Privacy policy
Last Updated: 09/03/2026
This Privacy Policy explains how Prelude Health Pte. Ltd. (“Prelude Health”, “Hormony®”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects your information when you:
-
Use the Hormony® Insights App
-
Visit findhormony.com and affiliated websites
-
Make purchases through our e-commerce store
-
Interact with our AI-powered wellness features
-
Participate in any programs, surveys, or communications with us
Hormony® is designed and marketed as a general wellness product that helps users observe patterns and receive educational insights.
It is not intended for diagnosis, treatment, or medical decision-making.
Regulatory requirements differ by country; availability and intended use may vary.
We comply with global privacy laws, including:
-
GDPR (EU/UK)
-
HIPAA-inspired safeguards (U.S.)
-
PDPA (Singapore)
-
APPI (Japan)
-
Hong Kong PDPO
-
Mexico Federal Data Protection Law
-
California Consumer Privacy Act (CCPA/CPRA)
-
Other applicable national and regional privacy regulations
1. WHO WE ARE
Prelude Health Pte. Ltd.
32 Pekin Street, #05-01
Singapore (048762)
WhatsApp
Prelude Health acts as the Data Controller for personal data collected through our Services.
2. DEFINITIONS
-
“Personal Data”: Any information that identifies or relates to an identifiable person.
-
“Wellness Data”: Self-reported symptom, lifestyle, and cycle-related inputs used for non-medical wellness insights.
-
“Biomarker Data”: Images of test strips, cortisol readings, timestamps, and related analytical patterns.
-
“AI Interaction Data”: Text inputs, prompts, messages, and related analytics generated through AI features.
-
“Processing”: Any operation performed on Personal Data (collection, storage, analysis, deletion).
-
“Sensitive Personal Information”: Data defined as sensitive under applicable laws (e.g., biomarker-like data, health-related data, precise geolocation, etc.).
-
“Controller” / “Processor”: Roles as defined by GDPR and other privacy laws.
3. INFORMATION WE COLLECT
3.1 Personal Information
Collected when you register, purchase, or contact us:
-
Name
-
Email
-
Phone number
-
Mailing & billing address
-
Country & language
-
Login credentials
3.2 SMS Communications
Prelude Health Pte. Ltd. (“Prelude Health”, “Hormony®”, “we”, “our”, or “us”) may send SMS text messages to users who have explicitly opted in to receive communications through our website, mobile application, customer support channels, or other consent forms.
SMS messages may include:
• customer support responses
• service notifications
• order confirmations and shipping updates
• appointment reminders
• account notifications
• product updates or educational wellness information
• optional marketing or promotional messages where separate consent is provided
Message frequency may vary depending on your interaction with our services.
Message and data rates may apply according to your mobile carrier plan.
Users may opt out of SMS communications at any time by replying STOP to any message received from us.
For assistance, users may reply HELP.
Users may also contact us to request removal from SMS communications.
SMS Consent
Users provide consent to receive SMS messages by entering their phone number and selecting an explicit SMS opt-in checkbox on our website forms, application interfaces, or other registration pages where phone numbers are collected.
SMS consent is obtained separately from acceptance of our Privacy Policy or Terms of Service and is not a condition of purchase.
Users may choose to opt in to:
• service-related or transactional messages
• optional marketing or promotional messages
Users may withdraw consent at any time.
Use and Protection of Mobile Information
Prelude Health does not sell, rent, or share mobile phone numbers or SMS consent data with third parties for marketing purposes.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Information sharing to subcontractors in support services, such as customer service providers, messaging infrastructure providers, and technical service partners, is permitted only to support our communications services.
All other use case categories exclude text messaging originator opt-in data and consent. This information will not be shared with any third parties.
3.3 Wellness & Self-Reported Data
Provided through app inputs:
-
Symptom logs
-
Mood, sleep, and stress data
-
Lifestyle and daily habits
-
Cycle and period tracking
-
Questionnaire responses
Used exclusively for wellness insights, not diagnosis.
3.4 Biomarker & Test Data
Collected using Hormony® test kits:
-
Test strip images
-
Cortisol concentration estimations
-
Scan confidence scores
-
Timestamps and patterns
-
Trend analyses
All insights are educational only.
3.5 Technical Data
Automatically collected:
-
IP address
-
Device model & OS
-
App version
-
Browser type
-
Cookies
-
Pixels, web beacons, SDKs, and similar tracking technologies
-
Crash logs, diagnostics, and performance analytics
3.6 E-commerce & Transaction Data
Collected for online purchases:
-
Order details
-
Shipping and delivery information
-
Payment confirmations
-
Refunds and replacements
-
Fraud checks
We do not store full payment card data.
3.7 AI Interaction Data
Collected when you use AI features:
-
Text inputs
-
Questions
-
Prompts
-
Interpretation context
-
Interaction metadata
AI outputs are exclusively wellness-oriented.
3.8 Customer Support Data
-
Emails, messages, attachments
-
Photos of test strips or packaging
-
Issue descriptions
-
Call recordings (where permitted by law)
3.9 Information from Third Parties
We may obtain data from:
-
Shopify (platform provider)
-
Payment processors
-
Analytics providers
-
Email/SMS platforms
-
Advertising partners
-
Social media integrations
-
Logistics and shipping providers
Treated in accordance with this Privacy Policy.
4. HOW WE USE YOUR DATA
4.1 Provide App & Wellness Services
-
Generate wellness insights
-
Display patterns and trends
-
Support test scanning
-
Provide educational content
-
Maintain functionality
4.2 Process Orders & Deliver Products
-
Process payments
-
Confirm purchases
-
Manage shipping
-
Handle returns and replacements
4.3 Communication
-
App updates
-
Customer support
-
Feedback and surveys
-
Marketing (with consent)
4.4 Improve & Develop Services
-
Enhance app performance
-
Improve AI model accuracy
-
Conduct anonymized analytics
-
Support research and development
4.5 Safety, Compliance & Quality
-
Fraud detection
-
Regulatory compliance
-
ISO 13485–aligned quality processes
-
Legal obligations
-
Data retention requirements
5. LAWFUL BASES FOR PROCESSING (GDPR)
|
Data Category |
Legal Basis |
|
Account & Profile Data |
Contract |
|
Wellness Data |
Consent |
|
Biomarker/Test Data |
Explicit consent (EU) / consent (global) |
|
AI Interaction Data |
Legitimate interest + consent |
|
E-commerce Data |
Contract + Legal obligation |
|
Marketing |
Consent |
|
Analytics & Performance |
Legitimate interest |
6. SHARING YOUR DATA
We never sell your data for profit.
We may share personal data with:
6.1 Service Providers
Including:
-
Cloud hosting
-
AI infrastructure
-
Analytics platforms
-
Customer support tools
-
Payment processors
-
Shopify
-
Logistics partners
Bound by strict confidentiality.
6.2 Research Partners (Aggregated & Anonymous)
Used for:
-
Product improvement
-
Academic collaboration
-
R&D
-
Public health insights
Never includes identifiable information without consent.
6.3 Legal & Regulatory Authorities
Only when:
-
Required by law
-
Necessary for safety or quality investigations
6.4 Business Transactions
If we undergo:
-
Acquisition
-
Merger
-
Financing
-
Restructuring
Data may transfer under confidentiality terms.
6.5 Sale or Sharing for Targeted Advertising (US Law)
Under U.S. state laws:
-
“Sale” refers to certain data exchanges for value
-
“Sharing” refers to cross-context behavioral advertising
We may share:
-
Identifiers (email, device ID)
-
Commercial data
-
Usage data
With advertising partners, only with your consent.
You may opt out at any time (details in “Your Rights”).
7. GLOBAL PRIVACY CONTROL (GPC)
Our website recognizes and honors the Global Privacy Control signal as a valid request to opt out of “sale” or “sharing” under U.S. law.
8. INTERNATIONAL TRANSFERS
We transfer data to:
-
Singapore
-
EU/UK
-
U.S.
-
Mexico
-
Japan
-
Hong Kong
-
Other locations where we operate
We use:
-
Standard Contractual Clauses (SCCs)
-
UK Addendum
-
PDPA-aligned safeguards
-
Other approved legal mechanisms
9. DATA SECURITY
We use:
-
Encryption (in transit & at rest)
-
Access control
-
Network security layers
-
Secure development practices
-
Routine audits & penetration tests
-
Privacy-by-design principles
No system is perfectly secure.
10. DATA RETENTION
We retain data according to:
-
Legal obligations
-
Quality system requirements
-
Customer support timelines
Typical retention:
-
Account data: active period
-
Wellness/Biomarker data: 36 months (user configurable)
-
E-commerce data: 7 years
-
Support data: 24 months
-
AI interactions: up to 12 months
You may request deletion unless law requires retention.
11. YOUR RIGHTS
Depending on your jurisdiction, you may have:
-
Access / Know
-
Correction
-
Deletion
-
Data portability
-
Restriction
-
Objection
-
Opt-out of sale/sharing/targeted advertising (U.S.)
-
Withdraw consent
-
Appeal (U.S.)
You may also:
-
Designate an authorized agent (California)
-
Submit GPC signals
To exercise rights:
privacy@findhormony.com
We will not discriminate against you for exercising your rights.
12. COOKIES & TRACKING
We use:
-
Essential cookies
-
Analytics cookies
-
Functional cookies
-
Performance cookies
-
Pixels
-
SDKs
-
Web beacons
You may manage cookie preferences through your browser.
13. PUBLIC CONTENT
If you submit user-generated content (UGC):
-
Reviews
-
Community posts
-
Public comments
It may become publicly visible.
We cannot guarantee how third parties use this content.
14. THIRD-PARTY LINKS
Our Site may link to third-party sites.
We are not responsible for their privacy practices or content.
15. CHILDREN’S PRIVACY
Hormony® is intended for adults 18+.
We do not knowingly collect data from minors.
Accounts created by minors will be deleted upon discovery.
16. E-COMMERCE & RETURNS
-
Opened biological test kits cannot be returned.
-
Refund eligibility varies by region.
-
Shipping partners receive delivery info only.
-
Fraud checks may be performed.
-
“Cooling-off” rights apply only where legally required.
17. AI SAFETY & LIMITATIONS
-
AI outputs are not medical advice.
-
No legal/medical decisions are automated.
-
AI uses only the data you provide.
-
Models undergo safety/fairness checks.
-
Only anonymized data is used for model improvement.
18. SECURITY INCIDENTS
If a breach may affect your rights:
-
We will notify you promptly
-
We will notify regulators when required
-
We will take corrective measures
19. YOUR RESPONSIBILITIES
To enhance data security:
-
Use strong, unique passwords
-
Keep your device updated
-
Do not share login credentials
-
Report unauthorized access immediately
20. CHANGES TO THIS POLICY
We may update this Policy to reflect:
-
Legal changes
-
Product updates
-
Regulatory requirements
-
New features
We will:
-
Update the “Last Updated” date
-
Publish updates on the website
-
Notify users if required by law
21. CONTACT US
Prelude Health Pte. Ltd.
32 Pekin Street, #05-01
Singapore (048762)
WhatsApp
Email: hello@findhormony.com
Support: support@findhormony.com
Your Regional Privacy Rights
Depending on your location, you may have additional rights regarding your personal data. To make a request, email us at hello@findhormony.com and we will respond within the timeframe required by applicable law.
- Singapore (PDPA): You have the right to access and correct your personal data, and to withdraw consent to its collection, use, or disclosure.
- Hong Kong (PDPO): You have the right to access and correct your personal data, and to opt out of direct marketing at any time.
- Japan (APPI): You have the right to request disclosure, correction, or suspension of use of your personal data. We obtain your consent before providing your personal data to third parties, except where permitted by law.
- Mexico (LFPDPPP): You have ARCO rights – Access, Rectification, Cancellation, and Opposition – and the right to withdraw consent. Our Privacy Notice (Aviso de Privacidad) is available on request.
- European Union & United Kingdom (GDPR): You have the right to access, rectify, erase, restrict, or port your personal data, to object to processing, and to lodge a complaint with your local data protection authority.
