← Back to home

family sharing and authorized representative terms

Effective: 16 August 2026Last updated: 16 August 2026

These terms form part of the Terms of Service and should be read with the Privacy Policy.

why this document exists

Every other health app assumes one person looking at their own data. Lifelong assumes a family — one person notices the symptom, another goes to the appointment, a third handles the follow-up. That is the whole point of the product, and it is also the part with the most ways to go wrong. So the rules are written down.

three principles

  1. Nothing is shared until you choose to share it. At setup, you explicitly choose what your family can see; nothing is visible until you confirm a choice.
  2. The person the data is about controls it. Not the family owner, not the person who uploaded it, not the person paying.
  3. You can always take it back. Revocation takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay.

1. families

Creating and joining. Any adult account holder can create a family and becomes its owner. Others join by invitation, including family members aged 13 to 17 under §3A, who join as members rather than owners. A person may belong to more than one family — people have parents and in-laws.

What the owner can do. Manage the family’s name and settings, invite and remove members, and end the family. The owner cannot see another member’s health information unless that member has shared it with them. Owning the family is an administrative role, not a privileged view.

Leaving. You can leave a family at any time. Access ends in both directions — yours to their shared information, and theirs to yours. That takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay. Content you contributed to a shared family space may remain with the family.

Removal. The owner may remove a member. Removal ends access in both directions on the same basis: immediately in the app, propagated across our systems promptly and without undue delay.

2. what sharing actually means

You choose at setup. When you join a family, the app asks you to choose what your family can see. Sharing all of your health data is the option we recommend — a family that can see the full picture is the point of the product — but it takes effect only if you affirmatively confirm that choice. Nothing of yours is visible to anyone until you have made a choice, and you can narrow or widen it at any time afterwards.

Categories you control separately

  • Daily signals — sleep, activity, heart
  • Health records and documents
  • Medications
  • Symptoms
  • Conditions
  • Allergies
  • Journal entries

Two levels of control. You set a family-wide default for each category, and you can then override it for any individual person. Your sister can see everything; your cousin can see nothing; both are in the same family. Where you have not set a person-specific override, your family-wide default applies.

Editing. For some categories — symptoms, medications, conditions, allergies — sharing also allows the person you shared with to help maintain that information. That is deliberate: the point of a care team is that someone else can add the medication change while you are still in the car park. The app tells you when a setting grants editing as well as viewing.

Changing your mind. Change or revoke any permission at any time in the app. Revocation takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay.

What revocation cannot do. It cannot un-see. Once a family member has seen your information, they know it, and they may have written it down, screenshotted it, or told someone. Lifelong controls access to data in Lifelong; it cannot control people. Share with people you trust.

3. people without an account, and the authority to act for them

Lifelong lets you keep health records for someone who is not a Lifelong user — a parent who will never install an app, a child, or someone you care for. This is one of the most useful things Lifelong does, and it is legally the most sensitive, because that person has not agreed to anything.

3.1 Your representation

When you create a profile for someone without an account, or file health information about them, you represent and warrant that you have the authority to do so. Specifically, that at least one of the following is true:

  • You are their parent or legal guardian and they are a minor
  • You hold a power of attorney, healthcare proxy, guardianship, or equivalent legal authority over their health decisions or health information
  • You are their personal representative as that term is used in health privacy law
  • They have given you permission to keep and manage their health information

When you add information about a family member, we collect that information on the basis of the consent or authority you give on their behalf. If a family member with capacity joins Lifelong or contacts us, they take control: they can see what is held about them, correct it, restrict who sees it, or have it deleted.

You are responsible for the accuracy of that representation. Lifelong relies on it and does not independently verify it.

3.1a Profiles for children: what goes in, and what must not

A profile you manage for a child holds what you put into it — records you upload, notes you write, appointments you enter, visits you record. That is the whole design, and it is what keeps a managed profile a matter between us and you rather than between us and a child.

So there is one hard limit: do not connect a child’s own device or accounts to a profile you manage for them. No Apple Health, Health Connect or Samsung Health from the child’s own phone or watch, no Oura, Whoop or other wearable account belonging to the child, and do not hand a child your device so they can talk to Alo as themselves. Device and wearable connections belong to a person’s own account, not to a profile someone else manages.

If a child is 13 or older and wants their own device data in Lifelong, the answer is a teen account (§3A), not a managed profile.

3.2 What we do with their information

We treat health information about a person without an account with exactly the same protections as information about an account holder. It is consumer health data, it is covered by every commitment in the Privacy Policy, it is not sold, and it is not used to train models in identifiable form.

Visibility follows the family permissions you set. Adding someone to Lifelong does not publish their records to your family.

3.3 If they later join Lifelong

The records become theirs. When a person without an account claims their profile, the information filed about them stays attached to that profile, and they acquire the full set of rights in the Privacy Policy over it — access, correction, deletion, and control over who in the family can see it, including you.

We think this is the only defensible design: the person the data is about should end up controlling it.

3.4 If you close your account

Profiles you created for people without accounts do not simply vanish, and they do not silently transfer to a stranger. Where another member of the family is in a position to continue caring for that person, the profile may pass to them; otherwise it is deleted with your account. The app explains what will happen before you confirm deletion.

3.5 If someone has filed information about you

Email privacy@trylifelong.com. Tell us who you are and what you believe has happened. We will investigate, and where a profile has been created without proper authority we will remove it. You do not need a Lifelong account to make this request, and we will not charge you or require you to create one.

3a. family members aged 13 to 17

A teenager in your family can hold their own Lifelong account rather than a profile you manage. This is the right answer for most teenagers, and it is written down here because it is the part of family sharing where a parent’s instinct and a teenager’s rights pull in different directions.

3A.1 Creating the account

The minimum age for an account is 13. Anyone under 18 needs the permission of a parent or legal guardian, given in the app and recorded — either the parent invites the teenager, or the teenager asks and the parent approves. The parent who gives permission agrees to the Terms of Service on the teenager’s behalf and is bound by them too.

The teenager consents for themselves. Permission from a parent is what allows the account to exist. It is not consent to our handling of the teenager’s health information — the teenager gives that themselves, and they exercise their own privacy rights over their own information. A parent cannot give it for them, and cannot withdraw it on their behalf.

3A.2 Sharing starts off

On a teenager’s account, family sharing starts off, category by category. Nothing is visible to anyone in the family until the teenager turns that category on. There is no pre-selected “share everything”, and we do not nudge a teenager to widen sharing or make them justify narrowing it.

A parent who approved the account can see a basic care picture by default — appointments, medications, immunisations, allergies, and general wellbeing summaries — so that the practical job of parenting a child’s health still works.

3A.3 What stays private from a parent

These categories are private from a parent by default on a 13-to-17 account:

  • Journal entries
  • Symptoms the teenager logs themselves
  • Conversations with Alo
  • Anything relating to reproductive or sexual health, mental health, or substance use

Only the teenager can open them. They can extend access to a parent, per category and per person, in exactly the same way any other member controls sharing, and they can take it back at any time — revocation takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay. A parent cannot switch these on, and we will not do it at a parent’s request.

We take this position deliberately. In most places a young person can obtain some kinds of care on their own consent, and a health record that a teenager cannot trust is a health record a teenager will not use.

3A.4 Safety

If a conversation with Alo raises a serious safety concern, a linked parent is notified that a safety resource was surfaced. They are not sent the conversation, the transcript, or what the teenager said. See the AI and Alo Disclosure.

3A.5 Turning 18

On the teenager’s eighteenth birthday the account becomes an ordinary adult account. Full control passes to them, and any parental access ends — including the basic care picture — unless the young adult chooses to grant it again. We tell both of them before it happens, so it is not a surprise to either side.

4. sharing outside your family

Not yet available. This section describes a capability we are building. It is published in advance so the rules are settled before the feature ships, and so that no one is asked to agree to something new at the moment they are trying to use it.

You will be able to share health information with people outside your family — a paid caregiver, a nanny, a home health aide, a clinician, a social worker, a lawyer. When you do, all of the following will apply:

  • It is authorised individually. Each external share requires a specific authorization from you at the time. There is no blanket permission and no default.
  • You set the scope. Which person’s information, which categories, and for how long. You can set an expiry, and we will suggest one.
  • It is time-limited by default. External access expires unless you renew it. A nanny who left two years ago should not still have your child’s records.
  • It is revocable. One tap. Revocation takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay.
  • It is logged. You can see who has access, what they can see, when they were granted it, and when they last looked.
  • We tell you what we cannot control. Once someone outside Lifelong has seen or downloaded information, it is out of our reach. We will say so at the moment you share, not in a footnote.
  • Only the subject can authorise it — or someone with authority to act for them under §3.

5. recording medical visits

Recording is covered in the Recording Consent Notice. The family-specific rules:

  • The recording is attached to the person the appointment is about, not the person who pressed record
  • Its visibility follows that person’s sharing settings, not the recorder’s — if you record your mother’s cardiology appointment, your mother’s settings decide who in the family sees it
  • If you record an appointment for someone without an account, §3 applies: you are representing that you have authority to do so

6. acting on your behalf with third parties

Not yet available. Published in advance for the same reason as §4.

We intend to build features that require Lifelong to act as your authorized representative with organisations outside Lifelong. All of them work the same way: a specific, informed, revocable authorization from you before anything happens. The capabilities we are building toward:

Retrieving your health records. Requesting your records from your healthcare providers, health information networks and exchanges on your behalf — using the patient access rights guaranteed by US law — so your history is assembled in one place instead of scattered across six portals. This requires you to authorise us as your representative, and in some cases to verify your identity with a third-party identity provider. We will explain exactly what is being requested, from whom, and what we will do with it, before you authorise anything.

Showing you your coverage, appointments and prescriptions retrieved from your providers and health plan.

Booking appointments and laboratory tests on your behalf, where you ask us to.

Referring you to care services. If you use our escalation features, we may suggest care providers. Where we would need to send your information to a provider, we will ask you first, each time, and you can decline. If we ever receive compensation in connection with a referral, we will disclose it plainly at the point of referral — not in a policy footnote. We will not sell your health data, and a referral fee will never be a reason we recommend one provider over another.

Each of these requires its own authorization, is limited to the scope you approve, is revocable at any time, and is logged so you can see what was done in your name.

Future connections. From time to time we may offer optional connections to other services and record systems, including government-operated health record systems where you live. Each connection is off unless you turn it on, each may carry its own additional terms, and each may be subject to its own rules — including rules about where that data can be stored. We will tell you what applies at the point you turn a connection on, not afterwards. See Privacy Policy §10 on where your information is held.

7. disagreements within a family

Families disagree, including about health information. Some of that we can help with and some we cannot.

What we will do:

  • Give the person the data is about final say over who sees it
  • Act on a verified request from a person whose information is held without authority (§3.5)
  • Remove a member from a family at the owner’s request
  • Preserve an audit trail of changes to health records so it is possible to see who changed what

What we will not do:

  • Adjudicate a family dispute, or decide who has authority over whose care
  • Take sides in a guardianship, custody or estate matter
  • Provide records in response to one family member’s request about another, absent legal authority
  • Restore access that someone has revoked

If a court order or other legal process requires us to act, we will comply, and we will notify the affected people unless prohibited.

8. death of a family member

If someone in your family dies, contact privacy@trylifelong.com. We will work with you sympathetically and will require documentation of your authority — a death certificate and evidence that you are the executor, next of kin, or personal representative — before transferring, releasing or deleting their information. Legal rights over a deceased person’s health information vary considerably by jurisdiction and we will follow the law that applies.

Please do not use another person’s account credentials after their death, even with the best of intentions. Contact us instead.

9. contact

privacy@trylifelong.comLifelong Company, 2810 North Church Street, Wilmington, DE 19802, United States.