Mito Health
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
No verified risks yet
AIRIN has not published verified findings for this record yet. The page shows the gap instead of guessing.
How to read this page: Overall risk rates what Mito Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 0 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 0 citationsLast captured 2026-07-20
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We retain personal information as long as necessary to fulfill the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and for security/fraud prevention. We may retain de-identified data without a time limit. Where feasible, we apply criteria such as data type/sensitivity, purpose, legal requirements, and operational nee...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“We use technical, administrative, and organizational measures to protect Consumer Health Data from unauthorized access, disclosure, or misuse. We retain your data only as long as necessary to fulfill the purposes described in this Notice or as required by law.”Open source citation
The clause permits sale of personal data or information.
“Opt-out of sale/share & targeted advertising. Where required, we provide a clear “Do Not Sell or Share My Personal Information” link and a universal opt-out mechanism for targeted advertising. We honor Global Privacy Control (GPC) and similar browser signals as opt-out requests. Authorized agents & verification. You may designate an authorized agent to submit a request on your behalf. We may require pr...”Open source citation
The clause permits sale of personal data or information.
““ Personal information ” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “ Sensitive personal information ” includes data such as precise geolocation, health/genetic data, and similar categories defined by law. “ Consumer health data (CHD) ” is defined by applicable state law and may include perso...”Open source citation
The clause permits sale of personal data or information.
“We may share your Consumer Health Data with: Service providers & vendors who support our operations (e.g., cloud hosting, analytics, customer support). Healthcare partners (if applicable) who provide services you request. Legal or regulatory authorities when required to comply with applicable law, regulation, or court order. Business transfers if we undergo a merger, acquisition, or sale of assets. We do not sell ...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | data retention | conditional | MEDIUM | 3 |
| All applicable tiers | privacy data use | worsens | HIGH | 4 |
| Team / Business | privacy data use | conditional | MEDIUM | 1 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on data retention
“This Privacy Policy describes how MITO HEALTH INC. and its affiliates (collectively, “Mito,” “we,” “us,” or “our”) collect, use, disclose, retain, and protect personal information through our websites, mobile applications, and online services that link to this Privacy Policy (collectively, the “Services”), as well as marketing activities, events, and other activities described here. In some cases, we may provide additional or “just-in-time” notices or supplemental policies for specific products or features. If you do not agree with this Privacy Policy, please do not use the Services.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We use personal information to: provide, operate, maintain, secure, and improve the Services; personalize the Services and communications; create, manage, and support accounts; authenticate users; and provide customer support; process orders and payments; fulfill and track services; coordinate with Providers/labs; verify eligibility and geographic availability; prevent fraud, abuse, and security incidents; conduct research, testing, quality assurance, and product development; send service-related announcements, security alerts, and administrative messages; market our Services (you may opt out of marketing communications); and comply with laws, enforce terms and policies, and protect rights, safety, and property. De-identified/aggregated data. We may de-identify and/or aggregate personal information and use or disclose it for any lawful purpose, and we will not attempt to re-identify de-identified data except as required by law. Research. We may use de-identified or aggregated information for internal research, quality assurance, and product development. We disclose identifiable information to external research partners only with your consent or under appropriate legal/ethical safeguards. De-identification pledge. For de-identified information, we maintain it in de-identified form, do not attempt to re-identify it, and require recipients to do the same.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We may disclose personal information to: Providers & labs: to facilitate services you request (e.g., test ordering, sample collection, results delivery). Providers/labs set their own policies and may have their own notices. Service providers & contractors: hosting, EHR integrations, analytics, customer support, communications, security, payment processing, fulfillment, and similar. Payment processors: (e.g., Stripe) process payments directly and use your data per their privacy policies. Affiliates & business partners: for operations, research, and co-marketing (with lawful bases and choices provided). Advertising/analytics partners: to enable measurement and interest-based advertising (exclude health/genetic data from ad targeting; honor applicable laws). Research partners: for approved research under appropriate legal/ethical safeguards. Parties to a corporate transaction: actual/prospective buyers, investors, and their advisors. Authorities & others: to comply with law; protect rights, privacy, safety, or property; detect/prevent fraud, security, or technical issues; or enforce terms. Parties you authorize: other third parties where you instruct us to disclose. Advertising and analytics boundaries. We do not use health or genetic data for targeted advertising. We contractually prohibit service providers and advertising/analytics partners from using any health or genetic data for their own independent purposes, and we limit what identifiers we share to what is necessary for measurement and brand-level reach, subject to your choices. We may also share de-identified/aggregated data that cannot reasonably be used to identify you.”Open timeline citation
Latest stance: sale or sell on privacy data use
“Opt-out of sale/share & targeted advertising. Where required, we provide a clear “Do Not Sell or Share My Personal Information” link and a universal opt-out mechanism for targeted advertising. We honor Global Privacy Control (GPC) and similar browser signals as opt-out requests. Authorized agents & verification. You may designate an authorized agent to submit a request on your behalf. We may require proof of the agent’s authority and verification of your identity. Appeals. If we deny your request, you may appeal by emailing help@mitohealth.com with “Appeal” in the subject line. We will respond within the timeframe required by applicable law. Sensitive personal information. Where state law provides a “Limit the Use of My Sensitive Personal Information” right, we will provide a means to exercise it and will honor your request as required by law.”Open timeline citation
Latest stance: sale or sell on privacy data use
““ Personal information ” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “ Sensitive personal information ” includes data such as precise geolocation, health/genetic data, and similar categories defined by law. “ Consumer health data (CHD) ” is defined by applicable state law and may include personal information linked or reasonably linkable to an individual’s health. “ Sell ” and “ Share ” have the meanings given in applicable state privacy laws and generally refer to disclosing personal information to third parties for monetary or other valuable consideration (sell) or for cross-context behavioral advertising (share). “ Consumer Health Data (CHD) ” means personal information linked or reasonably linkable to an individual’s past, present, or future physical or mental health status as defined by applicable state law.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
““ Personal information ” means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household. “ Sensitive personal information ” includes data such as precise geolocation, health/genetic data, and similar categories defined by law. “ Consumer health data (CHD) ” is defined by applicable state law and may include personal information linked or reasonably linkable to an individual’s health. “ Sell ” and “ Share ” have the meanings given in applicable state privacy laws and generally refer to disclosing personal information to third parties for monetary or other valuable consideration (sell) or for cross-context behavioral advertising (share). “ Consumer Health Data (CHD) ” means personal information linked or reasonably linkable to an individual’s past, present, or future physical or mental health status as defined by applicable state law.”Open timeline citation
Latest stance: sale or sell on subprocessors data sharing
“We may share your Consumer Health Data with: Service providers & vendors who support our operations (e.g., cloud hosting, analytics, customer support). Healthcare partners (if applicable) who provide services you request. Legal or regulatory authorities when required to comply with applicable law, regulation, or court order. Business transfers if we undergo a merger, acquisition, or sale of assets. We do not sell your Consumer Health Data without your explicit authorization.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We may share your Consumer Health Data with: Service providers & vendors who support our operations (e.g., cloud hosting, analytics, customer support). Healthcare partners (if applicable) who provide services you request. Legal or regulatory authorities when required to comply with applicable law, regulation, or court order. Business transfers if we undergo a merger, acquisition, or sale of assets. We do not sell your Consumer Health Data without your explicit authorization.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
23 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Mito Health's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Mito Health's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Mito Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.