← Back to home

privacy policy

Effective: 16 August 2026Last updated: 16 August 2026

a note from the founders

We built Lifelong because our own families needed it. The first version was a record one of us kept of our grandmother’s care in the last year of her life. That is the standard we hold ourselves to: we are asking you to put your family’s health in our hands, and there is no version of that which works without trust.

So, plainly, before the legal language:

  • We will never sell your health data. Not to advertisers, not to data brokers, not to insurers, not to anyone.
  • We will never run ads against your health data. Lifelong makes money from subscriptions. That is the whole business model, deliberately.
  • We will never train our models on your identifiable health data. We improve Lifelong using de-identified and aggregated data only, and we require our AI vendors by contract to use what we send them only to provide the service and never to train their models.
  • Your family sees only what you choose to share. During setup you explicitly choose what your family can see, and you can narrow, change, or revoke it — per category, per person — at any time.

If any of that ever stops being true, we will tell you before it changes, not after.

Questions, concerns, or a request about your data: privacy@trylifelong.com

1. who we are

Lifelong is operated by Lifelong Company, a Delaware corporation.

Legal entityLifelong Company
Address2810 North Church Street, Wilmington, DE 19802, United States
Privacy contactprivacy@trylifelong.com
Privacy OfficerRazi Syed, reachable at the address above

In this policy, "Lifelong", "we", "us" and "our" mean Lifelong Company. "You" means the person using our mobile application, our website at trylifelong.com, and any related services (together, the "Services").

2. what this policy covers, and what else you should read

This policy describes everything we do with personal information across the Services. Three other documents sit alongside it and form part of the same commitment:

  • Consumer Health Data Privacy Policy — required by Washington’s My Health My Data Act, Nevada SB 370, and Connecticut law. It covers consumer health data specifically and gives you additional rights. If you live in Washington, Nevada or Connecticut, read it.
  • Notice at Collection — the California-required summary of what we collect and why, in table form. Available on request from privacy@trylifelong.com.
  • Australian Privacy Addendum — if you are in Australia.

Where this policy and one of those documents differ for your location, the more specific document governs.

3. our regulatory position, stated honestly

Lifelong is not a HIPAA covered entity. We are a consumer application. You bring your own health information to us — we do not receive it from your doctor as a healthcare provider or insurer would. That means HIPAA does not apply to us as a matter of law, and we think you should know that rather than discover it.

What does apply to us, and what we hold ourselves to:

  • The FTC Act and the FTC Health Breach Notification Rule, which require us to tell you and regulators if health information is breached.
  • State consumer health privacy laws, including Washington’s My Health My Data Act, which give you specific rights over health data and, in Washington, a right to sue us directly.
  • State comprehensive privacy laws including the CCPA/CPRA in California.
  • GDPR and UK GDPR, if you access the Services from the EEA or the UK, under which your health data is "special category" data requiring your explicit consent.
  • The Australian Privacy Act 1988 and the Australian Privacy Principles.
  • Apple’s HealthKit terms, which independently prohibit us from using HealthKit data for advertising, selling it to data brokers, or storing it in iCloud. We comply.

If Lifelong ever becomes a business associate of a covered entity — for example if we integrate directly with a health system — we will sign a Business Associate Agreement and update this policy before that data starts flowing.

4. information we collect

4.1 Information you give us

WhatExamplesRequired?
AccountName, email address, password (held by our authentication provider, never by us in readable form)Required
ProfileDate of birth, gender, height, family role; ethnicity (optional — you can skip it); profile photo (optional)Date of birth, gender and height are asked at setup. Ethnicity and photo are optional
Onboarding contextYour health goals, your household situation, a free-text note about your familyOptional
Health recordsDocuments, lab results, discharge summaries, imaging reports and any other files you uploadOptional
Care informationConditions, allergies, medications, symptoms, journal entries, appointmentsOptional
Visit recordingsAudio you record of a medical appointment, and the transcript we produce from itOptional
ConversationsMessages you exchange with Alo, our health assistant, in the app or over iMessage, including files you attachOptional
Family informationThe family you create or join, who is in it, their roles, and the sharing permissions you setRequired to use family features
Information about othersHealth information you file about a family member who does not have a Lifelong account — see §7Optional
SupportWhat you tell us when you contact us or give feedbackOptional

4.2 Information from your devices and connected services

WhatSourceNotes
Health and fitness dataApple Health / HealthKit, Android Health Connect, Samsung HealthOnly after you grant permission, and only the categories you approve
Wearable dataApple Watch, Oura, Whoop and other services you connectOnly after you authorise the connection. We receive data; we never receive your password for those services
LocationYour device, once, at the moment you start recording a medical visitA single reading so the record can show which clinic you were at. We store the coordinates and the place name and address they resolve to. We never track you in the background. Refusing this permission is a completely normal way to use Lifelong
Device and app dataAutomaticallyDevice model, operating system, app version, language, time zone, and a device identifier for push notifications
Usage dataAutomaticallyWhich screens you open and which features you use. See §4.3
Crash dataAutomaticallyDiagnostic information when the app fails

4.3 A specific note on session recordings

Our analytics tool captures masked screen recordings of app sessions to help us find usability problems. These recordings are captured in a mode where all text, all input fields and all images are obscured — we see the shape of the screen and where you tapped, never the content. No health value, name, number or photograph appears in a frame. Console logs and network traffic are excluded. This runs only in the App Store version of the app, never in test builds.

4.4 Cookies and browser storage

We use a privacy-focused, cookieless analytics service on trylifelong.com. It sets no cookies, stores no persistent identifier, and does not track you across other websites. Because there is nothing to consent to, it runs for everyone and is not covered by the choice below.

Beyond that, we store two things in your browser. An attribution record, in local storage, remembering how you first arrived — the page you landed on, the site that referred you, and any campaign or advertising click identifiers carried in the link you followed (for example from Google, Meta, LinkedIn, TikTok, Microsoft or X) — so we can understand which campaigns work. And a short-lived session record, in session storage, which groups your page views into a single visit and holds your progress if you start the sign-up flow. The session record is strictly necessary for the sign-up flow to work, so it is not something we ask about.

If you are in the European Economic Area, the United Kingdom or Switzerland, we ask before writing the attribution record. A banner appears on your first visit offering Accept and Reject as equally weighted choices, with nothing pre-selected. Until you accept, nothing is written; if you reject, or close the banner without choosing, nothing is written and anything already stored is deleted. To work out which region you are in we set one short-lived cookie holding a two-value region flag and nothing that identifies you.

Everywhere else, including the United States, Canada and Australia, we store the attribution record on the basis of this disclosure. You can withdraw that at any time using the control below, or by clearing site data in your browser — and a rejection made here is honoured wherever you are.

Global Privacy Control. If your browser or an extension sends the Global Privacy Control signal, we treat it as a rejection of the attribution record — wherever you are, not only where the law obliges us to. In practice that means three things. We do not write the record, and we delete it if an earlier visit left one behind. We do not show you the banner, because asking someone to repeat a preference they have already expressed is not a real choice. And if you decide you want to change your mind, the control below still works — an explicit Accept from you overrides the signal, and we record that you overrode it, along with when.

We detect the signal two ways, because either one alone would miss people: the Sec-GPC header on the request, and the globalPrivacyControl property your browser exposes to the page. Either is enough. We do not keep a record of the signal beyond a short-lived cookie holding a single yes/no that lets the page see what the request already told us.

We do not use any of this to show you advertising, and we do not send it back to advertising platforms. There is no sale of personal information, no sharing for cross-context behavioural advertising and no targeted advertising to opt out of — so beyond the storage above, there is nothing else for a Global Privacy Control signal to switch off here.

4.5 Information we generate

Lifelong’s core function is turning your information into something useful, so a great deal of what we hold is derived rather than collected: health scores and baselines, trend alerts, a structured timeline of conditions and events built by reading your uploaded documents, appointment preparation briefs, summaries of family members’ health, and the assistant’s working memory of what matters to you.

We treat derived health information exactly as sensitively as the information it came from. It is health data, and it is covered by every commitment in this policy, including deletion.

4.6 Information we deliberately do not collect

  • We do not collect your government identification, social security number, or biometric identifiers.
  • We do not collect precise location on any ongoing basis, and never in the background.
  • We do not buy personal information from data brokers.
  • We do not use advertising identifiers or cross-app tracking, and we do not permit third parties to collect data about you across other apps and websites through Lifelong.

5. why we use your information

PurposeWhat this looks likeLegal basis (EEA/UK)
Providing the ServicesYour account, your family, your records, your timeline, your alerts, your assistantPerformance of a contract; explicit consent for health data
Making sense of your health informationReading your uploaded documents, extracting structure, generating insights, preparing you for appointmentsExplicit consent
Sharing within your familyShowing family members exactly what you have chosen to share with themExplicit consent
Communicating with youService messages, alerts, appointment reminders, security noticesContract; legitimate interests
MarketingProduct news, only if you opted inConsent
Improving LifelongUnderstanding which features work, fixing crashes, measuring performanceLegitimate interests; de-identified data only for anything involving health information
Safety and securityPreventing fraud, abuse and unauthorised accessLegitimate interests; legal obligation
Legal complianceResponding to lawful requests, defending claims, meeting our obligationsLegal obligation; legitimate interests

Automated decision-making: Lifelong generates insights, alerts and suggestions automatically. These are informational. They do not produce legal or similarly significant effects, they never determine access to healthcare, insurance, employment or credit, and they are not a diagnosis. See the Medical Disclaimer.

Which parts of Lifelong are substantially automated. So that this is concrete rather than a reassurance: the things Lifelong works out on its own are health scores and baselines, trend detection and the alerts that follow from it, the structure it builds by reading your uploaded documents, and AI-generated summaries, briefs and suggestions, including those from Alo. All of them inform you; none of them, by itself, makes a decision with a legal or similarly significant effect on anyone. Nothing is written to a health record, shared with anyone, or sent outside Lifelong on the strength of an automated output alone — a person is always the one who acts. The AI and Alo Disclosure explains each of these in more detail.

6. how we use artificial intelligence

Lifelong uses AI extensively — to read your documents, structure your health timeline, generate insights, transcribe visit recordings, and power Alo. This deserves its own explanation, and it has one: the AI and Alo Disclosure. The commitments in short:

  • Your identifiable health data is never used to train any AI model — not ours, not a vendor’s. Health information processed by our AI providers is encrypted in transit, contractually restricted to providing the service, and not used to train their models.
  • We improve our own product using de-identified and aggregated data only (see §9).
  • AI vendors process on our instructions. Content is sent, a result comes back, and the vendor is contractually prohibited from using it for anything else.
  • Transcription providers are purged. When a visit transcript is returned to us, we issue a deletion instruction to the transcription provider and record that it succeeded. If it fails, an automated process retries until it does.

What we do not claim. We do not tell you that content is de-identified before it reaches an AI provider, because for most of the product it is not. Some features strip names before the prompt is sent — visit summaries, visit-recording actions, home insights, and alert explanations — and names are reattached afterwards on our own systems. Other paths send identifiable content: a conversation with Alo carries your name, your account identifier and what you are asking about; a document you upload can be sent to a model as the file itself, including page images of a scan; audio of a visit is sent to a speech-recognition provider as recorded. What protects that content is not anonymity — it is encryption in transit, a written contract that limits the provider to processing on our instructions, and a prohibition on training. The AI and Alo Disclosure §3 sets out feature-by-feature what leaves our systems.

7. family sharing, and information about other people

This is the part of Lifelong that is genuinely different from other health apps, so it gets a plain explanation. Full detail is in the Family Sharing and Authorized Representative Terms.

You choose what your family sees, explicitly, during setup. When you set up Lifelong you decide what your family can see. Sharing your full health data with your family is the option we recommend — Lifelong works best when your family can actually help — and it takes your affirmative confirmation; we never share anything you have not confirmed. You can narrow, change, or revoke sharing per category — daily signals, records, medications, symptoms, conditions, allergies, journal — and per person, at any time. You can grant one relative access to everything and another access to nothing. Revocation takes effect immediately in the app, and we propagate it across our systems promptly and without undue delay.

When you file records about someone who does not have an account. Lifelong lets you keep records for a parent, a child, or anyone else you care for who is not a Lifelong user. When you do this, you are telling us you have the authority to act on that person’s behalf — as their legal representative, their parent, their carer, or with their permission. We rely on that. If that person later joins Lifelong, the records become theirs, along with every right in this policy. If you believe someone has filed information about you without the authority to do so, email privacy@trylifelong.com and we will investigate.

When you record a medical visit. Other people are in the room. Recording law varies by state and country, and in many places you need everyone’s consent. That obligation is yours, and our Recording Consent Notice — which you are asked to acknowledge in the app before you first record — explains it.

When you talk to Alo in a group chat. If you bring Alo into a group conversation, messages in that conversation are processed and stored as described in this policy — including messages from people who are not Lifelong users. Tell them.

8. who we share information with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either, and we have no plans to. If that ever changes we will obtain your consent first — and for health data, the separate written authorization that law requires.

We disclose personal information to:

Service providers. Companies that run parts of Lifelong under contract: service providers that assist us with cloud infrastructure and hosting, AI processing (large language model, transcription, and voice providers), authentication, payments, communications, and analytics. Each is bound by contract to process data only on our instructions, protect it, and not use it for their own purposes.

Because AI providers handle health information, we are specific about them: health information processed by our AI providers is encrypted in transit, contractually restricted to providing the service, and not used to train their models. De-identified data may be used to improve our own product.

Your family, as you direct. Only the categories and people you have chosen.

People and organisations you choose. If you use Lifelong to share records with a caregiver, a clinician or anyone else outside your family, we do that at your direction and only with the specific authorization you give at the time. You can revoke it.

Legal and safety. When we are legally required to, or where we believe in good faith it is necessary to protect someone’s life or safety, investigate fraud, or defend legal claims. We will notify you unless legally prohibited, and we will resist requests we think are overbroad.

A future owner. If Lifelong is acquired or merges, your information may transfer as part of that transaction. The acquirer would be bound by this policy, and we will notify you before your information becomes subject to a different one, with the ability to delete your account first.

We do not disclose your information to insurers, employers, credit agencies, data brokers, or advertising platforms. Full stop.

9. de-identified and aggregated data

We use de-identified and aggregated data to improve Lifelong, train and evaluate our own models, produce benchmarks, and conduct research about family caregiving.

Because "de-identified" is a word companies abuse, here is exactly what we mean:

  • We de-identify to a standard equivalent to HIPAA Safe Harbor — removing names, contact details, precise dates, geographic detail below state level, account identifiers, and every other direct or indirect identifier that could reasonably single someone out.
  • We contractually prohibit re-identification by anyone who receives it, and we do not attempt re-identification ourselves.
  • We maintain de-identified data as de-identified and do not attempt to link it back.
  • We do not sell de-identified health data.
  • These uses exclude data that law or feature-specific terms restrict — for example, information obtained from government-operated record systems is used only as those systems’ rules allow, and is excluded from our de-identified data uses.

If we publish research or benchmarks, they will describe populations, never people.

10. where your information is held, and international transfers

Lifelong is operated from the United States. Your personal and health information is stored and processed in the United States, except where we tell you otherwise for a specific feature, and in other locations where our service providers operate.

Some features or integrations — for example, connections to government-operated record systems — may be legally required to keep certain data only in a particular country. Where that applies, we will say so in the feature itself, and that data will not be transferred elsewhere.

If you are outside the United States, including in the EEA, the United Kingdom, Australia, Canada or New Zealand, your information is transferred to and processed in the United States, which may not provide the same level of legal protection as your home country.

If you access the Services from the EEA or the UK, transfers of your information rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical and organisational safeguards. You can request a copy of the relevant transfer mechanism by emailing privacy@trylifelong.com.

11. how long we keep information

While your account is open, we keep your information so the Services work. Health records are the point of Lifelong — a timeline that only goes back six months is not a timeline — so we keep them until you delete them or close your account.

CategoryRetention
Account and profileUntil you delete your account
Health records, care information, timelineUntil you delete them, or you delete your account
Visit recording audioDeleted automatically once the transcript is confirmed. If transcription fails, the audio is kept so you don't lose the appointment, and you can delete it
Visit transcripts and summariesUntil you delete them, or you delete your account
Audio held by our transcription providerDeleted at the provider once the transcript is returned to us — verified, with automatic retry if it fails
Assistant conversationsUntil you delete them, or you delete your account
Usage and analytics dataUp to 12 months
Crash and error diagnosticsUp to 90 days
Server logsUp to 30 days
Marketing contact recordUntil you unsubscribe or delete your account
Records we must keep by law (tax, accounting, proof we honoured a deletion request)As long as the relevant law requires

When you delete your account, deletion from our live systems is completed within 45 days of your verified request. Residual copies in encrypted backups expire within 7 days after that. After that, only the legally-required records above remain, and they are never used for any other purpose.

Two things we want to be exact about, because they are easy to gloss over:

  • Information you shared with your family may persist. If you added a record to a shared family space, deleting your account removes your access and your own data, but content your family relies on may remain with them. If you want it removed entirely, delete it before closing your account.
  • Deleting your Lifelong account does not cancel your subscription. Apple manages subscriptions. Cancel it in your device’s Settings.

12. security

We protect your information with:

  • Encryption in transit using TLS 1.2 or higher for every connection
  • Encryption at rest using AES-256 for stored data and backups
  • Authentication operated by a specialist provider; we never store your password in a form we can read
  • Access controls limiting which of our staff can reach production data, on a need-to-know basis, with access logged
  • Isolated environments so testing and development never touch real user data
  • Audit logging of changes to health records and of assistant activity
  • Vendor requirements including contractual security obligations and, where a vendor offers one, a Business Associate Agreement

We are honest about the limits: Lifelong is not end-to-end encrypted. We can read your data on our servers, because reading it is how the product works — extracting structure from a lab report, generating an insight, answering a question. Any service that does those things can see your data. We minimise who and what can reach it, we log access, and we never use it for anything outside this policy.

No system is perfectly secure. If a breach affects your health information, we will notify you and the appropriate regulators as required by the FTC Health Breach Notification Rule, GDPR, and applicable state laws.

13. your rights and choices

Everyone who uses Lifelong gets the following rights, regardless of where they live. We did not want a policy where your rights depend on your postcode.

RightWhat it means
KnowWhat we collect, why, who we share it with, and how long we keep it
AccessA copy of the personal information we hold about you
PortabilityOn request, your data in a structured, machine-readable format you can take elsewhere
CorrectFix anything inaccurate
DeleteRemove your information and close your account. Deletion from our live systems is completed within 45 days of a verified request
Withdraw consentTurn off health data processing, sharing, marketing or connected services at any time. Withdrawal does not undo processing that already happened
Non-discriminationWe will never give you a worse service or price for exercising these rights
AppealIf we deny a request, you can appeal, and we will explain ourselves

Additional rights where the law where you live provides them. Some rights exist only under particular laws, and we honour them for the people those laws cover — for example, if you are in the EEA or the UK, the right to object to processing based on legitimate interests and the right to ask us to restrict processing, along with the other rights the GDPR and UK GDPR give you. Other jurisdictions grant their own; where a law where you live gives you a right that is not in the table above, you have it, and you can exercise it the same way.

Opting out of sale, sharing, or targeted advertising: there is nothing to opt out of. We do not do any of these things.

How to exercise a right. Use the privacy request form — it records your request with the time it arrived and the date our answer is due — or, if you would rather, in the app (where available) or by email to privacy@trylifelong.com. All three are equally valid. We will acknowledge within 10 business days and complete verified requests within 45 days where the law sets that period or is silent, and sooner where the law where you live requires a faster response — in Australia, for example, we respond within 30 days. Where the law allows a longer period, we may take it, and we will say so. We may extend once by a further 45 days where the law permits, and if we do we will tell you why. We may need to verify your identity first — for health data we will ask for enough to be confident, because handing your records to an impostor is the worse failure.

Requests are free — with one narrow exception. We do not charge you for exercising these rights. Where a request is manifestly unfounded, excessive, or repetitive, we may instead charge a reasonable fee reflecting the administrative cost of dealing with it, or decline to act on it. If we decline, we will tell you why and how to appeal. This does not apply where the law prohibits a fee or a refusal — including requests about consumer health data, which are always free and unconditional; see the Consumer Health Data Privacy Policy.

Authorised agents. You may use an authorised agent. We will ask for proof of their authority and may verify with you directly. The request form asks who you are acting for, so we know which check applies before we start.

Appeals. Reply to our decision or email privacy@trylifelong.com with "Appeal" in the subject. We will respond within 45 days with our reasoning. If we deny your appeal you may complain to your state Attorney General, your supervisory authority in the EEA/UK, or the Office of the Australian Information Commissioner.

Complaints in the EEA/UK. You have the right to lodge a complaint with your local supervisory authority. We would rather you came to us first, but that right is yours regardless.

14. children and teenagers

Families include children, so Lifelong has to be clear about how young people appear in it. There are three situations, and they work differently.

1. A child of any age, on a profile a parent manages. Children can be the subject of health records in Lifelong from birth — that is a real and important use case, because families coordinate children’s care. The child does not have a login. A parent or legal guardian keeps the records on a profile they manage from their own account, and when they do they confirm they are that child’s parent or legal guardian, or are otherwise legally authorised to make decisions about their health information.

The important part, and the reason this is safe: information about a child on a managed profile is collected from the parent, not from the child. The parent types it, uploads it, or records it. Because of that, a child’s own device must not be connected to a profile you manage for them — no Apple Health, Health Connect, Samsung Health or wearable account belonging to the child. Those connections are only available on a person’s own account.

We do not knowingly collect personal information directly from a child under 13. If we learn that we have, we delete it.

Child-profile information is never used for marketing. It is excluded from marketing messages, from marketing and advertising audiences, and from any audience-building or profiling of any kind. It is health information and it is covered by every commitment in this policy.

2. A teenager aged 13 to 17, with their own account. The minimum age to hold a Lifelong account is 13. Anyone under 18 needs the permission of a parent or legal guardian, which we record before the account can be used, and that parent or guardian agrees to our Terms alongside the teenager.

A teenager gives their own consent to our handling of their health information and exercises their own privacy rights over it — the rights in §13 are theirs, not their parent’s. A parent’s permission to create the account is not a substitute for the teenager’s consent, and a parent cannot give that consent for them.

3. Under 13. No accounts. Under-13s appear in Lifelong only as a managed profile, as described above.

What a parent can and cannot see on a teenager’s account

Because a parent approved the account, a parent can see a basic care picture by default — appointments, medications, immunisations, allergies and general wellbeing summaries — and can be told when something needs their attention.

Some things are private from a parent by default, and only the teenager can change that:

  • Journal entries
  • Symptoms the teenager logs themselves
  • Conversations with Alo
  • Anything relating to reproductive or sexual health, mental health, or substance use

A teenager can choose to share any of these with a parent, in the same per-category, per-person way every other Lifelong member controls sharing. A parent cannot switch it on for them, and we will not do it on a parent’s request. Where there is a safety concern, a parent receives a notification that a safety resource was offered — not the conversation itself.

Sharing on a teenager’s account starts off, category by category. We explain all of this in plain language to both the teenager and the parent when the account is set up.

At 18 the account becomes an ordinary adult account: full control passes to the young adult and any parental access ends unless they choose to grant it again.

Questions, or something wrong. A parent or a teenager can email privacy@trylifelong.com at any time — to ask what is held, to correct or delete it, to withdraw permission or consent, or to tell us a child holds an account they should not, or that a child’s information is in Lifelong without proper authority. We act promptly, and we will not require a teenager to go through their parent to reach us about their own information.

15. changes to this policy

We will update this policy as Lifelong changes. When we do:

  • We update the "last updated" date and post the new version
  • For material changes — anything that meaningfully changes what we do with your information — we will notify you by email and in the app before the change takes effect, and where the law requires it, we will ask for your consent
  • We keep previous versions available so you can see what changed

We will never make a material change quietly.

16. contact us

Privacy questions and requestsprivacy@trylifelong.com
Privacy OfficerRazi Syed
PostLifelong Company, 2810 North Church Street, Wilmington, DE 19802, United States

If you are in Australia and are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the EEA or UK, you may complain to your local supervisory authority. If you are in the United States, you may contact your state Attorney General or the Federal Trade Commission.