Consumer Health Data Privacy Policy
Last updated: 31 July 2026
This Consumer Health Data Privacy Policy explains how Yellow collects, uses, shares, and protects "consumer health data." It is a separate policy required by US state health-data laws, including the Washington My Health My Data Act, Nevada SB370, and Connecticut's health-data law. It applies in addition to our general Privacy Policy. If anything here conflicts with the general Privacy Policy on the subject of consumer health data, this policy controls.
In this policy, "we," "us," "Yellow," and "our" mean Adventure Works Solutions LLP, a limited liability partnership registered in India (LLPIN AAF-6980), with its registered office at 364 C, Pocket J and K, Dilshad Garden, Delhi 110095. "You" means a person who uses spotyellow.com or the Yellow apps.
What "consumer health data" means
Consumer health data is personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. For Yellow, this includes information that relates to perimenopause and menopause, the symptoms you track, and the treatments you record.
The consumer health data we collect
We collect only the data you give us or generate by using Yellow. Depending on which products you use, this can include:
- Symptom and check-in data: mood, sleep, energy, hot flushes, cycle changes, and other symptoms you log in Mood or elsewhere in the apps.
- Treatment data: HRT details you enter or paste into the HRT Decoder, doses, side effects, dose adjustments, and supplement information you record.
- Assessment data: answers you give in the Perimenopause Quiz or the directory check-in, and the life-stage result we calculate from them.
- Apple Health (HealthKit) data: if you choose to connect Apple Health, readings such as sleep, heart rate, and steps, read from your device with your permission and used only to show your own trends. Access is read-only, and you can revoke it at any time in your device settings. We never use Apple Health data for advertising, and we never disclose it to third parties.
- Inferences: patterns we surface from your own data, such as a likely menopause stage or a symptom trend.
- Care Conversation Toolkit answers: what you write into Help Me Be Heard, Since My Last Appointment, After the Appointment, or My Care Handover Pack. This can include symptoms in your own words, medicines and doses as you have entered them, allergies, procedures and health history, practitioners you see, and what you remember from an appointment. We treat all of it as consumer health data. Read the section below on how the toolkit differs, because in most cases none of this reaches us at all.
- Contact data linked to the above: the email address you use to join the waitlist or create an account, where it is connected to your health data.
We do not collect precise geolocation data, and we do not track your location near healthcare facilities.
The Care Conversation Toolkit works differently
These four tools are built so that your answers stay with you. They are the one part of Yellow where, unless you choose otherwise, we never see what you wrote.
- Nothing is sent while you write. Your answers live in your browser. The draft is kept in your browser's local storage so you can return to it, expires by itself after 30 days, and "Clear my information" deletes it straight away. You can read, print or save your document without ever sending us anything.
- Emailing yourself a copy is the only thing that sends it. If you use it, your answers travel to our server, are used in memory to build that document, and go out in the email. We do not write them to a database, and we do not keep the document.
- What remains afterwards is a delivery record only: your email address, which tool it was, timestamps, whether our email provider accepted the message, its message identifier, and any failure reason. Alongside it we store a one-way cryptographic hash of your submission. It lets us spot a duplicate send and cannot be reversed into anything you wrote.
- We do not interpret any of it. Yellow organises what you enter into headings and sections. Unlike the quiz or the apps, the toolkit produces no inferences, no stage, no score, and no assessment.
- Email is not private. Anyone with access to your inbox can read a document sent there. We tell you this before you enter an address.
- Marketing is separate. Asking for a document never adds you to a marketing list. That is its own optional, unticked choice.
Where the data comes from
We collect consumer health data directly from you when you enter it, and we generate inferences from the data you provide. If you connect Apple Health, we also read the Apple Health categories listed above from your device, with your permission. We do not buy consumer health data from data brokers, and we do not collect it from third parties.
Why we collect it (purposes)
We use consumer health data only to:
- provide the Yellow products and features you ask for;
- show you your own patterns and summaries;
- prepare the review documents and summaries you choose to share with your clinician;
- maintain the security and integrity of the service;
- contact you about the product, where you have asked us to; and
- improve Yellow, using the smallest amount of data needed and de-identified data where possible.
We do not use consumer health data for advertising, and we do not use it to build advertising profiles.
How we share it, and with whom
We do not sell your consumer health data. We have never sold it, and we do not share it for cross-context behavioural advertising.
We share consumer health data only with the categories of service providers below, and only so they can run Yellow on our behalf under contracts that require them to protect it and use it for no other purpose:
- Cloud hosting and data storage providers (to store and run the service).
- Authentication and account sign-in providers (to let you log in securely).
- Email delivery providers (to send the messages you ask for).
- Product analytics providers, where used, restricted to de-identified or aggregated data and configured not to receive your health data.
We do not share consumer health data with insurers, employers, advertisers, advertising networks, or data brokers. We may disclose data if the law requires it, or to protect the safety of a person, and we will limit any such disclosure to what is necessary.
A current list of the specific service providers and any affiliates we share consumer health data with is available on request at [email protected].
Your rights over your consumer health data
Wherever you live, you can ask us to:
- Confirm whether we are collecting, sharing, or selling your consumer health data.
- Access the consumer health data we hold about you.
- List the third parties and affiliates with whom we have shared it.
- Withdraw consent to our collection or sharing of it.
- Delete your consumer health data.
To make a request, email [email protected] or use our Privacy Rights Request page. We will confirm your request, verify your identity, and respond within 45 days. We can extend this once, by a further 45 days, where reasonably necessary, and we will tell you if we do. We will not discriminate against you for exercising these rights.
If we deny a request, we will explain why and tell you how to appeal. To appeal, reply to our decision or email [email protected] with "Appeal" in the subject line.
Consent
We ask for your opt-in consent before we collect consumer health data, and separately before we share it for any purpose beyond providing a feature you asked for. We will not collect or share consumer health data in a way that is inconsistent with this policy without first getting your consent. We do not, and will not, sell consumer health data; if that ever changed, we would obtain your separate written authorization first.
How long we keep it
We keep consumer health data for as long as your account is active and you continue to use the relevant product, and then for the shortest period needed to meet legal and security obligations, after which we delete or de-identify it. If you delete your account, we delete your consumer health data within 30 days, except where law requires us to keep limited records.
How we protect it
We transmit data over encrypted connections, restrict access to staff and providers who need it, and follow recognised security practices appropriate to the sensitivity of health data.
A note on HIPAA
Yellow is not a HIPAA-covered entity and is not a business associate of one. HIPAA does not apply to the data you give us. This policy and US state health-data laws are what govern that data.
Changes to this policy
If we make a material change to how we handle consumer health data, we will get your consent before applying it to data we already hold, and we will update the date at the top.
Contact and grievances
For any question or request about your consumer health data, contact:
- Email: [email protected]
- Grievance Officer (India): Chandni Menda, [email protected], 364 C, Pocket J and K, Dilshad Garden, Delhi 110095
We publish a link to this policy on our homepage, as the law requires.