Privacy policy
Last updated 2026-08-15
This document is not finished
What follows is a structure, not a policy. It has not been written or reviewed by anyone qualified to write one, and it must not be published in this state.
That matters more here than for most products. Eternal Life processes health data, which GDPR treats as a special category, and this page has to be publicly reachable before Google or Facebook will approve social sign-in. A placeholder that reads like a real policy is the failure mode to avoid — so this one reads like what it is.
What the finished document has to cover
Who the controller is
Legal entity, address, contact address for data protection questions.
What is collected, and why
Split by purpose, because the legal basis differs per purpose:
- Account data — email address, authentication identifiers.
- Health data — measurements the user records. Special category under Article 9; needs explicit consent, not legitimate interest.
- Waitlist — email address only, collected before the account exists, for the single purpose of announcing availability.
Who else processes it
Every processor named here has to have a data processing agreement in place. Current and planned:
- Supabase — database, authentication, file storage. EU region.
- Anthropic and OpenAI — receive the content of prompts when the AI layer generates
an interpretation. What exactly leaves for them is still undecided; see
docs/architecture/security.md. The policy cannot be finished before that decision is.
How long it is kept
Retention per category, and what happens on account deletion — including embeddings in the vector store, which are derived from health data and are easy to forget.
What rights the user has
Access, rectification, erasure, portability, objection, and how to exercise each.
Consent for AI processing
Separate from consent to use the application. A user has to be able to use the product without their data being sent to a language model.
Cookies and analytics
Currently none. If that changes it changes here first.