Regrow Privacy Policy
Last updated: 13 August 2026
Effective date: 13 August 2026
Contents
- Introduction
- Information stored locally on the device
- Accounts and authentication
- Optional secure backup
- Sharing your recovery with a clinic
- Clinic invitations and Hair Passport
- Purchases
- Community information
- Photographs and files
- Analytics and technical information
- Notifications
- Service providers
- Selling and advertising
- Data separation
- Account deletion
- Retention
- Security
- International processing
- Privacy rights
- Children
- Changes and contact
Introduction
Regrow is a hair-transplant recovery companion operated by Authority On Demand, Inc. ("Regrow," "we," "us"). This Privacy Policy explains how we handle information in the Regrow mobile applications and on the regrowhair.app website.
Regrow is designed to be local-first. A person can use the core local Planning, Recovery, Hair Health, Photo Diary, Today, Journey, My Clinic, and educational features without providing a name or email address. Optional protected accounts, optional secure backup, Community participation, and clinic sharing are separate features that a user chooses to enable.
Information stored locally on the device
Information users may store on their device includes:
- Recovery stage and day
- Surgery date and procedure context
- Hair-transplant technique and graft-count notes
- Recovery photographs in Photo Diary
- Recovery videos
- Daily tasks, check-ins, milestones, and notes
- Private notes
- Clinic names, contact details, and documents
- Clinic instructions and aftercare plans
- Medication reminders and medication history
- Appointment details
- Planning and Hair Health records
- Companion history
- Application preferences and notification settings
Recovery details, check-ins, Companion history, clinic instructions, medications, private notes, Photo Diary originals, and recovery videos stay on the device unless the user separately enables an account-backed feature and approves the relevant data for that feature. This information is not transmitted to Regrow servers unless the user takes an additional action such as enabling secure backup, publishing Community content, or contacting support.
Accounts and authentication
When online services are available, Regrow may establish a pseudonymous or anonymous technical identifier to support security, access control, feature configuration, and later account protection. This anonymous identifier is not the same as a public Community profile.
Users may optionally protect their Regrow account using:
- Email address and password
- Password reset
- Google sign-in
- Apple sign-in when available on the relevant platform
- Other platform identity methods added in the future
Account protection can support account recovery, cross-device restoration, Community participation, secure backup, durable entitlements, security, and account deletion.
Information we may process when a user creates or uses a protected account includes account identifiers, authentication-provider information (such as an email address or provider user ID), and account security events (such as sign-in timestamps and device or IP information for abuse prevention). Creating an account does not by itself upload private recovery information.
Optional secure backup
Secure backup is a separate, optional feature. Every core patient feature remains free without it. Nothing is uploaded merely because a user signed in. The user must explicitly enable secure backup and select the supported categories they want to protect. Depending on what is selected, secure backup may include:
- Recovery profile information
- Surgery date and procedure context
- Selected recovery photographs
- Recovery videos
- Photo Diary records
- Notes
- Clinic documents added by the user
- Planning records
- Hair Health records
- Supported application settings
Users choose backup categories. Recovery photographs and recovery videos are separate choices. Videos keep the original on the device and, when selected, upload an optimized private copy that may include audio. Private recovery information is not published to Community. Private Photo Diary photographs are not posted automatically. Backup data can be restored on another supported device after authentication. Users can disable backup at any time and can delete backup data separately.
Direct protected accounts may receive the included backup period shown in the app and can later choose the store's monthly or annual plan. Eligible clinic-sponsored patients receive exactly one year of backup from the confirmed transplant date; merely receiving or accepting an invitation does not start the one-year period. Sponsorship never auto-charges the patient and never gives the clinic access to backup. If backup access ends, local originals on the device are unaffected.
Some limited security, fraud-prevention, moderation, or legal records may be retained where reasonably necessary.
Sharing your recovery with a clinic
In the current version of Regrow, a patient-created private clinic link can show only recovery photographs the patient deliberately selected and that are already in optional secure backup. The link does not include recovery videos, planning photographs, recovery timeline, care completion, clinic documents, Community activity, Companion conversations, email address, or secure backup itself.
Nothing is shared unless the patient creates such a link in the app. Creating a link is a deliberate action. Regrow does not send records to a clinic on its own, and no clinic can request access to them. Connecting to a clinic, accepting an invitation, receiving sponsorship, or receiving a Hair Passport does not create a link or share any patient data automatically.
The patient chooses how long the link works, up to one year, and it stops working by itself when that time is up. The patient can revoke a link at any time, and revoking takes effect immediately, including for somebody who has the page open. Regrow keeps a record of when each link was opened so that the patient can see whether it has been used, and shows that record in the app.
Anyone holding the link can open it. The link is the credential: the clinic does not need a Regrow account, and we do not verify who is at the other end. The patient should treat it as a private link, send it only to the clinic, and revoke it if unsure who has it. The link is shown to the patient once and is stored only as an unreadable fingerprint, so if it is lost nobody, including us, can recover it; the patient revokes it and makes a new one.
A shared link never includes Community activity, conversations with the Companion, email address, or anything that would let a clinic sign in as the patient. Sharing is separate from cloud backup: turning sharing on does not turn backup on, and turning backup off does not revoke links already created.
Clinic invitations and Hair Passport
A clinic identity can be previewed before a patient signs in, and the clinic relationship is connected only after the patient signs in and explicitly confirms. Regrow does not match patients to clinics by name, email address, or phone number.
A clinic may deliver an immutable, versioned Hair Passport. The patient separately accepts or declines it. A Hair Passport does not apply values to the patient's recovery record and does not grant the clinic access to private patient data. Accepting a Hair Passport is not medical or surgical consent.
Purchases
The patient app is free. Secure backup is the only optional paid patient product. Apple and Google process payments. Regrow does not receive full card or bank details.
Regrow may store the store subscription identifier, purchase or transaction validation record, entitlement status, subscription status, renewal status, refund status, and paid-through date for access, fraud prevention, support, and disputes.
Community information
Regrow Community is a live peer-support space. When a user participates in Community, we process:
- Public profile data such as handle or display name
- Optional profile photograph and biography
- Recovery stage or day when the user intentionally shares it
- Public posts, comments, and replies
- Helpful reactions
- Private bookmarks
- Friend requests and friendships
- Direct messages and message requests
- Community photograph attachments
- Reports and blocks
- Moderation actions
- Community notifications
- Leaderboards or contribution recognition when enabled
Public information (profile, posts, comments, reactions) is visible to other users. Direct messages are visible to the participants. Reports, blocks, and moderator notes are visible to Regrow moderators for enforcement.
Community content is separate from private recovery data. Users must intentionally select and confirm anything shared publicly. Community activity is not automatically shared with a clinic. Private Companion conversations are not automatically published. Clinic documents are not Community content. Community participation never gives a clinic access to Community or Companion data.
Photographs and files
Regrow requests camera, photo-library, or file access only when a user chooses a feature that requires it. Photographs and files are processed to provide the requested Photo Diary, Community post, or My Clinic functionality.
- Local Photo Diary originals remain on the device unless the user enables secure backup for photographs.
- Recovery videos remain on the device unless the user enables secure backup for videos.
- Optional private backup copies exist only when the user enables backup.
- Public Community photograph copies exist only when the user posts them to Community.
- Clinic documents are treated as private records and are not included in patient-created clinic links.
Regrow does not use recovery photographs for advertising, facial recognition, identity verification, automatic medical diagnosis, or automatic clinic sharing. Photograph metadata such as capture time may be used to organize timelines; users can strip or edit metadata using device tools where appropriate.
Analytics and technical information
Regrow may collect optional anonymous usage statistics when analytics is enabled. These statistics are allowlisted, use a random analytics identifier, and are not joined to account identifiers, email addresses, purchases, clinic relationships, or private content. Analytics can be disabled in Profile.
Analytics does not include recovery photographs, recovery videos, medication names, symptoms, clinic documents, message contents, private notes, or clinic data. Analytics is not used for advertising.
Security logs may include technical identifiers, timestamps, broad error categories, and authentication events. Website hosting may process limited technical information such as IP address, browser type, device type, and request logs for security and service delivery.
Notifications
Local reminders may be scheduled on the device. Community or account notifications may be delivered where enabled. Lock-screen copy is designed to avoid unnecessary sensitive information. Users can manage notification permissions in device settings. Notification permission is not used for advertising.
Service providers
Regrow works with categories of service providers that support the product. These may include:
- Hosting and infrastructure
- Authentication
- Private storage
- Email delivery
- Platform billing (Google Play, Apple)
- Security
- Support
- Moderation infrastructure
- Analytics when enabled
Service providers may only process information as necessary to provide their service to Regrow, under appropriate obligations. Service providers may not use Regrow health-adjacent information for their own advertising.
Selling and advertising
Authority On Demand, Inc. does not sell personal health or recovery information. Regrow does not use recovery photographs, recovery videos, clinic documents, Community messages, or health-adjacent information for targeted advertising. Regrow does not use health or Community data for advertising. Regrow does not use data to determine insurance eligibility, employment, or credit.
Data separation
Community data is separate from private recovery backup. Clinic information is separate from Community. Companion conversations are not automatically shared. Community activity is not shared with a clinic merely because the user added clinic information to My Clinic. Community participation never gives a clinic access to Community or Companion data.
Account deletion
A protected-account user can delete their Regrow account in the app from Profile> Delete account & data, or from Profile> Privacy, app lock & export> Delete account & data. Type DELETE to confirm. Full account deletion removes the authenticated identity, account-backed records, private cloud storage, and Regrow-owned local data from that installation. For security, the user may be asked to sign in again if they have not signed in recently.
Individual backup data can also be deleted separately without deleting the account. Some limited security, moderation, dispute, legal, financial, or tax records may be retained only when reasonably necessary. More details are available at https://regrowhair.app/delete-account.
Retention
- Local information can be removed using the in-app deletion controls.
- Protected-account users can delete their account through the app.
- Cloud backup can be disabled and deleted.
- Public Community content may be deleted or removed.
- Some records may be retained for security, moderation, fraud prevention, disputes, or legal obligations.
- Copies previously exported or shared outside Regrow must be deleted at their destination.
- Device or operating-system backups may retain information according to the user's device settings.
Support emails and purchase-support correspondence may be retained for as long as reasonably necessary to respond, maintain security, resolve disputes, or meet legal obligations.
Security
Regrow uses reasonable technical and organizational safeguards, including platform protections provided by iOS and Android and an optional local App Lock. No method of storage or transmission can be guaranteed to be completely secure.
International processing
Regrow and its service providers may process information in countries other than the user's own. Where required, appropriate safeguards will be used for international transfers.
Privacy rights
Depending on the user's country or region, the user may have rights relating to information Authority On Demand, Inc. holds, including access, correction, deletion, export, restriction, objection, and withdrawal of consent. Requests may be sent to support@regrowhair.app.
Children
Regrow is not directed to children and is intended for people who are legally able to use the service in their location.
Changes and contact
This Privacy Policy may be updated when the product, business, or legal requirements change. The latest version will display a revised "Last updated" date.
Regrow is not a medical device and does not provide medical advice, diagnosis, or treatment. Always follow the guidance of your qualified hair-transplant physician or clinic.
Regrow is operated by:
Authority On Demand, Inc.
447 Broadway, 2nd Floor, Suite #2056
New York, NY 10013
United States
Email: support@regrowhair.app
Telephone: +1 518 608 3655
Website: https://regrowhair.app


