VerbatermBetaVerbaterm is in beta. You may encounter bugs, incomplete features, or unexpected results while we improve reliability.

Privacy policy

Flo

Review these first

Score94.0
Reviewed
Policy typePrivacy policy
Concern findings4
Protections7
Source supportStrong

Source provenance

Verified official source
Retrieved
Last checked
PublishedAutomated refresh

What changedPolicy text changed materially since the previous snapshot. 5 new line(s), 3 removed line(s).

Snapshot hash f14d0cea1474d5ae649028650152cb9979a6a1aac73aab6c80257942821561dd

Snapshot of the source text at fetch time, not a live mirror of the policy page.

Plain-English summary

This privacy policy raises concerns about the potential for limited dispute rights due to an arbitration clause, the transfer and processing of personal data in countries with potentially lower protections, and the inherent inability to guarantee absolute security against data interception. Additionally, information posted in community areas may be used beyond the company's control (risk_flags-4), user's sex or gender may be inferred based on app usage (data_use-1), and personal data may be collected from external third parties (data_use-2). The policy also states that personal data is retained for three years after app deletion or inactivity (data_use-3), and payment transaction information (excluding full card details) is collected.

90% confidence

Ask Verbaterm

Follow up on findings with grounded answers from this review. Not legal advice.

Risk Flags

1 finding

Critical issues or potential legal/privacy violations that could lead to significant harm or legal action.

medium90% confidence

Personal data you post in community areas is accessible and may be used beyond control

Any information shared in community areas like Secret Chats and guided groups is accessible to the Flo community. The policy warns that what is posted can be seen, disclosed, or collected by others and may be used in ways beyond the company's control, including contacting users for unauthorized purposes.

Disclaimer of warranties

Why it matters: Information you share in public community areas can be accessed and potentially misused by others, including for unauthorized contact, and the company has no control over its use once posted.

Any information you share in these community areas is accessible to the Flo community. Please think carefully before posting anything that could identify you in any public forum. Remember, what you post can be seen, disclosed, or collected by others and may be used in ways beyond our control, including contacting you for unauthorised purposes.

Information posted by you, paragraph 1 · Citation strength: strong

Data Use

3 findings

How the company collects, uses, and shares your data.

medium90% confidence

Inferred sex or gender based on app usage

The policy states that based on how you use the Services, your sex or gender may be inferred.

Why it matters: Your sex or gender may be determined and recorded by the app based on your usage patterns, even if you do not explicitly provide this information.

Based on how you use the Services, we may also infer your sex or gender.

Personal data you provide to us directly:, paragraph 1 · Citation strength: strong

medium90% confidence

Personal data collected from external sources and third parties

The company may receive personal data about you from external sources and third parties, which they may use to enhance existing data, personalize your experience, and support analytics and statistics.

Why it matters: Your personal data may be shared with the company by external sources and third parties, which they can then use to enhance their data about you, personalize your experience, and for analytics.

Data from external sources: We may receive your personal data from third parties. For example, they may provide additional information to enhance your existing data, personalise your experience, and support analytics and statistics.

Personal data we collect automatically:, paragraph 2 · Citation strength: strong

low90% confidence

Retention of personal data for three years after inactivity or app deletion

If you delete the App from your device or your account becomes inactive, your personal data will be retained for three years in case you reactivate the Services or reinstall the App. After three years of inactivity, your personal data will be deleted.

Why it matters: Even if you delete the app or become inactive, your personal data will be stored for three years, during which it could still be accessed or used by the company.

Deleting the App or inactivity: If you delete the App from your device or your account becomes inactive, we will retain your personal data for three years in case you decide to reactivate the Services or reinstall the App. After three years of inactivity, your personal data will be deleted. Flo will apply this standard retention policy.

Retention of your personal data, paragraph 1 · Citation strength: strong

Cancellation & Renewal

All clear

Terms related to how subscriptions renew, how to cancel, and any associated fees or conditions.

Looking good

No billing surprises spotted

Verbaterm only flags concerns it can cite. No cancellation, auto-renewal, or refund terms needed attention here.

Gotchas

All clear

Potentially overlooked clauses that could be unfavorable.

Looking good

No hidden gotchas

Verbaterm only flags concerns it can cite. Nothing easy-to-miss stood out in this section.

Protections

7 findings

Commitments and features that protect users.

Protection95% confidence

No sale of personal data

The company states that it does not sell or rent personal data for money and will only share it as outlined in the Privacy Policy, including with service providers.

Why it helps: This commitment helps protect your personal data from being sold to third parties for financial gain, limiting its distribution.

No sale of personal data: we do not sell or rent your personal data for money. We will only share your personal data as outlined in this Privacy Policy.

scan for vulnerabilities to ensure security; and, paragraph 4 · Citation strength: strong

Protection95% confidence

No use of Apple HealthKit or Google Health Connect data for advertising

The company explicitly states that it will not use information from Apple HealthKit or Google Health Connect for advertising or sell it to advertising platforms, data brokers, or resellers.

Why it helps: This prevents sensitive health and activity data imported from these third-party services from being used for advertising purposes, enhancing your privacy.

We will not use information from Apple HealthKit or Google Health Connect for advertising or sell it to advertising platforms, data brokers or resellers.

scan for vulnerabilities to ensure security; and, paragraph 4 · Citation strength: strong

Protection90% confidence

Commitment to GDPR privacy rights for all users

Regardless of where users live, the company is committed to providing the same privacy rights afforded under the GDPR, which it regards as the highest standard for data protection globally.

Why it helps: This ensures that all users, regardless of location, benefit from a high standard of data protection rights, aligning with the comprehensive protections offered by GDPR.

Regardless of where you live, we’re committed to providing you the same privacy rights afforded under the GDPR, which is generally regarded as the highest standard for data protection globally.

Your privacy rights, paragraph 1 · Citation strength: strong

Protection95% confidence

Right to data portability

Users have the right to request their personal data in a format that allows them to easily move, copy, or transfer it to third parties for other services or purposes.

Why it helps: This gives you control over your data, allowing you to transfer it to other services and preventing vendor lock-in.

You can request your personal data in a format that lets you easily move, copy or transfer it to third parties for other services or purposes.

Right to data portability, paragraph 1 · Citation strength: strong

Protection95% confidence

Ability to withdraw consent for health data processing and delete account

Your consent is required for the company to use your health data, and you can withdraw this consent at any time by contacting the company or deleting your account through the App.

Why it helps: This provides you with control over the processing of your health data, allowing you to revoke permission or delete your account at any time.

Your consent is required for us to use your health data. You can withdraw this consent at any time by either contacting us or deleting your account through the App.

How to exercise your privacy rights, paragraph 1 · Citation strength: strong

Protection95% confidence

Health data not shared with third parties for marketing purposes

The company explicitly states that it does not share health data with third parties for marketing purposes. While it may share other information with specific marketing platforms (AppsFlyer, Firebase, TikTok Ad Manager) with user consent, health data is excluded from this sharing.

Why it helps: This commitment ensures that your sensitive health data is not used or shared with third parties for marketing and advertising, enhancing your privacy.

We do not share your health data with third parties for marketing purposes. With your consent, Flo may collect and share information with AppsFlyer and its partners, Firebase and TikTok Ad Manager. These are mobile app marketing and analytics platforms (not social media platforms) who help us improve our advertising campaigns, understand the performance of our campaigns and spread the word about Flo. They may also use information collected to remind you to revisit the App if you haven’t used it in a while. Your health data is not shared with AppsFlyer, Firebase or TikTok Ad Manager.

Third party data processing, paragraph 1 · Citation strength: strong

Protection95% confidence

Age limitation for service use to protect minors

The Services are not for children, and the company does not knowingly collect personal data from anyone under 13. For residents of the EEA, UK, Canada, and India, the age limit is at least 16.

Why it helps: This policy protects children by preventing the collection of personal data from individuals under specified age limits, contributing to their online safety.

General age limitation: our Services are not for children, and we do not knowingly collect personal data from anyone under 13. If you know of someone under 13 using the Services, please email us at support@flo.health. Age limitation for residents of the European Economic Area (EEA), United Kingdom (UK), Canada and India: For legal reasons, residents of the EEA, the UK, Canada or India must be at least 16.

Children’s privacy, paragraph 1 · Citation strength: strong

Report an issue

Flag a citation problem, stale policy text, or incorrect company match.

Verbaterm boundaries

This public review is informational only and is not legal advice. Verbaterm shows only findings tied to the cited source snapshot above.