Legal · YoLongevity
Consumer Health Data Privacy Policy
YoLongevity Consumer Health Data Privacy Policy
Version: 1.19 Effective date: 2026-09-18 Last updated: 2026-09-18 Companion documents: Privacy Policy · AI Transparency Notice · Cookie Policy · Terms of Service
A note on prominence and scope
Plain-language summary. This document is separate from our main Privacy Policy on purpose. Washington State's My Health My Data Act ("MHMDA") requires us to publish a distinct Consumer Health Data Privacy Policy and to display it with the same homepage prominence as our main Privacy Policy. That is what we have done.
This Consumer Health Data Privacy Policy is presented at the same level of prominence as our main Privacy Policy on our homepage, in our application, and on every page where we collect Consumer Health Data, in compliance with RCW 19.373.020 (Washington), NV SB 370 (Nevada), and Connecticut Public Act 23-56 ("CT SB 3"), which amended the Connecticut Data Privacy Act (Public Act 22-15) with consumer-health-data protections.
National US baseline. Although MHMDA, NV SB 370, and CT SB 3 protect residents of Washington, Nevada, and Connecticut respectively, YoLongevity applies the disclosures, rights, and operational rules in this Policy to all users in the United States. We treat MHMDA-grade protection as our US-wide baseline. We do not run state-detection logic to scale protection up or down by state. The legal protections under MHMDA, NV SB 370, and CT SB 3 are enforceable by residents of Washington, Nevada, and Connecticut by statute; the contractual and operational protections in this Policy apply to every US user.
Companion to the main Privacy Policy. This Policy supplements, but does not replace, our main Privacy Policy at https://yolongevity.com/privacy. Where the main Privacy Policy and this Policy address the same topic, this Policy is more specific and controls for Consumer Health Data.
0.1 Plain-language summary (read this first)
- What we collect: information about your health — what you tell us, your wearable data, your lab results, and the wellness inferences our AI generates from that data.
- What we use it for: to deliver your YoLongevity wellness program. Nothing else, unless we ask you separately.
- We do not sell your Consumer Health Data. We will not sell it without your separate, signed authorization in the specific form required by Washington law (RCW 19.373.070). In practice, our policy is: we do not sell Consumer Health Data — full stop.
- We do not use geofencing within 2,000 feet of any in-person healthcare facility for any purpose related to Consumer Health Data (RCW 19.373.080).
- You have rights. You can ask us what we have on you, ask us to delete it — or delete your entire account yourself, in the app, with immediate effect — and withdraw your consent at any time. Submit a request by email to
chd-requests@yolongevity.com, or manage your connections, sharing switches, and consents directly in your account settings. - 18+ only. You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
1. Who we are
Plain-language summary. YoLongevity, Inc. is a Delaware-incorporated company with its principal executive office in Budapest, Hungary. YoLongevity Hungary Zrt. is our Hungarian affiliate and joint controller for wellness-coaching activities. We act as the controller of your Consumer Health Data — that is, we decide why and how it is processed.
1.1 Primary US controller and global contracting party. YoLongevity, Inc., a Delaware corporation (Delaware File No. 10568801; date of incorporation 2026-03-31; EIN 38-4392504). Registered office: 131 Continental Dr, Suite 305, City of Newark, County of New Castle, Delaware 19713, USA (registered agent: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713; phone 302-894-8922). Principal executive office: Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary.
YoLongevity, Inc. is the global contracting party with users worldwide and is the regulated entity under MHMDA, NV SB 370, CT SB 3, and US state privacy law generally. All invoices for YoLongevity services are issued by YoLongevity, Inc. (Delaware, USA), regardless of the user's country of residence.
1.2 Hungarian affiliate and joint controller. YoLongevity Hungary Zrt. (full Hungarian name: YoLongevity Hungary Zártkörűen Működő Részvénytársaság; English name: YoLongevity Hungary Closed Company by Shares; Cégjegyzékszám 01-10-140516; EUID HUOCCSZ.01-10-140516; Adószám 27093708-2-41; EU VAT HU27093708; original incorporation 2019-10-24, originally MEDICAL HOLDING Zrt., renamed 2026-04-14), with registered office (székhely) at 1025 Budapest, Nagybányai út 44., Hungary, holds exclusive commercial rights for Hungary and employs or engages the medical staff (the Chief Medical Officer and the supervising physician team) and the Wellness Coaching Personnel — the degreed dietitians (each a degreed nutrition professional) who serve as the primary human point of contact for wellness coaching, together with any other suitably qualified personnel engaged for that purpose, in each case acting under the oversight of the supervising physician team — who provide wellness coaching to Tier 2 Transform and Tier 3 Elite users globally.
For these wellness coaching activities, YoLongevity, Inc. and YoLongevity Hungary Zrt. act as joint controllers under Article 26 of the GDPR. The contact point for data subject rights remains YoLongevity, Inc. via the contact channels in §1.3 below; the essence of the joint controller arrangement is summarized in the main Privacy Policy. YoLongevity Hungary Zrt. is not a contracting party with users (all contracting and invoicing is performed by YoLongevity, Inc. globally) and is not a healthcare facility — Nagybányai 44 is the registered office only, with no in-person service delivery there. See the main Privacy Policy for the full joint-controller disclosure and Article 26 arrangement summary.
1.3 Contact for Consumer Health Data matters.
- Dedicated CHD intake:
chd-requests@yolongevity.com - General privacy:
privacy@yolongevity.com - External Data Protection Officer:
dpo@yolongevity.com - Postal — Delaware (registered office): YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
- Postal — Hungary (principal executive office): YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary
The DPO is described in the main Privacy Policy. The DPO is available for matters concerning Consumer Health Data of EU/EEA/UK/Switzerland residents. Because YoLongevity, Inc. is established in the EU through its principal executive office in Budapest, no Article 27 EU representative is required; NAIH (Hungarian National Authority for Data Protection and Freedom of Information) is our lead supervisory authority — see the main Privacy Policy §1.
2. What is "Consumer Health Data"?
Plain-language summary. We use the broad statutory definition. If a piece of information is reasonably linkable to you and reveals something about your past, present, or future physical or mental health status, we treat it as Consumer Health Data — including the wellness inferences our AI generates about you.
Consumer Health Data ("CHD") means personal information that is linked, or reasonably linkable, to an identified or identifiable consumer and that identifies the consumer's past, present, or future physical or mental health status. This includes information that we derive or infer from other data, even when the source data was not itself health information.
The categories of CHD we may collect at YoLongevity are:
| Category | Examples within YoLongevity |
|---|---|
| Individual health conditions, treatment, diagnoses | Self-reported medical history, prior conditions, allergies, medications |
| Social, psychological, behavioral, and medical interventions | Lifestyle questionnaire (sleep, diet, stress, exercise, mood) |
| Health-related surgeries or procedures | Self-reported surgical history (rare) |
| Use or purchase of prescribed medications | Medication list disclosed by you |
| Bodily functions, vital signs, symptoms, measurements | Wearable data (heart rate, HRV, sleep, temperature, steps); self-reported anthropometrics |
| Diagnostic testing, treatments, medications | Lab results you upload or that we receive via partner APIs (e.g., Synlab, Semmelweis Premium) |
| Gender-affirming care information | Not collected by design |
| Reproductive or sexual health information | Collected only if you give separate, explicit Women's Health consent (GDPR Article 9(2)(a)): cycle tracking, pregnancy, and reproductive-health symptoms and related journal entries in our Women's Health module. See our separate Women's Health Data Consent notice. Not collected for anyone who has not activated Women's Health |
| Biometric data (fingerprint, face geometry, voiceprint) | Not collected — we do not perform biometric matching |
| Genetic data | Moleqlar BioAge methylation and proteomic results, NAD test results — treated as Article 9 genetic data and as CHD |
| Precise location indicating an attempt to acquire health services | Not collected; geofencing prohibited (see Section 8) |
| Data identifying a consumer seeking health services | Account creation, lab uploads, partner-clinic referral flows |
| Inferred CHD | AI-generated longevity insights, biological-age estimates, wellness-baseline deviations, and any other inference our systems produce from the data above |
Wellness, not medical. The fact that we treat data as CHD does not transform YoLongevity into a medical service. YoLongevity is not a Covered Entity, not a Business Associate, not a healthcare provider, not a clinical laboratory, and not a pharmacy. Our service is a wellness and lifestyle optimization service — see Terms of Service for the full positioning.
3. Where we get your Consumer Health Data
Plain-language summary. We get CHD only from sources you control: what you tell us, the wearables you connect, the labs you authorize, the partner clinics you choose to be referred to, and the AI inferences we generate from those inputs. We do not buy CHD from data brokers, and we do not enrich your account from external sources you did not authorize.
| Source | Examples |
|---|---|
| Directly from you | Account questionnaire, lifestyle questionnaire, lab uploads, anthropometric self-assessment, AI Coach conversations, support tickets |
| Wearable device APIs (with your authorization) | Oura, WHOOP, Garmin, Polar, Apple Health, Android Health Connect, Withings, and similar |
| Partner laboratories (with your authorization) | Moleqlar (BioAge methylation/proteomic, NAD test); user-uploaded results from Synlab, Semmelweis Premium, and other labs you choose |
| Internal AI processing | AI Coach inferences derived from your data (these inferences are themselves CHD) |
| Partner clinics (with separate, per-referral consent) | Outcome data after a referral — only when you consent specifically to that referral |
| Our staff, writing about you | A note a member of staff writes on your record, and the staff working thread with our assistant about your record (Section 4a.6) |
| The assistant on our public website (no account) | Anything you choose to type into the website assistant, including health details you volunteer there (Section 4a.7) |
We do not purchase Consumer Health Data from data brokers. We do not enrich your account from third-party sources. We do not source CHD from public records, scraped websites, or aggregator products.
4. Why we use Consumer Health Data
Plain-language summary. We use your CHD to deliver your wellness program, to support the human professionals in our higher tiers, to keep the service safe, and to comply with the law. We do not use CHD for advertising, training third-party AI, or any other secondary purpose without your separate consent.
We collect, process, and share Consumer Health Data only for the following purposes:
- Service delivery. To generate and adjust your AI longevity protocol, coordinate Tier 2 and Tier 3 dietitian and physician interactions, and maintain the availability and integrity of the Service.
- Wellness coaching support. To translate insights into actionable lifestyle guidance through the AI Coach and (in Tier 2/3) human wellness staff.
- Partner-clinic referrals. To facilitate referrals you request — only with separate, specific, per-referral consent.
- Certified Fitness Partner sharing. To disclose the categories you switch on to the Certified Fitness Partner you name, and to process them through the partner's AI coaching assistant, on your instruction and explicit consent (see Section 5.7).
- Wearable and laboratory integrations. To incorporate your authorized device and lab data into your wellness protocol.
- Service improvement and quality assurance. Limited internal review of AI outputs by our medical leadership for safety and quality. Aggregated, de-identified analytics that are no longer reasonably linkable to you.
- Security, fraud prevention, and integrity of the Service. To detect and prevent abuse, unauthorized access, and security incidents.
- Legal compliance. To respond to a subpoena, court order, or regulatory inquiry; to retain records required by tax, anti-money-laundering, or other applicable law.
We do NOT use Consumer Health Data for:
- Behavioral advertising, including cross-context behavioral advertising or targeted advertising.
- Sale, except with your separate, statutorily-prescribed authorization (see Section 7).
- Inferences about race, religion, sexual orientation, political belief, or other protected characteristics.
- Geofencing around healthcare facilities (see Section 8).
- Training third-party large-language models. Our LLM providers and the AI gateway we route requests through are contractually committed to no training on our data and to zero or minimum retention. See AI Transparency Notice.
4a. Your coach conversation is Consumer Health Data
Plain-language summary. What you write to the coach, the photos and documents you send it, its replies, the short summary it keeps of your thread and the things it remembers about you are all treated as Consumer Health Data. We keep them for as long as your account exists — we deliberately do not delete your photos on a timer — and we erase them when you delete your account, when you ask us to, or, for material a Women's Health consent covered, when you withdraw that consent. Two related but different things have their own rules: what our staff write about you (Section 4a.6) and the assistant on our public website that anyone can use without an account (Section 4a.7).
4a.1 What it consists of, and why all of it counts as CHD
Your coach conversation — in the portal, in our mobile app, and on any messaging channel you connect yourself — consists of your messages and the coach's replies; the files you attach (meal and body photos, screenshots, lab reports and other documents); a short rolling summary of the conversation so far; the things the coach remembers about you (preferences, constraints, goals, life events), which you can ask the coach to forget or ask us to delete; and a record of each action the coach carried out for you, such as logging a meal or a symptom.
A coaching conversation about your body cannot be split into "health" and "non-health" messages: a sentence about how you slept, a photograph of a plate, or a picture of a lab sheet identifies your physical health status, and a message that looks harmless alone can reveal it in context. We therefore treat the entire conversation store — messages, attachments, summaries, remembered facts and action records — as Consumer Health Data under Section 2, and as special-category health data under Article 9 GDPR, whether or not a particular message happens to contain a health fact. Every rule in this Policy that applies to CHD applies to it: no sale (Section 7), no advertising use (Section 4), no geofencing (Section 8), the security safeguards in Section 9, and the rights in Section 6.
4a.2 Where it lives, and what is authoritative
Health values you log through the coach — a meal, a symptom, a measurement, a medication, a preference — are written into our health system of record, the separate health database described in Section 5.1. That database, not the conversation, is the authoritative record of those values. The record of an action the coach performed keeps identifiers only: which action ran, the identifier of the row it created in your health record, whether it succeeded, and when — never a second copy of the value, so what you see in your health record cannot silently drift away from what the coach told you.
The conversation itself (messages, the rolling summary, the remembered facts) is stored in our application database in the EU. Attachments are stored as files in access-controlled EU storage; the conversation holds a reference to the file, and files are served only through short-lived, individually signed links.
4a.3 Who processes it
Only the sub-processors already listed in Section 5.1, for the purposes stated there: Anthropic (Claude), which receives your message, the relevant part of the conversation and any image or PDF you attached in order to generate the reply; OpenRouter, Inc. routing to Google Gemini models, which embeds your message text so we can search our own knowledge base, serves the Trainer Coach conversation, and is the documented fallback route if the primary model provider is unavailable; Supabase, which hosts the conversation database and the attachment storage; and — only if you connect that channel yourself — Meta Platforms (WhatsApp Business Platform) or Telegram, over which your messages and photos transit under that platform's own terms and are visible to it. That is inherent to using a third-party messaging channel, which is why it is optional and disconnectable at any time; the portal and the mobile app involve neither. No LLM provider or gateway may train on your conversation, and our analytics provider receives no coach message content at all.
You are always told when you are talking to AI, on every surface, in your language, with a link to our AI Transparency Notice.
4a.4 How long we keep it — and why there is deliberately no timer
We keep your coach conversation, including attachments and summaries, for as long as your account exists. Meal photos, body photos and uploaded documents do not expire on a schedule.
This is a considered decision, not an omission. The value of a coaching history is its continuity: a photograph from four months ago is what makes "this is the third time this pattern appears" possible — for you and for the staff supporting your tier — and a file that disappears on a timer removes that context without telling anyone. What we set against the longer retention is the CHD-grade governance above and erasure that is immediate and complete. If we ever introduce a timed deletion schedule for coach attachments, we will publish it in this Policy before it takes effect.
4a.5 Erasing it, and who can read it
- Delete your account (Section 6.2) — the conversation, every attachment, the summary, the remembered facts and the action records are erased with the account, immediately.
- Ask us —
chd-requests@yolongevity.com; verified requests are honored within 30 days (Section 6.2). You can ask us to delete the conversation without deleting your account. - Withdraw a Women's Health consent (Section 6.3) — we erase the conversation material from the period that consent covered: messages, attachments, the facts derived from them, and the rolling summary, which is reset so no withdrawn material survives inside it. Because a conversation is not tagged topic by topic, this removes the whole conversation from that period, including parts unrelated to Women's Health. That is deliberate — we would rather delete more than leave withdrawn material behind.
- Who can read it: you, and a small number of authorized staff who need it to do their job — the wellness-coaching and medical staff supporting your tier, and support or safety staff acting on a request or an escalation. Access is role-based, requires multi-factor authentication, and is subject to the CHD access-logging commitment in Section 9. When our own staff use the assistant to ask about you, the assistant is given the recent part of this conversation as well — at most the last 120 messages, only messages you can see yourself, and every such read is logged; Section 4a.6 sets out the detail, including the fact that a Certified Fitness Partner's assistant does not receive it.
4a.6 When our staff ask the assistant about you, and the notes they write on your record
The same assistant technology is also used by our staff, about you, in two shapes. Neither is part of your own coach conversation, and neither is shown to you as a message in it — but both are about your health, so both are Consumer Health Data and every rule in this Policy applies to them.
A staff working thread. An authorized member of staff — the wellness or medical staff supporting your tier, or a Certified Fitness Partner you named and switched on (Section 5.7) — can ask the assistant questions about your record while preparing for a call or reviewing your progress. That exchange is stored separately from your conversation, is never rendered to you, and is never treated as something you said. The snapshot of your record the assistant reads is fetched from the health system of record for that single request and discarded; the thread keeps the conversation, not a duplicate of your measurements — though the assistant's prose can restate a figure from your record, which is why the thread is governed as CHD. When a member of our own staff asks the assistant about you, the assistant is also given the most recent part of your coach conversation — at most the last 120 messages, and only messages you can see yourself. It is processed by the same sub-processor that generates your own coach replies, Anthropic, on the same terms and with no training on your data (Section 4a.3); it is fetched for that one request and is not copied into the staff thread. The assistant used by a Certified Fitness Partner does not receive your coach conversation at all — a partner works from the record you chose to share with them (Section 5.7), not from your words to your coach. We keep a staff working thread for 365 days after the last time it was used, and then delete it with its messages. Every time a member of staff opens your record this way — including every time your coach conversation is given to the assistant — we write an access-log entry — who, when, which record and which messages — under the CHD access-logging commitment in Section 9; you may request that log (Section 6.1).
A note on your record. A member of staff can also deliberately write a note into your record — staff prose, for the next colleague who supports you. That note is a row on your own record and follows your record's rules: it is retained and erased with the rest of your record (Sections 6.2 and 10), it is included in a verified deletion request, and it is your personal information — you may obtain a copy under your right of access and ask us to correct it (Sections 6.1 and 6.4). It is not displayed in your coach conversation. It is used by the staff who support you and may be taken into account by the coaching system when it prepares your guidance, so that something you told one colleague is not lost at the next hand-over. It is never sold, never used for advertising, and never disclosed outside the recipients in Section 5.
4a.7 The assistant on our public website (no account)
Our public website offers an assistant that anyone can use without an account. It is not your coach: it has no access to any customer account, health record, or the conversation described above, and if you are already a customer it does not know that. It answers from our own published material.
Under MHMDA and its Nevada and Connecticut counterparts, information can be Consumer Health Data even when we do not know your name — it is enough that it is reasonably linkable to you or to your device. A website-assistant session carries a browser session identifier and a one-way hash of your network address, so we treat whatever you type into it as CHD and apply this Policy to it, including the prohibitions on sale (Section 7), advertising use (Section 4) and geofencing (Section 8).
- Please do not describe your health there. The website assistant is a general information tool on a public page, not a consultation. The right place for anything about your own body is the coach inside your account.
- Retention — 30 days. A nightly job deletes website-assistant sessions older than 30 days; the messages in a session go with it. There is no archive. The abuse-prevention counters that rate-limit a public endpoint are kept for a week.
- An email address you leave is kept. The assistant can take your email so that a person from our team can contact you. That email survives the 30-day deletion — it is detached from the deleted conversation and held as the contact request you made, until you tell us to delete it. Write to
chd-requests@yolongevity.comorprivacy@yolongevity.comand we will. Leaving it does not subscribe you to marketing, which is a separate opt-in. - The older version of this widget. We are moving the website assistant onto our current assistant platform; the older version stores its conversations in a separate, older set of records that is not on the 30-day timer and has no scheduled deletion. Those records are kept until that older system is retired, at which point they are deleted in one pass with it. We state this rather than implying a schedule the old system does not have. If you can identify a conversation of yours in it, ask us and we will delete it — because those conversations carry no identity, we usually cannot find yours for you.
5. Who we share Consumer Health Data with
Plain-language summary. We share CHD only with vendors who help us run the service, with the wearables and labs you authorize, with partner clinics you choose, with our advisors and regulators when required, and with a successor in a business transaction. The complete, current list of vendors is published at our subprocessor page.
We share Consumer Health Data only with the categories of recipients below, and only as necessary for the purposes in Section 4.
5.1 Service providers (processors and sub-processors)
The current and complete list of our sub-processors is the table below, kept in step with the corresponding vendor disclosure in the main Privacy Policy. For each sub-processor we disclose the name, country of operation, the service provided, the categories of CHD accessed, and the legal mechanism (DPF, SCC, adequacy) used for any cross-border transfer; each is bound by a written Data Processing Agreement as described below.
| Category | Provider |
|---|---|
| Cloud infrastructure and managed database (Postgres) | Supabase (managed Postgres, authentication, and edge compute) |
| Application and health-data servers | Operated by YoLongevity on dedicated managed infrastructure; health and biomarker data is held in our own database, separate from the general application database |
| Web hosting and content delivery | Cloudflare, Inc. (United States) — serves the website and app shell; does not access the CHD databases |
| Encrypted database backups | Supabase Storage (S3-compatible object storage). Holds scheduled backups of the health database. Each backup archive is AES-256 encrypted before upload; the decryption key is held solely by YoLongevity and is never stored with the backups or accessible to the storage provider |
| Payment processor | Stripe (PCI-DSS) — limited CHD context only |
| Transactional email | Resend (Resend, Inc., United States) — account and service emails sent from our sending domain |
| Onboarding and marketing email | Brevo (Sendinblue SAS, France) — only where you have opted in to such emails |
| Push notifications | Pushwoosh Inc. (United States) — delivers push notifications to your device; receives your device push token and the notification text, never lab results or raw health streams |
| AI foundation-model provider (personalized longevity-protocol generation pipeline; YO Coach and Readiness Coach chat; daily guidance) | Anthropic (Claude) — direct API integration; bound by a no-training commitment; provider-side retention limited to up to 30 days for service delivery and trust-and-safety review, then deleted |
| AI gateway for Google Gemini workloads (Trainer Coach chat; knowledge-base embeddings and retrieval support, incl. transient embedding of your message text for search; readiness narrative) | OpenRouter, Inc. (United States), routing to Google Gemini models — no-training terms; requests routed with logging disabled |
| Analytics (privacy-respecting; opt-in everywhere) | PostHog Inc. (United States) — product & website analytics. Receives no consumer health data: no health metrics, lab/wearable data, health topics, or AI-coach message content; no IP address; no session replay. DPF self-certified; SCC fallback |
| Optional messaging channels (only if you connect one) | Meta Platforms (WhatsApp Business Platform) or Telegram — if you explicitly connect a messaging channel for your coach conversation, the message content transits that provider's platform under its own terms; you can disconnect the channel at any time |
Each sub-processor is bound by a written Data Processing Agreement that includes CHD-aware terms: no use of CHD for the sub-processor's own purposes; deletion or return of CHD at the end of the engagement; security commitments at least equivalent to ours; assistance with consumer rights requests; and breach-notification obligations.
Notice of changes. When we add a new sub-processor that processes CHD — including replacing an existing sub-processor with a provider not previously on this list — we update the published list within 30 days of the change taking effect, and we notify active users by email before the new sub-processor begins processing CHD. Removing a sub-processor, or moving a processing task to a provider already on this list, does not create any new destination for your CHD; such changes are reflected in the published list within the same 30-day window, without individual email notice.
5.2 Wearable data partners
When you authorize a wearable connection (e.g., Oura, WHOOP, Garmin, Polar, Apple Health, Android Health Connect, Withings), CHD flows from the wearable to YoLongevity. The wearable vendor remains independently responsible for data on its side under its own privacy policy. You can revoke a wearable connection at any time from your account settings or from the wearable's app.
5.3 Lab partners
- Moleqlar (BioAge methylation/proteomic; NAD test) — a separate Moleqlar privacy policy applies to data on Moleqlar's side. YoLongevity receives results via API once you have authorized Moleqlar to share them.
- Other external labs (e.g., Synlab, Semmelweis Premium) — when you upload a PDF result, you remain the customer of that lab under its own privacy policy. We process the upload as a data input only.
5.4 Partner clinics (per-referral consent only)
When you request a referral to a partner clinic, we transmit the minimum necessary clinical context to enable the referral. The partner clinic operates independently, holds its own clinical license and malpractice insurance, and bears the clinical relationship with you. We do not direct or supervise the partner clinic's clinical decisions. See Terms of Service for full positioning.
5.5 Professional advisors and regulators
- External counsel and our external Data Protection Officer (DPO) — bound by professional duties of confidentiality.
- Regulators on lawful demand (subpoena, court order, regulatory inquiry).
5.6 Successor in a business transaction
In the event of a merger, acquisition, sale of assets, or similar transaction, CHD may be transferred to the successor entity. The successor will be bound by privacy commitments at least equivalent to those in this Policy. We will notify users by email and through an in-app banner before the transfer becomes effective, and we will offer affected users an opportunity to delete their CHD before transfer to the successor.
5.7 Certified Fitness Partners (sharing you direct)
If you choose to link a Certified Fitness Partner — an independent personal trainer you select — you can direct us, through four separate switches in your Personal settings, to show that trainer (1) your readiness data, (2) your biomarker results, (3) your meal logs, and/or (4) your daily plan and supplement schedule — that is, today's training, recovery, sleep and nutrition plan, your goals and daily routine, and today's supplement/vitamin schedule (what you take and when, as written in your plan). We share only the categories you switch on, only with the specific trainer you name, and only for as long as the switch stays on.
To help your trainer coach you, an AI coaching assistant may process the categories you have switched on. It is software, not a person and not a doctor; it helps your trainer read your data and plan training. What it does NOT receive: your lab and test results, the medical interpretation of your biomarkers, any risk or clinical flags, and your full medical (master) protocol — these stay with the YoLongevity medical team and are never sent to your trainer or the assistant. Neither your trainer nor the assistant can change your supplements, doses, or medical plan.
Your trainer is an independent recipient who decides how to use the data you share to coach you and is responsible for their own use of it; they are not a YoLongevity doctor and do not diagnose or treat you. They are contractually bound to keep your data confidential, use it only to coach you, never sell or pass it on, and delete it when you stop sharing. You can switch any category off at any time — your trainer and the assistant lose access immediately, and chat history that used the shared data is deleted within 30 days. We do not share any category you have not switched on.
No other sharing. We do not share CHD with any party not listed above. We do not sell CHD to any third party (see Section 7).
6. Your rights regarding Consumer Health Data
Plain-language summary. You can ask us what CHD we have on you (right to access). You can ask us to delete it (right to delete). You can withdraw the consent you gave us (right to withdraw). We respond within 30 days. You can also designate someone to act on your behalf, and you can appeal if we deny your request.
The rights below are guaranteed by law to residents of Washington (RCW 19.373.040), Nevada (NV SB 370), and Connecticut (Connecticut Data Privacy Act, Public Act 22-15, as amended by Public Act 23-56 — "CT SB 3"). YoLongevity extends these rights to all US users as a national baseline.
6.1 Right to access
You may ask us to confirm whether we are processing your Consumer Health Data and to provide a copy of the CHD we have collected, processed, or shared about you, together with the categories of recipients with whom it has been shared. We respond within 30 days. We may extend by an additional 30 days for unusually complex requests, with notice to you.
6.2 Right to delete
You may ask us to delete your Consumer Health Data. We honor verified deletion requests within 30 days.
The fastest path is in the app. The Delete account control in the Personal section of your account settings erases your account — including your Consumer Health Data — from our active systems immediately. The erasure of our health database runs first and is a hard precondition of the deletion: the deletion either completes, health data included, or does not run at all — in which case nothing is deleted, your account stays intact, and you can retry (or use the email channel). The full description of what is erased and what happens is in Section 7.2 of the main Privacy Policy.
Limited exceptions:
- Data we are required to retain to comply with legal, tax, or anti-money-laundering obligations (we will tell you the specific obligation when we invoke this exception).
- Data subject to a current dispute or legal hold.
- Data that has been de-identified in accordance with the standard at RCW 19.373.010 and is no longer reasonably linkable to you. We commit not to re-identify de-identified data and to require the same of recipients.
- Proof of the consents you gave or withdrew, and a minimal, tamper-evident record of the deletion itself — step counts, timestamps, and a one-way hash of your email address; no content and no health data — retained so we can demonstrate that the erasure was carried out and answer your later verification request.
- Deleted data may persist in encrypted disaster-recovery backups until those rotate out on our backup schedule (fully within approximately six months). Backups are used for no purpose other than disaster recovery, and if we ever restore from a backup we re-apply the deletion.
6.3 Right to withdraw consent
You may withdraw your consent to our collection, processing, or sharing of Consumer Health Data at any time. Withdrawal is as easy as giving consent — a single action in your account or a one-line email. Effects of withdrawal:
- We pause AI protocol generation that depends on the withdrawn category.
- We stop further processing of the CHD covered by the withdrawal.
- We notify any sub-processor that needs to act on the withdrawal.
- The lawfulness of past processing — done before withdrawal — is not affected.
- Withdrawal does not, by itself, entitle you to a refund of pre-paid subscription fees. See Terms of Service for refund mechanics.
6.4 How to exercise your rights
- Email:
chd-requests@yolongevity.com— the dedicated Consumer Health Data request channel. - In the app: manage wearable connections, Certified Fitness Partner sharing switches, and your consents directly in your account settings; delete your entire account with the Delete account control in your Personal settings (Section 6.2); deletion and access requests can be raised from any authenticated session.
- Postal: YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA, OR YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary.
Identity verification. We verify your identity in proportion to the sensitivity of the request. We do not require government-ID upload by default. For most requests, we verify by confirming control of the email address on the account or by verifying through an authenticated session in the app. For deletion of CHD, an authenticated session is the default verification path.
Authorized agents. You may designate an authorized agent — for example, a family member, attorney, or privacy-rights service — to submit a request on your behalf. We require:
- Written, signed authorization from you naming the agent and the specific request.
- Verification of the agent's identity by the same proportionate method we use for direct requests.
- Confirmation from you (when reasonably possible) that you authorized the request.
We may decline to act on an agent request only if we cannot reasonably verify the authorization or the agent's identity. We will tell you why if we decline.
No fee. No discrimination. The first request in any 12-month period is free. We may charge a reasonable fee for excessive or repetitive requests, with notice. We do not discriminate against you for exercising your rights — your access to the Service, the level of service, and your pricing are not affected.
6.5 Appeals
If we deny your request in whole or in part, you may appeal by emailing chd-appeals@yolongevity.com. We respond to appeals within 45 days with a substantive decision and the reasoning.
If we deny the appeal, we will provide instructions for filing a complaint with:
- Washington Attorney General —
CHD@atg.wa.govandhttps://www.atg.wa.gov/file-complaint - Nevada Attorney General —
https://ag.nv.gov - Connecticut Attorney General —
https://portal.ct.gov/AG - The appropriate authority in your state of residence.
7. We do not sell Consumer Health Data — and we will not without your separate authorization
Plain-language summary. The law prohibits us from selling CHD without a separate, signed authorization from you in a specific statutory form. Our actual operating rule is stricter: we do not sell CHD at all. If we ever change that, we will tell you 30 days in advance and we will not sell your CHD unless you separately and specifically sign the authorization.
Operational commitment. YoLongevity does not sell Consumer Health Data. We treat the statutory baseline (no sale without separate, signed authorization) as a floor; our actual practice is more restrictive.
7.1 What "sale" means here
For purposes of this Policy, "sale" means the exchange of Consumer Health Data for monetary or other valuable consideration. The MHMDA definition (RCW 19.373.010) is broad and may capture transfers that controllers in other contexts would not characterize as "sale."
The following are not "sales" under this Policy:
- Transfers to a sub-processor acting solely on our behalf under a Data Processing Agreement (Section 5.1).
- Transfers to wearable, lab, or partner-clinic recipients that you have authorized for the specific service in question (Sections 5.2–5.4).
- Disclosures to a Certified Fitness Partner that you have authorized through the per-category switches, and processing of those categories by the partner's AI coaching assistant on our behalf (Section 5.7).
- Disclosures to professional advisors and regulators (Section 5.5).
- Transfer to a successor in a business transaction (Section 5.6).
7.2 Our affirmative rules
- We do not exchange CHD with any third party for monetary or other valuable consideration.
- We do not enable third-party advertising or data brokerage based on CHD.
- We do not engage in cross-context behavioral advertising using CHD.
- All sub-processor relationships are strict processor relationships under written Data Processing Agreements with use limited to providing the contracted service.
7.3 If we ever change this
If our business model ever evolves to include any sale of Consumer Health Data, we will:
- Update this Policy at least 30 days before the change takes effect, with email notice and an in-app banner.
- Obtain a separate, statutorily-prescribed, signed authorization from each affected consumer before any such sale, in the form required by RCW 19.373.070 — including the description of the CHD to be sold, the name of the purchaser, the purpose of the sale, the expiration date of the authorization, and the consumer's signature.
- Honor withdrawal of authorization with the same ease as giving it, and stop the sale promptly upon withdrawal.
8. Geofencing prohibition
Plain-language summary. We do not use any geofence — a virtual boundary based on your location — within 2,000 feet of an in-person healthcare facility for any purpose connected to your CHD. This is a flat, no-exception prohibition.
In compliance with RCW 19.373.080, YoLongevity does not use a geofence around any in-person healthcare facility — including a hospital, clinic, doctor's office, pharmacy, laboratory, family-planning clinic, or any place that provides physical or mental health services — to:
- Identify or track consumers seeking health services.
- Collect Consumer Health Data from a consumer.
- Send notifications, alerts, advertisements, or messages to a consumer related to Consumer Health Data or to the consumer's seeking of health services.
- Build profiles or targeted-advertising audiences based on a consumer's proximity to a healthcare facility.
8.1 How we operationalize the prohibition
- The prohibition is documented in our marketing and product policies and is part of staff onboarding.
- We have configured our advertising-platform exclusions to prevent geo-targeted advertising near healthcare facilities.
- Our marketing-vendor contracts include a flow-down geofencing prohibition.
- We perform a quarterly internal audit of marketing campaigns against this prohibition.
8.2 Reporting violations
If you believe we have violated this prohibition, please email compliance@yolongevity.com. You may also file a complaint with the Washington Attorney General. We treat suspected geofencing violations as a Severity-1 compliance incident: triage within 24 hours, full investigation within 30 days, and remediation reported back to the reporter.
9. How we secure Consumer Health Data
Plain-language summary. We protect your CHD with strong technical and organizational safeguards — encryption, access controls, audit logging, vendor reviews, incident response, and regular testing. The full security disclosure is in our main Privacy Policy.
We maintain reasonable administrative, technical, and physical safeguards designed to protect Consumer Health Data, in compliance with RCW 19.373.050, the EU GDPR Article 32, and the security expectations of NV SB 370 and CT SB 3:
- Encryption at rest (AES-256 minimum) and in transit (TLS 1.3 or equivalent).
- Access controls — role-based access, least privilege, mandatory multi-factor authentication for all staff with access to CHD.
- Audit logging of all access to CHD — tamper-evident, retained for 24 months.
- Vendor security review — Data Processing Agreements and security questionnaires with all sub-processors.
- Incident response plan — detection, triage, DPO escalation, regulator and user notification within applicable deadlines.
- Annual third-party penetration testing.
For the full security disclosure, see the security section of the main Privacy Policy at https://yolongevity.com/privacy.
10. How long we keep Consumer Health Data
Plain-language summary. We keep CHD only as long as we need it to provide the service or as required by law. Specific retention periods are below. Verified deletion requests are honored within 30 days.
| CHD type | Retention period |
|---|---|
| Health and genetic data (questionnaires, lab uploads, Moleqlar results) | 7 years after last activity, then deletion or de-identification |
| Wearable raw streams | 90 days raw; aggregated wellness summaries for 7 years |
| Coach conversation store — messages, the files you attach to the coach, the rolling summary, the remembered facts and the action records (Section 4a) | For the life of your account, with no timed deletion of attachments; erased when you delete your account, on verified request within 30 days, or — for the material a Women's Health consent covered — on withdrawal of that consent |
| Staff working thread with our assistant about your record (Section 4a.6) | 365 days after the last time it was used, then deleted with its messages |
| A note a member of staff wrote on your record (Section 4a.6) | With the rest of your record — erased when you delete your account and by a verified deletion request |
| Public website assistant, no account (Section 4a.7) — the conversation, the anonymous session record and the abuse-prevention hashes | 30 days, deleted nightly; abuse-prevention counters after 7 days |
| An email address you leave with the public website assistant (Section 4a.7) | Kept until you ask us to delete it; detached from the conversation when that is deleted at 30 days |
| Conversations held by the older version of the public website assistant (Section 4a.7) | No timed deletion; retained until that system is retired, when they are deleted with it |
| Tier 2 / Tier 3 consultation recordings (where a consultation is recorded, with notice to you) | 7 years per our records-retention policy |
| Audit logs of CHD access | 24 months, tamper-evident |
Verified deletion requests are honored within 30 days (see Section 6.2), and deleting your account in the app (Section 6.2) erases your Consumer Health Data from our active systems immediately, ahead of the schedules above. Retention periods may be shorter where required by law, by your withdrawal of consent, or by your verified deletion request.
11. Public sub-processor list
Plain-language summary. The current list of vendors that process your CHD on our behalf is published in Section 5.1 of this Policy and is updated within 30 days of any change. We notify active users by email before any new CHD-relevant sub-processor starts processing their data; removing a vendor, or moving work to a vendor already on the list, only means your data goes to the same or fewer places, so those changes appear in the list without an email.
The current sub-processor list is published in Section 5.1 of this Policy (with the corresponding vendor disclosure in the main Privacy Policy). The list discloses, for each sub-processor:
- Name.
- Country of operation.
- Service provided.
- Categories of CHD accessed.
- Cross-border transfer mechanism, where applicable (DPF, SCCs, adequacy decision) — see also Section 5.1 and the main Privacy Policy's international-transfers section.
Every listed sub-processor operates under a written Data Processing Agreement (Section 5.1).
Change notice. The addition of a new CHD-relevant sub-processor — including a replacement by a provider not previously on the published list — is notified to active users by email before the new sub-processor begins processing CHD, and reflected in the published list within 30 days. Sub-processor removals, and moves of a processing task to a provider already on the published list, are reflected in the published list within the same window without individual email notice. A consumer who objects to a CHD-relevant sub-processor may withdraw consent under Section 6.3, which will pause processing that depends on the objected-to sub-processor.
12. Children
Plain-language summary. YoLongevity is for adults only.
You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18. We do not knowingly collect Consumer Health Data from anyone under 18. If we learn that we have collected CHD from a person under 18, we will delete it.
13. EU establishment, Data Protection Officer, and lead supervisory authority
Plain-language summary. EU/EEA/UK/Switzerland residents have additional rights and dedicated contacts. Our principal executive office is in Budapest, Hungary, so we are EU-established and NAIH is our lead supervisory authority. The Data Protection Officer is described in our main Privacy Policy.
For EU/EEA/UK/Switzerland residents, YoLongevity, Inc. is established in the European Union by virtue of its principal executive office at Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary, and is therefore subject to the GDPR under Article 3(1) and Recital 22. No Article 27 EU representative is required. Our lead supervisory authority under the GDPR one-stop-shop mechanism is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, "NAIH"), 1055 Budapest, Falk Miksa utca 9-11., Hungary, naih.hu. Our external Data Protection Officer is described in Section 1.3 of the main Privacy Policy at https://yolongevity.com/privacy and is competent to receive Consumer Health Data inquiries.
The rights in Section 6 of this Policy do not displace the rights you have under the GDPR, the UK GDPR, and the Swiss FADP. Where those laws give you broader rights — for example, the right to data portability, the right to object to processing based on legitimate interests, or the right to lodge a complaint with a supervisory authority — those rights also apply, as described in the main Privacy Policy.
14. Separate consent UI for Consumer Health Data
Plain-language summary. Before we collect any CHD, we present a clear, dedicated consent screen — separate from any general account terms — and we collect granular consent by data category and purpose. You can review and change your consents at any time in your account.
Per RCW 19.373.030 and analogous Nevada / Connecticut requirements, we obtain your affirmative, opt-in consent before we collect Consumer Health Data, except where the collection is strictly necessary to provide a product or service you have specifically requested.
How the consent UI works:
- The consent screen is presented separately from general account terms — not bundled into a single click-through.
- Consents are granular: you can opt in to each data category (questionnaire, wearable connection, lab upload, AI Coach inferences, partner-clinic referral) and each purpose (service delivery, wellness coaching, partner-clinic referrals, service improvement) independently.
- We use plain language — not pre-checked boxes, not buried links, not "dark patterns."
- Consent is specific to YoLongevity and our identified purposes — not a blanket "anything we want."
- A persistent consent dashboard in your account lets you review, modify, and withdraw consents at any time — withdrawal is as easy as giving consent (see Section 6.3).
- Material changes to the categories or purposes of CHD processing trigger a new consent flow before the new processing begins.
15. Notice of changes to this Policy
Plain-language summary. If we make a material change to this Policy, we tell you at least 30 days before it takes effect, by email and an in-app banner. For changes that affect your CHD in a meaningful way, we will re-obtain your consent before the change takes effect.
We may update this Consumer Health Data Privacy Policy from time to time.
- Material changes — including new categories of CHD, new purposes, new categories of recipients, longer retention, or any change that materially expands processing — are notified at least 30 days in advance by email and through an in-app banner.
- For material changes that require renewed consent under MHMDA, NV SB 370, CT SB 3, or applicable law, we will re-obtain consent through the consent UI described in Section 14 before the change takes effect for your account.
- Non-material changes (e.g., contact details, formatting, clarifications) take effect on the next published version. Continued use after the effective date constitutes acceptance for non-material changes.
- The version number and effective date always appear at the top of this Policy; a summary of the changes in any published version is available on request at
chd-requests@yolongevity.com.
16. Contact
| Purpose | Contact |
|---|---|
| Consumer Health Data requests, questions, complaints | chd-requests@yolongevity.com |
| Privacy generally | privacy@yolongevity.com |
| External Data Protection Officer | dpo@yolongevity.com |
| Compliance / report a suspected violation | compliance@yolongevity.com |
| CHD appeals | chd-appeals@yolongevity.com |
| Postal — Delaware (registered office) | YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA |
| Postal — Hungary (principal executive office) | YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary |
| Hungarian affiliate / joint controller | YoLongevity Hungary Zrt., 1025 Budapest, Nagybányai út 44., Hungary |
| EU lead supervisory authority | NAIH, 1055 Budapest, Falk Miksa utca 9-11., Hungary, naih.hu |
| Washington Attorney General | CHD@atg.wa.gov · https://www.atg.wa.gov/file-complaint |
| Nevada Attorney General | https://ag.nv.gov |
| Connecticut Attorney General | https://portal.ct.gov/AG |
17. Effective date and version
- Version: 1.19
- Effective date: 2026-09-18
- Last updated: 2026-09-18
- Language: The English-language version of this Policy is the controlling version. The English version prevails in case of conflict with any translation, except where a non-waivable local-language obligation applies.
- Companion documents: Privacy Policy · AI Transparency Notice · Cookie Policy · Terms of Service
