Last updated:

August 26, 2026

VYO Health Privacy Policy

1. Introduction

VYO Health (“VYO Health”, “we”, “us”, or “our”) respects and protects the privacy of users of the VYO Health mobile application, website, and related services (collectively, the “Service”).


This Privacy Policy explains how we collect, use, store, protect, and process personal data and health-related data when users access or use the Service.


VYO Health is designed as a preventive, educational, and lifestyle support platform and does not provide medical diagnosis or treatment.


Our data protection practices follow internationally recognized standards and applicable data protection laws, including:


Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

Applicable EU data protection laws and international privacy standards

GDPR-aligned safeguards supporting global users, including those located in the United States

2. Data Controller

The controller responsible for the processing of personal data described in this Privacy Policy is:


VYO Health LLC

Ukraine, 79052,

Str. Roksolyana 87/47, Lviv

Email: privacy@vyohealth.com 


VYO Health acts as the Data Controller for personal and health-related data processed through the Service.

  1. Definitions

For this Privacy Policy purposes:


Personal Data

Any information relating to an identified or identifiable natural person (“data subject”).


Processing

Any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, or deletion.


Special Category Data (Health Data)

Personal data concerning physical or mental health, including reproductive and hormonal health information, as defined under Article 9 GDPR.

  1. Categories of Data We Collect

We collect several categories of data necessary to provide and improve the Service.

4.1 Personal Identification Data

When creating an account or interacting with the Service, users may provide:


  • Name

  • Email address

  • Age or age group

  • Account identifiers

  • Communication preferences


Users may choose to use the application with minimal personal identifiers or pseudonymous identifiers, where technically feasible.

4.2 Health and Wellness Data (Special Category Data)

The Service allows users to voluntarily record health-related information, which may include:


  • Menstrual cycle information

  • Reproductive and hormonal health information

  • Pregnancy or childbirth history

  • Symptoms and symptom severity

  • Pain levels

  • Lifestyle and wellness information (for example, age and body metrics, product and nutrition preferences, shopping lists, etc.)

  • Preventive health indicators

  • Diagnosis information voluntarily entered by the user

  • Data imported from wearable devices or integrations such as Apple Health Kit and others


This data constitutes special category personal data under Article 9 GDPR and is processed only with explicit user consent.

Profile images are treated as account information rather than health information.

4.3 Technical and Usage Data

When users interact with the Service, certain technical information may be collected automatically, including:


  • Device type and operating system

  • App usage patterns

  • Log data and performance metrics

  • Anonymous identifiers

  • System diagnostics and security logs

This information is used to ensure service functionality, security, and technical improvement.

We use crash reporting and analytics services (such as Firebase Crashlytics and Firebase Analytics) to identify software failures, monitor application stability, and understand product usage patterns.

Crash reports contain technical diagnostic information such as device model, operating system version, application version, and error logs. Crash reports are configured not to include health records, menstrual cycle information, symptoms, notes, diagnoses, or other special category personal data.

Analytics events are limited to product usage metrics, such as screen views and feature interactions, and are configured not to include health records or other special category personal data.

  1. How We Use Personal Data

We process personal and health-related data for the following purposes:


  • Providing the core functionality of the Service

  • Generating preventive health insights and recommendations

  • Supporting lifestyle and wellness monitoring

  • Improving application functionality and user experience

  • Maintaining service security and reliability

  • Conducting internal research and development of preventive methodologies

  • Supporting anonymized scientific or statistical analysis


The Service does not provide medical diagnosis, treatment, or clinical decision support.

  1. Legal Bases for Processing

Under GDPR, we process personal data based on the following legal bases:


Consent – Article 6(1)(a) GDPR


Users provide consent for:

  • creation and use of their account

  • operation of the Service

  • communication related to their use of the Service

Explicit Consent – Article 9(2)(a) GDPR

Explicit consent is required for processing health-related data and other special category data.

Users may withdraw consent at any time by contacting us or deleting their account.

  1. Data Minimization and Privacy-by-Design

VYO Health is designed with privacy-by-design and privacy-by-default principles, in line with Article 25 of the GDPR.

This includes:

  • collecting only the data necessary to operate the Service

  • reducing the use of direct identifiers where possible

  • applying pseudonymization techniques to sensitive datasets

  • limiting internal access to authorized personnel and systems only

  1. Data Storage, Infrastructure, and Protection

VYO Health uses secure cloud infrastructure to host and process data.

Primary infrastructure is hosted on secure cloud infrastructure operated by our service providers. Your data is stored in the European Economic Area (EEA), with our primary database located in the West EU region (Ireland). When data is processed outside the EEA, we use providers that offer adequate safeguards (e.g. standard contractual clauses, certifications).

Security measures include:

  • encryption of data in transit and at rest

  • access control mechanisms

  • system monitoring and logging

  • secure development practices


Some of the information processed in the app may qualify as health data under applicable data protection laws. We apply additional safeguards when processing such data, including restricted access, secure storage, and processing only for the purposes necessary to provide the service.


Security practices are designed in alignment with recognized standards, including ISO 27001 security principles and safeguards commonly applied to sensitive health data.

8.1 Where Your Data Is Stored

Our infrastructure manages authentication, our database, and file storage (such as profile images). Our primary database is located in the European Economic Area (EEA), in the West EU region (Ireland).

In some cases, data may be processed outside the EEA. In such cases, we rely on providers that implement appropriate safeguards required under applicable data protection laws (such as standard contractual clauses).

Within our infrastructure, account information, health records, user preferences, authentication records, and uploaded files are stored in separate logical storage areas according to their purpose.

Profile images are stored separately in secure object storage.

Some limited data (such as authentication tokens and basic app state) may be stored locally on your device to keep you signed in and improve app performance. This data is removed when you sign out or delete the app.

8.2 How We Protect Your Data

We implement appropriate technical and organizational measures to protect personal data.

Access to data is restricted to authorized personnel and systems necessary to operate the app.


We use standard security practices, including:

  • encrypted data transmission (e.g., TLS)

  • secure authentication

  • access control mechanisms

Our database also uses row-level security, ensuring users can access only their own data.

8.3 Pseudonymization and Data Separation

In practice, this means your name and email address are stored separately from your cycle, symptom, and health information.

We intentionally separate account information (such as your email address and profile details) from health information wherever reasonably possible. This architecture reduces the amount of personally identifiable information directly associated with health records and supports our privacy-by-design approach.

We implement privacy-by-design principles to protect user data and minimize the risk of identification.

Personal account information (such as name and email address) is stored in our authentication system and managed separately from health-related information.

Health and sensitive data (such as menstrual cycle information, symptoms, questionnaire responses, and assessment results) are stored in dedicated application tables. Health records are associated with an internal system identifier (user ID) rather than directly with personal identifiers such as your name or email address.

This approach allows health data to be processed without directly exposing personal identity information.

Access to these datasets is restricted through strict access controls and database security policies, including row-level security, which ensures that users and application services can only access data that belongs to the relevant account.

This architecture reduces the risk of unauthorized access and supports compliance with applicable data protection regulations, including the principles of data minimization and pseudonymization under the GDPR.

8.4 How Long We Keep Your Data

We retain your data while your account is active and as needed to provide our services.

You may request deletion of your data at any time, for instance, by deleting your account.

We will delete or anonymize your data unless we are required to retain certain information for legal reasons.

8.5 Deleting Your Account

You can delete your account at any time in the app:

Profile → Personal → Delete account

You will be asked to confirm this action. Once completed, it cannot be reversed.

When your account is deleted, your authentication record is permanently removed. As a result, the following data is also deleted:

  • profile information (name, email, avatar, body metrics, onboarding status, quiz progress, consent records)

  • all health and wellness data (from cycle information, symptoms, pain details, diagnoses, reports, or any product preferences, etc.)

    Deleted data is either permanently removed or irreversibly anonymized. Deleting your account permanently removes your personal data from our systems in accordance with this policy.

    Encrypted backup copies may temporarily retain deleted data solely for disaster recovery purposes until the normal backup rotation cycle completes, after which they are also deleted.

  1. Data Sharing and Processors

VYO Health does not sell personal data or health data.


Personal data may be shared only in limited circumstances:

  • with service providers acting as data processors that support infrastructure, analytics, or technical operations

  • when required to comply with legal obligations

  • when explicitly authorized by the user

All processors are contractually required to:

  • process data only under our instructions

  • comply with applicable data protection laws, including GDPR

  • implement appropriate technical and organizational safeguards

Health data is not shared with advertising platforms or data brokers.

Health and other special category data is not shared with processors for advertising, marketing, or analytics purposes. Where analytics or infrastructure processors are used, they receive only pseudonymized technical or usage data as described in Section 4.3.

9.1 Law Enforcement and Legal Requests

We disclose personal or health data in response to law enforcement or government requests only where we are presented with a valid legal order (such as a court order or equivalent binding legal process) from a jurisdiction in which we operate. We do not disclose such data in response to informal or non-binding requests.

Where legally permitted, we may notify the affected user before disclosure.

  1. International Data Transfers

In some cases, data processing may involve infrastructure or service providers located outside the European Economic Area (EEA).

When such transfers occur, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses approved by the European Commission

  • contractual data protection commitments

  • additional technical safeguards such as encryption and pseudonymization

  1. User Rights

Users have the following rights under applicable data protection laws, including GDPR:

  • Right of access to personal data

  • Right to correct inaccurate data

  • Right to deletion (“right to be forgotten”)

  • Right to restrict processing

  • Right to object to processing

  • Right to data portability

  • Right to withdraw consent at any time


Requests can be submitted to:

privacy@vyohealth.com

We will respond to requests within the timeframe required by applicable law.

Users also have the right to lodge a complaint with their local data protection authority.

  1. Data Security

VYO Health implements technical and organizational security measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction.

Security safeguards may include:

  • encryption of data in transit (for example, TLS)

  • encryption of stored data where supported by the underlying infrastructure

  • pseudonymization of certain sensitive datasets

  • restricted access controls and database security policies

  • secure cloud infrastructure and basic system monitoring

While we implement strong safeguards to protect personal data, no system can guarantee absolute security.

  1. Research and Preventive Health Insights

To improve preventive health methodologies and the quality of the Service, VYO Health may use aggregated or anonymized data for research and statistical analysis.

Such data:

  • cannot identify individual users

  • does not contain personal identifiers

  • may contribute to the scientific understanding of preventive health patterns

Anonymization applied for research purposes is irreversible. Aggregated or anonymized datasets cannot reasonably be used to re-identify individual users.

Any research involving identifiable personal data would require separate explicit consent.

  1. Evidence-Based Methodology

Insights and recommendations provided through the Service are based on scientific and evidence-based methodologies.

These may include:

  • peer-reviewed scientific literature

  • recognized clinical and academic research

  • expert input from qualified medical and scientific professionals

Internal documentation describing the research methodology and validation framework may be maintained and shared with relevant partners, certification bodies, or regulatory authorities where appropriate.

  1. Medical Disclaimer

VYO Health is a preventive, educational, and lifestyle support application.


The Service:

  • does not provide a medical diagnosis

  • does not provide medical treatment

  • does not replace professional medical advice

All information provided through the Service is for informational and educational purposes only.

Users should consult qualified healthcare professionals for medical decisions.


VYO Health assumes no liability for health decisions or outcomes resulting from reliance on the Service.

The Service is not intended to be classified as a regulated medical device under applicable EU or U.S. medical device regulations.


Never disregard professional medical advice or delay seeking medical care because of information provided by the Service.

  1. Children’s Privacy

The Service is not intended for children or underage individuals.

Users must be at least:

  • 16 years old, or

  • the minimum age required by applicable law in their jurisdiction (for example, if you are located in the United States, you cannot use the VYO Health app if you are under 13 years old)

We do not knowingly collect personal data from children who do not meet the applicable minimum age. If we become aware that such data has been collected, we will take steps to delete it.

  1. Changes to This Privacy Policy

Our website may use cookies and similar technologies to ensure the site functions correctly, remember your preferences, and understand aggregate site usage (for example, through website analytics tools).

You can control or disable cookies through your browser settings. Disabling cookies may affect certain website features.

  1. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in:

  • legal requirements

  • technology

  • data processing practices

  • service functionality


If material changes occur, users will be notified through the Service or by email where appropriate.

The latest version will always be available within the Service or on our website.

  1. Contact

For questions about this Privacy Policy or our data protection practices:

privacy@vyohealth.com 

Last updated:

August 26, 2026

VYO Health Privacy Policy

1. Introduction

VYO Health (“VYO Health”, “we”, “us”, or “our”) respects and protects the privacy of users of the VYO Health mobile application, website, and related services (collectively, the “Service”).


This Privacy Policy explains how we collect, use, store, protect, and process personal data and health-related data when users access or use the Service.


VYO Health is designed as a preventive, educational, and lifestyle support platform and does not provide medical diagnosis or treatment.


Our data protection practices follow internationally recognized standards and applicable data protection laws, including:


Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

Applicable EU data protection laws and international privacy standards

GDPR-aligned safeguards supporting global users, including those located in the United States

2. Data Controller

The controller responsible for the processing of personal data described in this Privacy Policy is:


VYO Health LLC

Ukraine, 79052,

Str. Roksolyana 87/47, Lviv

Email: privacy@vyohealth.com 


VYO Health acts as the Data Controller for personal and health-related data processed through the Service.

  1. Definitions

For this Privacy Policy purposes:


Personal Data

Any information relating to an identified or identifiable natural person (“data subject”).


Processing

Any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, or deletion.


Special Category Data (Health Data)

Personal data concerning physical or mental health, including reproductive and hormonal health information, as defined under Article 9 GDPR.

  1. Categories of Data We Collect

We collect several categories of data necessary to provide and improve the Service.

4.1 Personal Identification Data

When creating an account or interacting with the Service, users may provide:


  • Name

  • Email address

  • Age or age group

  • Account identifiers

  • Communication preferences


Users may choose to use the application with minimal personal identifiers or pseudonymous identifiers, where technically feasible.

4.2 Health and Wellness Data (Special Category Data)

The Service allows users to voluntarily record health-related information, which may include:


  • Menstrual cycle information

  • Reproductive and hormonal health information

  • Pregnancy or childbirth history

  • Symptoms and symptom severity

  • Pain levels

  • Lifestyle and wellness information (for example, age and body metrics, product and nutrition preferences, shopping lists, etc.)

  • Preventive health indicators

  • Diagnosis information voluntarily entered by the user

  • Data imported from wearable devices or integrations such as Apple Health Kit and others


This data constitutes special category personal data under Article 9 GDPR and is processed only with explicit user consent.

Profile images are treated as account information rather than health information.

4.3 Technical and Usage Data

When users interact with the Service, certain technical information may be collected automatically, including:


  • Device type and operating system

  • App usage patterns

  • Log data and performance metrics

  • Anonymous identifiers

  • System diagnostics and security logs

This information is used to ensure service functionality, security, and technical improvement.

We use crash reporting and analytics services (such as Firebase Crashlytics and Firebase Analytics) to identify software failures, monitor application stability, and understand product usage patterns.

Crash reports contain technical diagnostic information such as device model, operating system version, application version, and error logs. Crash reports are configured not to include health records, menstrual cycle information, symptoms, notes, diagnoses, or other special category personal data.

Analytics events are limited to product usage metrics, such as screen views and feature interactions, and are configured not to include health records or other special category personal data.

  1. How We Use Personal Data

We process personal and health-related data for the following purposes:


  • Providing the core functionality of the Service

  • Generating preventive health insights and recommendations

  • Supporting lifestyle and wellness monitoring

  • Improving application functionality and user experience

  • Maintaining service security and reliability

  • Conducting internal research and development of preventive methodologies

  • Supporting anonymized scientific or statistical analysis


The Service does not provide medical diagnosis, treatment, or clinical decision support.

  1. Legal Bases for Processing

Under GDPR, we process personal data based on the following legal bases:


Consent – Article 6(1)(a) GDPR


Users provide consent for:

  • creation and use of their account

  • operation of the Service

  • communication related to their use of the Service

Explicit Consent – Article 9(2)(a) GDPR

Explicit consent is required for processing health-related data and other special category data.

Users may withdraw consent at any time by contacting us or deleting their account.

  1. Data Minimization and Privacy-by-Design

VYO Health is designed with privacy-by-design and privacy-by-default principles, in line with Article 25 of the GDPR.

This includes:

  • collecting only the data necessary to operate the Service

  • reducing the use of direct identifiers where possible

  • applying pseudonymization techniques to sensitive datasets

  • limiting internal access to authorized personnel and systems only

  1. Data Storage, Infrastructure, and Protection

VYO Health uses secure cloud infrastructure to host and process data.

Primary infrastructure is hosted on secure cloud infrastructure operated by our service providers. Your data is stored in the European Economic Area (EEA), with our primary database located in the West EU region (Ireland). When data is processed outside the EEA, we use providers that offer adequate safeguards (e.g. standard contractual clauses, certifications).

Security measures include:

  • encryption of data in transit and at rest

  • access control mechanisms

  • system monitoring and logging

  • secure development practices


Some of the information processed in the app may qualify as health data under applicable data protection laws. We apply additional safeguards when processing such data, including restricted access, secure storage, and processing only for the purposes necessary to provide the service.


Security practices are designed in alignment with recognized standards, including ISO 27001 security principles and safeguards commonly applied to sensitive health data.

8.1 Where Your Data Is Stored

Our infrastructure manages authentication, our database, and file storage (such as profile images). Our primary database is located in the European Economic Area (EEA), in the West EU region (Ireland).

In some cases, data may be processed outside the EEA. In such cases, we rely on providers that implement appropriate safeguards required under applicable data protection laws (such as standard contractual clauses).

Within our infrastructure, account information, health records, user preferences, authentication records, and uploaded files are stored in separate logical storage areas according to their purpose.

Profile images are stored separately in secure object storage.

Some limited data (such as authentication tokens and basic app state) may be stored locally on your device to keep you signed in and improve app performance. This data is removed when you sign out or delete the app.

8.2 How We Protect Your Data

We implement appropriate technical and organizational measures to protect personal data.

Access to data is restricted to authorized personnel and systems necessary to operate the app.


We use standard security practices, including:

  • encrypted data transmission (e.g., TLS)

  • secure authentication

  • access control mechanisms

Our database also uses row-level security, ensuring users can access only their own data.

8.3 Pseudonymization and Data Separation

In practice, this means your name and email address are stored separately from your cycle, symptom, and health information.

We intentionally separate account information (such as your email address and profile details) from health information wherever reasonably possible. This architecture reduces the amount of personally identifiable information directly associated with health records and supports our privacy-by-design approach.

We implement privacy-by-design principles to protect user data and minimize the risk of identification.

Personal account information (such as name and email address) is stored in our authentication system and managed separately from health-related information.

Health and sensitive data (such as menstrual cycle information, symptoms, questionnaire responses, and assessment results) are stored in dedicated application tables. Health records are associated with an internal system identifier (user ID) rather than directly with personal identifiers such as your name or email address.

This approach allows health data to be processed without directly exposing personal identity information.

Access to these datasets is restricted through strict access controls and database security policies, including row-level security, which ensures that users and application services can only access data that belongs to the relevant account.

This architecture reduces the risk of unauthorized access and supports compliance with applicable data protection regulations, including the principles of data minimization and pseudonymization under the GDPR.

8.4 How Long We Keep Your Data

We retain your data while your account is active and as needed to provide our services.

You may request deletion of your data at any time, for instance, by deleting your account.

We will delete or anonymize your data unless we are required to retain certain information for legal reasons.

8.5 Deleting Your Account

You can delete your account at any time in the app:

Profile → Personal → Delete account

You will be asked to confirm this action. Once completed, it cannot be reversed.

When your account is deleted, your authentication record is permanently removed. As a result, the following data is also deleted:

  • profile information (name, email, avatar, body metrics, onboarding status, quiz progress, consent records)

  • all health and wellness data (from cycle information, symptoms, pain details, diagnoses, reports, or any product preferences, etc.)

    Deleted data is either permanently removed or irreversibly anonymized. Deleting your account permanently removes your personal data from our systems in accordance with this policy.

    Encrypted backup copies may temporarily retain deleted data solely for disaster recovery purposes until the normal backup rotation cycle completes, after which they are also deleted.

  1. Data Sharing and Processors

VYO Health does not sell personal data or health data.


Personal data may be shared only in limited circumstances:

  • with service providers acting as data processors that support infrastructure, analytics, or technical operations

  • when required to comply with legal obligations

  • when explicitly authorized by the user

All processors are contractually required to:

  • process data only under our instructions

  • comply with applicable data protection laws, including GDPR

  • implement appropriate technical and organizational safeguards

Health data is not shared with advertising platforms or data brokers.

Health and other special category data is not shared with processors for advertising, marketing, or analytics purposes. Where analytics or infrastructure processors are used, they receive only pseudonymized technical or usage data as described in Section 4.3.

9.1 Law Enforcement and Legal Requests

We disclose personal or health data in response to law enforcement or government requests only where we are presented with a valid legal order (such as a court order or equivalent binding legal process) from a jurisdiction in which we operate. We do not disclose such data in response to informal or non-binding requests.

Where legally permitted, we may notify the affected user before disclosure.

  1. International Data Transfers

In some cases, data processing may involve infrastructure or service providers located outside the European Economic Area (EEA).

When such transfers occur, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses approved by the European Commission

  • contractual data protection commitments

  • additional technical safeguards such as encryption and pseudonymization

  1. User Rights

Users have the following rights under applicable data protection laws, including GDPR:

  • Right of access to personal data

  • Right to correct inaccurate data

  • Right to deletion (“right to be forgotten”)

  • Right to restrict processing

  • Right to object to processing

  • Right to data portability

  • Right to withdraw consent at any time


Requests can be submitted to:

privacy@vyohealth.com

We will respond to requests within the timeframe required by applicable law.

Users also have the right to lodge a complaint with their local data protection authority.

  1. Data Security

VYO Health implements technical and organizational security measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction.

Security safeguards may include:

  • encryption of data in transit (for example, TLS)

  • encryption of stored data where supported by the underlying infrastructure

  • pseudonymization of certain sensitive datasets

  • restricted access controls and database security policies

  • secure cloud infrastructure and basic system monitoring

While we implement strong safeguards to protect personal data, no system can guarantee absolute security.

  1. Research and Preventive Health Insights

To improve preventive health methodologies and the quality of the Service, VYO Health may use aggregated or anonymized data for research and statistical analysis.

Such data:

  • cannot identify individual users

  • does not contain personal identifiers

  • may contribute to the scientific understanding of preventive health patterns

Anonymization applied for research purposes is irreversible. Aggregated or anonymized datasets cannot reasonably be used to re-identify individual users.

Any research involving identifiable personal data would require separate explicit consent.

  1. Evidence-Based Methodology

Insights and recommendations provided through the Service are based on scientific and evidence-based methodologies.

These may include:

  • peer-reviewed scientific literature

  • recognized clinical and academic research

  • expert input from qualified medical and scientific professionals

Internal documentation describing the research methodology and validation framework may be maintained and shared with relevant partners, certification bodies, or regulatory authorities where appropriate.

  1. Medical Disclaimer

VYO Health is a preventive, educational, and lifestyle support application.


The Service:

  • does not provide a medical diagnosis

  • does not provide medical treatment

  • does not replace professional medical advice

All information provided through the Service is for informational and educational purposes only.

Users should consult qualified healthcare professionals for medical decisions.


VYO Health assumes no liability for health decisions or outcomes resulting from reliance on the Service.

The Service is not intended to be classified as a regulated medical device under applicable EU or U.S. medical device regulations.


Never disregard professional medical advice or delay seeking medical care because of information provided by the Service.

  1. Children’s Privacy

The Service is not intended for children or underage individuals.

Users must be at least:

  • 16 years old, or

  • the minimum age required by applicable law in their jurisdiction (for example, if you are located in the United States, you cannot use the VYO Health app if you are under 13 years old)

We do not knowingly collect personal data from children who do not meet the applicable minimum age. If we become aware that such data has been collected, we will take steps to delete it.

  1. Changes to This Privacy Policy

Our website may use cookies and similar technologies to ensure the site functions correctly, remember your preferences, and understand aggregate site usage (for example, through website analytics tools).

You can control or disable cookies through your browser settings. Disabling cookies may affect certain website features.

  1. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in:

  • legal requirements

  • technology

  • data processing practices

  • service functionality


If material changes occur, users will be notified through the Service or by email where appropriate.

The latest version will always be available within the Service or on our website.

  1. Contact

For questions about this Privacy Policy or our data protection practices:

privacy@vyohealth.com 

Last updated:

August 26, 2026

VYO Health Privacy Policy

1. Introduction

VYO Health (“VYO Health”, “we”, “us”, or “our”) respects and protects the privacy of users of the VYO Health mobile application, website, and related services (collectively, the “Service”).


This Privacy Policy explains how we collect, use, store, protect, and process personal data and health-related data when users access or use the Service.


VYO Health is designed as a preventive, educational, and lifestyle support platform and does not provide medical diagnosis or treatment.


Our data protection practices follow internationally recognized standards and applicable data protection laws, including:


Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

Applicable EU data protection laws and international privacy standards

GDPR-aligned safeguards supporting global users, including those located in the United States

2. Data Controller

The controller responsible for the processing of personal data described in this Privacy Policy is:


VYO Health LLC

Ukraine, 79052,

Str. Roksolyana 87/47, Lviv

Email: privacy@vyohealth.com 


VYO Health acts as the Data Controller for personal and health-related data processed through the Service.

  1. Definitions

For this Privacy Policy purposes:


Personal Data

Any information relating to an identified or identifiable natural person (“data subject”).


Processing

Any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, or deletion.


Special Category Data (Health Data)

Personal data concerning physical or mental health, including reproductive and hormonal health information, as defined under Article 9 GDPR.

  1. Categories of Data We Collect

We collect several categories of data necessary to provide and improve the Service.

4.1 Personal Identification Data

When creating an account or interacting with the Service, users may provide:


  • Name

  • Email address

  • Age or age group

  • Account identifiers

  • Communication preferences


Users may choose to use the application with minimal personal identifiers or pseudonymous identifiers, where technically feasible.

4.2 Health and Wellness Data (Special Category Data)

The Service allows users to voluntarily record health-related information, which may include:


  • Menstrual cycle information

  • Reproductive and hormonal health information

  • Pregnancy or childbirth history

  • Symptoms and symptom severity

  • Pain levels

  • Lifestyle and wellness information (for example, age and body metrics, product and nutrition preferences, shopping lists, etc.)

  • Preventive health indicators

  • Diagnosis information voluntarily entered by the user

  • Data imported from wearable devices or integrations such as Apple Health Kit and others


This data constitutes special category personal data under Article 9 GDPR and is processed only with explicit user consent.

Profile images are treated as account information rather than health information.

4.3 Technical and Usage Data

When users interact with the Service, certain technical information may be collected automatically, including:


  • Device type and operating system

  • App usage patterns

  • Log data and performance metrics

  • Anonymous identifiers

  • System diagnostics and security logs

This information is used to ensure service functionality, security, and technical improvement.

We use crash reporting and analytics services (such as Firebase Crashlytics and Firebase Analytics) to identify software failures, monitor application stability, and understand product usage patterns.

Crash reports contain technical diagnostic information such as device model, operating system version, application version, and error logs. Crash reports are configured not to include health records, menstrual cycle information, symptoms, notes, diagnoses, or other special category personal data.

Analytics events are limited to product usage metrics, such as screen views and feature interactions, and are configured not to include health records or other special category personal data.

  1. How We Use Personal Data

We process personal and health-related data for the following purposes:


  • Providing the core functionality of the Service

  • Generating preventive health insights and recommendations

  • Supporting lifestyle and wellness monitoring

  • Improving application functionality and user experience

  • Maintaining service security and reliability

  • Conducting internal research and development of preventive methodologies

  • Supporting anonymized scientific or statistical analysis


The Service does not provide medical diagnosis, treatment, or clinical decision support.

  1. Legal Bases for Processing

Under GDPR, we process personal data based on the following legal bases:


Consent – Article 6(1)(a) GDPR


Users provide consent for:

  • creation and use of their account

  • operation of the Service

  • communication related to their use of the Service

Explicit Consent – Article 9(2)(a) GDPR

Explicit consent is required for processing health-related data and other special category data.

Users may withdraw consent at any time by contacting us or deleting their account.

  1. Data Minimization and Privacy-by-Design

VYO Health is designed with privacy-by-design and privacy-by-default principles, in line with Article 25 of the GDPR.

This includes:

  • collecting only the data necessary to operate the Service

  • reducing the use of direct identifiers where possible

  • applying pseudonymization techniques to sensitive datasets

  • limiting internal access to authorized personnel and systems only

  1. Data Storage, Infrastructure, and Protection

VYO Health uses secure cloud infrastructure to host and process data.

Primary infrastructure is hosted on secure cloud infrastructure operated by our service providers. Your data is stored in the European Economic Area (EEA), with our primary database located in the West EU region (Ireland). When data is processed outside the EEA, we use providers that offer adequate safeguards (e.g. standard contractual clauses, certifications).

Security measures include:

  • encryption of data in transit and at rest

  • access control mechanisms

  • system monitoring and logging

  • secure development practices


Some of the information processed in the app may qualify as health data under applicable data protection laws. We apply additional safeguards when processing such data, including restricted access, secure storage, and processing only for the purposes necessary to provide the service.


Security practices are designed in alignment with recognized standards, including ISO 27001 security principles and safeguards commonly applied to sensitive health data.

8.1 Where Your Data Is Stored

Our infrastructure manages authentication, our database, and file storage (such as profile images). Our primary database is located in the European Economic Area (EEA), in the West EU region (Ireland).

In some cases, data may be processed outside the EEA. In such cases, we rely on providers that implement appropriate safeguards required under applicable data protection laws (such as standard contractual clauses).

Within our infrastructure, account information, health records, user preferences, authentication records, and uploaded files are stored in separate logical storage areas according to their purpose.

Profile images are stored separately in secure object storage.

Some limited data (such as authentication tokens and basic app state) may be stored locally on your device to keep you signed in and improve app performance. This data is removed when you sign out or delete the app.

8.2 How We Protect Your Data

We implement appropriate technical and organizational measures to protect personal data.

Access to data is restricted to authorized personnel and systems necessary to operate the app.


We use standard security practices, including:

  • encrypted data transmission (e.g., TLS)

  • secure authentication

  • access control mechanisms

Our database also uses row-level security, ensuring users can access only their own data.

8.3 Pseudonymization and Data Separation

In practice, this means your name and email address are stored separately from your cycle, symptom, and health information.

We intentionally separate account information (such as your email address and profile details) from health information wherever reasonably possible. This architecture reduces the amount of personally identifiable information directly associated with health records and supports our privacy-by-design approach.

We implement privacy-by-design principles to protect user data and minimize the risk of identification.

Personal account information (such as name and email address) is stored in our authentication system and managed separately from health-related information.

Health and sensitive data (such as menstrual cycle information, symptoms, questionnaire responses, and assessment results) are stored in dedicated application tables. Health records are associated with an internal system identifier (user ID) rather than directly with personal identifiers such as your name or email address.

This approach allows health data to be processed without directly exposing personal identity information.

Access to these datasets is restricted through strict access controls and database security policies, including row-level security, which ensures that users and application services can only access data that belongs to the relevant account.

This architecture reduces the risk of unauthorized access and supports compliance with applicable data protection regulations, including the principles of data minimization and pseudonymization under the GDPR.

8.4 How Long We Keep Your Data

We retain your data while your account is active and as needed to provide our services.

You may request deletion of your data at any time, for instance, by deleting your account.

We will delete or anonymize your data unless we are required to retain certain information for legal reasons.

8.5 Deleting Your Account

You can delete your account at any time in the app:

Profile → Personal → Delete account

You will be asked to confirm this action. Once completed, it cannot be reversed.

When your account is deleted, your authentication record is permanently removed. As a result, the following data is also deleted:

  • profile information (name, email, avatar, body metrics, onboarding status, quiz progress, consent records)

  • all health and wellness data (from cycle information, symptoms, pain details, diagnoses, reports, or any product preferences, etc.)

    Deleted data is either permanently removed or irreversibly anonymized. Deleting your account permanently removes your personal data from our systems in accordance with this policy.

    Encrypted backup copies may temporarily retain deleted data solely for disaster recovery purposes until the normal backup rotation cycle completes, after which they are also deleted.

  1. Data Sharing and Processors

VYO Health does not sell personal data or health data.


Personal data may be shared only in limited circumstances:

  • with service providers acting as data processors that support infrastructure, analytics, or technical operations

  • when required to comply with legal obligations

  • when explicitly authorized by the user

All processors are contractually required to:

  • process data only under our instructions

  • comply with applicable data protection laws, including GDPR

  • implement appropriate technical and organizational safeguards

Health data is not shared with advertising platforms or data brokers.

Health and other special category data is not shared with processors for advertising, marketing, or analytics purposes. Where analytics or infrastructure processors are used, they receive only pseudonymized technical or usage data as described in Section 4.3.

9.1 Law Enforcement and Legal Requests

We disclose personal or health data in response to law enforcement or government requests only where we are presented with a valid legal order (such as a court order or equivalent binding legal process) from a jurisdiction in which we operate. We do not disclose such data in response to informal or non-binding requests.

Where legally permitted, we may notify the affected user before disclosure.

  1. International Data Transfers

In some cases, data processing may involve infrastructure or service providers located outside the European Economic Area (EEA).

When such transfers occur, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses approved by the European Commission

  • contractual data protection commitments

  • additional technical safeguards such as encryption and pseudonymization

  1. User Rights

Users have the following rights under applicable data protection laws, including GDPR:

  • Right of access to personal data

  • Right to correct inaccurate data

  • Right to deletion (“right to be forgotten”)

  • Right to restrict processing

  • Right to object to processing

  • Right to data portability

  • Right to withdraw consent at any time


Requests can be submitted to:

privacy@vyohealth.com

We will respond to requests within the timeframe required by applicable law.

Users also have the right to lodge a complaint with their local data protection authority.

  1. Data Security

VYO Health implements technical and organizational security measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction.

Security safeguards may include:

  • encryption of data in transit (for example, TLS)

  • encryption of stored data where supported by the underlying infrastructure

  • pseudonymization of certain sensitive datasets

  • restricted access controls and database security policies

  • secure cloud infrastructure and basic system monitoring

While we implement strong safeguards to protect personal data, no system can guarantee absolute security.

  1. Research and Preventive Health Insights

To improve preventive health methodologies and the quality of the Service, VYO Health may use aggregated or anonymized data for research and statistical analysis.

Such data:

  • cannot identify individual users

  • does not contain personal identifiers

  • may contribute to the scientific understanding of preventive health patterns

Anonymization applied for research purposes is irreversible. Aggregated or anonymized datasets cannot reasonably be used to re-identify individual users.

Any research involving identifiable personal data would require separate explicit consent.

  1. Evidence-Based Methodology

Insights and recommendations provided through the Service are based on scientific and evidence-based methodologies.

These may include:

  • peer-reviewed scientific literature

  • recognized clinical and academic research

  • expert input from qualified medical and scientific professionals

Internal documentation describing the research methodology and validation framework may be maintained and shared with relevant partners, certification bodies, or regulatory authorities where appropriate.

  1. Medical Disclaimer

VYO Health is a preventive, educational, and lifestyle support application.


The Service:

  • does not provide a medical diagnosis

  • does not provide medical treatment

  • does not replace professional medical advice

All information provided through the Service is for informational and educational purposes only.

Users should consult qualified healthcare professionals for medical decisions.


VYO Health assumes no liability for health decisions or outcomes resulting from reliance on the Service.

The Service is not intended to be classified as a regulated medical device under applicable EU or U.S. medical device regulations.


Never disregard professional medical advice or delay seeking medical care because of information provided by the Service.

  1. Children’s Privacy

The Service is not intended for children or underage individuals.

Users must be at least:

  • 16 years old, or

  • the minimum age required by applicable law in their jurisdiction (for example, if you are located in the United States, you cannot use the VYO Health app if you are under 13 years old)

We do not knowingly collect personal data from children who do not meet the applicable minimum age. If we become aware that such data has been collected, we will take steps to delete it.

  1. Changes to This Privacy Policy

Our website may use cookies and similar technologies to ensure the site functions correctly, remember your preferences, and understand aggregate site usage (for example, through website analytics tools).

You can control or disable cookies through your browser settings. Disabling cookies may affect certain website features.

  1. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in:

  • legal requirements

  • technology

  • data processing practices

  • service functionality


If material changes occur, users will be notified through the Service or by email where appropriate.

The latest version will always be available within the Service or on our website.

  1. Contact

For questions about this Privacy Policy or our data protection practices:

privacy@vyohealth.com