Skip to document
Symloom
SupportBack to Symloom ↗
Privacy PolicyTerms of UseHealth Data PrivacyDelete Account

Consumer health data notice

Consumer Health Data Privacy Policy

This notice describes Symloom’s practices for consumer health data. It is separate from our general Privacy Policy so the most sensitive information is easy to understand and control.

Effective and last updated October 9, 2026

On this page

  1. 01Scope
  2. 02Health data we collect
  3. 03Sources
  4. 04Why we collect and use it
  5. 05Health data sharing
  6. 06Health records and advertising
  7. 07Your health-data rights
  8. 08Policy changes
  9. 09Contact us
Back to top ↑
On this page +
  1. 01Scope
  2. 02Health data we collect
  3. 03Sources
  4. 04Why we collect and use it
  5. 05Health data sharing
  6. 06Health records and advertising
  7. 07Your health-data rights
  8. 08Policy changes
  9. 09Contact us

1. Scope

This Consumer Health Data Privacy Policy applies to consumer health data processed through Symloom by AppEcho Labs LLC (“AppEcho,” “Symloom,” “we,” “us,” or “our”). “Consumer health data” means personal information that identifies or can reasonably be linked to a consumer and that identifies the consumer’s past, present, or future physical or mental health status, as defined by applicable law.

This notice supplements our general Privacy Policy. If this notice and the general policy conflict regarding consumer health data, this notice controls.

2. Categories of consumer health data we collect

Depending on what you choose to use or enter, Symloom may collect:

  • symptoms, conditions, severity, duration, bodily location, daily impact, mood, energy, and notes;
  • medications, supplements, interventions, treatments, routines, and perceived helpfulness;
  • food, hydration, sleep, activity, stress, weather, menstrual or reproductive context, suspected triggers, and custom factors;
  • daily Apple Health or Health Connect summaries for sleep duration, steps, workouts, and resting heart rate; optional sleep timing, regularity, awake periods, heart-rate variability, respiratory rate, and sleeping wrist temperature where supported; and menstrual-flow information only if you separately enable cycle context in Symloom;
  • health goals, tracking templates, report preferences, reminder preferences, and appointment-preparation choices;
  • summaries, correlations, charts, insights, and reports derived from your entries;
  • identifiers needed to associate health records with your account, such as your Firebase user ID; and
  • limited health-related product interactions, such as whether a check-in or report was completed, but never the health contents of that check-in or report in analytics or attribution payloads.

Providing health information is voluntary, although Symloom cannot provide a feature that depends on information you choose not to provide. Apple Health and automatic weather are optional.

3. Categories of sources

We collect consumer health data from:

  • you, when you enter, edit, import, or communicate information;
  • Apple Health, only for data types you authorize through Apple’s system permissions;
  • Apple Weather, when you enable automatic weather context; and
  • Symloom itself, when it organizes your entries into summaries, patterns, charts, or reports.

4. Why we collect and use consumer health data

We collect and use consumer health data only to:

  • provide the tracking, synchronization, insight, summary, reminder, report, export, and sharing features you request;
  • personalize your templates, factors, and experience;
  • maintain, secure, troubleshoot, and support Symloom and your account;
  • prevent fraud, abuse, or security incidents and preserve system integrity; and
  • comply with law and establish or defend legal claims.

We do not use your health records, health answers, or journal content for targeted advertising, marketing profiles, cross-app tracking, data-broker products, insurance eligibility, employment decisions, credit decisions, or automated decisions that produce legal or similarly significant effects.

5. Categories of consumer health data we share

We disclose account-linked health entries, settings, summaries, and generated reports to Google LLC through Firebase solely as our cloud processor for authentication, storage, synchronization, messaging, and server functions needed to provide Symloom. Google processes this data on our behalf under contractual and security obligations.

Symloom also discloses narrowly limited product-interaction data to the following providers. PostHog events may be account-linked after sign-in; AppsFlyer attribution remains install-scoped. Because use of a health app may itself be considered consumer health data in some jurisdictions, we list these disclosures even though they do not contain the substance of your health records:

Meta and AppsFlyer remain off for users with a recorded age of 16–17. The app is not intended for anyone under 16. Advertising identifiers, tracking choices, and the treatment of existing adult accounts are explained in our Privacy Policy.

  • PostHog: allow-listed events such as whether onboarding, a check-in, or a report was completed; Firebase user ID after sign-in; platform; app version; and plan type.
  • AppsFlyer: install and campaign attribution, an install-scoped AppsFlyer identifier, and non-content funnel events such as onboarding, paywall, trial, or subscription milestones, plus device information and IP-derived approximate location. For adults, advertising identifiers may be available subject to iOS tracking permission or Android system settings. Symloom does not send AppsFlyer the Firebase user ID.
  • Meta: for adults, app activation, onboarding completion, trial-start and subscription-start events, SDK device information, and permitted advertising identifiers for measuring our campaigns. We do not send Meta check-in, insight or report events, health answers, your Firebase user ID, email or phone number.
  • RevenueCat and the applicable app store: account identifier, subscription product, entitlement, trial, renewal, and expiration status.
  • Weather providers: when you enable automatic weather, your device sends location to Apple Weather on iOS or OpenWeather on Android to request local conditions, forecasts, or historical weather where supported. AppEcho does not store the coordinates with your account or send them to advertising providers.

We may disclose the minimum necessary consumer health data to security, legal, or technical advisers when needed to investigate an incident, comply with valid law, or protect legal rights. We may also disclose data as part of a business transaction, subject to applicable law and protections consistent with this notice.

We do not disclose your symptom labels, medications, notes, severity values, report contents, Apple Health values, or Apple Health permission choices to PostHog, AppsFlyer, Meta, RevenueCat, advertising networks, or data brokers.

When you choose to export or share a report through your device, you direct that disclosure. Symloom does not choose the recipient. The recipient’s privacy practices apply after the information leaves Symloom.

We have no affiliates with whom we share consumer health data as of the effective date of this notice.

6. Health records are not sold or used for advertising

AppEcho does not sell your health records or journal content, exchange them for money or other valuable consideration, or use them for targeted advertising. Our cloud processors may not use those records for their own advertising. Limited app-use and conversion information sent to measurement partners is disclosed in Section 5 because use of a health app may itself be considered consumer health data.

7. Your consumer health data rights

Subject to applicable law and exceptions, you may request to:

  • confirm whether we collect, share, or sell your consumer health data;
  • access the consumer health data we maintain about you;
  • receive a list of third parties and affiliates with whom your consumer health data has been shared or sold, with contact information where required;
  • withdraw consent for future collection or sharing of consumer health data; and
  • delete your consumer health data.

You can edit or delete entries, export your data, disconnect optional sources, or delete your account in Symloom settings. You can also email support@symloom.com with “Health Data Request” in the subject. We may take reasonable steps to authenticate your request. An authorized agent may submit a request where permitted, subject to verification of authority and identity.

When a verified deletion request applies, we will delete covered health data from active systems and direct applicable processors or contractors to do the same. Deletion from archived or backup systems may be delayed for up to six months where permitted by law; affected data will not be restored to active use except as needed for security or integrity.

If we deny your request, we will explain why and provide instructions to appeal. To appeal, reply to our decision or email us with “Health Data Appeal” in the subject. We will not unlawfully discriminate against you for exercising these rights.

8. Changes to this notice

We will update this notice before collecting, using, or sharing new categories of consumer health data or using existing categories for materially new purposes. Where law requires, we will obtain your affirmative consent before the new collection, use, or sharing begins.

9. Contact us

AppEcho Labs LLC
Alexandria, Virginia 22304
United States
support@symloom.com
End of Consumer Health Data Privacy PolicyBack to top ↑
Symloom

Symloom is a personal tracking and communication tool. It does not provide medical advice, diagnosis, or treatment.

PrivacyTermsHealth dataSupport
© 2026 AppEcho Labs LLC