Legal
All policies effective 1 July 2026 · Unhide AI Ltd
DOCUMENT 4 — SENSITIVE DATA USE POLICY
Version: v1.0 Effective Date: 1 July 2026
Sensitive Data Use Policy
Unhide AI Ltd, trading as Unhide Registered in England and Wales Company Number: 14771976
1. Introduction — Why This Policy Exists
Unhide is a personal tracking platform. Because users can choose tracker templates that involve health, mental health, fertility, biometric, and other sensitive personal information, we are committed to treating sensitive data with the highest level of care, transparency, and legal rigour.
This Sensitive Data Use Policy explains:
- —What categories of data we treat as sensitive
- —The legal framework that applies
- —The consent we collect before you use a sensitive-category template
- —How your sensitive data flows through our AI analysis system
- —How your sensitive data is stored and protected
- —Who can access it
- —Your specific rights in relation to sensitive data
This Policy supplements our Privacy Policy, which governs all personal data we collect. In the event of any conflict between this Policy and the Privacy Policy, this Policy shall take precedence in relation to sensitive data.
2. What Is Sensitive Data Under UK Law?
2.1 Special Category Data (UK GDPR Article 9)
The UK General Data Protection Regulation ("UK GDPR") identifies specific categories of personal data that warrant heightened protection because of their particular sensitivity and the risks their processing could create. These are referred to as "special category data" and are listed in Article 9(1) UK GDPR. Special category data includes:
- —Data revealing health or medical information
- —Data relating to mental health
- —Data relating to sex life or sexual orientation
- —Genetic data
- —Biometric data (where processed to uniquely identify a person)
- —Data revealing racial or ethnic origin
- —Data revealing political opinions
- —Data revealing religious or philosophical beliefs
- —Data revealing trade union membership
Processing special category data is prohibited unless one of the conditions in Article 9(2) is met. For all sensitive tracker data on our Platform, we rely on Article 9(2)(a): the data subject has given explicit consent to the processing.
2.2 Financially Sensitive Data
Financial data (for example, income, spending habits, investment amounts, debt levels) is not special category data under Article 9 UK GDPR. However, financial data is inherently sensitive and requires robust protection. We treat financial tracker data with the same technical security standards as Article 9 special category data, while noting that the legal basis for processing financial tracker data is contract (Article 6(1)(b)) rather than explicit consent. See Section 13 for further detail.
3. Categories of Sensitive Data We Process
The following categories of sensitive data may be processed through the Platform, depending on which tracker templates you choose to use.
3.1 Health Data
Tracker templates that fall within this category include those relating to:
- —Blood marker results (e.g. cholesterol, vitamin D, thyroid function, haemoglobin)
- —Blood glucose levels (including continuous glucose monitoring data entered manually)
- —Medication tracking (type, dosage, frequency, effects)
- —Physical symptoms and illness journalling
- —General health metrics (e.g. blood pressure, resting heart rate, weight, body measurements)
- —Sleep quality and duration (including indicators of sleep disorders such as sleep apnoea)
- —Injury and recovery tracking
- —Allergy and intolerance tracking
3.2 Mental Health Data
Tracker templates that fall within this category include those relating to:
- —Mood and emotional state
- —Anxiety symptoms and severity
- —Depression indicators (self-reported mood, energy, motivation)
- —Stress levels and triggers
- —Mental wellness journalling
- —Therapy session notes or outcomes (where entered by the user)
- —Mindfulness and mental health habit tracking
3.3 Fertility and Reproductive Data
Tracker templates that fall within this category include those relating to:
- —Menstrual cycle tracking (cycle length, flow, symptoms)
- —Ovulation prediction indicators (basal body temperature, LH surge)
- —Fertility treatment tracking (IVF cycle stages, medication, outcomes)
- —Pregnancy progress and symptom tracking
- —Postpartum tracking
- —Contraception tracking
3.4 Biometric Data
Where users voluntarily enter data that could constitute biometric data (for example, detailed body measurements used in conjunction with other identifiers, or vital signs logged over time in a pattern that could be used to identify a person), we treat such data as sensitive under Article 9.
3.5 Data About Children (Caregiver Context)
Some tracker templates are designed for use by a parent or carer logging data about a child in their care — for example, tracking a child's growth milestones, developmental progress, or health metrics. In this context:
- —The account holder is always an adult (18+) — the child does not have an account and does not interact with the Platform
- —The data processed relates to the child but is entered by the adult account holder
- —The adult account holder is responsible for having appropriate parental or legal authority to log and process data relating to the child
- —Data about a child is treated as health or personal data of a particularly sensitive nature
- —We apply the same storage, security, access, and retention standards as to other sensitive data
We strongly recommend that data about children is stored only where there is a clear personal benefit to the caregiver (e.g. tracking health conditions for medical appointments) and is deleted when it is no longer needed.
4. How We Identify a Sensitive-Category Template
Each tracker template in our catalogue is internally flagged with a sensitive_category attribute. Templates where this flag is set to true are treated as sensitive-category templates for all purposes in this Policy.
The internal classification is made by our product team based on the typical nature of data users will enter when using that template. We review template classifications periodically and will update them if a template's scope changes.
You will always be made aware that a template is sensitive-category before you begin using it. The consent flow described in Section 5 is triggered automatically before you can access a sensitive-category template for the first time.
5. Consent We Collect Before You Use a Sensitive-Category Template
5.1 First-Use Double-Checkbox Consent
Before you can begin logging data to any sensitive-category tracker template, you are presented with a consent screen that:
- —Identifies the specific template you are about to use and the category of sensitive data it involves
- —Explains that the data you enter will be processed in accordance with this Sensitive Data Use Policy and our Privacy Policy
- —Explains that if you request AI analysis, your data (including all logged entries) will be transmitted to our AI provider, Anthropic PBC, for pattern analysis, and that Anthropic retains this data for up to 30 days
- —States that you may withdraw consent at any time
- —Presents two separate checkboxes, both of which you must actively tick:
- —Checkbox 1: "I understand that this tracker collects [category] data, which is treated as sensitive personal data under UK GDPR, and I consent to it being processed as described in the Sensitive Data Use Policy."
- —Checkbox 2: "I understand that if I request AI analysis, my data for this tracker (including any photos or PDFs I have uploaded) will be transmitted to Anthropic PBC's API servers in the United States for pattern analysis, and retained by Anthropic for up to 30 days."
You cannot proceed to the tracker without ticking both checkboxes.
5.2 Photo and PDF Consent
Where you upload a photo or PDF to a sensitive-category tracker template for the first time, a separate consent notice is presented before the upload proceeds. This notice explains that photos and PDFs uploaded to sensitive templates may be transmitted to Anthropic PBC as part of any AI analysis you request. You must confirm this consent before your first photo or PDF upload.
5.3 Re-Consent on Policy Changes
If we make material changes to how we process sensitive data (for example, changes to our AI provider, changes to retention periods, or the introduction of new data flows), we will present a re-consent screen to affected users before they can continue using the relevant sensitive-category template.
5.4 Consent Records
All consent events (first-use template consent, photo/PDF consent, re-consent events) are recorded in our database in append-only form. Consent records contain:
- —Your user ID
- —The template identifier
- —The consent type (template first-use, photo/PDF upload, re-consent)
- —The exact text of the consent presented
- —The date and time of the consent
- —A confirmation that both checkboxes were ticked
Consent records are retained for 7 years from the date of consent, in accordance with accountability requirements under UK GDPR Article 5(2).
6. How Sensitive Data Flows Through AI Analysis
6.1 What Is Sent to Anthropic PBC
When you request an AI analysis on a sensitive-category tracker, the following data is compiled and transmitted to Anthropic PBC via their API:
- —All logged field values for that tracker (including scale values, numbers, booleans, text, time entries, dates, and select responses)
- —Any photos you have uploaded to that tracker (transmitted as image data in the API request)
- —Any PDFs you have uploaded to that tracker (transmitted as document data in the API request)
We do not transmit your name, email address, or any other directly identifying account data to Anthropic.
6.2 Anthropic's Role and Obligations
Anthropic PBC acts as a data processor on our behalf in relation to the data transmitted via their API. Anthropic processes your data under a Data Processing Agreement that imposes obligations on Anthropic consistent with UK GDPR requirements.
The following terms apply to Anthropic's handling of your sensitive data:
- —Anthropic does not use API input or output data to train its AI models. Your sensitive tracker data is not used to improve or train Anthropic's models.
- —Anthropic retains API inputs and outputs for up to 30 days for safety monitoring, trust and safety evaluation, and abuse prevention purposes. After this period, the data is deleted from Anthropic's systems.
- —Anthropic is headquartered in the United States. Transmission of your data to Anthropic constitutes an international data transfer under UK GDPR. We ensure this transfer is lawful through the mechanisms described in our Privacy Policy (Section 9).
- —All data is transmitted over an encrypted connection using TLS 1.2 or higher.
- —Anthropic's privacy information is available at: https://www.anthropic.com/privacy
6.3 Storage of Analysis Results
The plain-English pattern analysis returned by Anthropic is stored in our database (hosted by Supabase Inc in the United States) and displayed to you in your dashboard. This analysis is associated with your account and tracker and is accessible only by you (and, in limited circumstances, by Unhide support staff as described in Section 9).
7. Storage and Security of Sensitive Data
We apply the following technical and organisational measures to protect your sensitive data, in accordance with UK GDPR Article 32:
- —Encryption at rest: All sensitive data stored in our Supabase database is encrypted at rest using AES-256 encryption
- —Encryption in transit: All data transmitted between your device, our Platform, and our sub-processors is encrypted using TLS 1.2 or higher
- —Row-level security ("RLS"): Our database enforces RLS policies at the database layer, ensuring that every query returning tracker data is scoped to your user ID. No query can return another user's data, regardless of application-layer logic
- —Access controls: Access to production database systems is restricted to authorised personnel and requires multi-factor authentication
- —Audit logging of sensitive data access: All access events relating to sensitive data — whether by you, by automated systems (AI analysis), or by Unhide support staff (impersonation) — are logged in our audit trail with the accessor's identity, the data accessed, and a timestamp
- —File storage security: Photos and PDFs uploaded to sensitive-category templates are stored in a private file storage bucket (Supabase Storage) with no public URL. Files are accessible only via authenticated, time-limited signed URLs generated at the time of access.
8. Data Retention — Sensitive Data
| Scenario | Retention |
|---|---|
| Account active, template in use | Data retained for as long as your account is active and you continue to use the template |
| Template deactivated (but account remains) | Data preserved in inactive state; not auto-deleted; accessible if you reactivate the template |
| Account deleted | All sensitive data (entries, analyses, uploaded photos/PDFs, consent records except as noted) cascade-deleted immediately and permanently |
| Consent records | Retained for 7 years from date of consent (append-only; not deleted on account deletion) |
| Audit logs (access records) | Retained for 7 years from date of the logged event |
| Anthropic API data | Deleted from Anthropic's systems within 30 days of the relevant API call |
You can also request deletion of all data for a specific template, without deleting your account, via Dashboard → [Tracker] → Settings → Delete All Data for This Tracker. This will permanently delete all entries, analyses, and uploaded files for that specific template.
9. Who Can Access Your Sensitive Data
Your sensitive data is strictly access-controlled. It can only be accessed in the following circumstances:
| Accessor | Circumstances | Safeguards |
|---|---|---|
| You | At all times via your dashboard | Authenticated session; RLS enforced at database level |
| Anthropic PBC (AI provider) | When you request an AI analysis — entries, photos, and PDFs for the relevant tracker are transmitted via API | Data processor; no model training; 30-day max retention; TLS encrypted |
| Unhide support staff (impersonation) | Only when you have raised a support ticket and impersonation is required to diagnose a specific technical issue | Read-only impersonation; all sessions audit-logged with staff identity, account accessed, date, time, and duration |
| Authorised Unhide technical staff | Emergency access to database infrastructure only (e.g. resolving a critical outage) | Requires two-person authorisation; access logged; RLS cannot be bypassed at application layer |
We never:
- —Sell your sensitive data to any third party
- —Share your sensitive data with third parties for marketing purposes
- —Provide your sensitive data to insurers, employers, or government bodies except where compelled by law
- —Allow any third party beyond those listed above to access your sensitive data
10. Your Rights in Relation to Sensitive Data
In addition to your general data subject rights under UK GDPR (detailed in our Privacy Policy, Section 11), the following rights apply specifically to sensitive data:
10.1 Right to Withdraw Consent
You may withdraw your explicit consent for a sensitive-category template at any time. Withdrawal of consent stops any future processing based on that consent. It does not affect any processing already carried out. You have two options when withdrawing:
- —Option A — Pause the template: The template is deactivated and no further data is logged. Your existing data is preserved and the template can be reactivated later (which will require you to re-consent). No AI analyses will be run while the template is paused.
- —Option B — Delete all data for this template: All entries, AI analyses, and uploaded files for this template are permanently and immediately deleted. You will need to give fresh consent and start from zero if you later wish to reactivate the template.
To withdraw consent, go to Dashboard → [Tracker] → Settings → Consent and Data or contact us at ****.
10.2 Right to Export Sensitive Data
You can request a full export of all your data — including sensitive tracker entries, analyses, and metadata — at any time via Dashboard → Settings → Privacy → Export My Data, or by contacting . Data will be provided in a structured, machine-readable format (JSON or CSV) within 30 days.
10.3 Right to Erasure of Sensitive Data
You have the right to request erasure of your sensitive data (Article 17 UK GDPR). You can:
- —Delete data for a specific template via your tracker settings (Option B above)
- —Delete your entire account (which cascade-deletes all sensitive data) via Dashboard → Settings → Account → Delete Account
On account deletion, all sensitive data is immediately and permanently deleted from our production systems. Note that audit logs and consent records are retained for their prescribed retention periods (see Section 8) as required by law.
10.4 Right to Request Human Review of AI Analysis
If you have concerns about any AI-generated analysis produced from your sensitive tracker data, you have the right to request that a human member of our team reviews the circumstances of the analysis. To make such a request, contact us at **** with the subject line "Human Review Request".
Note that our team will review the circumstances and technical correctness of the analysis process — we do not have the ability to "override" or modify the AI's output, but we can confirm whether the analysis was generated correctly and whether it appropriately reflected your data.
11. What AI Analysis Can and Cannot Do
We want to be completely transparent about the capabilities and limitations of AI analysis applied to your sensitive data.
11.1 What AI Analysis Can Do
- —Identify patterns and trends in your logged data over time (for example, correlations between sleep duration and mood score)
- —Surface observations about frequency, regularity, or change over time in the metrics you have logged
- —Present these observations in plain, non-technical English
11.2 What AI Analysis Cannot Do
- —Diagnose any medical condition, disorder, or disease — the AI identifies patterns in self-reported data only; it is not a diagnostic tool
- —Recommend any course of treatment, medication, supplement, or clinical pathway
- —Interpret clinical test results — for example, a blood glucose reading entered by a user will be analysed as a number in the context of your broader data, not assessed against clinical reference ranges
- —Replace professional medical consultation — if your tracker data relates to health or mental health, always discuss relevant patterns with a qualified healthcare professional
- —Act as clinical decision support software — the Platform is explicitly not intended to be used in a clinical setting or to support clinical decisions
11.3 Medical Device Disclaimer
Unhide is not a medical device. The Platform has not been registered with or cleared by the Medicines and Healthcare products Regulatory Agency ("MHRA"). Nothing in the AI analysis produced by the Platform constitutes medical advice, clinical guidance, or a therapeutic intervention.
You must not use any output of the Unhide Platform as the basis for a medical decision without consulting a qualified medical professional. If you are concerned about any data pattern highlighted by an AI analysis, please speak to your doctor or a qualified clinician.
12. Mental Health Data — Additional Note
We recognise that mental health tracker data is particularly sensitive and that some users may be in a vulnerable position when using these templates. We have built the Platform to be a supportive tool for personal awareness and habit tracking — it is not, and is not intended to be, a mental health intervention, a therapeutic tool, or a crisis support service.
If you are experiencing a mental health crisis, please contact:
- —Samaritans: 116 123 (24 hours, free, UK)
- —Crisis Text Line (UK): Text SHOUT to 85258
- —Your GP or a local mental health crisis team
13. Financial Data — Additional Note
Financial trackers (for example, income tracking, spending habit tracking, debt management tracking) allow users to log financial data. This data is not special category data under Article 9 UK GDPR. We process financial tracker data on the legal basis of contract (Article 6(1)(b) UK GDPR) — it is necessary to process it to deliver the tracker features you have requested.
However, because financial data is inherently sensitive, we apply the same technical security standards to financial tracker data as we do to Article 9 special category data (encryption at rest, RLS, access controls, audit logging).
No financial advice is provided by the Platform. AI analysis of financial tracker data identifies patterns in your self-reported data only. It does not constitute regulated financial advice, investment advice, or any advice that would require authorisation by the Financial Conduct Authority ("FCA"). If you require financial advice, please consult a qualified financial adviser.
14. Contact for Sensitive Data Concerns
For any concerns, questions, or rights requests specifically relating to your sensitive data:
Privacy Contact: Email: ****
Unhide AI Ltd 204 Southcote Lane, Reading, Berkshire, England, RG30 3AU
We aim to acknowledge sensitive data rights requests within 2 working days and resolve them within 30 calendar days (extendable where legally permitted, with notice to you).