Skip to document
Symloom
SupportBack to Symloom ↗
Privacy PolicyTerms of UseHealth Data PrivacyDelete Account

AppEcho Labs LLC

Privacy Policy

Symloom handles deeply personal information. This policy explains, in plain language, what we collect, why we need it, when it may be disclosed, and the choices you have.

Effective and last updated October 9, 2026

On this page

  1. 01Scope and key commitments
  2. 02Information we collect
  3. 03Sources of information
  4. 04How we use information
  5. 05How we disclose information
  6. 06Apple Health and location
  7. 07Analytics and advertising measurement
  8. 08Retention and deletion
  9. 09Security
  10. 10Your privacy rights
  11. 11Age requirement
  12. 12U.S. processing
  13. 13Changes to this policy
  14. 14Contact us
Back to top ↑
On this page +
  1. 01Scope and key commitments
  2. 02Information we collect
  3. 03Sources of information
  4. 04How we use information
  5. 05How we disclose information
  6. 06Apple Health and location
  7. 07Analytics and advertising measurement
  8. 08Retention and deletion
  9. 09Security
  10. 10Your privacy rights
  11. 11Age requirement
  12. 12U.S. processing
  13. 13Changes to this policy
  14. 14Contact us

1. Scope and key commitments

This Privacy Policy applies to the Symloom mobile application, the symloom.com website, and related services operated by AppEcho Labs LLC (“AppEcho,” “Symloom,” “we,” “us,” or “our”).

Our core commitments
  • We do not sell your health records or journal content.
  • We do not use health data for targeted advertising, marketing profiles, data-broker products, or cross-app tracking.
  • We do not send notes, symptom labels, medication names, severity values, report contents, Apple Health values, or Apple Health permission choices to analytics or advertising-measurement providers.
  • You can use Symloom without connecting Apple Health, and you control what you export or share.

Symloom is a consumer wellness and personal-record tool. AppEcho is not a health care provider, health plan, or health care clearinghouse, and Symloom is generally not governed by the Health Insurance Portability and Accountability Act (“HIPAA”). Other privacy and consumer-health laws may apply. Our separate Consumer Health Data Privacy Policy provides additional disclosures and rights relating specifically to consumer health data.

2. Information we collect

Information you provide

  • Account information: email address, authentication provider, account identifier, and any name provided by Apple, Google, or another sign-in provider, plus a name or profile photo you choose to add.
  • Health and wellness entries: symptoms, severity, mood, energy, meals, sleep, medications, interventions, menstrual or cycle context, possible triggers, notes, tags, daily impact, and other information you choose to track.
  • Preferences and goals: templates, reminders, tracked factors, report preferences, age range, optional gender, onboarding responses, and settings. Health-related responses may include symptom timing, what helps, appointment dates and topics, and changes you want to review. These answers are stored with your account and are not sent to advertising providers.
  • Communications: information you include in support, feedback, privacy, or other messages to us.
  • Website submissions: an email address or other information you submit for early access, product updates, or support.

Information collected through the app

  • Apple Health and Health Connect summaries: if you opt in, Symloom may read sleep duration and stages, step count, workouts, and resting heart rate. You can separately enable sleep timing and regularity, awake periods, heart-rate variability, respiratory rate, and sleeping wrist temperature where supported, as well as menstrual-flow information. Symloom processes raw samples on your device and keeps daily summaries needed for features you use. Summaries saved in a check-in may be synchronized with your account through Firebase; raw Health samples are not uploaded. Menstrual-flow information is not imported, analyzed, or displayed unless you separately enable cycle context in Symloom.
  • Weather context: if you enable automatic weather, Symloom receives local conditions such as temperature, pressure, pressure trend, cloud cover, and condition category for today’s check-in.
  • Subscription information: plan, entitlement status, trial status, purchase and renewal status, and expiration date. We do not receive your complete payment-card number.
  • Technical and product-usage information: app version, platform, device and operating-system information, crash or diagnostic information, IP-derived technical logs, push-notification tokens, app lifecycle events, and limited feature events.
  • Acquisition information: source, channel, campaign, ad-group, creative or keyword identifiers, storefront, referral or deep-link information, app-install identifiers, device information, approximate location derived from IP addresses, and limited events such as onboarding completion, trial start, and subscription start. For adults, AppsFlyer and Meta may receive advertising identifiers: on iOS, IDFA access requires App Tracking Transparency permission; on Android, availability depends on system advertising-ID settings. See Section 7 for the age restrictions and your choices.

Information Symloom creates

Symloom generates summaries, charts, reports, and cautious observations about associations in your entries. These are not diagnoses and do not establish that one factor caused or treated a symptom.

3. Sources of information

We receive information from:

  • you, when you enter information or contact us;
  • your device and the Symloom app;
  • Apple Health or Health Connect, and Apple Weather or OpenWeather, only when you enable the applicable feature and grant permission;
  • sign-in providers such as Apple and Google;
  • app stores and subscription infrastructure, including Apple and RevenueCat; and
  • service providers supporting hosting, security, analytics, attribution, notifications, and customer support.

4. How we use information

We use personal information to:

  • create and secure your account;
  • save and sync check-ins, personalize tracking, surface patterns, generate reports, and provide features you request;
  • process subscriptions, trials, renewals, and entitlements;
  • send reminders and service communications you request;
  • provide support and respond to privacy requests;
  • maintain, troubleshoot, secure, and improve Symloom without using your health content for advertising;
  • measure non-health product usage and acquisition performance under the restrictions described below;
  • detect fraud, abuse, security incidents, or violations of our Terms; and
  • comply with law and enforce our legal rights.

5. How we disclose information

We disclose information only as reasonably necessary for the purposes below:

  • Cloud and app operations: Google Firebase supports authentication, cloud storage, functions, synchronization, and messaging.
  • Sign-in: Apple and Google process information when you choose their sign-in services.
  • Subscriptions: Apple, Google Play where applicable, and RevenueCat process purchases and subscription entitlements.
  • Restricted analytics: PostHog receives only allow-listed product events and non-health properties.
  • Restricted attribution: AppsFlyer receives limited acquisition information and limited conversion events, including permitted advertising identifiers for adults as described in Section 7. It does not receive health records or journal content.
  • Meta ad measurement: Meta receives app activation, onboarding completion, trial-start and subscription-start events, along with SDK device information and permitted advertising identifiers for adults, to measure and optimize our Facebook and Instagram campaigns. We do not send Meta your account ID, email, phone number, health records, or journal content.
  • Professional advisers and vendors: lawyers, auditors, security providers, and support vendors may receive the minimum information needed to perform services for us under confidentiality obligations.
  • Legal and safety reasons: we may disclose information when we reasonably believe it is required by valid law or legal process, or necessary to protect rights, safety, and security. We review requests and may challenge overbroad or inappropriate demands where permitted.
  • Business transaction: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and protections consistent with this policy.
  • At your direction: when you export a report or use your device’s share sheet, the recipient and destination are chosen by you. Once shared, the recipient’s practices control that copy.

Our cloud processors handle health records to provide the services you request. The limited information sent to advertising-measurement partners is described separately in Section 7. We do not send them your health records or permit our cloud processors to use those records for their own advertising.

6. Apple Health and location

Apple Health

Apple Health access is optional and read-only. Symloom does not write to Apple Health. You choose which supported data types to permit in Apple’s system settings and can change those permissions there. Symloom treats missing data as unavailable, not as a zero or proof that permission was denied. Apple Health data is used only to provide health and wellness features you request and is never used for advertising, marketing, data-broker products, or unrelated profiling. Deleting information in Symloom does not delete the original information from Apple Health.

Location and weather

Symloom requests device location only if you enable automatic weather. On iOS, the native WeatherKit integration sends location to Apple; on Android, the device sends coordinates to OpenWeather when that service is available. Location is used to request local weather, including forecasts or historical conditions where supported. AppEcho does not store your coordinates with your account or send them to analytics or advertising providers. The weather provider processes the request under its own privacy practices. Weather observations saved with a check-in may be synchronized with your account.

Separately, analytics and attribution providers may derive approximate location from your IP address. This does not require the automatic weather feature or access to your device’s location permission.

7. Analytics and advertising measurement

Product analytics

PostHog receives allow-listed product events such as onboarding completion, a check-in being completed, a reminder being enabled, a report being created, a paywall being viewed, or a subscription beginning. Properties are limited to non-sensitive information such as platform, app version, plan type, display language, fixed screen identifiers, and experiment variants. PostHog uses your Firebase user ID, not your email, to link product events to your account. Session replay is disabled. We do not include health answers, notes, symptom labels, medication names, severity, report contents, or Health values.

Measuring advertisements for Symloom

Symloom does not display third-party ads inside the app. For adults, we use AppsFlyer to attribute installs and limited conversion events to acquisition sources, and Meta to measure and optimize our Facebook and Instagram campaigns. AppsFlyer receives onboarding completion, paywall-view, trial-start, and subscription-start events. Meta receives app activation, onboarding completion, trial-start, and subscription-start events. These events carry no health-content parameters. Meta does not receive check-in, insight, or report events.

These partners may process install or device identifiers, device and operating-system information, IP-derived approximate location, campaign information, and permitted advertising identifiers. Linking this information with activity across other companies’ apps or websites for advertising measurement is tracking. We do not send either partner your Firebase account ID, email, phone number, or health records. AppsFlyer uses its own install-scoped identifier. Apple Ads attribution can also use Apple’s AdServices mechanism without an IDFA.

Your choices and age restrictions

On iOS, the App Tracking Transparency prompt asks adults for tracking permission. IDFA access requires permission; declining does not block the journal or other app features. You can change that choice in Settings → Privacy & Security → Tracking. Declining does not turn off all product analytics or privacy-preserving attribution. On Android, you can manage or delete your advertising ID in your device’s settings. These controls do not delete previously collected records; you can make a privacy request using Section 10.

Meta and AppsFlyer start only after an adult age decision. An age answer of 16–17 keeps both services off, and an under-18 account stops them on a device where that account signs in. Accounts that completed onboarding before the age-range question were subject to the former 18+ requirement and are treated as adult accounts unless a younger age is recorded. Product analytics is separate from this age restriction.

8. Retention and deletion

We keep account, preference, and health information while your account is active and as needed to provide Symloom. You may delete individual entries at any time. You may also request an export or delete your account in Symloom settings.

When account deletion succeeds, Symloom removes the account’s profile and check-ins from active production systems. Deletion from archived or backup systems may take up to six months, where permitted by law; backup copies are isolated from ordinary use until overwritten. We may retain limited non-health records when reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, enforcing agreements, or documenting a privacy request. We may retain aggregated or deidentified information that cannot reasonably be linked back to you.

App-store transaction records are controlled by the applicable store and may remain subject to its retention rules. Deleting Symloom does not cancel an active subscription; cancel through your app-store account.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, data minimization, and restricted analytics. No system is perfectly secure, and we cannot guarantee absolute security. Protect your device and credentials, and contact us promptly if you suspect unauthorized access.

If a qualifying breach occurs, we will provide notices required by applicable law, including the Federal Trade Commission’s Health Breach Notification Rule where it applies.

10. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • confirm whether we process your personal information;
  • access or receive a portable copy of information;
  • correct inaccurate information;
  • delete information;
  • withdraw consent for future processing;
  • opt out of sale or sharing of personal information, targeted advertising, or certain profiling where applicable; and
  • appeal a decision on your privacy request.

Use the export and deletion controls in Symloom settings or email support@symloom.com. Put “Privacy Request” in the subject and describe the right you want to exercise. We may verify your identity before acting. If we deny a request, you may appeal by replying with “Privacy Appeal” in the subject. We will not unlawfully discriminate against you for exercising privacy rights.

You may use an authorized agent where applicable. We may request proof of authorization and verify your identity directly. If we cannot resolve a concern, you may contact your state attorney general or privacy regulator.

11. Age requirement

Symloom is intended for people aged 16 and older. Onboarding blocks users who report being under 16. Users aged 16–17 may use the app, with parent or guardian permission where required by applicable law; Meta and AppsFlyer remain disabled for these users. We do not knowingly collect personal information from children under 16. If you believe someone under 16 has provided information, contact us so we can investigate and delete it as appropriate.

12. U.S. processing

AppEcho is based in the United States. Symloom and its service providers may process information in the United States and other countries where privacy laws may differ from those where you live. Symloom is currently offered under this U.S.-focused policy and is not directed to jurisdictions where our processing would be unlawful.

13. Changes to this policy

We may update this policy as Symloom changes or law requires. We will post the revised policy with a new effective date and provide additional notice when a change is material. Where required, we will ask for consent before collecting, using, or disclosing health data in a materially new way.

14. Contact us

AppEcho Labs LLC
Alexandria, Virginia 22304
United States
support@symloom.com
End of Privacy PolicyBack to top ↑
Symloom

Symloom is a personal tracking and communication tool. It does not provide medical advice, diagnosis, or treatment.

PrivacyTermsHealth dataSupport
© 2026 AppEcho Labs LLC