GivePeace Consumer Health Data Privacy Policy

Version 1.0 — Effective October 3, 2026

This policy exists because two state laws — Washington's My Health My Data Act and Nevada's consumer health data law — ask companies to explain, in one dedicated place, exactly what health-related data they handle and why. This is that place. It is published by Give Peace Inc., a Delaware corporation ("GivePeace," "we," "us"), and covers the GivePeace iOS app and the givepeace.co website (together, the "Service").

GivePeace is not a health app. It is a service that delivers sealed video messages to the people you love after you pass away. But doing that job carefully means handling a small amount of data these laws call "consumer health data" — chiefly, your answers when we ask whether you are still alive. This policy describes that data completely: what we collect, where it comes from, why we have it, who touches it, and the rights you have over it.

This policy is deliberately limited to what these laws require. Everything else about how we handle personal data — including retention and deletion in full detail — lives in our Privacy Policy.

1. Who This Policy Applies To

1.1 This policy applies to consumer health data, as Washington's My Health My Data Act (RCW chapter 19.373) and Nevada's consumer health data law (Senate Bill 370 of 2023, codified in chapter 603A of the Nevada Revised Statutes) define it, belonging to the consumers those laws protect.

1.2 You do not need a GivePeace account to have rights under this policy. Trustees, recipients, and people named in verification documents are covered too. We honor the requests in Section 8 from any Washington or Nevada consumer, member or not.

2. The Consumer Health Data We Collect, and Why We Collect It

We collect consumer health data only as necessary to provide the service you request from us: verifying, carefully, that a person has passed away, and delivering the messages they sealed. Here is each category, with its purpose and how it is used.

2.1 Proof-of-life check-in responses, and their timing. When our verification process needs to hear from you — inactivity check-ins, countdown notices, and the 48-hour final call before any release — we ask you directly — by push notification, by email, and by text message if you enrolled a phone number you verified with us (our SMS & Communications Terms describe how) — to confirm you are alive. We record whether and when you respond, every "I'm alive" confirmation, and, if you armed the optional inactivity switch, the ordinary signs of account activity that tell us the switch should stay quiet. Under these laws, data showing you are alive is data about your present physical health status. We collect and use it for exactly one purpose: to make sure we never release a living person's messages. We draw on no clinical or third-party health sources in verification — no medical records, no wearable or device health data, and no death registries or health databases — as our Death Verification & Posthumous Release Policy also states.

2.2 Death-verification records, including the ones that undo a mistake. When a trustee reports that a member has passed away, we record the report, any confirmations or contests by other trustees, the state of the resulting countdown, and any response to the final call. If a death is declared and turns out to be wrong, we keep the record of putting it right as well: the emergency hold we place while we check, each step of the reversal as it runs, who saw a released message and when, and — if you signed in and told us you are alive so our team could start a recovery — the fact that you did. We also keep, in our audit records, any attempt by one of our own administrators to undo their own death record, because that is the one refusal worth never forgetting; our Privacy Policy's retention schedule says how long those records last. These records speak to a person's vital status. We collect and use them only to run the verification process that member set up, and to correct it when it goes wrong.

2.3 Death certificates and verification documents. A trustee may upload a death certificate. A certificate typically states a cause of death, and it can name living people — the informant, the deceased person's parents. We do not ask for cause-of-death information and do not use it in verification; where an uploaded certificate contains it, we treat those portions as extra-sensitive and may redact or delete them. We collect certificates for one purpose: manual review by our own trained reviewers to help corroborate that a person has passed away. Reviewer access is limited to the people who need it, opens through time-limited links, and is logged. A death certificate is never shown to recipients and never appears on any memorial or feed.

2.4 Memorial words that may reveal health information. Tributes, prayers, comments, and tombstone videos on public memorial surfaces may mention an illness or a cause of death, because grieving people speak plainly about what happened. We do not ask for this information; members choose what to say. We collect and use these words only to display them on the memorial surfaces the member posted them to.

2.5 Health information you volunteer inside your messages. A sealed video message may contain anything you choose to say, including things about your health. We store your sealed messages solely to deliver them to the recipients you chose — the messages tied to your plan, after you pass away, and a time capsule on the date you picked for it. Because a capsule arrives on its date whether or not you are still living, we keep the date you chose, who you chose, and the record of the delivery; if you have passed away by then, the note that carries it says so plainly and gently, because no one should learn that news from a cheerful message that does not match. Sealed private messages are not reviewed by moderation and are accessed only where the law requires.

2.6 That is the complete list. We collect no consumer health data for any other purpose — not for advertising, not for profiling, not to draw inferences about you, and not to build any product beyond the one you asked for.

3. Where This Data Comes From

3.1 From you — your check-in responses, your sealed messages, and the words you post on memorial surfaces.

3.2 From trustees you appointed — death reports, confirmations, contests, and uploaded death certificates. If you are 13 to 17 and a parent or guardian consented so you could arm your messages, they are the trustee on your plan, and these reports come from them.

3.3 From other members — words they post on public memorial surfaces, which may mention the health of someone they loved.

3.4 From our own systems — timestamps, countdown state, and the verification records generated as the process runs.

3.5 We never buy consumer health data, never obtain it from data brokers, and never collect it from any source outside those described in Sections 3.1 through 3.4.

4. How Consumer Health Data Is Shared

4.1 Never sold. We do not sell consumer health data. We never will. Because we never sell it, we will never ask you to sign the authorization these laws require before a sale.

4.2 Never for advertising. There is no advertising on GivePeace. No consumer health data goes to advertisers, advertising networks, or anyone else for advertising or marketing purposes.

4.3 No affiliates. Give Peace Inc. has no affiliates. The list of specific affiliates with whom we share consumer health data is: none.

4.4 The disclosures that do happen, by category. (a) The words and videos in your sealed messages go to the recipients you chose — delivering them is the service you asked us for. A message tied to your plan goes only after verification completes; a time capsule goes on the date you picked for it, whether or not you are still living. (b) The words members post on public memorial surfaces are visible to anyone who can see that memorial, because posting them there is what the member chose. (c) Your trustees are told what the process needs them to know: that check-ins have gone unanswered, that a report has been filed, and that we are asking them to confirm or contest it — never who your recipients are, which messages exist, or what any message says, except the name of a person claiming a message, when we ask your primary trustee — the first trustee you named, unless you have chosen another — to approve that claim. If you are 13 to 17 and a parent or guardian consented so you could arm your messages, that parent is the trustee on your plan and sees this same status — never the contents of anything you recorded. (d) If we ever declare a death that turns out to be wrong, we correct it out loud, because a quiet fix would leave the harm in place: you are told who saw your released messages and when, the trustee whose report caused it is told privately that it was incorrect, your other trustees are told without naming anyone, every recipient we wrote to gets a correction whether or not they opened the message, and anyone who reaches the withdrawn memorial is told plainly that it was created in error and you are alive. (e) Check-in responses, verification records, death certificates, and stored messages are processed by the service providers in Section 5, acting on our instructions; the limited public profile fields and published-memorial facts described in Section 5.2 are also indexed by our search provider, so that people can be found in the app. (f) Any category may be disclosed where valid legal process compels it, as our Legal Process & Estate Requests Policy describes. Death certificates are shown to no one outside (e) and (f).

5. The Processors That Touch Consumer Health Data

5.1 These service providers process consumer health data on our behalf, under contracts that limit them to our documented instructions and forbid them from using the data for their own purposes:

5.2 Our other service providers — for payments, analytics, and infrastructure, each named in our Privacy Policy — are not sent consumer health data. One exception is narrow and worth stating plainly: our search provider indexes the limited public profile fields and published-memorial facts our Privacy Policy lists, so that people can be found in the app. It receives no other data described in this policy, and it is bound by the same contractual limits as the providers in Section 5.1.

6. Biometric Data: Our Position

6.1 Your videos contain faces and voices. Under Washington's law, biometric data is a category of consumer health data, so we will be exact: we never extract, generate, derive, store, or transmit a biometric identifier or biometric template — a scan of face geometry, a voiceprint, or anything similar — from any video, image, or audio recording on the Service. We do not use face recognition or face matching. We do not permit any processor to perform biometric extraction on your data; our contracts limit every processor to our documented instructions, and biometric extraction is not among them. A video of your face is, to us, exactly what it is to the person you made it for: a message, not a measurement.

6.2 Face ID and Touch ID do two jobs here, and both happen entirely on your device through Apple's own systems: they can lock the app, and they ask you to confirm it is really you before the app registers an "I'm alive" check-in. The answer never leaves your phone. We never receive Face ID or Touch ID data, and nothing about your face or your fingerprint is stored, sent, or compared by us. If the check will not work, you can use your phone passcode instead, and if your device has no biometrics at all your check-in still goes through — we will never let a face stand between a living person and telling us they are alive.

7. Geofencing

7.1 We do not use geofencing. The Service collects no GPS or other precise location — the only place information you give us is the city, region, or country you choose to share on your profile — and we never create a geofence around any place, including any facility that provides in-person health care services.

8. Your Rights, and How to Exercise Them

8.1 Your rights. You have the right to: (a) confirm whether we collect, share, or sell consumer health data about you, and to access that data, including a list of all third parties with whom we have shared it and an email address you can use to contact each of them; (b) withdraw any consent you have given to our collection or sharing of your consumer health data; and (c) have your consumer health data deleted.

8.2 How to ask. Much of this you can do yourself in the app, at any time: delete an unreleased message, a memorial post, or your account; withdraw a parent or guardian consent; or cancel a scheduled time capsule. Sections 8.5 and 8.6 explain what deletion and withdrawal cover, and what they do not. To make a formal request under this Section 8, or for anything else, email support@givepeace.co with the subject line "Health Data Request". Tell us what you are asking for and that you are a Washington or Nevada consumer. You may also use an authorized agent; we will confirm the request with you directly.

8.3 How we verify it is you. We use commercially reasonable efforts to confirm your identity, in proportion to the sensitivity of the request — a request touching your videos or a death certificate requires stronger proof than a request about a contact preference — because handing this data to the wrong person is the greater harm. We start from the contact details we already hold: your account email or verified phone number if you are a member, or the contact details we were given if you are not. We will never ask for more information than verification needs.

8.4 Timing and cost. We respond within 45 days. If a request is complex, we may take one extension of a further 45 days, and we will tell you within the first 45 days if we do. Responses are free, up to twice per year per consumer.

8.5 How deletion works. When we honor a deletion request, we delete the data from our live systems, instruct every processor holding it to do the same, and remove it from archived and backup systems no later than six months after the request. A few narrow records can survive deletion: records another law requires us to keep, and the audit records of our verification and deletion processes that we keep to demonstrate legal compliance and to establish or defend legal claims — each kept only for the period stated in our Privacy Policy's retention schedule. Our response will tell you exactly what we kept, and why. You can also act directly, at any time while you are alive, through the in-app paths in Section 8.2 — our Privacy Policy describes exactly what deletion covers.

8.6 How withdrawing consent works. Most of it you can do yourself, right now, in the app. If you are a parent or guardian who gave consent so a member aged 13 to 17 could arm their messages, you can withdraw that consent in the app, and their plan disarms. The inactivity switch is different in one honest respect. We collect check-in data because it is necessary to provide the service you asked us for, not on the basis of consent, so there is no consent here to withdraw: you can turn the switch off whenever no messages are waiting to be delivered, but while messages still wait we keep it on, because that check is the only thing that would notice if you had died with goodbyes still armed. Set those messages aside first, which keeps them safe without keeping them waiting, and then the switch turns off; deleting your account in the app ends this collection entirely. That is about the check itself, not the channels it travels on: you can stop check-in text messages at any time by replying STOP, and the check-ins simply continue by push notification and email, as our SMS & Communications Terms explain. For anything else — including withdrawing consent you gave as a trustee or recipient — email us with the subject "Health Data Request" and we will act on it.

8.7 Words about you written by someone else. If a public memorial tribute reveals health information about you — a living person — you may ask us to remove it, even though another member wrote it. You can report the post in the app, which is the fastest route, or use the request process in Section 8.2.

8.8 Members who have passed away. The rights in this section belong to living people. We preserve the accounts and sealed messages of members who have passed away, because delivering their words is the promise they trusted us with. One thing is different, and it is the member's own choice: if someone asked us to delete their account and passed away during the 30 days before that deletion becomes permanent, the deletion still finishes — we do not overrule a decision they made about their own account. The messages they had armed, and asked us to keep delivering when they deleted, still reach the people they chose, through the small delivery archive our Privacy Policy describes.

9. Appeals

9.1 If we decline all or part of your request, we will tell you why. You may appeal by replying to our decision or by emailing support@givepeace.co with the subject line "Health Data Appeal".

9.2 We will review your appeal with fresh eyes and respond in writing within 45 days of receiving it, explaining our decision and the reasons for it.

9.3 If we deny your appeal, you may raise the matter with your state's Attorney General: in Washington, at www.atg.wa.gov/file-complaint; in Nevada, at ag.nv.gov. Our appeal response will include this information again, so you always have it in hand.

10. Changes to This Policy

10.1 The version number and effective date appear at the top of this policy. If we make a material change, we will give you at least 30 days' advance notice by email and in the app before the change takes effect.

10.2 We archive prior versions and will provide them on request to support@givepeace.co.

11. Contact Us

Before you write to us, please check our Help page at givepeace.co/help. Most questions — about your account, your messages, trustees, delivery, purchases, and your rights — are answered there, and it is the same page our support team relies on.

Give Peace Inc. support@givepeace.co givepeace.co

For requests under this policy, use the subject line "Health Data Request". For appeals, use "Health Data Appeal". If anything in this policy is unclear, write to us — on an app like this, the answer to "what does this mean for me?" should never be a mystery.

Consumer Health Data Privacy Policy v1.0 — Effective October 3, 2026