Biometric Data Consent
HEART HIPPO BIOMETRIC DATA CONSENT
EFFECTIVE JUNE 6, 2026
This Biometric Data Consent ("Consent") describes how biometric information is collected and used in connection with the Heart Hippo website and services (the "Site") — both during the identity-verification step and during the cardiac-monitoring service — and obtains your consent to that processing. It supplements, and is in addition to, Heart Hippo's Privacy Policy, Notice of Privacy Practices, Terms of Service, and Consent for Telehealth Services. As used in this Consent, "HEART HIPPO," "we," "us," and "our" refer collectively to Appendix, Inc. and Appendix Health, PLLC, each doing business as Heart Hippo, together with their respective affiliates.
Please read this Consent carefully before completing identity verification.
1. Why We Verify Your Identity
Before we release your cardiac-monitoring order, we confirm that you are who you say you are. Identity verification helps us protect your account and medical record, prevent fraud and medical identity theft, and meet our legal, regulatory, and clinical obligations as a telehealth provider.
2. What Is Collected, and By Whom
Biometric information may be collected in two distinct contexts on the Site: (a) when you verify your identity, and (b) when you wear the cardiac monitor. In each case the information is collected and stored by a third-party processor, not by Heart Hippo.
(a) Identity Verification — Stripe Identity
Identity verification is performed by Stripe Identity, a service provided by Stripe, Inc. ("Stripe"), our third-party identity-verification and payments processor. As part of that process, Stripe collects:
- an image of a government-issued photo identification document (such as a driver's license, state ID, or passport); and
- a photograph ("selfie") of your face.
To confirm that the selfie matches the photo on your identification document, Stripe uses facial-recognition technology that analyzes facial features and creates a biometric identifier (a mathematical representation of facial geometry). This biometric identifier, and the related images, are biometric information.
This processing is carried out by Stripe. Stripe presents its own notice and obtains its own consent within the verification flow, and Stripe's handling of your information is governed by Stripe's privacy policy, available at https://stripe.com/privacy.
(b) Cardiac Monitoring — Zio® Patch and iRhythm
The cardiac monitor you wear is the Zio® patch, a device provided and serviced by iRhythm Technologies, Inc. ("iRhythm"). Throughout the monitoring period (up to 14 days), the Zio® patch continuously records your heart's electrical activity (a single-lead electrocardiogram, or "ECG") together with related cardiac-rhythm data. This continuous recording is a unique measurement of your individual physiology and may constitute biometric information.
The recorded cardiac data is transmitted to and analyzed by iRhythm, which generates the diagnostic report that a licensed physician then reviews. iRhythm collects, stores, and processes this data as part of providing the Zio® service. iRhythm's handling of your information is governed by iRhythm's own privacy policy, available on iRhythm's website at https://www.irhythmtech.com.
3. How Long the Biometric Data Is Kept
The biometric information described in Section 2 is collected and stored by the applicable third-party processor — Stripe for the identity-verification data, and iRhythm for the cardiac-monitoring data. Each retains and disposes of that information in accordance with its own privacy policy. Stripe's privacy policy is available at https://stripe.com/privacy.
4. No Sale of Biometric Information
Heart Hippo does not sell, lease, trade, or otherwise profit from your biometric information, and does not disclose it to third parties except as necessary to perform identity verification through Stripe, to provide cardiac monitoring through iRhythm, or as otherwise permitted or required by law.
5. Your Consent
By selecting the confirmation checkbox presented to you at checkout, or by otherwise affirmatively assenting through any electronic mechanism made available on the Site, and by proceeding with identity verification and cardiac monitoring, you acknowledge that you have read and understood this Consent, and you consent to the collection, use, and processing of your biometric information as described above for the purposes of verifying your identity and providing your cardiac-monitoring service. You understand that identity verification is performed by Stripe, that cardiac monitoring is performed by iRhythm, and that each is the party that collects and stores the biometric information arising from its respective service.
If you do not wish to provide this consent, please do not complete identity verification or wear the Zio® patch; instead, contact us at the address below to discuss whether an alternative is available for your situation.
6. Questions or Contact
If you have questions about this Consent or about how your biometric information is handled, please contact us:
By mail: Appendix, Inc.
1800 JFK Blvd Ste 300-91200
Philadelphia, PA 19103with a subject line of "Biometric Data Consent."
By email: hello@hearthippo.com
with a subject line of "Biometric Data Consent."
7. Modifications and Modification Date
Heart Hippo may supplement, amend, or otherwise modify this Consent at any time. Modifications will be posted on this or a similar page of the Site and are effective as of their stated effective date. This Biometric Data Consent was last modified on June 6, 2026.