Effective: October 2, 2026
Privacy Policy
Introduction
Halftime Health LLC ("Halftime Health," "we," "our," or "us") is committed to protecting your privacy and handling your health information with the care it deserves. This Privacy Policy explains how we collect, use, disclose, and protect information about you in connection with our Services — including our member platform, mobile application, and all related products and services.
HIPAA Notice: Arora Health (and its affiliated professional entities) is the Clinical Affiliate and the HIPAA Covered Entity. Its clinicians authorize lab orders and provide clinician visits. GEN Health is Arora Health's electronic medical record vendor; GEN Health is not a medical practice and is not the Clinical Affiliate. Clinical Reference Laboratory, Inc., which tests blood samples, has its own duties under HIPAA and federal laboratory law. Halftime Health is a Business Associate of Arora Health and is not a medical practice. Halftime is not a HIPAA Covered Entity, because it does not conduct the standard electronic transactions, such as insurance claims, that make a health care provider a Covered Entity. When Halftime arranges a lab order that an Arora clinician authorizes, and delivers the result to you, Halftime acts as Arora Health's Business Associate. Halftime Health also operates its own electronic medical record for members on the Halftime platform, and keeps the PHI in it as a Business Associate of Arora Health. We handle protected health information (PHI) in accordance with HIPAA and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule. For your rights with respect to PHI held by Arora Health's provider entities, please also review Arora Health's Notice of Privacy Practices.
By using our Services, you agree to the collection and use of information as described in this Privacy Policy. This Policy is incorporated into our Terms of Service.
1. Information We Collect
We collect information you provide directly, information generated through your use of our Services, and information from third parties.
1.1 Information You Provide
Account Information: Name, email address, phone number, date of birth, biological sex, state of residence, and password (or authentication credentials).
Health Intake Information: Medical history, current medications, allergies, prior peptide or hormone therapy history, reproductive status, substance use history, height, weight, sleep patterns, energy levels, exercise habits, stress levels, health goals, and other health-related information you provide through our intake form.
Biometric and Lab Information: Blood biomarker results from your Halftime Baseline lab panel and any subsequent panels, organized by category (hormonal, metabolic, inflammation, thyroid, longevity, nutritional, and other markers). This constitutes PHI and is handled in accordance with Section 4.
Personalized Protocol Plan Information: Your biomarker analysis results, Personalized Protocol Plan, clinician review notes, prescription information (where applicable), and protocol history.
Payment Information: Credit/debit card numbers, billing address, and other payment details. Payment card data is processed by our third-party payment processor and is not stored by Halftime Health in an unencrypted form.
Communications: Emails, support requests, and other communications you send to us or our care team.
Feedback and Submissions: Surveys, reviews, feedback, or other submissions you provide.
1.2 Information Generated Through Your Use of Services
Usage Data: Pages viewed, features used, time spent, clickstream data, and how you interact with our platform.
Device and Technical Information: IP address, browser type and version, operating system, device identifiers, and similar technical information.
Location Information: Approximate geographic location derived from your IP address (for service eligibility verification and state-specific disclosures). We do not collect precise GPS location without your explicit consent.
Log Data: Server logs recording your interactions with our Services.
1.3 Information from Third Parties
Lab Results: Your blood test results. You collect the sample at home with a kit from Tasso, Inc. d/b/a Ramorra and return it by prepaid mail. Clinical Reference Laboratory, Inc. tests it, and the results reach us through our kit partner's system. This is PHI.
Identity Verification: Information from identity verification service providers used to verify your identity in connection with your account, where applicable.
Provider Network: Clinical notes, consultation records, and prescription information from Arora Health's contracted provider network, to the extent necessary to facilitate your Services. This is PHI.
Pharmacy Partner: Order status and fulfillment confirmation from our compounding pharmacy partner (Wellsync/BoomRx). We do not receive detailed prescription records from the pharmacy beyond what is necessary to confirm fulfillment.
Referral and Attribution Data: Information about how you learned of our Services, including referral codes and marketing attribution data.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- Creating and managing your Account
- Processing your lab panel order and arranging delivery of your Tasso at-home collection kit
- Generating your biomarker analysis as a clinical decision support tool for clinician review
- Showing you which protocols may be relevant to the goals you tell us, and recording the ones you ask to be considered for
- Sharing your health intake information and Lab Results with Arora Health's contracted provider network so a licensed clinician can review your case and issue any applicable prescriptions
- Routing approved prescriptions to our pharmacy partners for fulfillment
- Tracking and communicating order and shipment status
- Providing customer and clinical support
2.2 Clinical Decision Support
- Analyzing your biomarker results against reference ranges to produce your biomarker analysis
- Identifying biomarker patterns relevant to our approved peptide and hormone protocol formulary
- Flagging values requiring clinician attention or outside the scope of our Services
- Supporting your Ordering Clinician's independent clinical review
2.3 Account and Subscription Management
- Processing payments and managing your subscription
- Sending transactional communications (receipts, subscription updates, account alerts)
- Verifying your identity and eligibility
- Maintaining records required by applicable law (including HIPAA)
2.4 Communications
- Sending lab result notifications ("Your results are ready")
- Sending protocol status updates ("Your prescription has been approved")
- Sending appointment reminders and care team messages
- Responding to your support inquiries
- Sending educational content about health, longevity, and peptide therapy (with your consent where required)
- Sending marketing communications about new products, protocols, or promotions (with your consent where required; you may opt out at any time)
- If you buy a one-off blood test and do not hold a membership, sending you an email about once every three months that offers a Halftime membership and a new test, until you unsubscribe
2.5 Platform Improvement and Analytics
- Analyzing how members use our Services to improve the platform
- Developing new features and protocols
- Conducting research and analytics on aggregated, de-identified data
- Testing and quality assurance
2.6 Legal and Compliance
- Complying with applicable laws, regulations, and legal process (including HIPAA, state health data laws, and FDA regulations)
- Responding to lawful government requests and law enforcement inquiries
- Enforcing our Terms of Service and other agreements
- Detecting, preventing, and investigating fraud, security incidents, and other prohibited activity
- Protecting the rights, safety, and interests of Halftime Health, our members, our provider partners, and the public
2.7 Aggregated and De-Identified Data
We may use your information to create aggregated, anonymized, or de-identified datasets that cannot reasonably be used to identify you. We may use and share such de-identified data for research, analytics, product development, and other purposes without restriction.
2.8 One-off blood tests: what we collect and why
If you buy a one-off blood test, we collect and use the following. We use it only for the purposes shown.
| What we collect | Why we use it |
|---|---|
| Name, email address, phone number, date of birth, sex, shipping address and state | To create your account, confirm you are 21 or older, apply the rules for your state, choose the men's or women's version of your test, ship your kit, and contact you about your order |
| The code we email you, and your confirmation | To confirm your email address before you pay |
| The test you chose, and your order, kit and delivery status | To arrange the clinician's authorization and the lab test, ship and reship kits, and give support |
| Payment details | To take payment and issue refunds. Our payment processor handles your card. We do not keep your full card number. |
| The partner link or code you used, if any | To credit the partner for the sale. The partner sees a sales line with the test name and its code. The partner never sees your name, your contact details or your results. |
| Your lab results | To show them to you with plain-English explanations and a PDF summary, and to check them against our urgent cutoff so that our operations team is alerted if a result crosses it |
| The fact that you bought a test, and when | To send the quarterly email described in §2.9. We never use your results for this. |
2.9 The quarterly email to test buyers
If you buy a one-off blood test and do not hold a membership, we send you an email about once every three months that offers a Halftime membership and a new test. Section 7.3 explains how to stop it.
3. How We Share Your Information
We share your information only as described in this Policy or with your consent.
3.1 Arora Health (Practice / Covered Entity)
Arora Health (and its affiliated professional entities) is the Clinical Affiliate, the HIPAA Covered Entity, and the practice for your clinician visit. Halftime Health is a Business Associate of Arora Health and is not a medical practice.
We share your health intake information, Lab Results, and related clinical data with Arora Health so that a licensed clinician can review your case, determine what protocol (if any) is clinically appropriate for you, and issue any applicable prescriptions. We share PHI with Arora Health pursuant to our Business Associate Agreement.
GEN Health is Arora Health's electronic medical record vendor. GEN Health is not a medical practice and is not the Clinical Affiliate. The Ordering Clinician's chart is maintained in GEN Health on behalf of Arora Health. Halftime Health also operates its own electronic medical record for members on the Halftime platform.
3.2 Laboratory Partners
We share the identification and order information needed to ship your kit and test your sample with Tasso, Inc. d/b/a Ramorra, which supplies the collection kit and passes your order to Clinical Reference Laboratory, Inc., the CLIA-certified laboratory that tests the sample. Your results come to us, as your agent, through our kit partner's system. If the laboratory finds a result in its critical range, federal law requires it to alert the clinician who authorized your order.
3.3 Pharmacy Partners
We share your prescription information (as provided by the Ordering Clinician) with our licensed compounding pharmacy partner — Wellsync/BoomRx — for the purpose of fulfilling your clinician-prescribed protocol. Prescription data shared with the pharmacy is the minimum necessary to fulfill the order.
3.4 Identity Verification
We share limited identification data with third-party identity verification providers, where applicable, for the purpose of verifying your identity.
3.5 Technology and Infrastructure Partners
We share data with technology service providers under Business Associate Agreements (where PHI is involved) for the purpose of operating our platform:
- AWS (Amazon Web Services): Cloud infrastructure, encrypted storage (S3, KMS), email delivery (SES). BAA in place.
- Neon: Managed Postgres database hosting. BAA in place.
- AWS Cognito: Authentication and identity management. BAA in place where PHI is involved.
- NetValve / Corepay: Payment processing. PHI-isolated.
- Sentry: Application monitoring and error tracking. BAA in place. PHI excluded from error logs.
3.6 Marketing Technology (Non-PHI Only)
We use the following marketing and analytics tools. No PHI or individually identifiable health information is transmitted to any of these services:
- Klaviyo: Marketing email and lifecycle messaging. Non-PHI only (membership status, engagement signals, non-health attributes).
- Google Analytics: Website analytics. Non-PHI only.
- PostHog: Website analytics. Non-PHI only.
- Meta Pixel / Google Ads: Advertising measurement. Non-PHI only. We do not share health information with advertising platforms.
Lab results are never used for marketing or advertising. We never use your lab result values, or any conclusion drawn from them, for marketing or advertising, and we never send them to an advertising, analytics or email-marketing platform. This rule applies to everyone, members included. No advertising or analytics service receives data from the pages that show your results. The partner whose link you used never receives your name, your contact details or your results. If you pay through an employer program that AEP administers, AEP handles your payment and sees the order reference you give it; we send AEP no test data and no results. We do not sell your personal information or your health information.
We maintain technical controls and audit mechanisms to prevent PHI from being transmitted to non-BAA marketing platforms.
3.7 Legal Disclosures
We may disclose your information — including PHI, where legally required — to:
- Comply with applicable laws, regulations, subpoenas, court orders, or other legal process
- Respond to lawful requests from government authorities, regulators, or law enforcement
- Protect the safety, rights, or property of Halftime Health, our users, our provider and pharmacy partners, or the public
- Investigate or prevent fraud, security incidents, or illegal activity
- Comply with mandatory public health reporting obligations under applicable federal or state law
3.8 Business Transfers
In connection with a merger, acquisition, asset sale, or other business transaction, your information (including PHI, subject to applicable legal requirements) may be transferred to a successor entity, subject to the same privacy protections described in this Policy.
3.9 With Your Consent
We may share your information with other parties when you direct us to do so or otherwise provide your consent.
4. Protected Health Information (PHI) and HIPAA
4.1 HIPAA Applicability
Halftime Health handles PHI as a HIPAA Business Associate of Arora Health. Arora Health is the Covered Entity and the practice for your clinician visit. This includes the lab results for a one-off blood test that an Arora clinician authorizes, and the PHI in Halftime's own electronic medical record. As a Business Associate, we use and disclose PHI only as our Business Associate Agreement with Arora Health allows, and we implement the administrative, technical, and physical safeguards that HIPAA's Security Rule requires. GEN Health is Arora Health's electronic medical record vendor and is not a medical practice.
4.2 What Constitutes PHI
In connection with our Services, the following categories of information constitute PHI:
- Your Lab Results (blood biomarker values)
- Your health intake responses (medical history, medications, conditions)
- Your Personalized Protocol Plan and the clinical notes and analysis underlying it
- Your prescription information (protocol name, dosage, prescribing clinician, pharmacy)
- Any communications between you and our clinical support team that include health information
- Any other individually identifiable health information created, received, or maintained in connection with your care
4.3 Minimum Necessary Standard
We apply the HIPAA Minimum Necessary standard to all PHI access and disclosures. Staff and systems access only the PHI needed to perform their specific function. We do not share your full clinical record with any party that does not need it to perform services on your behalf.
4.4 HIPAA Notice of Privacy Practices
Arora Health, as the Covered Entity, gives you its own Notice of Privacy Practices for PHI its provider entities hold. Our HIPAA Notice describes how Halftime, as Arora Health's Business Associate, uses and discloses PHI, and how you can use your HIPAA rights.
Your rights with respect to PHI held by Halftime Health include:
- Access: You have the right to request access to PHI we maintain about you.
- Correction: You have the right to request correction of inaccurate PHI.
- Restriction: You have the right to request restrictions on how we use or disclose your PHI, though we are not always required to agree.
- Accounting of Disclosures: You have the right to request an accounting of certain disclosures of your PHI.
- Revocation of Authorization: Where we use PHI based on your Authorization, you have the right to revoke that Authorization at any time (see Authorization for Use of Medical Information).
To exercise these rights, contact us at privacy@halftime.health.
4.5 PHI Data Architecture
Halftime Health's PHI handling architecture:
- PHI is stored in our encrypted Postgres database (Neon, AES-256 encryption at rest) in our
clinicalschema - Sensitive fields (including biomarker values and clinician notes) receive additional field-level encryption using AWS KMS
- PHI is never transmitted to non-BAA destinations (including marketing platforms, advertising networks, or analytics services not covered by a BAA)
- Every access to PHI is recorded in our audit log with the actor, action, resource, purpose code, timestamp, and IP hash
- PHI access requires authentication. A member session ends after 60 minutes of inactivity. A staff session ends after 30 minutes of inactivity, and staff re-verify their second factor at least every 12 hours
4.6 PHI Retention
We retain PHI for the minimum period required by applicable law. HIPAA generally requires a minimum of 6 years for certain records. Consent records are retained for 7 years. You may request deletion of non-PHI personal information (see Section 7.2), but we may be required to retain PHI beyond the period of your account activity.
5. Data Retention
| Category | Retention Period |
|---|---|
| Account information (non-PHI) | Duration of account + 3 years |
| Health intake responses (PHI) | 6 years (HIPAA minimum) |
| Lab Results (PHI) | 6 years (HIPAA minimum) |
| Personalized Protocol Plans (PHI) | 6 years (HIPAA minimum) |
| Prescription records (PHI) | 6 years (HIPAA minimum) |
| Consent records | 7 years |
| Audit logs | 6 years (HIPAA Security Rule) |
| Payment information | As required by payment processor and applicable law |
| Marketing contact information (non-PHI) | Until opt-out + 3 years |
6. Security
We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, use, or disclosure. Our security measures include:
- Encryption at rest: All data in our Postgres database uses AES-256 encryption. PHI fields receive additional field-level encryption via AWS KMS.
- Encryption in transit: All data transmitted between your browser/app and our servers uses TLS 1.2 or higher.
- Access controls: Role-based access controls; staff access PHI only as needed for their function. Multi-factor authentication is required for ops and clinician staff. Members and partners may enroll optionally.
- Audit logging: All PHI access is logged with actor, action, resource, purpose, timestamp, and IP hash. Logs are append-only and retained for 6 years.
- Vendor management: All vendors accessing PHI are required to execute a Business Associate Agreement and demonstrate appropriate security controls.
- Incident response: We maintain a written incident response plan and breach notification procedures consistent with HIPAA's Breach Notification Rule.
- Annual risk assessment: We conduct annual security risk assessments in accordance with HIPAA Security Rule requirements.
No security system is perfect. Despite our efforts, we cannot guarantee that unauthorized parties will never be able to overcome our safeguards. If we become aware of a security breach affecting your PHI, we will notify you as required by HIPAA's Breach Notification Rule and applicable state law.
7. Your Rights and Choices
7.1 Access and Update Your Information
You may access and update most of your account information by logging into your account at halftime.health. For corrections to PHI, contact privacy@halftime.health.
7.2 Deletion Requests
You may request deletion of your non-PHI personal information by contacting privacy@halftime.health. We will honor deletion requests to the extent permitted by applicable law. Note that we may be required to retain PHI beyond your requested deletion date under HIPAA and other applicable law, and we may retain de-identified data.
7.3 Marketing Opt-Out
Members: you may opt out of marketing email by clicking "Unsubscribe" in any marketing email.
Test buyers: if you buy a one-off blood test and do not hold a membership, we send you an email about once every three months that offers a membership and a new test. We send it until you unsubscribe. To stop it, click "Unsubscribe" in the email, or email privacy@halftime.health. We stop within 10 business days. Each email shows our postal address.
This email uses your name, your email address and the fact that you bought a test. It never contains your result values or any conclusion drawn from them, and we never choose who receives it based on your results.
You cannot opt out of transactional and clinical messages, such as "your results are ready", without closing your account.
7.4 Data Portability
You may request a copy of your personal information in a machine-readable format by contacting privacy@halftime.health. For lab results, you may also ask Clinical Reference Laboratory, Inc. for a copy directly, under federal and state law.
7.5 Do Not Sell / Do Not Share
Halftime Health does not sell your personal information or PHI to third parties. We do not share your PHI with advertising networks. If you are a California resident, see Section 9 for additional rights.
7.6 State Privacy Rights
See Section 9 for state-specific privacy rights.
8. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, contact us immediately at privacy@halftime.health and we will promptly delete it.
9. State-Specific Privacy Rights
9.1 Texas
Texas residents may have rights under the Texas Data Privacy and Security Act (TDPSA), including rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of certain processing. To exercise these rights, contact privacy@halftime.health. We will respond within the timeframes required by applicable law.
Texas law also applies its medical-records privacy rules to anyone who holds protected health information (Texas Health and Safety Code chapter 181). Your protected health information may be disclosed electronically, for example to the laboratory and to our service providers.
9.2 Washington
Washington residents have rights under the Washington My Health My Data Act, RCW chapter 19.373, for consumer health data that the Act covers. PHI that we handle as Arora Health's Business Associate is governed by HIPAA and is exempt from the Act (RCW 19.373.100). We still ask for your consent at checkout for the data we collect when you buy a test. Our Consumer Health Data Notice explains what we collect, why, from where, who receives it, and how to use your rights. Your rights include the right to confirm whether we collect, share or sell your consumer health data, to access it and receive a list of the third parties that received it, to withdraw your consent, and to have it deleted. You can appeal our decision on a request. We do not sell consumer health data. To use your rights, contact privacy@halftime.health.
9.3 Nevada
Nevada residents have rights under Nevada's consumer health data law (Senate Bill 370, 2023). PHI that we handle as Arora Health's Business Associate is governed by HIPAA and is exempt from that law. We still ask for your consent at checkout for the data we collect when you buy a test. Our Consumer Health Data Notice explains what we collect, why, who receives it, and how to use your rights. Your rights include the right to confirm whether we collect, share or sell your consumer health data, to receive a list of the third parties that received it, to have us stop collecting it, and to have it deleted. We do not sell consumer health data. To use your rights, contact privacy@halftime.health. We respond within 45 days.
9.3A Connecticut
Connecticut residents have rights under the Connecticut Data Privacy Act, including its consumer health data provisions. At checkout, we ask for your consent to process your consumer health data to provide your test and to send the quarterly email described in §7.3. You can unsubscribe from that email at any time. Our Consumer Health Data Notice explains what we collect and why. Your rights include the rights to access, correct, delete and receive a copy of your personal data, to opt out of targeted advertising, sale and profiling, to withdraw consent, and to appeal our decision on a request. We do not sell consumer health data. To use your rights, contact privacy@halftime.health.
9.4 Other State Laws
Residents of other states with applicable consumer privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Montana, and other states) may have additional rights under applicable law. Virginia and Colorado residents have the right to opt-in consent before processing of sensitive personal data, including health information. To exercise state privacy rights, contact privacy@halftime.health. We will respond within the timeframes required by applicable law in your state.
9.5 CCPA / California
At this time, our Services are not available to California residents. If we expand to California in the future, we will update this section with CCPA/CPRA disclosures.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and platform for the following purposes:
- Strictly Necessary Cookies: Required for the platform to function (authentication, session management, security). Cannot be disabled.
- Analytics Cookies: Help us understand how you use our Services (e.g., PostHog). We prefer privacy-preserving analytics tools.
- Marketing Cookies: Used on our marketing website to measure campaign performance. We do not use marketing cookies within the authenticated member platform.
You may manage cookie preferences through your browser settings or through our cookie preference center. Note that disabling certain cookies may affect platform functionality.
We do not share cookie-derived data with advertising networks in connection with your health information.
Global Privacy Control (GPC): For Texas residents, we honor Global Privacy Control (GPC) browser signals as an opt-out of the sale of personal data and targeted advertising, as required by the Texas Data Privacy and Security Act (TDPSA) effective January 1, 2025.
11. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you visit.
12. Updates to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notification. The "Last Updated" date at the top of this Policy indicates when it was most recently revised. Continued use of our Services after a change becomes effective constitutes acceptance of the updated Policy.
13. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your privacy rights, contact us:
Privacy Officer
Halftime Health LLC
600 W 6th St, Suite 400
Fort Worth, TX 76102
Email: privacy@halftime.health
General: legal@halftime.health
Website: halftime.health
For HIPAA-specific complaints, you may also contact:
U.S. Department of Health & Human Services, Office for Civil Rights
Website: hhs.gov/hipaa
Phone: 1-800-368-1019
You will not be retaliated against for filing a complaint with the Office for Civil Rights.
This Privacy Policy is governed by applicable federal law and the laws of the State of Texas.