Legal · YoLongevity
Cookie Policy
YoLongevity Cookie Policy
Version: 1.18 Effective date: 2026-07-23 Last updated: 2026-07-23 Language: The English-language version of this Policy is the controlling version; it prevails over any translation in case of conflict.
Companion documents: Privacy Policy · Consumer Health Data Privacy Policy · AI Transparency Notice · Terms of Service
Cookie Preferences: A cookie consent banner is live, because YoLongevity uses analytics (PostHog) and — on public marketing pages only — advertising measurement & remarketing (Google Ads tag, Meta Pixel) in addition to strictly-necessary and first-party functional cookies/storage. Analytics and advertising are two separate consent categories, each off by default for every visitor, worldwide — each starts only after you explicitly accept that category in the banner (the banner's Settings layer offers per-category toggles). You can change your choices at any time via the "Cookie settings" link in our website footer, which reopens the consent banner; the "Do Not Sell or Share My Personal Information" footer link opens the same controls — see Current deployment status below and the full inventory in Section 4.
Quick contacts: privacy@yolongevity.com · DPO: dpo@yolongevity.com (served by external DPO-as-a-Service vendor) · Lead supervisory authority: NAIH (Hungary)
60-second summary
- We use cookies and similar technologies to make YoLongevity work, to remember your preferences, and — only with your explicit, per-category consent — to understand how you use the Services and to measure our advertising and show you relevant YoLongevity ads on Google and Meta platforms (remarketing).
- We do not sell personal information, we do not sell or share consumer health data through cookies, and we do not geofence healthcare facilities. Advertising tags run only on public marketing pages — never inside the logged-in application or the health questionnaire — and never receive names, e-mail addresses, or health data.
- Strictly necessary cookies are always on. Analytics and advertising are each off by default for every visitor, worldwide — including in the United States — and each starts only after you opt in to that category in the consent banner.
- If you opt in to the advertising category, a pseudonymous browser identifier is shared with Google and Meta — what US state privacy laws call "sharing" for cross-context behavioral advertising. You can opt out at any time via the "Do Not Sell or Share My Personal Information" link in our website footer, and we honor the Global Privacy Control (GPC) browser signal (Section 6).
- You can change your choices at any time by clicking the "Cookie settings" link in our website footer, which reopens the consent banner. Withdrawal is as easy as giving consent and takes effect immediately.
You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
Current deployment status (as of the effective date of v1.16)
As currently deployed, YoLongevity uses strictly-necessary cookies, first-party functional/preference storage, and — behind separate opt-in consents — analytics (PostHog) and advertising measurement & remarketing (Google Ads tag and Meta Pixel). The complete list is in Section 4. Analytics is configured for data-minimisation (no IP address, no session replay, no health data, no AI-coach message content). The advertising tags run only on public marketing pages — never inside the logged-in application, the questionnaire, or any page with health-related content — send no names, e-mail addresses, or health data, and are off by default for every visitor, worldwide: they start only after you opt in to the "Ad measurement & remarketing" category in the consent banner. We do not use Enhanced Conversions, Advanced Matching, server-side conversion APIs, or fingerprinting techniques.
Because analytics and advertising are non-essential technologies, a cookie consent banner is live and a first-party consent mechanism is in operation. No PostHog analytics cookie or storage is created and no event is sent unless and until you opt in to analytics; no advertising cookie is created — and the Meta Pixel is not loaded at all — unless and until you opt in to the advertising category. This applies to every visitor, worldwide, not only in strict-consent jurisdictions such as the EU, UK and Switzerland. Strictly-necessary storage, and first-party preference storage that only records a choice you explicitly make (such as your interface language), do not require consent under Article 5(3) of the ePrivacy Directive and equivalent rules.
PostHog processes analytics data in the United States; the transfer relies on the EU–US Data Privacy Framework (PostHog Inc. is self-certified), with Standard Contractual Clauses as a fallback — see the Privacy Policy and, for U.S. residents, the Consumer Health Data Privacy Policy. Where the advertising vendors (Google Ireland Ltd. / Google LLC; Meta Platforms Ireland Ltd. / Meta Platforms, Inc.) process personal data in the United States, the transfer safeguards described in Section 7 apply.
1. Who we are and what this Policy covers
In plain language: this Cookie Policy explains how YoLongevity uses cookies and similar tracking technologies on our websites, web app, mobile apps, and marketing emails. We — YoLongevity, Inc., a Delaware corporation, together with our Hungarian affiliate YoLongevity Hungary Zrt. — are the data controller (and joint controller for certain wellness-coaching activities) for the personal data collected through these technologies.
1.1 Identity of the controller
YoLongevity, Inc., a Delaware corporation (Delaware File No. 10568801; date of incorporation 2026-03-31; EIN 38-4392504), with registered office at 131 Continental Dr, Suite 305, City of Newark, County of New Castle, Delaware 19713, USA, and principal executive office at Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary ("YoLongevity", "we", "us", "our"), is the data controller for all personal data collected through cookies, local storage, pixels, mobile SDKs, server-side identifiers, fingerprinting techniques (where used), push notification tokens, and similar technologies described in this Policy.
YoLongevity, Inc. is the global contracting party with users worldwide. YoLongevity Hungary Zrt. (Cégjegyzékszám 01-10-140516; Adószám 27093708-2-41; EU VAT HU27093708; registered office 1025 Budapest, Nagybányai út 44., Hungary) is the Hungarian affiliate that holds exclusive Hungarian commercial rights and employs or engages the medical staff and the Wellness Coaching Personnel (the Chief Medical Officer and the supervising physician team, together with the degreed dietitians — each a degreed nutrition professional — who serve as the primary human point of contact for wellness coaching and any other suitably qualified personnel engaged for that purpose under the oversight of the supervising physician team) who provide wellness coaching to Tier 2 Transform and Tier 3 Elite users globally. For the personal data processed by these staff in the course of wellness coaching, YoLongevity, Inc. and YoLongevity Hungary Zrt. act as joint controllers under Article 26 of the GDPR.
1.2 EU establishment and lead supervisory authority
YoLongevity, Inc. is established in the European Union by virtue of its principal executive office at Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary, and is therefore subject to the General Data Protection Regulation under Article 3(1) and Recital 22. Because we have an EU establishment, no Article 27 EU representative is required.
The Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, "NAIH"), with offices at 1055 Budapest, Falk Miksa utca 9-11., Hungary, telephone +36 1 391 1400, website naih.hu, is our lead supervisory authority under the GDPR one-stop-shop mechanism for cross-border processing.
National privacy law supplement: the Hungarian Privacy Act ("Infotv.") — Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information — applies in addition to the GDPR for matters within Hungarian jurisdiction.
1.3 UK supervisory authority
For users in the United Kingdom, the UK Information Commissioner's Office (ICO) is the supervisory authority for cookie consent and PECR compliance in the UK; see Section 11.
1.4 Scope
This Policy applies to:
- the YoLongevity public website at
https://yolongevity.comand any sub-domains; - the YoLongevity web application;
- the YoLongevity mobile applications for iOS and Android;
- emails, transactional messages, and marketing communications we send (including embedded tracking pixels, where applicable); and
- any embedded YoLongevity widget that we operate on a third-party website.
If there is any conflict between this Policy and the runtime consent banner, the more user-protective disclosure governs.
1.5 How this Policy fits our other documents
This Cookie Policy is one of five core legal documents:
| Document | What it covers |
|---|---|
| Privacy Policy | General data processing, lawful bases, retention, your rights |
| Consumer Health Data Privacy Policy | Washington MHMDA, Nevada SB 370, Connecticut SB 3 — consumer health data specifically |
| AI Transparency Notice | EU AI Act Article 50 disclosures, AI logic, AI provider |
| Terms of Service | Subscription terms, tiers, refunds, governing law |
| This Cookie Policy | Tracking technologies, consent, opt-outs |
1.6 Fingerprinting stance
Where we use or permit any device-fingerprinting, browser-fingerprinting, or canvas-fingerprinting technique (whether first-party or third-party), we treat it as a tracking technology subject to the same consent requirements as cookies in the same category. We do not deploy fingerprinting to circumvent ePrivacy or GDPR consent. Where any such technique is used, it is enumerated in the per-cookie inventory (Section 4) and gated by our consent banner (Section 5). As of the effective date of this Policy, no fingerprinting technique is in production use.
2. What cookies and similar technologies are
In plain language: "cookies" is a shorthand for several different small pieces of data and software that read or write to your device. They all serve similar functions and we treat them all under the same consent rules.
In this Policy, "cookies" is shorthand for all of the following:
- HTTP cookies — small text files placed in your browser when you visit a website.
- Local storage and session storage (including IndexedDB) — similar mechanisms that store data inside your browser.
- Pixels and web beacons — small embedded images (often 1×1 transparent pixels) used to record that a page or email was opened.
- Mobile SDKs — software components inside our mobile applications that perform similar functions to web cookies.
- Mobile device identifiers — Apple's Identifier for Advertisers (IDFA) and Google's Android Advertising ID (AAID). YoLongevity does not collect IDFA or AAID for advertising purposes (see Section 5).
- Server-side identifiers — session tokens and similar identifiers issued by our servers; we treat these with consent rules equivalent to client-side cookies where they are used to recognize you across visits.
- Fingerprinting techniques — device, browser, canvas, audio, or font fingerprinting (see Section 1.6).
- Server-side conversion APIs — for example, Meta's Conversions API ("CAPI") or Google Enhanced Conversions (see Section 5.6).
- Push notification tokens — device tokens issued by Apple, Google, or web push services to deliver notifications (see Section 5.3).
We also distinguish between:
- First-party cookies (set by YoLongevity directly on our domain) and third-party cookies (set by a vendor on our pages or in our app).
- Session cookies (deleted when you close your browser) and persistent cookies (stored on your device for a defined duration). We do not set first-party persistent cookies with a duration longer than 13 months without renewed consent (per the French CNIL deliberation 2020-091 reference standard).
ePrivacy law is technology-neutral: a pixel, a fingerprint, an SDK identifier, and a server-side conversion event have the same legal status as a cookie when they are used to read from or write to your device. We treat them accordingly.
3. Categories of cookies we use
In plain language: there are four categories. Strictly necessary is always on. Consent-based functional items, analytics, and marketing are each opt-in — for every visitor, worldwide. Marketing on YoLongevity means the Google Ads tag and the Meta Pixel on our public marketing pages only; it never involves health data and never runs inside the logged-in application — see Sections 3.4 and 6.
3.1 Strictly necessary
Required for the Services to work. Cannot be disabled. Examples:
- Session token (login state)
- CSRF token (security protection)
- Load-balancer routing cookie
- The cookie that records your cookie consent itself, so we don't ask you on every page
Lawful basis: Article 5(3) ePrivacy Directive exception ("strictly necessary" for a service explicitly requested by the user) + GDPR Article 6(1)(b) (contract) or Article 6(1)(f) (legitimate interest, security).
The "strictly necessary" exemption is narrow. We construe it strictly per CNIL and EDPB guidance. Analytics cookies are NOT strictly necessary, even when they are anonymized or used by us for legitimate-interest measurement — analytics is a separate consent category (Section 3.3). Functional and preference cookies are also not strictly necessary. Marketing is never strictly necessary.
3.2 Functional / preferences
Make the Services more usable. Examples:
- Language preference
- Display preference (dark mode, units, accessibility settings)
- Transient screen state (for example, an open chat thread) during your visit
Where a functional item does nothing more than store a choice you explicitly make (for example, remembering the interface language you selected), it falls within the Article 5(3) "explicitly requested by the user" exemption and no separate consent is required. Any functional item that goes beyond recording your own explicit choices requires opt-in consent in the EU/UK/Switzerland before it is set.
Lawful basis: Article 5(3) ePrivacy Directive (user-requested exemption, or consent where the exemption does not apply); GDPR Article 6(1)(b) (contract) or Article 6(1)(a) (consent).
3.3 Analytics
Status: in use — PostHog. We use PostHog (PostHog Inc., United States) for product and website analytics. It is off by default for every visitor, worldwide, and starts only after you accept analytics in the consent banner — we apply the EU opt-in standard globally, including in the United States. The PostHog storage entries (beginning ph_) are listed in Section 4.
Analytics helps us understand how the Services are used so we can improve them. What we collect via PostHog:
- Pseudonymous page-view and session tracking (no IP address stored)
- Feature-engagement and click events (no input values; no health data; no AI-coach message content)
- Coarse technical metadata (browser, OS, referrer)
We do not record your IP address, do not use session replay, and our analytics events carry no special-category (health) data. URLs sent to PostHog are sanitised so that no health-revealing path or query string is transmitted.
Lawful basis: Article 5(3) ePrivacy Directive consent (EU/UK/Switzerland); GDPR Article 6(1)(a) consent. Following CNIL and Garante 2022–2024 enforcement guidance, we do not load Google Analytics for EU users without separate consent, and where we use any analytics provider that processes EU personal data in the United States we rely on the EU-US Data Privacy Framework or EU Standard Contractual Clauses (see Section 7).
3.4 Marketing
Status: in use — Google Ads and Meta Pixel, on public marketing pages only. With your prior opt-in to the "Ad measurement & remarketing" category, we use the Google Ads tag (gtag.js, Google Ireland Ltd. / Google LLC) and the Meta Pixel (Meta Platforms Ireland Ltd. / Meta Platforms, Inc.) to (a) measure which of our ads lead to signups, waitlist joins, and contact requests, and (b) build remarketing audiences of visitors to our public marketing pages (for example, visitors of the pricing page), so we can show YoLongevity ads to those visitors on Google and Meta platforms. This means that, for consenting visitors only, an identifier from your browser is shared with Google and Meta for advertising purposes — including what US state privacy laws call "sharing" for cross-context behavioral advertising (see Section 6).
Until you opt in, the Google tag operates in cookieless consent-mode (aggregate, non-identifying pings used for conversion modelling; no advertising cookies are set) and the Meta Pixel is not loaded at all.
Lawful basis: Article 5(3) ePrivacy Directive consent (EU/UK/Switzerland); GDPR Article 6(1)(a) consent — applied as opt-in for every visitor, worldwide.
What we explicitly do NOT do (operational commitments): we do not send names, e-mail addresses, or any account or health data to advertising platforms (no Enhanced Conversions, no Advanced Matching, no Customer Match uploads, no server-side conversion APIs); we do not run advertising tags inside the logged-in application, the health questionnaire, or any page with health-related content; we do not build audiences based on health conditions or health-related pages; we do not share cookie-derived data with data brokers; we do not use cookies to associate health data with advertising profiles; and we do not geofence healthcare facilities (Section 6). For visitors in the relevant US states, we enable Meta's Limited Data Use processing restriction.
3.5 Wearable and health-data SDKs — outside the cookie regime
The wearable-data streams you authorize (for example, heart-rate variability, sleep, activity, glucose data from Oura, WHOOP, Apple HealthKit, Google Health Connect, Withings, or similar), and any laboratory results you upload to YoLongevity, are processed under the Privacy Policy and the Consumer Health Data Privacy Policy — not under the cookie regime described here.
Cookie consent and your cookie preferences do not control your wearable or lab-data flows. Those flows are governed by separate, specific consents inside the Services. Withdrawing cookie consent does not disable a wearable integration; you must withdraw the wearable authorization separately in your account settings. Where a wearable SDK stores identifiers in your device storage, we treat that storage with cookie-equivalent consent (opt-in in the EU/UK/Switzerland; per-device authorization globally).
YoLongevity is not a Covered Entity, not a Business Associate, not a healthcare provider, not a clinical laboratory, and not a pharmacy. The handling of health-related data is described in the Consumer Health Data Privacy Policy.
4. Cookie and local-storage inventory (Appendix A)
In plain language: this is the complete list of the cookies and browser storage YoLongevity actually uses today. Everything is first-party except the PostHog analytics entries and the advertising entries (Google, Meta), each created only after you opt in to its category. Advertising items are set only on public marketing pages, never inside the logged-in application.
This inventory is maintained manually and updated whenever we add, remove, or change a cookie or storage item. As explained in Section 2, we treat HTTP cookies, local storage, and session storage under the same rules, so all three are listed together below. Items marked "(mobile app only)" exist only inside the YoLongevity iOS/Android app.
As of the effective date of this Policy, every item below is either strictly necessary, functional/preference, analytics (the PostHog entries, gated behind the analytics opt-in), or marketing (the Google Ads and Meta Pixel entries, gated behind the separate ad-consent opt-in). Marketing items (Google Ads, Meta Pixel) exist only behind the separate ad-consent opt-in and run only on public marketing pages. There are no cross-context tracking technologies outside those listed marketing items, and no fingerprinting technologies in use. If we add any further item, we will list it here and gate it behind consent (see Current deployment status and Section 5) before it goes live.
| Name | Provider | Purpose | Category | Type | Duration |
|---|---|---|---|---|---|
sb-<project-ref>-auth-token | YoLongevity via Supabase (1P) | Keeps you signed in (authenticated session / login state). During sign-in and password-reset flows, short-lived companion entries with the same prefix (ending -code-verifier and -user) may briefly exist and are removed automatically | Strictly necessary | Local storage | Until sign-out or token expiry |
site_language | YoLongevity (1P) | Remembers your selected interface language | Functional | Local storage | Until changed |
yl-swipe-hint-shown | YoLongevity (1P) | Remembers that a one-time swipe hint was shown during this visit | Functional | Session storage | Session |
yolo_play_login_splash | YoLongevity (1P) | One-time flag so the welcome animation plays right after you sign in, and not on later page loads | Functional | Session storage | Session |
yolo_onboarding_return | YoLongevity (1P) | Remembers where you left the guided onboarding flow during your visit, so you can resume it after viewing another page | Functional | Session storage | Session; self-clearing |
yolo_onb_autostart:<entry-id> | YoLongevity (1P) | One-time per-device flag recording that your guided onboarding was already auto-started, so it is not restarted on every visit | Functional | Local storage | Persistent |
yolo_trainer_ui_session | YoLongevity (1P) | Holds transient Trainer chat screen state during your visit | Functional | Session storage | Session |
yolo_coach_ui_session | YoLongevity (1P) | Holds transient Coach chat screen state during your visit | Functional | Session storage | Session |
yolo_session_sync_debug | YoLongevity (1P) | Diagnostic flag, present only if you manually enable session-sync debugging | Strictly necessary | Session storage | Session |
yolo_boot_diag | YoLongevity (1P) | Local toggle for app-startup (sign-in) diagnostics. While we investigate a reported sign-in defect, the app sends us technical startup and authentication-state events (your account identifier and timing/sign-in-state details only — no health data, no message content) to help us reproduce and fix it; this is a time-limited troubleshooting measure. The stored item is written only if startup debugging is manually enabled or disabled (?boot_diag=1 / ?boot_diag=0) | Strictly necessary | Local storage | Persistent until you clear it |
yolo:native-health-device-id | YoLongevity (1P) | Stable per-device identifier used to pair your device for wearable / health-data sync (mobile app only) | Strictly necessary | Local storage | Persistent |
native-health:last-foreground-sync-at | YoLongevity (1P) | Timestamp of your last health-data sync, used to avoid redundant syncs (mobile app only) | Functional | Local storage | Persistent |
yolo_capacitor_context | YoLongevity (1P) | Records that the app is running inside the native mobile shell (mobile app only) | Strictly necessary | Session storage | Session |
yolo_pushwoosh_pending_deep_link | YoLongevity (1P) | Briefly holds the destination of a push notification you tapped while the app was starting, so the app can open the right screen (mobile app only) | Strictly necessary | App preferences (native) | Until consumed |
yolo_pushwoosh_pending_user_id | YoLongevity (1P) | Briefly holds your account identifier while the push-notification service finishes initializing, so notifications reach the right device (mobile app only) | Strictly necessary | App preferences (native) | Until consumed |
ph_<project-key>_posthog | PostHog Inc. (US) — first-party | Stores the pseudonymous PostHog device/distinct identifier and session identifier so repeat analytics events attribute to the same browser. No health data, no names, no message content. Created only after analytics opt-in | Analytics | HTTP cookie (1P) | 12 months (rolling) |
ph_<project-key>_posthog | PostHog Inc. (US) — first-party | Mirrors/extends the cookie value in browser storage: distinct ID, device ID, session ID, active feature-flag values, super properties. No health values, no message content | Analytics | Local storage (1P) | Persistent; purged on withdrawal (opt_out_capturing() + reset()) |
__ph_opt_in_out_<project-key> | PostHog Inc. (US) — first-party | Records your PostHog capture opt-in/opt-out state (1/0) so the SDK respects your choice across page loads | Functional / consent-record | HTTP cookie or local storage (1P) | ~1 year |
_gcl_au | Google (1P, set for Google Ads) | Conversion linker — helps attribute a signup/waitlist/contact conversion to the Google ad you clicked. Created only after ad-consent opt-in | Marketing | HTTP cookie (1P) | 90 days |
_gcl_aw | Google (1P) | Stores the Google Ads click identifier (GCLID) when you arrive via a Google ad, for conversion attribution. Created only after ad-consent opt-in and only on ad-click visits | Marketing | HTTP cookie (1P) | 90 days |
_fbp | Meta Platforms (1P, set by Meta Pixel) | Pseudonymous browser identifier used by the Meta Pixel for ad measurement and remarketing-audience membership. Created only after ad-consent opt-in | Marketing | HTTP cookie (1P) | 90 days |
_fbc | Meta Platforms (1P) | Stores the Meta ad click identifier (fbclid) when you arrive via a Meta ad, for conversion attribution. Created only after ad-consent opt-in and only on ad-click visits | Marketing | HTTP cookie (1P) | 90 days |
yolo_ads_conv_<action> | YoLongevity (1P) | Prevents double-counting an ad conversion during a visit | Functional | Session storage | Session |
yolo_consent | YoLongevity (1P) | Stores your cookie-banner choices (analytics and ad-consent choices per category) with a timestamp and policy version, so we can prove and respect your choices and suppress each consent-based category until you opt in — for every visitor, worldwide | Strictly necessary (consent management) | Local storage (1P) | Persistent until you change the choice |
yolo_readiness_narrative_v1 | YoLongevity (1P) | Briefly caches the plain-language explanation of your current readiness state on your device, so we do not regenerate the same text every time you reload the page. Holds only the short explanation, not your underlying health metrics | Functional | Local storage (1P) | ~10 minutes (refreshed when your readiness changes) |
yolo_dna_coach_sid | YoLongevity (1P) | Random identifier that groups your messages with the YoLo Coach helper on our public pages (marketing site and DNA content portal) into one conversation, so the coach can follow the thread and so we can review conversation quality. Contains no name, email, or account information | Functional | Local storage (1P) | Persistent until you clear browser data |
yolo_dna_coach_state | YoLongevity (1P) | Remembers how far your conversation with the YoLo Coach helper has progressed (a message counter and a yes/no flag indicating whether you already left an email address), so the chat resumes where you left off after a page reload. Tied to the yolo_dna_coach_sid identifier; contains no message content, no email address, and no account information | Functional | Local storage (1P) | Persistent until you clear browser data |
Infrastructure note. Our hosting and backend providers may set their own strictly-necessary cookies or tokens that are essential to deliver the Services you request: Cloudflare (static hosting / CDN / security — for example, bot-management and load-balancing cookies) and Supabase (authentication backend). These are operational and security cookies, not analytics or advertising. <project-ref> in the session-token name above is your environment's Supabase project reference.
You can use YoLongevity with strictly-necessary cookies and storage only; the functional items above simply remember preferences and improve usability. If you spot a cookie at YoLongevity that does not appear in this inventory, please contact us at privacy@yolongevity.com so we can resolve the discrepancy.
5. How we ask for and manage your consent
In plain language: on your first visit, our cookie banner asks whether you accept analytics and ad measurement & remarketing — you can decide separately for each in the banner's Settings layer. "Accept" and "Only necessary" are equally prominent. Nothing is pre-ticked. You can change your mind at any time via the "Cookie settings" link in the footer.
5.1 The cookie banner
Status: the banner is live, because YoLongevity uses analytics (PostHog) and advertising measurement & remarketing (Google Ads tag, Meta Pixel) in addition to strictly-necessary and first-party functional storage (see Section 4 and Current deployment status). On your first visit to the Services in any browser or device:
- A prominent banner appears at the bottom of the page.
- The banner does not pre-tick anything, and no analytics or advertising technology runs before you decide.
- The "Accept" and "Only necessary" buttons appear at the same level and with the same visual prominence, in line with EDPB Guidelines 03/2022 on deceptive design and the recommendations of CNIL, AEPD, and Garante.
- The banner offers per-category controls: "Analytics" and "Ad measurement & remarketing" can be accepted or refused independently in the banner's Settings layer; "Accept" grants both, "Only necessary" refuses both, with equal prominence.
- A "Details" link in the banner opens this Cookie Policy, including the full inventory in Section 4.
- Strictly necessary cookies are always on and are described in this Policy.
We do not use cookie walls (forced consent in exchange for access). Continued browsing does not constitute consent. We do not bundle consent across categories.
5.2 How consent is managed
Consent is managed by our own first-party consent banner — no third-party Consent Management Platform is involved, so your consent choice itself is never shared with an external vendor. The mechanism:
- your choice is stored per category, with a timestamp and the version of this Policy in force, in the
yolo_consentitem (see Section 4), so we can respect and evidence your choice under GDPR Article 7(1); - each consent-based category's tooling is loaded and allowed to write storage only after you accept that category — until you opt in, nothing in the analytics category runs, the Google tag operates only in cookieless consent-mode (no advertising cookies set), and the Meta Pixel is not loaded at all;
- because the advertising category is new in v1.16, a consent given under an earlier version of this Policy does not extend to advertising: we ask you again before any advertising tag runs;
- we re-ask for consent on material changes (a new vendor, a new consent-based category, or a substantive change to this Policy);
- we honor the Global Privacy Control (GPC) signal: where your browser sends GPC, the advertising category is treated as refused (see Section 6.1);
- withdrawing analytics consent immediately stops analytics capture and purges the PostHog identifiers from your device; withdrawing advertising consent immediately stops the advertising tags, so no further data is sent to Google or Meta from your browser.
If we ever introduce additional non-essential or third-party tracking technologies, we will extend this consent layer (or deploy a dedicated Consent Management Platform) and update this Policy before they go live.
IAB TCF v2.2 participation
YoLongevity does not currently participate in the IAB Europe Transparency and Consent Framework (TCF v2.2 or any successor version). We do not transmit a TCF consent string and do not rely on TCF Vendor List signals for any cookie or vendor decision. If we ever join an ad-tech ecosystem that depends on TCF, we will disclose participation here, list our CMP-ID, and integrate the framework consent string into our consent layer.
5.3 Changing your choice at any time
You can reopen the consent banner at any time via the "Cookie settings" link in the footer of our public website pages. The "Do Not Sell or Share My Personal Information" footer link opens the same controls (see Section 6.1).
You can change your choice at any time with the same ease as giving consent. Withdrawal takes effect immediately for prospective processing: analytics capture stops at once and the PostHog identifiers are deleted from your device as part of the withdrawal itself, without waiting periods. If anything prevents the automatic deletion, you can also clear the items listed in Section 4 through your browser's site-data controls.
5.4 Mobile device controls
In our mobile applications:
- Apple App Tracking Transparency (ATT): if a screen on iOS prompts you to allow tracking across apps, your choice is honored. If you select "Ask App Not To Track", we do not engage in cross-app tracking.
- Android user-consent prompts: honored equivalently.
- We do not use device fingerprinting to re-identify users who have refused ATT.
- We do not set or use any IDFA or AAID for advertising purposes.
- We do not load advertising or ad-attribution SDKs that do not respect user opt-out.
5.5 In-app SDKs
The YoLongevity iOS and Android apps embed only the software components needed to deliver the Services you request: authentication and secure session storage, push notifications (Pushwoosh — see Section 5.7), and the health-data synchronization you explicitly authorize (Apple HealthKit / Android Health Connect). The device-storage items these components create are marked "(mobile app only)" in the Section 4 inventory. The apps embed no advertising, ad-attribution, or cross-context tracking SDKs. If we add an SDK that reads or writes device storage for a new purpose, we will list its storage in Section 4 and, where consent is required, gate it behind the consent banner before it goes live.
5.6 Server-side conversion APIs
Some advertising platforms accept conversion events directly from a server rather than from a browser cookie or pixel — for example, Meta Conversions API ("CAPI") and Google Enhanced Conversions. If we ever transmit a conversion event to such a server-side API, we treat the event as inheriting your cookie-marketing consent state: without your prior opt-in to the marketing category (Section 3.4), no server-side conversion event is sent for you. We do not use server-side conversion APIs to bypass the consent layer.
As of the effective date of this Policy, server-side conversion APIs are not in production use. This disclosure is conservative.
5.7 Push notification tokens
Push notification tokens (Apple Push Notification service tokens, Firebase Cloud Messaging tokens, web push tokens) are device identifiers, managed for YoLongevity by our push-notification provider Pushwoosh Inc. (see the Privacy Policy for details). We treat them as similar technologies subject to consent rules equivalent to the corresponding cookie category:
- Operational push (for example, "your AI protocol has been updated") is sent under contract or legitimate-interest basis with a granular opt-out in app settings;
- Marketing push is sent only after your prior opt-in;
- Push notification tokens are not used for cross-context behavioral advertising and are not shared with ad-tech vendors.
6. United States — sale/sharing posture and health-data positions
In plain language: US visitors get the same protection as everyone else — analytics and advertising are each off unless you switch them on. We never sell personal information. If you opt in to advertising, a pseudonymous browser identifier is shared with Google and Meta; you can switch that off at any time via the "Do Not Sell or Share My Personal Information" footer link, and we honor the GPC browser signal. We never sell or share consumer health data through cookies, and we never geofence healthcare facilities.
6.1 No sale; "sharing" only after your opt-in — and how to opt out
Under California's CCPA/CPRA and the parallel state privacy laws (Colorado, Connecticut, Maryland, New Jersey, Oregon, Minnesota, Montana, and others), businesses that sell personal information or share it for cross-context behavioral advertising must offer opt-outs, honor universal opt-out signals such as the Global Privacy Control (GPC), and post a "Do Not Sell or Share My Personal Information" link.
YoLongevity does not sell personal information. If — and only if — you opt in to the "Ad measurement & remarketing" category, we "share" (in the CCPA/CPRA sense) a pseudonymous browser identifier with Google and Meta for cross-context behavioral advertising. You can opt out of this sharing at any time, with immediate effect, via the "Do Not Sell or Share My Personal Information" link in our website footer (which opens the same cookie-settings control), and we honor the Global Privacy Control (GPC) browser signal as a valid opt-out: where GPC is present, the advertising category stays off regardless of any stored choice. Because advertising tags are opt-in for every visitor worldwide, no sharing ever occurs unless you have first enabled it yourself. We never sell or share consumer health data through any tracking technology (Sections 6.4–6.5), and advertising tags never run on health-related pages.
6.2 If our practices ever change
If we ever begin selling personal information (we have no plans to), or sharing personal information for cross-context behavioral advertising beyond the consent-based advertising described in Section 6.1, we will — before any such processing starts — update this Policy, post any additionally required opt-out links, continue to honor the GPC signal as a valid universal opt-out, and provide single-click opt-out paths as required by the state privacy laws listed above.
6.3 "Limit the Use of My Sensitive Personal Information" — Limit-SPI
We honor the "Limit the Use of My Sensitive Personal Information" right under the CCPA/CPRA. If any cookie or tracking technology infers or reveals health-related characteristics — a Sensitive Personal Information ("SPI") category — that cookie is flagged as SPI-bearing in our per-cookie inventory. A user-submitted Limit-SPI request automatically applies to all SPI-flagged tracking technologies, in addition to backend SPI processing.
As of the effective date of this Policy, no YoLongevity cookie is intended to infer health-related characteristics. We provide this disclosure conservatively to cover any future cookie or third-party SDK that falls within scope.
6.4 No geofencing within 2,000 feet of healthcare entities
YoLongevity does not, and does not permit any partner or vendor through any cookie, mobile SDK, server-side identifier, fingerprinting technology, or push notification token to, establish a geofence within 2,000 feet of any in-person healthcare service location, including hospitals, clinics, mental-health facilities, reproductive-health facilities, or any place that provides healthcare services, for the purpose of identifying or tracking consumers seeking healthcare services, sending notifications regarding such services, or building consumer-health-data profiles.
This is the explicit posture mandated under Washington's My Health My Data Act, RCW 19.373.020 (and parallel provisions in Nevada SB 370 and Connecticut SB 3). We apply this posture nationally — to every US user — and globally as an operational standard.
6.5 No sale or share of consumer health data via cookies
YoLongevity does not sell, rent, lease, or share for cross-context behavioral advertising any consumer health data through any cookie, pixel, mobile SDK, server-side identifier, fingerprinting technique, or push notification token. This commitment is independent of, and in addition to, the Consumer Health Data Privacy Policy. Our cookie banner, our first-party consent layer, and our per-cookie inventory all enforce this posture: no data-broker cookie is ever set, served, or activated by YoLongevity for any user, regardless of consent state; and the advertising cookies described in Section 3.4 exist only behind your explicit opt-in, never carry health data, and never run on health-related pages, the health questionnaire, or the logged-in application.
6.6 Ad-platform sensitive-category exclusions
Where an advertising platform offers a "sensitive category" or health-exclusion mechanism (for example, Meta's sensitive-category prohibitions), we configure our account and campaign settings to exclude health and health-adjacent categories. This is operationalized in our cookie-vendor onboarding checklist.
7. International data transfers
In plain language: when a third-party cookie or SDK provider sends data outside the EEA or the UK, we use legal mechanisms to protect it: the EU-US Data Privacy Framework, EU Standard Contractual Clauses, and (for UK transfers) the UK International Data Transfer Agreement.
For third-party cookie, pixel, or SDK providers located outside the EEA:
- Vendor participation in the EU-US Data Privacy Framework (DPF) preferred. Where a vendor is self-certified under the DPF (as PostHog Inc. is), we rely on that adequacy mechanism and verify the vendor's DPF status.
- EU Standard Contractual Clauses (SCCs) where DPF participation is not available — typically Module 2 (controller-to-processor) or Module 3 (processor-to-processor).
- Cookie data transferred internationally is minimized. We prefer first-party cookies; third-party cookies are used only where necessary for the Service.
7.1 Transfer Impact Assessment (TIA)
For each cookie, SDK, or pixel provider whose transfer of personal data outside the EEA cannot rely on the EU-US Data Privacy Framework adequacy decision, YoLongevity:
- (a) executes the EU SCCs;
- (b) conducts a documented Transfer Impact Assessment evaluating the legal regime of the destination country, the practical likelihood of disclosure to third-country authorities, and the supplementary measures applied — technical (encryption, pseudonymization), organizational (provider-side challenge of overbroad requests), and contractual (SCC-mandated commitments);
- (c) refreshes the TIA at least annually and on any material change.
Our TIAs are maintained in our internal records of processing and are available to supervisory authorities on request.
7.2 UK transfers
For transfers of UK personal data to a country lacking UK adequacy, YoLongevity uses the UK International Data Transfer Agreement (UK IDTA) issued by the UK ICO, or alternatively the EU SCCs supplemented by the UK International Data Transfer Addendum to the EU SCCs. Where the UK Extension to the EU-US Data Privacy Framework covers the destination importer, that extension serves as the lawful transfer basis.
7.3 Right to obtain a copy of the safeguards
You have the right to request a copy of the safeguards we use for international transfers. Contact privacy@yolongevity.com or our external Data Protection Officer at dpo@yolongevity.com (see Section 11).
8. AI personalization and cookies
In plain language: cookie data is not used to train AI models. If we ever use a cookie to feed our AI, we will say so first. Cross-context behavioral advertising profiles are never sent into our longevity AI.
8.1 No cookie data used to train AI models
Data collected through cookies, local storage, pixels, mobile SDKs, server-side identifiers, fingerprinting techniques, or push notification tokens is NOT used to train YoLongevity's own AI models, and is NOT passed to any third-party Large Language Model (LLM) provider for training their foundation models or any fine-tuned variant. The third-party AI providers used by YoLongevity are disclosed by name in the AI Transparency Notice §5.1 — currently Anthropic (Claude, direct API) for the protocol-generation pipeline and the YO Coach and Readiness Coach chat interfaces, and Google Gemini models accessed through the OpenRouter gateway (OpenRouter, Inc., United States) for the Trainer Coach chat and knowledge-base search support. Cookie-derived data is isolated from those AI providers and from the AI training pipeline by design. This commitment mirrors the no-training commitments in our AI Transparency Notice and our Privacy Policy.
8.2 If a cookie ever feeds the AI personalization layer
As of the effective date of this Policy, no cookie or similar tracking technology feeds inputs into the YO Coach AI personalization layer. If we ever begin using cookie-derived data as an input to that layer (for example, to remember a UI preference that influences how the AI presents protocols), we will:
- disclose that change in the per-cookie inventory (Section 4);
- update this Policy at least 30 days before such use begins; and
- gate the use on consent.
8.3 No advertising profiles fed back into the longevity AI
YoLongevity does not permit any cross-context behavioral advertising profile, ad-tech segment, data-broker enrichment, or third-party tracking-derived inference to be ingested into the longevity AI as an input or signal — regardless of consent state. Our AI inputs are limited to data you provide directly (self-reported, lab uploads, wearable authorizations) and our framework knowledge base. Tracking-technology data is structurally isolated from the AI personalization layer.
9. Children
In plain language: YoLongevity is for adults 18 and over. We do not knowingly use cookies to collect data from minors.
You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
We do not knowingly use cookies, pixels, SDKs, fingerprinting techniques, push notification tokens, or other tracking technologies to collect data from minors. Our services are not directed at children, and the cookie banner and preference center contain no child-targeted features.
Where any third-party advertising network's cookie or tag would, by default, target or collect data from users believed to be minors (for example, a "general audience" configuration that includes under-18 segmentation), YoLongevity affirmatively disables that default in the network's configuration on our properties. This is a positive operational duty, independent of the broader 18+ eligibility gate, and is part of our cookie-vendor onboarding checklist.
As of the effective date of this Policy, the third-party advertising technologies in production use are the Google Ads tag and the Meta Pixel, on public marketing pages only and behind the separate advertising opt-in (Section 3.4). In our Google and Meta advertising accounts we target adults only (18+) and affirmatively exclude under-18 segments wherever the platform provides such a control.
10. Updates to this Cookie Policy
In plain language: we tell you in advance when we materially change cookie practices, and we ask for new consent when there are new categories or vendors.
Material changes to this Policy — for example, a new vendor category, a new tracking technology, a change in the legal basis for processing, or a change to the consent UI — are notified at least 30 days in advance by email and via an in-app banner, and we will re-ask for your consent for the new categories or vendors before they go live. The 30-day notice mirrors the material-change definition in our Privacy Policy.
Routine changes to the cookie inventory (for example, a new sub-version of an existing analytics SDK or removal of a vendor) are reflected in the Section 4 inventory of this Policy as they happen — the version and "Last updated" date at the top of this Policy tell you when it last changed.
Version history: the version number and effective date always appear at the top of this Policy; a summary of the changes in any published version is available on request at privacy@yolongevity.com.
10.1 Forward-looking note: ePrivacy Regulation
The European Commission's proposed ePrivacy Regulation is intended to replace the current ePrivacy Directive 2002/58/EC and may change the technical and procedural requirements for cookie consent in the EU. We will update this Policy and our consent mechanics when the ePrivacy Regulation enters into force, and we are committed to honoring forthcoming W3C-level browser signals as they are adopted.
11. Contact and complaints
In plain language: contact our privacy team or our external Data Protection Officer for any cookie-related question. You can also lodge a complaint with a data-protection regulator. Our lead supervisory authority is NAIH (Hungary).
11.1 Contact us
- Privacy and cookie questions:
privacy@yolongevity.com - Data Protection Officer:
dpo@yolongevity.com(served by external DPO-as-a-Service vendor) - Postal — Delaware (registered office): YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
- Postal — Hungary (principal executive office): YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary
- Hungarian affiliate / joint controller: YoLongevity Hungary Zrt., 1025 Budapest, Nagybányai út 44., Hungary
- Lead supervisory authority: NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság), 1055 Budapest, Falk Miksa utca 9-11., Hungary, naih.hu.
11.2 Right to lodge a complaint
You have the right to lodge a complaint with a competent supervisory authority concerning our processing of personal data through cookies and similar technologies.
- EU/EEA: the supervisory authority of your country of habitual residence, your place of work, or the place of the alleged infringement. A directory is available at edpb.europa.eu/about-edpb/about-edpb/members_en. For Hungarian users by default, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) at naih.hu.
- United Kingdom: the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. The ICO is the supervisory authority for cookie consent and PECR compliance in the UK.
- Switzerland: the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
- United States: state attorneys general for state privacy law (for example, the California, Colorado, Connecticut, Texas, Maryland, and Washington state attorneys general) and the Federal Trade Commission for federal consumer-protection issues. For Washington consumer-health-data matters, see also our Consumer Health Data Privacy Policy.
We encourage you to contact us first at privacy@yolongevity.com so we can attempt to resolve any concern directly, but you are not required to do so before contacting a regulator.
End of Cookie Policy v1.16.
