Effective Date: October 7, 2025
Hormonly Health Technologies (“Company,” “Tolu,” “we,” “our,” or “us”) values your privacy and is committed to protecting your personal and health information. This Privacy Policy explains how we collect, use, protect, and share your data when you access our mobile application, website, or affiliated platforms (collectively, the “Services”).
Tolu is currently undergoing a HIPAA Critical Controls Risk Assessment to align with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and related healthcare data protection standards. This work demonstrates our proactive commitment to building and maintaining a secure, compliant environment for all users.
This Privacy Policy applies to all users of our Services. It covers:
This policy does not cover third-party websites, links, or external services. Their privacy practices are governed by their own policies.
a. Information You Provide
b. Information Collected Automatically
We use your information to:
We will never use your Protected Health Information (PHI) for advertising or marketing purposes without your explicit written authorization, in accordance with HIPAA.
We do not sell your personal or health information. We may share limited data under these conditions:
Tolu is currently conducting a HIPAA Critical Controls Assessment led by an external security consultant to evaluate key safeguards, including:
While Tolu is not yet a covered entity or certified HIPAA-compliant organization, we are actively implementing the administrative, technical, and physical safeguards required by HIPAA’s Security Rule.
You have the right to:
For HIPAA-related inquiries or requests, please contact:
📧 support@tolu.health
Subject line: “HIPAA-related request”
Your information is protected using industry-standard encryption, access controls, and secure cloud hosting through AWS, a HIPAA-eligible service provider.
Tolu also undergoes regular security audits, including the current Critical Controls Risk Assessment, to identify and mitigate risks. While no system is completely immune to breaches, we continuously update our safeguards to protect your data.
We retain your data only as long as needed to provide the Services and fulfill legal or regulatory requirements. You may request deletion of your information, subject to HIPAA record retention rules and legitimate business needs.
Tolu uses cookies and related tools to improve user experience and system analytics. You can adjust your cookie preferences through your browser settings.
Tolu’s Services are not intended for children under 13 years of age. If we discover that a child’s data has been collected, we will promptly delete it.
By using our Services from outside the United States, you consent to the transfer, processing, and storage of your information within the United States under applicable U.S. privacy laws.
You may:
We may update this Privacy Policy from time to time. Any material updates will be communicated via email or in-app notifications. Continued use of our Services after such changes constitutes acceptance of the revised policy.
If you have any questions, requests, or concerns about this Privacy Policy or our privacy practices, contact:
Hormonly Health Technologies (Tolu App)
📧 support@tolu.health
Subject Line: “Privacy Officer”