LifespanOS is a personal health and longevity dashboard for iPhone. This policy
explains what data the app uses, where it is stored and processed, and the choices you
have. Our guiding principle is simple: your health data stays on your
device.
We are not a covered entity under HIPAA and LifespanOS does not provide medical
advice, diagnosis, or treatment. See the disclaimer at the end.
The short version
- Everything is stored on your device by default. Your Apple Health
data, manual entries, meals, lab results, and settings stay on your iPhone — the only
exceptions are optional iCloud sync (to your own private iCloud) and optional AI
features.
- We have no server or database for your health data. There is no
account to create, and we do not collect, sell, rent, or share your health
information.
- No advertising. No data brokers. No tracking.
- Optional AI features (AI chat, daily briefing, meal-photo
estimate) send only the information needed for that single request to our AI provider,
and the result is returned to your device.
- Lab-report scanning runs entirely on your device using Apple's
on-device text recognition — the photo of your blood work is never uploaded.
- Optional iCloud sync. If you're signed into iCloud, your entries
sync across your own devices via Apple's iCloud — your private storage, which
we cannot access.
Data we access and why
LifespanOS reads the following only on your device, to build your
dashboard and analysis:
- Apple Health / HealthKit data you grant permission to (steps,
heart rate, HRV, resting heart rate, sleep, workouts, VO₂max, body measurements). Read
through HealthKit; remains on your device.
- Information you enter — manual measurements (blood pressure,
weight, body composition, grip strength, waist), lab/blood-panel results, meals and
water, and onboarding answers.
- App settings and preferences (theme, goals, units, feature
toggles).
We do not access your contacts, your photo library beyond a photo
you explicitly pick or capture, location history, browsing history, or device
identifiers for tracking.
Where your data is stored and processed
- HealthKit data is managed by iOS and stays in Apple's secure
on-device Health store. We read it on demand and do not copy it to any server.
- Manual entries, meals, lab results, and settings are saved
locally on your device. They are included in your device's encrypted backups (iCloud or
local) only if you have those enabled — that backup is controlled by you and Apple, not
by us.
- iCloud sync (optional). If you're signed into iCloud, the app uses
Apple's iCloud Key-Value storage to sync your entries across your own
devices and restore them on a new device. This is your private iCloud account, governed
by Apple's privacy policy; we have no access to it and operate no
server of our own. It works automatically and you can disable it in iOS Settings →
your name → iCloud.
- We operate no backend database for your health data. We cannot see
your data.
If you delete the app, the data it stored locally is removed with it.
Optional AI features and third-party processing
Some features are optional and powered by a third-party AI provider
(Google LLC — the Gemini API). They run only when you actively
use them, and only after you give explicit consent in the app — the first time
you use any AI feature, LifespanOS shows a consent dialog that lists exactly what will
be sent and to whom, and nothing is transmitted unless you agree. You can withdraw
consent at any time from the 🔒 button in the AI chat, and the app stops sending data
immediately.
What each feature sends when you use it:
- AI chat and daily/weekly briefing — send a
summary of the relevant health metrics needed to answer your request (activity, heart
metrics, sleep, workouts, body measurements, trends), plus nutrition entries, lab
values you've added, your questions, goals, and coach-memory notes.
- Meal-photo estimate — sends the meal photo you take so the AI can
estimate calories and macros.
- Blood-work diet plan — sends the lab values you entered and your
nutrition profile.
Requests travel from your device to our relay server (which verifies
your subscription and holds the API credential — it does not log or store your health
data) and on to Google's Gemini API. Data is sent over an encrypted
(HTTPS) connection, processed to generate your result, and returned to your
device. We
do not store the photo or request on any server of ours — the meal photo is
used for that single estimate and then discarded; only the extracted values are saved
locally. The AI provider processes the request under its own terms and privacy policy;
depending on the service tier, it may or may not retain inputs to improve its products.
We configure the integration to minimize retention and do not authorize the provider to
use your data to target advertising to you. These features are off until you use them and
require an optional paid subscription — you can use the entire dashboard without sending
any data off your device.
Lab-report scanning does not use the AI provider on iPhone. It uses
Apple's on-device Vision text recognition, so the image of your blood work is read
locally and never leaves your device.
What we do NOT do with your data
In line with Apple's HealthKit requirements and our own commitments, we will
never:
- Sell or rent your health data.
- Use your health data for advertising or marketing, or share it with advertising
networks or data brokers.
- Use your health data for any purpose other than providing LifespanOS features to
you, for your benefit, and (with your consent) improving the app.
- Share your health data with third parties except a processor strictly necessary to
deliver a feature you chose to use, or where required by law.
Payments
The optional AI subscription is processed by Apple through the App
Store. We do not receive or store your payment card details.
Children
LifespanOS is not directed to children under 13 (or the equivalent minimum age in
your region), and we do not knowingly collect data from them.
Your rights and choices
- Access / export: your data is on your device; view it in the app
and in Apple Health.
- Delete: remove entries in the app, revoke Health permissions in
iOS Settings → Privacy & Security → Health, or delete the app to remove its locally
stored data.
- Regional rights: depending on where you live (e.g., GDPR in the
EEA/UK, CCPA/CPRA in California), you may have additional rights. Since we do not hold
your data on a server, most requests are satisfied on your device; for anything else,
contact us below.
Security
We rely on iOS platform protections (device encryption, app sandboxing, HealthKit's
permission model) and encrypted connections (HTTPS) for optional AI requests. No method
is 100% secure, but because we keep data on-device and operate no central database, the
exposure surface is intentionally minimal.
Changes to this policy
We may update this policy as the app evolves. We will post the updated policy here
with a new "Last updated" date and, for material changes, surface a notice in the
app.
Contact
Questions about this policy or your data:
Email: privacy@longevityos.app
Developer: Charles Scheibler
Medical disclaimer. LifespanOS is for informational and educational
purposes only. It does not provide medical advice and is not a substitute for
professional medical care. The app does not diagnose, treat, cure, or prevent any
disease, and any biological-age or readiness estimates are non-clinical. Always seek the
advice of a qualified health provider with questions about your health.