Privacy Policy
How we collect, use, share, and protect your information.
Last updated: June 6, 2026
Allora Care, Inc. ("Allora," "we," "us," or "our") operates the website at allora.care and the Allora telehealth platform (collectively, the "Services"), which connect patients with independent, licensed healthcare providers and partner pharmacies and laboratories for physician-led peptide therapy and related care. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have. By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
1. Scope and Who We Are
This Privacy Policy covers both our marketing website at allora.care and our patient platform at app.allora.care. Allora is a technology platform. We build and operate the software and services that help you connect with care, but we do not ourselves practice medicine. The medical care, clinical decisions, prescriptions, dispensing of medications, and interpretation of laboratory results are provided by independent, licensed healthcare providers, pharmacies, and laboratories who are solely responsible for the professional services they deliver.
Some of the information handled through the Services is protected health information ("PHI") that is created in connection with your relationship with these providers. PHI is also governed by the federal Health Insurance Portability and Accountability Act ("HIPAA") and by the Notices of Privacy Practices issued by your providers and pharmacies. Depending on the specific activity and our role, Allora may handle PHI as a business associate, as a covered entity, or both, and we enter into Business Associate Agreements with providers, pharmacies, laboratories, and vendors where required by law. Where a provider's or pharmacy's Notice of Privacy Practices applies, that notice, together with your treatment consents, governs the handling of your PHI within that relationship.
2. Information We Collect
We collect the categories of information described below. The specific information we collect about you depends on how you interact with the Services and the care you receive.
Identity and contact information
- Your name and any preferred or display name
- Date of birth
- Sex assigned at birth
- Email address and phone number
- Shipping and billing addresses
- Emergency contact information
Account and authentication information
- Account credentials. Passwords are stored only as salted hashes — we never store them in plain text.
- Multi-factor authentication settings
- Session and device information
- Your acceptance of our terms and policies
Health and clinical information (PHI)
- Intake questionnaire and assessment responses
- Medical history, allergies, current medications, and conditions
- Vitals such as height, weight, and blood pressure, among others
- Provider consultation notes, diagnoses, and treatment protocols
- Messages you exchange with your providers
Prescription information
- Medications prescribed to you
- Dosage and directions for use (SIG)
- Refill information
- Pharmacy fulfillment status
Laboratory information
- Lab orders you place or that providers order for you
- The panels selected
- Your answers to "ask at order entry" questions
- Lab results and biomarker values
Identity verification information
To comply with prescribing requirements, we (acting through our identity-verification vendor) collect government-issued ID images, a selfie, and the resulting verification results. Document images are processed by our vendor and stored securely. Allora retains the verification status and the verification method, rather than the underlying document images.
Payment and billing information
- Your subscription tier and billing cadence
- Membership status
- Order and invoice history
- Payment processor identifiers
We do not store full payment-card numbers. Card payments are tokenized and processed by our payment processor (Stripe).
Communications
- Emails and SMS/text messages
- In-app messages and notifications
- Support requests
- Where you consent, telehealth video sessions, which may be recorded and transcribed
Usage and technical data
- IP address
- Device and browser information
- Log and audit data
- Cookies and similar technologies
3. How We Collect Information
We collect information in three principal ways:
- Directly from you — for example, when you create an account, complete intake questionnaires, message a provider, place an order, or contact support.
- Automatically — through cookies and similar technologies as you use the website and patient platform.
- From third parties — including your treating providers, our partner pharmacies and laboratories, our identity-verification and address-validation vendors, and provider-credentialing sources.
4. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Services. These fall into a few broad categories: essential cookies that are required for the site and platform to function (such as authentication and security), functional cookies that remember your preferences, and analytics cookies that help us understand how the Services are used so we can improve them.
You can manage or disable cookies through your browser settings, although disabling certain cookies may affect how the Services work. Where applicable, we honor browser-based privacy controls, including the Global Privacy Control ("GPC") and "Do Not Sell" signals.
We do not sell PHI, and we do not use PHI for third-party advertising.
5. How We Use Your Information
We use the information we collect to:
- Provide and operate the Services;
- Facilitate consultations, prescriptions, fulfillment, and lab testing;
- Verify your identity and eligibility;
- Process payments and memberships;
- Communicate with you, including appointment, order, and lab notifications;
- Provide customer support;
- Ensure safety, security, and fraud prevention;
- Comply with legal, regulatory, and clinical-compliance obligations; and
- Improve and develop the Services.
Some clinical features use artificial-intelligence tools to assist — but not replace — licensed providers. For example, AI tools may help draft consultation summaries or suggest diagnostic codes. A licensed provider reviews clinical decisions, and AI processing is performed under appropriate confidentiality and security controls.
6. How We Share Your Information
We share information in the following circumstances:
- With your care team — your treating providers, partner pharmacies, and laboratories, in order to deliver your care.
- With service providers and sub-processors — companies that process data on our behalf under contract (see the table below).
- For legal and safety reasons — when we believe in good faith that disclosure is necessary to comply with law, enforce our terms, or protect the rights, safety, or property of you, us, or others.
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections.
We do not sell your personal information or PHI, and we do not share PHI for third-party marketing.
Key service providers (sub-processors):
| Provider | Purpose |
|---|---|
| Stripe | Payments and identity verification |
| Junction / Vital | Laboratory ordering and results |
| Partner pharmacy networks (incl. RxVortex and secure fax) | Prescription transmission and fulfillment |
| Resend | Transactional email |
| Twilio | SMS / text messaging |
| Daily.co | Telehealth video, recording, and transcription |
| SmartyStreets | Address validation |
| Shippo | Shipping and tracking |
| Amazon Web Services | Secure cloud hosting and document storage |
| Anthropic / AWS Bedrock | AI-assisted clinical tooling |
| PostHog | Product and web analytics (US-hosted; loaded only after cookie-consent acceptance; no PHI) |
| Attio | CRM for lead and partnership management (no PHI; pre-clinical marketing only) |
A current list of our sub-processors is available on request. We require our sub-processors to protect data under written agreements, including HIPAA Business Associate Agreements where applicable.
7. SMS / Text Messaging
With your consent, we send service-related and (optionally) informational text messages, such as appointment reminders and order updates. Message and data rates may apply. You can reply STOP at any time to opt out of text messages, and HELP for help. Opting out of text messages does not affect clinically necessary communications sent by other means. Please note that carrier message delivery is not guaranteed.
8. Telehealth Sessions and Recordings
Video visits take place through our telehealth vendor. Where permitted by law and with appropriate consent, sessions may be recorded and transcribed. Recordings and transcripts may be used as part of your medical record and for quality and compliance purposes, are retained in accordance with our retention schedule, and are stored securely.
9. Data Retention
We retain information for as long as needed to provide the Services and as required by law. Medical records and prescription records are retained for the periods mandated by applicable state and federal law, which often exceed the life of your account. De-identified or aggregated data, which cannot reasonably be used to identify you, may be retained indefinitely.
10. Data Security
We maintain administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption of data in transit and at rest;
- Envelope encryption for sensitive secrets;
- Role-based access controls and adherence to the minimum-necessary principle;
- Audit logging;
- Multi-factor authentication;
- Security requirements imposed on our vendors; and
- Continuous monitoring of our systems.
No system or method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Your Privacy Rights and Choices
Depending on where you live and the nature of the information, you may have rights to access, correct, delete, and port your personal information; to opt out of certain processing; and to withdraw consent. These rights are subject to legal and clinical-record retention limits, which may require us to retain certain records even after a request.
HIPAA rights
Where PHI is involved, you have rights under HIPAA and applicable state law, including the right to access and request amendment of your medical records and to receive an accounting of certain disclosures. These rights are exercised through the applicable provider or covered entity, and Allora will assist in facilitating your request.
California residents (CCPA / CPRA)
California residents have rights to know, access, correct, and delete personal information; to opt out of the "sale" or "sharing" of personal information (we do not sell personal information or share it for cross-context behavioral advertising); and to non-discrimination for exercising these rights. Note that PHI handled under HIPAA, and medical information handled under California's Confidentiality of Medical Information Act ("CMIA"), are exempt from the CCPA to the extent they are covered by those laws.
Other U.S. state privacy laws
Residents of states with comprehensive privacy laws — including, for example, Virginia, Colorado, Connecticut, Texas, and others — may have similar rights to access, correct, delete, and opt out of certain processing.
How to exercise your rights
To exercise your rights, contact us at privacy@allora.care or 1-800-ALLORA-P. We will verify your identity before responding to your request. You may use an authorized agent to submit a request where permitted by law.
12. Children's Privacy
The Services are intended for adults 18 years of age and older. We do not knowingly collect information from children under 18. If we learn that we have collected information from a child under 18, we will delete it.
13. Third-Party Links and Services
The Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
14. International Users
The Services are intended for use in the United States. Your information is processed and stored in the United States.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version with a new "Last updated" date and, for material changes, provide additional notice.
16. Contact Us
If you have questions about this Privacy Policy or our privacy practices, you can reach us at:
- Allora Care, Inc.
- Email: privacy@allora.care
- Phone: 1-800-ALLORA-P
- [Company Mailing Address]
This Privacy Policy is provided for general transparency. Together with any provider or pharmacy Notice of Privacy Practices and your treatment consents, it governs how your information is handled.
