Effective August 31, 2026
Privacy Policy
This Privacy Policy explains how Aryunisi Inc., carrying on business as Stowe Health (“Stowe,” “we,” “us,” or “our”), collects, uses, discloses, stores, and protects personal information through the Stowe Health mobile application, our website at www.stowehealth.com, and related services (collectively, the “Services”).
Stowe is built to help adults securely collect, store, organize, understand, and manage their own health and wellness information. We recognize that health information is highly sensitive and apply heightened protections to it.
This Privacy Policy is a transparency document. Where we ask for consent, we do so through a clear affirmative action in the app or another appropriate interface. A feature-specific notice may provide additional details at the point where information is collected or used. If a feature-specific notice conflicts with this Privacy Policy, the more specific notice will apply to that processing.
1. Who operates Stowe and who may use it
The Services are operated by Aryunisi Inc., carrying on business as Stowe Health, a federally incorporated corporation headquartered in Ontario, Canada.
At launch, the Services are offered only to individuals who:
- are at least 18 years old;
- are acting on their own behalf and have capacity to consent;
- reside in Canada, other than Québec; and
- meet any other eligibility requirements in our Terms of Use.
The Services are not currently offered to Québec residents. We collect and use eligibility information, including a user's stated province or territory, date of birth, approximate location, and relevant information identified in uploaded records, to confirm that a user is eligible. Eligibility is primarily self-reported. If we reasonably believe that a user is under 18, resides in Québec, is using the Services on behalf of another person, or is otherwise ineligible, we may request verification, restrict access, or suspend or close the account. We will handle any information already provided in accordance with this Privacy Policy and applicable law.
2. Stowe's role
Stowe is a consumer health-information management service. Stowe is not a health care provider, hospital, clinic, pharmacy, laboratory, insurer, or government health service, and is not a health information custodian under Ontario's Personal Health Information Protection Act in its current direct-to-consumer configuration.
Stowe is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Stowe does not provide medical advice, diagnosis, treatment, or emergency services and does not create or modify official clinical records. Information and artificial intelligence outputs made available through the Services are for informational and organizational purposes only. They are not a substitute for advice from a qualified health care professional. Users should consult an appropriate health care professional about medical questions and call emergency services when urgent assistance is required.
Stowe handles personal information in accordance with applicable Canadian private-sector privacy laws, including the Personal Information Protection and Electronic Documents Act and, where applicable, the private-sector privacy laws of Alberta and British Columbia. PIPEDA continues to apply to interprovincial and international information flows.
3. Personal information we collect
The information we collect depends on the features a user chooses to use. It may include the following categories.
3.1 Account and contact information
- name, preferred name, and email address;
- account identifier, login and verification records, authentication information, and consent records;
- communication preferences and notification settings; and
- information needed to respond to support, privacy, or security requests.
We do not store a readable copy of a user's password. Authentication credentials are protected using appropriate technical controls.
3.2 Profile and preference information
- date of birth and confirmation that the user is at least 18;
- sex assigned at birth;
- province or territory of residence;
- preferred language and measurement units;
- optional height, weight, health or wellness goals, and other profile information; and
- onboarding and profile-completion status.
3.3 Health and wellness information
- medical, dental, optical, pharmacy, paramedical, mental health, laboratory, imaging, treatment, medication, symptom, and other health or wellness information;
- information manually entered by a user, including symptoms, experiences, notes, categories, tags, dates, and descriptions;
- information contained in documents, images, photographs, reports, files, and other content a user chooses to upload;
- file names, file types, dates, source labels, and other metadata associated with uploaded content; and
- information that may incidentally appear in an uploaded record, such as health card information, provider information, contact details, signatures, or information about another person.
Users should upload only their own information, information they are legally entitled to provide, and information necessary for their use of the Services. Users must not create an account for another person or upload another person's records.
3.4 Artificial intelligence information
When a user uploads a record or uses an AI-powered feature, we process:
- the documents, images, text, and metadata selected for AI processing;
- text extracted from uploaded documents;
- questions, prompts, instructions, feedback, and corrections submitted by the user;
- AI-generated summaries, explanations, insights, classifications, and answers; and
- technical information about the AI request, such as timestamps, processing status, model or service version, source references, and error information.
3.5 Subscription and transaction information
- subscription product, status, renewal and expiry information;
- app-store transaction identifier, purchase history, entitlement status, and limited billing metadata; and
- records needed for accounting, fraud prevention, customer support, and legal compliance.
Payments are processed by Apple, Google, or their payment partners. Stowe does not receive or store full payment-card numbers entered through the Apple App Store or Google Play.
3.6 Device, usage, and security information
- Internet Protocol address, device and app identifiers, operating system, app version, language, and time zone;
- approximate location derived from an Internet Protocol address and, where the user grants permission, device location information used to verify Canadian eligibility and protect the Services;
- login, session, authentication, upload, and feature-interaction records;
- push-notification token and delivery status, if notifications are enabled;
- diagnostic, crash, performance, error, and security-event data; and
- access and audit records showing actions taken in an account and, where applicable, access by authorized Stowe personnel or service providers.
We do not use health information for advertising or cross-service tracking.
3.7 Device permissions
Depending on the feature used and the user's device settings, the app may request access to:
- the camera, photo library, or files selected by the user for record upload;
- device location for eligibility and security purposes; and
- notifications for service, security, subscription, and product-function messages.
The app does not access Apple HealthKit, Google Health Connect, contacts, advertising identifiers, or biometric information. Device permissions can be managed through the device settings, although disabling a permission may prevent the related feature from working.
3.8 Website and communications information
When a person visits our website, joins a waitlist, subscribes to communications, or contacts us, we may collect contact information, submitted messages, IP address, browser and device information, referring page, pages viewed, and cookie or similar-technology information. We use essential technologies needed to operate and secure the website. If we use optional analytics or marketing technologies, we will provide any notice and choice required by applicable law.
4. How we collect personal information
We collect personal information:
- directly from users during registration, onboarding, profile management, document upload, manual entry, AI interactions, support, and privacy requests;
- automatically from the app, website, device, and supporting systems when the Services are used;
- from Apple, Google, and subscription-management providers in connection with purchases and entitlements; and
- from service providers acting on our instructions, including document-processing, artificial intelligence, authentication, email, infrastructure, and technical-service providers.
At launch, Stowe does not receive health records directly from health care providers, provincial health record systems, or other health information custodians. If that changes, we will conduct an additional privacy review and provide updated notice and consent before enabling the relevant integration.
5. How we use personal information
We use personal information only for identified and reasonable purposes, including to:
- create, verify, authenticate, secure, and administer accounts;
- determine eligibility for the Services, including province and age requirements;
- receive, store, organize, display, search, retrieve, provide copies of, and delete user health records and related information;
- provide onboarding, profile, record-management, subscription, notification, and customer-support functionality;
- process uploaded records and provide AI-powered extraction, summaries, explanations, insights, and question-answering as part of the record-upload and AI experience;
- process subscriptions, maintain entitlements, reconcile transactions, prevent fraud, and meet accounting obligations;
- send service, security, privacy, subscription, and support communications;
- investigate errors, maintain availability, protect users, prevent misuse, detect security threats, and respond to incidents;
- maintain consent, access, transaction, and compliance records;
- understand and improve the reliability, accessibility, security, and performance of the Services using information that is minimized, aggregated, de-identified, or otherwise used with appropriate consent; and
- comply with applicable law, valid legal process, regulatory requirements, and enforceable agreements.
We do not sell or rent personal information. We do not use health information for advertising, behavioural advertising, insurance underwriting, employment decisions, data brokerage, or unrelated marketing. We do not disclose health information to advertisers, employers, or insurers for their own purposes. Stowe and its providers do not use user documents, health information, prompts, or AI outputs to train general-purpose artificial intelligence models. We do not track users across third-party apps or websites. Any materially different secondary use, including research, benchmarking, advertising, or model training involving identifiable or reasonably re-identifiable information, would require a separate assessment, clear notice, and express opt-in consent and would not be a condition of receiving the Services.
6. Consent and user choices
Because Stowe handles highly sensitive health information, we seek express consent through affirmative user action. During account creation, users are required to review and accept the Terms of Use and acknowledge this Privacy Policy before using the Services.
Certain processing is necessary to provide the Services a user requests. A user who does not consent to the collection and use of information required for account security, storage, record management, and subscription administration cannot use those parts of the Services.
Users retain control over the content they provide and certain device-level choices. Users may:
- decide which documents and information to upload or enter;
- enable or disable push notifications through the app or device settings;
- opt in to or withdraw from non-essential communications; and
- delete individual uploaded records using available in-app controls.
Consent may be withdrawn at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate processing already lawfully performed. If withdrawing consent means we can no longer provide a feature, we will explain that consequence before the withdrawal takes effect.
We maintain records of consent, including the user, date, action taken, and version of the relevant notice or terms. If we make a material change to a purpose, recipient, processing location, or feature that requires new consent, we will request it before applying that change to existing user information.
7. Document processing and AI-powered features
Stowe uses automated document processing and artificial intelligence to extract text and information from uploaded records, organize records, create plain-language summaries, surface relevant information, and answer users' questions about their uploaded content.
AI and document processing are integrated into the record-upload workflow. During onboarding and before a user confirms an upload, Stowe explains that the selected content will be processed by Stowe's document-processing and AI providers. Acceptance of the Terms of Use and acknowledgement of this Privacy Policy are mandatory. By selecting and confirming a file upload, the user instructs Stowe to process that file for these purposes.
Stowe currently uses:
- LandingAI to perform optical character recognition, document extraction, and parsing. LandingAI processes selected uploaded content outside Canada using a zero-data-retention configuration. Under that configuration, LandingAI processes the content transactionally and is not authorized to retain the uploaded document after completing the request; and
- Cohere to generate summaries, explanations, insights, and answers. Stowe uses a Canadian processing configuration for Cohere. Content processed through Cohere is not authorized for provider model training or unrelated use.
The original records, extracted information, and AI outputs retained by Stowe are stored in Stowe's Canadian Amazon Web Services (AWS) environment. During AI and document processing:
- only information reasonably necessary for the selected feature is provided to the relevant processors;
- Stowe selects service configurations and contractually prohibits providers from using user content, prompts, or outputs to train or improve general-purpose models or for unrelated purposes;
- AI outputs are labelled as AI-generated and, where feasible, linked to the source material used to generate them;
- outputs may be incomplete, inaccurate, or inappropriate for a particular situation and must not be treated as medical advice, diagnosis, or treatment;
- users can report an apparent error and request correction or deletion of stored derived information.
Stowe remains accountable for personal information transferred to an AI or document-processing provider for processing on our behalf. Cross-border processing is addressed in Section 9.
8. When we disclose personal information
We disclose personal information only as described below, with consent, or as permitted or required by law.
8.1 Service providers
We use service providers acting on our instructions to operate the Services. Material providers include:
- Amazon Web Services (AWS) for Canadian cloud hosting, databases, file storage, backups, authentication through Amazon Cognito, and transactional email through Amazon Simple Email Service;
- LandingAI for optical character recognition, document extraction, and parsing under a zero-data-retention configuration;
- Cohere for Canadian-hosted large-language-model processing used in Stowe's AI features;
- RevenueCat for subscription entitlement and billing orchestration; and
- Apple and Google as the exclusive payment processors for purchases made through their respective app stores.
We may also use limited security, monitoring, logging, error-detection, professional-advisory, and technical-service providers, and authorized engineering and technical contractors working under confidentiality, access-control, and data-protection obligations.
Service providers receive only the information reasonably needed to perform their assigned services. Stowe remains accountable for information transferred for processing and contractually requires service providers to provide a comparable level of protection consistent with this Privacy Policy and applicable law. Providers are not authorized to sell the information, use it for their own marketing, or use identifiable user health information to train general-purpose AI models.
Current information about material service-provider categories, purposes, and processing countries is available by contacting tech@stowehealth.com. This information may change as providers and their subprocessors change. If a change materially affects how health information is handled, we will update this Privacy Policy and provide any additional notice or consent required by law.
8.2 Authorized Stowe personnel
Access by Stowe employees and contractors is limited according to role and need. Authorized personnel may access information when reasonably necessary for security, support, troubleshooting, incident response, legal compliance, or maintaining the Services. Access is subject to confidentiality, least-privilege controls, and logging where appropriate. Production access is not permitted for routine development or testing.
8.3 Legal and safety requirements
We may disclose personal information where permitted or required by applicable law, including in response to a valid court order, warrant, subpoena, regulatory requirement, or other lawful process. We review requests and disclose only information we reasonably determine is legally required.
8.4 Corporate transactions
If Stowe is involved in a proposed financing, reorganization, merger, acquisition, sale, or transfer of all or part of its business, limited personal information may be disclosed under confidentiality and use restrictions for evaluating or completing the transaction. If control of personal information transfers, we will require the recipient to handle it consistently with applicable law and this Privacy Policy and will provide notice where required.
9. Storage in Canada and processing outside Canada
Stowe stores its primary application databases, uploaded files, retained AI outputs, and backups in Canadian AWS regions. Amazon RDS, Amazon S3, Amazon Cognito, and the other AWS services used for the Stowe production environment are configured in Canada.
Some processing and access occur outside Canada:
- LandingAI processes selected content outside Canada on a transactional basis using Stowe's zero-data-retention configuration;
- Apple, Google, RevenueCat, and their subprocessors may process limited subscription, transaction, device, support, or account information in the United States or other countries where they operate; and
- authorized Stowe personnel and contractors may securely access Canadian-hosted systems from outside Canada, when reasonably necessary for operations, security, support, troubleshooting, or incident response.
Cohere processing used by Stowe is configured in Canada. Remote access from another country is subject to authorization, confidentiality duties, access controls, and security monitoring. Remote access does not change the location of Stowe's primary databases or file storage, but it constitutes processing in the country from which the access occurs.
When personal information is processed in another country, it may be subject to that country's laws and may be accessible to courts, law enforcement, or national-security authorities in that jurisdiction. Stowe assesses service providers and transfers, limits the information involved, applies access controls, and uses contractual or other measures intended to provide a comparable level of protection.
Alberta residents may request further information about Stowe's policies and practices concerning service providers outside Canada, including the countries in which information may be processed and the purposes for which a provider is authorized to handle it, by contacting our Privacy Officer.
10. Security safeguards
Stowe maintains administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including measures such as:
- encryption of personal information in transit and encryption of stored health information and backups;
- multi-factor or multi-step account verification and protections against unauthorized login attempts;
- role-based access, least-privilege permissions, tenant separation, and time-limited elevated access;
- logging and monitoring of account, system, and administrative access;
- secure software-development, vulnerability-management, patching, and incident-response practices;
- restrictions on the use of production health information in development, testing, logs, error traces, and support tools;
- confidentiality, security, and offboarding requirements for personnel and service providers; and
- encrypted backups, restoration testing, and business-continuity controls.
No system can be guaranteed to be completely secure. Users also have a role in protecting their information and should maintain control of their email account and devices, use strong and unique credentials, enable available device protections, and notify Stowe promptly of suspected unauthorized access.
11. Retention and deletion
Stowe is designed to maintain a longitudinal health record. We therefore retain account information and user-selected health content while the account remains active, unless the user deletes particular content sooner.
Users may delete individual records through available in-app controls. When a user requests deletion of an account, Stowe will normally:
- disable access promptly after confirming the request;
- delete or de-identify account content from active systems within 30 days; and
- remove remaining copies from routine backups through the normal backup cycle, normally within 90 days.
Service providers are required to delete information in accordance with their agreements and applicable retention cycles. Information scheduled for deletion is not used for new purposes.
We may retain limited information for longer where reasonably necessary or legally required, including:
- transaction, tax, and accounting records, generally for up to seven years;
- consent, complaint, and legal-compliance records;
- security logs and records of privacy or security incidents;
- information subject to litigation, investigation, preservation, or other legal hold; and
- information needed to establish, exercise, or defend legal claims, prevent fraud, or enforce agreements.
When information must be retained after account deletion, we restrict it to the permitted purpose and delete or de-identify it when that purpose ends. We describe information as de-identified or anonymized only where appropriate measures have been applied and the term accurately reflects the residual risk of identification.
12. Account deletion and subscriptions
Users may request account deletion by emailing tech@stowehealth.com from the email address associated with the account. We may take reasonable steps to verify identity and confirm that the request is intentional. Once verified, we will promptly disable access and complete deletion according to the periods and exceptions in Section 11.
Deleting a Stowe account and cancelling an app-store subscription are separate actions. Cancelling a subscription does not delete the account or its health records. Account deletion may not automatically cancel billing managed by Apple or Google. Before deleting an account, users should cancel an active subscription through the Apple App Store or Google Play account used to purchase it. We will explain the applicable process during account deletion.
We will confirm completion of an account-deletion request. The retention periods and exceptions in Section 11 continue to apply.
13. Access, correction, and privacy requests
Subject to applicable law, users may request:
- access to personal information Stowe holds about them, including account data, consent records, AI outputs, and relevant access information;
- correction of inaccurate or incomplete personal information;
- a portable or machine-readable copy of available records and associated structured information;
- deletion of particular information or the account;
- withdrawal of consent for optional processing; or
- information about Stowe's privacy practices and service providers outside Canada.
Users can review their information and delete individual uploaded records through available in-app controls. Requests for an account-level correction, a copy or export of available records, deletion of an account, or another privacy request may be sent to tech@stowehealth.com from the email address associated with the account. These requests are fulfilled manually. To protect health information, we may need to verify the requester's identity. We will respond within the period required by applicable law, generally within 30 days, and will explain any lawful limitation or refusal.
If a user believes an AI-generated output is incorrect, the user may use the available feedback mechanism or contact us. Correcting an AI output does not alter an original source document supplied by the user.
14. Privacy and security incidents
If Stowe becomes aware of a privacy or security incident, we will take reasonable steps to contain, investigate, remediate, and document it. Where required by applicable law, we will report the incident to the appropriate privacy regulator, notify affected individuals, and notify other organizations that may be able to reduce the risk of harm.
15. Communications
We may send communications necessary to administer and secure the Services, including account verification, security, privacy, subscription, service, and support notices. These communications are part of the Services and cannot always be opted out of while an account remains active.
Stowe does not display advertising in the Services and does not use personal information or health information to target advertising. If we send promotional or product-news communications, we will do so only as permitted by law and will provide an unsubscribe method. Unsubscribing from those communications does not stop necessary service communications.
16. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, providers, technology, law, or our practices. We will post the current version on our website and make it accessible in the app, with the effective date shown at the top.
If a change is material, we will provide additional notice through the app, email, or another appropriate channel. Where a change introduces a new purpose or disclosure requiring consent, we will obtain that consent before applying the change to existing personal information.
17. Contacting Stowe and raising a concern
The Privacy Officer is accountable for Stowe's privacy program and responds to questions, access requests, complaints, and concerns.
Privacy OfficerAryunisi Inc., carrying on business as Stowe Health725 King Street West 1005, Toronto, ON M5V 2W9, CanadaEmail: tech@stowehealth.comWebsite: https://stowehealth.comWe will investigate privacy complaints and explain the outcome. If a concern is not resolved, an individual may contact the Office of the Privacy Commissioner of Canada or, where applicable, the Office of the Information and Privacy Commissioner of Alberta or British Columbia.