Palmos Labs
About usPatientsWork with usContact

Privacy Policy

Effective Date: May 20, 2026 · Last Updated: August 10, 2026

Palmos Labs ("Palmos Labs," "we," "us," or "our") respects your privacy and is committed to protecting the personal and health information you entrust to us. This Privacy Policy explains what information we collect, how we use and share it, the safeguards we apply, and the rights and choices available to you when you use our application, website, and related services (collectively, the "Services").

US-Only Operations. Palmos Labs offers the Services only to individuals located in the United States. The Services are not directed to, and are not intended for use by, individuals outside the United States. By using the Services, you represent that you are a U.S. resident.

Palmos Labs maintains a Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), third-party attestation and operates its production systems in HIPAA-compliant environments hosted by trusted third-party vendors. We treat your data — including health and biometric sensor data from supported wearable devices — with the safeguards required by HIPAA and applicable U.S. federal and state privacy laws.

Please read this Policy carefully. By creating an account or using the Services, you acknowledge that you have read and understood this Policy. Collection and use of certain categories of information, including wearable device data and electronic medical records, are additionally governed by separate consents and authorizations, which you must complete before that data is collected, used, or shared.

1. Scope of This Policy

This Policy applies to information collected through:

  • Our mobile and web applications;
  • Our website and any pages linking to this Policy;
  • Paired wearable devices supported by the Services; and
  • Communications with Palmos Labs (email, support tickets, in-app messaging).

This Policy does not apply to third-party websites, applications, or services that we do not own or control, including the device platforms operated by third parties. Your use of those services is governed by their own privacy policies.

2. Our Status Under HIPAA

Palmos Labs has obtained a HIPAA attestation and, where we receive, create, maintain, or transmit Protected Health Information ("PHI") on behalf of a Covered Entity, acts as a Business Associate as defined in 45 C.F.R. § 160.103. Where required by HIPAA, we have executed Business Associate Agreements ("BAAs") with our third-party infrastructure and analytics providers covering the storage and processing of PHI.

When you provide health-related information directly to Palmos Labs outside of a Covered Entity relationship, we voluntarily extend HIPAA-aligned safeguards to that information. We also comply with the Federal Trade Commission’s Health Breach Notification Rule (16 C.F.R. Part 318) where it applies to identifiable health information that is not otherwise covered by HIPAA.

3. Information We Collect

3.1 Personally Identifiable Information (PII)

When you register for and use the Services, we collect the following PII directly from you:

  • Full legal name;
  • Mailing address;
  • Email address;
  • Date of birth (used to verify age eligibility and to support clinically relevant interpretation of health metrics);
  • Account credentials, including username and password; and
  • Health care provider(s).

3.2 Health and Biometric Sensor Data

When you pair a supported wearable device and provide your opt-in consent through our in-app Health Data Consent Screen, we receive biometric and physiological data from that device, which may include, but is not limited to:

  • Heart rate, resting heart rate, and heart rate variability (HRV);
  • Blood oxygen saturation (SpO₂);
  • Skin temperature;
  • Step counts, activity intensity, calories, and workout sessions;
  • Stress and recovery metrics derived by the device;
  • Geolocation data; and
  • Device-reported timestamps and contextual metadata associated with the above readings.

Where the Services integrate with a healthcare provider and you have signed the Patient Directive and Authorization for Disclosure of Health Information, we may also receive electronic medical records ("EMR/EHR data"), including, but not limited to, diagnoses, medications, lab results, and clinical notes relevant to the Services.

Sensitive Personal Information. We treat health information, biometric data, and precise geolocation as "sensitive personal information" under applicable U.S. state privacy laws and limit our use and disclosure of that information accordingly.

3.3 Automatically Collected Information

When you use the Services, we automatically collect limited technical information, including:

  • Device identifiers, model, and operating system;
  • IP address, approximate location derived from IP, and time zone;
  • Application usage data (screens viewed, features used, session duration, crash logs).

3.4 Information from Third Parties

We receive information from the wearable platforms you authorize and, where applicable, from healthcare providers or health information exchanges that you have authorized to share data with us.

4. How We Collect Information

  • Directly from you through account registration, in-app forms, surveys, and support requests;
  • Automatically through your interaction with the Services and from your paired wearable device; and
  • From third parties you have authorized to share data with us.

5. Consent and Authorization

We use separate, purpose-specific consents and authorizations for the categories of data described in this Policy. Each is presented at the appropriate point in the user experience, must be affirmatively accepted or signed, and may be independently revoked. Each document is incorporated into this Policy by reference and controls in the event of any conflict regarding the data it covers.

  • In-App Health Data Consent Screen — your opt-in consent, presented at the time that your first device is paired, for the collection of wearable device data described in Section 3.2.
  • In-App Sharing Consent Screen — your separate opt-in consent, presented when you choose to share your health information with a healthcare provider, authorizing the outbound disclosure of identified categories of data to a specific provider, as described in Section 7.3.
  • Patient Directive and Authorization for Disclosure of Health Information — your signed authorization, under 45 C.F.R. § 164.524 and the 21st Century Cures Act, directing your healthcare provider to disclose your medical records to Palmos Labs.
  • Patient Authorization for Use and Disclosure of Health Information for Research and Product Development — your signed authorization, under 45 C.F.R. § 164.508, permitting Palmos Labs to use identifiable health information for internal research and internal product development.

State consumer health data laws. Some U.S. states regulate the collection, use, and sharing of consumer health data, including wearable biometric measurements. Where these laws apply to the data we collect — including the Washington My Health My Data Act ("MHMDA") — we obtain the additional consent and, where required, the separate written authorization that the law requires before collecting, sharing, or selling such data. We maintain written retention and destruction schedules for the data covered by those laws. We do not sell identifiable consumer health data. We may use and share de-identified data as described in Section 7.6.

You may withdraw consent at any time as described in Section 10. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing, operating, and maintaining the Services, including pairing your wearable devices and displaying your health and activity data;
  • Generating personalized insights, trends, and recommendations based on your biometric and PII data;
  • Verifying your identity and managing your account;
  • Communicating with you about your account, service updates, security notices, and support requests;
  • Improving the Services through aggregated and de-identified analytics;
  • Detecting, investigating, and preventing fraudulent, unauthorized, or illegal activity, and protecting the rights, property, and safety of Palmos Labs, our users, and others;
  • Complying with legal obligations, including those imposed by HIPAA, the FTC Health Breach Notification Rule, and applicable U.S. state privacy laws; and
  • Conducting internal research and product development. We use identifiable health or biometric data for research and product development only with your separate, specific authorization. We may also use and share de-identified and aggregated data as described in Section 7.6.

We do not use your information for automated decisions that produce legal or similarly significant effects on you without your knowledge.

7. How We Share Your Information

We do not sell your identifiable personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We disclose your information only in the limited circumstances described below. We may use and share de-identified and aggregated data as described in Section 7.6.

7.1 Service Providers and Sub-processors

We engage trusted third-party vendors to provide services such as cloud infrastructure and storage, data analytics, communications, identity management, customer support, and monitoring. These vendors only process information on our behalf under written contracts that restrict their use of the information to the services they provide to us. Where required by HIPAA, we have executed Business Associate Agreements with vendors that may access or process PHI.

7.2 Wearable Device Platforms

To deliver the Services, we exchange data with third-party APIs as authorized by you when you connect your devices through our In-App Health Data Consent Screen. The flow and scope of that exchange are described at the point of consent.

7.3 Healthcare Providers and Covered Entities

Where the Services are provided in connection with a healthcare provider or other Covered Entity, we may disclose your health information to that provider only after you have separately authorized that outbound sharing through the In-App Sharing Consent Screen, which identifies the recipient provider, the categories of data shared, and the purpose of the disclosure. Any such disclosure is also subject to the applicable Business Associate Agreement between Palmos Labs and the provider. You can review or revoke your sharing consent at any time in the app.

7.4 Legal and Regulatory Disclosures

We may disclose information when we believe in good faith that disclosure is required to comply with applicable law, valid legal process, or a lawful request from a public authority, or to enforce our agreements, protect rights and safety, or respond to a security incident.

7.5 Business Transfers

If Palmos Labs is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, information may be transferred as part of that transaction, subject to the protections in this Policy and applicable law. We will notify you of any such change and any resulting changes to this Policy.

7.6 Aggregated or De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you. De-identification is performed in accordance with HIPAA standards under 45 C.F.R. § 164.514.

8. Data Storage, Security, and Infrastructure

Palmos Labs maintains an information security program designed to align with HIPAA Security Rule requirements and industry best practices. All data is stored and processed within the United States. Key safeguards include:

  • HIPAA attestation covering the company’s administrative, physical, and technical safeguards;
  • Signed BAAs with our third-party infrastructure providers where required by HIPAA, before any PHI is processed in those environments;
  • Encryption in transit using TLS 1.2 or higher for all network communications;
  • Encryption at rest using AES-256 or equivalent for all stored PII, PHI, and biometric data;
  • Access controls, including role-based access, least-privilege provisioning, and mandatory multi-factor authentication for all workforce access to production systems;
  • Network isolation via segmented Virtual Private Clouds, private subnets, and security groups limiting traffic to required services;
  • Key management through AWS Key Management Service ("KMS") with documented key rotation;
  • Audit logging of access to PHI and administrative actions, retained per HIPAA requirements;
  • Vulnerability management, penetration testing, and continuous monitoring of the production environment; and
  • Workforce training on HIPAA privacy and security and on Palmos Labs’ incident response procedures.

Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will notify affected individuals and applicable authorities of any breach of unsecured PHI or personal data within the time frames required by HIPAA, the FTC Health Breach Notification Rule, and applicable state breach notification laws.

9. Data Retention and Deletion

We retain information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specific retention periods are documented in our internal Data Retention Schedule and summarized below:

Data CategoryDefault RetentionTrigger for Deletion
Account PII (name, address, email, DOB)Duration of account + 7 yearsAccount deletion or verified user request
Wearable biometric sensor dataDuration of account + 7 years (or earlier per BIPA / CUBI requirements)Revocation of In-App Health Data Consent or verified deletion request
Electronic medical recordsPer applicable provider agreement and state medical recordkeeping law (typically 6–10 years)Revocation of the Patient Directive and Authorization for Disclosure of Health Information, subject to legal hold
Application logs and security telemetryUp to 24 monthsRolling expiration
Encrypted backupsUp to 90 days after primary deletionBackup rotation cycle

When data is no longer required, we either securely delete it or de-identify it in accordance with HIPAA standards so that it can no longer be linked back to you. De-identified data may be retained indefinitely for analytics and product improvement.

10. Your Rights and Choices

Depending on the U.S. state in which you reside, you may have some or all of the following rights regarding your personal information:

  • Access / Know — request a copy of, or information about, the personal information we hold about you;
  • Correction — request that we correct inaccurate or incomplete information;
  • Deletion — request that we delete your personal information, subject to legal retention obligations;
  • Portability — request a copy of certain information in a structured, machine-readable format;
  • Opt out of sale, sharing, or targeted advertising — we do not engage in these activities, but you retain the right to direct us not to;
  • Limit use of sensitive personal information — direct us to use sensitive personal information only for purposes permitted by law;
  • Withdrawal of consent — revoke any of your consents or authorizations at any time, which will stop further use or disclosure of your data for the purpose covered by that document, subject to legal retention obligations;
  • Non-discrimination — we will not discriminate against you for exercising your rights; and
  • Appeal — if we decline a request, you may appeal in writing as described in our response.

These rights are provided under state laws including the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, the Washington My Health My Data Act, and similar laws in other states as they take effect.

To exercise these rights, contact us at privacy@palmoslabs.com. We will verify your identity before fulfilling a request and will respond within the time frames required by applicable law (generally 45 days, with one extension permitted where allowed). You may also disconnect a paired wearable device at any time through the in-app settings, which will stop further data collection from that device.

Authorized agents. California and certain other state residents may designate an authorized agent to submit a request on their behalf. We will require proof of the agent’s authorization and may also require you to verify your identity directly.

HIPAA-specific rights. If we hold PHI about you, you also have the rights set forth in 45 C.F.R. § 164.524 et seq., including the right to inspect and copy PHI, request amendments, and receive an accounting of certain disclosures. Where Palmos Labs acts as a Business Associate, requests should generally be directed to the Covered Entity, and we will support that entity in responding.

11. Children’s Privacy

The Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act ("COPPA"). We use your date of birth to enforce this age requirement. If we learn that we have collected information from a child under 13 without verifiable parental consent, we will delete that information promptly. Several states (including California, Connecticut, and Colorado) provide additional protections for minors under 16; we honor those protections where applicable. If you believe a child has provided information to us, please contact us at privacy@palmoslabs.com.

12. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will revise the "Last Updated" date above and provide additional notice — for example, by email or in-app notification — at least 30 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

13. Contact Us and Complaints

If you have questions, concerns, or complaints about this Policy or our privacy practices, please contact our Privacy Officers:

Palmos Labs — Privacy Officers (Chief Information Security Officer and Head of Operations)

Email: privacy@palmoslabs.com

Mail: Palmos Labs, Attn: Privacy, 19 Cumberland Street #3, San Francisco, CA 94110

You also have the right to lodge a complaint with a regulatory authority. Complaints regarding HIPAA may be filed with the U.S. Department of Health and Human Services, Office for Civil Rights. Complaints regarding state privacy law may be directed to the Attorney General of your state of residence (for example, the California Privacy Protection Agency or the California, Colorado, Connecticut, Virginia, Texas, Utah, or Washington Attorney General, as applicable).

© 2026 Palmos Labs, Inc.

Privacy PolicyTerms of Use

All rights reserved.