Legal
Privacy Policy
Last updated: June 2026 (draft, pending legal review)
Draft pending final legal review. This page is being finalized with counsel; bracketed items (for example, [LIKE THIS]) are placeholders not yet set, and this version is not yet in effect.
This Privacy Policy describes how Ryo Health, Inc. (“Ryo”) handles information from people who use the Ryo Health website and services (the “Services”). The Services are intended for users in the United States; your information is processed and stored in the United States.
Ryo is not a medical provider
Ryo connects you with an independent medical group (the “Medical Group”) and licensed pharmacies (the “Pharmacy”) and is not responsible for their independent use or disclosure of your information.
HIPAA posture
Ryo Health, Inc. is not a HIPAA covered entity. It acts as a business associate of the Medical Group and Pharmacy and protects Protected Health Information (PHI) accordingly. The Medical Group and Pharmacy are the covered entities; their Notices of Privacy Practices govern your PHI and are linked here: [NPP LINKS]. Information you give Ryo that is not PHI (for example, account registration data) is handled under this Policy.
What we collect
- Registration data: name, contact details, date of birth, and an image of your government ID.
- Health Information you submit for your consultation.
- Purchase data — card details go directly to Stripe; Ryo does not store full card numbers.
- Device, usage, and analytics data.
How we use information
To operate the Services, route your consultation, coordinate dispensing, support you, communicate with you, and improve the Services. Health Information is used only as needed to provide the care you request, except where de-identified as permitted by law.
We do not sell your personal information
Ryo does not sell your personal information. [Confirm with counsel, including under the consumer-health-data laws below; if any “sharing” for advertising occurs, it is disclosed and you are offered an opt-out.]
Sharing
We share information with the Medical Group, the Pharmacy, and vetted service providers under contract; for legal and safety reasons; and in a business transfer. De-identified or aggregate data may be shared without restriction.
Your privacy rights
Depending on where you live, you may have rights to access, delete, or correct your information and to be free from discrimination for exercising them (for example, under the California Consumer Privacy Act). [Counsel to enumerate the other state consumer-privacy and consumer-health-data laws Ryo is subject to, which are strict for weight-management data, plus Nevada sale opt-out and any EU/GDPR coverage.] We do not currently respond to browser Do-Not-Track signals. The Services are not intended for and may not be used by anyone under 18.
Cookies and analytics
We use cookies in these categories: strictly necessary, performance, functionality, and advertising. A consent manager lets you accept or reject non-essential cookies. Advertising pixels never receive PHI; our advertising pixel fires a non-PHI custom event, never a purchase event.
Data security
We use encryption in transit and at rest, access controls, and vendor agreements to protect your information. [Match to Ryo’s actual security stack with the Medical Group and Pharmacy; state only what is true.]
Retention
We keep information as long as needed to provide the Services and as required by law. Medical records are retained by the Medical Group and Pharmacy under applicable state law.
Contact and data requests
Contact [privacy@ryohealth.com] or [SUPPORT PHONE] to ask a question or make a privacy request.