Privacy policy

First published
This version effective since
Last updated

This policy explains what personal data Liv processes, why, on what legal basis, who receives it, where it is processed, how long we keep it, and what rights you have. Next to each part of the text is a plain-language summary (above it on small screens). The summaries help you find your way; the full text is what applies.

1. Who is responsible

This policy applies to the website liv.health, the Liv web app, the Liv mobile apps for iOS and Android, our events and all related services (together, the "Services"). The controller within the meaning of Art. 4(7) of the General Data Protection Regulation ("GDPR") is:

Liv Longevity Labs UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany. Registered at Amtsgericht Charlottenburg, HRB 262707 B. Managing director: Amer Hamzeh. Email: privacy@liv.health.

For every question about your data and for every request to exercise your rights, write to privacy@liv.health.

2. What data we process

Depending on which Services you use, we process the following categories of personal data:

  • Account data: name, email address, date of birth, biological sex, language, and, if you sign in with Google or Apple, the basic profile data that provider shares with us.
  • Wellness data you enter or connect: measurements such as weight, body composition, blood pressure, heart rate, heart-rate variability, VO2 max and grip strength; questionnaire answers, goals and plans. In the mobile app, only if you allow it, we read the measurement types you release from Apple Health or Google Health Connect, including in the background, and store them in your Liv account.
  • Test results: epigenetic results from TruDiagnostic, blood-panel results from Remi Health, and measurements taken at a Liv event or by a partner you book through Liv (for example VO2 max or grip strength), together with the reports, scores and recommendations we derive from them.
  • Sample collection details: when you confirm that you collected a sample, the collection date and the conditions you record (fasting, time of day, menstrual-cycle day, alcohol, illness, hard exercise, and a free-text note).
  • LivAI Chat conversations: the messages you write, the answers LivAI Chat gives, conversation titles, and any rating or feedback you leave on an answer.
  • Purchase data: products and plans bought, amounts, promo codes used, billing and shipping address, and a Stripe customer identifier. Card details are entered directly with Stripe; we never see or store your full card number.
  • Marketplace and booking data: products you buy from partners, appointments you book, and whether an appointment took place, was cancelled or missed.
  • Kit identifiers: the three-word Liv kit ID (for example quiet-cedar-dawn) printed on your test kit and linked to your account.
  • Circles: the circles you create or join and the people you invite by email.
  • Communication data: emails and messages you send us, and your email preferences.
  • Usage and device data: IP address, device and browser type, operating system, language, pages and screens viewed, actions taken in the Services, and error reports.
  • Partner account data: if you manage a partner profile on our marketplace, your name, email address, role, and any photo or text you publish on that profile.

Our legal counsel classifies the data you share with Liv as wellness data rather than health data within the meaning of Art. 9 GDPR, because Liv provides wellness and lifestyle information, not diagnosis or treatment. We nevertheless protect all of it with the same care.

3. What we do not do

  • We do not sell your personal data.
  • We do not buy data about you from data brokers.
  • We do not use your measurements, test results or LivAI Chat conversations to target advertising, on our Services or anywhere else.
  • We do not access your device location.
  • We do not collect biometric identifiers such as face or fingerprint data.

4. Purposes, legal bases and retention

For each purpose we list the legal basis under Art. 6(1) GDPR and how long we keep the data. Where we rely on legitimate interests (Art. 6(1)(f) GDPR), the interest is named in the table.

To provide the Services you use:

Purpose
Providing your account and the Services: sign-in, profile, measurements, results, reports, plans and Circles.
Legal basis
Performance of a contract, Art. 6(1)(b).
Retention
Until you ask us to delete your account.
Purpose
Running tests: shipping kits, registering samples with our lab partners and importing results, including measurement reports from events and partner sessions.
Legal basis
Performance of a contract, Art. 6(1)(b).
Retention
Until you ask us to delete your account.
Purpose
Operating LivAI Chat (section 5).
Legal basis
Performance of a contract, Art. 6(1)(b).
Retention
Conversations: until you delete them or your account.
Purpose
Payments, invoices and accounting.
Legal basis
Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c).
Retention
Up to 10 years, as required by § 257 HGB and § 147 AO.
Purpose
Marketplace purchases and bookings with partners (section 7).
Legal basis
Performance of a contract, Art. 6(1)(b).
Retention
Until you ask us to delete your account; invoices as above.
Purpose
Service emails: sign-in codes, order, shipping and booking confirmations, reminders.
Legal basis
Performance of a contract, Art. 6(1)(b).
Retention
Delivery logs are deleted by our email providers after a limited period.
Purpose
Support and answering your requests.
Legal basis
Performance of a contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f): helpful support.
Retention
Up to 3 years after the request is closed.

Only with your consent:

Purpose
Newsletter, event and product-update emails.
Legal basis
Consent, Art. 6(1)(a).
Retention
Until you unsubscribe.
Purpose
Web analytics and session recordings on the website (section 9).
Legal basis
Consent, Art. 6(1)(a) together with § 25(1) TDDDG.
Retention
Until you withdraw consent; recordings up to 90 days.
Purpose
Measuring our advertising (section 9).
Legal basis
Consent, Art. 6(1)(a) together with § 25(1) TDDDG.
Retention
Until you withdraw consent.

Based on our legitimate interests or a legal obligation:

Purpose
Monitoring and improving the quality of LivAI Chat answers (section 5).
Legal basis
Legitimate interests, Art. 6(1)(f): answers that are correct and safe.
Retention
Up to 400 days.
Purpose
Product analytics in the mobile app and server-side usage events (section 9).
Legal basis
Legitimate interests, Art. 6(1)(f): understanding which features work so we can improve them.
Retention
Until you ask us to delete your account.
Purpose
Error monitoring, security and bot protection.
Legal basis
Legitimate interests, Art. 6(1)(f): a working and secure service.
Retention
Up to 90 days.
Purpose
Understanding how sample-collection conditions affect results, so we can make our tests more reliable.
Legal basis
Legitimate interests, Art. 6(1)(f): reliable tests.
Retention
Until you ask us to delete your account.
Purpose
Legal obligations and defending legal claims.
Legal basis
Legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f).
Retention
For the statutory period or until the claim is resolved.

Where we rely on legitimate interests, you have the right to object (section 13).

5. LivAI Chat

LivAI Chat is an AI assistant in the Services. It answers questions about your measurements, results and goals, and to do so it can look up the data in your Liv account.

When you write to LivAI Chat, we send the following to Anthropic, PBC (San Francisco, USA), which runs the Claude language models that generate the answers: your message and the earlier messages in the conversation, your age and biological sex, and the measurements, results and focus areas LivAI Chat looks up to answer you. Anthropic processes this as our processor and, under our commercial terms, does not use it to train its models. A shorter model call generates a title for each conversation from its first messages.

We chose Anthropic because of how it builds its models. Anthropic trains Claude with a method it calls Constitutional AI: the model is given a written set of principles, its constitution, and during training it learns to judge and improve its own answers against those principles, guided by feedback that follows them rather than by human ratings alone. Anthropic publishes this constitution, so anyone, including us, can read the rules the model is trained to follow: to be genuinely helpful while being honest and avoiding harm.

For an assistant that reads your measurements and results, we think that matters more than anything else. We can check the principles behind its answers instead of taking them on trust. Anthropic is also organised as a public benefit corporation, which obliges it to weigh the public good alongside profit, and it does not train its models on the data we send. In our assessment, no other provider currently combines this openness with models of comparable quality, which is why we trust Anthropic more than any alternative.

Our long-term goal is to run our own models on infrastructure we control. We are not there yet. Until we are, we consider Anthropic the best available choice. If we change provider, we will update this policy before the change takes effect.

We record each LivAI Chat exchange in LangSmith, a monitoring service from LangChain, Inc., hosted in the EU. A record contains the conversation, the data LivAI Chat looked up, your Liv user ID, a one-way hash of your email address, and any rating or feedback you leave. We use these records to find errors and improve the quality and safety of answers, and keep them for up to 400 days.

Your conversations are stored in your Liv account so that you can return to them. You can delete any conversation at any time. Deleting it removes it from your account; monitoring records in LangSmith are removed when their retention period ends or when you ask us to delete your data.

Our team also uses an internal AI assistant, likewise powered by Anthropic, to answer support and operational questions. It can look up member data, including name, email address, date of birth and measurements, when a team member needs it to help you.

LivAI Chat gives general wellness information. It is not a medical device, does not diagnose or treat anything and does not replace a doctor. Answers can be wrong. In an emergency, call 112.

6. Circles

Circles let you share your Liv data with people you choose, such as your family. Everyone in a circle can see the profile, measurements, reports and test results of every other member, and can edit other members’ profiles and plans. We only process this sharing because you asked for it (Art. 6(1)(b) GDPR).

Only invite people you trust with this data. When you leave a circle, its members lose access to your data from that moment on.

7. Labs, measurement partners and marketplace partners

TruDiagnostic LLC (Lexington, Kentucky, USA) analyses epigenetic kits. It receives your blood sample, labelled only with your kit ID, together with your date of birth, biological sex, collection date and a random Liv user identifier. It does not receive your name, email address or postal address, and it cannot link the kit to you without information only Liv holds. TruDiagnostic processes this data for us and is additionally responsible for its own statutory laboratory records.

Remi Health GmbH (Knesebeckstraße 33–34, 10623 Berlin) processes blood-panel kits. To match your sample to you, Remi receives your first and last name, date of birth, sex, kit activation code and sample date, and sends the results back to us.

VentriJect ApS (Denmark) calculates your VO2 max from the measurement taken at a Liv event or a session booked through Liv, as our processor.

When you are measured at a Liv event or by a partner at a session booked through Liv, the partner or the maker of the measuring device sends us the measurement report. Our team matches each report to your booking and checks it before the results appear in your account.

Our marketplace partners (for example practices, clinics and product brands) are independent controllers for the services and products they provide to you. When you buy from a partner through Liv, the payment is made to the partner’s own Stripe account: a customer record containing your email address and your Liv user ID is created there, and the partner can see the purchase. Partners can also see the Liv products and services you have bought from them. When you book an appointment, the partner receives your name, email address, the service and the time. If you follow a partner’s link to their own website, their privacy policy applies there.

When your plan includes a partner product, such as RIISE supplements, we pass the partner the order details needed to fulfil it. Shipping carriers receive your name and shipping address to deliver your kit.

8. Service providers and where your data is processed

We use the following service providers. Unless the table says otherwise, they process data only on our instructions under a data processing agreement pursuant to Art. 28 GDPR. These providers process data in the EU or the European Economic Area:

Provider
Supabase, Inc.
Purpose
Database, sign-in and file storage for all account data
Location
Frankfurt, Germany
Provider
LangChain, Inc. (LangSmith)
Purpose
Quality monitoring of LivAI Chat
Location
EU
Provider
PostHog, Inc.
Purpose
Product analytics, session recordings, feature flags
Location
Frankfurt, Germany
Provider
Functional Software, Inc. (Sentry)
Purpose
Error monitoring
Location
Frankfurt, Germany
Provider
Stripe Payments Europe, Ltd.
Purpose
Payments; independent controller for payment processing
Location
Dublin, Ireland
Provider
Brevo (Sendinblue SAS)
Purpose
Newsletter, email preferences and purchase confirmations
Location
France
Provider
Usercentrics A/S (Cookiebot)
Purpose
Cookie consent management
Location
Copenhagen, Denmark
Provider
Apple Distribution International Ltd.
Purpose
Sign in with Apple; independent controller
Location
Cork, Ireland
Provider
Sanity AS
Purpose
Content management for our blog and website content
Location
Oslo, Norway
Provider
Remi Health GmbH
Purpose
Blood-panel analysis (section 7)
Location
Berlin, Germany
Provider
VentriJect ApS
Purpose
VO2 max calculation (section 7)
Location
Denmark

These providers process data in the USA, fully or in part:

Provider
Vercel, Inc.
Purpose
Hosting of the website and web app; privacy-friendly page statistics without cookies
Location
USA (servers in Washington, D.C.); content delivered from Frankfurt
Provider
Anthropic, PBC
Purpose
AI models for LivAI Chat and our internal assistant
Location
USA
Provider
ActiveCampaign, LLC (Postmark)
Purpose
Sign-in codes, booking emails and newsletter confirmation links
Location
USA
Provider
Cloudflare, Inc. (Turnstile)
Purpose
Bot protection on sign-in forms
Location
USA
Provider
Google Ireland Limited
Purpose
Tag Manager, Google Analytics and Google Ads measurement (only with consent), web fonts, Google sign-in
Location
Ireland and USA
Provider
Reclaim.ai, Inc.
Purpose
Scheduling onboarding calls
Location
USA
Provider
Salesforce, Inc. (Slack)
Purpose
Internal order notifications, with email addresses masked
Location
USA
Provider
Luma (lu.ma)
Purpose
Event registration; independent controller when you register on lu.ma
Location
USA
Provider
TruDiagnostic LLC
Purpose
Epigenetic analysis (section 7)
Location
Lexington, USA

Some of these providers process data in the USA, or are US companies that may access data held in the EU. For transfers to the USA we rely on the EU-U.S. Data Privacy Framework (adequacy decision under Art. 45 GDPR) where the recipient is certified under it, and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can request a copy of the safeguards at privacy@liv.health.

9. Cookies, analytics and advertising measurement

On our website we use cookies and similar technologies in three groups, managed with Cookiebot:

  • Necessary: keeping you signed in, remembering your language and consent choice, processing payments with Stripe, and protecting forms with Cloudflare Turnstile. These are allowed without consent under § 25(2) no. 2 TDDDG.
  • Statistics (only with consent): PostHog product analytics and session recordings, and Google Analytics. Text you type into forms is masked in recordings.
  • Marketing (only with consent): Google Ads conversion measurement through Google Tag Manager. We report only that a sign-up or purchase happened and its value, never your measurements or results.

You can change your choice at any time using the Cookiebot banner, or, once you are signed in, via "Manage cookies" in the web app menu. Withdrawing consent does not affect processing that happened before.

Independently of cookies, we use Vercel Web Analytics, which counts page views without cookies or cross-site identifiers, and Sentry, which records technical error reports. Both are based on our legitimate interest in a working service (Art. 6(1)(f) GDPR). Our website also loads fonts from Google’s servers, which transmits your IP address to Google (Art. 6(1)(f) GDPR: consistent display of our website).

In the mobile apps we use PostHog to understand which screens and features are used. The app links these events to your account, including your email address, and does not record your screen. We also record certain events on our servers, such as sign-ups and bookings, linked to your account. This is based on our legitimate interest in improving the Services (Art. 6(1)(f) GDPR); you can object at any time (section 13).

10. Mobile app permissions

The Liv app only asks for permissions it needs:

  • Apple Health / Google Health Connect (optional): read access to VO2 max, resting heart rate, heart-rate variability, heart-rate recovery, blood pressure, weight, lean body mass and body fat, including in the background so your data stays current. Liv only reads this data, never writes to it, and stores it in your Liv account. You can revoke access at any time in your phone’s settings.
  • Camera (optional): to scan your payment card at checkout. The image is processed on your device by Stripe’s payment form.

Data from Apple Health and Google Health Connect is never used for advertising or passed to data brokers.

11. Emails

We send service emails, such as sign-in codes, order, shipping and booking confirmations, and reminders, because they are part of the Services. When you create an account, your email address is stored with our email provider Brevo so that we can send these messages and manage your preferences.

Newsletters, event invitations and product updates are sent only if you have subscribed. When you subscribe, we first email you a link to confirm; only after you confirm do we add you to the list, together with when you confirmed, where you signed up and your language, so that we can show your consent. If you are on our blocklist and subscribe and confirm again, we lift the blocklist for the newsletter only. You can choose which emails you receive in Settings → Emails, and every newsletter contains an unsubscribe link. After you unsubscribe, we keep your email address on a blocklist so that you are not emailed again. This is based on our legitimate interest in respecting your choice (Art. 6(1)(f) GDPR).

12. Other recipients

Beyond the recipients named in this policy, we disclose personal data only where the law requires it (for example to courts or authorities), and in the event of a merger, sale or financing of Liv, to the other party under confidentiality and only if the transaction completes. We will tell you about such a change in advance.

13. Your rights

You have the right to:

  • access the data we hold about you and receive a copy (Art. 15 GDPR);
  • have incorrect data corrected (Art. 16 GDPR);
  • have your data deleted (Art. 17 GDPR), except where we are legally required to keep it;
  • restrict processing (Art. 18 GDPR);
  • receive your data in a machine-readable format (Art. 20 GDPR);
  • object to processing based on legitimate interests (Art. 21 GDPR), and to direct marketing at any time;
  • withdraw any consent with effect for the future (Art. 7(3) GDPR);
  • lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin.

To exercise any of these rights, including deleting your account, email privacy@liv.health from the address linked to your account. We respond within one month.

14. Security

Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to your data is restricted by database access rules, and only team members who need it for their work can access production data. We choose providers that meet recognised security standards. If a data breach puts your rights at risk, we will inform the supervisory authority and, where required, you, as set out in Art. 33 and 34 GDPR.

15. Minors

The Services are intended for adults aged 18 and over. If you believe that someone under 18 has given us their data, please let us know at privacy@liv.health and we will delete it.

16. No automated decisions

We do not make decisions based solely on automated processing that have legal effects on you or similarly significantly affect you (Art. 22 GDPR). Scores, reports and LivAI Chat answers are information for you, not decisions about you.

17. Changes to this policy

We update this policy when our Services, providers or the law change. The dates at the top show when this version took effect and when it was last updated. We will tell you directly about significant changes before they take effect.