Privacy Policy
How your data is handled, in plain English.
The short version
- Your health data belongs to you. You can export or delete it at any time.
- We never sell your data — identifiable or de-identified.
- Research participation is opt-in, off by default. You choose how far in you want to go.
- If we ever generate revenue from research access to de-identified data, we will share that revenue with the users whose data made it possible.
- Raw data from third-party providers is never shared with researchers. Only your derived signals and self-reported data may participate in research, and only if you opt in.
- Kosei uses HIPAA-grade safeguards but is not HIPAA-compliant and is not a covered entity.
Who we are
Kosei is a paid precision-health membership operated from New Jersey. We do not run advertising, and we do not sell your data. Contact: longevitycorner@gmail.com.
What data we collect
We only collect data you explicitly provide or connect:
- Wearables (direct OAuth): WHOOP, Withings, Oura, Garmin — heart rate, HRV, sleep stages, weight, body composition, recovery scores, training load, and similar device-measured signals.
- Wearables (via platform bridge): Fitbit; Samsung Health and Galaxy Watch via Google Health Connect on Android; data routed through Apple Health on iOS where applicable.
- Health platforms: Apple Health (HealthKit live sync on iOS; export upload on web), Google Health Connect (Android), Google Fit (one-time import).
- Calendar (read-only): Google Calendar, Microsoft Outlook / Microsoft 365 — event titles, times, locations, and descriptions for configured lookback and lookahead windows.
- Lab results: Files you upload (PDF, image, CSV) and structured biomarker values we extract.
- Epigenetic reports: TruAge, SymphonyAge, and similar reports you upload.
- Self-reported events: Workouts, meals, supplements, symptoms, and other entries you log manually or via natural language.
- Experiments: Self-tracked N=1 experiments, hypotheses, and outcomes you create.
- Account basics: Email address used to sign in and billing metadata required for your subscription.
We continuously evaluate additional data sources based on scientific utility, security review, and member demand. Supported integrations may expand or change; connecting any source always requires your explicit authorization.
We do not collect: location tracking, advertising IDs, contacts, browsing history, or any data from sources you have not explicitly connected.
How we use your data
Your data is used only for the following purposes:
- Showing you your own dashboards, scores, and insights
- Powering the AI coach features you interact with
- Running the experiments and analyses you set up
- Maintaining and improving Kosei (debugging, performance, security)
- Research use — only with your explicit, separate opt-in per tier (see Section 6)
Scores and derived data
Your raw health data remains yours. Kosei computes proprietary scores, indices, and derived insights for your account. Our scoring logic — including the Kosei Health Index, dimension weights, and organ-system models — is proprietary to Kosei.
Where scores incorporate documented public formulas (for example, PhenoAge-style biological age estimates), we document methodology in-app and cite primary literature. See our Terms of Service for the full intellectual-property split.
AI processing
Coach K and other AI features (including lab PDF extraction, voice transcription, and coaching) send relevant subsets of your data to third-party AI model providers (currently xAI / Grok) to generate insights and answer your questions. By accepting these Terms and this Privacy Policy at signup, you consent to that processing for product features you use. You can still review Coach K context controls in the app. These providers process data to return a response and, per their terms, do not train on it.
Calendar events you mark as private are excluded from any AI prompt. You can also disable any individual data source from the AI context in Profile → Connections.
Research participation — opt-in tiers
We believe consumer health data, properly de-identified and ethically governed, can power important longevity research — research that is currently difficult because no one has continuous, longitudinal, multi-modal data with real-life context.
We want to help build that future, but only with your explicit consent at each level. During onboarding you may record a preference for each tier. All tiers are off by default. Research sharing is not active until we launch the research program and give you a clear in-app control to confirm or change your preference. Preferences you set today are stored only as intent, not as live enrollment.
The model below is described publicly on our Principles page — see commitment #11: "You are a participant, not a product."
Tier 1 — Aggregate insights inside the app
Off by default
Your data contributes to anonymous, aggregated population statistics shown inside the app — for example, 'people on a similar protocol averaged 7.2 hours of sleep this week.' Aggregates are released only when at least 20 users contribute (k-anonymity ≥ 20).
Tier 2 — Kosei-internal de-identified research
Off by default
Your data, de-identified to the HIPAA Safe Harbor standard, becomes part of an internal research dataset used by Kosei to study patterns, validate features, and publish non-commercial findings. No data leaves Kosei systems.
Tier 3 — Academic / non-commercial researcher access
Off by default
Vetted academic and clinical researchers may run IRB-approved, non-commercial studies on a de-identified, federated copy of the dataset. Researchers query inside a secure environment and only take aggregated, k-anonymous results out — they never download raw individual data.
Tier 4 — Commercial researcher access (pharma, insurance, device makers)
Off by default — separate consent required
A separate, more deliberate consent. Vetted commercial entities may run IRB-approved studies under the same federated, k-anonymous, no-raw-export rules as Tier 3. We require additional disclosures: the type of organization, the question being studied, and the duration of access. You may revoke at any time.
Hard rules that apply to all tiers:
- Raw third-party data is never in the research pool. Data received from wearables, health platforms, and calendar providers stays in your account only. Their terms forbid redistribution. Only your derived signals (computed scores, trends, experiment outcomes) and self-reported data may participate in research, and only if you opt in.
- De-identification standard: HIPAA Safe Harbor — all 18 identifier categories removed (name, email, exact dates, geographic detail finer than state, device IDs, etc.). For high-dimensional records, we additionally apply k-anonymity ≥ 20 and generalize timestamps to week-of-year.
- Federated access only. External researchers query inside a secure enclave we control. They never receive raw individual records.
- IRB required. Every external study must have approval from a recognized Institutional Review Board.
- Audit log. Every external query is logged and reviewable on request.
- No re-identification attempts. Researchers contractually agree not to attempt re-identification, and not to combine the dataset with outside data for that purpose.
Revenue sharing
If we ever generate revenue from Tier 3 or Tier 4 research access, we will share that revenue with the users whose data made it possible. This is a foundational commitment — restated as commitment #11 on our Principles page.
The exact mechanism, percentages, and distribution method will be published before any paid research access is offered, and users will be notified and given the option to participate or to revoke their tier consent. We will not retroactively claim rights to data contributed before the revenue-sharing program is finalized.
No revenue-generating research access exists today. This section reserves the structure for the future.
What we will never do
- Sell your data — identifiable or de-identified — to anyone, ever.
- Share your identifiable data with advertisers, data brokers, or marketing platforms.
- Hand raw data to researchers, even with consent.
- Allow re-identification attempts under any circumstance.
- Share data with insurance companies, employers, or law enforcement absent a valid, narrowly scoped legal demand. We will challenge overbroad requests and notify you whenever legally permitted.
- Use partner-API data for any purpose outside your account.
Your rights and controls
- Access: View all your data inside the app.
- Export: Download a complete copy of your data on request.
- Delete: Permanently delete your account and all associated data. Deletion includes any de-identified copies up until they are aggregated into a published study or released aggregate — once aggregated, individual contributions are mathematically inseparable.
- Disconnect: Disconnect any integration at any time from Profile → Connections. Already-synced data remains until you delete it.
- Revoke research consent: Turn off any research tier any time. New data will not flow into the pool, and we will exclude your existing data from any not-yet-aggregated future studies.
- Per-event privacy: Mark any calendar event as private to exclude it from AI processing.
Security
Kosei protects your health information with HIPAA-grade safeguards: encryption in transit and at rest, multi-factor authentication, strict access controls, audit logging, and permanent deletion within 30 days of account closure.
Kosei implements administrative, technical, and physical safeguards aligned with the HIPAA Security Rule. Kosei is a wellness technology company, not a healthcare provider or health plan, and is not HIPAA-compliant. We do not assert covered-entity status under HIPAA.
Technical details, subprocessors, and how to report a vulnerability are on our Security page. If we experience a breach affecting your data, we will notify you promptly with details of what happened and what to do.
Third-party services we use
These vendors process data on our behalf. We review their security posture regularly and pursue business associate agreements where health data is stored or processed.
- Fly.io — application hosting, compute, and encrypted volumes.
- Neon — managed Postgres database (all user health and account data at rest).
- xAI (Grok) — AI coaching, transcription, and lab extraction (after legal accept / product consent).
- Upstash Redis — caching, rate limits, and ephemeral Coach K session state.
- Sentry — error monitoring (PHI scrubbed from payloads).
- Resend — transactional email (verification, login alerts, password reset).
- Stripe — payment processing for paid memberships (when you subscribe).
- Amazon S3 (or equivalent object storage) — encrypted storage of uploaded lab PDFs when configured.
- Wearable, calendar, and health-platform providers — only when you explicitly connect them. Each governs data on its side under its own privacy policy.
Children
Kosei is not intended for users under 18. Do not connect or upload data for anyone under 18.
Changes to this policy
If we change this policy in a way that materially expands how your data may be used, we will notify you in-app and require a fresh opt-in before applying the change to your data. Cosmetic changes will be noted with an updated "Effective" date above.
Contact
For any privacy question, request, or concern, email longevitycorner@gmail.com. We aim to respond within a few business days.