The Lounge App Privacy Policy

The Lounge App Privacy Policy


Last Revised: August 23, 2022

We, Memorial Sloan Kettering Cancer Center (“MSKCC”, “we” or “us”), give you the power to share information on the Lounge App (“App”) to provide you an opportunity to connect with other current and former MSKCC patients.  This Privacy Policy describes how MSKCC uses and discloses Personal Information received from users of the App (“Users” or “you”). 

When we use the term “Personal Information”, we mean information that relates to an identified or identifiable natural person, which can be used to determine a person’s identity, either alone or when combined with other identifiers which may include but are not limited to name, an identification number, email address, physical address, or location data. 

If Personal Information collected on or provided to us through the App is “protected health information” as defined under the Health Information Portability and Accountability Act (HIPAA), MSKCC’s use and disclosure of that information is governed by the HIPAA Patient Authorization you signed in connection with your use of the App


1. Information You Provide to Us.  We collect and use Personal Information on the App in the following ways:

  • When you register to use the App, we collect your contact information, invitation passcode, phone number, birthday, username and password, which we use to create your account (“Account”) and to communicate with you. 
  • When you create a profile, you may choose to upload a photograph of yourself and provide information about your gender identity, location, employment, relationship status, living situation, medical diagnosis(es), and any of your interests and hobbies.
  • If you submit comments, photos, location data, or other content while you use the App, we collect whatever information you provide and use it to communicate with you and/or facilitate your use of the App. Please be aware that any stories, comments or other information that you post on the App using the “share with the entire community” setting will be viewable by all Users of the App.
  • If you connect to other Users or interact with groups on the App, we collect information about the people or groups you interact with, such as the Users you communicate with most frequently and the groups with which you are most engaged.
  • When you complete a survey or report a problem with the App, we collect the content of your communications with us in order to communicate with you and improve your experience in the App.

2. Information We Collect Automatically. We and our service providers may collect certain information about how you use and access the App, some of which may be Personal Information:

  • Information about your device. We may collect information automatically about you.  Like most other mobile applications, we may collect other information about the computer(s) or mobile device(s) you use to access the App, device settings, and software version.   We use this information to manage the App, to improve the content, performance, and User experience on the App, and for fraud protection and protecting our rights.
  • Cookies or Other Data Collection Technologies. We and our service providers use cookies and similar technologies to manage the App and to collect information about you when you use the App.  These technologies help us to recognize you, analyze your use of the App and identify solutions for how to make the App more useful.  These technologies also allow us to enhance the usability of the App by aggregating demographic and statistical data and providing this information to our service providers.

3. Additional Uses of Personal Information

In addition to the uses described above, MSKCC may use your Personal Information and any other content you input into the App for the following purposes:

  • Contacting you to respond to your inquiries or to provide support.
  • Maintaining and delivering the App to Users.
  • To communicate with you about MSKCC activities and news, new features or content in the App, or about MSKCC’s services.
  • To obtain User feedback.
  • To contact you about updated MSKCC policies or terms.



We do not sell your Personal Information. However, we may share or disclose Personal Information collected through the App in the following ways:

  1. To our Service Providers. We engage certain trusted service providers to provide services to us, including, without limitation, analytics services and database storage and management.
  2. Affiliates. We may share Personal Information with legal entities that are affiliates with us for purposes and uses that are consistent with this Privacy Policy and applicable law.
  3. Business Transfers.  To the extent permitted by law, we may transfer, or otherwise share some or all of the information obtained from the App, in connection with a merger, acquisition, reorganization, or other business transaction.  Personal Information may be disclosed to a successor hospital, provider, or other legal entity in the event of insolvency, bankruptcy, or receivership.
  4. Legal Process, Safety, and Terms Enforcement.  We may disclose Personal Information to legal or government regulatory authorities in response to a lawful search warrant, subpoena, court order, or other request for such information or to assist in investigations. We may also disclose Personal Information in connection with claims, disputes or litigation, or when otherwise required by law, if we determine that such disclosure is necessary to protect the property and enforce our rights, for the safety of the public or any person, or to prevent or stop any illegal, unethical, or legally actionable activity.


The App may contain links to external websites or applications. The fact that we link to such a site or application is not an endorsement, authorization or representation of our affiliation with the third party(ies) that own and/or operate those sites or applications. We do not exercise control over third party websites or applications. These sites or applications may place their own cookies or other files on your device or collect data or solicit personal information from you. Other sites and applications follow different rules regarding the use or disclosure of the Personal Information you submit to them. We encourage you to read the privacy policies or statements of the sites or applications you visit.


The App is not directed to persons under 18 and we do not knowingly collect personal information from children under 13. MSKCC complies with the Children’s Online Privacy Protection Act and all other applicable laws and regulations concerning children and the internet. If a parent or guardian becomes aware that his or her child has provided us with Personal Information without their consent, or is the subject of any image to which they have not provided consent, he or she should contact the email address set out in the “About” section of the App and be sure to include in the message the name of the minor and identification of the information and/or image.  If we become aware that a child under 13 has provided us with their Personal Information, or if the subject of any uploaded media is a minor, and the parent or guardian of such minor notifies us that such minor has submitted his or her Personal Information, or is the subject of any uploaded media, without the parent or guardian’s permission or consent, MSKCC will take reasonable steps to remove that information and content from the App.


  1. Submitting Your Personal Information and Unsubscribing.  MSKCC respects your choices about how your Personal Information is used when you register an Account with us or that you provide us for other purposes.  You can opt-out of receiving communications from MSKCC at any time by following the unsubscribe instructions at the bottom of any e-mail communication you receive. However, we may still send you updates to our legal notices or Privacy Policy, or correspondence regarding any account you have created with us. 
  2. Changing or Deleting Information.  If you are a registered User of the App, you may access and update or correct the Personal Information you provided to us by e-mailing us at the contact address set out in the “About” section of the App. You may request a correction or removal of your Personal Information, or request that MSKCC no longer solicit you by email or any other means, at any time, by emailing a request to us at the contact address set out in the “About” section the App. To ensure that your request is handled in an effective manner, please provide your exact e-mail address, name, address and/or telephone number(s). If you seek to delete your Account, we will delete the things you have posted, such as your photos, status updates, and direct messages.  Please note that any information that other Users have shared about you, or any information you post or share with other Users, is not part of your Account and will not be deleted when you delete your Account.  If you wish to temporarily suspend your Account without deleting it, you may deactivate your account instead.
  3. Management of Your Content. When you share information on the App (e.g., by posting content), you can choose the audience who can see what you share.  For example, when you post on the App, you can select the audience for the post, such as a customized group of individuals, all of your connections, or to all Users.  Likewise, when you send a direct message, you can also choose the Users you send content to.  You can manage the content and information you share on the App through the privacy settings page.
  4. Other Users. The Users you share and communicate with may download or re-share your content with other Users.  When you comment on another User’s port or “like” his or her content, said User can decide the audience who can see your comment, emoticon reaction, or “like.”  Additionally, other Users may use the App to share content about you with the audience they choose (e.g., sharing a photo of you, or information about you that you shared with them).  If you have concerns about another User’s post, please flag the post for MSKCC to review or otherwise notify MSKCC.
  5. App Permissions. You may be asked to consent to giving the App certain permissions, including allowing it to access to your mobile device’s camera function, to send push notifications about content in the App, and to send push notifications about MSKCC events.  You are not obligated to provide any such permissions, however, deciding not to provide the App with the requested permissions may impact your experience in the App.


We maintain an information security program intended to protect Users’ Personal Information.  However, no information security program is entirely guaranteed to protect against all threats to Personal Information, so it is your responsibility to restrict others from access your Account without your permission.


Personal Information about individuals located in the United Kingdom  (“UK”), Switzerland, or the European Economic Area are subject to special protections under law when the processing of those data are within the scope of the European Union’s General Data Protection Regulation (EU Regulation 2016/679) (“EU GDPR”), its incorporation into the laws of England and Wales, Scotland, and Northern Ireland by virtue of the UK European Union (Withdrawal) Act 2018 and/or the Swiss Federal Act on Data Protection, as applicable (together, the “GDPR”).  This portion of our Privacy Policy (the “GDPR Policy”) applies to Personal Information subject to the GDPR collected through the App (“EEA Processing Activities”).  If we collect or receive information about you, please note that this GDPR Policy applies only where we are a controller of your data, i.e., where the purpose and means of processing your data is determined by us.  When you use the App to transfer your Personal Information to MSKCC in the United States for EEA Processing Activities, MSKCC is a controller of your Personal Information.

We rely on multiple bases to process your Personal Information lawfully.  MSKCC will use the Personal Information provided or collected through the App only for the purposes described in this Privacy Policy.   MSKCC’s legal bases for processing such Personal Information include furthering our legitimate interests, your consent, and for our performance of a contract with you, if applicable.  When we process special categories of Personal Information, including data concerning your health, our legal bases for processing such data include your explicit consent, collected via the HIPAA Authorization Form you completed or via another means, and/or where the processing is necessary for the establishment, exercise or defense of legal claims, if applicable.  Legitimate interests that we rely on in processing your Personal Information include (i) improving and providing the App for your use, (ii) understanding how the App is being used, (iii) exploring ways to develop and grow our operations, (iv) ensuring the safety and security of the App, and (v) enhancing protection against fraud, spam, harassment, intellectual property infringement, crime and security risks.  Without the ability to collect and process your Personal Information, MSKCC would not be able to further those interests.  We may also use your Personal Information for purposes that are compatible with the purposes for which such data were initially collected.

If our processing is based solely on consent, you have the right to withdraw your consent.  You may withdraw your consent by deleting your Account.  Please note that, in certain cases, we may continue to process your Personal Information after you have withdrawn consent, if we have a legal basis to do so.  For example, we may retain certain information if we need to do so to comply with an independent legal obligation, or if it is necessary to do so to pursue our legitimate interest in keeping the App safe and secure.

If your Personal Information is processed for EEA Processing Activities, you may have certain rights available to you under the GDPR.  However, those rights are not absolute and may not apply or will be subject to exemptions in some cases.  You may exercise your rights by emailing us at [email protected] and we will aim to respond to your request as required by applicable data protection laws. These rights may include:

  • Access: to access and obtain a copy of your Personal Information processed by MSKCC.
  • Correction: to correct or update your Personal Information, if inaccurate.
  • Deletion: to request that your Personal Information be deleted, subject to any exceptions under applicable law, including MSKCC’s need to keep such data to comply with its legal obligations.
  • Restriction: to request a restriction on the processing of your Personal Information subject to certain conditions.
  • Transfer: to request to receive your Personal Information which you have provided to MSKCC, and the right to transfer that data to another controller.
  • Object: to object to MSKCC’s processing of your Personal Information.

You also have the right to file a complaint with the applicable Data Protection Authority in the jurisdiction where you live or work, or in the place where you think an issue has occurred concerning your Personal Information. You can find contact details for each Data Protection Authority in the EU and UK at

If you have questions about the processing of your Personal Information or rights associated with your Personal Information, see the section “Contact Us” below.


MSKCC is located in the United States and almost all data we process to manage the App will be transferred to or accessed from the United States.   In addition, we may transfer your Personal Information to, and access your Personal Information from, other countries throughout the world, in order to support our operations and provide services to you.  When we transfer your Personal Information, we do so in compliance with relevant data protection laws to provide adequate measures to safeguard your privacy rights and maintain the security of your Personal Information. If MSKCC transfers your Personal Information outside of the EEA, UK, Switzerland, or another country that requires legal protections for international data transfer, MSKCC will ensure that an adequate level of protection is provided for your Personal Information using one or more of the following means:  (i) transferring your Personal Information to countries that have privacy laws recognized by the relevant authority in the country that we transfer your data from as providing adequate protection of your Personal Information; (ii) entering into written agreements, such as standard contractual clauses or other data transfer agreements, with data exporters or importers that require all parties to protect your Personal Information in accordance with applicable data protection law; (iii) obtaining your consent to transfer your Personal Information for specific purposes after informing you about the possible risks of such a transfer; or (iv) in reliance on other transfer mechanisms approved by the competent authorities in the country from which your Personal Information are transferred.


We will retain your Personal Information for as long as is necessary for the purposes set out in this Privacy Policy, subject to any rights available to you under certain circumstances to have your Personal Information erased or transmitted to a third party, unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights.


This Privacy Policy is subject to change from time to time.  We will notify you of changes by posting the new version in the App and updating the effective date of the policy. We encourage you to review this Privacy Policy regularly to stay informed about how we collect, process, and share your Personal Information. Your continued use of the App following such changes will indicate your acknowledgement and acceptance of the changes.


To contact us about our App privacy practices, you may contact us in the following ways:

Teen and Young Adult Program

Memorial Sloan Kettering Cancer Center

1275 York Avenue

New York, NY 10065

TELEPHONE: 646-227-3573

EMAIL: [email protected]


In addition, you may contact our Data Protection Officer at [email protected].


To ensure that your request is handled in an effective manner, please provide your exact e-mail address, name, physical address, and/or telephone number(s).