1. OUR PRIVACY POLICY
25th February, 2026
WE DO NOT SELL, TRADE, OR RENT your personal information to anyone, under any circumstances.
We use your information solely to provide and improve our services to you. You may choose to share your personal information with third parties, and you remain the owner of your data and may delete it at any time.
Hora Health is hereinafter referred to as 'Hora Health', 'we', 'us', 'our'. We, at Hora Health, believe that our technology and data offer a unique opportunity to empower people to take control of their hormonal health. Hora Health provides tools to track your hormones, nutrition, exercise, and other lifestyle factors that affect hormonal health.
We aim to bring expert-level Hormonal healthcare to everyone, especially those managing chronic conditions, while providing you with the tools and expertise to manage, optimize, and advocate for your care. We acknowledge the responsibility that comes with managing your personal and health data on Hora Health, and we pledge to always uphold high standards of privacy and security in compliance with EU GDPR, HIPAA, and all other applicable laws.
We will keep your data safe and secure and provide clear, transparent information to ensure you fully understand how we store, process, and manage it, as outlined below.
1.1 Consent
Please read our Privacy Policy carefully to understand how we handle your data before using Hora Health. This Privacy Policy does not cover the practices of companies we don't own or control, or people we don't manage.
In accordance with Article 9(a) of GDPR, the processing of health data to provide our service to you is based on your consent and acceptance of this Privacy Policy on how Hora Health processes the data you choose to share on the platform.
By accepting this privacy policy, you consent to the information outlined here being collected and processed.
You can manage your consent preferences in the app at any time after onboarding to control the collection and processing of non-essential data for delivering and improving our Services to you.
If you have any questions or concerns, you may contact us by email at hello@hora.health
Please note that when you communicate with us, you explicitly consent to the processing of your personal data to address your request.
1.2 Our Recommendations for Protecting Your Data
The biggest threat to the security and privacy of your data is someone gaining access to any of the device(s) in which you avail of our Services, without your consent. The personal and health data you enter into the Hora Health is private, and we will make sure it stays that way.
Here are some recommendations on how to protect your data:
Protect your Hora Health account: Make sure you create a unique password for your Hora Health Account. We have made sure your password must have eight (8) characters with at least one(1) letter and one(1) number.
Protect your Device: Activate passcode, or passkey sign-in on your device(s). This is the first line of defence that automatically secures your data on Hora Health and prevents anyone else from accessing your app without your permission. Set up a feature that lets you erase all data on your device if it's lost or stolen. For iOS, 'Find my IPhone' should be activated, then 'Erase your device' should be enabled. For Android, 'Find my Device' must be set up, and if needed, the connected web interface can be used to lock or wipe your phone remotely.
1.3. Change(s) to our Privacy Policy
We may make change(s) to this Privacy Policy from time to time to reflect changes in the law, our data collection and data use practices, the features of Hora Health, or advances in our
technology, and services.
It is your responsibility to check the Privacy Policy periodically for changes by referring to the updated date at the top of the page, in order to know if it has been revised since your last visit. You will be notified of any change(s) to this Privacy Policy that we consider to require your consent.
1.4 Primary Language of our Privacy Policy:
Whilst our Services are available in English It may be translated into other language but please note that the English version of this Privacy Policy is the original version. However, we will internally proofread translations of all our communications, including this Privacy Policy, to ensure they are as accurate as possible. The English version of this document prevails over all other versions.
1.5 Definitions
'Anonymous Data' means information that does not relate to an identified or identifiable natural person. Personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.
'Cookies' mean small files of information generated by a web server, and sent to a web browser. Collective term for cookies and similar technology such as pixel tags, web beacons, clear GIFs and lavaScript.
'Health Information' means any personal information relating to your physical or mental health.
'Personal Information' means any information that identifies or relates to you (health information) and also includes information referred to as 'Personally Identifiable Information' or 'Personal Data' under applicable Privacy and/or Data Protection Laws.
"Process' means any operation(s) performed on personal information, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, otherwise make available, align or combine, restrict, erase or destroy.
'Pseudonymised' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific person without the use of additional information.
'Services' means the services which have been made available through the website, and our app, along with any such other related goods, equipment, services and information made available to you from us. 'SSL' means Secure Sockets Layer, which is a protocol that secures link exchanges between servers and browsers.
2. TYPES OF DATA WE COLLECT & PROCESS
2.1 Legal Basis for Processing We will only process your Personal Information if we have a lawful basis under EU GDPR for doing so, such as:
• Consent: Except for the specific situations explained below, we process your Personal Information and Health Information, provided by you, with your consent. You may withdraw your consent at any time, and we will stop processing your Personal Information in this way.
• Contractual Necessity: In order to be able to perform our contract with you in providing our services, we need to collect Personal Information and Health Information we have indicated as required.
• Compliance with a legal obligation:
We will sometimes have to process Personal Information in order to comply with a legal obligation imposed on us. Where those obligations are imposed by Italian law, that law will provide us with a lawful ground for processing.
• Legitimate Interest: We process the following categories of Personal Information when we believe it is in our legitimate interest to do so, and we do not believe that your rights or freedoms
will be unduly interfered with by our processing: In short, Hora Health are allowed to process
all health information you choose to input into the Hora Health App, because you have provided us with consent to do so.
2.2 Personal Information
When you create an account, we require information to manage your account. Such information includes your name and email address. We need this information in order to provide our service to you; therefore, you will not be able to create an account without providing this information. We require your age to comply with applicable laws and standards and to provide our services. This information ensures that we protect the privacy and security of all users, particularly those under the age of sixteen (16) years old. Also, it is essential that we know your age group to provide you with the best possible insight into your hormonal health.
You can provide a different name, such as a nickname and/or a made-up name, which you would like to be known as on Hora Health App. However, your email address shall be used for two-factor authentication to access the Hora Health App, so it must be correct.
When you create an account, we may also use your email address to send you emails for the following purposes:
Providing you with information about our products or services.
Keeping you updated with you about the Hora Health App, its performance as well as new versions and/or similar Apps we may develop.
Inviting you to participate in user feedback sessions to help improve our service.
Our legal basis for the above, is our legitimate interest in improving and promoting our Services. For more information, see the User Research and Mailing Lists sections below. You have the option to amend/update all personal information in the Hora Health App, in 'Profile Settings.
Please note that we do not retain your data in an identifiable format for longer than is required to provide our services.
2.3 Health Information
We require health information to provide the Services to you. Such information includes menstrual cycle data, Labs data, hormone and lifestyle data, medications and symptom logs. We require this data to provide our services, including app functionality, personalised advice, recommendations, and trends, as well as symptom pattern recognition and cycle predictions.
We also ask you to provide further health information in your profile, such as location, height, weight, pre-existing conditions and contraceptive use, to further personalise your profile and experience.
You can amend, delete or add information in the Hora Health App under Profile Settings.
2.4 Usage Information
If you use our Services, including apps and websites, we will also collect information about you. Some of this information is direct (IP address, browser type, smartphone make, and cookie contents) as set out in our Cookie Policy. We also use third-party analytics providers, such as Google Analytics, to collect similar information and provide us with the analysis derived from it.
We process this data in order to:
Locate errors in our systems, and/or problems that our system may be facing with other systems (such as compatibility with a web browser).
Improve the functioning of our Service.
Prevent fraud or other criminal activity. This information is automatically provided to us and due to the nature of both browser and App software, it is inevitable that we process it.
However, there are ways you can prevent us from receiving this information. For example, by changing the information your browser supplies to us or deleting cookie history.
2.5 Payment Information
Payment information is necessary in order for payments to be processed by a third-party payment processor. Such information includes the amount of payment, payment card type, payment card number and your billing address.
When you subscribe to Hora Health Premuim all your payment information is securely processed by the Apple App Store or Google PlayStore. Hora Health does not collect or process your payment information at any time.
2.6 Correspondence Information
Where you directly correspond with us (such as by sending an email to hello@hora.health we will process information about you concerning that communication, including the content of that email and our responses. We are required to keep that information for as long as necessary to deal with that correspondence. For example, if you make a complaint, we shall retain that information for as long as needed to deal with the complaint, and then for a further five (5) years following close-out of the complaint.
3. ANONYMISING PERSONAL & HEALTH INFORMATION
We may create Aggregated, Pseudonymised or Anonymized Data from the Personal and Health
Information we collect, by removing information that makes the data personally identifiable to a particular user.
We use your Health Information to improve our models on how hormones impact health. The models we create have no individual information about you, nor can it be traced to you; they are an aggregation of data from many individuals within the Hora Health community.
We may use Anonymous Data and share it with third parties for our lawful business purposes, including serving users, analysing, building upon, and improving our services, and promoting our business. We retain Anonymous Data indefinitely.
4. HOW & WHY WE PROCESS YOUR DATA
4.1 Providing our Services
Data processing is essential to provide our Services. Whenever you use our services, some personal and health information is collected, stored and analysed using both internal and third
party tools.
We process health information when you track your health data in the app to provide our core service as a hormonal health platform. Device data is processed when you use the Hora Health
App or website, in order to understand how you interact with our services and to technically improve performance.
When you set up your Hora Health account, we process account information to enable login, and to communicate with you on service-related topics. Communications may include
information about your account, essential app updates, or insights and recommendations based on the health information you have provided. These communications shall be via email, or in-
app notifications. By accepting the Privacy Policy, you agree to your personal and health
information being processed so that Hora Health can provide our hormonal health improvement services.
4.2 Essential Third-Party Providers of our Services
In order to provide our Services, we use the following third party services and integrations.
• Open AI: Hora Health uses Open AI to process images, texts and queries you make on the app to provide insights and other in-app services.
• Supabase: Hora Health uses Supabase, a secure web service to analyse and store your data, and send two-factor authentication. We only utilise AWS data centres in the European Union. All data stored on AWS Cloud is pseudonymised.
• Firebase Platform: Hora Health uses services operated by Google Firebase, a company based in the United States, to help us facilitate communication with you via in-app push notifications and emails. Such communication may include information about your account, essential app updates, or insights and recommendations based on the health data you have provided.
When you first create your account, there are several options to sign up. In addition to signing up with your email address, you can also use the services provided by Apple or Google:
• Signing in with Apple: Allows you to create and sign into your Hora Health Account using your Apple credentials, authorising us to collect your email address. If you sign up using Apple, Hora Health will exchange certain information with Apple, such as device data, IP-address, and information you provided to Apple when creating an account with Apple Inc. This may include
a transfer of your Personal Information to Apple servers located outside the European Union. It is your choice if and to what extent you use the "Sign in with Apple" service and what information you provide to Apple. No health data will be exchanged with Apple for the purpose of using the "Sign in with Apple" service.
• Signing in with Google: Allows you to create and sign into your Hora Health Account using your Google credentials, authorising us to collect your email address. If you sign up using Google, Hora Health will exchange with Google the types of data you provided to Google
when creating an account with them (such as name, email address). This may include a transfer of your personal data to Google servers located outside the European Union. It is your choice if and to what extent you use the "Sign in with Google" service and what information you provide to Google. No health data will be exchanged with Google for the purpose of using the 'Sign in with Google' service.
By accepting the Privacy Policy, and creating an account you agree to our use of third-party services outlined above in order to provide our Services, and meet the conditions laid out in our Terms and Conditions, in accordance with EU GDPR Article 6(b):
4.3 Providing Customer Service
When you contact us at hello@hora.health with questions regarding our Services, you authorise Hora Health to access your personal and health Information depending on the nature of your query, in order to adequately answer your query.
By contacting us at our email address with a query, you provide consent for Hora Health to process your personal and health information that may be contained within, to deal with the correspondence, in accordance with EU GDPR Article 6(a).
4.4 To Analyse, Build & Improve our Services
In order to build valuable features in our App, we process health information you have provided, to better understand which features are most useful to you. By doing this, we can better understand how our community uses the app to individualise your experience.
Analysing how the Hora Health Community uses and interacts with the app allows us to understand which features are loved and valued. These insights are hugely important for driving feature development and improvement, ensuring we deliver a service that meets your needs. This could mean improving prediction accuracy, building new algorithms to offer more insights, or creating content based on topics submitted by our community or the food recipes most loved.
By accepting the Privacy Policy, you agree to your information being processed so that Hora Health can analyse performance to improve our Services, in accordance with EU GDPR Article 6(b).
4.5 To Personalise your Experience by Making Recommendations
In order to individualise your experience, we process certain usage data to understand how you interact with the app, including the health information you have provided. Collecting this data allows us to send you recommendations via email and push notifications (if enabled).
We do this with your Pseudonymised Data and aggregate it with similar users' Pseudonymised Data in order to provide information that's more tailored to you. This includes sending you updates on new features, based on what you have logged, or suggesting interesting products/services from partnerships.
By accepting the Privacy Policy, you provide your consent for Hora Health to process your account, usage and health information, so that we can provide personal recommendations for products and services based on the interactions, and information you have provided in the app, in accordance with EU GDPR Article 6(a). You can opt out of receiving recommendations for this purpose by unsubscribing from promotional emails and notifications.
4.6 To Advance Health Research
To help advance Hora Health research, we may share relevant Anonymised and/or Pseudonymised Data with trusted research partners.
The data you choose to provide to Hora Health is incredibly powerful, and, collectively with the entire Hora Health community, it is essential to advancing hormonal health research, especially around understudied and underrepresented women’s health field. With your help, we aim to close the gender research gaps, and to do so, we may need support from trusted partners to accelerate research.
Where we share this Anonymous Data, it must be directly relevant to the research question, and follow strict protocols to ensure your data remains fully anonymous to the researchers.
By accepting the Privacy Policy, you explicitly provide your consent for Hora Health to use your health information, being Anonymised/Pseudononymised, processed and shared with trusted partners to advance Hora Health Research, in accordance with EU GDPR Article 6(a). You can opt out of the use of your data for this purpose at any time in 'Profile > Terms & Conditions> Privacy Preferences > Withdraw Consent'.
4.7 User Research
As a member of the Hora Health Community, users may be invited via email to share feedback by completing surveys, participating in interviews, or contributing to focus groups. Interaction and feedback from the Hora Health Community are key to us developing Services/Products you love. We may use surveys and run interviews to gain insights on certain health topics, the performance of our Services, or the value of features. Any information provided by you in a survey and/or interview is processed to provide and improve our services.
Hora Health uses 'Google Forms', a survey tool provider offered by Google. By completing the survey and returning to us, and/or agreeing and attending an interview, you provide your consent for Hora Health to collect and process any personal and health information contained within, in accordance with EU GDPR Article 6(a). We do not retain your personal data in an identifiable format for longer than is required for the purpose it was collected.
5. TRACKING, ADVERTISING & NOTIFYING
5.1 General Tracking
Our Services use Cookies to enable our servers to recognise your web browser, tell us how and when you visit our website, analyse trends, and learn about our user base to operate and improve our Services. Cookies are small pieces of data, usually text files, placed on your computer, tablet, phone or similar device when you use the device to access our
Services. This helps us identify whether you've already downloaded Hora Health and subscribed to Hora Health Premium, and to find out which advertisements you have interacted with (if any). We collect information from you, including that received from third parties, including third parties that have placed their own Cookies on your device(s).
5.2 Third Party App Integrations
In order to track customer interaction with our Services, we utilise the following third-party services and integrations.
• RevenueCat: Hora Health uses services operated by RevenueCat, an open source to allow our users to opt-in to subscriptions on iOS and Android within the app.
5.3 Google Analytics
Our website uses Google Analytics, a web analysis service operated by Google. Google Analytics uses Cookies stored on your computer to allow for analysis of your visits to websites and interactions with them in order to personalise your experience and improve our services.
Google analyses this information to offer reports to Hora Health on website usage and online usage of associated services. Under the terms of Google's analytics service, Google may also transfer this information to third parties, either when this is required by law or when third parties are contracted by Google to process this data. Google must not allow your IP address to be linked to any other personal data.
By opting in via the cookie banner, you consent to data being used and processed by Google as described above. You can withdraw consent for this use of your data in this way at any time in your browser settings. Please note that this withdrawal only applies to future activities.
5.4 AppsFlyer
We have instructed AppsFlyer to aggregate the anonymised information we provide it with, in order to group our users and provide us with reports and insights to optimise promotional campaigns and target audiences for advertising. Appsflyer obtains the anonymised data from Hora Health, and analyses it to aggregate data into profiles and groups. Appsflyer passes on this analysis to third-party integrations, such as Meta and Google to find people similar on social media and browsing platforms. Tracking in this way can be managed within settings on your device and is not controlled by our App.
5.5 Notifications
By enabling notifications, you provide consent for us to provide Firebase with your unique Hora Health ID and email address, and pseudonymised Health Information, including the current cycle phase you are in, and tracking activities, in order to do so.
In-app notifications can be enabled/disabled in your devices settings under
'Notifications'. By accepting the Privacy Policy, you provide your consent for Hora Health to process your email address and health information, to allow Firebase to provide personalised notifications in accordance with EU GDPR Article 6(a). You can opt out of receiving recommendations for this purpose at any time in 'Menu > Terms & Conditions> Privacy Preferences > Withdraw Consent.
5.6 Mailing Lists
You can subscribe to our mailing lists to get the latest updates on Hora Health and/or our Services without creating a Hora Health account, via our website. We will use the Personal Information you provide, such as your email address, to do so. By signing up to mailing lists and entering your details, you consent to us processing your Personal Information for that purpose. If you do not wish to receive these emails from us, you can opt out anytime by clicking 'unsubscribe' at the bottom of our email, and/or by requesting to unsubscribe by emailing hello@hora.health. If you unsubscribe, we are required to retain some information to ensure we respect your preferences in the future.
6. STORING INFORMATION WE COLLECT
All information we collect in the Hora Health App is stored securely in the backend of
our App in our internal Hora Health Database in the European Union. All access information is encrypted and stored on your phone's secure storage (If you use an iPhone, this is called Keychain; if you use an Android, this is called Keystore), to ensure that they are accessible only by you. When you select to register for an account using Google or Apple, the password is not shared with us. However, when you manually register your email and create a password, all information is transmitted to us over SSL and stored in our encrypted database.
Internally, the entire Hora Health team uses a secure password-sharing system to maintain the security of our systems, including our databases. Only very limited, trusted team members have access to the pseudonymised database. All information in our database is identified by your unique Hora Health User ID. This ID is a meaningless sequence of numbers to anyone else but us. We do not process any identifiable information from our database, we clone our database and only process Pseudonymised Information. We use two-factor authentication to access all third-party providers and integrations to ensure that even your Pseudonymised Information remains secure. We also ensure that all third-party services and integrations we use are in compliance with EU GDPR and that Pseudonymised Information is stored in databases located in the European Union.
7. SHARING YOUR PERSONAL DATA
We do not share Personal Data with anyone else other than:
• Contractors providing services we use for processing Personal Data under a professional duty of confidence, including:
• Others who carry out research into health, including academic research organisations (Universities), and commercial organisations (Pharmaceutical and LifeScience companies) for product development. When we collaborate with others in this way, we will always provide anonymous data in place of your personal details.
All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.
8. HORA HEALTH USERS UNDER THE AGE OF 16
When creating your Hora Health account, you are required to provide your date of birth. Where a date of birth is entered that is below the age of sixteen (16) years old, we ask for confirmation that your parent/legal guardian has provided their consent that you can use our Services. If you are a parent/legal guardian who has learnt that your child/ a child you are responsible for, is using the Hora Health App without your permission, or you have a query about data privacy at Hora Health, a query about data privacy at Hora Health, please get in contact with us via email at hello@hora.health
We do not knowingly collect personal information from children under the age of thirteen (13) years old. Where we discover a user that is below that age, Hora Health reserves the right to delete the account and wipe all relevant information about the account and user from our Servers.
9. YOUR DATA PROTECTION RIGHTS
Your privacy, and most importantly privacy of your data, is a basic human right, a right we at Hora Health truly respect. Our Services are designed to collect only the information necessary to provide our Services. We only collect and process your data for the purposes outlined in the policy. Internally, the entire Hora Health team uses a secure password-sharing system to protect our databases. Only a very limited, highly trusted team of members has access to your Personal Information. We do not retain your personal information in an identifiable format for longer than is necessary. We do not process any identifiable information from our database; we clone our database and process Pseudonymised Information there. We use two-factor authentication to access all third-party providers and integrations to ensure that even your Pseudonymised Information remains secure.
As a user of our Services, you may exercise your rights under EU GDPR to:
• Manage and/or correct your Personal Information and Health Information in the app settings.
• Request your Personal Information processed by Hora Health. Upon your request, such information will be provided to you electronically. Please request at hello@hora.health to be provided with your data within ten (10) working days.
• Gain access to your information by requesting a copy of your data in a format that is readable by other companies or organisations.
• Withdraw your consent from ongoing processing at any time by deleting your account, changing your privacy preferences, disabling notifications, and/ or unsubscribing to mailing lists.
• Request complete deletion of your data, including past data obtained, and sent to third-party providers and integrations by reaching out to hello@hora.health. Your data will be deleted within one (1) month of the request being received.
• Lodge a complaint with the relevant format that is readable by other companies or organisations.
• Withdraw your consent from ongoing processing at any time by deleting your account, changing your privacy preferences, disabling notifications, and/or unsubscribing to mailing lists.
• Request complete deletion of your data, including past data obtained, and sent to third-party providers and integrations by reaching out to hello@hora.health. Your data will be deleted within one (1) month of the request being received.
• Lodge a complaint with the relevant supervising authority where you believe Hora Health is processing your Personal Information in violation of applicable data protection regulations.
If you have any questions or if something in this privacy policy isn't clear, please feel free to reach out to us at hello@hora.health.
1. OUR PRIVACY POLICY
25th February, 2026
WE DO NOT SELL, TRADE, OR RENT your personal information to anyone, under any circumstances.
We use your information solely to provide and improve our services to you. You may choose to share your personal information with third parties, and you remain the owner of your data and may delete it at any time.
Hora Health is hereinafter referred to as 'Hora Health', 'we', 'us', 'our'. We, at Hora Health, believe that our technology and data offer a unique opportunity to empower people to take control of their hormonal health. Hora Health provides tools to track your hormones, nutrition, exercise, and other lifestyle factors that affect hormonal health.
We aim to bring expert-level Hormonal healthcare to everyone, especially those managing chronic conditions, while providing you with the tools and expertise to manage, optimize, and advocate for your care. We acknowledge the responsibility that comes with managing your personal and health data on Hora Health, and we pledge to always uphold high standards of privacy and security in compliance with EU GDPR, HIPAA, and all other applicable laws.
We will keep your data safe and secure and provide clear, transparent information to ensure you fully understand how we store, process, and manage it, as outlined below.
1.1 Consent
Please read our Privacy Policy carefully to understand how we handle your data before using Hora Health. This Privacy Policy does not cover the practices of companies we don't own or control, or people we don't manage.
In accordance with Article 9(a) of GDPR, the processing of health data to provide our service to you is based on your consent and acceptance of this Privacy Policy on how Hora Health processes the data you choose to share on the platform.
By accepting this privacy policy, you consent to the information outlined here being collected and processed.
You can manage your consent preferences in the app at any time after onboarding to control the collection and processing of non-essential data for delivering and improving our Services to you.
If you have any questions or concerns, you may contact us by email at hello@hora.health
Please note that when you communicate with us, you explicitly consent to the processing of your personal data to address your request.
1.2 Our Recommendations for Protecting Your Data
The biggest threat to the security and privacy of your data is someone gaining access to any of the device(s) in which you avail of our Services, without your consent. The personal and health data you enter into the Hora Health is private, and we will make sure it stays that way.
Here are some recommendations on how to protect your data:
Protect your Hora Health account: Make sure you create a unique password for your Hora Health Account. We have made sure your password must have eight (8) characters with at least one(1) letter and one(1) number.
Protect your Device: Activate passcode, or passkey sign-in on your device(s). This is the first line of defence that automatically secures your data on Hora Health and prevents anyone else from accessing your app without your permission. Set up a feature that lets you erase all data on your device if it's lost or stolen. For iOS, 'Find my IPhone' should be activated, then 'Erase your device' should be enabled. For Android, 'Find my Device' must be set up, and if needed, the connected web interface can be used to lock or wipe your phone remotely.
1.3. Change(s) to our Privacy Policy
We may make change(s) to this Privacy Policy from time to time to reflect changes in the law, our data collection and data use practices, the features of Hora Health, or advances in our
technology, and services.
It is your responsibility to check the Privacy Policy periodically for changes by referring to the updated date at the top of the page, in order to know if it has been revised since your last visit. You will be notified of any change(s) to this Privacy Policy that we consider to require your consent.
1.4 Primary Language of our Privacy Policy:
Whilst our Services are available in English It may be translated into other language but please note that the English version of this Privacy Policy is the original version. However, we will internally proofread translations of all our communications, including this Privacy Policy, to ensure they are as accurate as possible. The English version of this document prevails over all other versions.
1.5 Definitions
'Anonymous Data' means information that does not relate to an identified or identifiable natural person. Personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.
'Cookies' mean small files of information generated by a web server, and sent to a web browser. Collective term for cookies and similar technology such as pixel tags, web beacons, clear GIFs and lavaScript.
'Health Information' means any personal information relating to your physical or mental health.
'Personal Information' means any information that identifies or relates to you (health information) and also includes information referred to as 'Personally Identifiable Information' or 'Personal Data' under applicable Privacy and/or Data Protection Laws.
"Process' means any operation(s) performed on personal information, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, otherwise make available, align or combine, restrict, erase or destroy.
'Pseudonymised' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific person without the use of additional information.
'Services' means the services which have been made available through the website, and our app, along with any such other related goods, equipment, services and information made available to you from us. 'SSL' means Secure Sockets Layer, which is a protocol that secures link exchanges between servers and browsers.
2. TYPES OF DATA WE COLLECT & PROCESS
2.1 Legal Basis for Processing We will only process your Personal Information if we have a lawful basis under EU GDPR for doing so, such as:
• Consent: Except for the specific situations explained below, we process your Personal Information and Health Information, provided by you, with your consent. You may withdraw your consent at any time, and we will stop processing your Personal Information in this way.
• Contractual Necessity: In order to be able to perform our contract with you in providing our services, we need to collect Personal Information and Health Information we have indicated as required.
• Compliance with a legal obligation:
We will sometimes have to process Personal Information in order to comply with a legal obligation imposed on us. Where those obligations are imposed by Italian law, that law will provide us with a lawful ground for processing.
• Legitimate Interest: We process the following categories of Personal Information when we believe it is in our legitimate interest to do so, and we do not believe that your rights or freedoms
will be unduly interfered with by our processing: In short, Hora Health are allowed to process
all health information you choose to input into the Hora Health App, because you have provided us with consent to do so.
2.2 Personal Information
When you create an account, we require information to manage your account. Such information includes your name and email address. We need this information in order to provide our service to you; therefore, you will not be able to create an account without providing this information. We require your age to comply with applicable laws and standards and to provide our services. This information ensures that we protect the privacy and security of all users, particularly those under the age of sixteen (16) years old. Also, it is essential that we know your age group to provide you with the best possible insight into your hormonal health.
You can provide a different name, such as a nickname and/or a made-up name, which you would like to be known as on Hora Health App. However, your email address shall be used for two-factor authentication to access the Hora Health App, so it must be correct.
When you create an account, we may also use your email address to send you emails for the following purposes:
Providing you with information about our products or services.
Keeping you updated with you about the Hora Health App, its performance as well as new versions and/or similar Apps we may develop.
Inviting you to participate in user feedback sessions to help improve our service.
Our legal basis for the above, is our legitimate interest in improving and promoting our Services. For more information, see the User Research and Mailing Lists sections below. You have the option to amend/update all personal information in the Hora Health App, in 'Profile Settings.
Please note that we do not retain your data in an identifiable format for longer than is required to provide our services.
2.3 Health Information
We require health information to provide the Services to you. Such information includes menstrual cycle data, Labs data, hormone and lifestyle data, medications and symptom logs. We require this data to provide our services, including app functionality, personalised advice, recommendations, and trends, as well as symptom pattern recognition and cycle predictions.
We also ask you to provide further health information in your profile, such as location, height, weight, pre-existing conditions and contraceptive use, to further personalise your profile and experience.
You can amend, delete or add information in the Hora Health App under Profile Settings.
2.4 Usage Information
If you use our Services, including apps and websites, we will also collect information about you. Some of this information is direct (IP address, browser type, smartphone make, and cookie contents) as set out in our Cookie Policy. We also use third-party analytics providers, such as Google Analytics, to collect similar information and provide us with the analysis derived from it.
We process this data in order to:
Locate errors in our systems, and/or problems that our system may be facing with other systems (such as compatibility with a web browser).
Improve the functioning of our Service.
Prevent fraud or other criminal activity. This information is automatically provided to us and due to the nature of both browser and App software, it is inevitable that we process it.
However, there are ways you can prevent us from receiving this information. For example, by changing the information your browser supplies to us or deleting cookie history.
2.5 Payment Information
Payment information is necessary in order for payments to be processed by a third-party payment processor. Such information includes the amount of payment, payment card type, payment card number and your billing address.
When you subscribe to Hora Health Premuim all your payment information is securely processed by the Apple App Store or Google PlayStore. Hora Health does not collect or process your payment information at any time.
2.6 Correspondence Information
Where you directly correspond with us (such as by sending an email to hello@hora.health we will process information about you concerning that communication, including the content of that email and our responses. We are required to keep that information for as long as necessary to deal with that correspondence. For example, if you make a complaint, we shall retain that information for as long as needed to deal with the complaint, and then for a further five (5) years following close-out of the complaint.
3. ANONYMISING PERSONAL & HEALTH INFORMATION
We may create Aggregated, Pseudonymised or Anonymized Data from the Personal and Health
Information we collect, by removing information that makes the data personally identifiable to a particular user.
We use your Health Information to improve our models on how hormones impact health. The models we create have no individual information about you, nor can it be traced to you; they are an aggregation of data from many individuals within the Hora Health community.
We may use Anonymous Data and share it with third parties for our lawful business purposes, including serving users, analysing, building upon, and improving our services, and promoting our business. We retain Anonymous Data indefinitely.
4. HOW & WHY WE PROCESS YOUR DATA
4.1 Providing our Services
Data processing is essential to provide our Services. Whenever you use our services, some personal and health information is collected, stored and analysed using both internal and third
party tools.
We process health information when you track your health data in the app to provide our core service as a hormonal health platform. Device data is processed when you use the Hora Health
App or website, in order to understand how you interact with our services and to technically improve performance.
When you set up your Hora Health account, we process account information to enable login, and to communicate with you on service-related topics. Communications may include
information about your account, essential app updates, or insights and recommendations based on the health information you have provided. These communications shall be via email, or in-
app notifications. By accepting the Privacy Policy, you agree to your personal and health
information being processed so that Hora Health can provide our hormonal health improvement services.
4.2 Essential Third-Party Providers of our Services
In order to provide our Services, we use the following third party services and integrations.
• Open AI: Hora Health uses Open AI to process images, texts and queries you make on the app to provide insights and other in-app services.
• Supabase: Hora Health uses Supabase, a secure web service to analyse and store your data, and send two-factor authentication. We only utilise AWS data centres in the European Union. All data stored on AWS Cloud is pseudonymised.
• Firebase Platform: Hora Health uses services operated by Google Firebase, a company based in the United States, to help us facilitate communication with you via in-app push notifications and emails. Such communication may include information about your account, essential app updates, or insights and recommendations based on the health data you have provided.
When you first create your account, there are several options to sign up. In addition to signing up with your email address, you can also use the services provided by Apple or Google:
• Signing in with Apple: Allows you to create and sign into your Hora Health Account using your Apple credentials, authorising us to collect your email address. If you sign up using Apple, Hora Health will exchange certain information with Apple, such as device data, IP-address, and information you provided to Apple when creating an account with Apple Inc. This may include
a transfer of your Personal Information to Apple servers located outside the European Union. It is your choice if and to what extent you use the "Sign in with Apple" service and what information you provide to Apple. No health data will be exchanged with Apple for the purpose of using the "Sign in with Apple" service.
• Signing in with Google: Allows you to create and sign into your Hora Health Account using your Google credentials, authorising us to collect your email address. If you sign up using Google, Hora Health will exchange with Google the types of data you provided to Google
when creating an account with them (such as name, email address). This may include a transfer of your personal data to Google servers located outside the European Union. It is your choice if and to what extent you use the "Sign in with Google" service and what information you provide to Google. No health data will be exchanged with Google for the purpose of using the 'Sign in with Google' service.
By accepting the Privacy Policy, and creating an account you agree to our use of third-party services outlined above in order to provide our Services, and meet the conditions laid out in our Terms and Conditions, in accordance with EU GDPR Article 6(b):
4.3 Providing Customer Service
When you contact us at hello@hora.health with questions regarding our Services, you authorise Hora Health to access your personal and health Information depending on the nature of your query, in order to adequately answer your query.
By contacting us at our email address with a query, you provide consent for Hora Health to process your personal and health information that may be contained within, to deal with the correspondence, in accordance with EU GDPR Article 6(a).
4.4 To Analyse, Build & Improve our Services
In order to build valuable features in our App, we process health information you have provided, to better understand which features are most useful to you. By doing this, we can better understand how our community uses the app to individualise your experience.
Analysing how the Hora Health Community uses and interacts with the app allows us to understand which features are loved and valued. These insights are hugely important for driving feature development and improvement, ensuring we deliver a service that meets your needs. This could mean improving prediction accuracy, building new algorithms to offer more insights, or creating content based on topics submitted by our community or the food recipes most loved.
By accepting the Privacy Policy, you agree to your information being processed so that Hora Health can analyse performance to improve our Services, in accordance with EU GDPR Article 6(b).
4.5 To Personalise your Experience by Making Recommendations
In order to individualise your experience, we process certain usage data to understand how you interact with the app, including the health information you have provided. Collecting this data allows us to send you recommendations via email and push notifications (if enabled).
We do this with your Pseudonymised Data and aggregate it with similar users' Pseudonymised Data in order to provide information that's more tailored to you. This includes sending you updates on new features, based on what you have logged, or suggesting interesting products/services from partnerships.
By accepting the Privacy Policy, you provide your consent for Hora Health to process your account, usage and health information, so that we can provide personal recommendations for products and services based on the interactions, and information you have provided in the app, in accordance with EU GDPR Article 6(a). You can opt out of receiving recommendations for this purpose by unsubscribing from promotional emails and notifications.
4.6 To Advance Health Research
To help advance Hora Health research, we may share relevant Anonymised and/or Pseudonymised Data with trusted research partners.
The data you choose to provide to Hora Health is incredibly powerful, and, collectively with the entire Hora Health community, it is essential to advancing hormonal health research, especially around understudied and underrepresented women’s health field. With your help, we aim to close the gender research gaps, and to do so, we may need support from trusted partners to accelerate research.
Where we share this Anonymous Data, it must be directly relevant to the research question, and follow strict protocols to ensure your data remains fully anonymous to the researchers.
By accepting the Privacy Policy, you explicitly provide your consent for Hora Health to use your health information, being Anonymised/Pseudononymised, processed and shared with trusted partners to advance Hora Health Research, in accordance with EU GDPR Article 6(a). You can opt out of the use of your data for this purpose at any time in 'Profile > Terms & Conditions> Privacy Preferences > Withdraw Consent'.
4.7 User Research
As a member of the Hora Health Community, users may be invited via email to share feedback by completing surveys, participating in interviews, or contributing to focus groups. Interaction and feedback from the Hora Health Community are key to us developing Services/Products you love. We may use surveys and run interviews to gain insights on certain health topics, the performance of our Services, or the value of features. Any information provided by you in a survey and/or interview is processed to provide and improve our services.
Hora Health uses 'Google Forms', a survey tool provider offered by Google. By completing the survey and returning to us, and/or agreeing and attending an interview, you provide your consent for Hora Health to collect and process any personal and health information contained within, in accordance with EU GDPR Article 6(a). We do not retain your personal data in an identifiable format for longer than is required for the purpose it was collected.
5. TRACKING, ADVERTISING & NOTIFYING
5.1 General Tracking
Our Services use Cookies to enable our servers to recognise your web browser, tell us how and when you visit our website, analyse trends, and learn about our user base to operate and improve our Services. Cookies are small pieces of data, usually text files, placed on your computer, tablet, phone or similar device when you use the device to access our
Services. This helps us identify whether you've already downloaded Hora Health and subscribed to Hora Health Premium, and to find out which advertisements you have interacted with (if any). We collect information from you, including that received from third parties, including third parties that have placed their own Cookies on your device(s).
5.2 Third Party App Integrations
In order to track customer interaction with our Services, we utilise the following third-party services and integrations.
• RevenueCat: Hora Health uses services operated by RevenueCat, an open source to allow our users to opt-in to subscriptions on iOS and Android within the app.
5.3 Google Analytics
Our website uses Google Analytics, a web analysis service operated by Google. Google Analytics uses Cookies stored on your computer to allow for analysis of your visits to websites and interactions with them in order to personalise your experience and improve our services.
Google analyses this information to offer reports to Hora Health on website usage and online usage of associated services. Under the terms of Google's analytics service, Google may also transfer this information to third parties, either when this is required by law or when third parties are contracted by Google to process this data. Google must not allow your IP address to be linked to any other personal data.
By opting in via the cookie banner, you consent to data being used and processed by Google as described above. You can withdraw consent for this use of your data in this way at any time in your browser settings. Please note that this withdrawal only applies to future activities.
5.4 AppsFlyer
We have instructed AppsFlyer to aggregate the anonymised information we provide it with, in order to group our users and provide us with reports and insights to optimise promotional campaigns and target audiences for advertising. Appsflyer obtains the anonymised data from Hora Health, and analyses it to aggregate data into profiles and groups. Appsflyer passes on this analysis to third-party integrations, such as Meta and Google to find people similar on social media and browsing platforms. Tracking in this way can be managed within settings on your device and is not controlled by our App.
5.5 Notifications
By enabling notifications, you provide consent for us to provide Firebase with your unique Hora Health ID and email address, and pseudonymised Health Information, including the current cycle phase you are in, and tracking activities, in order to do so.
In-app notifications can be enabled/disabled in your devices settings under
'Notifications'. By accepting the Privacy Policy, you provide your consent for Hora Health to process your email address and health information, to allow Firebase to provide personalised notifications in accordance with EU GDPR Article 6(a). You can opt out of receiving recommendations for this purpose at any time in 'Menu > Terms & Conditions> Privacy Preferences > Withdraw Consent.
5.6 Mailing Lists
You can subscribe to our mailing lists to get the latest updates on Hora Health and/or our Services without creating a Hora Health account, via our website. We will use the Personal Information you provide, such as your email address, to do so. By signing up to mailing lists and entering your details, you consent to us processing your Personal Information for that purpose. If you do not wish to receive these emails from us, you can opt out anytime by clicking 'unsubscribe' at the bottom of our email, and/or by requesting to unsubscribe by emailing hello@hora.health. If you unsubscribe, we are required to retain some information to ensure we respect your preferences in the future.
6. STORING INFORMATION WE COLLECT
All information we collect in the Hora Health App is stored securely in the backend of
our App in our internal Hora Health Database in the European Union. All access information is encrypted and stored on your phone's secure storage (If you use an iPhone, this is called Keychain; if you use an Android, this is called Keystore), to ensure that they are accessible only by you. When you select to register for an account using Google or Apple, the password is not shared with us. However, when you manually register your email and create a password, all information is transmitted to us over SSL and stored in our encrypted database.
Internally, the entire Hora Health team uses a secure password-sharing system to maintain the security of our systems, including our databases. Only very limited, trusted team members have access to the pseudonymised database. All information in our database is identified by your unique Hora Health User ID. This ID is a meaningless sequence of numbers to anyone else but us. We do not process any identifiable information from our database, we clone our database and only process Pseudonymised Information. We use two-factor authentication to access all third-party providers and integrations to ensure that even your Pseudonymised Information remains secure. We also ensure that all third-party services and integrations we use are in compliance with EU GDPR and that Pseudonymised Information is stored in databases located in the European Union.
7. SHARING YOUR PERSONAL DATA
We do not share Personal Data with anyone else other than:
• Contractors providing services we use for processing Personal Data under a professional duty of confidence, including:
• Others who carry out research into health, including academic research organisations (Universities), and commercial organisations (Pharmaceutical and LifeScience companies) for product development. When we collaborate with others in this way, we will always provide anonymous data in place of your personal details.
All of your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.
8. HORA HEALTH USERS UNDER THE AGE OF 16
When creating your Hora Health account, you are required to provide your date of birth. Where a date of birth is entered that is below the age of sixteen (16) years old, we ask for confirmation that your parent/legal guardian has provided their consent that you can use our Services. If you are a parent/legal guardian who has learnt that your child/ a child you are responsible for, is using the Hora Health App without your permission, or you have a query about data privacy at Hora Health, a query about data privacy at Hora Health, please get in contact with us via email at hello@hora.health
We do not knowingly collect personal information from children under the age of thirteen (13) years old. Where we discover a user that is below that age, Hora Health reserves the right to delete the account and wipe all relevant information about the account and user from our Servers.
9. YOUR DATA PROTECTION RIGHTS
Your privacy, and most importantly privacy of your data, is a basic human right, a right we at Hora Health truly respect. Our Services are designed to collect only the information necessary to provide our Services. We only collect and process your data for the purposes outlined in the policy. Internally, the entire Hora Health team uses a secure password-sharing system to protect our databases. Only a very limited, highly trusted team of members has access to your Personal Information. We do not retain your personal information in an identifiable format for longer than is necessary. We do not process any identifiable information from our database; we clone our database and process Pseudonymised Information there. We use two-factor authentication to access all third-party providers and integrations to ensure that even your Pseudonymised Information remains secure.
As a user of our Services, you may exercise your rights under EU GDPR to:
• Manage and/or correct your Personal Information and Health Information in the app settings.
• Request your Personal Information processed by Hora Health. Upon your request, such information will be provided to you electronically. Please request at hello@hora.health to be provided with your data within ten (10) working days.
• Gain access to your information by requesting a copy of your data in a format that is readable by other companies or organisations.
• Withdraw your consent from ongoing processing at any time by deleting your account, changing your privacy preferences, disabling notifications, and/ or unsubscribing to mailing lists.
• Request complete deletion of your data, including past data obtained, and sent to third-party providers and integrations by reaching out to hello@hora.health. Your data will be deleted within one (1) month of the request being received.
• Lodge a complaint with the relevant format that is readable by other companies or organisations.
• Withdraw your consent from ongoing processing at any time by deleting your account, changing your privacy preferences, disabling notifications, and/or unsubscribing to mailing lists.
• Request complete deletion of your data, including past data obtained, and sent to third-party providers and integrations by reaching out to hello@hora.health. Your data will be deleted within one (1) month of the request being received.
• Lodge a complaint with the relevant supervising authority where you believe Hora Health is processing your Personal Information in violation of applicable data protection regulations.
If you have any questions or if something in this privacy policy isn't clear, please feel free to reach out to us at hello@hora.health.
