← Ascently Stack Audit

Ascently Stack Audit — Consumer Health Data Privacy Policy (Washington)

Effective: 2026-09-09 Applies to: audit.ascently.com, the free Stack Audit. Not the main website, not any future product. Version: 0.1 — interim, founder-signed, not yet reviewed by outside counsel

This is the separate consumer health data policy that Washington's My Health My Data Act asks for (RCW 19.373). It stands next to our Privacy Policy and adds to it.

Ascently is operated by Stanislav Chentsov, Miami, Florida, United States. Contact: privacy@ascently.com. There is no account here. We do not ask for your name and we do not want it.

1. What we collect, why, and how we use it

In one request we receive: the supplements in your stack with the doses you enter (up to 50); medication names you type or pick from our catalogue (up to 50); an age band — 18–29, 30–44, 45–64, 65+, never a date of birth; a two-letter country code; up to 1,024 characters of optional notes; your choice on the aggregate-research checkbox, which is off by default; and a random id for that one submission, which our server mints per request and sends back to you in a response header. It is not a cookie, it is not stored in your browser, and it does not recognise you on a later visit.

We use every one of those for a single purpose: to run the audit you asked for and show you the result. Your notes are also scanned for emergency signals — chest pain, severe bleeding, thoughts of self-harm, a severe allergic reaction. If one appears we stop and show an emergency message instead. Nothing is collected for any purpose beyond delivering the audit you requested.

We process your IP address while the request is open, for a rate limit and a bot check. The rate-limit key is a salted hash; the address itself never reaches our database.

2. Where it comes from

One source: you, typing into the form at audit.ascently.com. We buy no data, receive none from data brokers, take none from another company, and derive none from tracking you elsewhere. There is no account, so nothing carries over from an earlier visit.

3. What we share

No category of consumer health data is shared with any third party. Not your stack, not your medication names, not your notes, not your age band. What you type runs the audit and is then gone; only the record in section 6 remains.

4. Third parties and affiliates

Third parties: none. Affiliates: none — Ascently has no parent, subsidiary, or affiliated company. Two service providers handle data on our behalf, under our instructions:

  • Fly.io — hosting and the database, United States region.
  • Cloudflare — the "are you a bot" check (Turnstile), which sees your IP address.

We have not yet put a reviewed data-processing agreement in place with either. That review is on the list for our first engagement with outside counsel. We are telling you this rather than implying a review that has not happened.

5. Why we would ever share

Two reasons, neither commercial: to run the service through the two providers above, and to answer a valid legal demand. We do not sell consumer health data. A sale would need your separate signed authorisation under the act; we have never asked for one and have no plan to. We run no advertising, no advertising script, no profiling, and no geofence around any health care facility.

6. What we keep, and for how long

Each audit writes one row to an append-only log. The row is shape, not content: the submission id, country, age band, how many supplements and how many medications you entered, how many findings came back, whether an emergency signal fired, which rules fired and how many of your items each matched, the length and a SHA-256 hash of the text you were shown, and a SHA-256 fingerprint of your sorted stack items. Where a medication produced a warning panel, the row keeps our internal catalogue key for it — a string like MED_2a9ee30f28af, not the name you typed, though that key is one we could look up in our own catalogue.

The row does not keep your supplement names, the medication names you typed, your notes, your IP address, your name, your date of birth, your address, any lab value, or any genetic data.

During the alpha, audit records are kept indefinitely: the audit store is append-only by design and no scheduled expiry exists yet; when one is built, this notice will state the period. If you join the waitlist we keep your email address, the time you signed up, and your consent flag, until you ask us to remove it. Our host keeps ordinary server logs, which include IP addresses, for its own operational period.

7. Your rights, and how to use them

Write to privacy@ascently.com. We answer within 45 days. If we need longer we may take up to 45 more days, and we will tell you why inside the first 45.

To confirm what we hold, and who it went to. Expect an honest and short answer: the audit rows carry no name, no email, and no identifier we can match to a person, so in almost every case we hold nothing linkable to you and shared nothing with anyone. We will not gather extra information about you to try to find a record. If you kept the submission id — it comes back in the X-Correlation-ID response header — tell us and we will look, though we cannot verify that it is yours.

To delete. Same answer, same reason: normally there is nothing keyed to you to delete. If you are on the waitlist, say so and we delete that row — the one place we hold something that identifies you.

To withdraw consent. The only consents we ask for are the aggregate-research checkbox and the waitlist. Tell us and we stop from that point on. The limit, stated plainly: counts already folded into an aggregate cannot be unmixed, and they point at no one.

To appeal. If we refuse a request, our answer says why and how to appeal. Reply with "appeal" in the subject line; we answer an appeal in writing within 45 days. If we still refuse, we give you a way to complain to the Washington State Attorney General.

8. Changes

If we change this policy we change the effective date above and post the new version here. We will not collect a new category of consumer health data, or use it for a new purpose, before this page says so.

Contact

privacy@ascently.com

Ascently Stack Audit is a general-wellness information service. It is not medical advice and is not intended for the diagnosis, mitigation, or management of any condition. Consult a clinician for personalized medical decisions.

We do not store the medication names you type; the audit record keeps counts and an internal catalogue key for any medication that produced a warning. See our privacy notes for details.

  • Privacy
  • Terms
  • Disclaimer
  • Consumer health data (Washington)