Privacy Policy

Last updated: January 2025

Your health data is encrypted and never sold.

1. Introduction

Yovitai ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services. We comply with the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) for California residents, and other applicable privacy laws.

2. Information We Collect

Personal Information: • Account information (name, email address, date of birth) • Health data (lab results, weight, health metrics) • Documents you upload (lab reports, medical documents) • Usage data (app interactions, feature usage) Sensitive Health Data: We collect sensitive health information only with your explicit consent. This includes: • Laboratory test results and biomarkers • Weight and body measurements • Health conditions and medications • Lifestyle factors (sleep, exercise, nutrition) Automatically Collected Information: • Device information (model, operating system) • Log data (access times, pages viewed) • Analytics data (anonymized usage patterns)

3. How We Use Your Information

We use your information to: • Provide and maintain our services • Analyze your health data and provide insights • Generate personalized health recommendations • Calculate biological age and longevity metrics • Enable AI-powered health chat features • Send notifications about your health trends • Improve our services and develop new features • Comply with legal obligations Legal Bases for Processing (GDPR): • Consent: For processing sensitive health data • Contract: To provide services you requested • Legitimate Interest: For service improvement and security • Legal Obligation: For compliance with applicable laws

4. Data Sharing and Disclosure

We do NOT sell your personal information. We may share your information with: • Service Providers: Cloud hosting (AWS), AI services (Google Gemini) for processing • Legal Requirements: When required by law or to protect our rights • Business Transfers: In case of merger or acquisition (with notice) Third-Party AI Processing: We use Google Gemini AI to analyze your health data and provide insights. Your data is processed according to Google's data processing terms and is not used to train AI models.

5. Documents Are Reviewed On Your Phone First

Before a lab report leaves your device, the app opens it for review and gives you tools to black out anything that identifies you — your name, date of birth, address, phone number, email, insurance or patient number. What actually happens: • On devices that support it, the app reads the text on the page locally, on your phone, and marks what looks identifying. That text recognition never leaves the device and is not sent to us or to anyone else. • You review every suggestion, remove any that are wrong, and add anything we missed. Nothing is applied without you seeing it. • Blacking out destroys the pixels underneath and re-encodes the file. It is not a rectangle drawn over the content that could be lifted off later, and there is no text layer surviving beneath it. • Photo metadata is stripped from the new file, including the camera make and model, the capture time and any GPS coordinates your phone recorded. The original file on your device is never modified — a new one is created and uploaded. • What we receive, store and pass to the extraction model is the redacted file. We never hold the original. PDFs work differently, and more thoroughly: A black rectangle drawn on a PDF is not a redaction — the text sits in its own layer underneath and copies straight out of any reader. So instead of drawing on the file, your phone renders every page to an image, you review each one, and a brand-new PDF is built from the redacted pages. The result has no text layer at all, so there is nothing beneath the black boxes to recover, and it cannot carry the original's document properties — lab exports frequently put the patient's name in the Author and Title fields. The trade-off is that the text in the redacted copy is no longer selectable and the file is larger. If your device cannot open a PDF for review, or the file is password-protected, damaged or very long, we tell you and ask before anything is uploaded. Choosing to send it anyway sends it exactly as it is. One honest limit: This is a tool, not a guarantee. Automatic detection cannot reliably find every identifier on every lab's stationery, so the person reviewing the page is what makes it work. We never describe an uploaded document as anonymised. Documents uploaded before this feature existed were not redacted.

6. Data Security

We implement industry-standard security measures: • Encryption in transit (TLS 1.3), and sensitive health fields encrypted before they are written to the database • Photo metadata stripped from every uploaded image • Secure authentication with JWT tokens • Access controls and least-privilege file permissions • Infrastructure-level encryption of the volumes your data sits on We have not commissioned a third-party penetration test and we are not SOC 2 certified. Our security page lists what is in place and what is not, and we would rather say so here than let a phrase in a policy imply otherwise. Despite our efforts, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

7. Your Rights

GDPR Rights (EEA Users): • Right to Access: Request a copy of your data • Right to Rectification: Correct inaccurate data • Right to Erasure: Request deletion of your data • Right to Portability: Export your data • Right to Restrict Processing: Limit how we use your data • Right to Object: Object to certain processing • Right to Withdraw Consent: Withdraw consent at any time CCPA Rights (California Residents): • Right to Know: What personal information we collect • Right to Delete: Request deletion of your data • Right to Opt-Out: Opt-out of sale of personal information (we don't sell data) • Right to Non-Discrimination: Equal service regardless of privacy choices To exercise your rights, contact us at privacy@yovit.ai or use the in-app data export and deletion features.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. • Account data: Until account deletion • Health data: Until you delete it or your account • Analytics data: 2 years (anonymized) • Backup data: 30 days after deletion You can request complete data deletion at any time through the app settings or by contacting us.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your residence, including the United States. For EEA users, we ensure appropriate safeguards: • Standard Contractual Clauses (SCCs) • Adequacy decisions where applicable • Additional technical and organizational measures

10. Children's Privacy

Our services are not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected data from a child under 16, please contact us immediately at privacy@yovit.ai.

11. Cookies and Tracking

Our mobile app uses: • Essential cookies for authentication • Analytics (Firebase Analytics) for app improvement • No third-party advertising trackers You can disable analytics in the app settings.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes through: • In-app notifications • Email to your registered address • Updated "Last modified" date Continued use after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related inquiries: Email: privacy@yovit.ai Website: https://yovit.ai/privacy Data Protection Officer (for EEA users): dpo@yovit.ai You have the right to lodge a complaint with your local data protection authority.