Privacy choices
Consumer health data
This pre-launch summary explains potential consumer health data practices and the choices that may apply under local law.
Shiora is in development. This page is a general, non-operative summary, not a service-specific consumer health data notice. Before a covered service launches, its notice must describe the actual data, sources, uses, sharing, choices, and request routes that apply.
Scope
Consumer health data is defined differently across jurisdictions. Depending on applicable law, it may include personal information that identifies, describes, or can reasonably be linked to a person's physical or mental health, symptoms, diagnosis, treatment, medication, reproductive or sexual health, or care seeking.
This summary concerns Shiora websites and services that link to it. A clinician, provider, employer, health plan, research organisation, or other partner may control some information under its own notice and legal responsibilities.
Before a covered service launches, its service-specific notice must be based on the approved data map and applicable jurisdiction. Where required, it must identify the actual categories collected, sources, processing purposes and manner, categories shared, relevant third-party categories and affiliates, rights process, appeal route, material-change process, and whether third parties collect consumer health data across sites or services.
Data we may handle
The categories depend on the service and the choices you make. They may include health concerns, symptoms, goals, cycle or reproductive information, pregnancy information, medications, appointments, care interactions, communications, and other details you choose to provide.
Consumer health data may also include information inferred from your use of a health feature, or account, device, security, and usage data when it is linked to a health interaction. Information may come from you, a connected device or service you direct us to use, or an authorised clinician or organisation where an appropriate basis applies.
How data may be used
Consumer health data may be used to provide and personalise a requested service, support communication and care coordination, maintain safety and security, troubleshoot and improve reliability, comply with applicable obligations, and conduct analysis or research where an appropriate legal basis and safeguards apply.
The purpose and legal basis can differ by service, location, and relationship. A service notice or consent prompt should explain a material additional purpose when required.
Rights and choices
Depending on your jurisdiction and Shiora's role, you may be able to ask whether consumer health data is being processed, access or delete it, correct certain information, withdraw consent, receive information about certain third parties, or appeal a decision about a request.
A request may require identity verification. Some information or requests may be limited by clinical record duties, legal retention requirements, security needs, another person's rights, or an exception under applicable law. Withdrawing consent does not necessarily affect processing that already occurred under a valid basis.
You may also be able to change permissions within the relevant service or disconnect a connected source. The effect of a choice should be explained at the point where it is offered.
Before a covered service launches, its notice must explain the available rights, secure request method, response process, appeal route, and any regulator contact required for that jurisdiction.
Contact the privacy team
For a current privacy question, email privacy@shiora.health. Data protection enquiries can also be sent to dpo@shiora.health.
This public website does not currently provide a consumer health data request portal. Do not send a rights request or sensitive health information by ordinary email. Before a covered service launches, its service-specific notice must identify the secure request and appeal routes available to people using it.


