MyLimb Privacy Policy
MyLimb is a community for people living with limb loss and limb difference, their families, and the clinicians and professionals who work with them. It is operated by MyLimb Tech, Inc., a Delaware corporation (“MyLimb”, “we”, “us”).
This policy explains what personal data we collect, why we collect it, who else handles it on our behalf, how long we keep it, and the choices and rights you have. It covers the MyLimb website at www.mylimb.org and the MyLimb apps for iPhone and Android.
The short version:
- We collect what we need to run a community: who you are, what you post, and how the app is performing.
- Some of what you may choose to share — information about your limb difference, amputation or health — is sensitive. It is optional, it is yours, and we treat it accordingly. See section 3.
- We do not currently sell personal data, serve third-party behavioral advertising, or track users across third-party apps or websites. We use analytics and similar technologies only as described in this Privacy Policy.
- You can delete your account from inside the app, or by emailing us if you no longer have it.
1. Who we are and how to reach us
Data controller: MyLimb Tech, Inc.
1024 N Highland Ave
Murfreesboro, TN 37130
United States
Privacy contact: privacy@mylimb.org
General support: support@mylimb.org
Child safety: safety@mylimb.org
We will respond to verified privacy requests within the time required by applicable law. We may need to verify your identity before processing a request, and we may extend our response time where permitted by law.
2. What data we collect
This is the inventory we keep in sync with our Apple privacy label and our Google Play data-safety declaration.
2.1 Account and identity data
| Data | How we get it | Why |
|---|---|---|
| Name (display name) | You give it at sign-up | To identify you in the community |
| Username (your @handle) | You choose it, or we generate one | Your public identity and profile address |
| Email address | You give it at sign-up | Sign-in (we email you a one-time code), account recovery, service and notification emails |
| Referral code, and the code you were referred by | Generated by us; you may enter someone else’s | Invitations and community growth |
| Roles and permissions (member, article author, moderator, admin) | Assigned by us | Access control |
| Notification preferences (email, in-app, push) | Your settings | To send only what you’ve asked for |
| Last active time | Recorded automatically | Showing activity, and inactivity handling |
| Terms of Service acceptance (timestamp, version) | Recorded when you accept the terms | To show you agreed to them before contributing |
| Your acknowledgement that MyLimb is not medical advice (timestamp, version) | Recorded at the same moment, from the same screen | To show the notice was given and acknowledged before you took part |
MyLimb has no passwords, and we don’t use phone numbers. You sign in with your email address plus a one-time code we send you — so there is no password to steal, guess or reuse.
2.2 Profile data
Everything in your profile beyond your name and email is optional. You choose what to fill in and what to leave blank, and you can edit or clear it at any time in Profile → Edit profile.
| Data | Notes |
|---|---|
| Profile photo | Optional |
| Bio / about you | Free text — may contain whatever you choose to share, including health details |
| Website and social links | Optional |
| How you describe yourself — one of amputee, caregiver, clinician, or something else (with a short free-text description if you pick “something else”) | Sensitive — see section 3 |
| Time since amputation | Sensitive — see section 3 |
| Clinician verification details, if you identify as a clinician and ask to be verified | Reviewed to confirm professional status |
| Topics you’re interested in, and the rooms you pick during onboarding | To set up your feed |
We do not ask for your date of birth, your gender, or your home address, and we do not collect them.
2.3 Content you create
- Posts, comments and replies — including their text, and any titles
- Reviews and ratings — including star ratings and written reviews of products and services
- Articles — if you write for MyLimb: body, cover image, categories, metadata, drafts
- Images and videos you upload, including any metadata embedded in the file. We remove location metadata (EXIF/GPS) from photos you upload — both from new uploads and from photos uploaded before we introduced this — so the place a photo was taken is not stored with it or shared with anyone who views it.
- Likes and reactions
- Room memberships — the public and private rooms you join
- Follows — the members you follow
- Event RSVPs — where you respond to events
- Reports you file about content or members, including the reason and any notes
- Invitations you send
Content in public areas of MyLimb is visible to anyone, including people without an account, and may be indexed by search engines. Content in private rooms is visible to the members of that room.
2.4 Device and technical data
- Device identifiers — an identifier for your device or app installation
- Device and app information — device model, operating system and version, app version, language, time zone
- IP address
- Approximate location inferred from IP address — city/region level, for security and abuse prevention, and to understand which regions members use MyLimb from. We do not collect precise GPS location.
- Cookies and local storage — your sign-in token, session state and interface preferences. See section 8.
2.5 Usage analytics
- Screens and pages you view, features you use, and actions you take in the app (for example: posting, commenting, searching, joining a room)
- Session information — when you use the app and for how long
- Referring page and navigation paths
This is first-party product analytics — we use it to understand how MyLimb is used and to make it better. We do not currently use it for advertising or share it with advertising networks.
2.6 Crash and performance diagnostics
- Crash reports and error messages, including stack traces
- Performance data — load times, API response times, failures
- The device and app state around a crash
2.7 Push notification tokens
- The push token issued by Apple or Google for your device, so we can deliver notifications you’ve asked for
- Your notification preferences
2.8 Communications with us
- Emails and support requests you send us, and our replies
2.9 Moderation records
- The outcome of automated safety screening on your content, and any resulting reports
- Records of moderation actions on your account or content, and any appeal
2.10 People who aren’t members yet
A few records reach us about people who haven’t joined — or never will:
- Invitations. When a member invites someone, we record the invited person’s name and email address, so the invitation can reach them and be claimed.
- The waitlist. When someone asks to join, we hold their email address, their first name, and any optional profile details they chose to share while asking — which can include limb-difference information.
- The suppression list. When someone asks us not to email them, we keep their address on a do-not-contact list — honoring that request means remembering it.
We hold these records for those purposes and nothing else. Invitation and waitlist records left unclaimed or inactive are deleted after 14 days. And you don’t need an account to be forgotten: email privacy@mylimb.org and we will delete what we hold about you (see section 9.3).
What we do not collect
- We do not collect precise or GPS location.
- We do not collect contacts, calendars, photos beyond what you upload, microphone or camera data beyond what you deliberately capture and upload.
- We do not collect financial or payment data.
- We do not collect biometric data.
- We do not buy personal data about you from data brokers.
- We do not currently track you across other companies’ apps or websites or use advertising identifiers (IDFA / GAID).
3. Sensitive personal data: limb difference and health information
This section matters most, so we are being explicit about it.
MyLimb is a community about limb loss and limb difference. That means information you share here can reveal your disability and your health — for example your amputation level, the cause of your limb loss, your congenital limb difference, the prosthesis or components you use, your rehabilitation, your pain, your mental health, or your medical history.
This is sensitive personal information. It is treated as “sensitive personal information” under California’s CPRA and as sensitive data under the other US state privacy laws, as special category data under European data-protection law, and as “Sensitive Info” and “Health & Fitness” data under Apple’s App Store privacy definitions and Google Play’s Data safety framework.
A note on HIPAA: MyLimb is a peer community, not a healthcare provider, health plan, or clearinghouse, and we are not a business associate of one. That means HIPAA does not apply to what you post here — and it also means the protections you get in a clinical setting do not travel with you into a public forum. Treat what you post as public writing about your health, not as a medical record.
It can reach us in three ways:
- Profile fields you fill in about your limb difference or health — specifically, whether you describe yourself as an amputee, caregiver or clinician, the free-text description if you choose “something else”, and how long it has been since your amputation. All of these are optional.
- Content you post — a post, comment, review, article, photo or video in which you describe or show your limb difference, health, treatment or recovery.
- Inference — the simple fact of holding a MyLimb account can suggest you or someone close to you has limb loss or limb difference.
How we handle it:
- It is always optional. No health or limb-difference information is required to create an account or use MyLimb. You can use the community, read, and participate without disclosing any of it. You can leave every optional profile field blank.
- You control who sees it. Before you post, check whether you are in a public room (visible to anyone on the internet) or a private room (visible to that room’s members). Your profile is visible to others in the community; there is no separate profile-visibility setting.
- We do not currently use it for advertising or sell it. We use analytics and similar technologies only as described in this Privacy Policy.
- We do not use it to make automated decisions about you that produce legal or similarly significant effects.
- We limit internal access to staff who need it to run and moderate the Service, under confidentiality obligations.
- Automated processing of your content — what is sent to OpenAI, why, and the commitments about AI training that apply — is described in one place: section 5.2.
- You can withdraw it. Edit or clear any profile field, delete any post, or delete your account entirely.
Please think before you post. Content in public areas of MyLimb can be seen by anyone and indexed by search engines. Once something is public on the internet, others may have copied it, and we cannot claw that back. If you would rather your health details were not linked to your real name, consider using a display name that isn’t your full name, and posting in private rooms. And a good rule of thumb: share your experience, not your records. Nobody here needs your diagnosis codes, your appointment dates, your insurance details, or your clinician’s name to help you.
Consent. Health and limb-difference information is always voluntary. None of it is required to create an account or to take part, and you choose what to share and where. You may edit or clear any profile field, delete any post or comment that contains it, or delete your account entirely.
4. How we use your data, and on what basis
| What we use it for | Data used | Basis |
|---|---|---|
| Create and run your account; sign you in | Account, identity | Performance of our contract with you / consent |
| Show you the community, and show your content to others | Profile, content | Contract / consent |
| Deliver notifications you’ve enabled (in-app, email, push) | Push token, email, preferences, activity | Consent; you can turn these off |
| Send service emails you can’t opt out of (sign-in codes, security alerts, policy changes) | Contract / legitimate interest | |
| Keep the community safe: automated screening, moderation, handling reports | Content, moderation records, device, IP | Legitimate interest in member safety / legal obligation |
| Prevent fraud, spam, abuse and bot sign-ups; secure our systems | Device, IP, usage, Turnstile signals | Legitimate interest / legal obligation |
| Understand how MyLimb is used and improve it | Usage analytics, device | Consent / legitimate interest |
| Diagnose crashes and fix performance | Diagnostics, device | Legitimate interest |
| Power search, including semantic search | Content | Contract |
| Respond to your support requests | Communications, account | Contract / legitimate interest |
| Comply with law and respond to lawful requests | As required | Legal obligation |
5. Who else handles your data
We use a small number of service providers (“processors”) to run MyLimb. They process data only on our instructions, only for the purposes below, and are contractually bound to keep it confidential and secure.
We require every provider we share personal data with to provide the same or equal protection of your data as stated in this policy. None of them is permitted to sell your data, use it for their own advertising, or use it for any purpose other than delivering their service to us.
5.1 Infrastructure and delivery
| Provider | What they do | What they receive |
|---|---|---|
| Cloudflare | Hosting and CDN; Stream for video hosting and playback; Turnstile bot protection | Videos you upload; IP address; device and request data; bot-protection signals |
| Amazon Web Services (AWS) | Application hosting, database, and S3 object storage for images and files | All data described in section 2, including the images and files you upload |
| Resend | Sends transactional email — sign-in codes, notifications, service messages | Your email address and the content of those messages |
| Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM), delivered via Expo push notification service | Deliver push notifications to your device | Push token, device identifier, and the notification content |
| Google Places | Event-location search — when you type a venue while creating an event, our server sends the search text to Google to find matching places | The venue search text only. It goes through our server, so your IP address and identity are not sent to Google |
Note: MyLimb’s mobile apps use Expo’s push notification service as the relay to Apple APNs and Google FCM. Expo therefore receives push tokens and notification payloads.
5.2 Automated safety screening and search (OpenAI)
| Provider | What they do | What they receive |
|---|---|---|
| OpenAI | Automated moderation of text and images; alt-text generation that makes images accessible; text embeddings that power semantic search; email-digest summaries; topic classification | The text and images of posts, comments and articles |
This is important and we want to be plain about it. Every post, comment and article on MyLimb is automatically screened for harmful text and images at the time it is posted (flagged items are removed and sent to human moderators), and content is converted into mathematical representations (“embeddings”) so that search can find posts by meaning and not just by keyword. Both of those are done by sending the content to OpenAI’s API.
That means the text and images you post — which may include health and limb-difference information — are transmitted to OpenAI for processing. They are processed to return a safety result or an embedding, and are not used by OpenAI to train its models. We do not send your name, email or account identifiers alongside the content.
5.3 Analytics and monitoring
| Provider | What they do | What they receive |
|---|---|---|
| PostHog | First-party product analytics — how features are used | Usage events, device and browser data, IP address, a pseudonymous user identifier |
| New Relic | Performance monitoring and error tracking | Crash and error reports, performance traces, device and request data, IP address |
Both are configured as first-party analytics for MyLimb only. Neither is an advertising network, and neither is used to track you on other companies’ apps or sites.
5.4 Other disclosures
We may also disclose personal data:
- To comply with law — in response to a valid legal request, court order, or where required by applicable law.
- To protect people — where we believe in good faith it is necessary to prevent serious harm, including to report child sexual abuse and exploitation to NCMEC and/or law enforcement, and to investigate fraud, abuse or security incidents.
- To professional advisers — lawyers, accountants and auditors, under confidentiality.
- In a business transaction — if MyLimb is involved in a merger, acquisition, reorganization or sale of assets, your data may transfer to the successor. We will tell you, and the successor will be bound by a policy no less protective than this one.
- With your direction — where you ask us to share something.
6. Where your data is processed
MyLimb is based in the United States and may process or store personal information in the United States and other countries where we or our service providers operate. Those countries may have data protection laws that differ from those in your jurisdiction. Where required by applicable law, we use appropriate safeguards for cross-border transfers.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | While your account is open; deleted on account deletion (see section 9) |
| Your posts, comments, reviews, articles and uploads | While your account is open, unless you delete them; on account deletion, see section 9 |
| Usage analytics | 6 months |
| Crash and performance diagnostics | 6 months |
| Server and security logs (including IP addresses) | 6 months |
| Push tokens | Until you disable notifications, uninstall, or delete your account |
| Records relating to child sexual abuse and exploitation (CSAE) | As required by law, and preserved for law enforcement |
| Records of banned accounts and serious safety incidents (minimal — a hashed identifier and the moderation record) | For as long as the ban is in force — indefinitely, unless the law requires us to delete it |
| Support correspondence | 24 months |
| Records we must keep by law (for example, to establish or defend legal claims) | For the period the law requires |
Copies of your data held in rolling backups are overwritten within 30 days.
8. Cookies and local storage
We use cookies, local storage and similar technologies to operate and secure MyLimb, remember preferences, understand usage, and improve performance. Some of these technologies are necessary for MyLimb to function properly. You can manage cookies through your browser or device settings, but some features may not work properly if you disable them. We do not currently use cookies for third-party behavioral advertising.
9. Deleting your account and your data
9.1 In the app
Profile → Settings → scroll to Danger zone → Delete my account.
9.2 Without the app
You do not need the app to delete your account. Email support@mylimb.org from the email address on your account with the subject “Delete my account”. We will verify that the request is really from you — normally by emailing a confirmation code to the account address — and then process the deletion.
Full instructions are on our public deletion page: www.mylimb.org/delete-account.
We aim to confirm within 3 business days and complete deletion within 30 days, with backups cycling out within a further 30 days.
9.3 What deletion does
Deleting your account always removes who you are. If you request deletion of your account, we will delete or de-identify personal information associated with your account, subject to legal, security, fraud-prevention, backup, archival, and recordkeeping needs:
- your account and the ability to sign in;
- your name, email address, username, bio, and limb-difference fields, along with every other profile field;
- your profile photo, and every photo and video you uploaded;
- your push tokens and notification preferences;
- your room memberships, follows, likes and RSVPs;
- your referral code and pending invitations;
- your analytics profile in PostHog, and its association with your identifiers.
Your posts and comments — the text — stay in the community, detached from any account. Content you posted may remain visible in MyLimb in de-identified or disassociated form, and copies may remain in cached or archived pages, backups, or where retained by other users or service providers. If you’d rather they didn’t stay, ask us when you delete — email support@mylimb.org or use the contact form on our deletion page — and we will delete all your posts and comments with the account.
Plainly, though: your name, photo and profile link are removed and the posts are no longer connected to any account — but text you wrote may still contain details that identify you. If you want those gone, delete those posts, or ask us to delete everything you posted, and they will be.
People who never joined: if we hold an invitation or waitlist record about you (see section 2.10), email privacy@mylimb.org and we will delete it — you don’t need an account.
Retained after deletion — and only for these reasons. We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a legitimate business need to do so, or as required or permitted by law. Specific retention periods may vary depending on the type of information, the purpose for which it is used, and applicable legal, accounting, reporting, safety, and recordkeeping requirements. The table below is illustrative of typical retention periods:
| What | Why | For how long |
|---|---|---|
| A one-way hash of your email address | To enforce a ban, if your account was banned, and prevent evasion | For as long as the ban is in force — indefinitely, unless the law requires us to delete it |
| Minimal records of serious safety incidents and moderation actions | Member safety; preventing a banned member’s return | For as long as the ban is in force — indefinitely, unless the law requires us to delete it |
| CSAE-related records | Legal obligation; preservation for law enforcement | As required by law |
| Security and server logs containing your IP address | Security and fraud investigation | 6 months, then deleted on the normal cycle |
| Backups | Overwritten on the normal cycle | Within 30 days |
| Aggregated, de-identified statistics that cannot identify you | Understanding the Service | Indefinitely |
| The record that you accepted these terms and the medical-advice notice, and when | Showing they were accepted before the content was written | Kept for as long as we keep the content it relates to |
Deletion is permanent. We cannot restore a deleted account, its content, or its history. An email address that was used on a deleted account cannot currently be used to open a new one.
Content others have already copied, quoted or screenshotted is outside our control, and anything that was public may persist in search-engine caches or web archives for a time.
10. Your rights and choices
Whatever country you’re in, you can:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate — most of it directly in Profile → Edit profile.
- Delete your account and personal data (section 9).
- Withdraw consent at any time, including consent to process sensitive information. This doesn’t affect processing already carried out.
- Object to or restrict certain processing.
- Port your data — receive it in a structured, commonly used, machine-readable format.
- Opt out of the sale or sharing of personal information, and of targeted advertising — we do none of these, so there is nothing to opt out of, but the right stands.
- Limit the use of sensitive personal information — we use it only to run the community, never for advertising or profiling.
- Be free from discrimination for exercising any of these rights granted by applicable law. However, some features of MyLimb may require certain information to function, so if you ask us to delete or stop processing that information, some functionality may no longer be available.
- Complain to us, or to your state Attorney General or data-protection authority.
- Appeal a decision we make on your request — email privacy@mylimb.org with “Appeal” in the subject line. Several US state laws give you this right, and we extend it to everyone. If we deny the appeal we will tell you why and how to complain to your Attorney General.
Practical controls in the app:
- Edit or clear any profile field: Profile → Edit profile
- Turn notifications on or off by type: Profile → Settings → Notifications, and in your device’s OS settings for push
- Delete an individual post or comment: the post’s own menu
- Delete your account: Profile → Settings → scroll to Danger zone → Delete my account
To make a request: email privacy@mylimb.org from the address on your account. We’ll verify it’s you and respond — usually much sooner, and within 45 days at most, extendable by a further 45 where the law allows, in which case we’ll tell you why. There’s no charge, unless a request is manifestly excessive or repetitive. You may use an authorized agent where state law permits; we will still verify your identity and the agent’s authority.
If we can’t act on a request we’ll tell you why.
11. Children
MyLimb is not directed to children under 13. We do not knowingly collect information from children under that age. If we learn that we have collected personal information from a child under that age without appropriate authorization, we will take reasonable steps to delete that information. Parents or guardians who believe a child has provided personal information may contact us at privacy@mylimb.org.
The MyLimb mobile apps are rated 18+ and are intended for adults. Anyone under 18 should use MyLimb through the website at www.mylimb.org. See Terms of Service §2.1.
Parents and caregivers of children with limb difference are welcome — the account must belong to and be operated by the adult, and an adult posting about their child should think carefully about what they share, since a child cannot consent to having their medical history published.
We have zero tolerance for child sexual abuse and exploitation. See our Community Guidelines and Terms of Service.
12. How we protect your data
- We use reasonable administrative, technical, and physical safeguards designed to protect personal information appropriate to the nature of the information and the risks involved, including measures such as encryption in transit and at rest, access controls, and security monitoring. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
- Sign-in by one-time email code — there is no password to store, so none can be stolen or leaked
- Role-based access control, with staff access limited to what the job needs
- Bot and abuse protection at the edge (Cloudflare Turnstile)
- Automated safety screening of all content at the time it is posted
- Audit trails on administrative actions
- Regular dependency and security review
No system is perfectly secure, and we can’t guarantee absolute security. Please use a unique email, keep access to it secure, and never share your sign-in codes.
13. If there is a data breach
If a personal-data breach occurs, we will:
- act to contain and remedy it;
- notify the regulators the law requires — including state Attorneys General under US state breach-notification laws, and any other applicable authority — within the timeframes those laws set;
- notify affected members directly, without undue delay, describing what happened, what data was involved, what we’re doing about it, and what you can do; and
- keep a record of the incident and what we learned.
We will not hide a breach that affects you.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the effective date. If we make material changes, we may provide additional notice, such as through MyLimb or by email, where required by law. Where required by law, we will obtain your consent to material changes affecting previously collected information.
Previous versions are available on request.
15. Contact
MyLimb Tech, Inc.
1024 N Highland Ave
Murfreesboro, TN 37130
United States
- Privacy: privacy@mylimb.org
- Support: support@mylimb.org
- Child safety: safety@mylimb.org
- Copyright: copyright@mylimb.org
Terms of Service · Community Guidelines · Delete your account · Support