This is the privacy policy for the inLive iOS app. The separate policy for this website and the inLive shop is at /legal.
Effective Date: 2026-08-26 (confirm or bump to the App Store listing go-live date on publication)
Last Updated: 2026-08-26
This revision: documents Stripe as the payment processor for the in-app Store (§4.1 and the new §4.1.1) and links Stripe's policy in §10. No other section changed.
This Privacy Policy explains how David Murdych, operating as “inLive” ("inLive", "we", "us", or "our") collects, uses, shares, and protects information about you when you use the inLive iOS application (the "App"), our website at www.inlive.health, and related services (collectively, the "Services").
inLive helps you understand and improve your health and longevity using on-device data analysis, AI assistance, and integrations with Apple Health and other health platforms. Because the Services involve health, fitness, and (optionally) genetic information, this policy goes into more detail than a typical consumer-app policy.
Quick Summary
- Health data is yours. We never sell, rent, or share it for advertising or marketing.
- Cross-device sync is on by default for signed-in accounts so your meals, fasts, and preferences follow you between your iPhone and iPad. Synced data is stored privately for your account (row-level security), you can pause sync for your whole account with one switch, and a separate control permanently deletes every synced record from our servers. Journal entries sync end-to-end encrypted — our servers only ever store sealed bytes we cannot read. See §5.2.
- You can sign in with Apple, Google, or email/password. We use Supabase for authentication; no passwords are stored in plain text.
- Genetic data (e.g., 23andMe) is optional and encrypted. Your raw genetic file never leaves your device. You can delete it any time.
- No tracking, no advertising SDKs, no IDFA. Our
PrivacyInfo.xcprivacydeclaresNSPrivacyTracking = false.- AI features are off until you approve them, and you control where they run. By default, inLive's AI runs on-device (Apple Intelligence) and nothing leaves your phone. If you turn on a cloud model, it receives only identifier-scrubbed health data plus a small set of coarse genetic markers — never your raw DNA. The optional paid BioMod Concierge tier sends that same scrubbed context to Anthropic through our own server. See §2 and §4.1.
- You can request a copy of your data or delete your account at any time from the in-app Profile screen.
Read on for the full details.
We collect only what we need to provide the Services. The categories below match what we declared in our App Store privacy nutrition label and our PrivacyInfo.xcprivacy privacy manifest.
If you connect Apple Health, the App reads the following types from HealthKit:
With your separate HealthKit write authorization, the App also writes back to Apple Health — only entries you create yourself, and only two kinds: a mindfulness session when you log a mood, and water you log (including from Apple Watch). Nothing else is written back: not supplements or medications, not menstrual-cycle data, not workouts, not body measurements. Writes are never AI-inferred. You can revoke write access at any time in iOS Settings → Privacy & Security → Health → inLive.
inLive writes data to Apple Health only for entries you create yourself — specifically, a mindfulness session when you log a mood and water you log from your Apple Watch. We never write AI-inferred data to Apple Health.
Clinical health records. inLive does not read or store HealthKit clinical records or medical-record types, and does not request the HealthKit clinical-records entitlement, in v1. The "Lab results & medical records" data in §1.1 refers only to lab panels you import yourself (PDF/photo) — not to Apple Health's clinical-records API.
If you authorize OAuth connections to:
we sync the data they expose via their APIs, scoped strictly to what is needed for inLive's features.
Importing genetic data (e.g., 23andMe raw export) is strictly opt-in and requires affirmative consent each time. Genetic data is encrypted at rest using a key stored in iOS Keychain, and your raw genetic file (SNPs / genotypes / rsIDs) is never transmitted off your device. If you enable a cloud AI model, only a small set of coarse, derived markers (e.g., caffeine / lactose / alcohol metabolism, MTHFR status, vitamin-D and inflammation tendencies) may be included in the AI context — never the raw data — and only after your separate genetic-data consent. You can delete your genetic data and all derived markers at any time from the in-app Profile screen; on withdrawal of consent, derived data is destroyed within 30 days.
If you take or pick a photo to scan a lab report, food label, or supplement barcode, the image stays on your device unless you explicitly use a feature (e.g., AI lab interpretation) that requires server-side OCR. In that case the image is sent to our edge function, processed in-memory, and discarded after the structured data is returned. We do not retain images server-side.
If you grant location permission, the App uses your precise location to find nearby clinics, gyms, healthy restaurants, and wellness venues. We do not persistently track your location, do not build a location history, and never share your location with third parties.
If you use the AI Coach voice feature, audio is processed on-device (Apple's Speech framework with on-device recognition required, or a local WhisperKit model as fallback). Raw audio is not transmitted to our servers. Transcribed text may be sent to your chosen AI provider as part of a chat message, subject to that provider's privacy policy and to your AI-data consent (§2).
NSPrivacyTracking = false.We use the information we collect to:
noreply@inlive.health. We do not send marketing emails by default.inLive's AI features (Coach, Council, insights, and the BioMod programs) are off by default and stay locked until you grant explicit "AI & Data" consent in the App. You control where AI inference happens:
In every cloud case, before any data leaves your device we run an on-device filter that removes direct identifiers (such as email addresses, phone numbers, and similar) from the context. Some health signals you are asking about (for example, lab values or vitals) are intentionally included so the AI can answer your question — this is consented processing, not anonymization. Raw DNA, genotypes, and rsIDs are never sent to any cloud provider.
We do not use your information to train AI models, build advertising profiles, or for any purpose unrelated to providing the Services to you. We do not authorize our hosted AI provider to train its models on your data; Anthropic's commercial API does not train on submitted data by default. Where you bring your own provider key, that provider processes your prompts under its own terms.
Per the Apple Developer Program License Agreement and App Store Review Guideline §5.1.3, we make the following binding commitments about health data accessed through HealthKit:
These commitments survive the termination of your inLive account and your deletion of the App.
We share information only in the limited circumstances described below.
We use the following sub-processors to operate the Services. Each is engaged under appropriate data-processing terms:
| Provider | Purpose | Data accessed |
|---|---|---|
| Supabase, Inc. | Cross-device sync (on by default; §5.2), authentication, database hosting, edge functions (including the BioMod Concierge AI proxy) | Account credentials, profile, synced health data (journal entries as unreadable ciphertext only), lab results, scrubbed AI context |
| Apple Inc. | Sign in with Apple, App Store, Push Notifications (if enabled), on-device Apple Intelligence | Account identifier, opaque relay email; on-device AI processes data locally and transmits nothing to us or Apple |
| Anthropic, PBC | Hosted AI for the optional BioMod Concierge tier (server-side, using inLive's key) | The text of your chat message + an identifier-scrubbed health/context window (coarse derived genetic markers only; never raw DNA) |
| Google LLC | Sign in with Google (optional) | Account identifier, name, email |
| Argmax (WhisperKit) | On-device speech recognition (no data transmitted) | None — runs locally |
| Stripe, Inc. | Payment processing for the in-app Store (physical goods and services — lab / DNA test panels, supplements, merchandise), on a Stripe-hosted checkout page | The order's line items and amounts, plus opaque order and account identifiers. Your name, billing details, and payment method are entered on Stripe's own page and are held by Stripe — they never pass through inLive. See §4.1.1 |
| AI providers you configure yourself (OpenAI, Anthropic, Google AI, xAI) | AI responses, only when you supply your own API key — your device talks to them directly | The text of your chat messages + scrubbed context |
We do not use Google Analytics, Firebase Analytics, Meta SDK, advertising SDKs, crash-reporting services that collect PHI, or any other analytics tools that would collect personal information from the App in v1.
The in-app Store sells physical goods and services (lab and DNA test panels, supplements, and merchandise). These are not in-app purchases, and inLive never collects, transmits, or stores your card details. There is no card field anywhere in the App.
SFSafariViewController), which runs outside the App's process — the App cannot read that page, its form fields, or Stripe's cookies.cs_… handle — not a card number and not a Stripe customer record) so the payment can be reconciled. Every price is re-derived from our own catalog server-side; the amount charged is never taken from your device.Orders you place in the App and orders you place on our website are the same record, so an order made in one place appears in the other.
If you connect Oura, Withings, Garmin, or other third-party platforms, data flows from those platforms to inLive subject to your authorization on each platform. We do not share your inLive data back to those platforms.
We may disclose your information when we believe in good faith that it is necessary to:
When legally permitted, we will give you advance notice of any required disclosure.
If inLive is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections. We will give you advance notice via email and the App at least 30 days before any such transfer where legally permitted.
inLive is local-first. Health data, including lab results, sleep records, vital readings, and genetic data, is stored on your device in an encrypted SwiftData store with iOS file protection — meaning the data is unreadable until your device has been unlocked at least once after boot. Your device's local store remains the primary copy and keeps working fully offline; the cloud copy described in §5.2 exists to keep your other devices in step.
Signed-in accounts sync automatically so your data follows you between your iPhone, iPad, and (via your iPhone) Apple Watch. Here is exactly what that means:
gugbfufbiajevxwaqbzl, hosted on Supabase's infrastructure on Amazon Web Services). Each record carries your account ID, the record type and ID, the record's content, timestamps, and an anonymous per-install device identifier used only for diagnostics.auth.uid() = user_id on read and write, so no user — even with the App's public API key — can read or modify another user's data.RAJH8R6U7T.PrivacyInfo.xcprivacy; no use of Required-Reasons APIs without disclosed reasons.If you install the inLive watch app, your paired Apple Watch shows a compact snapshot of your day (recovery score, calories, plan progress, fasting timer, supplement checklist) and lets you log water, mood, supplements, and meals from your wrist. This data moves only between your own iPhone and your own Watch over Apple's encrypted WatchConnectivity channel — the Watch never talks to our servers directly. The snapshot deliberately excludes your name and account identity. Entries you log on the Watch are applied on your iPhone and then follow the normal sync rules in §5.2. Signing out of the App wipes the Watch's local snapshot.
You can exercise the following rights at any time. If you are in a jurisdiction that grants additional rights (e.g., the EU, UK, California), those rights apply.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to:
Our lawful bases under GDPR Article 6 are: (a) consent, for optional features like genetic data import and AI features; (b) performance of a contract, for core App functionality you've requested — including keeping your account's data consistent across the devices you sign in on (cross-device sync), which you can pause or purge at any time; (c) legitimate interests, for security, fraud prevention, and improving the Services in ways that do not override your rights and freedoms.
For special-category data (Article 9), including health and genetic data, our lawful basis is explicit consent (Article 9(2)(a)) — captured when you accept health-data processing at account creation and reaffirmable at any time in Settings. Because cross-device sync stores health data on our servers, pausing sync (or deleting synced data) is the withdrawal mechanism for that specific processing; local-only use of the App continues unaffected.
The data controller is: David Murdych, operating as “inLive”. Contact: privacy@inlive.health.
Our Data Protection Officer / Privacy Contact: privacy@inlive.health.
California residents have additional rights to:
To exercise California rights, email privacy@inlive.health with your full name, the email associated with your account, and your specific request. We will respond within 45 days.
We honor analogous rights under Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Washington My Health My Data Act, and other state comprehensive privacy laws. Requests can be made to privacy@inlive.health.
For users in jurisdictions with specific genetic-information statutes (e.g., California CGIPA), you have the right to:
If you sign in with Apple, you may use Apple's "Hide My Email" feature to share a relay email address with us instead of your real email. We treat the relay email exactly as we would any other email address: it is used only for the purposes described in §2 of this policy. If you stop using Apple to sign in to inLive (Settings → Apple ID → Sign-In & Security → Apps Using Apple ID → inLive → Stop Using), your inLive account remains linked to whatever email was associated with it; you can transition to email/password authentication via the "Forgot Password" flow.
inLive is not intended for users under 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child under 18 has created an account, contact us at privacy@inlive.health and we will delete the account and any associated data. The Services are not designed for compliance with the Children's Online Privacy Protection Act (COPPA) and we do not seek to support under-18 users.
If you use inLive from outside the country where our servers and providers operate (primarily the United States), your data is transferred internationally. We rely on the following safeguards:
You can withdraw consent for international transfers at any time, but doing so will likely make it impossible to continue providing you with the Services.
When you use links, content, or services from third parties within or alongside the App (e.g., the websites of Oura, Withings, Garmin, or AI providers), those third parties' privacy policies apply to data they collect — not this Privacy Policy. We are not responsible for the privacy practices of third parties.
We encourage you to read the privacy policies of:
We may update this Privacy Policy from time to time. When we make material changes (changes that meaningfully reduce your rights or change how we use your data), we will:
For non-material changes (typo fixes, clarifications, structural reorganizations that don't change the substance), we will simply update the page. Your continued use of the Services after a non-material change constitutes acceptance of the updated policy.
For questions, requests, or complaints about this Privacy Policy or your personal information, contact us at:
We aim to respond to all privacy requests within 30 days, with extensions only when reasonably necessary and with prior notice to you.
This document is published at https://www.inlive.health/privacy. The version controlled in our public repository at github.com/David-NextHome/inLive under legal/privacy-policy.md is the canonical source.