Xenter

XenME Consumer Privacy Notice

Last Updated: August 6, 2026

1. Introduction and Scope

Xenter, Inc. and its subsidiaries (“Xenter,” “we,” “us,” or “our”) respect your privacy and are committed to handling personal information responsibly.

This Privacy Notice describes how we collect, use, disclose, and process personal information when you use XenME, and any other Xenter application or service that lets you as an individual consumer (a) connect and aggregate your health records from other healthcare providers, health plans, and health information networks, (b) connect to wearable and fitness data platforms — such as Garmin Connect, Apple Health, and Whoop — that collect data from your wearable devices, so that Xenter can pull that data into a combined view of your health information, and (c) receive results of diagnostic assessments your healthcare provider has arranged for Xenter to perform (collectively, the “Services”).

This Notice applies to you if you are an individual consumer using the Services. It does not apply to Xenter’s corporate websites, or to Xenter’s relationships with healthcare provider customers and other business partners, which are addressed in the separate Xenter Website & Business Privacy Notice, available at xenter.io/privacy.

In addition, if your healthcare provider has engaged Xenter to perform a diagnostic assessment — such as Xenter's Cognitive Assessment Program — your provider may ask you to use XenME to receive your results. That category of information is addressed separately in Section 3 below and is governed by HIPAA and your provider's HIPAA Notice of Privacy Practices, not by the consumer-focused provisions of this Notice.

When we provide the Services directly to you, Xenter acts as:

  • A business/controller of the personal information described in this Notice;
  • A non-HIPAA-covered health service provider — because we do not conduct HIPAA standard transactions, Xenter is not a HIPAA covered entity when we provide the Services directly to you. We nonetheless collect sensitive health information, which is governed by applicable state consumer health-data laws and FTC rules — not HIPAA; and
  • A HIPAA Business Associate — when your healthcare provider has engaged Xenter to perform a diagnostic assessment (such as our Cognitive Assessment Program) and has directed us to deliver your results to you through XenME. See Section 3.

Much of the health and claims information in your aggregated record originates with a healthcare provider or health plan that is itself subject to HIPAA. When you connect an account or authorize a data-sharing request, you are directing that provider or plan to release your records to Xenter, using the data-sharing APIs that healthcare providers and health plans are required to make available under federal interoperability rules. Once Xenter receives that information, it is no longer subject to HIPAA in our hands — it is instead governed by this Notice, the FTC Health Breach Notification Rule (see Section 17), and applicable state law. (Legal basis: 45 CFR §164.524; 21st Century Cures Act Information Blocking Rule; CMS Interoperability and Patient Access Rule.)

This is different from the diagnostic assessment results described in Section 3, which Xenter delivers to you as your provider's Business Associate, and which remain governed by HIPAA even after you receive them in XenME.

3. Diagnostic Assessment Results From Your Healthcare Provider

Some healthcare providers may engage Xenter to perform a diagnostic assessment as part of your care — for example, Xenter's Cognitive Assessment Program, which utilizes an EEG+ERP test and/or various laboratory tests to enable your provider to better diagnose and/or assess risks for Alzheimer's, dementia, traumatic brain injury and/or other cognitive impairment. When this happens:

  • Xenter performs the EEG+ERP test (and may arrange for a contracted clinician, such as a reviewing neurologist, to interpret it) under a Business Associate Agreement (“BAA”) with your healthcare provider;
  • A licensed laboratory performs any laboratory tests requisitioned by your healthcare provider;
  • Your provider's BAA with Xenter authorizes us to ask you to use XenME so that your results can be delivered to you, alongside delivering them to your ordering provider; and
  • If and as additional assessments are added to this program or other diagnostic-enabling programs in the future, results from those tests may also be delivered to you through XenME under this same framework.

This category of information is governed by HIPAA and by your healthcare provider's HIPAA Notice of Privacy Practices — not by the rest of this Notice. In particular:

  • Your ordering healthcare provider, not Xenter, is responsible for fulfilling your HIPAA rights with respect to these results (including access, amendment, accounting of disclosures, and restriction requests). If you have questions about these results or want to exercise those rights, contact your ordering healthcare provider directly.
  • This information is not “consumer health data” for purposes of the Washington My Health My Data Act or Nevada law, and is separately exempt from the CCPA/CPRA as protected health information collected by a HIPAA Business Associate (Cal. Civ. Code §1798.145(c)(1)(A)), because it is protected health information governed by HIPAA.
  • Your provider's BAA with Xenter permits us to de-identify this information in accordance with HIPAA's de-identification standard (45 CFR §164.514), including for research, product development, and quality improvement. Once de-identified in accordance with that standard, the information is no longer protected health information.

For more information about how Xenter handles information as a Business Associate, see Section 9 of the Xenter Website & Business Privacy Notice, available at xenter.io/privacy.

4. Washington Residents

If you are a resident of Washington State, or your consumer health data is collected in Washington, our processing of your consumer health data is governed exclusively by our separate Washington Consumer Health Data Privacy Notice, and not by this general Privacy Notice. The Washington Consumer Health Data Privacy Notice is available at xenter.io/consumer-health-privacy.

5. Nevada Consumer Health Data Notice

If you are a Nevada resident, your consumer health data collected through the Services — including records aggregated from your providers and health plans and data pulled from the wearable and fitness platforms you connect — may be subject to Nevada law (NRS 603A.400 to 603A.550). Xenter will not collect or share your consumer health data without your consent, and you may withdraw consent at any time by contacting privacy@xenter.io.

Xenter will obtain your authorization before connecting a new data source and will provide you with a clear description of the data to be collected and how it will be used before you authorize the connection.

6. Categories of Personal Information Collected

The following table summarizes the categories of personal information we collect through the Services, the sources, our purposes, and to whom we disclose it. Retention periods are described in Section 16.

CategoryExamplesSourcesPurposesDisclosures

Identifiers

Name, email address, date of birth, mailing address, mobile phone number, device IDs

Directly from you

Account management; communication

Service providers

Internet & App Activity

App usage data, log files

The app; analytics tools

Improve the app; security; analytics

Service providers

Diagnostic Assessment Results

Test data and diagnostic reports (e.g., EEG/ERP data and neurologist report from the Cognitive Assessment Program)

A diagnostic test performed by Xenter (or its contracted clinicians) at your healthcare provider's direction, under a Business Associate Agreement

Delivering your results to you and your ordering provider — see Section 3

Your ordering healthcare provider; governed by HIPAA, not by this table — see Section 3

Health & Clinical Data (Aggregated Records)

Diagnoses, medications, lab results, clinical notes, immunizations

Your healthcare providers, via a connection you authorize; health information networks/exchanges

Building and displaying your combined health record; enabling you to share it as you direct

Only recipients you direct — see Section 10; authorized vendors; as required by law

Insurance & Claims Information

Coverage details, claims history, plan benefits

Your health plan(s), via a connection you authorize

Building and displaying your combined health record

Only recipients you direct — see Section 10

Wearable & Fitness Data (Biometric Information)

Heart rate, heart rate variability, sleep stages, blood oxygen, activity/steps, stress or recovery scores

Wearable and fitness platforms you connect (e.g., Garmin, Apple Health, Whoop)

Building and displaying your combined health record; trend summaries (see Section 14)

Only recipients you direct — see Section 10; authorized vendors

Precise Geolocation Data

GPS location and routes recorded during workouts by connected wearables/apps

Wearable and fitness platforms you connect

Displaying workout/activity history you have connected

Not disclosed except as required by law

Account & Authentication Credentials

Login credentials or access tokens for provider portals, health plans, and wearable platforms

Directly from you, when you authorize a connection

Establishing and maintaining connections to your other accounts, at your direction

Not disclosed to any third party

Inferences

Trends or summaries derived from the above

Derived internally

Helping you understand your health information over time

As described above

7. Sources of Personal Information

  • Directly from you — when you use the Services, create an account, or contact us;
  • Your healthcare providers — via a patient-portal connection or FHIR/API connection you authorize (for example, connecting your hospital's patient portal pulls in your visit notes and lab results);
  • Your health plan(s) — via a connection you authorize, for claims and coverage information;
  • Health information networks and exchanges (e.g., CareQuality, CommonWell) — used to help locate and retrieve your records when a direct connection is not available;
  • Wearable and fitness platforms you connect (for example, connecting Garmin Connect, Apple Health, or Whoop can bring in data like your heart rate, sleep, and activity, depending on what that platform tracks and what you’ve authorized);
  • Family members whose records you are authorized to manage within your account, for example if you are a parent adding a child's records (see Section 11); and
  • Publicly available sources.

8. How We Use Personal Information

  • Providing, operating, and improving the Services, including retrieving, combining, and displaying your health, claims, and wearable data;
  • Enabling you to view, organize, and share your own health information as you direct;
  • Conducting research, development, and quality improvement;
  • Communicating with you about the Services;
  • Maintaining system security, integrity, and fraud prevention;
  • Complying with legal and regulatory obligations; and
  • Analytics to develop new or improved products and services — using de-identified or aggregated data where possible (see Section 16).

Sensitive personal information (including health, claims, and wearable data) is processed only for the purposes described above and not for inferring characteristics unrelated to the Services, except as separately authorized by you.

When we de-identify or aggregate personal information so that it can no longer reasonably be used to identify you, we commit to maintain and use that information only in de-identified or aggregated form, and we take reasonable measures to prevent it from being re-identified. Once information has been de-identified or aggregated in this way, it is no longer “personal information,” and this Privacy Notice no longer applies to it.

9. Disclosure of Personal Information

We do not sell your personal information.

Outside of the diagnostic assessment results described in Section 3 (which your ordering healthcare provider also receives, as explained there), Xenter does not automatically send your aggregated health record to any healthcare provider, health plan, or other party. We share personal information only with:

  • Recipients you choose — when you use the Services to share your record with a person or organization; see Section 10;
  • Service providers — vendors that provide hosting, IT support, security, analytics, and other operational services on our behalf under contractual data protection obligations;
  • Regulatory authorities and law enforcement — when required by applicable law, court order, or to protect legal rights; and
  • Successors — in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.

We do not knowingly sell or share the personal information of minors under the age of 16.

We do not disclose personal information to third parties for their own direct marketing purposes.

10. Your Choice to Share Your Information

The Services let you share your aggregated health record with people and organizations you choose — for example, by generating a shareable link, downloading a copy, or adding records to a digital wallet.

  • You control what you share and with whom. You may revoke or set an expiration on a share where the Services provide that option.
  • Once a recipient has accessed information you shared, that copy is no longer in Xenter’s control. The recipient’s use of it is governed by their own privacy practices, not this Notice.
  • We recommend sharing only with people and organizations you trust, and reviewing a recipient’s own privacy practices before sharing sensitive health information with them.

11. Family Members and Dependents

If you add or manage health information for a family member or dependent within your account, you represent that you have the legal authority to do so — for example, as the parent or legal guardian of a minor child, or as an authorized representative or holder of a healthcare power of attorney for an adult dependent. You are responsible for that individual’s information within your account, including for exercising or responding to privacy rights requests on their behalf where applicable.

Where a family member’s records include a minor child’s health information, see Section 18 (Children’s Privacy) for how we apply COPPA and applicable state law to that information.

12. Sensitive Personal Information

Certain categories of personal information we collect through the Services are considered “sensitive” under applicable law, including:

  • Health and clinical data aggregated from your providers and health plans (consumer health data);
  • Wearable and fitness data, including sleep, heart rate, and exercise data, which is expressly included within the statutory definition of “biometric information” under the California Consumer Privacy Act;
  • Reproductive or sexual health information, if included in records you connect (for example, from certain Apple Health data categories); and
  • Precise geolocation data derived from connected wearable or fitness platforms.

We collect and use sensitive personal information only to:

  • Provide the Services you have requested, including retrieving, combining, and displaying your aggregated record;
  • Share your information with recipients you direct, as described in Section 10;
  • Comply with applicable law; and
  • Maintain the security and integrity of our systems.

We will obtain your affirmative authorization (opt-in consent) before connecting a new data source and collecting consumer health data, as required by applicable state law. California residents may also request to limit the use of their sensitive personal information for purposes beyond those described above.

13. Your U.S. Privacy Rights

Depending on your state of residence, you may have the rights described in the table below.

RightDescriptionHow to Exercise

Access / Know

Request a copy of personal information we hold about you

Submit via email or web form

Delete

Request deletion of personal information

Submit via email or web form

Correct / Rectify

Request correction of inaccurate information

Submit via email or web form

Portability

Receive a copy in portable format

Submit via email or web form

Opt Out of Sale / Sharing

Opt out of sell or sharing of personal information for targeted advertising

N/A – we do not sell or share personal information for targeted advertising.

Opt Out of Profiling

Opt out of profiling for significant decisions

We do not profile for significant decisions

Limit Sensitive PI Use

Limit use of sensitive personal information beyond certain purposes

Submit via email

Consent Withdrawal (Health Data)

Withdraw authorization for collection or sharing of consumer health data, including disconnecting a data source

Contact privacy@xenter.io, or disconnect within the app

Non-Discrimination

Exercise rights without discriminatory treatment

Automatic

A. How to Submit a Request

  • Email: privacy@xenter.io (include “Privacy Rights Request” in the subject line)
  • Web form: xenter.io/privacy-request
  • Toll-free phone: 1-888-238-7204

We will verify your identity before processing your request. We will respond within the timeframe required by your state’s law.

B. Appeals

If we deny your request, you may appeal our decision within 30 days by emailing privacy@xenter.io with “Privacy Rights Appeal” in the subject line. We will respond within the timeframe required by your state’s law. If your appeal is denied, you may contact your state’s Attorney General.

C. Global Privacy Control (GPC) and Opt-Out Signals

We recognize and honor browser-based opt-out preference signals, including Global Privacy Control (GPC), as required by applicable law, wherever you access the Services through a web browser. If we detect a GPC signal, we will treat it as a request to opt out of the sale or sharing of your personal information for targeted advertising purposes. Because we do not currently sell or share personal information for cross-context behavioral advertising (see Section 15), honoring a GPC signal has no practical effect on your experience of the Services today. We are nonetheless configured to detect and honor GPC signals wherever they are technically transmitted, and will apply them automatically if our practices change.

D. Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights, except as permitted by law.

14. Profiling and Automated Processing

The Services may use automated processing to generate summaries, trends, or other insights from your aggregated health, claims, and wearable data, to help you understand your own health information over time. Xenter does not use this processing to make automated decisions that produce legal or similarly significant effects on you.

If this changes — for example, if the Services begin generating risk scores, health assessments, or similar outputs — residents of Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other states that have enacted automated decision-making rights may have the right to opt out of automated profiling that produces decisions with legal or similarly significant effects, and we will update this Notice accordingly and provide the applicable opt-out mechanism.

If you have questions about automated processing, contact privacy@xenter.io.

15. Tracking Technologies

The app uses first-party analytics and service-provider technologies to operate, secure, and improve the Services. These technologies may collect device and app-usage information, diagnostic data, and approximate location derived from your device, and are used to make the Services work, measure and improve performance, maintain security, and troubleshoot issues. We do not currently use these technologies for targeted advertising, cross-context behavioral advertising, or third-party advertising networks.

You can control certain tracking through your device and app settings. If you disable these settings, some features of the Services may not function properly.

16. Data Retention

Data CategoryRetention Period

Identifiers and account information

Duration of your account + 3 years, or as required by applicable law

Diagnostic assessment results (e.g., Cognitive Assessment Program)

Governed by the applicable Business Associate Agreement with your healthcare provider and by HIPAA — not by this table. See Section 3.

Aggregated health and claims records

Duration of your account, then securely deleted

Wearable and fitness data

Duration of your account, then securely deleted

Account and authentication credentials/tokens

Retained only as needed to maintain an active connection; deleted promptly upon disconnection or account closure

App and network activity data

13 months from collection, unless a shorter period is required by law

Records of privacy rights requests

2 years from date of request

De-identification for Research and Analytics

We may retain de-identified or aggregated data for longer periods for research, analytics, and product and service development. See Section 8 for our commitments regarding de-identified and aggregated information.

17. Data Security

We have implemented commercially reasonable technical, administrative, and physical security safeguards designed to protect your personal information from unauthorized access, use, disclosure, deletion, and modification. These measures include encryption of data in transit and at rest, access controls, and regular security assessments.

Because the Services rely on credentials and access tokens to connect to your provider, health plan, and wearable accounts, we apply additional safeguards to that information specifically, including encrypted storage, use of revocable access tokens where supported by the connected platform rather than storing your passwords directly, and prompt deletion of credentials/tokens upon disconnection.

No security measures are perfect or impenetrable, and we cannot guarantee that your information will not be accessed, disclosed, altered, or destroyed by a breach of our safeguards.

XenME combines health records from multiple sources and is likely to qualify as a personal health record (PHR) related service provider under the FTC Health Breach Notification Rule (16 CFR Part 318), as updated. In the event of a breach of unsecured identifiable health information, we will notify affected individuals, the Federal Trade Commission, and, where required, prominent media outlets, within the timeframes specified by applicable law. We will also comply with applicable U.S. state breach notification laws, which impose varying timelines (generally 30–90 days) and scope requirements across all 50 states and territories.

18. Children's Privacy

The Services are not directed at children under the age of 13, and we do not knowingly collect personal information directly from children under 13. If you add or manage a family member’s or dependent’s records within your account (see Section 11) and that individual is a minor:

  • We treat the information as furnished by a parent or guardian on the child’s behalf, and obtain parental or guardian consent in accordance with COPPA and applicable state law before providing the Services with respect to that child;
  • Parents or guardians may exercise privacy rights on behalf of minor children by contacting privacy@xenter.io; and
  • California residents between the ages of 13 and 15 must affirmatively opt in before Xenter sells or shares their personal information.

If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact us at privacy@xenter.io and we will take prompt steps to delete that information.

19. Additional Disclosures

International Data Transfers

Xenter is headquartered in the United States. If you are accessing the Services from outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other jurisdictions where data protection laws may differ from those in your home country.

California “Shine the Light” Notice

Under California Civil Code §1798.83, California residents may request certain information about disclosures of personal information to third parties for direct marketing purposes.

Xenter does not disclose personal information to third parties for their own direct marketing purposes. Accordingly, no such disclosure list exists.

Changes to This Privacy Notice

We may update this Privacy Notice periodically to reflect changes in our practices, applicable law, or other operational, legal, or regulatory requirements. Changes will be reflected by updating the “Last Updated” date at the top of this Notice. For material changes affecting how we handle your personal information, we will provide additional notice (such as by email or an in-app notice) where required by law.

We encourage you to review this Notice periodically to stay informed about how we protect your information.

20. Contact Information

For questions about this Privacy Notice, to exercise your privacy rights, or to raise a concern about our data practices, please contact:

Xenter, Inc.

344 West 13800 South, Suite 400

Draper, Utah 84020, United States

For MHMD requests (Washington residents): Include “MHMD Request” in the subject line.

For U.S. privacy rights requests: Include “Privacy Rights Request” in the subject line.

For privacy rights appeals: Include “Privacy Rights Appeal” in the subject line.

If you are a healthcare provider, business partner, or website visitor, please see the Xenter Website & Business Privacy Notice at xenter.io/privacy.