Privacy Policy
SHIELD Longevity · Last updated 6 August 2026
SHIELD is not a medical device and does not diagnose. It provides educational longevity guidance based on data you choose to share. Take medical decisions with your physician. Nothing in the app replaces clinical care.
1. Who we are
SHIELD Longevity is the data controller for the information described here. For any privacy request, contact privacy@shieldlongevity.ai.
2. What we collect
Only what you give us or what the service generates from it. We do not buy data, and we do not track you across other apps or websites.
Account
Email address or phone number (whichever you sign up with), and your name if you provide one. Optionally date of birth, sex, height and weight — these refine your score and are not required to use the app.
Health information
- Lab reports you upload — the photograph or PDF itself, and the biomarker values read from it.
- Wearable and device readings, if you connect a source.
- Your SHIELD Score and per-domain results calculated from the above.
Coach sessions
If you use the AI coach: the transcript of the conversation, and any plan generated from it. During a live video session your audio is transcribed and the coach's replies are synthesised into speech — see section 4.
Records we keep for accountability
Your consent decisions and when you made them, session bookings, and your credit balance history. The consent record exists so we can prove we had your permission — it is deliberately not deletable while your account is open.
3. Why we use it
Your explicit consent is the legal basis for processing health data, and you can withdraw it at any time (section 6). We use your information to calculate your score, to let the coach give you guidance grounded in your own results rather than generalities, to keep the service secure, and to meet our record-keeping obligations. We do not use your health data for advertising, and we do not sell it.
4. Who else processes it
These are the only third parties that receive your data, and only for the purpose stated. Each acts as our processor under contract.
| Processor | What it receives | Why |
|---|---|---|
| Amazon Web Services | All stored data | Hosting, database, encrypted file storage. Ireland (eu-west-1). |
| Anthropic | Your lab report image or PDF; your score and biomarkers during coach sessions | Reading values from your report, and grounding the coach's guidance in your results. |
| OpenAI | Your voice audio during a live coach session, and the coach's reply text | Speech-to-text and text-to-speech. Only during a live session. |
| Google (Firebase) | Your email or phone number, and your password (which we never see) | Verifying it is really you when you sign in. Nothing else. |
| LiveKit | Real-time audio and video of a coach session | Carrying the call. Not stored by us as video. |
| Anam | The coach's spoken reply | Rendering the animated avatar you see. |
| Sentry | Technical error reports | Diagnosing crashes. Configured to exclude health values. |
We do not send your data to anyone else, and no processor is permitted to use it for their own purposes, including training their models on it.
5. How it is protected
- Encrypted at rest. Databases, uploaded reports and backups are encrypted with keys we control.
- Encrypted in transit. TLS everywhere, including between our own internal services.
- Isolated. Databases sit in a private network segment with no route to the internet.
- Nothing is scored without your confirmation. Values read from your report are held as drafts and shown to you first. A number only affects your score after you accept it, and you can correct or reject any of them. This exists because a misread decimal would otherwise change your health score without ever looking wrong.
6. Your rights
You can, at any time:
- See everything we hold about you.
- Correct anything inaccurate — including biomarker values.
- Export your data in a portable format.
- Delete your account and health data.
- Withdraw consent to health-data processing. Doing so stops scoring and coaching, because neither can function without it.
- Object or complain — to us, or to your local data protection authority.
Email privacy@shieldlongevity.ai. We respond within 30 days.
7. How long we keep it
Your health data is kept while your account is open, so your score has history to compare against. Uploaded reports move to lower-cost archival storage after 90 days and superseded versions are removed. Encrypted database backups are retained for disaster recovery and age out automatically. When you delete your account we remove your personal and health data; the consent audit record is retained only as long as we are required to keep it.
8. Where it is stored
Your data is stored in Ireland (eu-west-1). Some processors in section 4
operate outside the EEA; those transfers rely on the European Commission's Standard
Contractual Clauses.
9. Children
SHIELD is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
10. Beta programme
SHIELD is currently in closed beta. Features change, and data may be reset between beta phases — we will tell you before that happens. Do not treat the beta as your only record of a lab result: keep your original report.
11. Changes
If we change how we use your data in a way that affects you, we will tell you in the app before it takes effect, and ask again for consent where the law requires it.
SHIELD Longevity ·
privacy@shieldlongevity.ai
This page describes the SHIELD Longevity mobile application and its backend services.