XenME Consumer Privacy Notice
Last Updated: August 6, 2026
1. Introduction and Scope
Xenter, Inc. and its subsidiaries (“Xenter,” “we,” “us,” or “our”) respect your privacy and are committed to handling personal information responsibly.
This Privacy Notice describes how we collect, use, disclose, and process personal information when you use XenME, and any other Xenter application or service that lets you as an individual consumer (a) connect and aggregate your health records from other healthcare providers, health plans, and health information networks, (b) connect to wearable and fitness data platforms — such as Garmin Connect, Apple Health, and Whoop — that collect data from your wearable devices, so that Xenter can pull that data into a combined view of your health information, and (c) receive results of diagnostic assessments your healthcare provider has arranged for Xenter to perform (collectively, the “Services”).
This Notice applies to you if you are an individual consumer using the Services. It does not apply to Xenter’s corporate websites, or to Xenter’s relationships with healthcare provider customers and other business partners, which are addressed in the separate Xenter Website & Business Privacy Notice, available at xenter.io/privacy.
In addition, if your healthcare provider has engaged Xenter to perform a diagnostic assessment — such as Xenter's Cognitive Assessment Program — your provider may ask you to use XenME to receive your results. That category of information is addressed separately in Section 3 below and is governed by HIPAA and your provider's HIPAA Notice of Privacy Practices, not by the consumer-focused provisions of this Notice.
2. Our Role and Applicable Legal Frameworks
When we provide the Services directly to you, Xenter acts as:
- A business/controller of the personal information described in this Notice;
- A non-HIPAA-covered health service provider — because we do not conduct HIPAA standard transactions, Xenter is not a HIPAA covered entity when we provide the Services directly to you. We nonetheless collect sensitive health information, which is governed by applicable state consumer health-data laws and FTC rules — not HIPAA; and
- A HIPAA Business Associate — when your healthcare provider has engaged Xenter to perform a diagnostic assessment (such as our Cognitive Assessment Program) and has directed us to deliver your results to you through XenME. See Section 3.
Much of the health and claims information in your aggregated record originates with a healthcare provider or health plan that is itself subject to HIPAA. When you connect an account or authorize a data-sharing request, you are directing that provider or plan to release your records to Xenter, using the data-sharing APIs that healthcare providers and health plans are required to make available under federal interoperability rules. Once Xenter receives that information, it is no longer subject to HIPAA in our hands — it is instead governed by this Notice, the FTC Health Breach Notification Rule (see Section 17), and applicable state law. (Legal basis: 45 CFR §164.524; 21st Century Cures Act Information Blocking Rule; CMS Interoperability and Patient Access Rule.)
This is different from the diagnostic assessment results described in Section 3, which Xenter delivers to you as your provider's Business Associate, and which remain governed by HIPAA even after you receive them in XenME.
3. Diagnostic Assessment Results From Your Healthcare Provider
Some healthcare providers may engage Xenter to perform a diagnostic assessment as part of your care — for example, Xenter's Cognitive Assessment Program, which utilizes an EEG+ERP test and/or various laboratory tests to enable your provider to better diagnose and/or assess risks for Alzheimer's, dementia, traumatic brain injury and/or other cognitive impairment. When this happens:
- Xenter performs the EEG+ERP test (and may arrange for a contracted clinician, such as a reviewing neurologist, to interpret it) under a Business Associate Agreement (“BAA”) with your healthcare provider;
- A licensed laboratory performs any laboratory tests requisitioned by your healthcare provider;
- Your provider's BAA with Xenter authorizes us to ask you to use XenME so that your results can be delivered to you, alongside delivering them to your ordering provider; and
- If and as additional assessments are added to this program or other diagnostic-enabling programs in the future, results from those tests may also be delivered to you through XenME under this same framework.
This category of information is governed by HIPAA and by your healthcare provider's HIPAA Notice of Privacy Practices — not by the rest of this Notice. In particular:
- Your ordering healthcare provider, not Xenter, is responsible for fulfilling your HIPAA rights with respect to these results (including access, amendment, accounting of disclosures, and restriction requests). If you have questions about these results or want to exercise those rights, contact your ordering healthcare provider directly.
- This information is not “consumer health data” for purposes of the Washington My Health My Data Act or Nevada law, and is separately exempt from the CCPA/CPRA as protected health information collected by a HIPAA Business Associate (Cal. Civ. Code §1798.145(c)(1)(A)), because it is protected health information governed by HIPAA.
- Your provider's BAA with Xenter permits us to de-identify this information in accordance with HIPAA's de-identification standard (45 CFR §164.514), including for research, product development, and quality improvement. Once de-identified in accordance with that standard, the information is no longer protected health information.
For more information about how Xenter handles information as a Business Associate, see Section 9 of the Xenter Website & Business Privacy Notice, available at xenter.io/privacy.
4. Washington Residents
If you are a resident of Washington State, or your consumer health data is collected in Washington, our processing of your consumer health data is governed exclusively by our separate Washington Consumer Health Data Privacy Notice, and not by this general Privacy Notice. The Washington Consumer Health Data Privacy Notice is available at xenter.io/consumer-health-privacy.
5. Nevada Consumer Health Data Notice
If you are a Nevada resident, your consumer health data collected through the Services — including records aggregated from your providers and health plans and data pulled from the wearable and fitness platforms you connect — may be subject to Nevada law (NRS 603A.400 to 603A.550). Xenter will not collect or share your consumer health data without your consent, and you may withdraw consent at any time by contacting privacy@xenter.io.
Xenter will obtain your authorization before connecting a new data source and will provide you with a clear description of the data to be collected and how it will be used before you authorize the connection.
6. Categories of Personal Information Collected
The following table summarizes the categories of personal information we collect through the Services, the sources, our purposes, and to whom we disclose it. Retention periods are described in Section 16.
| Category | Examples | Sources | Purposes | Disclosures |
|---|---|---|---|---|
Identifiers | Name, email address, date of birth, mailing address, mobile phone number, device IDs | Directly from you | Account management; communication | Service providers |
Internet & App Activity | App usage data, log files | The app; analytics tools | Improve the app; security; analytics | Service providers |
Diagnostic Assessment Results | Test data and diagnostic reports (e.g., EEG/ERP data and neurologist report from the Cognitive Assessment Program) | A diagnostic test performed by Xenter (or its contracted clinicians) at your healthcare provider's direction, under a Business Associate Agreement | Delivering your results to you and your ordering provider — see Section 3 | Your ordering healthcare provider; governed by HIPAA, not by this table — see Section 3 |
Health & Clinical Data (Aggregated Records) | Diagnoses, medications, lab results, clinical notes, immunizations | Your healthcare providers, via a connection you authorize; health information networks/exchanges | Building and displaying your combined health record; enabling you to share it as you direct | Only recipients you direct — see Section 10; authorized vendors; as required by law |
Insurance & Claims Information | Coverage details, claims history, plan benefits | Your health plan(s), via a connection you authorize | Building and displaying your combined health record | Only recipients you direct — see Section 10 |
Wearable & Fitness Data (Biometric Information) | Heart rate, heart rate variability, sleep stages, blood oxygen, activity/steps, stress or recovery scores | Wearable and fitness platforms you connect (e.g., Garmin, Apple Health, Whoop) | Building and displaying your combined health record; trend summaries (see Section 14) | Only recipients you direct — see Section 10; authorized vendors |
Precise Geolocation Data | GPS location and routes recorded during workouts by connected wearables/apps | Wearable and fitness platforms you connect | Displaying workout/activity history you have connected | Not disclosed except as required by law |
Account & Authentication Credentials | Login credentials or access tokens for provider portals, health plans, and wearable platforms | Directly from you, when you authorize a connection | Establishing and maintaining connections to your other accounts, at your direction | Not disclosed to any third party |
Inferences | Trends or summaries derived from the above | Derived internally | Helping you understand your health information over time | As described above |
7. Sources of Personal Information
- Directly from you — when you use the Services, create an account, or contact us;
- Your healthcare providers — via a patient-portal connection or FHIR/API connection you authorize (for example, connecting your hospital's patient portal pulls in your visit notes and lab results);
- Your health plan(s) — via a connection you authorize, for claims and coverage information;
- Health information networks and exchanges (e.g., CareQuality, CommonWell) — used to help locate and retrieve your records when a direct connection is not available;
- Wearable and fitness platforms you connect (for example, connecting Garmin Connect, Apple Health, or Whoop can bring in data like your heart rate, sleep, and activity, depending on what that platform tracks and what you’ve authorized);
- Family members whose records you are authorized to manage within your account, for example if you are a parent adding a child's records (see Section 11); and
- Publicly available sources.
8. How We Use Personal Information
- Providing, operating, and improving the Services, including retrieving, combining, and displaying your health, claims, and wearable data;
- Enabling you to view, organize, and share your own health information as you direct;
- Conducting research, development, and quality improvement;
- Communicating with you about the Services;
- Maintaining system security, integrity, and fraud prevention;
- Complying with legal and regulatory obligations; and
- Analytics to develop new or improved products and services — using de-identified or aggregated data where possible (see Section 16).
Sensitive personal information (including health, claims, and wearable data) is processed only for the purposes described above and not for inferring characteristics unrelated to the Services, except as separately authorized by you.
When we de-identify or aggregate personal information so that it can no longer reasonably be used to identify you, we commit to maintain and use that information only in de-identified or aggregated form, and we take reasonable measures to prevent it from being re-identified. Once information has been de-identified or aggregated in this way, it is no longer “personal information,” and this Privacy Notice no longer applies to it.
9. Disclosure of Personal Information
We do not sell your personal information.
Outside of the diagnostic assessment results described in Section 3 (which your ordering healthcare provider also receives, as explained there), Xenter does not automatically send your aggregated health record to any healthcare provider, health plan, or other party. We share personal information only with:
- Recipients you choose — when you use the Services to share your record with a person or organization; see Section 10;
- Service providers — vendors that provide hosting, IT support, security, analytics, and other operational services on our behalf under contractual data protection obligations;
- Regulatory authorities and law enforcement — when required by applicable law, court order, or to protect legal rights; and
- Successors — in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
We do not knowingly sell or share the personal information of minors under the age of 16.
We do not disclose personal information to third parties for their own direct marketing purposes.
10. Your Choice to Share Your Information
The Services let you share your aggregated health record with people and organizations you choose — for example, by generating a shareable link, downloading a copy, or adding records to a digital wallet.
- You control what you share and with whom. You may revoke or set an expiration on a share where the Services provide that option.
- Once a recipient has accessed information you shared, that copy is no longer in Xenter’s control. The recipient’s use of it is governed by their own privacy practices, not this Notice.
- We recommend sharing only with people and organizations you trust, and reviewing a recipient’s own privacy practices before sharing sensitive health information with them.
11. Family Members and Dependents
If you add or manage health information for a family member or dependent within your account, you represent that you have the legal authority to do so — for example, as the parent or legal guardian of a minor child, or as an authorized representative or holder of a healthcare power of attorney for an adult dependent. You are responsible for that individual’s information within your account, including for exercising or responding to privacy rights requests on their behalf where applicable.
Where a family member’s records include a minor child’s health information, see Section 18 (Children’s Privacy) for how we apply COPPA and applicable state law to that information.
12. Sensitive Personal Information
Certain categories of personal information we collect through the Services are considered “sensitive” under applicable law, including:
- Health and clinical data aggregated from your providers and health plans (consumer health data);
- Wearable and fitness data, including sleep, heart rate, and exercise data, which is expressly included within the statutory definition of “biometric information” under the California Consumer Privacy Act;
- Reproductive or sexual health information, if included in records you connect (for example, from certain Apple Health data categories); and
- Precise geolocation data derived from connected wearable or fitness platforms.
We collect and use sensitive personal information only to:
- Provide the Services you have requested, including retrieving, combining, and displaying your aggregated record;
- Share your information with recipients you direct, as described in Section 10;
- Comply with applicable law; and
- Maintain the security and integrity of our systems.
We will obtain your affirmative authorization (opt-in consent) before connecting a new data source and collecting consumer health data, as required by applicable state law. California residents may also request to limit the use of their sensitive personal information for purposes beyond those described above.
13. Your U.S. Privacy Rights
Depending on your state of residence, you may have the rights described in the table below.
| Right | Description | How to Exercise |
|---|---|---|
Access / Know | Request a copy of personal information we hold about you | Submit via email or web form |
Delete | Request deletion of personal information | Submit via email or web form |
Correct / Rectify | Request correction of inaccurate information | Submit via email or web form |
Portability | Receive a copy in portable format | Submit via email or web form |
Opt Out of Sale / Sharing | Opt out of sell or sharing of personal information for targeted advertising | N/A – we do not sell or share personal information for targeted advertising. |
Opt Out of Profiling | Opt out of profiling for significant decisions | We do not profile for significant decisions |
Limit Sensitive PI Use | Limit use of sensitive personal information beyond certain purposes | Submit via email |
Consent Withdrawal (Health Data) | Withdraw authorization for collection or sharing of consumer health data, including disconnecting a data source | Contact privacy@xenter.io, or disconnect within the app |
Non-Discrimination | Exercise rights without discriminatory treatment | Automatic |
A. How to Submit a Request
- Email: privacy@xenter.io (include “Privacy Rights Request” in the subject line)
- Web form: xenter.io/privacy-request
- Toll-free phone: 1-888-238-7204
We will verify your identity before processing your request. We will respond within the timeframe required by your state’s law.
B. Appeals
If we deny your request, you may appeal our decision within 30 days by emailing privacy@xenter.io with “Privacy Rights Appeal” in the subject line. We will respond within the timeframe required by your state’s law. If your appeal is denied, you may contact your state’s Attorney General.
C. Global Privacy Control (GPC) and Opt-Out Signals
We recognize and honor browser-based opt-out preference signals, including Global Privacy Control (GPC), as required by applicable law, wherever you access the Services through a web browser. If we detect a GPC signal, we will treat it as a request to opt out of the sale or sharing of your personal information for targeted advertising purposes. Because we do not currently sell or share personal information for cross-context behavioral advertising (see Section 15), honoring a GPC signal has no practical effect on your experience of the Services today. We are nonetheless configured to detect and honor GPC signals wherever they are technically transmitted, and will apply them automatically if our practices change.
D. Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights, except as permitted by law.
14. Profiling and Automated Processing
The Services may use automated processing to generate summaries, trends, or other insights from your aggregated health, claims, and wearable data, to help you understand your own health information over time. Xenter does not use this processing to make automated decisions that produce legal or similarly significant effects on you.
If this changes — for example, if the Services begin generating risk scores, health assessments, or similar outputs — residents of Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other states that have enacted automated decision-making rights may have the right to opt out of automated profiling that produces decisions with legal or similarly significant effects, and we will update this Notice accordingly and provide the applicable opt-out mechanism.
If you have questions about automated processing, contact privacy@xenter.io.
15. Tracking Technologies
The app uses first-party analytics and service-provider technologies to operate, secure, and improve the Services. These technologies may collect device and app-usage information, diagnostic data, and approximate location derived from your device, and are used to make the Services work, measure and improve performance, maintain security, and troubleshoot issues. We do not currently use these technologies for targeted advertising, cross-context behavioral advertising, or third-party advertising networks.
You can control certain tracking through your device and app settings. If you disable these settings, some features of the Services may not function properly.
16. Data Retention
| Data Category | Retention Period |
|---|---|
Identifiers and account information | Duration of your account + 3 years, or as required by applicable law |
Diagnostic assessment results (e.g., Cognitive Assessment Program) | Governed by the applicable Business Associate Agreement with your healthcare provider and by HIPAA — not by this table. See Section 3. |
Aggregated health and claims records | Duration of your account, then securely deleted |
Wearable and fitness data | Duration of your account, then securely deleted |
Account and authentication credentials/tokens | Retained only as needed to maintain an active connection; deleted promptly upon disconnection or account closure |
App and network activity data | 13 months from collection, unless a shorter period is required by law |
Records of privacy rights requests | 2 years from date of request |
De-identification for Research and Analytics
We may retain de-identified or aggregated data for longer periods for research, analytics, and product and service development. See Section 8 for our commitments regarding de-identified and aggregated information.
17. Data Security
We have implemented commercially reasonable technical, administrative, and physical security safeguards designed to protect your personal information from unauthorized access, use, disclosure, deletion, and modification. These measures include encryption of data in transit and at rest, access controls, and regular security assessments.
Because the Services rely on credentials and access tokens to connect to your provider, health plan, and wearable accounts, we apply additional safeguards to that information specifically, including encrypted storage, use of revocable access tokens where supported by the connected platform rather than storing your passwords directly, and prompt deletion of credentials/tokens upon disconnection.
No security measures are perfect or impenetrable, and we cannot guarantee that your information will not be accessed, disclosed, altered, or destroyed by a breach of our safeguards.
XenME combines health records from multiple sources and is likely to qualify as a personal health record (PHR) related service provider under the FTC Health Breach Notification Rule (16 CFR Part 318), as updated. In the event of a breach of unsecured identifiable health information, we will notify affected individuals, the Federal Trade Commission, and, where required, prominent media outlets, within the timeframes specified by applicable law. We will also comply with applicable U.S. state breach notification laws, which impose varying timelines (generally 30–90 days) and scope requirements across all 50 states and territories.
18. Children's Privacy
The Services are not directed at children under the age of 13, and we do not knowingly collect personal information directly from children under 13. If you add or manage a family member’s or dependent’s records within your account (see Section 11) and that individual is a minor:
- We treat the information as furnished by a parent or guardian on the child’s behalf, and obtain parental or guardian consent in accordance with COPPA and applicable state law before providing the Services with respect to that child;
- Parents or guardians may exercise privacy rights on behalf of minor children by contacting privacy@xenter.io; and
- California residents between the ages of 13 and 15 must affirmatively opt in before Xenter sells or shares their personal information.
If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact us at privacy@xenter.io and we will take prompt steps to delete that information.
19. Additional Disclosures
International Data Transfers
Xenter is headquartered in the United States. If you are accessing the Services from outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other jurisdictions where data protection laws may differ from those in your home country.
California “Shine the Light” Notice
Under California Civil Code §1798.83, California residents may request certain information about disclosures of personal information to third parties for direct marketing purposes.
Xenter does not disclose personal information to third parties for their own direct marketing purposes. Accordingly, no such disclosure list exists.
Changes to This Privacy Notice
We may update this Privacy Notice periodically to reflect changes in our practices, applicable law, or other operational, legal, or regulatory requirements. Changes will be reflected by updating the “Last Updated” date at the top of this Notice. For material changes affecting how we handle your personal information, we will provide additional notice (such as by email or an in-app notice) where required by law.
We encourage you to review this Notice periodically to stay informed about how we protect your information.
20. Contact Information
For questions about this Privacy Notice, to exercise your privacy rights, or to raise a concern about our data practices, please contact:
Xenter, Inc.
344 West 13800 South, Suite 400
Draper, Utah 84020, United States
- Email: privacy@xenter.io
- Phone: 1-888-238-7204
- Web: xenter.io/privacy-request
For MHMD requests (Washington residents): Include “MHMD Request” in the subject line.
For U.S. privacy rights requests: Include “Privacy Rights Request” in the subject line.
For privacy rights appeals: Include “Privacy Rights Appeal” in the subject line.
If you are a healthcare provider, business partner, or website visitor, please see the Xenter Website & Business Privacy Notice at xenter.io/privacy.