Privacy Notice
Effective September 2026 · Version 2026-09 · UK GDPR and EU GDPR
In short. To build your protocol we need to process information about your health. We do that only with your explicit consent, we host it in the EU, we let a carefully chosen AI provider process it under a data-processing agreement that forbids training on your data, and you can withdraw consent and erase everything from inside the app.
1. Who is responsible for your data
The controller of your personal data is Longevity Bros Ltd (UK) — [registered address to be inserted]. You can reach us about anything in this notice at info@longevity-bros.ltd. [Data-protection contact / representative in the EU, if required under Art. 27 GDPR: to be confirmed by counsel.]
This notice explains what we collect when you use the Research Protocol Builder (the “Service”), why, on what legal basis, who sees it, how long we keep it, and what rights you have. It should be read together with our Terms of Service.
2. What data we collect
We only collect what the Service needs. The categories are:
- Account data — email address, name (optional), password hash held by our authentication provider, account role and status, sign-in timestamps, and the affiliate code you entered at registration, if any.
- Intake data — the answers you give in the intake questionnaire: age, sex, body measurements, goals, training and lifestyle habits, diet, sleep, current and previous supplements, medications and research compounds, medical history, symptoms and any free-text notes.
- Laboratory data — files you upload (for example blood-panel PDFs or images), the values we extract from them, and the sample dates.
- Generated content — the protocol drafts and released documents built from the above, the automated review of them, and the notes our reviewers add.
- Consent records — which version of the Terms, this notice and the health-data consent you accepted, and when.
- Audit and technical data — a minimal log of significant actions (for example “intake submitted”, “protocol released”, “account erased”) with the actor, time and affected record; standard server logs; and the authentication cookie described in section 10.
Intake data, laboratory data and generated content are special-category data concerning health under Article 9 GDPR. We treat them with the additional protections described in this notice.
3. Why we process it and on what legal basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and administering your account, signing you in, and providing the Service you asked for | Account data, consent records | Art. 6(1)(b) — performance of a contract |
| Building, reviewing and releasing your research protocol | Intake data, laboratory data, generated content | Art. 6(1)(a) consent and Art. 9(2)(a) explicit consent to the processing of health data, given in the app before any health field is stored |
| Sending you service notifications (intake received, protocol released) | Email address, protocol version | Art. 6(1)(b) — performance of a contract |
| Keeping the Service secure, preventing misuse and demonstrating compliance | Audit and technical data | Art. 6(1)(f) — our legitimate interest in security and accountability; Art. 6(1)(c) where a legal obligation applies |
| Recording which affiliate introduced you to the Service | Affiliate code, date of sign-up | Art. 6(1)(f) — our legitimate interest in running an affiliate programme; affiliates never see your identity |
| Responding to your requests and complaints | Account data, correspondence | Art. 6(1)(b), (c) and (f) |
We do not use your data for advertising, we do not sell it, and we do not use it to make decisions that produce legal or similarly significant effects on you. Every protocol is reviewed by a person before it is released to you.
4. Who receives your data
Your data is visible to a small number of our staff who review protocols and administer accounts, and to the processors listed below, each of which acts only on our instructions under a written data-processing agreement:
- Supabase — database, authentication and file storage. Hosted in the European Union (Frankfurt, Germany). Your data is held in a private database and a private storage bucket protected by row-level security.
- Anthropic — the artificial-intelligence provider whose models draft the protocol, review it and extract values from laboratory files. Anthropic processes data under a data-processing agreement and its commercial terms, does not use your data to train its models, and retains it only for the short period needed to provide the service and enforce its usage policies.
- Email provider (only if notifications are enabled) — receives your email address and the content of the notification, which never includes health data. [Provider name and location to be inserted once confirmed; currently Resend, Inc.]
- Hosting and edge network for the web application — [provider and region to be confirmed by counsel].
We may also disclose data where the law requires it, to protect our rights or the safety of any person, or to a successor in the event of a merger or sale of the business (in which case this notice continues to apply).
5. International transfers
Our primary storage is in the European Union. Where a processor is established outside the UK or the European Economic Area — in particular Anthropic, which is established in the United States — transfers are made under the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, supplemented by encryption in transit and the provider’s contractual commitments on confidentiality and non-training. You can ask us for a copy of the relevant safeguards. [Transfer mechanism per processor: to be confirmed by counsel.]
6. How long we keep it
- Account, intake, laboratory data and generated content are kept while your account exists so that you can view your history and we can build new versions on top of earlier ones. They are deleted when you erase your account from the Account page, when you ask us to erase them, or when we close an account that has been inactive for [retention period to be confirmed] .
- Consent records are kept for as long as we need to demonstrate that consent was obtained, and are deleted with the account.
- Audit log entries are minimal by design: they record the action, the time, the acting user and the identifier of the affected record, not the content. When an account is erased the entry recording the erasure is kept with the email address that requested it, so that we can prove the request was honoured; nothing else about the account survives.
- Backups held by our database provider expire on a rolling basis within [backup retention to be confirmed] days.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectify inaccurate or incomplete data — you can edit your intake and account details at any time;
- Erase your data (“right to be forgotten”) — use the erasure option on the Account page, which removes your profile, intakes, laboratory files, protocols and consents;
- Restrict or object to processing that relies on legitimate interests;
- Port the data you provided to us in a machine-readable format;
- Withdraw consent at any time for the processing of your health data. Withdrawal does not affect processing that already took place, but it means we can no longer build or hold protocols for you, so it is handled as an erasure of the related data. You can withdraw from the Account page or by emailing us;
- Not be subject to a solely automated decision — every protocol is reviewed by a person before release; and
- Complain to a supervisory authority (see section 11).
To exercise any right that is not available in the app, email info@longevity-bros.ltd from the address on your account. We respond within one month, extendable by two further months for complex requests, and we may ask you to verify your identity first.
8. How we protect your data
- All traffic is encrypted in transit (TLS) and data is encrypted at rest by our database and storage provider.
- Row-level security is enforced in the database itself: you can only read and write your own rows, and unreleased protocols are invisible to you until an administrator releases them.
- Laboratory files are stored in a private bucket and are served only through short-lived signed URLs.
- Administrative functions are role-gated; staff sign in with their own accounts and the role is checked on the server for every action.
- Significant actions are written to an audit log that staff cannot edit.
- Service credentials with elevated privileges are held only on the server and never shipped to the browser.
- Our AI provider is bound by contract not to train on your data.
No system is perfectly secure. If a breach affecting your data occurs we will notify you and the relevant authority as the law requires.
9. Children
The Service is for adults only. We do not knowingly collect data from anyone under 18, and registration requires you to confirm your age. If you believe a minor has created an account, tell us and we will delete it.
10. Cookies
The Service uses only strictly necessary cookies: the authentication session cookies set by our sign-in provider, which keep you signed in and are removed when you sign out. We do not use analytics, advertising or tracking cookies, and we do not load third-party trackers. Because these cookies are essential to provide the Service you requested, no cookie banner is required.
11. Complaints
We would like the chance to resolve any concern first — write to info@longevity-bros.ltd. You also have the right to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner’s Office (ICO, ico.org.uk); in the European Union, the data-protection authority of the member state where you live or work.
12. Changes to this notice
We will update this notice when our processing changes. The version number and effective date at the top will change, and for material changes we will ask you to review and re-accept it in the app before continuing. Earlier versions are available on request.
13. Contact
Longevity Bros Ltd (UK) — [registered address to be inserted]
Email: info@longevity-bros.ltd
Longevity-bros™ | Not your average health cult · Research & educational information · not medical advice · your physician has the final word.