Longevity PulseAnmelden
Back
Legal

Privacy Policy

This page is maintained by the operator (see Legal Notice) to explain how CompiledHuman handles personal data. It describes app-visible controls and current practices and is not an independent certification.

1. Controller

Controller within the meaning of the GDPR is the operator listed in the Legal Notice.

2. What data we process

  • Account data — when you sign in via Google or Apple: name, email address, and a stable user identifier provided by the OAuth provider.
  • Health & performance data you enter yourself — sleep, focus, output scores, manual training entries, habit check-ins.
  • Wearable data you connect — recovery, sleep, HRV, workouts from Whoop, Oura, or Apple Health. Only the metrics needed to render your dashboard are stored.
  • Technical data — server logs (IP, user agent, timestamps) for security and abuse prevention, kept for a maximum of 30 days.

3. Why we process it (legal basis)

  • Contract performance, Art. 6 (1) (b) GDPR — providing the dashboard and features you sign up for.
  • Consent, Art. 6 (1) (a) and Art. 9 (2) (a) GDPR — for health-related data and wearable integrations.
  • Legitimate interest, Art. 6 (1) (f) GDPR — security, fraud prevention, and aggregate analytics.

4. The public Longevity Pulse feed

The Longevity Pulse news feed is fully public. We do not require sign-in to read it and we do not set tracking cookies for visitors.

5. Processors and sub-processors

  • Lovable Cloud — hosting, database, authentication (EU region).
  • Google LLC / Apple Inc. — OAuth sign-in providers.
  • Firecrawl — scraping public news sources for the Longevity Pulse feed; no user data is sent.
  • Lovable AI Gateway — generating news summaries and the AI-compiled analysis on your dashboard.
  • Wearable vendors (Whoop, Oura, Apple Health) — only after you explicitly connect them via OAuth.

6. AI processing

We use large language models to (a) rewrite public news in fresh language with a strategic outlook and (b) generate the "AI-Compiled Analysis" on your dashboard.

Inputs are not used to train third-party models. Your personal metrics are sent only when you are signed in and only the minimum necessary to produce the analysis.

7. Cookies

We use only technically necessary cookies to keep your session signed in. No advertising, analytics, or tracking cookies. See the Cookie Notice.

8. Categories of recipients

Beyond the processors listed in section 5, your personal data may be disclosed to:

  • Public authorities — only where we are legally required to do so (e.g. court orders, tax authorities, law-enforcement requests under §§ 100a ff. StPO).
  • Legal advisors, auditors, insurers — to defend or enforce legal claims (Art. 6 (1) (f) GDPR).
  • Business successors — in case of a merger, acquisition, or asset sale, your data may be transferred to the acquiring entity. You will be notified before any such transfer occurs.

We do not sell your personal data and we do not share it for cross-context behavioural advertising.

9. Data security (TOMs)

Pursuant to Art. 32 GDPR we maintain technical and organisational measures appropriate to the risk, including:

  • TLS 1.2+ encryption in transit for all client–server traffic.
  • Encryption at rest of the production database and backups (AES-256).
  • Row-level security on every personal-data table — your records are isolated by your user ID at the database level.
  • OAuth-only authentication (Google/Apple) — we never store passwords.
  • Principle of least privilege for backend access; service-role keys are scoped server-side only.
  • Automated backups with a maximum 30-day restore window.
  • Documented incident-response and breach-notification procedure (Art. 33/34 GDPR).

10. Retention

  • Account data: until you delete your account.
  • Health, training, and wearable data: until you delete it or disconnect the source.
  • After account deletion, residual copies in encrypted backups are overwritten within a maximum of 30 days.
  • Server logs: 30 days.

11. Automated decision-making & profiling

The "AI-Compiled Analysis" on your dashboard analyses the metrics you have logged to produce written observations and suggestions. This constitutes automated processing / profiling within the meaning of Art. 22 (1) GDPR, but it does not produce legal effects or similarly significant effects for you — it is informational only, you remain in full control of any action you take, and the analysis can be ignored, regenerated, or disabled by deleting your account at any time.

You have the right to obtain a human review of, express your point of view on, or contest any output of this feature by contacting us at the address in the Legal Notice.

12. Minors

The service is not intended for persons under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without verified parental consent (Art. 8 GDPR), we will delete the data without undue delay. Parents or guardians can request deletion via the contact address in the Legal Notice.

13. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15), rectification (Art. 16), and erasure (Art. 17) of your data.
  • Restriction of processing (Art. 18) and data portability (Art. 20) — a one-click JSON export is available in your profile.
  • Object to processing (Art. 21) and withdraw consent at any time (Art. 7 (3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Lodge a complaint with a supervisory authority (Art. 77) — in Germany, the data protection authority of your federal state.

To exercise any of these rights, contact us at the email address in the Legal Notice.

14. International transfers

Where processors operate outside the EU/EEA, transfers are based on EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) or adequacy decisions.

15. Data protection officer

The operator is not required to designate a data protection officer under § 38 BDSG (fewer than 20 persons are regularly engaged in the automated processing of personal data, and no large-scale processing of special categories under Art. 9 GDPR is performed in the meaning of Art. 35 GDPR). For any privacy-related request, please use the contact address in the Legal Notice.

16. Changes to this policy

We may update this policy when the service or the legal framework changes. The current version date is shown at the bottom of this page. Material changes will be highlighted in-app before they take effect.

Last updated: June 2026