Privacy Policy
Last updated: 11 September 2026
This policy explains what information HowBody collects, why, how it is protected, who it is shared with, and the rights you have. Health information is sensitive, so we collect as little as possible and never sell it.
Who is responsible for your data
HowBody (“we”, “us”) is operated by [OPERATOR FULL NAME], based in Cameroon. For the purposes of data-protection law, the operator is the data controller. You can reach us about privacy at hello@howbody.app.
We follow Cameroon's Law No. 2010/012 on cyber-security and cyber-criminality, and, for users in those regions, the EU/UK General Data Protection Regulation (GDPR). Where GDPR applies to you, the rights and lawful bases below apply in full.
What we collect
- Account details you give us: name, email, password (stored only as a secure hash), and optionally phone, country, city, language and blood type.
- Health information you choose to enter: symptoms and answers in the symptom checker, questions to the AI assistant, appointment and consultation details, and blood-donor information. This is special-category (sensitive) data and is treated with extra care.
- Provider verification documents (for professionals and facilities): identity, licence, qualification and registration documents, and a verification selfie. These are stored privately and shown only to our reviewers.
- Location, only when you use the map or facility features, to show clinics near you. Core guidance works without it.
- Device and usage information needed to run and secure the service (for example app version and basic diagnostics).
- Payment information for paid consultations or marketplace orders is handled by our payment partners; we do not store full card or mobile-money credentials.
Why we use it, and our lawful basis
- To provide the service you ask for (triage, booking, consultations, blood matching, marketplace) — performance of a contract with you.
- To handle sensitive health data — only with your explicit consent, given when you use those features, and withdrawable at any time.
- To verify providers and keep the platform safe (fraud prevention, moderation) — our legitimate interest in a trustworthy health service.
- To meet legal obligations where the law requires us to keep or disclose certain records.
The AI health assistant
When you use the AI assistant, your message is processed by a third-party AI provider on our behalf to generate a response. We send only your message, never your identity, and the request runs through our own server so the AI key is never exposed. The assistant gives general guidance, not a diagnosis. Please do not enter information you do not want processed for this purpose.
Who we share it with
- Providers you choose to interact with (for a booking or consultation you initiate).
- Service providers who host, secure or process data for us (cloud hosting, the AI provider, payment processors), under contracts that limit them to our instructions.
- Authorities, only where the law requires it.
We do not sell your personal data or share it for third-party advertising.
How we protect it
Verification documents and other private files are stored in access-controlled storage and served only through short-lived, signed links. Passwords are hashed, connections are encrypted in transit, and sensitive keys stay on our servers, not in the app. No system is perfectly secure, but we take reasonable measures to protect your data.
How long we keep it
We keep your data for as long as your account is active and as needed to provide the service, then delete or anonymise it within a reasonable period, unless the law requires us to keep certain records longer. You can ask us to delete your account and data at any time.
International transfers
We may process data on servers outside your country. Where we do, we use providers and safeguards intended to keep your data protected to the standard described here.
Your rights
Depending on where you live, you can:
- Access a copy of your data, and correct anything inaccurate.
- Delete your data, or ask us to restrict how we use it.
- Receive your data in a portable format, and object to certain processing.
- Withdraw consent (for example for health-data features) at any time, without affecting what happened before.
- Complain to your local data-protection authority.
To exercise any of these, email hello@howbody.app. We respond within a reasonable time.
Children
HowBody is not intended for children under 16 (or the minimum age in your country) without the consent of a parent or guardian. If you believe a child has given us data without that consent, contact us and we will remove it.
Cookies
The website uses only what is needed to function, and (with your consent) analytics to understand usage. See our Cookie Policy for details and how to change your choice.
Changes to this policy
We may update this policy as the service grows. We will change the “last updated” date above and, for significant changes, tell you in the app or on HowBody.