Privacy Policy

Last Updated: February 23, 2026

1. Overview

This Privacy Policy explains how EVBOhealth ("we", "us", "our") collects, uses, discloses, and protects information when you use HealthFlow (the “Service”).

By using HealthFlow, you agree to this Privacy Policy. If you do not agree, do not use the Service.

2. Eligibility / Age

You must be at least 18 years old to use the Service, or use the Service under the supervision and consent of a parent or legal guardian. We do not knowingly collect personal information from children without appropriate authorization.

3. Information We Collect

3.1 Account & Profile Information

When you create an account, we may collect information such as your name, email address, phone number, date of birth, timezone, and emergency contact details (name, phone, relationship).

3.2 Health & Device Data

If you connect health devices or enter health readings, we may collect health-related information you provide or that devices transmit (e.g., vitals, measurements, timestamps, device identifiers, firmware/app versions, signal/battery metrics, and related logs).

3.3 Usage & Technical Data

We may collect technical information such as IP address, device type, browser, operating system, pages/screens viewed, feature usage, and diagnostic logs (including crash reports) to operate and improve the Service.

3.4 Communications

If you contact us (email/support), we collect the contents of your message and related contact information.

4. How We Use Information

We use information to:

  • Provide, maintain, and secure the Service
  • Create and manage your account
  • Display your health data and provide tracking/monitoring features
  • Send notifications you request (e.g., email/SMS alerts) and service-related messages
  • Improve performance, reliability, and user experience
  • Detect, prevent, and address fraud, misuse, or security issues
  • Comply with legal obligations and enforce our Terms

5. No Medical Advice

HealthFlow is an informational and support tool only. The Service is not intended to provide medical advice, diagnosis, or treatment, and it should not be used to make medical decisions.

Always seek the advice of a qualified healthcare professional with any questions regarding a medical condition. In an emergency, call 911 (or your local emergency number).

6. Device Data Accuracy

Wearables and home medical devices can produce inaccurate or incomplete readings. HealthFlow does not guarantee the accuracy of device data, calculations, alerts, or insights. Confirm clinically significant readings with appropriate medical evaluation and/or approved clinical devices.

7. How We Share Information

We may share information in the following circumstances:

7.1 Service Providers (Third Parties)

We use third-party providers to operate the Service (for example: Firebase/Google Cloud services, device vendors/integration partners, and email/SMS delivery providers). These providers may process information on our behalf to provide hosting, authentication, data storage, messaging, analytics, and support functions.

We are not responsible for third-party outages or actions outside our control. However, we generally require service providers to handle data in a manner consistent with this Privacy Policy and to use it only for providing services to us.

7.2 Legal & Safety

We may disclose information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect the rights, property, or safety of users, our company, or others.

7.3 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.

7.4 With Your Direction or Consent

We may share information when you request it, authorize it, or provide consent (for example, sharing data with a provider or caregiver, if the Service offers that feature).

8. HIPAA & Protected Health Information (PHI)

HealthFlow is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA) when handling Protected Health Information (PHI). We take our obligations seriously and implement comprehensive safeguards to protect your health data.

8.1 What is PHI?

Protected Health Information includes any individually identifiable health information such as your medical history, health conditions, vital signs, medications, lab results, and any other data that relates to your past, present, or future health.

8.2 Administrative Safeguards

  • Workforce training on HIPAA compliance and data privacy
  • Designated Privacy and Security Officers
  • Regular risk assessments and security audits
  • Documented policies and procedures for handling PHI
  • Business Associate Agreements (BAAs) with all vendors who access PHI
  • Incident response and breach notification procedures

8.3 Technical Safeguards

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256)
  • Unique user identification and authentication
  • Automatic session timeout after 30 minutes of inactivity
  • Strong password requirements (minimum 8 characters with complexity)
  • Audit controls and activity logging
  • Role-based access controls limiting PHI access to authorized personnel

8.4 Physical Safeguards

  • Data hosted on HIPAA-compliant cloud infrastructure (Google Cloud/Firebase)
  • Facility access controls at data center locations
  • Workstation and device security policies

8.5 Your Rights Under HIPAA

You have the right to:

  • Access and obtain a copy of your health information
  • Request corrections to your health information
  • Request restrictions on certain uses and disclosures
  • Receive an accounting of disclosures of your PHI
  • Request confidential communications
  • File a complaint if you believe your privacy rights have been violated

8.6 Minimum Necessary Standard

We apply the "minimum necessary" standard, meaning we limit access to PHI to only the information needed for a specific purpose. Staff and providers only see the patient data necessary for their role in your care.

8.7 Business Associate Relationships

When HealthFlow is used by healthcare providers, clinics, or organizations, we may act as a Business Associate under HIPAA. In such cases, we enter into Business Associate Agreements that define our obligations for protecting PHI.

9. Breach Notification

In the unlikely event of a data breach involving your PHI, we will notify you and relevant authorities as required by HIPAA and applicable state laws. Notification will occur without unreasonable delay and no later than 60 days after discovery of a breach.

Breach notifications will include: a description of what happened, the types of information involved, steps you can take to protect yourself, what we are doing to investigate and mitigate harm, and contact information for questions.

10. Account Security

You are responsible for maintaining the confidentiality of your login credentials and for all activity under your account. If you believe your account has been compromised, notify us immediately at info@evbohealth.com.

11. Acceptable Use & Misuse

You agree not to misuse the Service. This includes (but is not limited to):

  • Attempting to access accounts or data that are not yours
  • Reverse engineering, scraping, automated extraction, or probing the Service
  • Uploading malicious code or interfering with system integrity/security
  • Using the Service for illegal activities or to violate others’ rights

12. Data Retention

We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and for legitimate operational needs (such as security and audit logging). Retention periods may vary depending on data type and context.

13. Your Choices

  • Access/Update: You may be able to update certain profile details within the Service.
  • Device Connections: You can disconnect devices (where supported), which may stop future data syncing.
  • Communications: You can opt out of certain non-essential messages where applicable (service/security messages may still be sent).

14. SMS/Text Message Communications

By providing your phone number and consenting to SMS communications during registration, you agree to receive text messages from HealthFlow related to your health monitoring.

14.1 Types of Messages

We may send you the following types of SMS messages:

  • Health Alerts: Notifications about abnormal vital signs or health readings that may require attention
  • Vital Sign Notifications: Daily or periodic summaries of your health data
  • Medication Reminders: Scheduled reminders to take your medications
  • Task Reminders: Reminders for health-related tasks you have scheduled
  • Emergency Contact Alerts: Critical health alerts sent to your designated emergency contacts

14.2 Message Frequency

Message frequency varies based on your health data, device readings, and configured alerts. You may receive multiple messages per day if abnormal readings are detected, or no messages on days when your health data is within normal ranges.

14.3 Carrier Charges

Message and data rates may apply depending on your mobile carrier plan. HealthFlow does not charge for SMS messages, but your carrier may charge standard messaging rates.

14.4 How to Opt Out

You can stop receiving SMS messages at any time by:

  • Replying STOP to any message from HealthFlow
  • Updating your notification preferences in your account settings
  • Contacting us at info@evbohealth.com

Important: Opting out of SMS messages means you will not receive critical health alerts via text. Ensure you have alternative means to monitor your health data.

14.5 Help

For help with SMS messages, reply HELP to any message or contact us at info@evbohealth.com.

14.6 SMS Service Provider

We use Twilio, a third-party telecommunications provider, to deliver SMS messages. Twilio processes your phone number and message content to deliver notifications. Twilio's use of your information is governed by their privacy policy, and we have a Business Associate Agreement in place to ensure HIPAA compliance.

14.7 Consent Records

We maintain records of your SMS consent, including the date and time you provided consent and the version of the consent language you agreed to. This information is retained for compliance and audit purposes.

15. Account Closure, Deletion, and What Happens to Data

If you close your account, we may disable access to the Service. We may retain certain information as required or permitted by law and for legitimate business purposes (for example, security logs, fraud prevention, and compliance). Where supported, you may request deletion of certain data by contacting us.

16. International Data Transfers

If you access the Service from outside the United States, your information may be processed and stored in the United States or other locations where our service providers operate. By using the Service, you consent to such transfers, subject to applicable law.

17. Security

We use reasonable administrative, technical, and physical safeguards designed to protect your information. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last Updated” date at the top. If changes are material, we may provide additional notice (such as an in-app notice or email), where appropriate.

19. Contact

If you have questions about this Privacy Policy or your data, contact us at info@evbohealth.com.