Privacy Policy
Effective:
/
Last updated:
Information we collect
When you create an account, complete your intake, or use our services, we collect account information (name, email address, date of birth, billing address, and payment details), health information (symptoms, cycle history, medications, and anything you share with your clinician), lab results from your hormone panel, and communications you send to your clinician or support team.
We also collect usage data automatically - pages visited, features used, session duration, and error reports to help us improve the platform and diagnose issues.
All health-related information is classified as Protected Health Information (PHI) under HIPAA and handled with the highest level of legal protection.
How we use your information
We use your information to provide clinical care, process payments, operate the platform, prevent fraud, and improve our services using de-identified data. Where we send you marketing communications, we do so only with your consent you may opt out at any time.
We do not use your Protected Health Information for marketing, advertising, or sale to third parties ever.
Sharing your data
We share your information only in the following circumstances:
Your care team - your assigned clinician and clinical support staff required to provide your care.
Accredited labs - Quest Diagnostics and Labcorp process your samples under HIPAA Business Associate Agreements.
Pharmacy partners - your prescription and necessary health information are shared for dispensing.
Payment processors - billing information is shared with Stripe. Stripe never receives your health information.
Technology vendors - cloud hosting, analytics, and support tools operate under strict data processing agreements.
Legal requirements - when required by law, court order, or to protect user safety.
Business transfers -if Healthio is acquired, you will be notified before your data becomes subject to a different privacy policy.
We never sell your health data, share identifiable health information with advertisers, or allow third parties to use your data for their own marketing.
HIPAA and health data
Healthio Health is a Covered Entity under HIPAA. Your Protected Health Information is subject to strict federal privacy and security rules. Under these rules, you have the right to access your health records, request corrections, receive an accounting of disclosures, and be notified of any breach affecting your unsecured PHI.
We protect your health information using end-to-end encryption for all clinician communications, encryption at rest for stored data, role-based access controls, regular third-party security audits, and HIPAA-compliant cloud infrastructure.
Data retention
Health records and clinician communications are retained for 7 years from the date of service as required by law. Account information is retained for the duration of your membership plus 12 months. Payment records are retained for 7 years. Usage and analytics data is retained for 24 months in de-identified form.
After the applicable retention period, data is securely deleted or de-identified. You may request deletion of non-health data at any time. Health records cannot be deleted before the legally required retention period expires.
Your rights
Depending on where you live, you have the right to access, correct, delete, and port your personal information - and to opt out of marketing communications at any time. To exercise any right, contact us at support@yourbrand.com. We respond within 30 days.
California residents (CCPA): You have additional rights under the California Consumer Privacy Act, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
Cookies
We use essential cookies (required for authentication and security), analytics cookies (de-identified usage data to improve the platform), and preference cookies (to remember your settings). We do not use advertising cookies or allow third-party advertisers to place cookies on our platform.
Children
Healthio's services are for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe we have inadvertently done so, contact us and we will delete the information promptly.
Changes
When we make material changes to this policy, we will notify you by email and post the updated version here with a revised date. Your continued use of our services after a policy update constitutes acceptance of the revised policy.
Contact
For privacy questions, data requests, or concerns, contact our Privacy team at support@yourbrand.com