Privacy Policy
Last updated: August 6, 2026
Mylo, a service of MyloTech, Inc. (“Mylo,” “we,” “us,” or “our”), provides an AI health companion (the “App”) and this website (the “Site”). Your health data is the product we protect, not the product we sell. This policy explains what we collect, where it goes, and the controls you have — for both the Site and the App. It is written to be read. By using the Site, submitting your email, or using the App, you agree to this Policy and our Terms of Service.
The App and beta are currently offered in the United States only. Consumer health data is also covered by our separate Consumer Health Data Privacy Policy, which exists because Washington, Nevada, and Connecticut law require specific disclosures about health data.
Part I — This website & the beta waitlist
1. Information we collect on the Site
Information you give us
- Email address — when you join the beta waitlist, so we can send you an invitation and related beta communications.
- Messages — anything you include if you contact us by email.
Information collected automatically
When you visit the Site, we and our service providers automatically collect technical and usage data using cookies and similar technologies, including the Meta Pixel and analytics tools:
- Device and browser information (browser type, operating system, device type);
- Approximate location derived from your IP address;
- Usage data — pages viewed, links clicked, referring page, and on-site actions such as submitting the signup form;
- Campaign attribution parameters (
utm_*) present in the URL when you arrive; - Identifiers set by cookies and advertising or analytics pixels.
We do not collect health, biometric, or wearable data through this website. Health data lives in the App and is covered in Part II.
2. How we use Site information
- To add you to the beta waitlist and send you an invitation and beta updates;
- To operate, maintain, secure, and improve the Site;
- To measure, analyze, and optimize our marketing and advertising, including ads on Meta platforms;
- To respond to your messages;
- To comply with law and enforce our terms.
3. Advertising, the Meta Pixel, and your choices
The Site uses the Meta Pixel so we can measure ad performance and reach people likely to be interested in Mylo. The Pixel may set cookies and share your Site activity and technical identifiers with Meta, which may act as an independent controller of that information under its own policies.
The Meta Pixel exists on this marketing website only. It is not in the App, and it never receives health data. We do not send health information, wearable data, lab results, or anything you tell the App to any advertising platform, and we do not build advertising audiences from health data.
Your choices:
- Use your browser or device settings to block or delete cookies, or enable a Global Privacy Control signal;
- Adjust your Meta ad preferences in your Facebook or Instagram account settings;
- Use the industry opt-out tools at optout.aboutads.info (DAA) or optout.networkadvertising.org (NAI).
4. Who we share Site information with
We share Site information only with providers who help us run the Site and the waitlist:
| Provider | What they do |
|---|---|
| Supabase | Securely stores beta-waitlist email addresses. |
| Vercel | Website hosting and privacy-friendly analytics. |
| Meta Platforms | Advertising measurement and delivery (Meta Pixel). |
| Apple (TestFlight) | Distribution of the beta app to invited testers. |
We also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition — in which case this Policy continues to govern the transferred information until you are notified of a replacement.
Part II — The Mylo app
5. What the App collects
- Account information — your name, email address, and authentication identifiers, handled by our sign-in provider.
- Health and wellness data you provide — symptoms, measurements, supplements and medications, protocols you are running, how you feel, photos of meals, and anything you type or say to the App.
- Connected device and health-app data — if you connect Apple Health, a wearable, or a continuous glucose monitor, the metrics you authorize (for example sleep, heart rate, heart-rate variability, activity, glucose).
- Lab results — if you upload a panel or order one through the App.
- Usage and diagnostics — event names, feature flags, and crash traces. Never message text, never health values.
Apple Health is read-only. Mylo reads the categories you authorize and never writes back to Apple Health. You can revoke any category at any time in the iOS Health app.
6. How the App uses your data — one purpose
We use your health data for a single purpose: to provide the service you asked for — to organize your health information, track the protocols you are running, and tell you whether they appear to be working. That includes generating your responses, computing your charts and trends, sending reminders you set up, and keeping the App working and secure.
We do not sell your health data. We do not use it for advertising or share it with advertising platforms. We do not use it to train AI models, and our agreements with our AI providers prohibit them from training on it either.
7. Connecting with a clinician (optional)
Some people use Mylo alongside a healthcare practitioner. If — and only if — you affirmatively choose to connect your account to a participating practice:
- That practice can see the health data you have agreed to share with them, so they can follow your progress between visits;
- Your clinician may review and approve changes to the protocol you are running. Mylo does not change your protocol on its own — a licensed clinician has to approve it first, and you see who approved it;
- You can withdraw that sharing at any time in the App. Withdrawing stops future sharing; it does not erase what the practice has already seen or recorded in its own records, which are governed by that practice’s own privacy practices and not by this Policy.
We are not a healthcare provider and we do not practice medicine. Your practitioner is responsible for your care and for their own records. If a practice we work with is a HIPAA covered entity and we handle protected health information on its behalf, we enter into a Business Associate Agreement with that practice before any such information is exchanged.
8. Who we share App data with
We share App data only with the providers that make the product work. Each is bound by contract to use it solely to provide services to us:
| Provider | What they do |
|---|---|
| Convex | Our database and backend. App data lives here, encrypted in transit and at rest. |
| Clerk | Sign-in and account identity. |
| Google (Gemini) and Anthropic (Claude) | The AI models that generate responses. Relevant parts of your data are sent to these APIs to produce your answer, under agreements that prohibit training on your data. |
| Junction (Vital) | Wearable-device connections and lab integrations, only if you connect a device or order a panel. |
| Expo | Push-notification delivery (a device token and the notification content). |
| PostHog | Product analytics — event names and flags only. No message text, no health values. Crash reports contain code stack traces, never your content. |
If we begin offering paid subscriptions, payment is processed by the Apple App Store and by our subscription-management provider. We receive confirmation of your subscription status; we never receive your card number.
General
9. Your controls
- Export — Settings → Export produces a complete bundle of your data in a portable, machine-readable format.
- Delete — you can delete your account from Settings. Deletion is scheduled with a 7-day grace period during which signing back in cancels it; after that it is permanent and cascades to our sign-in and device-integration providers.
- Disconnect — you can disconnect Apple Health, any wearable, or a clinician connection at any time without deleting your account.
- Notifications — controllable in the App and in iOS settings.
10. Retention
We keep your account data while your account is open. When you delete your account we delete your data after the 7-day grace period, except where we must keep something to comply with law, resolve disputes, or enforce our agreements. Waitlist emails are kept until you ask us to remove you or the beta program ends. De-identified and aggregated data that can no longer reasonably identify you may be retained.
11. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a portable copy of your personal information, to opt out of targeted advertising or the sale or sharing of personal information, and to appeal a decision we make about your request. We extend these rights to all our users regardless of state.
Email privacy@mylotech.org to make a request. We respond within 30 days, and will tell you if we need more time. We will not discriminate against you for exercising a privacy right. Health-data-specific rights, including our appeals process, are described in the Consumer Health Data Privacy Policy.
We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under California law. The Meta Pixel described in Section 3 may nonetheless be considered “sharing” under some state laws; you can opt out using the controls in that section or by sending a Global Privacy Control signal, which we honor.
12. Security
Data is encrypted in transit and at rest. Access to production systems is limited to people who need it. Our analytics pipeline is built so that message text and health values cannot enter it, and that constraint is enforced by an automated test that runs on every change. No system is perfectly secure, and we cannot guarantee absolute security.
We are not a HIPAA covered entity and we do not claim to be. As a consumer health app we are subject to the FTC Health Breach Notification Rule. If a breach of your unsecured health data occurs, we will notify you and the FTC as that rule requires.
13. Children
Mylo is for adults 18 and over. We do not knowingly collect information from anyone under 18. If we learn we have, we delete it. If you believe a minor has given us information, email us.
14. International
The Site and App are intended for use in the United States, and data is processed there. We do not currently offer the App in the European Economic Area, the United Kingdom, or Switzerland.
15. Changes to this Policy
We will update this page and change the “last updated” date when this Policy changes. For material changes that affect how we handle your health data, we will give notice in the App or by email before the change takes effect.
16. Contact
MyloTech, Inc. — privacy@mylotech.org