Product
Product
Health Library
Health Library
Calculators
Calculators
About
About

Consumer Health Data Privacy Notice

Effective as of 13 November 2025 

This Consumer Health Data Privacy Notice applies to residents of Washington and Nevada and supplements Flo’s Privacy Policy to describe how we process consumer health data collected through our websites, social media accounts, mobile applications, and other online interactions and communications such as email (collectively, our “Services”).

Changes: We may update this Consumer Health Data Privacy Notice from time to time. Any updated Consumer Health Data Privacy Notice will be effective when posted. Please check this Consumer Health Privacy Notice periodically for updates. If required by law, we will contact you directly to provide you with updates.

What is consumer health data?

Consumer health data means personal information that is linked or could be linked to you and shows or suggests your past, present, or future physical or mental health (“Health Data”). 

Sources of Health Data

As described in more detail in our main Privacy Policy, we collect Health Data from the following sources:

  • directly from you: We collect your Health Data from you directly, such as when you input it into the App to use our Services and interact with us through your use of the Services; and 
  • from third parties: You may also allow us to connect to third-party services, such as Apple HealthKit and Google Health Connect. This enables us to import Health Data and information about your activities into the App without the need for you to log it yourself. 

 

Types of Health Data we collect 

As described in our main Privacy Policy, we collect Health Data outlined below. Additionally, we may be able to infer health information from non-Health Data you provide during your use of our Services.

You remain in control of your data. We may collect Health Data that you input into the App, which includes:

  • information collected as part of the Services you have selected, including: mode you have selected, menstrual cycle dates, pregnancy dates, symptoms related to your menstrual cycle, perimenopause and menopause symptoms, information relating to your sex life, sexual history, pregnancy and ovulation test results;
  • your physical and mental well-being: mood, appetite, cycle-related pain, discharge, menstrual flow, water intake, disease or injury, sleep, energy levels, skin concerns, medication (including hormonal birth control and painkillers), and lifestyle/activity data; 
  • information collected from third-party services (including wearables), including: your heart rate, weight, height, calories burned, BMI, body temperature, step count, sleep data, and other activity data you choose to share with us; and 
  • information entered into our Symptom Checker*, including: common symptoms associated with reproductive health conditions, menstrual history, previously diagnosed reproductive health conditions, family medical history, and lifestyle data. 

*Symptom Checker is not a substitute for professional medical advice, diagnosis, or treatment of any kind. 

How we use Health Data

As described in our main Privacy Policy, we will process your Health Data to provide you with the Services including to support existing functions of the App and provide you with tailored content, insights and materials you see when you use the App. This includes using your Health Data to: 

  • register, verify and maintain your account with us;
  • provide and deliver you the Services you have requested; 
  • provide customized product and service offerings - for example, via push notifications; 
  • respond to your comments, questions, requests and provide customer service; and
  • verifying member eligibility for certain benefits or offers. 

To provide you with our Services, we may also use your Health Data for the following purposes: 

Legal, safety and security reasons, such as activities to: 

  • prevent, detect and investigate security incidents that compromise the availability, integrity or confidentiality of your Services, which may include your Health Data; 
  • comply with legal, reporting and similar requirements; 
  • investigate, assert and defend legal rights or legal claims; 
  • review App content, feedback and complaints raised to ensure clinical safety and medical accuracy of the App; and
  • protect against malicious, fraudulent or other illegal activities. 

Internal business purposes, such as: 

  • monitoring and improving the performance of our Services through analytics, site and application optimization and quality control;
  • relating to corporate transactions, such as if we acquire assets of another business or sell or transfer all or part of Flo; 
  • developing and improving our algorithms or machine learning tools for Services such as cycle predictions; and
  • as necessary to fulfill the limited circumstances detailed below. 

Research

We may aggregate, anonymize, or de-identify your Health Data so it can no longer reasonably be used to identify you. For example, we may use your general age and symptoms to help identify patterns across our members to improve the Services you receive. 

For targeted research that uses Health Data that has not been aggregated, anonymized or de-identified, we will contact you and will rely on your explicit consent. You can withdraw this consent at any time by emailing us at dpo@flo.health

How we disclose Health Data

We do not sell your personal information, including your Health Data.

We engage service providers to process your data, including Health Data, to help operate our Services, facilitate communication with you, provide the products and Services you request, and perform other app-related tasks. These companies, referred to as “processors,” are only allowed to use your Health Data in accordance with our contracts and in compliance with applicable law. For the list of the main processors we rely on, please refer to our main Privacy Policy

We may also share your Health Data with entities within Flo’s corporate group. These include: 

  • Flo Health UK Limited (based in the United Kingdom, and our registered data controller); 
  • Flo Health Cyprus Ltd (based in Cyprus); 
  • Flo Health LTU UAB (based in Lithuania); and
  • Flo Health NL. B.V. (based in the Netherlands). 

We may also disclose your Health Data when you have provided your consent - for example, third party providers like Apple HealthKit and Google Health Connect.

We may also disclose your Health Data under the following limited circumstances:

  • in response to subpoenas, court orders, or legal processes, as required by law (including to meet national security or law enforcement requirements) - we will exhaust available legal remedies to challenge such a request and will seek to limit the disclosure to the minimum necessary for the purpose. Learn more about Flo’s award-winning Anonymous Mode here;
  • when necessary to maintain the security and integrity of our Services or to protect the safety of any user or others, in accordance with applicable laws. In such cases, we may also delete certain personal data (e.g., resetting your password to prevent unauthorized access);
  • to assert our legal rights or defend against legal claims;
  • when you, as the user, direct or consent to the disclosure of your personal data; and
  • during an acquisition, business transfer, or reorganization involving any part of our business.

 

How we collect your consent

When we rely on your consent to process your Health Data, you will be asked to provide it when signing up for our Services. You can withdraw your consent at any time by contacting us at support@flo.health or by deleting your account through the App.

Please note that because our Services rely on your consent, withdrawing it will require you to delete your account.

Your rights

Regardless of your country, state, or region of residence, we’re committed to providing you the same privacy rights afforded under the GDPR, which is generally regarded as the highest standard for data protection globally.

In addition to the GDPR rights outlined in our main Privacy Policy, you have specific rights related to your Health Data, including the right to:

  • request confirmation that we collect or share your Health Data; 
  • request access to your Health Data that we have collected or control, including:
  • a list of all third parties and affiliates that we have shared your Health Data to; and
  • the email addresses or other online methods to contact those third parties and affiliates;
  • withdraw your consent for our collection and sharing of your Health Data. If you withdraw your consent to process Health Data, we will be unable to provide our Services; 
  • request that we delete your Health Data; 
  • be free from discriminatory treatment for exercising any of your privacy rights; 
  • If you are a resident of Washington, you have the right not to be subjected to discriminatory treatment for exercising any of your privacy rights. No matter where you are, exercising these rights will not result in discriminatory treatment, such as different prices or a reduction in the quality of our Service; 
  • please note: while your privacy rights will not impact the Service you receive, our pricing may vary over time or based on when you originally signed up. If you choose to stop using our Service in connection with exercising your rights and decide to return later, the price at that time may differ from your original rate; and
  • if we deny your rights-related request, you have the right to appeal the decision by contacting us at dpo@flo.health

You may exercise the rights available to you by emailing us at support@flo.health.

Contact Information

If you have any questions or concerns about your privacy, you may contact us or our data protection officer by writing to us at:

Flo Health, Inc.,

108 W. 13th Street,

Suite 100 Wilmington, DE 19801

Or by emailing us at support@flo.health or dpo@flo.health.