Privacy Policy.

Last updated on 2026-01-23.

1. Introduction

Welcome to Longeve. We are committed to protecting your privacy and ensuring you have a positive experience using our Longeve mobile application ("App") privided by One bad idea, MB ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.

We are based in Lithuania and comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Online Privacy Protection Act (CalOPPA).

By using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the App.


2. Information We Collect

2.1 Health and Fitness Data (via Apple HealthKit)

With your explicit permission, we access and process the following types of health data from Apple HealthKit:

Biometric Data:

  • Heart rate and resting heart rate

  • Heart rate variability (HRV)

  • Blood oxygen saturation

  • Respiratory rate

  • Body temperature (wrist temperature during sleep)

  • VO2 Max

Activity Data:

  • Workouts and exercise sessions

  • Active and basal energy burned

  • Step count

  • Physical effort and workout effort scores

  • Distance (walking, running, cycling, swimming, etc.)

  • Stand time, move time, and exercise time

Sleep Data:

  • Sleep analysis and sleep stages

  • Breathing disturbances during sleep

Other Health Data:

  • Mindfulness sessions

  • Environmental audio exposure

  • Time in daylight

Characteristic Data:

  • Biological sex (for metric calculations)

  • Date of birth (for age-based calculations)

2.2 User-Provided Information

You may optionally provide:

  • Age

  • Weight

  • Activity level

  • Sleep schedule preferences

2.3 Automatically Collected Information

Device and Usage Information:

  • Device type and operating system version

  • App version and build number

  • Anonymous usage analytics (screens viewed, features used)

  • Crash reports and error logs

Important: We use anonymous authentication only. We do not collect your name, email address, phone number, or any other personally identifiable contact information.


3. How We Use Your Information

We use the information we collect to:

  • Calculate Health Metrics: Generate your Recovery Score, Strain Score, Sleep Score, and Stress levels

  • Display Insights: Show trends, charts, and personalized health insights

  • Improve the App: Analyze usage patterns to enhance features and user experience

  • Ensure Stability: Identify and fix crashes and technical issues

  • Provide Support: Respond to your inquiries and support requests

We do not use your data for:

  • Advertising or marketing purposes

  • Selling to third parties

  • Creating advertising profiles


4. Data Storage and Security

4.1 Local Storage Only

All your health and fitness data is stored locally on your device. We do not upload, sync, or store your health data on external servers or cloud services. Your health information never leaves your device.

Your data is stored in a secure SQLite database protected by:

  • iOS device encryption

  • App sandboxing

  • Secure Enclave protection (on supported devices)

4.2 Data You Control

Since all health data is stored locally:

  • Only you have access to your health information

  • Deleting the App removes all stored health data

  • No account recovery is possible (data exists only on your device)


5. Third-Party Services

We use the following third-party services that may collect limited, non-health information:

5.1 Firebase Analytics (Google)

5.2 Firebase Crashlytics (Google)

5.3 Apple HealthKit

Important: We do not share any health data with these third-party services. Analytics and crash reporting contain only technical, non-health information.


6. Your Privacy Rights

6.1 Rights Under GDPR (European Users)

If you are located in the European Economic Area (EEA), you have the following rights:

  • Right to Access: Request a copy of your personal data

  • Right to Rectification: Request correction of inaccurate data

  • Right to Erasure: Request deletion of your data ("right to be forgotten")

  • Right to Restrict Processing: Request limitation of data processing

  • Right to Data Portability: Receive your data in a structured, machine-readable format

  • Right to Object: Object to processing of your data

  • Right to Withdraw Consent: Withdraw consent at any time

To exercise these rights, contact us at hi@longeve.app.

6.2 Rights Under CCPA (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know: Request disclosure of personal information collected, used, and shared

  • Right to Delete: Request deletion of your personal information

  • Right to Opt-Out: Opt out of the "sale" of personal information

  • Right to Non-Discrimination: Receive equal service regardless of exercising privacy rights

We do not sell your personal information. We have not sold personal information in the preceding 12 months and do not intend to sell personal information.

To exercise these rights, contact us at hi@longeve.app.

6.3 CalOPPA Compliance

In accordance with CalOPPA, we disclose:

  • Do Not Track Signals: Our App does not respond to "Do Not Track" browser signals, as we do not track users across third-party websites. However, you can disable analytics through your device settings.

  • Third-Party Tracking: We do not allow third parties to collect personally identifiable information about your online activities over time and across different websites or online services.

6.4 How to Exercise Your Rights

Access Your Data:

  • View all your health data within the App

  • Export your data using the App's export feature

Delete Your Data:

  • Delete the App to remove all locally stored health data

  • Revoke HealthKit permissions in iOS Settings > Privacy > Health > Longeve

Opt-Out of Analytics:

  • Disable analytics in iOS Settings > Privacy & Security > Analytics & Improvements


7. Children's Privacy

Our App is not intended for children under 13 years of age.

We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hi@longeve.app. If we discover that a child under 13 has provided us with personal information, we will take steps to delete such information promptly.

For users between 13 and 16 years of age in the EEA, parental consent may be required under GDPR.


8. International Data Transfers

While your health data remains on your device, anonymous analytics and crash data may be processed by Firebase services located in the United States. Google (Firebase's parent company) participates in data protection frameworks and implements appropriate safeguards for international data transfers.

For users in the EEA, we rely on:

  • Standard Contractual Clauses approved by the European Commission

  • Google's compliance with applicable data protection frameworks


9. Data Retention

9.1 Health Data

Your health data is retained on your device until you:

  • Delete the App

  • Clear the App's data

9.2 Analytics Data

Anonymous analytics data is retained by Firebase according to their data retention policies (typically 14 months for user-level data).

9.3 Crash Reports

Crash reports are retained by Firebase Crashlytics for 90 days.


10. Security Measures

We implement appropriate technical and organizational measures to protect your information, including:

  • Local-only storage for all health data

  • iOS platform security features (encryption, sandboxing)

  • Secure communication protocols (HTTPS/TLS)

  • Regular security reviews

However, no method of electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

11. Beta App Releases (Apple TestFlight)

When you sign up for beta versions of our app, we collect your email address to invite you to participate in beta testing via Apple TestFlight and to send essential information related to the beta program.

Data collected:

  • Email address

Purpose:

  • Sending TestFlight beta invitations

  • Communicating important beta-related updates

We do not use beta signup emails for marketing purposes without separate, explicit consent.

Legal basis:

Processing is based on your consent under Article 6(1)(a) GDPR, given when you sign up for the beta program.

Apple TestFlight:

Beta distribution is handled through Apple TestFlight, a service provided by Apple Inc. Apple may process your email address as an independent data controller in accordance with its own privacy policy.

Data retention:

We retain your email address only for the duration of the beta program or until you withdraw your consent.

Withdrawal & rights:

You may withdraw consent and request deletion at any time by contacting hi@longeve.app. You have the right to access, correct, or erase your personal data and to lodge a complaint with a supervisory authority.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy in the App

  • Updating the "Effective Date" at the top of this policy

  • Displaying an in-app notification for significant changes

We encourage you to review this Privacy Policy periodically for any changes. Changes are effective when posted.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: hi@longeve.app

We will respond to your inquiry within 30 days (or sooner as required by applicable law).


14. Additional Information for Specific Jurisdictions

14.1 European Economic Area (EEA)

Legal Basis for Processing:

  • Consent: Processing health data based on your explicit consent when granting HealthKit access

  • Legitimate Interests: Processing analytics data to improve our services

Data Protection Officer: For GDPR-related inquiries, contact us at hi@longeve.app.

Supervisory Authority: You have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija) or your local supervisory authority.

14.2 California

California Shine the Light Law: California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

Categories of Personal Information Collected (CCPA):

  • Health information (from HealthKit, with consent)

  • Inferences drawn from the above (health scores)

  • Internet or electronic network activity (app usage)