Privacy Policy
Last updated: September 24, 2026
Longevity Assistant ("the Service") is a private, non-commercial, self-hosted application operated by an individual for personal use. This policy explains what data the Service handles and how. If you have questions, contact [email protected].
Who this applies to
The Service is intended for use by its operator and any individuals the operator explicitly authorizes. It is not a public product and does not create accounts for the general public.
What data we access
With your explicit authorization, the Service may access:
- Oura — sleep, readiness, heart-rate variability, activity, workouts and related biometric summaries, via the Oura API using OAuth2.
- Garmin — activity, sleep, heart rate, stress and related metrics.
- Strava — activities and related workout details, via the Strava API using OAuth2.
- Manual entries — notes you choose to record, such as how you feel, soreness, body weight or nutrition.
Access is granted by you through each provider's own authorization screen, and can be revoked by you at any time (see "Your choices" below).
How we use the data
- To display your own health and training information back to you.
- To compute a daily "readiness" score and training guidance.
- To answer your questions about your trends through an assistant feature.
The data is used only to provide these features to you. It is never sold.
Where data is stored
Data is stored on a private server controlled by the operator. It is not hosted on a public multi-tenant platform and is not shared with advertisers or data brokers.
Third-party processing
The assistant feature sends a summary of your recent metrics to Anthropic's Claude API to generate responses. Anthropic processes this data to return an answer and does not use API inputs to train its models. Data is also retrieved from the providers you connect (Oura, Garmin, Strava). Each of those providers has its own privacy policy.
Data retention
Data is retained on the private server for as long as the Service is in use, so it can show trends over time. You may request deletion of stored data at any time by contacting the operator, and you can disconnect any data source to stop further access.
Your choices
- Revoke Oura access in your Oura account under connected applications.
- Revoke Strava access in your Strava account settings.
- Disconnect Garmin or delete manual entries within the Service.
- Request deletion of all stored data by email.
Security
The Service runs behind encrypted (HTTPS) connections. Credentials and access tokens are kept in server-side configuration and are not exposed to third parties beyond the processing described above. No system is perfectly secure, and the Service is provided without warranty (see the Terms of Service).
Children
The Service is not directed to children and is not intended for anyone under 16.
Changes to this policy
This policy may be updated from time to time. The "last updated" date above reflects the most recent change.
Contact
Questions or requests: [email protected].