1. Overview
Zoe Health Market ("Zoe," "the Platform," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how it is stored and used, and what rights you have over your data.
Because Zōe is built on the Internet Computer Protocol (ICP), data handling is fundamentally different from conventional web applications. There is no central server or cloud database. All data is stored on-chain, and all health data is encrypted client-side before it ever leaves your device. The canister (smart contract) that runs the Platform never receives or stores plaintext health information.
2. What We Collect
We collect only the minimum information necessary to operate the Platform:
Encrypted health data: When you upload a dataset as a Seller, your health data is encrypted client-side using vetKeys Identity-Based Encryption (IBE) with your ICP principal as the encryption identity. The resulting ciphertext — not your plaintext data — is stored on-chain. Zōe cannot decrypt it.
ICP Principal ID: Your Internet Identity principal is your unique identifier on the Platform. It is a cryptographic public key, not a name or email address. All actions you take on the Platform are associated with your principal.
Transaction records: Purchase events, escrow state, fund distributions, and consent actions are logged immutably on-chain. These records include principal IDs, timestamps, dataset references, and amounts — never the underlying health data content.
Dataset metadata: Sellers provide metadata when listing data — such as data types, demographics (age range, health conditions), research permissions, and price. This metadata is public and visible to Researchers browsing the marketplace.
We do not collect names, email addresses, postal addresses, phone numbers, or any other conventional personal identifiers unless you voluntarily provide them (e.g., in a support message).
3. How Data Is Stored
All Platform data is stored exclusively on the Internet Computer blockchain. There is no off-chain database, no cloud object storage, and no third-party analytics service that receives your data.
Health data is encrypted before upload using vetKeys IBE. The encryption key is derived from your ICP principal and controlled by the vetKeys system, not by Zōe. Zōe cannot access, decrypt, or export your health data.
Blockchain records (transactions, consent records, audit logs) are immutable by design. Once written, they cannot be altered or deleted by anyone — including Zōe. This is a deliberate architectural choice to ensure legal defensibility and auditability.
5. Your Rights
You retain full ownership and control over your health data at all times. Specifically:
Withdraw consent: You may withdraw consent and delist any of your datasets at any time from your Seller dashboard. Once delisted, no new purchases will be accepted. Note: withdrawal cannot revoke access already granted to Researchers who purchased before the withdrawal — this is an inherent property of on-chain access control.
Export consent record: You may request a downloadable copy of your consent record, which includes the consent agreement text, your declared research permissions, retention period, and timestamp. This export is available from your dashboard.
Delete account: You may request account deletion at any time by contacting support. Because blockchain records are immutable, on-chain transaction and audit logs cannot be deleted, but your profile and active listings will be removed.
Where applicable under GDPR or other privacy regulations, you may also have rights of access, rectification, restriction of processing, and data portability with respect to any off-chain data we hold. To exercise these rights, contact us at support@zoe.health.
6. Data Retention
Encrypted health data stored on-chain persists until you delist the dataset. After delisting, the ciphertext may remain on-chain as part of the immutable ledger, but access will no longer be granted to new purchasers.
Transaction records, consent records, and audit logs are retained indefinitely on the blockchain. This immutability is essential for legal compliance and auditability.
Any support correspondence or off-chain communications you initiate are retained for up to 3 years and then deleted.
8. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us at support@zoe.health immediately.
9. Contact
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
Email: support@zoe.health
We will respond to all privacy inquiries within 30 days.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. For material changes, we will provide notice within the Platform.
Continued use of the Platform after changes take effect constitutes your acceptance of the updated Policy.