1. Who we are and what this policy covers
The Live Every Day Foundation, D-U-N-S® 145033751 (referred to as “Live Every Day,” “we,” “us,” or “our”) provides the Live Every Day mobile application, web application, and websites linking to this policy (together, the “Service”). This policy applies to personal information collected through the Service and through related support, pilot, and contact communications.
Live Every Day is an independent, patient-led health information service. It is not a healthcare provider, health plan, pharmacy, or emergency service. Some health information may be protected by health privacy laws depending on the circumstances. We treat all health information as sensitive whether or not a particular law applies.
Our commitment: We do not sell personal or health information. We do not run advertising, use health information for targeted advertising, or permit data brokers to use it. We share information only at your direction, to operate and secure the Service with contracted providers, or when law and safety require it.
2. Information we collect
We collect information you provide, information created as you use the Service, and limited technical information needed to authenticate, operate, and secure it. You can choose not to provide optional information, but some features may then be unavailable.
| Category | Examples | How collected |
|---|---|---|
| Account and contact information | Name, email address, profile image, account identifier, login provider, and email verification status. | You enter it or authorize Google or Apple to provide it when signing in. |
| Health profile and questionnaire responses | Condition and diagnosis details, diagnosis year, mutations, procedures, related conditions, MPN-10 and other check-in answers, symptom scores, and response dates. | You enter it during onboarding and check-ins. |
| Labs and health records | Lab values, units, reference ranges, abnormal flags, collection dates, source labels, extraction confidence, and corrections you make. If you upload a lab PDF, photo, or screenshot, the file may include identifiers and other health information visible in that document. | You enter values or choose a document to upload and review. |
| Medications and vitals | Medication name, dose, schedule, start and end dates, notes, blood pressure, pulse, temperature, weight, and measurement dates. | You enter it or, when available, import it from an authorized source. |
| Connected health-source data | If you enable Apple Health or Android Health Connect: normalized daily step totals, asleep duration, resting heart-rate averages, and heart-rate-variability averages (Apple SDNN or Health Connect RMSSD); the local date and time zone for each summary; requested data types and accessible-data status; and sync history. | Only after you choose to connect a source and grant system-level permission. Apple Health is available in the iPhone app and Health Connect is available on supported Android devices. |
| Circle, care team, and appointment information | Names, relationships, initials, invitation emails, sharing permissions, support messages, care team details, appointment dates, locations, and notes. | You add it or another participant sends it through a feature you enabled. If you use address suggestions, Google Maps processes the partial address you type and the address you select. |
| Communications | Support requests, bug reports, emails, survey feedback, pilot-interest form responses, disease type, and optional comments. | You email us or submit a website form or survey. |
| Technical and security information | Session and account identifiers, IP address, browser or device user agent, authentication method, timestamps, request identifiers, security events, feature actions, and privacy-safe error diagnostics. | Collected automatically when you access or use the Service. |
Uploaded lab documents
When you choose “Upload and review,” the document is transmitted to Google Vertex AI to extract visible lab values for your review. Live Every Day stores the extracted values, your corrections, the document type and filename (when available), file size, and a one-way file hash used for integrity and duplicate detection. The original document bytes are not stored in Live Every Day’s application database after the extraction request completes. Google may process the document transiently under its cloud service terms and our service-provider arrangements.
Cookies and similar storage
The web application uses essential cookies or browser storage to maintain secure sessions and preferences. The mobile app stores authentication material in the device’s secure storage. We do not use advertising cookies or cross-app tracking technologies. Our websites may load resources or submit forms through service providers, which can receive standard request information such as an IP address and user agent.
3. Why we collect and use information
We use personal information only for the following purposes:
- Provide the Service: create and authenticate accounts; save and display health information; calculate questionnaire scores; show trends; prepare summaries; support lab review; and operate circle, care-team, and appointment features.
- Honor your sharing choices: provide selected information to the people you invite and only within the permissions you configure.
- Generate observations: identify deterministic patterns in your own data. When AI-assisted wording is enabled, Google Vertex AI receives a limited set of structured facts needed to phrase an already-established pattern. It does not receive unrestricted history, names, email addresses, notes, or uploaded source documents for this wording feature.
- Maintain your Journey: store published observation history, supporting evidence and chart snapshots, source labels, milestones, your optional experience feedback, and links to appointment-brief questions. Feedback remains patient-only in the current version.
- Support and communicate: answer questions, troubleshoot problems, deliver requested invitations and service messages, and administer pilots or feedback programs.
- Protect users and the Service: prevent fraud and abuse, investigate incidents, authenticate users, maintain audit records, and enforce our terms.
- Improve reliability and accessibility: diagnose failures and understand whether core features work, using the minimum information reasonably needed. We do not use health information for advertising or unrelated profiling.
- Comply with law: meet legal, regulatory, accounting, and valid governmental requirements and establish or defend legal claims.
Depending on where you live, our legal basis may be your consent, performance of our agreement with you, our legitimate interests in operating and securing the Service, protection of vital interests, or compliance with law. Where consent is required for sensitive health data, you may withdraw it prospectively, subject to the consequences described in the Service and this policy.
5. Apple Health, Health Connect, and connected health sources
Apple Health is an optional, read-only connection in the iPhone app. Immediately before requesting access, the Service identifies Steps, Sleep, Resting Heart Rate, and Heart Rate Variability (Apple SDNN). You can choose access separately for each type in Apple’s permission screen and continue using the Service if you decline access. HealthKit does not tell apps whether you denied a read permission, so the Service may report that no accessible data was found rather than identifying a denied type.
Health Connect is an optional, read-only connection in the Android app for Steps, Sleep, Resting Heart Rate, and Heart Rate Variability (RMSSD). Android lets you grant each data type separately. Optional past-data access permits up to 180 days of initial history; without it, the app uses the history window Health Connect allows by default.
The app reads the authorized source on your device and sends normalized daily summaries to your Live Every Day account. We do not upload raw HealthKit or Health Connect records, source-app or device identifiers, or write data back to either platform.
If you connect a health source, we will:
- use authorized data only to provide user-facing health organization, trend, and sharing features;
- request only data types reasonably needed for features you choose;
- not use the data for advertising, marketing profiles, credit, insurance, or data-broker purposes;
- not write data to Apple Health or Health Connect in the current read-only integrations; and
- not store HealthKit data in iCloud.
You can stop syncing under Manage sources or revoke access in Apple Health or Health Connect settings. Either choice stops new collection but leaves previously imported summaries in your account. Each source has a separate delete-imported-data control that removes its observations from active Live Every Day views without deleting anything from the device platform. An observation that depended on removed source data is marked withdrawn, removed from active views, and has derived evidence and chart values from that source redacted. Account deletion also removes connected-source data under the retention terms below.
6. Retention and deletion
- Account and health data: retained while your account is active so you can maintain a longitudinal record. It is removed from the active application database when you delete your account, unless a narrow legal exception applies.
- Original lab files: processed for extraction and not retained in our application database after the request completes. Extracted values, corrections, and associated metadata remain with your account until deletion.
- Support, pilot, and contact communications: retained while the request or program is active and afterward only as reasonably needed for follow-up, recordkeeping, consent management, dispute resolution, or legal compliance.
- Security and audit records: restricted audit records may be kept for up to six years to support security investigations, access accountability, and compliance. These records are designed to contain identifiers and event metadata, not lab values, questionnaire answers, document content, or support-message text.
- Backups: deleted data may remain in encrypted, access-restricted backups until those backups expire or are overwritten, typically within 30 days. We do not restore deleted data to active use except when needed for disaster recovery, and deletion controls are reapplied after a restoration.
We may retain limited information longer when required by law, necessary to complete a transaction you requested, or needed to prevent fraud, protect safety, resolve a dispute, or establish legal rights. We isolate retained information and limit its use to that purpose.
See the Data Deletion page for account deletion steps and timelines.
7. How we protect information
We use administrative, technical, and organizational safeguards designed for sensitive health information. They include encryption in transit; provider-managed encryption at rest; secure authentication and session handling; access controls based on least privilege; private database networking; secrets management; audit logging; restricted backups; and logging rules designed to keep health payloads, uploaded documents, and authentication secrets out of diagnostic logs.
No system is completely secure. Please use a unique password if you create a password account, protect your device, sign out of shared devices, and contact us promptly if you suspect unauthorized access. Learn more on our Security page.
8. Your choices and privacy rights
Subject to applicable law and identity verification, you may ask us to:
- confirm whether we process your information and provide access to it;
- correct inaccurate account or health information;
- provide a portable copy of information you supplied;
- delete your account and associated information;
- restrict or object to certain processing;
- withdraw consent for future processing; or
- appeal a decision we make about a privacy request where applicable.
The Service also lets you review and correct extracted lab values, manage circle permissions, disconnect sources, and delete your account directly. We do not discriminate against you for exercising a privacy right.
To make a request, email info@liveeveryday.health with the subject “Privacy request.” Describe the request and the email address tied to your account. We may ask you to verify control of the account or provide other information reasonably necessary to protect your data. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct verification with you.
We aim to respond within 30 days, or within the shorter or longer period required by applicable law. If we cannot fulfill a request, we will explain why and describe any available appeal process.
9. Children
The Service is intended for adults and is not directed to children under 13. You must be at least 18 years old to create and manage a patient account unless Live Every Day expressly provides an authorized caregiver or guardian flow. If we learn that we collected a child’s information outside such a lawful flow, we will take steps to delete it. Contact us if you believe this has occurred.
10. Where information is processed
Live Every Day is based in the United States, and the Service’s primary cloud systems are hosted in the United States. If you access the Service from another country, your information may be transferred to and processed in the United States and other locations where our providers operate. We use contractual and other safeguards required by applicable law for cross-border transfers.
11. Changes to this policy
We may update this policy as the Service, providers, or legal requirements change. We will post the revised policy with a new effective date. If a change materially affects how we use health information, we will provide additional notice in the Service or by email when appropriate and obtain consent when required.
12. Contact us
Questions, complaints, and privacy requests may be sent to the Live Every Day Foundation, D-U-N-S® 145033751, at info@liveeveryday.health.
The Live Every Day Foundation5824 Harbor Breeze Dr
Wilmington, NC 28409-3726
United States
Please do not send lab reports, medical records, passwords, or other unnecessary health details by ordinary email. Use the secure features in the Service for health data.