Consumer Health Data Privacy Policy

Consumer Health Data Privacy Policy

MedSense Labs, LLC d/b/a Brux Aware Last Updated: September 8, 2026

This policy describes how we collect, use, share, and delete consumer health data as that term is defined by the Washington My Health My Data Act, Nevada SB 370, and comparable state laws. It applies in addition to our Privacy Policy. Where the two differ about consumer health data, this policy controls.

Brux Aware is a general wellness product intended to help you become more aware of recognized clenching activity and related usage patterns to support stress management, promote relaxation, and encourage general sleep hygiene. It is not a medical device and does not diagnose, treat, cure, mitigate, or prevent any disease or condition. Some of what it records is nonetheless treated as consumer health data by these laws, and we handle it accordingly.

The Short Version

  • The Brux Aware sensor records your nights on your phone. That happens whether or not you ever share anything with us.
  • Sharing health data with us is off by default. Nothing leaves your phone until you turn it on.
  • What you share is stored against your account so it can be backed up and restored. Separately, and only if you also say so, a copy stripped of your name, email, and sensor serial joins a pool used to improve Brux Aware.
  • We never sell your personal consumer health data and never use it for advertising. (We may license strictly anonymous, aggregated statistics to researchers, but your individual records are never sold.)
  • You can delete it, all of it, from inside the app, without contacting us. The pooled copy is deleted by the app on your phone, because only your phone holds the random identifier it is filed under.

1. What Consumer Health Data We Collect

Nightly summaries For each night: hours the sensor was worn, number of recognized clenching episodes, total seconds of recognized jaw activity, episodes per hour, average episode length, a relative intensity figure, and your Brux Score.
Linking identifiers Only when you have turned on cloud backup. See Section 4.

What stays on your phone and never reaches us. Raw, moment-by-moment force readings. Your reference bite, the deliberate clench used as your personal scale. Your resting baseline. The temperature the sensor records while you wear it. All of these are used by the app on your own device to work out your score, and none of them is transmitted to us.

What we do not collect at all. We do not collect biometric identifiers such as fingerprints, faceprints, voiceprints, or retina or iris scans. We do not collect precise location. We do not use geofences around health-care facilities.

2. How We Collect It

Only from you, and only through the Brux Aware sensor and the Brux Aware app on your own phone. We do not buy consumer health data, and we do not receive it from data brokers, advertising partners, or any other third party.

3. Why We Collect It

  • To show you your own nights, trends, streaks, and score.
  • To keep a backup of your nights, if you have turned on cloud backup, so a lost or replaced phone does not lose your history.
  • To let our support team help you when you ask, if you have separately allowed that.
  • Where you have provided a separate, affirmative consent, or where the data has been legally de-identified, to understand, in aggregate, whether the product works, and to improve it and develop new features and products.

4. Your Choices: Cloud Backup, and Helping Improve Brux Aware

Collection of consumer health data is off by default. It begins only when you turn it on, and turning it on is a separate, affirmative act. It is never pre-selected, never bundled with your purchase, and never a condition of buying or using the sensor.

The app asks you two separate questions, each with its own unticked box:

Enable cloud backup and linked data. Your nights are stored against your account, which means your email address and the serial number of your sensor. One account may have more than one sensor. This is what makes backup, restore on a new phone, and support able to see your nights possible. If you leave this off, nothing about your nights leaves your phone.

Help improve Brux Aware. Offered only once backup is on, and never pre-selected. If you also agree to this, a copy of your nightly summaries is stored in a research pool under a random identifier generated on your phone. Your email address and your sensor serial number are not sent with it and are not stored with it. There is no lookup table, anywhere, that connects that random identifier back to your account. We use the pool for research, development, and improving the product, as described in Section 8.

What the pooled copy costs you, stated plainly. Because we cannot tell which pooled records are yours, we cannot restore them to a new phone and cannot show them to support to help you. Everything you have recorded still lives on your phone and in your backup. Because the pooled copy is tied only to a random identifier held on your phone, the app on that phone is the only thing that can delete it. Switching Help improve Brux Aware off, turning backup off, or deleting your account in the app sends that identifier to our servers with an instruction to purge every record filed under it. If you lose the phone, or erase the app before switching it off, the pooled copy cannot be found and cannot be deleted remotely by our team. We think that is the right trade for people who want to contribute without being identifiable, and we would rather say it than let you discover it later.

You may change either choice at any time in the app. Withdrawal is prospective. It stops future collection and deletes what we hold: your linked nights when you turn backup off, and the pooled copy when you turn Help improve Brux Aware off. It does not reach into aggregate figures already computed, which are described in Section 8.

5. Who We Share It With

We do not sell consumer health data. We do not share it for targeted advertising. We do not disclose it to advertising, analytics, or marketing partners in any form that identifies you.

We share it only with service providers who process it on our instructions and for no purpose of their own:

Vercel Inc. Application hosting, United States
Neon Inc. Managed database, United States

We may also disclose consumer health data at your direction, with your consent, to comply with a legal obligation, or in connection with a merger, acquisition, or sale of assets, in which case we will give notice as required by law.

If you affirmatively choose to enable health platform integrations (such as Apple Health or Google Health Connect), we will share your data with those platforms based on your device permissions. Once exported, that data becomes subject to the respective privacy policies of those third-party platforms.

6. Who Inside Brux Aware Can See It

Access is limited to the people who need it to run the service or to answer a support request you have made.

Today Brux Aware is a very small company and there is one administrator account, used by a company officer. We are building a second, limited role for support staff that can see your device, its settings, its battery and connection health, and whether it has been syncing, but cannot open your individual nights unless you have turned on support access. Until that exists, nobody else is given access. We will update this policy when it ships.

Every read is logged. Each time anyone at Brux Aware opens individual health data, our system records who, when, whose sensor, and how much was returned. You may request that record by emailing us.

The pooled copy cannot be viewed by anyone at Brux Aware as belonging to a person, because it is not connected to one.

7. Your Rights

You may confirm whether we hold consumer health data about you, access it and receive a copy, delete it including directing our processors to delete it, and withdraw consent at any time.

Two ways to exercise them:

  1. In the app. Turn backup or Help improve Brux Aware off, or use Delete my account. All act immediately and none requires contacting us.
  2. By email. hello@bruxaware.com with the subject line “Consumer Health Data Request.”

We respond within 45 days, and may extend once by a further 45 days where the law allows, telling you why. There is no charge. If we decline a request we will say why, and you may appeal by replying to our response. If we deny the appeal, you may contact the Washington State Attorney General or your own state’s Attorney General.

We will not deny you goods or services, charge you a different price, or give you a lesser experience because you exercised these rights.

One limit, stated honestly. We cannot access, correct, or manually delete the pooled copy if you contact us by email, because we cannot identify those records as yours. To delete the pooled copy, use the app on the phone that shared it: switch Help improve Brux Aware off, turn backup off, or delete your account. Any of these securely directs our servers to purge the records filed under your phone’s random identifier. That is the point of the setting, and it is why the app tells you so before you choose it.

8. Deletion, and What Survives It

When you delete your consumer health data, we delete the individual records we hold for you and direct our service providers to do the same.

What survives, and why. Figures already calculated across many people, for example the median night across all Brux Aware sensors in a given month, are not reversed. We have not yet published or licensed any such figure. Our rule, before we do, is that identifiers are removed and any figure derived from fewer than five people is suppressed, so that no remaining number can be traced to an individual. We do not attempt to re-identify de-identified data, and we require by contract that anyone who receives it does not either.

How we use aggregate data. We use strictly de-identified and aggregated information to improve Brux Aware, develop new features and new products, publish general findings about jaw activity, and, where it is lawful to do so, to license de-identified datasets to third parties such as researchers. Because this data is fully anonymized and de-identified so that it cannot be linked back to you, it is no longer considered "consumer health data". To ensure your privacy, nothing licensed or published identifies you, no individual record is ever included, and we contractually prohibit any third-party recipient from attempting to re-identify the data.

Operational information about the sensor itself, its serial number, firmware version, battery and connection history, is not consumer health data and is retained as inventory and product-safety history after the sensor stops being associated with you.

9. How Long We Keep It

We keep linked consumer health data for as long as your account holds it, and delete it when you delete it or close your account. Copies may persist for a short period in our hosting provider’s routine backups before those are overwritten in the ordinary course. De-identified aggregates are kept indefinitely as described in Section 8.

10. How It Is Protected

Health data travels over encrypted connections and is stored separately from the operational records of your device, in its own table that the operational parts of the service do not read. Sign-in credentials are never stored in readable form. Access is limited as described in Section 6, every access to individual health data is logged, and the servers that accept health data reject any submission that does not carry a record of the consent that permitted it.

11. Changes

If we materially change how we handle consumer health data, we will post an updated policy and, where the law requires, obtain your consent before the change applies to data already collected.

12. Contact

MedSense Labs, LLC, doing business as Brux Aware
Email: hello@bruxaware.com, subject line “Consumer Health Data Request”
Mailing address: 2 N. Lake Ave., Suite 520, Pasadena, CA 91101
Website: www.bruxaware.com