You're reading an archived version of our Privacy Policy. View the current version.​

When you use Flo, you are trusting us with intimate personal data. We are committed to keeping that trust, which is why our policy as a company is to take steps to ensure that individual user's data and privacy rights are protected and to provide transparency about our data practices. 

The purpose of our Privacy Policy is to explain what data we collect, how it is used and shared, and how you can control it.

Here’s a summary of our Privacy Policy to give you a quick overview of our data practices. The summary is not a substitute for reading the full policy to obtain important information about your personal data, how we use it and your rights with respect to it. Please read this Privacy Policy in full along with our Terms of Use, but here are a few key takeaways we hope you will find useful:
  • The data that serves you

    The data that serves you

    When you use Flo, we collect your Personal Data and may use it to improve the user experience, such as increasing the accuracy of predictions, personalizing product offers, the insights you get, etc. For research activities we use only de-identified or aggregated data, which cannot be associated with you.

  • You can contribute to the growth of the Flo community

    You can contribute to the growth of the Flo community

    If you consent, we may use technical information about your device and other information about you (such as your device’s unique technical identifier, age group, subscription status, and the fact of application launch) for promotional purposes to reach more people like you who we believe may be interested in using the Services. You can always withdraw your consent. Please see the section below titled “Processing to find new Flo users and stay in touch with you” for more information about how to withdraw your consent. 

  • You are in control

    You are in control

    You may ask to access, modify, correct, erase, and update your Personal Data by writing to us at support@flo.health. For iOS Flo Premium users, the App also enables you to download a report containing some of your Personal Data from within the App. Please be aware that erasing or modifying some Personal Data you have provided could affect your ability to use certain features of the App that rely on historic data. 

  • Securing your data

    Securing your data

    We take reasonable and appropriate measures to protect your Personal Data from loss, theft, misuse or unauthorized access.

  • We limit children’s access to the App

    We limit children’s access to the App

    You must be at least 13 to use the App (16 for European Economic Area (“EEA”) residents). We do not knowingly collect information from children under 13 (16 for EEA residents), and we do not allow people to use the App if they are younger than 13 (16 for EEA residents). Moreover, some of the App functions are limited for users that are younger than 18.

  • You can freely talk to us

    You can freely talk to us

    We believe in transparent and open dialogue, so we strongly encourage you to contact our Support Team at support@flo.health, our Data Protection Officer at dpo@flo.health or send a message via our dedicated email if you have questions about this Privacy Policy, how we collect or process your Personal Data, or anything else related to our privacy practices.

Introduction

This Privacy Policy explains how Flo Health, Inc. (“Flo” or “we” or “us”) collects, stores, uses, transfers and shares Personal Data from our users (“you”) in connection with the Flo mobile application, Flo Period & Ovulation Tracker (the “App”)*, and the flo.health website including any products and services related to it (the "Website") (all collectively, the “Services”).

*Please note the App may be listed under a different name depending on your location. A full list of names is available here

We reserve the right to and may change this Privacy Policy from time to time. If we make any material changes, we will notify you by email (sent to the email address provided when you register), through the App, or by presenting you with a new version of this Privacy Policy. If permitted by applicable law, your continued use of the Services after the effective date of an updated version of the Privacy Policy will indicate your acceptance of the Privacy Policy as modified. In some cases, you will be given a choice about whether to explicitly accept changes to the Privacy Policy. If you do not accept the terms of the Privacy Policy, please do not use the Services. 

Please check the Privacy Policy posted on our Website and in the App for the latest updates on our data privacy practices.

We collect Personal Data about you in a variety of ways. Sometimes we collect Personal Data automatically when you interact with the Services, and sometimes we collect the Personal Data directly from you. At times, we may receive Personal Data about you from other sources and third parties. 

Personal Data you provide to us directly:

General Information. When you sign up to use the Services, we may collect Personal Data about you such as:

  • Name;
  • Email address;
  • Year of birth;
  • Password or passcode;
  • Place of residence and associated location information including time zone and language;
  • ID (for limited purposes).

In many cases, we may be able to infer your gender by your use of the Services. 

Health and Well-being. When you sign up to use the Services, you may choose to provide Personal Data about your health and well-being such as:

  • Weight;
  • Body temperature;
  • Menstrual cycle dates;
  • Details of your pregnancy (if you select the pregnancy mode);
  • Various symptoms related to your menstrual cycle, pregnancy and health;
  • Other information about your health (including sexual activities), physical and mental well-being, and related activities, including personal life.

You may also allow us to connect to third-party services, such as Apple HealthKit and Google Fit, to enable us to import Personal Data about your health and activities into the App. This imported data may include sports activities, weight, calories burned, heart rate, number of steps/distance traveled, and other data about your health. We will process this data in order to provide you with the App functionality described below.  When you choose to have this data imported you are subject to the Google Fit and Apple HealthKit privacy policies and practices. 

Personal Data we collect automatically:

When you access or use the Services, we may automatically collect the following information:

Device Information:

  • Device model;
  • Information about the operating system and its version;
  • Unique device identifiers (e.g. IDFA);
  • Mobile operator and network information;
  • Device storage information;
  • Version of your device system.

Location Information:

  • IP address;
  • Time zone;
  • Information about your mobile service provider.

Data about your use of the Services, including, among others:

  • Frequency of use;
  • Areas and features of the Services that you access, visit or use;
  • Engagement with particular features.

To collect this and other information, we may use cookies and other tracking technologies. See more in our Cookie Policy.

Data from external sources. We may receive Personal Data about you from third parties. For example, we may obtain information from third parties, to enhance or supplement existing user information, including to customize and personalize your experience and for statistical purposes and analytics, as described below.

We will not collect and use your Personal Data without letting you know. Depending on which features of the Services you use, we will process your Personal Data based on one or more of the following legal bases:

  • Your consent. For example, on the registration screen when you give us permission to process your Personal Data;
  • To fulfill our contractual obligations to you in order to provide the Services to you;
  • Legitimate interest. We may process your Personal Data in relation to our interests in providing the Services to you, our commercial interests, including our interest in protecting the security and integrity of the Services, and wider societal benefits;
  • Legal obligation. We may be obligated to process some of your Personal Data to comply with applicable laws and regulations.

Below we describe the purposes for which we process your Personal Data and our lawful bases for doing so, including some basic examples:

Purpose of processingLegal basis for processingExample
To support the existing functions of the App, including customization of content and materials you see when you use the AppConsentWe make automated decisions using your cycle data to predict your future cycles or ovulation, analyze your data to provide you new features and services, and provide certain suggested articles or materials (e.g., stories, health assistant and secret chats) to read
customization of product and service offerings and making recommendations to you, including third-party products and offerings (excluding data from Apple HealthKit and Google Fit)ConsentWe may  offer you a discount for Flo Premium
to provide and deliver the products and services you request, process transactions and send you related information, including confirmations and remindersContractUsing your device data we may send you a reminder, e.g., via push notifications, to log your period or symptoms to make predictions more accurate. You can disable this anytime in your device settings or from within the App using the consent toggle screens
for billing (invoicing), account management and other administrative purposes, if applicableContractWe may send you an email containing your invoice, if applicable
to respond to your comments, questions and requests and to provide customer serviceLegitimate interestWe may process your name and email to reply to your support request or to contact you about a specific query or question you have raised
to send you technical notices, updates, security alerts and support and administrative messagesLegitimate interestWe may send you an email notification that contains a customer satisfaction survey. You can opt-out of receiving such surveys anytime by contacting us at support@flo.health
to integrate data between the Website and App in connection with onboarding usersLegitimate interestAs an example, when you sign-up for the Services on the Website we use a third-party, AppsFlyer, to help us identify you as an existing user when you use the App
to monitor and analyze trends, usage and activities in connection with our AppConsentWe may analyze your browsing activity in the App to understand what you like or dislike about it in order to improve your future experience
solely with respect to information that you agree to share, for Flo promotional purposes (except data from Apple HealthKit and Google Fit)ConsentIf you give your consent, we can post your review or comment on our website
to verify your identity Legal obligationWe may ask for age verification (e.g., an ID) if we have reasonable doubts regarding your age

Principles of processing

Data minimization and purpose limitation. We will not process Personal Data in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by you or collect any Personal Data that is not needed for the mentioned purposes. For any new purpose of processing we will ask your separate consent. 

No sale of Personal Data. We will not sell or rent your Personal Data. We will not disclose your Personal Data except as otherwise described in this Privacy Policy. We may share your Personal Data with our service providers solely as described in this Privacy Policy. We will also not use information received through your use of the HealthKit and Google Fit framework for advertising or similar services, or sell it to advertising platforms, data brokers, or information resellers.

It does not matter what country or region you come from, we are committed to providing you vast privacy rights in relation to your Personal Data.

What rights?

Correction of your Personal Data

Correction of your Personal Data

If you believe that your Personal Data is inaccurate, you have a right to contact us and ask us to correct such Personal Data.

Restriction of Processing

Restriction of Processing

You have a right to request that the processing of your Personal Data be restricted in some circumstances. For example, you have the right to request the restriction of your Personal Data if you contest the accuracy of your Personal Data and we need some time to verify its accuracy. 

Access to your Personal Data (including in portable form)

Access to your Personal Data (including in portable form)

You have a right to request information about what Personal Data we process about you, to access all your Personal Data, and receive a copy of it, including in a structured and portable form (.json). For iOS Flo Premium users, the App also enables you to download a report containing some of your Personal Data from within the App.

Erasure of your Personal Data

Erasure of your Personal Data

You may ask us to erase your Personal Data if you withdraw your consent to processing, if you believe such processing is unlawful. Please be aware that erasing some Personal Data may affect your experience using certain features of the Services that rely on historic data.

Right to object to the processing of your Personal Data

Right to object to the processing of your Personal Data

In some cases, you can object to the processing of your Personal Data, for example, if we process it under the legitimate interest basis, by contacting us at support@flo.health

How to exercise your privacy rights

Сontact us at support@flo.health to exercise your privacy rights.

We will address your request within 30 days after receipt. It may take us up to 90 days in some cases, for example for full erasure of your Personal Data stored in our backup systems. We will let you know if we need more time and explain the reasons for the delay. 

What else?

Please keep in mind that if we receive a vague request, we may contact you to better understand the request. We may also refuse to comply with a request that is manifestly unfounded and with excessive (repetitive) requests. 

We might also require you to prove your identity in some cases. Normally, we make sure to verify that the request is coming from the same email as you provided when registering. Where you have not registered your account, we may ask you to undergo additional verification measures in an effort to ensure we are appropriately responding to requests. 

Subject to applicable laws, you may have a right to lodge a complaint with your local data protection authority about any of our activities (related to your privacy rights, among others) that you think are not compliant with applicable law. If you have any concerns about our privacy practices, please let us know at privacy@flo.health

We will not share your Personal Data with third parties except as specified below.

Processing to find new Flo users and stay in touch with you

With your consent we may share some of your non-health Personal Data with AppsFlyer for marketing and promotional purposes. AppsFlyer is a mobile marketing platform that handles your Personal Data in accordance with our instructions. By using AppsFlyer and its integrated partners for marketing and promotional purposes we are able to reach you and people like you on various platforms and spread the word about Flo. If we need to share your Personal Data with other platforms for this purpose, except as we have explained in this Privacy Policy, we will ask for your consent

Here is a step-by-step illustration of how we work with AppsFlyer and its integrated partners for marketing and promotional purposes:

1. You become a Flo user and with your consent we start sharing the following Personal Data with AppsFlyer and its integrated partners for marketing and promotional purposes: 

a)  Technical identifiers: IP address (which may also provide general location information), User agent, IDFA (Identifier for advertisers), Android ID (in Android devices), Google Advertiser ID, Customer-issued user ID and other similar unique technical identifiers;
b) Your age group;
c) Your subscription status;
d) The fact of application launch.

2. Flo sends your Personal Data to AppsFlyer, which analyzes it and provides us reports and insights on how to optimize our promotional campaigns.

3. At the same time, AppsFlyer sends your Personal Data to some of its integrated partners (e.g., Pinterest, Google Ads, Apple Search Ads, FB marketing network and others) to find you or people like you on different platforms, including social media websites. These integrated partners analyze your Personal Data and show relevant information about Flo to people who might be potentially interested in it or remind you about revisiting the App, if you stopped using it a while ago. 

4. We reach out to you and new users and provide you with more information about Flo, accurate cycle predictions, information about the meaning of your bodies’ cues and credible information about your health. 

Read more about AppsFlyer here and its integrated partners here.

5. Opt-out options. You can withdraw your consent or opt-out from the sharing of your Personal Data with AppsFlyer for marketing and promotional purposes in accordance with this subsection anytime by adjusting your device settings in iOS or Android.

Please note that we also use AppsFlyer to integrate data between the Website and App in connection with onboarding users. You are not able to opt out of AppsFlyer’s processing of your Personal Data for these purposes.  

Processing to make the App run 

In some situations, we engage other companies to process your Personal Data on our behalf. We refer to these companies as “processors.” 

Processors are companies that help us run the Services, support our communication with you or perform other App-related activities. They may process certain Personal Data on our behalf to accomplish the goals related to the App functions and associated activities. We remain responsible for any acts or omissions of our processors and undertake to execute formal data processing agreements with them to the extent required by applicable law.

Here is the list of our main processors upon which we rely:

TypeProcessorProcessor's privacy policyData collectedPurpose
Infrastructure and securityAWS (Amazon Web Services, Inc.) AWS privacy policy
  • All Personal Data
  • storage of all Personal Data when you use the App
Infrastructure and securityCloudflare (Cloudflare, Inc.)Cloudflare privacy policy
  • All Personal Data
  • security of the App, content delivery
Infrastructure and securityAuth0 (Auth0, Inc.)Auth0 privacy and cookie policy
  • Email address
  • IP address
  • Name
  • authentication and authorization services
Email communicationsSendGrid (SendGrid, Inc., USA)SendGrid privacy policy
  • Email address
  • to reach you with our newsletters, surveys and notifications
Email communicationsHubSpot (HubSpot, Inc)HubSpot privacy policy
  • Email address
  • to reach you with our newsletters, emails and notifications
Email and in-App communicationsSurveyMonkey (SurveyMonkey Inc., USA)SurveyMonkey privacy policy
  • IP address
  • User ID
  • Results of surveys
  • to deliver different Service-related surveys
Analytical toolsLooker (Looker Data Sciences, Inc., USA)Looker privacy policy
  • App usage data
  • to understand how you use the App, engage with particular features and what you like or dislike the most
  • to generate statistical reports
Analytical toolsAmplitude (Amplitude, Inc.)Amplitude privacy policy
  • App usage data
  • to understand how you use the Web services, engage with particular features and what you like or dislike the most to engineer product experiences
Analytical toolsDataBricks (Databricks, Inc.)Databricks Privacy Policy
  • App usage data
  • to understand how you use the Web services, engage with particular features and what you like or dislike the most to engineer product experiences
Internal functionsAlgolia (Algolia, Inc.) Algolia privacy policy
  • IP address and user ID
  • Content of the search request
  • Age
  • Aim and usage purpose
  • to provide you search functions inside the App, including search suggestions for all users
  • Some Personal Data is needed to increase the accuracy of the search
Customer supportZendesk (Zendesk Inc., USA)Zendesk privacy policy
  • Email address
  • Content of the emails
  • to process and sort all emails received from you
Customer SupportCustomer ThermometerCustomer Thermometer privacy policy
  • Email address
  • Responses to surveys
  • to obtain customer feedback
Machine Learning Development PlatformTecton (Tecton, Inc.)Tecton Privacy Policy
  • Data relating to cycle dates, goals, symptoms
  • to enable the development of automated-decision making for providing you with predictions and app functionality
Payments 
Apple (Apple, Inc.)
Apple privacy policy
  • Payment and banking information
  • Personal identifiers
  • to collect and process payments for subscription to the App
Payments Google (Google LLC, USA)Google privacy policy
  • Payment and banking information
  • Personal identifiers
  • to collect and process payments for subscription