Valdura Privacy Policy
Last updated: July 24, 2026.
This Privacy Policy explains how Valdura Health (a limited liability company, "Valdura," "we," "us," or "our") collects, uses, shares, and protects your information when you use the Valdura app and related services. Valdura Health LLC is not a HIPAA covered entity. We have chosen to protect your health information to HIPAA-grade standards anyway, and we rely on the established HIPAA compliance program of our affiliated company, Crystal Clear RX Wellness LLC, under a written intercompany services agreement, as explained in Section 1. Your enforceable privacy rights are set by consumer health-data laws, principally the Washington My Health My Data Act and the California Consumer Privacy Act as amended (CCPA/CPRA).
Plain-language summary
Valdura is an AI-first health platform. To help you understand your bloodwork and health data, we collect the information you give us (account details, lab results, health history, and, if you choose to connect a device, wearable data), and we use it to power your AI health assistant, to let our licensed clinicians review any guidance that is prescription-adjacent or could change your care plan, and to route product recommendations. Our production AI runs on Anthropic's Claude API, in the United States, on models that do not train on your data, under a Business Associate Agreement. We do not sell your personal or health information, and we run no third-party advertising or analytics trackers. You can access, export, correct, or delete your data at any time, and we honor deletion requests within 30 days, including from our backups. Questions or requests go to privacy@valdura.health.
1. Who we are and the scope of this policy
Valdura Health operates the Valdura platform: a text-based AI health assistant that interprets your bloodwork and health data and gives you guidance, an optional bloodwork membership (an annual baseline panel plus add-ons, drawn at a lab partner or at your home), a network of licensed-clinician advisors who review AI output that is prescription-adjacent or care-plan-changing before it reaches you, and partner-routed product recommendations.
This policy applies to the information we handle when you create a Valdura account, use the app, connect a device, order labs, or otherwise interact with our services. It applies to our website at www.valdura.health and to the mobile app.
Who is responsible for your health information. Valdura Health LLC operates the Valdura platform and brand. Valdura is a direct-to-consumer, cash-pay service: it does not bill health insurance and does not submit any healthcare claim to a health plan, which is the activity that would bring a provider under HIPAA. For that reason Valdura is not a HIPAA covered entity. We have nonetheless chosen to protect your health information to HIPAA-grade standards. Valdura Health LLC and Crystal Clear RX Wellness LLC are affiliated companies under common ownership and shared personnel, and under a written intercompany services agreement Valdura relies on Crystal Clear RX Wellness's established HIPAA compliance program: its policies, procedures, technical safeguards, workforce, and training. The agreements that cover the vendors handling your data are held under our shared compliance program with Crystal Clear RX Wellness LLC: a Business Associate Agreement with each infrastructure vendor and with our AI provider. Your enforceable privacy rights are set by consumer health-data laws, principally the Washington My Health My Data Act and CCPA/CPRA, and we commit to the practices described in this policy. When this policy refers to what "we" do with your information, it refers to Valdura operating under this program.
Valdura is intended only for adults 18 years of age and older. See the "Children" section below.
A note on emergencies: Valdura is not an emergency service and is not a substitute for professional medical judgment. If you are experiencing a medical emergency, call 911 or your local emergency number immediately.
A note on health-privacy laws: Valdura is not a HIPAA covered entity (see Section 1). This policy is nonetheless written to honor the spirit and substance of HIPAA, and your enforceable rights come from consumer health-data laws, including the Washington My Health My Data Act and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), where they apply to you. Valdura relies on the HIPAA compliance program of its affiliated company, Crystal Clear RX Wellness LLC, under a written intercompany services agreement (see Section 1). We commit to the data practices and protections described here.
2. Information we collect, and how we collect it
We collect the categories of information below. Much of this is information you provide directly. Some is generated as you use the service, and some comes from sources you connect.
Account and contact information. Your name, email address, phone number, date of birth, biological sex, and zip code. You provide this when you sign up and manage your account.
Bloodwork and biomarker results. The results of any baseline panel or add-on tests you order through your membership, and any lab results you upload yourself.
Wearable and device data. If, and only if, you choose to connect a wearable or device (for example, an Oura ring, a Whoop band, or a Garmin device), we receive data such as sleep, heart rate, heart-rate variability (HRV), and activity. We do not receive this data unless you authorize the connection, and you can disconnect at any time.
Self-reported health information. Health history, lifestyle details, and the goals you share with us, whether through intake or in conversation with the AI assistant.
AI chat conversations. The text of your conversations with the AI health assistant, so the assistant can give you continuous, context-aware guidance and so a clinician can review clinical-adjacent output.
Uploaded documents and photos. Files you upload, such as lab PDFs and meal photos.
App usage information. Basic information about how you use the app, which we use to operate, secure, and improve the service.
Consumer health data. Much of what we collect (bloodwork and biomarkers, wearable streams, health history, AI conversations about your health, and uploaded health documents) is "consumer health data" under laws like the Washington My Health My Data Act. We treat all of it as sensitive and handle it according to this policy and your authorizations.
We do not buy personal or health information about you from data brokers, and we do not run third-party advertising or analytics trackers that would collect information about you across other apps or websites.
3. How and why we use your information
We use your information for the following purposes, and not for unrelated purposes without your consent.
To provide the service. We use your data to power your AI health assistant, to interpret your lab results, to track your biomarkers and health data over time (longitudinal tracking), and to generate recommendations tailored to you.
Clinician review. When the AI produces output that is prescription-adjacent or could change your care plan, a licensed clinician in our advisor network reviews that output before it reaches you or before you act on it. To do this, the reviewing clinician sees the relevant parts of your information.
AI processing on a secured US rail. Our production AI inference runs on Anthropic's Claude API, in United States regions, on models that do not train on, or share, your data. Anthropic retains what it processes only briefly (up to 30 days, for security and abuse monitoring) and then deletes it. Anthropic processes this data under a Business Associate Agreement. The AI does not make clinical decisions autonomously. As described above, clinical-adjacent output is reviewed by a licensed clinician before you act on it.
Partner-routed recommendations. When we recommend a product, we may route you to a partner. As explained in the "How and with whom we share your information" section, our recommendation partners receive only de-identified, per-click attribution tokens, never your health data or stable identifiers.
Service operations and security. We use your information to operate, maintain, secure, troubleshoot, and improve the platform, to prevent fraud and abuse, to keep audit logs, and to meet our legal and compliance obligations.
We do not use your information for third-party advertising, and we do not use third-party analytics trackers.
4. How and with whom we share your information
We share your information only in the limited ways described below. We do not sell your personal or health information, and we do not share it with third parties for their own advertising.
Service providers (subprocessors). We rely on a small set of vendors to run the platform, and each may use your data only to provide services to us. Our infrastructure vendors (Vercel, Neon, and Paubox) each operate under a signed Business Associate Agreement held by Crystal Clear RX Wellness LLC under our shared compliance program; our AI provider, Anthropic, operates under a signed Business Associate Agreement held by the same program. These vendors are:
- Vercel, for application hosting, including Blob object storage for the lab files and documents you upload.
- Neon, for our database.
- Anthropic, for AI inference on the Claude API (United States regions; models that do not train on your data; under a Business Associate Agreement).
- Paubox, for encrypted email.
Lab partners. When you order labs, a lab partner (Quest, Labcorp, or Getlabs) processes your order and returns your results so we can interpret them for you.
Connected wearable providers. When you connect a wearable, the provider (Oura, Whoop, or Garmin) shares your device data with us under your authorization. You control this connection and can revoke it at any time.
Clinician advisor network. Our licensed clinicians review clinical-adjacent AI output before it reaches you, as described above. They access only the information needed to perform that review.
Recommendation partners (de-identified only). When you click a product recommendation, we route the click to a recommendation partner (the retail partner storefront tied to your membership for supplements, or Avellum for peptide protocols) for attribution. These partners receive only a de-identified, per-click attribution token. They do not receive your health data, your name, or any stable identifier that would let them recognize you across visits.
Legally required disclosures. We may disclose information when we are legally required to do so, for example in response to a valid subpoena, court order, or other lawful request, or where disclosure is necessary to protect the rights, safety, or security of our members, the public, or Valdura. Where the law permits, we will limit any such disclosure to what is required.
Business transfers. If Valdura is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will require the successor to honor this policy, and we will notify you of any change in who controls your information or any material change in how it is handled.
We do not sell your personal or health data, we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, and we run no third-party ad or analytics trackers.
5. Your privacy rights and how to exercise them
You have the following rights regarding your information. These rights apply to all Valdura members, and they include the rights granted by laws such as the Washington My Health My Data Act and the CCPA/CPRA.
- Access and a copy. You can ask to access the personal and health information we hold about you and to receive a copy of it.
- Deletion. You can ask us to delete your information. We honor deletion requests without undue delay and within 30 calendar days. Deletion reaches our backups and is passed through to our subprocessors, consistent with the Washington My Health My Data Act and similar consumer health-data laws. We retain only a de-identified audit trail, which does not identify you.
- Correction and amendment. You can ask us to correct or amend information about you that is inaccurate or incomplete.
- Withdraw an authorization. Where we rely on your authorization (for example, to receive data from a connected wearable, or to collect or share consumer health data), you can withdraw that authorization at any time. Withdrawing an authorization does not affect processing that already took place while it was in effect.
- Opt out of marketing. You can opt out of marketing communications at any time, including by using the unsubscribe link in any marketing email.
- Data portability and export. You can ask us to export your data in a portable, machine-readable format.
- Non-discrimination. We will not discriminate or retaliate against you for exercising any of these rights. Exercising a right will not cause us to deny you service, charge you a different price, or provide you a different level of service, except where a feature genuinely cannot function without the data in question (for example, AI guidance that depends on lab results you have asked us to delete).
How to exercise your rights. Send your request to privacy@valdura.health, which is also the mailbox for our Privacy Officer. We will verify your identity before acting on a request, to protect your information. You may authorize an agent to make a request on your behalf, and we may ask the agent for proof of authorization. We do not charge a fee for most requests. If you believe we have not resolved your request appropriately, you may contact us again at privacy@valdura.health, and you may also have the right to lodge a complaint with the regulator in your jurisdiction.
6. Data security
We protect your information with administrative, technical, and physical safeguards designed for sensitive health data. Our controls include:
- Encryption in transit and at rest. All connections are encrypted using TLS, and your data is encrypted at rest in our database.
- Field-level encryption of sensitive tokens. OAuth tokens for connected devices are encrypted at the field level using AES-256-GCM, and session tokens are stored only in hashed form.
- Role-based access control with audit logging. Access to health data is restricted by role, and every read and write of health data is recorded in an audit log.
- Clinician review. Clinical-adjacent AI output is reviewed by a licensed clinician before it reaches you.
- Launch-flag gate. During our build and beta phases, a launch-flag gate keeps the system on synthetic data until we deliberately enable real data. The agreements covering our production data vendors are in place: a Business Associate Agreement with each infrastructure vendor (Vercel, Neon, Paubox), held by Crystal Clear RX Wellness LLC, and a Business Associate Agreement with our AI provider (Anthropic).
- Secure deletion. A scheduled job permanently purges deleted accounts after a 30-day grace window, while retaining only a de-identified audit trail.
No system can be guaranteed perfectly secure, but we work continuously to protect your information and to improve our safeguards. If you discover a security issue, please report it to security@valdura.health.
7. Data retention
We keep your information for as long as your account is active and as long as we need it to provide the service, to meet our legal and compliance obligations, to resolve disputes, and to enforce our agreements. When information is no longer needed for these purposes, we delete or de-identify it.
When you delete your account or ask us to delete your data, we follow the deletion process described in "Your privacy rights": deletion is honored within 30 calendar days, reaches our backups, and is passed through to our subprocessors. A scheduled purge permanently removes deleted accounts after a 30-day grace window. After that, we retain only a de-identified audit trail, which cannot be used to identify you. Our internal data-retention policy governs the specific retention periods for each category of data, and we update it as our practices and legal obligations evolve.
8. Where your information is processed (US data location)
Valdura is operated from, and stores and processes your information in, the United States. Our production AI inference runs in United States regions on Anthropic's Claude API. If you access the service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.
9. Children
Valdura is intended only for adults who are 18 years of age or older. We do not knowingly collect personal or health information from anyone under 18. If you believe a minor has provided us with information, please contact us at privacy@valdura.health, and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the "Last updated" date above and, where appropriate, notify you in the app or by email before the change takes effect. If a change would require your consent under applicable law, we will obtain it. Your continued use of Valdura after an update means you accept the revised policy, except where your consent is separately required.
11. How to contact us
If you have questions about this policy or about how we handle your information, or if you want to exercise a privacy right, please contact us:
- Privacy and data-rights requests (Privacy Officer): privacy@valdura.health
- Security and incident reports: security@valdura.health
- General support: support@valdura.health
- Website: www.valdura.health
- Mailing address: Valdura Health (privacy@valdura.health)
Valdura Health, a limited liability company. This policy is effective on the launch of the Valdura beta.