Legal · YoLongevity
Privacy Policy
YoLongevity Privacy Policy
Effective date: 2026-07-24 Last updated: 2026-07-24 Version: 1.17
Companion documents:
Contact at-a-glance:
- General privacy:
privacy@yolongevity.com - Data Protection Officer:
dpo@yolongevity.com - Lead supervisory authority: NAIH (Hungary) — see Section 1.2
- Privacy requests:
privacy@yolongevity.comand the Privacy Settings section of your account — see Section 8.5
0.1 The 60-second summary
This is the short version. The full policy below has the detail. If anything in the summary and the full text appear to conflict, the full text controls.
- We process your health data only to deliver the YoLongevity wellness service. We do not sell it. Ever.
- We use AI to generate your personalized longevity protocol. We tell you when you are talking to AI, what data it sees, and what it does not do.
- Your data is hosted in the European Union. Where a US-based provider is involved (payments, analytics, AI processing), it receives only what its service needs, and the transfer is protected by that provider's EU–US Data Privacy Framework certification or by Standard Contractual Clauses.
- You can export, correct, or delete your data at any time. We honor verified requests within 30 days.
- YoLongevity is a wellness service, not a medical service. YoLongevity is not a Covered Entity, not a Business Associate, not a healthcare provider, not a clinical laboratory, and not a pharmacy.
1. Who we are and how to reach us
We are YoLongevity, a wellness company. This section tells you who controls your personal data, who is the joint controller for our wellness-coaching activities, how to contact us and our Data Protection Officer, and which EU authority is our lead supervisor.
1.1 Controllers
Primary controller and global contracting party. YoLongevity, Inc., a Delaware corporation (Delaware File No. 10568801; date of incorporation 2026-03-31; EIN 38-4392504). Registered office: 131 Continental Dr, Suite 305, City of Newark, County of New Castle, Delaware 19713, USA (registered agent: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713; phone 302-894-8922). Principal executive office: Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary.
YoLongevity, Inc. is the global contracting party with users worldwide and is the data controller for personal data processed in connection with the Services. All invoices for YoLongevity services are issued by YoLongevity, Inc. (Delaware, USA), regardless of the user's country of residence.
Hungarian affiliate and joint controller for wellness-coaching activities. YoLongevity Hungary Zrt. (full Hungarian name: YoLongevity Hungary Zártkörűen Működő Részvénytársaság; English name: YoLongevity Hungary Closed Company by Shares; Cégjegyzékszám 01-10-140516; EUID HUOCCSZ.01-10-140516; Adószám 27093708-2-41; EU VAT HU27093708; original incorporation 2019-10-24, originally MEDICAL HOLDING Zrt., renamed 2026-04-14), with registered office (székhely) at 1025 Budapest, Nagybányai út 44., Hungary, holds exclusive commercial rights for Hungary and employs or engages the medical staff (the Chief Medical Officer and the supervising physician team) and the Wellness Coaching Personnel — the degreed dietitians (each a degreed nutrition professional) who serve as the primary human point of contact for wellness coaching, together with any other suitably qualified personnel engaged for that purpose, in each case acting under the oversight of the supervising physician team — who provide wellness coaching to Tier 2 Transform and Tier 3 Elite users globally.
For these wellness-coaching activities, YoLongevity, Inc. and YoLongevity Hungary Zrt. act as joint controllers under Article 26 of the GDPR. The contact point for all data subject rights remains YoLongevity, Inc. via the contact channels in §1.3 and §8.5. The full Article 26 joint controller arrangement is documented internally; its essence is summarized in Section 9.1.1 of this Policy. YoLongevity Hungary Zrt. is not a contracting party with users (all contracting and invoicing is performed by YoLongevity, Inc. globally) and is not a healthcare facility — Nagybányai 44 is the registered office only, with no in-person service delivery there.
1.2 EU establishment and lead supervisory authority
YoLongevity, Inc. is established in the European Union by virtue of its principal executive office at Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary, and is therefore subject to the General Data Protection Regulation under Article 3(1) and Recital 22. The Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, "NAIH"), with offices at 1055 Budapest, Falk Miksa utca 9-11., Hungary (telephone +36 1 391 1400; website naih.hu), is our lead supervisory authority under the GDPR one-stop-shop mechanism for cross-border processing.
Because YoLongevity, Inc. has an EU establishment, no Article 27 EU representative is required. The Hungarian Privacy Act (Infotv. — Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information) applies in addition to the GDPR for matters within Hungarian jurisdiction.
For users in the United Kingdom, the UK Information Commissioner's Office (ico.org.uk) is the supervisory authority. For users in Switzerland, the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch) is the supervisory authority.
1.3 Data Protection Officer
We have appointed an external Data Protection Officer because we process special-category health and genetic data on a large scale (Article 37(1)(c) GDPR). You can contact our DPO directly:
- Email:
dpo@yolongevity.com - Postal: YoLongevity, Inc., Attn: DPO, Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary
The DPO is independent, reports to our board (Sole Director: Zsigmond Bodnár), and you are free to contact the DPO without going through any other YoLongevity channel. Communications to the DPO are confidential.
1.4 Privacy contact channels
For any other privacy question or request, write to privacy@yolongevity.com — the primary channel for access, deletion, correction, opt-out, and right-to-limit requests — or use the Privacy Settings section of your account for the consents and connections you can manage directly. Postal requests are also accepted (Section 19); email and postal mail are our designated request methods under California law and other state laws.
2. What this Privacy Policy covers — and what it does not
This policy covers how YoLongevity handles your personal data. It does not cover what happens to your data once it is in the hands of a partner clinic, a wearable manufacturer, or a third-party laboratory — those organizations have their own privacy notices.
2.1 What is covered
This Privacy Policy applies to:
- The YoLongevity website (
yolongevity.com) and any sub-domains - The YoLongevity mobile and web applications
- The YO Coach AI assistant and all in-product AI features
- Communications with our dietitians and supervising physicians on the YoLongevity platform (the YoLongevity-side data flow only)
- Wearable-device integrations (Oura, WHOOP, Garmin, Polar, Apple Health, Android Health Connect, Withings, and similar) once you have authorized them
- Laboratory result uploads (PDFs you provide directly)
- Partner-clinic referral flows (the YoLongevity-side data flow only)
2.2 What is not covered
- External partner clinics that receive a referral from us — those clinics process your data under their own privacy notices and applicable law (HIPAA in the US, GDPR in the EU, etc.)
- Moleqlar (BioAge methylation/proteomic testing, NAD testing, supplements) — Moleqlar processes your sample and results under its own privacy policy
- Wearable manufacturers (Oura, WHOOP, Garmin, Polar, Apple, Withings, and others) — manufacturers process your raw device data under their own privacy policies before sending us only what you have authorized
- External laboratories (Synlab, Semmelweis Premium, and any other lab whose PDF results you upload) — labs process your sample under their own notices
2.3 HIPAA non-applicability
YoLongevity is not a Covered Entity, not a Business Associate, not a healthcare provider, not a clinical laboratory, and not a pharmacy. The data we process is not Protected Health Information within the meaning of the United States Health Insurance Portability and Accountability Act (HIPAA). HIPAA does not apply to us.
This is an unconditional positioning. If at any future point we need to enter a Business Associate Agreement with a covered entity to enable a specific feature, we will notify you and obtain separate consent before that data flow begins.
2.4 Consumer Health Data Privacy Policy — homepage prominence
For Washington, Nevada, and Connecticut residents — and as our nationwide US baseline — the Consumer Health Data Privacy Policy at https://yolongevity.com/consumer-health-data-privacy describes the additional rights and protections that apply to your consumer health data. That document is presented at the same prominence as this Privacy Policy on our homepage and on every page where consumer health data is collected, in line with Washington Revised Code § 19.373.020(2). If you live in Washington, Nevada, or Connecticut, please read that document together with this one.
3. Categories of personal data we collect
This section lists every category of data we collect, where it comes from, and whether it counts as "special category" data under Article 9 GDPR or "Sensitive Personal Information" under California law. Health data, genetic data, and biometric data carry the strongest protections.
3.1 Identity and contact data
- What: name, email address, phone number, postal address, date of birth (used to verify you are at least 18 years old)
- Source: directly from you
- Special category? No
- Lawful basis (EU): performance of contract, Article 6(1)(b) GDPR
3.2 Account and authentication data
- What: username, password hash (we never store your plaintext password), multi-factor authentication tokens, device identifiers, IP address, login timestamps
- Source: directly from you and automatically collected when you use the service
- Special category? No
- Lawful basis (EU): performance of contract, Article 6(1)(b); legitimate interest in security, Article 6(1)(f); legal obligation under Article 32 to secure personal data
3.3 Self-reported health and lifestyle data — special category
- What: biological sex, medical history questionnaire responses, current medications, allergies, prior conditions, family medical history, lifestyle questionnaire (sleep, nutrition, stress, exercise, alcohol, tobacco, supplements)
- Source: directly from you
- Special category? Yes — "data concerning health" under Article 9 GDPR. Sensitive Personal Information under California's CPRA. Consumer Health Data under Washington's MHMDA, Nevada's SB 370, and Connecticut's SB 3.
- Lawful basis (EU): explicit consent under Article 9(2)(a) GDPR, in addition to performance of contract under Article 6(1)(b)
3.4 Laboratory, biomarker, and genetic data — special category
- What: blood-panel and urine-panel results you upload as PDFs; Moleqlar BioAge methylation and proteomic results; NAD test results; other biomarker uploads (organic acids, hormones, micronutrients, oxidative-stress markers, inflammation markers, etc.)
- Source: uploaded by you; received from Moleqlar via API integration after you have authorized it; received from external laboratories (Synlab, Semmelweis Premium, and others) when you upload their PDF reports
- Special category? Yes — "data concerning health" under Article 9 GDPR. The Moleqlar BioAge methylation and proteomic panel is also "genetic data" within the meaning of Article 4(13) and Recital 34 GDPR. Sensitive Personal Information under California's CPRA. Consumer Health Data under Washington's MHMDA.
- Lawful basis (EU): explicit consent under Article 9(2)(a) GDPR, in addition to performance of contract under Article 6(1)(b)
Genetic-data commitment (US): We will never voluntarily share your genetic data with employers, insurers, or any party that could use it for discriminatory purposes — even where a future change in law might otherwise permit such sharing. This commitment is consistent with the spirit of the United States Genetic Information Nondiscrimination Act (GINA). The only exception is a valid, binding legal order that compels disclosure, which we review and challenge as described in Section 9.7.
3.5 Wearable and connected-device data
- What: sleep stages, heart-rate variability, resting heart rate, readiness, recovery, strain, body temperature, activity, ECG-derived heart-rhythm context (for wellness only, not diagnostic), weight, body composition, blood pressure
- Sources: Oura Ring; WHOOP; Garmin; Polar; Apple Watch and Apple Health; Android Health Connect; Withings; and similar device platforms you authorize
- Special category? Yes by derivation — when this data is used to draw a wellness inference about your health or sleep, it constitutes "data concerning health" under Article 9 GDPR. Consumer Health Data under MHMDA.
- Lawful basis (EU): explicit consent under Article 9(2)(a) (you authorize each device separately) plus performance of contract
Apple HealthKit ring-fence: if your data reaches us through Apple HealthKit, we never use it for advertising or marketing, never share it with third parties for advertising or marketing, and never disclose it to data brokers, in line with Apple's HealthKit terms.
Android Health Connect ring-fence: if your data reaches us through Android Health Connect, we use it only to provide the health and fitness features you request, never for advertising, never for sale, and never for any use prohibited by Google's Health Connect permissions policy. You can revoke Health Connect permissions at any time in the app or in Health Connect settings.
WHOOP connection: when you connect WHOOP, we access your WHOOP data through the WHOOP API only after you grant access on WHOOP's OAuth consent screen, and only for the scopes you approve (recovery, sleep, workout/activity, physiological cycle, profile, and body measurements). We use it solely to compute your daily readiness, personalize your protocol and coaching, and display your metrics and trends. We never sell WHOOP data and never use it for advertising. You can disconnect WHOOP at any time in the app (connected devices → revoke access), which revokes our access token at WHOOP and deletes the WHOOP-sourced data we hold; deleting your account purges all WHOOP tokens and WHOOP-derived data.
3.5.1 Connected calendar data (Google Calendar)
- What: if you connect Google Calendar, we access your calendar events — event start and end times, busy/free status, and, where relevant to a given feature, event titles and Google Meet conferencing details — focused on your current-day schedule.
- Source: the Google Calendar API, accessed only after you grant access on Google's OAuth consent screen and only for the scopes you approve: reading your calendar events, and — when you schedule a session with us — creating a calendar event with a Google Meet link on your behalf.
- Special category? No. Calendar entries are ordinary personal data; we do not use them to infer health information.
- Lawful basis (EU): performance of contract, and your consent — you authorize the Google connection separately and can withdraw it at any time.
- Purpose: we use your calendar data solely to give your coach real-time context about your day (so it does not suggest activities while you are busy) and, at your request, to schedule coaching or protocol sessions and attach a meeting link. We read this data per request to render your coaching and protocol; we do not build a separate long-term archive of your calendar history.
Google API Limited Use. YoLongevity's use and transfer to any other app of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide and improve the calendar-aware coaching and scheduling features described above. We do not sell this data; we do not use it for advertising; we do not transfer it to others except as necessary to provide or improve these features, for security purposes, to comply with applicable law, or as part of a merger or acquisition; we do not allow humans to read it except where you explicitly grant permission, where necessary for security or to comply with applicable law, or on data that is aggregated and anonymized; and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. You can disconnect Google Calendar at any time in the app, under your connected-accounts settings, which revokes our access at Google; deleting your account purges the Google authorization tokens we hold.
3.6 AI-generated protocol data
- What: the personalized longevity protocols our AI generates for you (nutrition, sleep, exercise, stress, supplement and lifestyle recommendations); version history of your protocol; protocol adjustments over time; physician-validation notes for Tier 2 and Tier 3 users
- Source: generated by our AI system from your inputs and our framework knowledge base; reviewed and validated by a licensed physician for Tier 2 and Tier 3 users
- Special category? Treated as health data because it is derived from health inputs
- Lawful basis (EU): performance of contract; explicit consent for the underlying health-data inputs
- More detail: see our AI Transparency Notice
3.7 Communications and interaction data
- What: transcripts and recordings of dietitian calls (Tier 2 and Tier 3); transcripts and recordings of physician question-and-answer consultations (Tier 2 single Q&A; Tier 3 ongoing); your chat history with YO Coach (text and metadata); emails, in-app messages, support tickets; and, where you explicitly connect an optional messaging channel, your coach conversation over WhatsApp or Telegram (see Section 9.1)
- Source: directly from you and from our staff
- Special category? Yes, where the content concerns your health
- Lawful basis (EU): performance of contract; separate explicit consent for any audio or video recording, taken at the start of each session
3.8 Anthropometric self-assessment data
- What: weight, body-mass index (BMI), waist and hip circumference, blood pressure, resting heart rate, body composition (InBody, Withings), grip strength
- Source: directly from you, on the schedule recommended for your tier
- Special category? Yes — health data under Article 9 GDPR
- Lawful basis (EU): explicit consent under Article 9(2)(a) plus performance of contract
3.9 Payment and subscription data
- What: card type, last four digits of your card, billing address, transaction history, subscription tier, renewal status
- Source: directly from you and from our payment processor (Stripe)
- Special category? No
- Lawful basis (EU): performance of contract; legal obligation (tax and anti-money-laundering retention)
- Note: we never store your full card number or your card-verification value. These are handled exclusively by our PCI DSS-certified payment processor.
3.10 Device, log, and usage data
- What: IP address, device type, operating system, browser, session timestamps, in-app actions, error logs, performance telemetry
- Source: automatically when you use the service
- Special category? No
- Lawful basis (EU): legitimate interest, Article 6(1)(f) (security and product reliability); legal obligation under Article 32
3.11 Cookies and similar technologies
- See our Cookie Policy for the full inventory and the consent mechanism. Categories: strictly necessary, functional, analytics (we use no marketing cookies).
- All users, worldwide: analytics is off by default and starts only after you accept it in the consent banner — we apply the EU opt-in standard globally, including in the United States.
- We do not sell or share personal information through cookies, so US state-law "sale/sharing" opt-outs have no data flows to act on (see Section 8.4).
3.12 Inferred and derived data
- What: AI-generated insights, biological-age estimates, readiness state, wellness-baseline deviations, risk-flag prompts (which surface in-app and may suggest a physician consultation)
- Source: generated by our system from the data you provide
- Special category? Treated as health data because it is derived from health inputs
- Lawful basis (EU): performance of contract; explicit consent for the underlying special-category inputs
3.13 What we do not collect
- We do not collect data we do not need (the data-minimization principle, Article 5(1)(c) GDPR).
- We do not collect children's data — YoLongevity is 18+ only. You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
- We do not collect biometric identifiers within the meaning of the Illinois BIPA or California CPRA. We do not capture fingerprints, do not perform facial-recognition matching, and do not capture voiceprint matching. Audio recordings of consultations (Section 3.7) are stored as audio files for service-delivery and documentation purposes only and are not used to build a voiceprint identifier.
- We do not infer your race, religion, sexual orientation, political beliefs, or trade-union membership from your health data.
4. Lawful bases for processing (GDPR Article 6 and Article 9)
The EU GDPR requires us to identify a "lawful basis" for every processing activity, and a separate one for any special-category processing. This section maps each activity to its basis.
4.1 Lawful-bases matrix
| Processing activity | Article 6 basis | Article 9 basis (if applicable) |
|---|---|---|
| Account creation, login, service delivery | (b) Contract | n/a |
| Personalized AI longevity-protocol generation | (b) Contract + (a) Consent | (a) Explicit consent |
| Physician validation of AI protocols (Tier 2 / Tier 3) | (b) Contract + (a) Consent | (a) Explicit consent |
| Wearable data ingestion and analysis | (b) Contract + (a) Consent | (a) Explicit consent |
| Laboratory result and Moleqlar genetic-data processing | (b) Contract + (a) Consent | (a) Explicit consent |
| Dietitian interactions (Tier 2 / Tier 3) | (b) Contract + (a) Consent | (a) Explicit consent |
| Physician question-and-answer consultations | (b) Contract + (a) Consent | (a) Explicit consent |
| Recording of consultations | (a) Consent (separately collected at the start of each session) | (a) Explicit consent |
| Partner-clinic referral with data sharing | (a) Consent (per-referral, separate, specific) | (a) Explicit consent |
| Disclosure of your daily plan + supplement schedule (and the other categories you switch on) to your Certified Fitness Partner, and processing of those categories by our AI coaching assistant, at your direction | (a) Consent (per-category, default-off, withdrawable; also your instruction); international transfer to the AI sub-processor on the basis of your explicit consent, Art 49(1)(a) | (a) Explicit consent — Art 9(2)(a) |
| Aggregated, de-identified statistical analysis | (f) Legitimate interest | (j) Scientific or statistical purposes with safeguards |
| Fraud prevention and security monitoring | (f) Legitimate interest | n/a |
| Tax, accounting, anti-money-laundering retention | (c) Legal obligation | n/a |
| Service announcements (transactional emails) | (b) Contract | n/a |
| Marketing emails | (a) Consent (opt-in for EU/UK/CH) | n/a |
4.2 Legitimate-interest balancing test (summary)
Where we rely on legitimate interest under Article 6(1)(f), we have run a balancing test. The two main legitimate-interest categories:
- Security and fraud prevention. Necessary to protect you and us from unauthorized access, account takeover, and abuse. Limited to log data and metadata; no special-category data is processed under this basis.
- Aggregated de-identified analytics. Used only after the data has been irreversibly de-identified (per Recital 26 GDPR). Aggregated counts, distributions, and trends — never individual records.
If you would like a copy of the full legitimate-interest assessment for any specific activity, write to dpo@yolongevity.com.
4.3 Withdrawal of consent (Article 7(3) GDPR)
You can withdraw any consent at any time. Withdrawal is as easy as giving consent in the first place. You can manage every consent in the Privacy Settings section of your account or by writing to privacy@yolongevity.com.
- Withdrawal takes effect prospectively only — it does not affect the lawfulness of processing that already happened before withdrawal.
- Withdrawing consent does not automatically entitle you to a refund. Refund mechanics are governed by our Terms of Service, Sections 5.4 and 5.5.
4.4 Consequences of withdrawing your Article 9 consent
If you withdraw your explicit consent under Article 9(2)(a) for health-data processing:
- We will pause AI protocol generation and all health-data-driven features.
- Your account will continue to function in a limited form — you can still log in, see your historical data, export it, and ask for deletion.
- We will not delete your existing health data automatically; we will retain it under the schedule in Section 7 unless you separately request deletion under Section 8.
- You can re-enable processing at any time by re-confirming consent in your Privacy Settings.
5. Why we process your data — purposes
This section describes the purposes for which we process your data. We will not later use your data for a different, unrelated purpose without first telling you and, where required, obtaining your consent.
We process your personal data for these purposes:
- Service delivery. Generate, deliver, and adjust your AI longevity protocol for your tier (Life Coach / Transform / Elite); coordinate dietitian and physician interactions where included; maintain the availability of the service.
- Wellness coaching support. Translate AI insights into actionable lifestyle guidance; monitor adherence; document interactions in our internal documentation system.
- Partner-clinic referrals. Where a wellness conversation surfaces something that may need a clinical evaluation, we offer to refer you to a partner clinic. This requires a separate, specific, per-referral consent that you give at the moment of referral. We transmit the minimum necessary clinical context to the clinic.
- Wearable and laboratory integrations. Receive data from authorized devices and laboratories; process for protocol adjustment.
- Payment and subscription management. Process billing, renewals, cancellations, and refunds in line with our Terms of Service.
- Service improvement and research. Aggregated, de-identified analytics. Identifiable data is used in research only with your separate explicit opt-in through a Research Consent form, which you may revoke at any time.
- AI model evaluation and quality assurance. Our medical and product teams review AI outputs for quality. We do not use your data to train external or third-party AI models without your separate explicit opt-in for US users; for EU users, we never use your data to train external models by default. See our AI Transparency Notice.
- Fraud prevention, security, and compliance. Detect abuse, prevent unauthorized access, comply with applicable law.
- Communications. Transactional service announcements (no opt-out — these are necessary to operate your account); marketing communications only with your opt-in for EU/UK/Swiss users, and on an opt-out basis for US users.
- Legal compliance. Retain records to comply with tax, accounting, anti-money-laundering, and regulatory inquiries.
5.1 Our promises to you — the affirmative "we do not"
- We do not sell your personal data.
- We do not sell your consumer health data. (See the Consumer Health Data Privacy Policy.)
- We do not share your health data with advertising partners.
- We do not use your health data for behavioral advertising.
- We do not train external AI models on your data without your separate opt-in — and never for EU users by default.
- We do not monetize your data through third-party data brokers.
- We do not geofence healthcare facilities to target consumers (in line with MHMDA).
6. AI processing — summary and pointer to the AI Transparency Notice
We use AI to generate your personalized longevity protocol. This summary covers the most important points. Our standalone AI Transparency Notice gives you the full picture, including our LLM provider, retention windows, model evaluation, and your AI-specific rights.
6.1 You are interacting with AI (EU AI Act Article 50(1))
The YO Coach assistant and certain in-product features are AI systems, not humans. We mark every AI interaction clearly in the user interface so you always know when you are talking to AI and when you are talking to a human dietitian or physician.
6.2 What our AI does and does not do
Our AI does:
- Generate a personalized longevity protocol from your data and our framework's wellness knowledge base
- Adjust your protocol when you log new data
- Surface wellness-baseline deviations and prompt a physician consultation where appropriate
Our AI does not:
- Diagnose disease
- Prescribe medication
- Make clinical decisions
- Classify itself as Medical Device Software (MDSW) under the EU Medical Device Regulation
- Replace a doctor
For Tier 2 and Tier 3 users, a licensed physician validates the AI output from a wellness-validation perspective before it is activated for you. For Tier 1 (Life Coach) users, the service is fully self-directed — there is no routine human review; you can request a non-clinical framework-compliance review (an "AI Review Request") at any time, free of charge once every six months (see the AI Transparency Notice §7.2).
6.3 LLM providers and AI subprocessors
Our AI architecture uses the following upstream providers:
- Anthropic (Claude) — the foundation large-language model integrated directly (not via a gateway or agent platform) for the personalized longevity-protocol generation pipeline (submitted through Anthropic's asynchronous batch-processing API), the YO Coach (longevity) and Readiness Coach (recovery and wellness) chat interfaces, and our daily-guidance generation, under a Data Processing Agreement with a no-training commitment.
- OpenRouter, Inc. (United States), routing to Google's Gemini models — an AI gateway used for defined workloads: the Trainer Coach (exercise and training) chat interface; the knowledge-base embeddings and retrieval support (to search our knowledge base during a chat, your message text is translated and embedded via the gateway); the short readiness narrative; and internal content processing. OpenRouter is contractually barred from training on request content and routes our requests with logging disabled; a documented fallback configuration also allows the other coaches to run through the gateway, under the same terms.
Each provider — and the OpenRouter gateway — is contractually prohibited from training its own foundation or fine-tuned models on YoLongevity user inputs. Every API call runs in the shortest-commercially-available retention configuration for its workload; the precise configuration is documented in the AI Transparency Notice §5.1 (which controls for AI-provider retention specificity). The full subprocessor list, including the LLM providers and the gateway, is published in Section 9.1 of this Policy and in Section 5.1 of the Consumer Health Data Privacy Policy, and is updated within 30 days of any change.
6.4 Article 22 GDPR — your right not to be subject to fully-automated decisions
YoLongevity does not make decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of Article 22(1) GDPR. Our AI generates educational wellness recommendations; it does not deny you a service, approve or deny a benefit, set a price for you individually, or make any binding decision about you.
To the extent that the personalized AI protocol could be characterized as automated decision-making with similarly-significant effect:
- Tier 1 users consent under Article 22(2)(c) to receive AI-generated longevity protocols with no routine human review, and we honor your right to:
- Express your point of view
- Contest the AI's output
- Request human review at any time — the "AI Review Request", a non-clinical framework-compliance check by YoLongevity non-medical staff, free of charge once every six months (see the AI Transparency Notice §7.2). Where a deeper review is warranted, we will recommend an upgrade to a physician-reviewed tier or a consultation with your own physician.
- Tier 2 and Tier 3 users receive ongoing human oversight by design — a licensed physician validates protocol changes from a wellness-validation perspective.
To request human review, write to privacy@yolongevity.com or use the in-app "Request human review" button on any AI-generated protocol.
6.5 AI hallucination warning
Like any AI system, our AI can produce inaccurate output. Never rely on AI output for a clinical decision about yourself or anyone else. Always consult a qualified healthcare professional before making significant changes to your health regimen. This warning is also in our Terms of Service, Section 3.4.
6.6 AI training opt-in (US users)
US users may opt in to allow their de-identified data to be used to improve our internal models. The default is off. You can change this setting in your Privacy Settings at any time. EU, UK, and Swiss users are never opted in by default, and we never train external models on your data.
6.7 More detail
For our LLM provider, retention windows, model-evaluation methodology, AI-specific rights under the EU AI Act and GDPR Article 22, and our risk-classification rationale, see our AI Transparency Notice.
7. How long we keep your data — retention periods
We keep your data only as long as we need it for the purpose we collected it for, with two exceptions: legal-retention obligations (tax, anti-money-laundering) and ongoing legal holds.
7.1 Retention matrix
| Data category | Retention period | Why |
|---|---|---|
| Account and profile data | Active account + 90 days after cancellation | Service continuity and refund window |
| Health data (Article 9) | 7 years after last activity, then deletion or de-identification | Conservative alignment with EU MDR § 10.8 medical-records analog and US state professional-records norms (CA 7 years, NY 6 years) |
| Laboratory results, including Moleqlar genetic data | 7 years (same as health data) | Same |
| Wearable raw data streams | 90 days | Reduce raw-data exposure |
| Wearable aggregated daily and weekly summaries | 7 years | Preserve longitudinal wellness analytics |
| YO Coach chat history | Active account + 12 months | Recall and product-quality value |
| Consultation recordings (Tier 2 / Tier 3) | 7 years | Documentation of the conversation |
| Payment and billing records | 7 years | US tax law and EU AML obligations |
| Audit logs (security and Article 9 data access) | 24 months | Article 32 GDPR and security need |
| AI inference logs (inputs / outputs / metadata) | 24 months (extended for active investigation, contestation, or regulatory inquiry) | Trust-and-safety review and GDPR Article 22(3) explainability — see AI Transparency Notice §11.1 |
| Tier 1 onboarding acknowledgment and AI-review log | 7 years | Article 22 record + regulatory-inquiry preservation — see Schedule A, Section A.7 of the Terms of Service |
| Marketing-consent records | Until withdrawn + 3 years | Proof of consent under Article 7(1) GDPR |
| Aggregated and de-identified data | Indefinite | No longer "personal data" once irreversibly de-identified (Recital 26 GDPR) |
7.2 Deletion on request
You can request deletion of your data at any time (see Section 8). We honor verified deletion requests within 30 days. Exceptions are tightly scoped:
- Legal-retention obligations with citation to the specific law (e.g., tax retention).
- Ongoing dispute or legal hold.
- De-identified statistical data that no longer counts as personal data under Recital 26.
7.3 No "perpetual research" carve-out
We do not retain identifiable data indefinitely under a generic research justification. Research uses are limited to (a) de-identified data, or (b) identifiable data covered by a separate explicit Research Consent form which you can revoke at any time.
8. Your rights
The law gives you a long list of rights. We respect them and we do not penalize you for using them. This section covers EU/UK/EEA, California, and other US-state rights, plus the universal opt-out signal and the children's-rights position.
8.1 Your rights in the European Union, the United Kingdom, the EEA, and Switzerland
| Right | Article | What it means |
|---|---|---|
| Access | Art 15 GDPR | A copy of all personal data we hold about you, plus the processing metadata |
| Rectification | Art 16 GDPR | Correction of inaccurate or incomplete data |
| Erasure ("right to be forgotten") | Art 17 GDPR | Deletion, subject to retention obligations described in Section 7 |
| Restriction | Art 18 GDPR | Pause processing while a question is being resolved |
| Portability | Art 20 GDPR | A machine-readable export of data you provided to us, where we process under consent or contract |
| Objection | Art 21 GDPR | Object to processing based on legitimate interest, including marketing |
| Withdraw consent | Art 7(3) GDPR | Withdraw any consent at any time, prospectively |
| Article 22 rights | Art 22 GDPR | Express your view, contest, and request human review of AI-generated protocols (see Section 6.4) |
| Lodge a complaint | Art 77 GDPR | File a complaint with your supervisory authority |
Lead supervisory authority. Our lead supervisory authority under the GDPR one-stop-shop mechanism is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) at naih.hu — see Section 1.2. You also have the right to complain to the supervisory authority of the EU Member State where you live, where you work, or where the alleged infringement occurred.
Selected supervisory-authority contacts:
| Country | Authority | Web |
|---|---|---|
| Hungary | NAIH | naih.hu |
| United Kingdom | ICO | ico.org.uk |
| France | CNIL | cnil.fr |
| Germany (federal) | BfDI | bfdi.bund.de |
| Spain | AEPD | aepd.es |
| Italy | Garante | garanteprivacy.it |
| Netherlands | AP | autoriteitpersoonsgegevens.nl |
| Austria | DSB | dsb.gv.at |
| Switzerland | FDPIC | edoeb.admin.ch |
8.2 Your rights in California (CCPA / CPRA)
If you are a California resident, you have the following rights:
- Right to know what personal information we have collected, used, disclosed, and sold or shared
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share your personal information for cross-context behavioral advertising. Even though there is nothing to opt out of, we honor opt-out requests for clarity.
- Right to limit the use and disclosure of Sensitive Personal Information. We use Sensitive Personal Information only to provide the services you request and for the purposes permitted by the CCPA regulations (§ 7027(m)), so a "Limit" link is not required by law — but you may submit a limit request at any time at
privacy@yolongevity.comand we will honor it. - Right against discrimination for exercising any of these rights — we will not deny services, charge a different price, or provide a different level of quality because you exercised a right.
- Right to authorized agent to make a request on your behalf.
Sensitive Personal Information categories we process:
- Health data (Section 3.3, 3.4, 3.5, 3.6, 3.8, 3.12)
- Genetic data (Section 3.4, where Moleqlar BioAge is involved)
- Account login credentials with the password (Section 3.2)
- Precise geolocation — only if you choose to enable it for any optional location-aware feature
- Contents of consultation recordings to the extent they reveal sensitive content (Section 3.7)
Categories of Sensitive Personal Information sold or shared in the past 12 months: none.
California opt-out links. Because we do not sell personal information and do not share it for cross-context behavioral advertising, California law does not require us to post a "Do Not Sell or Share My Personal Information" link, and because we use Sensitive Personal Information only for permitted service-delivery purposes, a "Limit the Use of My Sensitive Personal Information" link is likewise not required. You can nevertheless submit either request at any time by emailing privacy@yolongevity.com (subject line "California opt-out request" or "Limit SPI request"), and we will honor it. If our practices ever change, we will post the required links before any sale or sharing begins.
Shine the Light (California Civil Code § 1798.83). California residents who have an established business relationship with us may request, once per calendar year, information about the disclosure of their personal information to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes. To exercise this right, write to privacy@yolongevity.com with the subject line "California Shine the Light Request."
Financial incentives (CCPA § 1798.125). We do not currently offer financial incentives for the sale or processing of personal information. If we ever do, we will provide a separate notice with all required disclosures.
8.3 Your rights in other US states
You may have rights under your state's comprehensive privacy law if you live in any of the following states. The rights are largely uniform across states; we handle them through the same Privacy Request Center.
- Virginia (VCDPA)
- Colorado (CPA)
- Connecticut (CTDPA) — see also the Consumer Health Data Privacy Policy
- Utah (UCPA)
- Texas (TDPSA)
- Oregon (OCPA)
- Florida (FDBR)
- Maryland (MODPA)
- Minnesota (MNCDPA)
- New Jersey (NJDPA)
- New Hampshire (NHDPA)
- Kentucky (KCDPA)
- Iowa (ICDPA)
- Indiana (INCDPA)
- Tennessee (TIPA)
- Montana (MCDPA)
- Rhode Island (RIDTPPA)
- Nebraska (NDPA)
- Delaware (DPDPA)
Common rights across these laws include: right to know, right to delete, right to correct (in most), right to portability (in most), right to opt out of sale, right to opt out of targeted advertising, right to opt out of profiling for decisions producing legal or similarly significant effects, right to appeal a denied request.
Maryland Online Data Privacy Act (MODPA) — special data-minimization commitment. For Maryland residents, we collect, process, and share sensitive data only as strictly necessary to provide the service you requested. We do not sell sensitive data of Maryland residents.
8.4 Universal Opt-Out Signal — Global Privacy Control
YoLongevity does not sell personal information and does not share it for cross-context behavioral advertising — for any user, in any state. There is therefore no sale or sharing for a Global Privacy Control (GPC) signal to act on: our analytics is opt-in for every visitor (Section 3.11 and the Cookie Policy), and no other tracking exists. If we ever introduce sale or sharing of personal information, we will — before any such processing starts — honor the GPC signal as a valid universal opt-out and post the required opt-out links.
8.5 How to exercise your rights
You have multiple ways to make a privacy request — choose the one easiest for you:
- Email:
privacy@yolongevity.com— the primary channel for all request types - In the app: the Privacy Settings section of your account, for the consents, connections, and sharing switches you can manage directly
- Postal: YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA, OR YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary
Verification. We will verify your identity before fulfilling a request, and we will use the least intrusive verification method that is reasonable for the type of request. We will not require you to upload a government-issued ID by default. We may ask you to confirm information already in your account or to confirm a request from your registered email.
Response time.
- EU / UK / Swiss residents: within 30 days, extendable by up to two further months for complex requests with notification of the extension and the reasons for it (Article 12(3) GDPR).
- California and other US states: within the statutory deadline (typically 45 days, with a single 45-day extension where permitted).
Cost. No fee for the first request in any 12-month period. We may charge a reasonable fee for excessive or manifestly unfounded repeat requests, or refuse to act and explain why.
Authorized agent. A third party may submit a request on your behalf if they provide written authorization signed by you. We may verify your identity directly to confirm the authorization.
Right to appeal a denied request. If we deny your request in whole or in part, you may appeal by writing to privacy@yolongevity.com with the subject line "Privacy Request Appeal." We will respond to the appeal within 60 days. If we maintain the denial, we will tell you about your right to contact your state attorney general or your supervisory authority.
Non-retaliation. We will not deny services, charge a different price, or provide a different level of quality because you exercised any right under this policy or applicable law.
8.6 Children's rights — 18+ only
You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
We do not knowingly collect personal information from individuals under 18. If we discover that we have collected data from someone under 18, we delete it promptly. If you are a parent or guardian and you believe your child has provided personal information to us, write to privacy@yolongevity.com and we will delete it.
Article 8 GDPR (children's consent for information-society services) does not apply because we are 18+ only. The US Children's Online Privacy Protection Act (COPPA) does not apply for the same reason.
9. Who we share data with
This section lists the categories of recipients who may receive your data, and what we do not do with your data. The vendor table in Section 9.1 (mirrored in Section 5.1 of the Consumer Health Data Privacy Policy) is our public subprocessor list.
9.1 Service providers (processors under Article 28 GDPR)
Each of the following processors operates under a Data Processing Agreement that meets Article 28 GDPR requirements. Where international transfers are involved, we use the EU–US Data Privacy Framework (where the vendor is enrolled) or Standard Contractual Clauses with supplementary measures.
| Category | Vendor (representative) | Purpose | Region |
|---|---|---|---|
| Cloud infrastructure and application database | Supabase (managed Postgres, authentication, and edge compute) | Hosting, application database | EU |
| Application and health-data servers | Operated by YoLongevity on dedicated managed infrastructure; health and biomarker data is held in our own database, separate from the general application database | Health-data system of record | EU |
| Web hosting and content delivery | Cloudflare, Inc. (United States) | Serves the website and app shell; does not access the application or health databases | Global edge network |
| Encrypted database backups | Supabase Storage (S3-compatible object storage) — each archive is AES-256 encrypted before upload; the decryption key is held solely by YoLongevity and is never stored with the backups or accessible to the provider | Scheduled disaster-recovery backups of the health database | EU |
| Payment processor | Stripe | Billing, refunds | EU + US (PCI DSS) |
| Transactional email | Resend (Resend, Inc., United States) | Account and service emails, sent from our own sending domain | US |
| Onboarding and marketing email | Brevo (Sendinblue SAS, France) — only where you have opted in to such emails | Onboarding and marketing email | EU |
| Push notifications | Pushwoosh Inc. (United States) — receives your device push token and the notification text, never lab results or raw health streams | Push-notification delivery | US |
| Analytics | PostHog Inc. (2261 Market St #4008, San Francisco, CA 94114, USA) — PostHog US Cloud; pseudonymous usage events, device/session identifiers, coarse technical metadata; no IP address, no health data, no AI-coach message content; DPF self-certified, SCC fallback | Product & website analytics (opt-in) | US |
| AI providers — foundation model (direct) | Anthropic (Claude) — direct API integration; no-training DPA | Personalized longevity-protocol generation pipeline; YO Coach and Readiness Coach chat; daily guidance generation (see AI Transparency Notice §5.1 and §6) | US |
| AI gateway — Google Gemini workloads | OpenRouter, Inc. (United States), routing to Google Gemini models — no-training terms; requests routed with logging disabled | Trainer Coach chat; knowledge-base embeddings and retrieval support; readiness narrative; internal content processing (see AI Transparency Notice §5.1) | US |
| Optional messaging channels (only if you connect one) | Meta Platforms (WhatsApp Business Platform) or Telegram — if you explicitly connect a messaging channel for your coach conversation, message content transits that provider's platform under its own terms; disconnect at any time | Coach conversation over the channel you choose | Global |
Analytics (PostHog) and transfers to the United States. We use PostHog Inc. ("PostHog") as a processor for product and website analytics. PostHog stores and processes the analytics data described in our Cookie Policy on its U.S. cloud infrastructure, so this involves a transfer of personal data from the EEA, the UK and Switzerland to the United States. We rely on (i) adequacy via the Data Privacy Framework — PostHog Inc. is self-certified under the EU-U.S. DPF, its UK Extension, and the Swiss-U.S. DPF and appears on the U.S. Department of Commerce DPF List, benefiting from the European Commission's adequacy decision of 10 July 2023; and (ii) Standard Contractual Clauses (Module 2) plus the UK Addendum in PostHog's Data Processing Agreement as a fallback should DPF certification lapse. As a data-minimisation measure, PostHog does not receive your IP address and our analytics events contain no special-category (health) data. PostHog's commitments: posthog.com/privacy and posthog.com/dpa.
9.1.1 Hungarian affiliate / joint controller
YoLongevity Hungary Zrt. (1025 Budapest, Nagybányai út 44., Hungary; Cégjegyzékszám 01-10-140516; Adószám 27093708-2-41; EU VAT HU27093708) is the Hungarian affiliate of YoLongevity, Inc. with exclusive Hungarian commercial rights. YoLongevity Hungary Zrt. employs or engages the medical staff (the Chief Medical Officer and the supervising physician team) and the Wellness Coaching Personnel (the degreed dietitians who serve as the primary human point of contact for wellness coaching, together with any other suitably qualified personnel engaged for that purpose under the oversight of the supervising physician team) who provide wellness coaching to Tier 2 Transform and Tier 3 Elite users globally (including users outside Hungary). For these wellness-coaching activities, YoLongevity, Inc. and YoLongevity Hungary Zrt. act as joint controllers under Article 26 of the GDPR.
The contact point for data subject rights remains YoLongevity, Inc. via the contact channels in Section 1 of this Policy. The joint controllership arrangement is documented in an Article 26 Joint Controller Agreement between the two entities; this section is the summary of its essence, and you can request further detail at privacy@yolongevity.com. The arrangement allocates: (a) responsibility for transparency and information-provision under Articles 13–14 GDPR primarily to YoLongevity, Inc.; (b) responsibility for data-subject-rights handling primarily to YoLongevity, Inc. (with operational support from YoLongevity Hungary Zrt. for staff-collected data); and (c) joint responsibility for security measures and breach notification.
Public subprocessor list. The vendor table in Section 9.1 (mirrored in Section 5.1 of the Consumer Health Data Privacy Policy) is updated within 30 days of any change. Existing customers receive advance notification of new subprocessors via email and an in-app banner before the change takes effect, and may object.
9.2 Wearable-data partners
When you authorize a wearable-device platform (Oura, WHOOP, Garmin, Polar, Apple, Android Health Connect, Withings, and similar), data flows from the manufacturer to YoLongevity according to the scopes you have authorized in that platform. Manufacturer privacy policies apply upstream.
For WHOOP specifically: data is accessed via the WHOOP API under the OAuth scopes you grant, and is used only to deliver the YoLongevity wellness service (readiness, personalization, and metric display) — never sold and never used for advertising. You can revoke access at any time in the app or in your WHOOP account; revoking deletes the WHOOP-sourced data we hold. WHOOP is a third-party provider governed by its own Terms and Privacy Policy.
9.3 Laboratory partners
- Moleqlar (BioAge methylation/proteomic, NAD test) — you give a separate consent before any Moleqlar data flow begins. Moleqlar processes your sample under its own privacy policy. We act as the receiver of your results via API integration.
- External laboratories (Synlab, Semmelweis Premium, and others) — you upload PDF results to us. The lab processes your sample under its own privacy policy.
9.4 Partner clinics (referrals)
Where a wellness conversation surfaces something that may need clinical evaluation, we may offer to refer you to a partner clinic.
- A separate, specific, per-referral consent is required at the moment of referral.
- We transmit only the minimum-necessary clinical context to the receiving clinic.
- The partner clinic carries clinical liability and malpractice insurance for any clinical service it provides; YoLongevity does not provide any clinical service.
- Once your data is received by the partner clinic, the clinic's own privacy notice governs.
See the Partner-Clinic Referral Notice you sign at the moment of referral, which sits alongside our Terms of Service, Section 6.
9.4.1 Certified Fitness Partners (sharing at your direction)
If you link a Certified Fitness Partner — an independent personal trainer you select — you can direct us, through four separate per-category switches in your Personal settings, to share specific categories of your data with that trainer: your readiness data, your biomarker results, your meal logs, and/or your daily plan and supplement schedule. We share only the categories you switch on, only with the trainer you name, and only while the switch stays on.
Each trainer is a separate, independent controller for the data you share and for their own coaching use of it. The data you switch on may include your daily plan and supplement schedule (today's training, recovery, sleep and nutrition plan, goals and routine, and the supplement/vitamin schedule as written in your plan). To support the trainer, an AI coaching assistant processes the shared categories on our behalf; our AI sub-processor is Anthropic, PBC (United States), integrated directly, which processes the data under our instructions and our data-processing agreement and does not use it to train its models. Your lab results, biomarker interpretation, risk/clinical flags and full medical protocol are never sent to the trainer or the assistant. The AI assistant is not available where we cannot lawfully transfer the data (for example, the assistant is disabled for clients resident in the United Arab Emirates; the trainer can still see the data you shared in-portal).
You can switch any category off at any time — the trainer and the assistant lose access immediately, and chat history that used the shared data is deleted within 30 days. Controller/processor framing: the trainer is an independent controller for their coaching use (bound by the Certified Fitness Partner Agreement, not Article 28); Anthropic, PBC is YoLongevity's processor/sub-processor for the assistant (bound by our DPA and Article 28), with YoLongevity as controller of the AI-processing step. Lawful basis: your explicit consent (Article 9(2)(a)), which also serves as your instruction to disclose; the transfer to the AI sub-processor in the United States relies on your explicit consent under Article 49(1)(a).
9.5 Professional advisors
- Lawyers, accountants, and auditors, all bound by professional confidentiality
- Our external Data Protection Officer
9.6 Business transactions
In a merger, acquisition, financing, asset sale, restructuring, or similar transaction, your data may be transferred to the surviving or acquiring entity, with appropriate safeguards. We will notify you in advance of any material transfer becoming effective. The receiving party will be bound by privacy commitments at least equivalent to those in this policy.
9.7 Legal and safety
- Compliance with a subpoena, court order, or law-enforcement request, where the request is valid and proportionate. We carefully review requests and challenge those that are over-broad or lack a sound legal basis. Where the law allows, we will notify you of the request before complying.
- Protection of YoLongevity's legal rights, property, and safety.
- Emergency situations involving a risk to life or safety, in line with our emergency protocol described in our Terms of Service, Section 4.
9.8 Aggregated and de-identified data
We may use aggregated and de-identified data — data that no longer identifies any individual within the meaning of Recital 26 GDPR — to improve our service, support scientific publications, and produce statistical citations in marketing materials. We never re-identify de-identified data.
9.9 What we never do
- We never sell your personal data.
- We never sell your consumer health data — see the Consumer Health Data Privacy Policy.
- We never share your personal information for cross-context behavioral advertising.
- We never disclose your health data to advertising partners.
- We never disclose your data to data brokers.
- We never use geofencing of healthcare facilities to target consumers (in line with MHMDA).
10. International data transfers
Where your data goes when it crosses borders, what mechanism makes that transfer lawful, and what backup we have if a primary mechanism is invalidated.
10.1 Default architecture — data residency
- Our application and health databases are hosted in the European Union.
- YoLongevity Hungary Zrt. (the joint controller whose staff provide wellness coaching from Hungary) accesses EU-hosted data flows from Hungary; this access constitutes a Hungary-internal processing context for EU/EEA-resident users.
- A limited set of US-based providers (Section 9.1: payments, transactional email, push notifications, analytics, AI processing) receive only the data their service needs, under the transfer mechanisms in Sections 10.2–10.3.
10.2 Cross-border processing within YoLongevity, Inc.
YoLongevity, Inc. operates from its Budapest principal executive office and maintains its registered office in Delaware. Processing performed by YoLongevity, Inc.'s own personnel, wherever located, occurs within a single legal entity; consistent with EDPB Guidelines 05/2021, such intra-entity access is not a third-country "transfer" requiring an Article 46 instrument, but we nevertheless protect it with the supplementary measures described in Section 10.3 (encryption, access controls, need-to-know limits). Data flows to YoLongevity Hungary Zrt. — a separate entity and joint controller — remain within the EU.
10.3 Transfers to US-based providers — DPF (vendor-level) and Standard Contractual Clauses
Transfers of EU/EEA personal data to the US-based providers listed in Section 9.1 rely on:
- the provider's own EU–US Data Privacy Framework self-certification, where the provider participates (for example, PostHog Inc. — see Section 9.1); and otherwise
- Standard Contractual Clauses (Implementing Decision 2021/914) in the appropriate Module — Module 1 (controller-to-controller), Module 2 (controller-to-processor), or Module 3 (processor-to-processor).
Together with the SCCs we apply supplementary measures (encryption in transit and at rest, transfer impact assessment, access controls) to address the Schrems II requirements. YoLongevity, Inc. does not itself currently claim a DPF self-certification; if we obtain one, we will update this Policy with the certification record and the independent recourse mechanism before relying on it.
10.4 UK and Swiss equivalents
- UK transfers: where a vendor holds the UK Extension to the EU–US DPF, we rely on it; where SCCs are used, the UK International Data Transfer Addendum (UK ICO Addendum) or the standalone UK IDTA applies.
- Swiss transfers: Swiss FADP-compliant transfer mechanism via the vendor's Swiss-US DPF certification or equivalent SCC adaptations.
10.5 Adequacy decisions
For transfers to the United Kingdom, Switzerland, and other countries the European Commission has formally found adequate, we rely on the European Commission's adequacy decisions under Article 45 GDPR.
10.6 Transfer Impact Assessment
We have completed a Transfer Impact Assessment (TIA) for each transfer flow, in line with EDPB Recommendations 01/2020. The TIA is available to EU supervisory authorities on request.
10.7 Right to a copy of safeguards
You have the right to obtain a copy of, or place where you can access, the safeguards used for cross-border transfers (Article 13(1)(f) GDPR). Write to dpo@yolongevity.com and we will share the relevant SCCs (with confidential commercial terms redacted) and the DPF certification record.
10.8 Onward transfers
Where data we have received in the US is onward-transferred to another country, we apply the DPF Accountability for Onward Transfer Principle and / or SCCs with the further recipient.
11. How we secure your data
This section is a high-level summary. Our internal Information Security Policy and Incident Response Plan are the operational documents; this is what you need to know as a user.
We protect your data with technical and organizational measures, including:
- Encryption at rest: AES-256 minimum for all production data stores
- Encryption in transit: TLS 1.3 for all network connections
- Access controls: role-based access control (RBAC); multi-factor authentication mandatory for all staff and contractors
- Audit logging: every access to Article 9 health data is logged. Audit logs are tamper-evident and retained for 24 months.
- Vendor security review: Data Processing Agreement and security questionnaire for every processor that handles personal data
- Penetration testing: independent annual third-party penetration test
- Staff training: privacy and security training at onboarding and annually
- Coordinated vulnerability disclosure:
vulnerability-disclosure@yolongevity.comand asecurity.txtfile at our root domain (/.well-known/security.txt)
No system can guarantee absolute security. If we suspect a breach has affected your account, we will tell you (see Section 12).
12. Data-breach notification
If a security incident affects your personal data, we move fast. This section explains what we commit to.
12.1 Detection and internal escalation
- Detection target: within 24 hours of any potential breach.
- Internal escalation: the Chief Medical Officer, the Data Protection Officer, and executive leadership are notified within 4 hours of detection.
12.2 Notification to supervisory authorities
- GDPR Article 33: within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority. Where the 72-hour deadline cannot be met, we notify with the reasons for the delay.
- US states: as required by state law (typically 30 to 60 days, sometimes shorter).
- FTC Health Breach Notification Rule: for breaches affecting 500+ individuals, we notify the FTC within 10 business days, and we notify affected individuals within 60 days.
- MHMDA (Washington): as described in our Consumer Health Data Privacy Policy.
12.3 Notification to you
- GDPR Article 34: without undue delay, where the breach is likely to result in a high risk to your rights and freedoms.
- State laws: within the statutory deadlines.
We will tell you what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
12.4 Internal documentation
We log every breach internally regardless of whether external notification is triggered, in line with the Article 33(5) accountability requirement.
12.5 Multi-jurisdiction notification map
For an incident affecting users in multiple Member States, we notify our lead supervisory authority (NAIH) under the GDPR one-stop-shop mechanism (Section 1.2), and any additional authorities where the law of a specific jurisdiction independently requires it. We maintain a notification map per market for this purpose.
13. Cookies and similar technologies
This is a summary. Our Cookie Policy is the full inventory and the place where you can change your preferences.
We use cookies and similar technologies (local storage, SDKs in our mobile app) for four categorical purposes:
- Strictly necessary — required to deliver the service (login, security, load balancing). Always on.
- Functional — remember your preferences and settings.
- Analytics — measure how the service is used so we can improve it.
- Marketing — measure the effectiveness of our marketing.
All users, worldwide: analytics is opt-in via our first-party consent banner — the reject choice is offered with the same prominence as accept, and nothing in the analytics category runs before you decide. We apply this EU standard globally, including in the United States (see Section 8.4 on the Global Privacy Control).
You can change your cookie choice at any time via the "Cookie settings" link in our website footer; the full inventory is in the Cookie Policy.
14. State-specific notices (United States)
14.1 California
This Privacy Policy serves as our California Privacy Notice at Collection under Cal. Civ. Code § 1798.100(b). The Sensitive Personal Information categories we process are listed in Section 8.2 above. Because we do not sell or share personal information and use Sensitive Personal Information only for permitted service-delivery purposes, the "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information" links are not required; you can submit either request at privacy@yolongevity.com (Section 8.2).
- Right to Know — see Section 8.2
- Right to Delete — see Section 8.2
- Right to Correct — see Section 8.2
- Right to Opt Out of Sale or Sharing — see Section 8.2; we do not sell or share for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information — see Section 8.2
- Shine the Light — see Section 8.2
- Financial Incentives — none currently. See Section 8.2
14.2 Washington — Consumer Health Data Privacy Policy
If you live in Washington, please read our Consumer Health Data Privacy Policy for the rights and protections that apply to your consumer health data under the Washington My Health My Data Act (MHMDA, RCW 19.373).
14.3 Nevada — Consumer Health Data Privacy Policy
If you live in Nevada, please read our Consumer Health Data Privacy Policy for the rights and protections that apply to your consumer health data under Nevada SB 370.
14.4 Connecticut — Consumer Health Data Privacy Policy
If you live in Connecticut, please read our Consumer Health Data Privacy Policy for the rights and protections that apply to your consumer health data under Connecticut SB 3 (the Connecticut consumer-health-data law). Your CTDPA rights are described in Section 8.3.
14.5 Maryland (MODPA)
For Maryland residents:
- We collect, process, and share sensitive data only as strictly necessary to provide the service you requested.
- We do not sell sensitive data of Maryland residents, regardless of consent.
14.6 Other state comprehensive privacy laws
If you live in Virginia, Colorado, Connecticut, Texas, Utah, Florida, Oregon, Minnesota, New Jersey, New Hampshire, Kentucky, Iowa, Indiana, Tennessee, Montana, Rhode Island, Nebraska, or Delaware, you have rights described in Section 8.3. Write to privacy@yolongevity.com to exercise them (Section 8.5).
14.7 New York — SHIELD Act data-security compliance
For New York residents, YoLongevity operates as a person or business that owns or licenses computerized data which includes the private information of New York residents within the meaning of New York General Business Law § 899-aa (breach notification) and § 899-bb (the Stop Hacks and Improve Electronic Data Security Act, "SHIELD Act"). The SHIELD Act requires reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of New York residents' private information, and timely breach notification to affected residents and to the New York Attorney General.
YoLongevity's information-security program — the encryption, access controls, audit logging, vendor security review, penetration testing, staff training, and incident response described in Section 11 of this Policy, together with the breach-notification commitments in Section 12 — is designed to satisfy the SHIELD Act requirements. Our incident-response plan includes the specific notification pathway to the New York Attorney General and to the New York State Department of State Division of Consumer Protection where § 899-aa is triggered.
14a. Consumer Health Data — homepage prominence statement
Washington's MHMDA requires us to present a separate Consumer Health Data Privacy Policy at the same prominence as the main Privacy Policy. This is that pointer.
For Washington, Nevada, and Connecticut residents — and as our nationwide US baseline standard — we maintain a separate Consumer Health Data Privacy Policy. That document describes:
- The categories of consumer health data we collect
- The purposes
- The recipients
- Our subprocessor list
- Your rights
- Our commitments regarding sale and geofencing
The Consumer Health Data Privacy Policy is presented at the same prominence as this Privacy Policy on our homepage and on every page where consumer health data is collected (RCW 19.373.020(2)).
15. EEA, UK, and Swiss-specific notices
15.1 EU establishment — no Article 27 representative required
YoLongevity, Inc. is established in the EU through its principal executive office at Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary, and is therefore subject to the GDPR under Article 3(1) and Recital 22. No Article 27 EU representative is required — see Section 1.2.
15.2 UK supervisory authority
For UK users, the UK Information Commissioner's Office (ICO) at ico.org.uk is the supervisory authority. We comply with the UK GDPR and the Data Protection Act 2018.
15.3 Swiss FADP
We operate consistently with the revised Swiss Federal Act on Data Protection (FADP), which closely mirrors the GDPR. Swiss users may contact the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
15.4 Lead supervisory authority and complaint right
NAIH (Hungary) is our lead supervisory authority under the GDPR one-stop-shop mechanism (Section 1.2). EU/EEA users also retain the right to lodge a complaint with the supervisory authority of their country of habitual residence, place of work, or place of the alleged infringement (Section 8.1).
15.5 30-day refund + 14-day EU mandatory cooling-off
If you are a user globally, you have a 30-day full-refund right (provided as a contractual extension of, and in addition to, EU mandatory rights). If you are an EU/EEA/UK/Swiss consumer, the 14-day mandatory right of withdrawal under the EU Consumer Rights Directive 2011/83/EU additionally applies. Both withdrawal mechanics are described in our Terms of Service, Section 5.
15.6 Consumer dispute resolution in the EU
The European Commission's Online Dispute Resolution (ODR) platform was discontinued on 20 July 2025 (Regulation (EU) 2024/3228). EU consumers can instead turn to the national consumer alternative-dispute-resolution (ADR) bodies of their Member State — a directory is available through the European Commission's consumer-redress pages — or to their national consumer-protection authority. We encourage you to contact us first at legal@yolongevity.com so we can try to resolve the issue directly; you are not required to do so before contacting an ADR body.
16. Other jurisdictions
We currently launch in the European Economic Area, the United Kingdom, Switzerland, and the United States. If you access YoLongevity from another country (Brazil, Canada, South Korea, Japan, and others), local data-protection laws may give you additional rights. Write to privacy@yolongevity.com and we will work with you in good faith to honor those rights to the extent they apply. We will publish jurisdiction-specific notices for additional markets as our user base in those markets grows.
17. Children's privacy
We are 18+. Period.
- You must be at least 18 years old to use YoLongevity. Do not use these Services if you are under the age of 18.
- We do not knowingly collect personal information from individuals under 18.
- The account-creation flow includes an age confirmation as a click-through verification.
- If we discover that we have collected data from someone under 18, we delete it promptly upon verified discovery.
- Parents or guardians who believe their child has provided personal information to us can write to
privacy@yolongevity.comand we will delete the data and the account.
18. Changes to this Privacy Policy
We update this policy from time to time. For material changes, we tell you at least 30 days in advance.
- Material changes are notified at least 30 days before they take effect by email and an in-app banner. Material change includes any change to:
- the purpose of processing,
- the lawful basis,
- categories of recipients (including any new subprocessor),
- retention periods,
- new categories of data,
- AI provider change or material upstream LLM change,
- tier structure, refund mechanics, or arbitration mechanics,
- the way we handle consumer rights.
- For material changes affecting EU, UK, or Swiss users, we may obtain your explicit re-consent before the change applies to your data.
- Non-material changes (wording or formatting only) take effect on posting; the "Last updated" date at the top of this policy is refreshed.
- Version history: the version number and effective date always appear at the top of this Policy; a summary of the changes in any published version is available on request at
privacy@yolongevity.com.
Continued use of YoLongevity after a non-material change takes effect constitutes acceptance of the changed policy.
19. How to contact us
| Purpose | Contact |
|---|---|
| General privacy inquiries | privacy@yolongevity.com |
| Data Protection Officer | dpo@yolongevity.com |
| Lead supervisory authority | NAIH, 1055 Budapest, Falk Miksa utca 9-11., Hungary, naih.hu |
| Privacy requests | privacy@yolongevity.com and the Privacy Settings section of your account (Section 8.5) |
| Postal — Delaware (registered office) | YoLongevity, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA |
| Postal — Hungary (principal executive office) | YoLongevity, Inc., Kertvárosi krt 22, C building, 6/2, 1237 Budapest, Hungary |
| Hungarian affiliate / joint controller | YoLongevity Hungary Zrt., 1025 Budapest, Nagybányai út 44., Hungary |
| Vulnerability disclosure | vulnerability-disclosure@yolongevity.com |
19a. Pilot Cohort applications (August 2026)
Plain-language summary: if you apply to our closed 2026 pilot cohort through the pilot pages, we collect your application details to evaluate your application and contact you about the outcome. This is separate from having a customer account, and you can withdraw at any time.
We run a closed pilot cohort with a limited number of places in Hungary and in Miami, Florida. The application window runs until 31 July 2026 and the pilot begins 1 August 2026. If you apply through the pilot pages, we process the following as a distinct activity:
- What we collect: your name, email, and phone number; the qualification answers you provide (age band, wearable/device status, primary goal, city, and any motivation you choose to write); the consents you give (privacy acknowledgment, optional marketing consent, and your acceptance of the pilot commitment terms) together with the timestamp and the text version you accepted; and technical and attribution data (user agent, and UTM campaign parameters if you arrived from an advertisement).
- Purpose: to receive, evaluate, and administer pilot applications; to contact you about the outcome; and to fill the limited pilot places.
- Lawful bases (GDPR Articles 6 and 9): we process your application on the basis of your consent (Art. 6(1)(a)) — to assess your application and to contact you about it — and, separately and optionally, your consent to marketing. Your chosen goal and any free-text motivation you write may reveal information about your health; we do not ask for health details, but because you can volunteer them, we rely on your explicit consent (Art. 9(2)(a)), given via the application checkbox, to process any such special-category data. You may withdraw any consent at any time, free of charge, without affecting processing already carried out.
- Recipients: your application is stored in our own database and is processed only by us and our email provider (Brevo, EU), which sends your confirmation and an internal notification. We do not sell application data and do not share it with any third party for that party's own purposes.
- Retention: if you are not selected, we delete or de-identify your application by 30 September 2026 at the latest. If you are selected and become a customer, your data transitions into the customer relationship governed by the rest of this Policy. Marketing is separate: if you ticked the optional marketing box, your email stays on our marketing list until you unsubscribe (see the retention matrix in Section 7), independently of your pilot application.
- Your rights: every right in Section 8 applies — you may access, correct, or delete your application data, or withdraw a consent, at any time via
privacy@yolongevity.com.
20. Effective date and version
- Effective date: 2026-07-24
- Last updated: 2026-07-24
- Version: 1.17
- Reviewed by: YoLongevity Data Protection Officer
- Changelog: available on request at
privacy@yolongevity.com - Language: The English-language version of this Policy is the controlling version. The English version prevails in case of conflict with any translation, except where a non-waivable local-language obligation applies.
End of YoLongevity Privacy Policy v1.17.
