Skip to main content
AIRIN
PricingSign in

Mito Health policy evolution

Before/after stance changes across captured policy versions, with exact citations. If no before/after delta is available yet, AIRIN shows the latest citation-backed stance events instead.

Diffs
0
Improved
0
Worsened
0
Changed
0
No before/after stance delta is available for this filter yet. Latest citation-backed stance events are shown below.
Jul 20, 2026retentionmedium

data sharing

Latest stance: third party or vendor sharing

This Privacy Policy describes how MITO HEALTH INC. and its affiliates (collectively, “Mito,” “we,” “us,” or “our”) collect, use, disclose, retain, and protect personal information through our websites, mobile applications, and online services that link to this Privacy Policy (collectively, the “Services”), as well as marketing activities, events, and other activities described here. In some cases, we may provide additional or “just-in-time” notices or supplemental policies for specific products or features. If you do not agree with this Privacy Policy, please do not use the Services.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

We use personal information to: provide, operate, maintain, secure, and improve the Services; personalize the Services and communications; create, manage, and support accounts; authenticate users; and provide customer support; process orders and payments; fulfill and track services; coordinate with Providers/labs; verify eligibility and geographic availability; prevent fraud, abuse, and security incidents; conduct research, testing, quality assurance, and product development; send service-related announcements, security alerts, and administrative messages; market our Services (you may opt out of marketing communications); and comply with laws, enforce terms and policies, and protect rights, safety, and property. De-identified/aggregated data. We may de-identify and/or aggregate personal information and use or disclose it for any lawful purpose, and we will not attempt to re-identify de-identified data except as required by law. Research. We may use de-identified or aggregated information for internal research, quality assurance, and product development. We disclose identifiable information to external research partners only with your consent or under appropriate legal/ethical safeguards. De-identification pledge. For de-identified information, we maintain it in de-identified form, do not attempt to re-identify it, and require recipients to do the same.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

We may disclose personal information to: Providers & labs: to facilitate services you request (e.g., test ordering, sample collection, results delivery). Providers/labs set their own policies and may have their own notices. Service providers & contractors: hosting, EHR integrations, analytics, customer support, communications, security, payment processing, fulfillment, and similar. Payment processors: (e.g., Stripe) process payments directly and use your data per their privacy policies. Affiliates & business partners: for operations, research, and co-marketing (with lawful bases and choices provided). Advertising/analytics partners: to enable measurement and interest-based advertising (exclude health/genetic data from ad targeting; honor applicable laws). Research partners: for approved research under appropriate legal/ethical safeguards. Parties to a corporate transaction: actual/prospective buyers, investors, and their advisors. Authorities & others: to comply with law; protect rights, privacy, safety, or property; detect/prevent fraud, security, or technical issues; or enforce terms. Parties you authorize: other third parties where you instruct us to disclose. Advertising and analytics boundaries. We do not use health or genetic data for targeted advertising. We contractually prohibit service providers and advertising/analytics partners from using any health or genetic data for their own independent purposes, and we limit what identifiers we share to what is necessary for measurement and brand-level reach, subject to your choices. We may also share de-identified/aggregated data that cannot reasonably be used to identify you.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

Opt-out of sale/share & targeted advertising. Where required, we provide a clear “Do Not Sell or Share My Personal Information” link and a universal opt-out mechanism for targeted advertising. We honor Global Privacy Control (GPC) and similar browser signals as opt-out requests. Authorized agents & verification. You may designate an authorized agent to submit a request on your behalf. We may require proof of the agent’s authority and verification of your identity. Appeals. If we deny your request, you may appeal by emailing help@mitohealth.com with “Appeal” in the subject line. We will respond within the timeframe required by applicable law. Sensitive personal information. Where state law provides a “Limit the Use of My Sensitive Personal Information” right, we will provide a means to exercise it and will honor your request as required by law.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

“ Personal information ” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “ Sensitive personal information ” includes data such as precise geolocation, health/genetic data, and similar categories defined by law. “ Consumer health data (CHD) ” is defined by applicable state law and may include personal information linked or reasonably linkable to an individual’s health. “ Sell ” and “ Share ” have the meanings given in applicable state privacy laws and generally refer to disclosing personal information to third parties for monetary or other valuable consideration (sell) or for cross-context behavioral advertising (share). “ Consumer Health Data (CHD) ” means personal information linked or reasonably linkable to an individual’s past, present, or future physical or mental health status as defined by applicable state law.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

“ Personal information ” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “ Sensitive personal information ” includes data such as precise geolocation, health/genetic data, and similar categories defined by law. “ Consumer health data (CHD) ” is defined by applicable state law and may include personal information linked or reasonably linkable to an individual’s health. “ Sell ” and “ Share ” have the meanings given in applicable state privacy laws and generally refer to disclosing personal information to third parties for monetary or other valuable consideration (sell) or for cross-context behavioral advertising (share). “ Consumer Health Data (CHD) ” means personal information linked or reasonably linkable to an individual’s past, present, or future physical or mental health status as defined by applicable state law.
Open citation
Jul 20, 2026subprocessors / sharinghigh

data sharing

Latest stance: sale or sell

We may share your Consumer Health Data with: Service providers & vendors who support our operations (e.g., cloud hosting, analytics, customer support). Healthcare partners (if applicable) who provide services you request. Legal or regulatory authorities when required to comply with applicable law, regulation, or court order. Business transfers if we undergo a merger, acquisition, or sale of assets. We do not sell your Consumer Health Data without your explicit authorization.
Open citation
Jul 20, 2026subprocessors / sharingmedium

data sharing

Latest stance: third party or vendor sharing

We may share your Consumer Health Data with: Service providers & vendors who support our operations (e.g., cloud hosting, analytics, customer support). Healthcare partners (if applicable) who provide services you request. Legal or regulatory authorities when required to comply with applicable law, regulation, or court order. Business transfers if we undergo a merger, acquisition, or sale of assets. We do not sell your Consumer Health Data without your explicit authorization.
Open citation
Jul 20, 2026retentionmedium

retention

Latest stance: indefinite or necessity based

We retain personal information as long as necessary to fulfill the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and for security/fraud prevention. We may retain de-identified data without a time limit. Where feasible, we apply criteria such as data type/sensitivity, purpose, legal requirements, and operational needs to determine retention. Illustrative retention periods: Account & profile data: life of account + up to 3 years. Health/biomarker data: life of account + up to 7 years (or longer if required by law). Transactions: 7 years (tax/audit). Support chats/calls: up to 3 years. Actual periods may vary based on legal, security, and operational needs.
Open citation
Jul 20, 2026retentionmedium

retention

Latest stance: indefinite or necessity based

We use technical, administrative, and organizational measures to protect Consumer Health Data from unauthorized access, disclosure, or misuse. We retain your data only as long as necessary to fulfill the purposes described in this Notice or as required by law.
Open citation

Generated from live stance events. Informational only, not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.