Consumer Health Data Privacy Policy
Last updated: 13 June 2026
This Consumer Health Data Privacy Policy explains how Yellow collects, uses, shares, and protects "consumer health data." It is a separate policy required by US state health-data laws, including the Washington My Health My Data Act, Nevada SB370, and Connecticut's health-data law. It applies in addition to our general Privacy Policy. If anything here conflicts with the general Privacy Policy on the subject of consumer health data, this policy controls.
In this policy, "we," "us," "Yellow," and "our" mean Adventure Works Solutions LLP, a limited liability partnership registered in India (LLPIN AAF-6980), with its registered office at 364 C, Pocket J and K, Dilshad Garden, Delhi 110095. "You" means a person who uses spotyellow.com or the Yellow apps.
What "consumer health data" means
Consumer health data is personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. For Yellow, this includes information that relates to perimenopause and menopause, the symptoms you track, and the treatments you record.
The consumer health data we collect
We collect only the data you give us or generate by using Yellow. Depending on which products you use, this can include:
- Symptom and check-in data: mood, sleep, energy, hot flushes, cycle changes, and other symptoms you log in Mood or elsewhere in the apps.
- Treatment data: HRT details you enter or paste into the HRT Decoder, doses, side effects, dose adjustments, and supplement information you record.
- Assessment data: answers you give in the Perimenopause Quiz or the directory check-in, and the life-stage result we calculate from them.
- Inferences: patterns we surface from your own data, such as a likely menopause stage or a symptom trend.
- Contact data linked to the above: the email address you use to join the waitlist or create an account, where it is connected to your health data.
We do not collect precise geolocation data, and we do not track your location near healthcare facilities.
Where the data comes from
We collect consumer health data directly from you when you enter it, and we generate inferences from the data you provide. We do not buy consumer health data from data brokers, and we do not collect it from third parties.
Why we collect it (purposes)
We use consumer health data only to:
- provide the Yellow products and features you ask for;
- show you your own patterns and summaries;
- prepare the review documents and summaries you choose to share with your clinician;
- maintain the security and integrity of the service;
- contact you about the product, where you have asked us to; and
- improve Yellow, using the smallest amount of data needed and de-identified data where possible.
We do not use consumer health data for advertising, and we do not use it to build advertising profiles.
How we share it, and with whom
We do not sell your consumer health data. We have never sold it, and we do not share it for cross-context behavioural advertising.
We share consumer health data only with the categories of service providers below, and only so they can run Yellow on our behalf under contracts that require them to protect it and use it for no other purpose:
- Cloud hosting and data storage providers (to store and run the service).
- Authentication and account sign-in providers (to let you log in securely).
- Email delivery providers (to send the messages you ask for).
- Product analytics providers, where used, restricted to de-identified or aggregated data and configured not to receive your health data.
We do not share consumer health data with insurers, employers, advertisers, advertising networks, or data brokers. We may disclose data if the law requires it, or to protect the safety of a person, and we will limit any such disclosure to what is necessary.
A current list of the specific service providers and any affiliates we share consumer health data with is available on request at privacy@spotyellow.com.
Your rights over your consumer health data
Wherever you live, you can ask us to:
- Confirm whether we are collecting, sharing, or selling your consumer health data.
- Access the consumer health data we hold about you.
- List the third parties and affiliates with whom we have shared it.
- Withdraw consent to our collection or sharing of it.
- Delete your consumer health data.
To make a request, email privacy@spotyellow.com or use our Privacy Rights Request page. We will confirm your request, verify your identity, and respond within 45 days. We can extend this once, by a further 45 days, where reasonably necessary, and we will tell you if we do. We will not discriminate against you for exercising these rights.
If we deny a request, we will explain why and tell you how to appeal. To appeal, reply to our decision or email privacy@spotyellow.com with "Appeal" in the subject line.
Consent
We ask for your opt-in consent before we collect consumer health data, and separately before we share it for any purpose beyond providing a feature you asked for. We will not collect or share consumer health data in a way that is inconsistent with this policy without first getting your consent. We do not, and will not, sell consumer health data; if that ever changed, we would obtain your separate written authorization first.
How long we keep it
We keep consumer health data for as long as your account is active and you continue to use the relevant product, and then for the shortest period needed to meet legal and security obligations, after which we delete or de-identify it. If you delete your account, we delete your consumer health data within 30 days, except where law requires us to keep limited records.
How we protect it
We transmit data over encrypted connections, restrict access to staff and providers who need it, and follow recognised security practices appropriate to the sensitivity of health data.
A note on HIPAA
Yellow is not a HIPAA-covered entity and is not a business associate of one. HIPAA does not apply to the data you give us. This policy and US state health-data laws are what govern that data.
Changes to this policy
If we make a material change to how we handle consumer health data, we will get your consent before applying it to data we already hold, and we will update the date at the top.
Contact and grievances
For any question or request about your consumer health data, contact:
- Email: privacy@spotyellow.com
- Grievance Officer (India): Chandni Menda, cm@spotyellow.com, 364 C, Pocket J and K, Dilshad Garden, Delhi 110095
We publish a link to this policy on our homepage, as the law requires.