Privacy Policy

Wavely Diagnostics, Inc. (referred to below as “WavelyDx,” “we,” “our,” or “us”) values your privacy.  This Privacy Policy explains how WavelyDx may collect and use Personal Information when you use our Services (each as defined below). 

For purposes of this Privacy Policy, “Personal Information” means any information relating to an identified or identifiable individual, which may include protected health information such as medical history, health conditions, test and laboratory results, physician referrals, insurance information and other data that a healthcare professional may collect to identify an individual and determine appropriate care (“PHI”). This includes Personal Information you provide or generate when you access or use our devices and applications for at-home ear-infection detection, our platform for app-based health tools, our website at www.wavelydx.com and other website(s) (collectively, the “Sites”), and other applications, tools, software, subscriptions, memberships, content, API(s), widgets, and/or other devices, products and services that we may offer from time to time (collectively, the “Services”). 

We may update or modify this Privacy Policy from time to time. If we make material changes, we will revise the “Last Updated” date, and we may also choose to send you a notification of such changes.  We encourage you to review this Privacy Policy frequently to stay informed about our privacy practices and how you can exercise your options related to those practices.

Your continued use of the Services will constitute your understanding and acknowledgment of this Privacy Policy.  If you do not agree with our Privacy Policy or any updates, you must stop using our Services.

1. Personal Information We Collect

We may collect the following types of Personal Information:

Personal Information You Provide to Us

We collect Personal Information that you provide to us when you use the Services, for example by using the Platform or contacting us directly with questions or feedback.  We also may collect Personal Information that you provide to us offline, such as at industry or marketing events. This Personal Information may include:

  • Identifiers, such as your name, email address, telephone number, or physical address.

  • Account and registration information, such as name, addresses, email addresses, telephone numbers, occupation and information imported from social log in permissions granted to us).

  • Purchase and transaction information, such as billing information, billing address, purchase history;

  • Communication data, such as your phone number or preferred email address when you contact us directly, the contents of chats you initiate with our chat services, and your communications with other users of our Services, social media, or otherwise. 

  • Personal Information about others, such as Personal Information about others that may be contained in the information you provide to us. (Before you provide Personal information about others to us, you must first obtain the necessary permissions to share it with us.)

  • Marketing and promotions data, such as your preferences for receiving our marketing communications, and information about how you engage with our marketing communications.

  • Other information you provide directly to us, such as your responses to surveys and questionnaires, and other content or information that you generate, transmit, or otherwise make available through our Services (such as photos, images, videos, comments, questions, messages, works of authorship), as well as associated metadata. 

  • Sensitive Personal Information needed to provide our Services, including (a) your username in combination with a password or other credential that allows access to your account, (b) information relating to your health or any medical conditions, and (c) audio and related transmission data as described above.

  • Personal information that we infer from other personal information about you and other information that we process, including information we obtain from other sources as described below.

  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.

Personal Information We Collect from Third Parties

We may collect Personal Information from third parties. This information may include:

  • Service provider information, such as Personal Information we receive from the third-party service providers we work with to collect the Device information and Activity information described below. 

  • Publicly available information, such as Personal Information provided on customer or prospective customer websites or on publicly accessible portions of social media or networking sites, or from government agencies or public records.

  • Third party cookie information, as described below under “How We Use Cookies.”

  • We may receive contact information about prospective customers that may be interested in the Services from third-party sources. We may use this information to contact prospective customers about the Services.

In addition, we may receive Personal Information from third parties in connection with an actual or prospective business transaction. For example, we may receive your Personal Information from an entity we acquire or are acquired by, a successor, or assignee, or any party involved in a business transaction such as a merger, acquisition, sale of assets or similar transaction, and/or in the context of an insolvency, bankruptcy, or receivership.

Personal Information We Collect Automatically

We may automatically collect Personal Information when you use the Services. This information may include:

  • Device information, such as device model, operating system and version, unique device or personal identifiers, mobile network information, IP address, browser type, screen resolution, RAM and disk size, CPU usage, device type, IP address, unique identifiers, language settings, mobile device carrier, radio/network information, and general location information such as city, state, or geographic area. 

  • Activity information, such as when you accessed the Services, which pages you viewed on the Site and for how long, information about the searches you perform on our websites or in our other Services and how you use the results of those searches, and which sites you visited before and after accessing the Site. 

  • Communication engagement data, such as how you engage with our emails or other communications (for example, opening, forwarding, or clicking links within our emails).

  • Location information, such as your approximate location, which we infer via the IP address you use to access the Services.  Note that we do not have access to or collect your precise geolocation data.

  • Cookie information, as described below under “How We Use Cookies.”

Aggregated Data

We may also collect, create, and use aggregated data sets for our commercial purposes.  These data sets may be derived from Personal Information, but they are not Personal Information because such data cannot be reasonably linked back to a specific individual.  

2. How We Use Personal Information

We may use the Personal Information we collect to serve the following purposes:

  • to create your account and provide the Services to you; 

  • to manage our relationship with you, including responding to your inquiries, providing you with notices (such as service-related announcements, updates, security alerts, and support and administrative messages), and requesting your feedback;

  • to market the Services to you;

  • to analyze your use of our Services;

  • for research and development purposes, including to analyze and improve our Services, our business, and to develop new products and services;

  • to personalize your experience with our Services;

  • to detect and protect against security incidents or fraudulent or unlawful activity;

  • to comply with legal and regulatory requirements, lawful requests, and legal process, such as to respond to subpoenas, investigations, or requests from government authorities; 

  • to protect our, your, or others’ rights, privacy, safety, or property (including by making and defending legal claims);

  • to audit our internal processes for compliance with legal and contractual requirements or our internal policies;

  • to enforce the terms and conditions that govern our services;

  • to communicate with your healthcare providers as applicable; and

  • for other purposes at your direction or with your consent.

How We Use Cookies 

We and some of our third-party service providers collect and store some of the information described under “Personal Information We Collect Automatically” by using cookies and other similar technologies like pixels, tags, and web beacons (collectively, “Cookies”). Cookies are small strings of information that a website you visit transfers to your browser.  Cookies can be used to track your internet activity, remember your preferences, improve your user experience, or support marketing activities, like targeted advertising. Some cookies are necessary to operate a website, while others are not. You can decide if and how your device will accept cookies by configuring your browser settings (see below under “Your Privacy Choices” → “Cookies”).  If you choose to reject cookies, you may not be able to use certain features of the Services.

We currently use the following types of third party cookies:

  • Functionality cookies, which help us enhance how the Site work, including by remembering your specified preferences and enabling customer support interactions. Our third party partners that set functionality cookies on the Site and within the App are: Squarespace.

  • Analytics cookies, which help us analyze how you use the Site, including by tracking how you interact with the Site, which pages you visit, and errors you may encounter. Our third party partners that set analytics cookies on the Site and within the App are: Google.

3. How We Disclose Personal Information

We may disclose Personal Information to third parties as follows:

  • to our vendors, agents, consultants, and other service providers who need access to your information to perform services on our behalf, such as cloud services, web hosting, data labeling, analytics, marketing, or advertising. This may also include disclosing Personal Information to health care providers: (i) to schedule and fulfill appointments and provide health care services as part of the Services, (ii) to whom you send messages through our Services, and (iii) for other treatment, payment or health care operations purposes, including pharmacy, laboratory, radiology or other ancillary services, upon your request. 

  • to third parties with whom we partner, including parties with whom we co-sponsor events or promotions, with whom we jointly offer products or services, or whose products or services may be of interest to you, which includes our platform for app-based health tools, which offerings may include features or functionalities provided by third parties, or may integrate or interact with third-party products and services (including, without limitation, via APIs, plug ins, links, frames, embedding, or other interactions);

  • to our professional advisers, such as auditors, accountants, or lawyers;

  • in connection with the change to the control or financial status of WavelyDx, such as a merger, sale of our assets, financing, acquisition, or bankruptcy;

  • to our current and future affiliate companies;

  • to protect the legal rights, safety, or security of WavelyDx and our community, such as to enforce our Terms of Service; to prevent fraudulent or unlawful activity; or to respond to a law enforcement or government authority request or other legal or regulatory process;

  • on an aggregated and anonymized basis; or

  • to other parties at your direction or with your consent.

4. Your Privacy Choices

Your use of the Services is voluntary. You may decline to share certain information with us, or you may opt-out or withdraw your prior consent to share Personal Information with us (as set forth in this section and in Sections 9 through 11 below); in such instances, we may not be able to provide you with some or all of the features and functionality of the Services.

  • Emails: If you no longer wish to receive marketing emails from us, you can unsubscribe at any time by following the instructions in our marketing emails. Please note that even if you unsubscribe from marketing emails, you may still receive emails from us related to the Services, such as emails about changes to our policies or about purchases you’ve made from us.

  • Cookies: Many web browsers enable cookies by default.  Depending on where you are located, you may either need to opt-in or opt-out of our use of nonessential cookies. You can change your cookie settings or disable cookies at any time by updating your browser settings or, in the case of third party cookies, by visiting the site of the third party partners. For example, you can opt out of Google Analytics by visiting https://tools.google.com/dlpage/gaoptout or via Google’s Ad settings. You can find more information on how to opt-out of cookies at USA.gov

  • Do Not Track Signals: We do not currently recognize or respond to automated browser signals regarding tracking, such as “Do Not Track” signals.

5. Children’s Privacy

You must be over the age of 18 (or the age of majority in your jurisdiction, whichever is older) to access or use the Services. We do not knowingly collect Personal Information from individuals under the age of 18 (each, a “Child”) except as provided to us by and with the prior consent of the Child’s parent or legal guardian (“Parent”). Personal Information about a Child that the Parent provides may be used and shared for purposes described above under “How We Use Personal Information” and “How We Disclose Personal Information” in order to provide our Services to the Parent.

WavelyDx is located and can be reached at: Wavely Diagnostics, Inc., 2311 N 45th Street #270 Seattle, WA 98103, and support@wavelydx.com. Parents have the right to review the Personal Information we have collected from their Child, withdraw consent to prevent further collection or use of Personal Information from their Child, or request that we delete the Personal Information of their Child. If you would like to exercise these rights or believe we might have any Personal Information from or about a Child without parental consent, please contact us at support@wavelydx.com. If we become aware that we have collected Personal Information from a Child without the consent of their Parent, we will delete the Personal Information in accordance with applicable law. 

6. Security

We take reasonable steps to protect your Personal Information from loss or unauthorized use, access, disclosure, or destruction. Even so, we can’t guarantee the complete security of any Personal Information you disclose online. For example, emails sent to or from our Services may not be secure, and so you should take care when considering what information you send to us via email. To the extent permitted under applicable law, we assume no liability or responsibility for the loss, disclosure, or destruction of your Personal Information due to errors in transmission, unauthorized access by third parties, or other causes beyond our control.

7. Retention

We retain your Personal Information for as long as necessary to fulfill the purposes for which it was collected, or for other essential purposes, such as complying with our legal obligations, resolving disputes, enforcing our agreements, or otherwise as required or permitted by law. 

Notwithstanding the foregoing, all protected health information and certain other data that may be considered part of a medical record will be maintained in accordance with all applicable medical retention laws, rules and regulations, by your healthcare provider. If after your user account has been deactivated, you need access to your medical data, please contact your healthcare provider directly.

8. Location of Personal Information

Currently, we only use data centers located in the United States to store and process the Personal Information we collect; we have chosen this storage location to operate efficiently and improve performance. We take steps to process and protect Personal Information as described in this statement; however, the country where we store Personal Information may have laws that offer a different level of data protection than the country in which you reside.

9. Third Party Content

The Site may make available or provide links to third party content. WavelyDx does not control, and is not responsible for, any third party content, and this Privacy Policy does not apply to third party content.  We encourage you to review the privacy policies applicable to any third party content before engaging with it.

10. Contact

If you have any questions about this Privacy Policy or would like to exercise one of your privacy rights, you can reach us at support@wavelydx.com or by mail at 2311 N 45th Street #270, Seattle WA 98103.

Last Updated: September 18, 2025