8.3 How we verify it is you. We use commercially reasonable efforts to confirm your identity against the contact details we already hold — your account email or verified phone number if you are a member, or the contact details we were given if you are not. We will never ask for more information than verification needs.
8.4 Timing and cost. We respond within 45 days. If a request is complex, we may take one extension of a further 45 days, and we will tell you within the first 45 days if we do. Responses are free, up to twice per year per consumer.
8.5 How deletion works. When we honor a deletion request, we delete the data from our live systems, instruct every processor holding it to do the same, and remove it from archived and backup systems no later than six months after the request. A few narrow records can survive deletion: records another law requires us to keep, and the audit records of our verification and deletion processes that we keep to demonstrate legal compliance and to establish or defend legal claims — each kept only for the period stated in our Privacy Policy's retention schedule. Our response will tell you exactly what we kept, and why. You can also act directly, at any time while you are alive: delete any unreleased message, remove your memorial posts, or delete your account — our Privacy Policy describes exactly what deletion covers.
8.6 How withdrawing consent works. You can pause or disarm the inactivity switch at any time in the app, which stops inactivity check-ins. You can delete any unreleased sealed message and any memorial post you made. For anything else — including withdrawing consent you gave as a trustee or recipient — email us with the subject "Health Data Request" and we will act on it.
8.7 Words about you written by someone else. If a public memorial tribute reveals health information about you — a living person — you may ask us to remove it, even though another member wrote it. Use the same request process.
8.8 Members who have passed away. The rights in this section belong to living people. We preserve the accounts and sealed messages of members who have passed away, because delivering their words is the promise they trusted us with.
9. Appeals
9.1 If we decline all or part of your request, we will tell you why. You may appeal by replying to our decision or by emailing support@givepeace.co with the subject line "Health Data Appeal".
9.2 We will review your appeal with fresh eyes and respond in writing within 45 days of receiving it, explaining our decision and the reasons for it.
9.3 If we deny your appeal, you may raise the matter with your state's Attorney General: in Washington, at www.atg.wa.gov/file-complaint; in Nevada, at ag.nv.gov. Our appeal response will include this information again, so you always have it in hand.
10. Changes to This Policy
10.1 The version number and effective date appear at the top of this policy. If we make a material change, we will give you at least 30 days' advance notice by email and in the app before the change takes effect.
10.2 We archive prior versions and will provide them on request to support@givepeace.co.
11. Contact Us
Give Peace Inc. support@givepeace.co givepeace.co
For requests under this policy, use the subject line "Health Data Request". For appeals, use "Health Data Appeal". If anything in this policy is unclear, write to us — on an app like this, the answer to "what does this mean for me?" should never be a mystery.
Consumer Health Data Privacy Policy v1.0 — Effective July 30, 2026