Legal
The short version: Lō is a personal wellness app. You enter your own health data to help yourself. We store it securely, we don’t sell it, we don’t share it with third parties, and you can delete it at any time. That’s it.
Lō is not a medical device or healthcare provider. The information and tracking tools in this app are for personal wellness and education purposes only. Nothing in this app constitutes medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider for medical concerns.
Lō is a personal wellness application operated by Lō Health LLC (“we”, “us”, or “our”), a California limited liability company. Our website is joinlo.co and our app is available at joinlo.co.
If you have questions about this privacy policy or how we handle your data, contact us at support@joinlo.co.
Lō Health LLC is registered as a data controller with the UK Information Commissioner's Office (ICO). ICO registration number: ZC171013.
We collect only the data you voluntarily provide when using the app. Here is a complete list:
| Data type | What it includes | Why we collect it |
|---|---|---|
| Account information | First name, last name, email address, password (hashed) | To create and manage your account |
| Health profile | Date of birth, height, weight, target weight, menopause life stage | To calculate personalised nutrition targets |
| Location data | Country of residence | To provide region-appropriate content and for anonymised geographic research into menopause symptom patterns |
| Ethnic background | Optional self-reported ethnic background (multi-select) | Menopause timing and symptom severity vary by ethnic background. This optional data helps us surface more relevant insights. It is never shared and is used solely to improve personalisation. |
| Symptom data | Symptoms you log, frequency, severity scores | To track patterns and generate appointment reports |
| Weekly check-ins | Energy score, mood score, sleep quality | To show trends and support pattern detection |
| Nutrition logs | Meals you log, macro values you enter | To track progress against your nutrition targets |
| Goals | Health and fitness goals you select | To personalise your experience |
| Activity data | Training frequency, occupation activity level, daily steps | To calculate your calorie targets accurately |
| HRT/MHT information | Whether you are on hormone therapy and what type, if you choose to enter this | To contextualise symptom tracking and personalise your protocol |
| Medications and supplements | Medications and supplements you choose to log | To personalise your health protocol and flag relevant interactions |
| Training data | Your training plan, workout logs, and session completion | To track training progress and generate personalised plans |
| Billing information | Subscription plan, billing country, payment status and transaction history. Card details are held by Paddle, not by Lō | To provide and manage your paid subscription, and to meet tax and accounting obligations |
| Wearable device data | If you connect a wearable (such as Oura Ring): sleep scores, HRV, readiness, activity, and temperature deviation | To enrich your health protocol and provide deeper insights |
| Contact submissions | Messages you send us via the in-app contact form, including topic and message content | To respond to your enquiries and improve the product |
| Email preferences | Your choices about which reminder and marketing emails you receive | To respect your communication preferences |
| Device & technical data | IP address collected at the point of account creation | For fraud prevention, security monitoring, and geographic analytics |
We do not collect your precise GPS location, contacts, microphone, camera, or any other device data beyond what you explicitly enter into the app.
Your data is used exclusively to provide the features of the Lō app to you. Specifically:
We do not use your data for advertising. We do not build profiles for marketing purposes. We do not use your data to train AI models.
We do not sell your data. We do not share your data with third parties for marketing purposes.
We use the following service providers to operate the app. Each receives only the minimum data necessary to perform their function:
| Service provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database and authentication infrastructure | All app data (stored securely in US infrastructure) |
| Resend | Transactional and reminder emails | Your email address and email content only |
| Anthropic (Claude) | AI-powered protocol generation, appointment brief, and Ask Lō features | Your health profile, symptoms, goals, medications, and wearable data (no name or email) |
| OpenAI | Generating embeddings for AI-powered protocol personalisation | Anonymised health context only |
| Trigger.dev | Background processing for training plan generation | Your training preferences and health profile |
| Oura | Wearable device integration (only if you connect your Oura Ring) | OAuth token exchange only; wearable data flows from Oura to Lō, not the reverse |
| Vercel | Application hosting and content delivery | Standard web request data such as IP address, handled as hosting infrastructure |
| Paddle | Payments, subscription billing and tax compliance, acting as merchant of record | Your name, email address, billing country and payment details. Payment card details are handled by Paddle and never reach Lō |
| Loops | Onboarding, reminder and lifecycle email | Your first name, email address, and whether you have completed certain actions in the app |
| hCaptcha | Bot protection on sign-up and sign-in | IP address and browser signals at the moment you authenticate |
| Sentry | Error monitoring so we can find and fix faults | Technical error data only. Personal data is scrubbed and IP addresses are not stored |
We may disclose your data if required by law, such as in response to a valid legal process. We will notify you of any such request where legally permitted to do so.
We take security seriously. Here is what we have implemented:
No system is completely secure. If you become aware of any security vulnerability in Lō, contact us immediately at support@joinlo.co.
You have the following rights regarding your personal data:
If you are located in California, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to opt out of its sale (we do not sell your data).
If you are in the United Kingdom, you have the following additional rights under UK GDPR, administered by the Information Commissioner's Office (ICO):
If you are in the European Union, you have rights under EU GDPR and may lodge a complaint with your local supervisory authority. If you are in Australia, you have rights under the Privacy Act 1988. Contact us at support@joinlo.co to exercise any of these rights.
Lō is operated by Lō Health LLC, a company incorporated in California, United States. If you access the app from outside the United States, your data will be transferred to and processed in the United States where our infrastructure is hosted (Supabase, running on Amazon Web Services).
United Kingdom users: Lō Health LLC is registered as a data controller with the UK Information Commissioner's Office (ICO). Registration number: ZC171013. The transfer of your personal data from the UK to the United States is made on the basis of the UK-US Data Bridge, which came into force on 12 October 2023 and provides appropriate safeguards for international data transfers. Your data is processed under UK GDPR with the ICO as the relevant supervisory authority.
European Union users: The transfer of your personal data from the EU to the United States is covered by standard contractual clauses and our service providers' compliance with the EU-US Data Privacy Framework. You have the right to lodge a complaint with your local data protection authority.
Australian users: We handle your personal information in accordance with the Australian Privacy Act 1988. Health information is treated as sensitive information and collected only with your consent.
We are committed to ensuring your data is handled with appropriate safeguards regardless of where you are located.
The data you enter into Lō includes health information, which is classified as special category personal data under UK GDPR and EU GDPR (Article 9). This includes menopause symptoms, medications, hormone therapy details, lab values, training data, and nutrition information.
We process this data solely on the basis of your explicit consent, given at the point of account creation. You may withdraw this consent at any time by deleting your account. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
We apply additional security measures to health data:
If you have questions about how we handle your health data, contact us at support@joinlo.co.
We retain your data for as long as your account is active. If you delete your account, we will delete all your personal data within 30 days, except where we are required to retain it by law.
Billing records are the main exception. Where you have paid for a subscription, tax and accounting law requires us and our payment provider to keep a record of the transaction, typically for six to seven years. These records contain your name, email address, billing country and what you paid. They do not contain any of your health data, and they are kept separately from your app data. Everything else is deleted on the timetable above.
Aggregated, anonymised data (such as general usage statistics with no identifying information) may be retained indefinitely for product improvement and research purposes.
Lō is designed for women navigating perimenopause, menopause, and post-menopause. We do not knowingly collect data from anyone under the age of 18. If you believe a minor has created an account, contact us at support@joinlo.co and we will delete it promptly.
Lō uses session cookies strictly necessary for authentication and app functionality. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not track you across other websites.
The app uses local storage on your device to save preferences such as notification dismissals. This data stays on your device and is not transmitted to our servers.
We may update this privacy policy from time to time. We will notify you of significant changes by email or via an in-app notification. The effective date at the top of this page will always reflect the most recent update.
Continued use of Lō after a policy update constitutes acceptance of the revised terms.
If you have any questions, concerns, or requests related to this privacy policy or your personal data, please contact us:
Lō Health LLC
Email: support@joinlo.co
Website: joinlo.co
We aim to respond to all privacy-related enquiries within 5 business days.