Legal
Privacy Policy
Last updated October 3, 2026
1. Introduction
Welcome to Longevity ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our health tracking application.2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Authentication credentials handled by Firebase Authentication (we do not receive your plain-text password)
2.2 Health Data
You choose to provide health-related information including:
- Daily sleep, movement, drinks, water, energy, mood, and clarity logs
- Optional notes, goals, plans, and Coach messages
- Urge and crisis-tool entries you choose to save
- Health signals from Apple Health or Health Connect when you connect them
- Biomarker readings you save: resting heart rate, heart rate variability, VO2 max, weight, blood pressure, and blood glucose, each with the day, the value, and where it came from
- Lab values you type (ApoB, HbA1c, hs-CRP, cholesterol and triglycerides), with the date, the unit and the reference range as printed: stored on your device only
- Nutrition entries you save: plant-food servings, grams of protein, and energy eaten, each with the day, the value, and where it came from
2.3 Usage Data
Longevity does not currently enable optional product analytics or third-party crash reporting in the released web app. The app supports Sentry error reporting when a future release is configured for it; in that case Sentry receives technical crash, performance, and device information plus a pseudonymous account ID for signed-in users, but not your email address or entered health data. The other service providers listed below may process the limited technical information required to deliver their services.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Longevity service
- Authenticate your account and prevent fraud
- Provide adaptive Coach replies using Google Gemini when you explicitly enable them
- Sync your data across your devices
- Send important notifications (if enabled)
- Improve and optimize our service
- Respond to your support requests
4. Data Storage and Security
4.1 Firebase/Google Cloud
Your data is stored securely using Google Firebase services, which comply with industry-standard security practices:
- All data is encrypted in transit (HTTPS/TLS)
- Data is encrypted at rest on Google Cloud servers
- Firebase Authentication manages secure access
- Firestore Security Rules ensure user-based access control
4.2 Data Access
Your health data is private and accessible only to:
- You - Full access to all your data
- Google Gemini - Processes the message and recent context needed for an adaptive Coach reply only after you turn that feature on
- Authorized service operators - Only as needed to secure or operate the service, or respond to a support request
5. Third-Party Services
We use the following third-party services:
- Firebase (Google) - Authentication, database hosting, cloud functions, and static hosting
- Google Gemini - Adaptive Coach replies when enabled (processes the message and recent context needed to answer)
- Stripe - Payment processing for web subscriptions (processes payment card data; Longevity does not store your full card number)
- RevenueCat - In-app purchase management if iOS or Android builds are distributed (processes purchase receipts and subscription status; does not access health data)
- Sentry - Supported but not enabled in the current released web app. If configured in a future release, it processes the technical error, device, and pseudonymous account information described above.
- Health Connect (Android) / Apple HealthKit (iOS) - With your explicit permission, the installed app reads recent sleep and today's steps and workouts from your device's health platform. The snapshot stays in app memory. If you choose a sleep or workout value, or keep a step count, in Check in and save it, that observation becomes part of your daily log and can sync to your private Firestore account when you sign in. A kept step count, sleep value or workout value is saved with the source name your phone reported and the time the app read it, so the log can say where the number came from. If you change that value yourself, the source label is removed. Raw health-platform samples are never uploaded. Stopping health reads in Settings keeps your saved check-ins. We never use Health Connect or HealthKit data for advertising.
- Biomarker readings - On the Biomarkers screen you can type a resting heart rate, heart rate variability, VO2 max, weight, blood pressure, or blood glucose reading with an optional label for what measured it. In the installed app, and only after you allow health reads in Settings, you can also ask it to read the last 30 days of those values from Health Connect or HealthKit. What it reads is shown first and kept only if you tap Save, as one value per day with the source name your phone reported. Saved readings are stored with your daily log on your device and in your private Firestore account when you sign in. They are included when you export your data and erased when you delete your account, and you can remove any single reading on the Biomarkers screen. Stopping health reads in Settings stops further reads and keeps readings you already saved. Raw samples are never uploaded.
- Lab values - On the Lab values screen you can type results from a lab report. They are encrypted and stored only on the device where you typed them, kept separately for each account on that device. They are never uploaded to your account, never synced to another device, never sent to Coach, and never read by our servers, so they are not part of the account export and a new device starts without them. You can download them as a file, remove any single value, or delete all of them on the Lab values screen; Start over and account deletion also erase them from the device.
- Nutrition entries - On the Nutrition screen you can type, for any day, plant-food servings, grams of protein, or energy eaten, with an optional label for where the number came from. In the installed app, and only after you allow health reads in Settings, you can also ask it to read the last 30 days of energy eaten that a food-tracking app wrote to Health Connect or HealthKit. What it reads is shown first and kept only if you tap Save, as one daily total with the source name your phone reported. Individual meal entries are added up on your device and never saved or uploaded; food names are not read. Saved entries are stored with your daily log on your device and in your private Firestore account when you sign in. They are included when you export your data and erased when you delete your account, and you can remove any single entry on the Nutrition screen. Stopping health reads in Settings stops further reads and keeps entries you already saved.
Each service has its own privacy policy governing how they handle data:
- Firebase Privacy Policy(opens in new tab)
- Google Privacy Policy(opens in new tab)
- Stripe Privacy Policy(opens in new tab)
- RevenueCat Privacy Policy(opens in new tab)
- Sentry Privacy Policy(opens in new tab)
6. Cookies & Tracking Technologies
Longevity uses the following technologies to provide and improve the service:
- Session cookies — Firebase Authentication uses session tokens to keep you signed in. They are cleared when you sign out and may be revoked for account or security reasons.
- Local storage — Your health data is stored locally on your device using browser storage (localStorage) with encryption. It is mirrored to your private account only when you sign in; Coach context is sent for external processing only when you turn on adaptive replies.
- Product analytics — Not enabled in the current release.
- Optional error monitoring (Sentry) — Not enabled in the current release. If a future release enables it, the limited technical and pseudonymous data described in Section 2.3 is sent to Sentry.
We do not use advertising cookies, cross-site tracking, or sell any data to third parties.
7. Your Privacy Rights
You have the right to:
- Access - View all your stored data anytime
- Export - Download your dataset in JSON format
- Delete - Request permanent deletion of your account and associated data
- Correct - Edit or update any of your information
- Opt-Out - Disable adaptive Coach replies
8. Data Retention
We retain your data:
- Active Accounts - Indefinitely, or until an account-deletion request completes
- Completed deletion requests - Active account data and the login are removed when the request completes and cannot be recovered through the app
- Service-provider backups - Expire under the provider's backup retention process and are not used to restore a deleted account
9. Children's Privacy
Longevity is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
10. International Users
Your data may be transferred to and stored on servers located outside your country of residence. By using Longevity, you consent to this transfer. We ensure appropriate safeguards are in place as required by applicable data protection laws.
11. Do Not Sell My Personal Information
We do NOT sell your personal information under any circumstances. We do not share your health data with advertisers or data brokers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will show changes by:
- Updating the "Last Updated" date at the top of this policy
- Publishing the updated policy at this same in-app path
13. Contact Us
If you have questions, want to exercise a privacy right, or want your account deleted, please contact us:
- Email: support@beyondvolatility.com
14. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to be informed (this policy)
- Right of access (data export)
- Right to rectification (data editing)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
To exercise these rights, contact us at support@beyondvolatility.com
15. CCPA/CPRA Compliance (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know what personal information is collected, used, and shared
- Right to delete personal information held by us
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
We do NOT sell or share your personal information as defined by the CCPA/CPRA. To exercise these rights, contact us at support@beyondvolatility.com
16. HIPAA Disclaimer
Longevity is NOT a HIPAA-covered entity. This is a personal wellness tool, not a medical device or healthcare service. The information you enter should not replace professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition.
By using Longevity, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.