Superlife

Consumer Health Data Privacy Policy

Last updated: September 10, 2026

Effective date: September 4, 2026.

This policy explains how Superlife collects, uses, and shares consumer health data, and the rights you have over that data. It is separate from our general Privacy Policy on purpose: laws such as the Washington My Health My Data Act ask companies to explain health data on its own page, and health data is most of what Superlife touches, so it deserves its own page anyway.

The short version: your health data exists in Superlife so that you can see it, keep it in one place, and ask questions about it. We do not sell it. We do not use it for advertising. We share it only with the service providers needed to run the app, listed by name below.

The health data we collect

We collect health data from these sources: you directly (documents you upload or photograph, information you enter, and questions you ask), visit recordings you choose to make, which become transcripts and notes in your record (the audio is transcribed and discarded, never stored by us, as described below), the patient portals and device accounts you choose to connect (Epic, WHOOP, Oura), Apple Health if you connect it, and family members or caregivers who share their records with you or who manage a record about you and enter information into it. There are no other sources.

  • Records and documents you add. Medical records you connect or upload, photographed lab reports, and the documents themselves. When you photograph or upload a document, its pages are sent to Google to read the text so the results can be organized into your record (see the provider list below).
  • Your connected providers. When you connect a patient portal or a device account, we store which organization you connected. Who your provider is says something about your health, so we treat it as health data. These connections are direct between Superlife and the provider (Epic patient portals, WHOOP, Oura); no data broker or aggregator sits in between.
  • Health details you tell us. Information you enter in the app, including pregnancy status, and your answers about why you are using Superlife.
  • Conversations about your health. Your questions to the Superlife assistant and its answers, and transcripts of visit recordings.

Apple Health measurements. If you connect Apple Health, Superlife reads the measurements listed below and saves them to your Superlife account. Superlife reads from Apple Health only. It never writes to Apple Health.

  • Heart and vitals: heart rate, resting heart rate, heart rate variability, heart rate recovery, respiratory rate, blood oxygen, blood pressure (systolic), blood pressure (diastolic), blood glucose, VO2 max, wrist temperature while asleep
  • Activity: steps, walking and running distance, cycling distance, swimming distance, flights climbed, active energy, resting energy, exercise minutes, stand minutes, time in daylight
  • Body measurements: weight, height, body mass index, body fat percentage, lean body mass, waist circumference
  • Walking steadiness and mobility: walking speed, walking steadiness, walking asymmetry, double support time, stair ascent speed, stair descent speed, six-minute walk distance
  • Nutrition: dietary energy, protein, carbohydrates, total fat, water, caffeine
  • Sound exposure: headphone audio levels, environmental sound levels
  • Sleep and mindfulness: sleep, including time in bed, time awake, and time in core, deep, REM and unspecified stages; mindful minutes

About visit recordings specifically: when you finish a recording, the audio file is sent over an encrypted connection to Groq, our transcription provider, which turns it into text. The audio is processed under a zero-data-retention setting and is not kept by Groq, and we never store it on our servers — the transcript is what is saved to your account. A copy of the audio stays on your phone, where it plays back, until you delete it; the app deletes it after 90 days in any case.

Data we collect that is not health data

Your name and email from Apple or Google sign-in, your phone number if you sign in by phone, your account id, a push notification token, and your subscription status. These are covered in the general Privacy Policy, and they appear here because some of them travel with your health data inside the app.

What we do not collect

We do not collect your location and we do not use geofencing. We do not collect your contacts, browsing history, or search history outside the app. We do not run advertising trackers. Face ID and Touch ID stay on your device; Apple never shares biometric data with us.

We do measure how the app is used and we do receive crash reports, and neither one carries consumer health data. Those tools receive the screen you opened, the action you took, the fault when the app breaks, and an identifier for your account. They never receive a value from your chart, a document, a message, or a measurement from Apple Health.

We do record how the app looks while you use it. Every word, every image, and every chart is covered before the picture leaves your phone, so the recording shows the layout and where you tapped. It carries no consumer health data.

How we use health data

One purpose: making Superlife work for you. Showing you your records, keeping them organized, syncing your measurements, and answering the questions you ask. That is the whole list.

We do not sell consumer health data, and we have not sold it. We do not share it for advertising. We do not use it to train advertising or marketing systems.

Who we share health data with, by name

We share data only with service providers that process it for us to run the app.

Providers that receive health data:

  • OpenAI. When you ask the Superlife assistant a question, the relevant parts of your record are sent to OpenAI to generate the answer, and OpenAI also generates conversation titles and summaries. The app asks for your consent before your first question and tells you at that moment what leaves your phone. OpenAI does not use API data to train its models by default and may retain API data for up to about 30 days for abuse monitoring.
  • Groq. When you finish a visit recording, the audio file is sent to Groq to be turned into text. Groq processes it under a zero-data-retention setting, does not keep the audio, and does not use it to train models. It receives the audio and nothing else about you.
  • Google. When you photograph or upload a document, its pages are sent to Google to read the text. Google also processes short text snippets used to suggest trackers. Google also stores the document files themselves, in Google Cloud Storage. Those files are encrypted while they are stored and while they travel, with keys Google manages, which is not the same as end-to-end encryption.
  • Fly.io. Runs our servers.
  • Neon. Hosts our database, where your account data, including health data, is stored.
  • Apple. Carries push notifications to your phone. When the assistant checks in on something you raised in a chat, the question itself is the notification, so Apple carries that text. Apple holds the message until your phone receives it, or for at most one day, then discards it. We send Apple nothing else.

Providers that receive no health data:

  • RevenueCat. Manages subscriptions. Receives your account id, purchase data, and device information.
  • PostHog. Measures how the app is used. Receives the screen you opened, the action you took, and an identifier for your account.
  • Upstash. Rate-limits sign-in attempts. Sees IP addresses only.
  • Prelude. Sends phone sign-in codes. Sees phone numbers only.
  • Vercel. Hosts our website, including this policy page. Sees standard web requests from your browser when you visit the site. Receives nothing from the app.

No affiliate receives consumer health data.

No third party collects consumer health data about you over time and across different websites or apps through Superlife. We run no advertising trackers. Our usage measurement and crash reporting receive no consumer health data, as described above.

We share data beyond this list only if the law requires it, and we will tell you it happened unless the law forbids that.

Your rights over your health data

You can:

  • Ask what we have. Confirm whether we collect health data about you and get access to it.
  • Ask who received it. Get the list of third parties we have shared your health data with, which is the list above.
  • Withdraw consent. Stop future collection or sharing at any time. Turn the assistant off in Settings, and nothing more goes to a model provider. Disconnect a patient portal or a device account in Settings, and nothing more arrives from it. Apple Health is different: iOS owns that permission, so you turn off Superlife in the Health app, under Sharing, Apps and Services. We stop reading it from that moment. You can review and edit much of your health data directly in the app, including your chart and the entries you track and log. For anything you cannot edit in the app, ask us to correct it using the contact procedure below.
  • Delete. Delete your account in Settings. This deletes your account and every record you own, including records you share with family and records you manage for them, and every document in those records: the files themselves, not just the entries that point to them. The files are deleted first. If some files cannot be deleted, the deletion stops with an error and your account remains. Files already deleted stay deleted, and retrying finishes the job. A record that someone else manages about you belongs to their account, and deleting your account does not affect it. You can also delete any single document at any time without deleting your account. You do not have to delete your account to exercise your deletion right: you can ask us to delete your health data, or any part of it, while keeping your account. Contact us as described below, and the response times below apply.

To exercise any of these, email support@getsuperlife.com. If you sign in with Apple or Google, email us from the address on your account. If you sign in with a phone number, email us from any address and tell us that number. We then send a code to that number, and you send it back to us. We respond within 45 days. If a request is unusually complex, we can take one more 45 days, and we will tell you.

If we decline a request, we will explain why, and you can appeal by replying to our response. If the appeal fails, you can contact the attorney general in your state. We will never treat you differently for exercising these rights.

Where this policy lives

A link to this policy appears on the getsuperlife.com homepage and in the app under Settings, Privacy.

Changes

If this policy changes, the effective date above changes, and material changes will be announced in the app before they take effect.

Contact

support@getsuperlife.com