Thrive In2Health

Last updated: January 2025

Privacy Policy

The Thrive program is provided by In2Health Solutions Pty Ltd (ABN 97607583264) (“In2Health”, “we”, “us”). We are committed to protecting your privacy as a user of our services. We use the information we collect about you to provide and improve the services we deliver to you. We respect the privacy and confidentiality of the information you give us and adhere to the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, for health information, the Health Privacy Principles under the Health Records Act 2001 (Vic) and equivalent State and Territory laws. Please read this privacy policy carefully. It was last updated on [date].

INFORMATION WE COLLECT FROM YOU

In the course of using our services, we may collect the following information about you: name, company or organisation name, email address, telephone number, billing address, geographic location, IP address, your Thrive Health Check responses, measurements you enter or connect from a wearable device, your goals and activity within Thrive, your conversations with the Thrive AI Health Navigator, and support queries (together “Personal Data”). Where you purchase a subscription, your card details are entered directly with our payment processor and never touch our systems.

Much of what you tell us in a Thrive Health Check is health information, which is sensitive information under Australian privacy law. We only collect it with your consent, and only to provide Thrive to you.

Thrive is designed for adults. The medical evidence behind our assessment questions and calculations relates to people aged 18 and over. Thrive is not directed to anyone under 16, and we do not knowingly collect Personal Data from anyone under 16. If we become aware that a person under 16 has provided us with Personal Data, we will delete it as quickly as possible. If you are the parent or guardian of a child and believe they have provided us with Personal Data, please contact us.

You can review, correct, update or delete your Personal Data at any time by contacting us at privacy@in2health.com. We are required to keep your Personal Data accurate and up to date, so we may ask you to review it from time to time.

HOW WE USE YOUR INFORMATION

Personally identifiable information: We use the information we collect to deliver our services to you, including calculating your scores, generating your dashboard, Personal Health Profile and Plan and referrals, coordinating any consultations or tests you request, communicating with you, diagnosing problems, measuring satisfaction, and providing information about services to assist you further.

Marketing communications are only sent to you if you have requested or subscribed to them or given us your email address to receive them. You can opt out at any time by unsubscribing or emailing us, and your request will be actioned immediately.

Non-personally identifiable information: We also use information in aggregated and de-identified forms to improve our services, including administering our services, producing reports and analytics, identifying user needs and, with health departments, hospitals and research institutes, improving population health. Information used in this way cannot identify you.

Your health information: You are not required to complete any Thrive Health Check; participation is entirely your choice. If you do, we collect, store, use and destroy your health information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Health Records Act 2001 (Vic).

IF YOU JOINED THROUGH YOUR EMPLOYER, GYM OR ANOTHER ORGANISATION

If you joined Thrive through your employer, gym or another organisation, that organisation pays for your access but is not a party to your relationship with us. Your agreement is with In2Health, and your participation is voluntary. The organisation never receives your individual answers, scores, reports, goals, clinical records or conversations, and cannot ask us for them. It receives only statistical reports that combine the results of at least 30 people, from which no individual can be identified. We may tell the organisation whether you have registered, so that it can manage the places it has paid for, but never anything about your results.

If you leave that organisation, you may keep using Thrive until the end of the period it has paid for. We will then offer you the option to continue directly with us.

WHERE YOUR INFORMATION IS STORED

All of the personal and health information we hold about you is stored in Australia.

Our system of record is a ServiceNow cloud platform hosted in ServiceNow’s Australian data centres in Sydney and Melbourne. It holds your account details, your Thrive Health Check responses, your scores and reports, your goals, any clinical records created through Thrive, and your notification history. Completed health checks are also archived as a PDF on your record there.

We also operate a small application database, hosted in Sydney, that supports the Thrive web application. It holds only limited, short-lived information: your conversations with the Thrive AI Health Navigator (encrypted, and deleted seven days after your last activity); a short-lived cache of your score trends (encrypted, and deleted within 24 hours); usage statistics that do not contain your name, email address or any health measurement; records of which health checks and notifications have been assigned to you; and sign-up verification codes (deleted after ten minutes). Health check answers are moved to your ServiceNow record within minutes of completion and removed from the application database; unfinished drafts are deleted after seven idle days.

No health check answers, health measurements, clinical records, reports or scores are stored anywhere other than your ServiceNow record. Your password is held only by ServiceNow and is never stored, cached or logged by the Thrive application. Your date of birth is never stored outside ServiceNow.

THE THRIVE AI HEALTH NAVIGATOR

The Thrive AI Health Navigator is an AI assistant that explains your results in plain language, helps you understand your plan and supports your goals. It is provided using large-language-model services from third-party providers, some of which process requests outside Australia (see “Overseas disclosure” below).

When you use the Navigator, the following is sent to the AI provider so that it can answer you: the messages you type (and, if you choose, images you attach or your voice in spoken sessions); your health scores and the content of your action plan, with your name removed; and, in spoken sessions only, your first name so that the assistant can address you. Requests are linked to an anonymous session identifier only. We do not send your surname, email address, date of birth, contact details, Medicare or other government identifiers, or your record identifier. Your clinical plans are never sent.

The AI providers process each request only to generate the response. Under our agreements with them, your messages and the response are not stored, are excluded from the provider’s abuse-monitoring logs, are deleted as soon as the response is delivered or within one hour at most, and are never used to train or improve any AI model.

When you search Thrive’s knowledge library, the words you type are sent to a separate provider to be converted into a search index. No identifying information is sent with them.

Please remember that free text is under your control: if you type identifying details into a conversation, they will form part of that request.

AUTOMATED PROCESSING AND DECISIONS

Thrive uses automated processing to calculate your scores, generate your dashboard, produce your Personal Health Profile and Plan, suggest goals and select which notifications and health checks to send you. The personal information used by these automated systems is the information you provide in your health check and profile, measurements you enter or connect from a wearable device, and your activity within Thrive.

No decision that could significantly affect your rights or interests is made about you by automated means alone. Your Personal Health Profile and Plan, and every referral, is reviewed by a registered medical practitioner before it is released to you. Thrive does not make, and is not used by your employer or organisation to make, any decision about your employment, membership, insurance or benefits.

STORAGE AND SECURITY OF YOUR INFORMATION

We use all reasonable means to protect the confidentiality of your Personal Data while it is in our possession or control. Your information is encrypted in transit and at rest. Access to your health information is restricted to staff and practitioners who need it to provide Thrive to you, is protected by multi-factor authentication, and is logged. Credit card information is handled entirely by our payment processor and is not stored on our servers.

We keep clinical records created through Thrive for at least seven years from your last interaction with us (or, if you were under 18 when a record was made, until you turn 25), as required by Australian health-records law. Everything held in the application database is deleted on the schedule described under “Where your information is stored”. We otherwise retain your Personal Data for as long as needed to provide services to you and to comply with our legal obligations, resolve disputes and enforce our agreements. You can ask us to delete your information at any time by emailing privacy@in2health.com; we will action deletion across our systems within 30 days, other than the clinical records we are legally required to keep.

If there is a breach of our security and your Personal Data is compromised, we will promptly notify you and, where required, the Office of the Australian Information Commissioner, in accordance with the Notifiable Data Breaches scheme.

SHARING YOUR INFORMATION WITH SERVICE PROVIDERS

We do not and will not sell or deal in Personal Data or any customer information.

We share Personal Data with service providers only where needed to provide Thrive to you: hosting and running the platform, delivering messages you have asked for, processing payments, booking consultations, and operating the AI Health Navigator. Every provider is bound by contract to use your information only to provide its service to us, to keep it confidential and secure, and not to use it for any other purpose. Our Australian providers — ServiceNow, Vercel, Supabase and Amazon Web Services — host and process your information in Sydney and Melbourne only.

Where you use the clinical services included in Thrive, your information is shared with the treating medical practitioner and, with your consent, with the pathology laboratory or other provider carrying out a test or consultation you have requested. These are all located in Australia.

OVERSEAS DISCLOSURE

We disclose limited information to the service providers below, which are located outside Australia. In every case the provider is bound by contract as described above, and we remain responsible for that information under the Australian Privacy Principles. No employer, wellness organisation or other third party receives your individual information, in Australia or overseas.

Provider Country What they receive Why
xAI  United States Your Navigator messages, images and voice; your scores and action-plan content with your name removed; your first name in spoken sessions only To operate the Thrive AI Health Navigator
OpenAI United States The words you type into knowledge-library search; no identifying information To index and search the knowledge library
Twilio and Meta (WhatsApp) United States Your mobile number and the content of SMS or WhatsApp messages you have chosen to receive, which may include your health scores To deliver messages you have opted in to
Stripe United States Your name, email address and payment status. Your card details are entered directly with Stripe and never touch our systems To process subscription payments
Calendly United States Your name and email address To book consultations

We do not otherwise disclose your personal or health information outside Australia.

DISCLOSURE REQUIRED BY LAW

We may from time to time need to disclose certain information, which may include your Personal Data, to comply with a legal requirement such as a law, regulation, court order, subpoena or warrant, in the course of a legal proceeding, or in response to a law enforcement agency request. We may also use or disclose your Personal Data where necessary to lessen or prevent a serious threat to the life, health or safety of any person, or to protect the rights, property or safety of our business, our customers or third parties.

If there is a change of control in our business (whether by merger, sale, transfer of assets or otherwise), customer information, which may include your Personal Data, could be transferred to a purchaser under a confidentiality agreement and on terms no less protective than this policy.

ACCESS, CORRECTION AND COMPLAINTS

You can ask us for a copy of the Personal Data we hold about you, or ask us to correct it, by emailing privacy@in2health.com. We will respond within 30 days. If you are concerned about how we have handled your information, please contact our Privacy Officer at the same address; we will acknowledge your complaint within two business days and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in Victoria, the Health Complaints Commissioner (hcc.vic.gov.au).

CHANGES TO THIS PRIVACY POLICY

This policy is subject to change so that it remains current. We may modify it at any time in accordance with changing privacy legislation or regulation. We will notify you of any material change and provide you with the updated version.

CONTACT US

If you have any questions or concerns about this privacy policy or the use of your Personal Data, please contact us at privacy@in2health.com or hello@in2health.com and we will respond within 48 hours.

Scroll to Top