Privacy Policy

Effective September 13, 2026 · Applies to the LIFE1 app for iPhone and Apple Watch and to life1.ai

  1. Who we are and what this policy covers
  2. Summary of what we collect
  3. Information you give us
  4. Information from Apple Health
  5. Location information
  6. Information collected automatically
  7. How we use information
  8. AI processing
  9. Apple Health and HealthKit commitments
  10. How we share information
  11. Where information is stored and international transfers
  12. How long we keep information
  13. Your rights and choices
  14. Region-specific notices
  15. Children and family members
  16. Security
  17. Changes to this policy
  18. How to contact us

The short version: LIFE1 collects the health, fitness, nutrition and location information needed to run the app for you, stores it under a random user ID on servers in the United States, never sells it, never uses it for advertising, and lets you export or delete all of it from Settings at any time.

1. Who we are and what this policy covers

This Privacy Policy explains how Life1 Health Corporation (Toronto, Ontario, Canada) and its affiliate OpenMD AI Inc. (Lewes, Delaware, United States), together "LIFE1", "we" or "us", collect, use, disclose and protect personal information when you use the LIFE1 application for iPhone and Apple Watch, the LIFE1 widgets and complications, and the website at life1.ai (together, the "Service"). Life1 Health Corporation is the organization responsible for your personal information; OpenMD AI Inc. operates the Service on its behalf.

It applies to everyone who uses the Service, whether or not you create an account. If you use LIFE1 in "Try without an account" mode, most information stays on your device, and the sections below tell you which parts still reach our servers.

Capitalized terms not defined here have the meaning given in our Terms of Service.

2. Summary of what we collect

CategoryExamplesWhyLinked to you
Contact informationName, email addressYour account, restoring your data, answering youYes
Health and fitness informationWorkouts, weight, sleep, heart rate variability, resting heart rate, steps, meals and nutrition, fasting windows, Health Score, conditions, medications and allergies you enterProviding the Service and personalizing it to your protocolYes
Precise locationLatitude and longitude while the app is in useNearby events, restaurants and care providers; GPS activity trackingYes
PhotosMeal photos you choose to scanEstimating calories and nutrientsYes
IdentifiersA random user ID created by the appKeeping your data together and secureYes
Usage informationFeature usage events such as completing onboardingUnderstanding which features are used and improving themYes
DiagnosticsCrash reports and performance metricsFixing defects and keeping the app reliableYes

We do not collect payment information (LIFE1 1.0 has no purchases), contacts, browsing history, advertising identifiers or audio recordings, and we do not track you across other companies' apps or websites. This table matches the privacy labels shown for LIFE1 on the App Store.

3. Information you give us

Account information. If you create an account: your name, email address and a password, which we store only as a salted hash. Signing in with Apple gives us the name and email Apple shares with us, which may be a private relay address.

Profile information. Your chosen protocol (Lean, Lift or Longevity), sex, age or date of birth, height, weight, goal weight and target date, fitness level, focus areas, wake and sleep times, equipment, injuries, dietary preferences, allergies, smoking status, and any conditions or medications you choose to record. You can leave most of these blank.

Information you log. Meals (including any photo you scan, the text you type or dictate, and the resulting nutrition estimates), workouts and sets, weigh-ins, water, fasting start and end times, readiness check-ins, progress photos you take, and notes you attach to screenings or appointments.

Family members and dependents. If you use the Family dashboard, the names, dates of birth and health information you enter about your children, parents or other dependents. See section 15.

Correspondence. What you send us when you contact support.

4. Information from Apple Health

With your permission, LIFE1 reads from Apple Health (HealthKit): activity and workouts, active energy, steps, distance, heart rate, heart rate variability, resting heart rate, sleep analysis, body mass, and related measurements. We use them to compute your Health Score, Recovery Score and insights, to prefill weight, and to show sleep and vitals in the app. LIFE1 writes to Apple Health only when you take an action that creates a record: finishing a workout, logging water, or logging your weight.

You control every category in the Health app under Sharing, Apps, LIFE1, and you can revoke access at any time. Our commitments for this data are in section 9.

5. Location information

With your permission, LIFE1 uses your device's precise location while the app is open to find nearby community events and activities, restaurants and care providers, and to record the route, distance and pace of outdoor activities you start (run, walk, hike, bike). Your coordinates are sent to our servers with your user ID when you search for nearby content. Outdoor activity routes are stored on your device and in your activity history. LIFE1 does not collect location in the background.

6. Information collected automatically

Identifiers. The app generates a random user ID on first launch. We do not use the advertising identifier.

Device and app information. Device model, operating system version, app version and language.

Usage events. A small number of product events, for example that onboarding was completed or which protocol was selected, so we can understand which features are used.

Diagnostics. Crash reports and performance metrics generated by Apple's MetricKit framework, sent to our servers on the next launch after a crash. These contain technical stack traces and device information, not your health records.

Server logs. Our servers record the requests they receive, including IP address, time and the endpoint called, for security and troubleshooting.

Voice and microphone. If you dictate a food entry, the audio is transcribed by Apple's speech recognition on your device or through Apple's services under Apple's privacy terms; only the resulting text reaches us. The optional sleep sound analysis runs entirely on your device and no recording is uploaded.

7. How we use information

We do not use your information for advertising, we do not build advertising profiles, and we do not sell it. Under Canadian law, our processing relies on your consent, which you give when you create an account or begin using the Service and can withdraw as described in section 13. Where the GDPR or UK GDPR applies, we process account and usage information to perform our contract with you and for our legitimate interests in operating a secure and reliable service, and we process health information only with your explicit consent.

8. AI processing

Some features use machine-learning models. Meal photos you scan, menu photos, and requests for meal plans or recipe nutrition are processed by models hosted in our own cloud account through Amazon Bedrock, operated by Amazon Web Services in the United States. Under our agreement with Amazon Web Services, prompts and outputs are not used to train the underlying models and are not shared with the model providers. Results are estimates that you can correct before saving.

LIFE1 does not make decisions about you that have legal or similarly significant effects using automated processing alone. Scores and insights are informational, and you can always see the inputs behind them in the app.

9. Apple Health and HealthKit commitments

In line with Apple's requirements for apps that use HealthKit, we commit that health information obtained through Apple Health:

10. How we share information

We share personal information only in these cases:

We do not "sell" or "share" personal information as those terms are defined under California law, and we have not done so in the preceding 12 months.

11. Where information is stored and international transfers

Your information is stored on your device and on servers operated for us by Amazon Web Services in the United States (US East region). If you live outside the United States, including in Canada, Quebec, Mexico, the European Economic Area or the United Kingdom, your information is transferred to and processed in the United States, where privacy laws may differ from those of your jurisdiction. We protect it with the safeguards described in section 16 and with contractual commitments from our service providers. By using the Service you consent to this transfer. Quebec residents: personal information communicated outside Quebec is subject to a privacy impact assessment as required by Quebec law, and is protected by contract.

12. How long we keep information

13. Your rights and choices

Wherever you live, you can:

We never discriminate against you for exercising a privacy right.

14. Region-specific notices

Canada (PIPEDA and provincial laws). You may access and correct your personal information and withdraw consent, subject to legal and contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.

Quebec (Law 25). Life1 Health Corporation has designated a Person in Charge of the Protection of Personal Information, reachable at privacy@life1.ai or at First Canadian Place, 57-100 King Street West, Toronto, Ontario M5X 1B1, Canada. You have the rights of access, rectification, withdrawal of consent, and, where technically feasible, to receive computerized personal information you provided in a structured, commonly used technological format. You may file a complaint with the Commission d'accès à l'information du Québec. A French version of this policy is available at life1.ai/fr/privacy.html.

United States, including California (CCPA/CPRA). The categories of personal information we collect, the purposes, and the categories of third parties are described in sections 2 to 10. California residents have the right to know, delete, correct, and to opt out of sale or sharing; we do not sell or share personal information and do not use or disclose sensitive personal information other than to provide the Service. We do not offer financial incentives for personal information. You may use an authorized agent; we will verify the request. Residents of other states with comprehensive privacy laws have similar rights under those laws.

Mexico (LFPDPPP). This policy serves as our privacy notice (aviso de privacidad). You may exercise ARCO rights (access, rectification, cancellation, opposition) and revoke consent by contacting us. A Spanish version is available at life1.ai/es/privacy.html.

European Economic Area and United Kingdom. Our legal bases are described in section 7. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority. Transfers to the United States rely on standard contractual clauses and the UK Addendum with our service providers.

15. Children and family members

The Service is intended for adults. You must be 18 or older, or the age of majority where you live, to create an account, and we do not knowingly collect personal information directly from anyone under that age. If you believe a minor has provided us information directly, contact us and we will delete it.

The Family dashboard lets an adult account holder record health information about their own minor children or other dependents. By entering it you confirm you are the parent, legal guardian or otherwise authorized to do so. That information is stored with your account, protected like your own, and deleted when you delete it or your account.

16. Security

We protect information with encryption in transit (TLS 1.2 or higher on every connection) and at rest (AES-256 in our cloud storage and databases), salted password hashing, signed session tokens that are checked on every request, per-user authorization so one account cannot read another's data, least-privilege access for our staff, secrets kept in a managed vault, and monitoring of our infrastructure. No system is perfectly secure; if a breach creates a real risk of significant harm, we will notify you and the relevant authorities as the law requires. Details are on our Security page.

17. Changes to this policy

We may update this policy as the Service and the law change. The effective date at the top tells you when it last changed. For material changes we will notify you in the app or by email before they take effect, and where required we will ask for your consent again.

18. How to contact us

Privacy questions and requests: privacy@life1.ai
General support: help@life1.ai · 1-833-91-LIFE1
Life1 Health Corporation, First Canadian Place, 57-100 King Street West, Toronto, Ontario M5X 1B1, Canada
OpenMD AI Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States