Effective: 1 August 2026
This policy has a main part that applies to everyone, then two annexes with extra rights depending on where you live. Annex A covers the United States. Annex B covers the United Kingdom and the European Economic Area.
The short version
We do not sell your personal information, and we never have.
We never use your health information for advertising, and we never share it with advertising networks or data brokers.
Your information is stored on servers we control in Europe, not on someone else's health platform.
There is no advertising or session recording software anywhere inside the Cento app, or on our checkout and questionnaire pages.
You can get a copy of your information, correct it, or delete it, at any time, wherever you live.
The rest of this policy explains all of that properly.
1. Who we are
FIRST TO SMILE HOLDINGS LTD, trading as Cento Care, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the controller of your information. Contact us at hello@centocare.com.
This policy covers centocare.com and the Cento mobile apps for iOS and Android.
2. Where Cento is available
The Cento app is available worldwide. Anyone can create an account, log blood pressure readings, and use the insights, Action Plan, and content.
The BP Check-Up is available only in the United States. It involves care from a clinician licensed in the state where you are, so we sell it only to people in the United States, in states where we have a licensed clinician. If you are outside the United States, the BP Check-Up sections of this policy will never apply to you, because you cannot buy one.
Nothing in Cento can be purchased outside the United States.
3. Two kinds of information, handled differently
This is the most important thing to understand about how Cento works.
Your clinical record exists only if you have had a BP Check-Up, and therefore only if you are in the United States. It is everything connected to that BP Check-Up: the readings you submitted for it, your answers to its questions, the identity document and photograph you provided, the clinician's assessment, and any blood test results. It is held for the clinicians who review your BP Check-Ups, and used for your care and nothing else. It is never used for marketing and never shared with advertising partners.
Everything else is your health data and account data: the readings you log day to day, your Action Plan activity, your symptom diary, data from a wearable you connected, and ordinary account details. We hold this to run the app for you. This is all that exists for users outside the United States.
When you submit a BP Check-Up, a copy of the relevant parts of your health data crosses into your clinical record so the clinician can see the full picture. You authorise that separately, in the Telehealth Informed Consent, which tells you exactly what is copied.
4. What we collect
You give us:
Account details: name, email address, phone number, date of birth or year of birth, sex, country, region or state, and postal code.
Blood pressure readings, including systolic and diastolic values, pulse, arm used, time taken, and any notes, symptoms, or context you add.
Medications you record, and whether you took them.
Symptoms you record and how severe they were.
Height, weight, and arm circumference.
Details of your blood pressure monitor.
Anything you write to us in support chat.
In the United States, for a BP Check-Up only: your answers to the questionnaire on our website and to the BP Check-Up questions, a photograph of a government issued identity document, a photograph of your face, and the details read from the document, which are your name, date of birth, nationality, document type, document number, and expiry date. These confirm you are the person the assessment is about, and are seen only by staff who review them.
Your device gives us, only if you connect Apple Health, Health Connect, or Garmin, and only the categories you approve:
Sleep duration and sleep stages, sleep score, step count, active minutes, calories burned, resting heart rate, average heart rate, heart rate variability, blood oxygen saturation, respiratory rate during sleep, stress score, and Garmin body battery. We read these as daily summaries. We do not write anything back to Apple Health or Health Connect.
You can disconnect at any time in Settings, and paid features never depend on connecting.
We collect automatically:
Technical information needed to run the app: device model, operating system version, app version, and crash reports.
On centocare.com, standard web analytics on marketing pages, described in section 8.
We receive from others:
Stripe confirms that a payment succeeded, and gives us the last four digits and card type. We never see or store your full card number.
5. How we use it
To run the app and give you your readings, insights, trends, and Action Plan.
To send you reminders and notifications you have asked for.
To answer your support messages.
To keep the Service secure, detect fraud, and fix faults.
To understand how the app is used, in aggregate, so we can improve it. This is done in our own systems.
To send you marketing about Cento, if you opted in. You can unsubscribe from any email, or at hello@centocare.com.
To meet our legal obligations.
In the United States only: to take payment, manage your membership, confirm your identity for a BP Check-Up, and prepare your BP Check-Up assessment.
About automated software. Parts of a BP Check-Up assessment are drafted with the help of automated software, including software that produces summary text. No decision about your care is made by automated means alone. A licensed clinician reviews, edits, and is responsible for everything you receive.
6. Who we share it with
We share only what each company needs to do its job, under a contract that requires it to protect your information, to use it only for us, and to provide the same or an equivalent level of protection as this policy describes.
CompanyWhat they doWhat they receiveDigitalOceanServers and file storage, in EuropeEverything we store, on infrastructure we control and configureSentryCrash and error reportingTechnical error data. Health information is removed automatically before anything is sentSanityDelivers articles and audio to the appNo personal informationResendSends our emailsName and email addressExpoDelivers push notificationsA device notification token and the notification textStripeTakes payment. United States members onlyName, email, billing details. No health informationGoogle CloudDrafts summary text for a clinician to review. United States members onlyBlood pressure and related health data for the BP Check-Up being reviewed
We also share:
With the licensed clinicians who review your BP Check-Ups. United States only.
If your membership includes a blood panel and you complete it, with Adept Labs, Inc., trading as Junction, which arranges the test and returns your results to us, and with the CLIA and CAP certified laboratory in Junction's network that performs it. United States only.
If the law requires it, or to protect someone's safety.
If Cento is sold or merges, in which case we will tell you first and this policy continues to apply until we tell you otherwise.
7. What we never do
We do not sell your personal information, to anyone, for any price.
We never use health information for advertising, marketing, or data mining, whether by us or by anyone else. This includes everything read from Apple Health, Health Connect, and Garmin.
We never share health information with advertising networks, ad platforms, or data brokers.
We never store health information in iCloud.
There is no advertising software, no advertising identifier, and no session recording software anywhere in the Cento app. The app does not track you across other apps or websites, and never asks to.
8. Cookies and tracking on our website
Our marketing pages use cookies and similar technologies from Google Analytics, Google Ads, Meta, and Hotjar, to understand how people find us and how the site performs. These are set only after you agree in the banner shown on your first visit. Refusing is as easy as accepting, and you can change your mind at any time.
They do not run on our questionnaire pages or on checkout. Those pages carry no advertising, no analytics, and no session recording software. When someone buys, we record the sale through our own systems, and no information about anyone's health is included.
We honour Global Privacy Control. If your browser sends that signal, we treat it as an objection to any sharing for advertising, automatically.
Our Cookie Notice at centocare.com/legal/cookies lists what is set, and when.
9. How we protect your information
Your information is held on servers we control and configure ourselves, in Europe, not on a third party health platform.
We use encryption in transit and at rest, access controls so staff see only what their role requires, individually identified staff accounts, audit logging of access to clinical information, automatic removal of health information from crash reports before they leave your device, and regular review of who has access.
For United States members, we are not a HIPAA covered entity. We do not bill health insurance and we do not submit insurance claims, which is what brings a provider under HIPAA. We apply the technical safeguards of the HIPAA Security Rule as our engineering standard anyway, because it is the right benchmark for information like this.
No system is completely secure, and we cannot guarantee that your information will never be exposed. If a breach affects your personal information we will tell you, and notify the relevant regulator, within the time your law requires. Specific timings are in the annexes.
10. How long we keep it
Account and app data: while your account is open, and deleted when you delete your account.
Clinical records, United States only: kept for as long as the law of your state requires, typically between six and ten years, because clinicians are legally obliged to retain them. Deleting your Cento account does not delete these, and they are not used for anything else afterwards.
Identity documents and photographs, United States only: deleted once verification is complete and the retention period for the associated BP Check-Up ends.
Payment records: seven years, for tax and accounting.
Support conversations: three years.
Marketing preferences: kept so we can honour your choice.
11. Your rights, wherever you live
You can ask us to:
Tell you what we hold about you, where it came from, how we use it, and who we share it with.
Give you a copy in a portable format.
Correct anything inaccurate.
Delete it.
Stop or limit certain uses.
Withdraw consent you have given, at any time. This does not affect anything done before you withdrew it.
You will never be treated differently, charged more, or given a worse service for exercising any of these rights.
How to ask: email hello@centocare.com. We will verify your identity first, using information you have already given us. Timings differ by region and are set out in the annexes.
12. Deleting your account
You can delete your account:
In the app, in Settings.
On the web, at centocare.com/delete-account, without opening the app.
We will tell you what will be deleted and what has to be kept before you confirm. Deleting your account does not cancel a membership. United States members cancel separately at centocare.com.
13. Children
Cento is for adults. It is not intended for anyone under 18, we do not knowingly collect information from anyone under 18, and if we learn we have, we delete it. Contact hello@centocare.com if you believe a child has given us information.
14. Changes to this policy
If we make a material change, we will tell you by email or in the app before it takes effect. Smaller changes are published here with an updated effective date. Previous versions are available on request at hello@centocare.com.
15. Contact
FIRST TO SMILE HOLDINGS LTD, trading as Cento Care
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
hello@centocare.com
Annex A: United States
This annex applies if you live in the United States. It adds to the main policy, and does not replace it.
A1. Your state privacy rights
Depending on your state, you have the right to know what we collect, to get a copy, to correct it, to delete it, to opt out of sale or of sharing for targeted advertising, to limit how we use sensitive personal information, to opt out of profiling with legal or similarly significant effects, to appeal a refusal, and not to be discriminated against for exercising any of these.
We do not sell personal information, and we do not share health information for advertising at all.
How to ask: email hello@centocare.com. We will confirm receipt within 10 days and respond within 45 days. If we need longer we will tell you why, within that first 45 days, and take no more than another 45. If we refuse, we will explain why and you can appeal by replying. We will answer an appeal within 60 days.
You may use an authorised agent if you give them written permission and we can verify it.
A2. Sensitive personal information
Health information, and the identity documents collected for a BP Check-Up, are sensitive personal information. We use them only to provide the service you asked for, to keep it secure, and to meet legal obligations. We do not use them to infer characteristics about you and we do not disclose them for advertising.
A3. Consumer health data
Washington, Nevada, Connecticut, and Maryland residents have separate rights over health data. These are set out in full in our Consumer Health Data Privacy Policy at centocare.com/legal/consumer-health-data, which is a standalone document as Washington law requires.
A4. California Shine the Light
California residents may ask once a year whether we disclosed personal information to third parties for their own direct marketing. We do not. Email hello@centocare.com.
A5. Breach notification
If a breach affects your health information, we will tell you without unreasonable delay and no later than 60 days, as the FTC Health Breach Notification Rule requires, and we will tell you what was involved and who received it.
Annex B: United Kingdom and European Economic Area
This annex applies if you are in the United Kingdom or the EEA. It adds to the main policy, and does not replace it. In this annex, "GDPR" means the UK GDPR or the EU GDPR, whichever applies to you.
B1. Controller and representative
The controller is FIRST TO SMILE HOLDINGS LTD, at the address in section 15.
Our representative in the European Union, appointed under Article 27 GDPR, is:
Nils Wilbert
Christinenstraße 6
10119 Berlin
Germany
eu-representative@centocare.com
If you are in the EEA you may contact either us or our representative on any matter relating to your personal data. Contacting our representative is the same as contacting us.
B2. Our lawful bases
What we doLawful basisFor health data, the Article 9 conditionGive you an account and run the appPerformance of a contractNot applicableStore and show your blood pressure readings, symptoms, medications, and wearable data, and build insights from themPerformance of a contractYour explicit consent, Article 9(2)(a)Send you reminders you have setPerformance of a contractYour explicit consentKeep the Service secure and prevent fraudOur legitimate interests in protecting the ServiceNot applicableUnderstand app usage in aggregate to improve CentoOur legitimate interests in improving our productNot applicableSend you marketingYour consentNot applicableSet non-essential cookiesYour consentNot applicableMeet legal, tax, and accounting obligationsLegal obligationNot applicable
Where we rely on explicit consent for health data, the consent you give is the Health Data Consent at centocare.com/legal/health-data-consent, and you can withdraw it at any time in Settings or by emailing hello@centocare.com. Withdrawing it means we can no longer store or process that health data, so those parts of the app will stop working. It does not affect anything done before you withdrew.
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time.
You are never obliged to give us health data. Providing it is what makes the app useful to you, and nothing else depends on it.
B3. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection, including objection to processing based on legitimate interests and to direct marketing at any time.
We will respond within one month. We may extend by two further months for complex requests, and will tell you within the first month if we do. There is no charge unless a request is manifestly unfounded or excessive.
B4. Automated decision-making
We do not make decisions about you by automated means alone, and we do not carry out profiling that produces legal or similarly significant effects. Automated software helps draft summary text within a BP Check-Up, which is available only in the United States, and a licensed clinician reviews, edits, and is responsible for the result.
B5. Where your information goes
Your information is stored in Europe. Transfers between the United Kingdom and the EEA rely on the European Commission's UK adequacy decisions, renewed on 19 December 2025 and in force until 27 December 2031, and on the United Kingdom's adequacy regulations for the EEA.
Some of our service providers process limited data outside the UK and EEA. Where they do, we rely on the UK International Data Transfer Agreement, the UK Addendum, or the EU Standard Contractual Clauses, together with additional safeguards, and we assess each transfer before it begins. You can ask us for details at hello@centocare.com.
The BP Check-Up services described in the main policy, including Stripe, Google Cloud, Junction, and the reviewing clinicians, involve United States processing. They apply only to United States members, so if you are in the UK or the EEA your information is not sent to them.
B6. Complaints
Please contact us first at hello@centocare.com so we can put things right.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office at ico.org.uk. In the EEA it is the authority in the country where you live, where you work, or where the problem happened.
B7. Breach notification
If a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If it is likely to result in a high risk to you, we will tell you without undue delay.
