Superlife

Privacy Policy

Last updated: September 16, 2026

Superlife helps you keep your health information in one place. The app is operated by Invezo Finance Inc, doing business as Standard Code (“Standard Code”, “we”, “us”). Your health data is sensitive, and this policy explains plainly what we collect, why, and what we never do with it.

We have written this to describe what the app actually does today, not what we plan to add. When we ship something that changes how your data is handled, we update this page at the same time.

What we collect

  • Account information. Your name and email address when you sign in with Apple or Google, and your phone number if you sign in that way.
  • Profile details. Basics you choose to share during setup, such as your date of birth, sex, and country, used to put your results in the right context.
  • Health information you add. Documents and results you upload, and the messages you send in chat.
  • Recordings you make. When you record a conversation or a note to yourself, the audio is sent over an encrypted connection to be turned into text, and the written transcript is saved to your record. We never store the audio on our servers — it is transcribed and discarded in the same request. A copy stays on your phone, where it plays back, until you delete it; the app deletes it after 90 days in any case.
  • Health information from accounts you connect. If you connect a health system or a wearable, we receive the records and measurements that account holds for you. See Accounts you connect below.
  • Apple Health measurements. If you turn on Apple Health, we read the measurements you allow, such as steps, heart rate, sleep, and weight, and save them to your Superlife account so they sit beside your labs. Superlife reads from Apple Health only, and never writes to it. These measurements are handled the same way as everything else here: never sold, never used for advertising, never used to train an AI model. The assistant reads the ones needed to answer a question you ask.
  • Subscription status. Whether you have an active subscription, and an identifier linking it to your account. Payments are handled by Apple or Google — we never see your card details.
  • How the app is used, and how it fails. Which screens you open, which actions you take, and the technical details of a crash: the device model, the version of the app, and where in our code it stopped. Each one carries an identifier for your account, so we can see that one person hit the same bug twice. None of it carries anything from your record. We record that a document was opened, never which document. We record the screen you were on as a pattern, so a document’s identifier never travels with it.

We do not use advertising software or cross-app tracking. No company builds a profile of you across other apps through Superlife. We do not record your screen.

How we use it

  • To provide the app: storing your records and answering your questions about them.
  • To keep the service secure, prevent abuse, and fix problems.

We do not use your health information for advertising, for profiling, or for any purpose other than running Superlife for you.

AI providers

Some things Superlife does require sending part of your information to an AI provider. We name them here, and we say what each one receives, because the two are not the same.

  • Together AI — answers your questions in chat, writes the summary shown when you open a recording, and reads the text of a document into the results we store. In chat it receives your message and the parts of your record needed to answer it, not your whole record. It can read a recording’s transcript when your question is about what was said. To write a recording’s summary it receives that whole transcript. Both are described below. It never receives audio. Together AI runs every request under a zero-data-retention setting: what you send is processed and then removed, and none of it is used to train a model.
  • OpenAI — writes the short name at the top of a conversation, and does nothing else. It receives your first message and the assistant’s first reply. It never receives your documents, your labs, your recordings, or audio.
  • Groq — turns your recordings into text. When you finish a recording, the audio file is sent to Groq’s transcription service, which returns the written transcript. Groq processes the audio under a zero-data-retention setting and does not keep it, does not train on it, and receives nothing else from your record — not your name, not your account, and not the transcript of any other recording.
  • Google — reads documents that are scans or photographs of paper. When a document has no readable text in it, we send an image of the entire page to Google’s Gemini API so that the text can be read. It also picks the check-ins a new progress starts with, and for that it receives the name you gave the progress and nothing else.

The model answering you runs on Together AI’s servers. It is open-weight software, hosted in the United States by Together AI and operated by them under the terms above. The company that published the model receives nothing from you and operates none of it.

The whole transcript means the whole transcript. To summarise a recording the model has to read all of it, so the entire text of that one recording is sent — including the parts that end up in no summary at all. For a summary, only that one recording is sent— not your other recordings, and nothing else from your record.

In chat, the assistant can read a transcript too, and what it reads is kept. When your question is about what was said in a recording, the assistant opens that recording and reads it — one at a time, only when the question calls for it, and never all of them at once. Over a long conversation it may open more than one. What it reads is stored with that conversation, the same way the lab values it looks up are, so it can still see them on later turns.

That copy outlives the recording. Deleting a recording removes the recording, its transcript and your notes. It does not reach back into a conversation that already read it. To remove that copy, delete the conversation. We are telling you this here rather than leaving you to discover it, because the delete button on a recording does not say it.

The summary is written by AI, and the recording is the record. The sentences you read at the top of a recording are the model’s own, not a quotation and not a clinician’s note. It is told to use only what is in the recording — not to add advice, not to say what anything might mean, not to name a condition nobody named — but it is software writing a summary, and it can get something wrong or leave something out. The full transcript sits underneath it, unedited, for exactly that reason.

The entire page means the entire page. Your name, date of birth, medical record number, the ordering clinician and the lab’s letterhead are printed on the same sheet as the results, and there is no way to read one without sending the other. We would rather say that plainly than describe it as sending “the document.”

A document’s words go to Together AI. Its page images go to Google. Most documents already carry readable text, and a report downloaded from a patient portal is one of them. We pull that text out on our own servers and send the text to Together AI, which reads the results, the findings and the follow-ups off it. No page image leaves for a document we can read this way. A page whose text we cannot read is the one that goes to Google as a picture.

  • Your data is never used to train AI models — not ours, not theirs.
  • Together AI and Groq keep nothing at all. Both run under a zero-data-retention setting, so a request is processed and then removed from their systems.
  • Google and OpenAI may keep a request for a limited period, no more than 30 days, to detect abuse of their service, and use it for nothing else.
  • A page image is sent only after you have accepted a document into your record — never while you are still deciding whether to keep it.

If we add another AI provider, we will name it here before any of your information reaches it.

Medical literature lookups

When you ask a research question in chat, our servers search public medical databases for relevant studies and health topics: PubMed and MedlinePlus, both run by the U.S. National Library of Medicine, Europe PMC, run by EMBL-EBI in the United Kingdom, and supplement fact sheets from the NIH Office of Dietary Supplements. These searches leave from our servers, never from your device, and carry only search terms derived from your question — never your name, account, or anything from your record. If your question names a medication, that medication's name is also sent to the National Library of Medicine's DailyMed service to fetch its official FDA label, and to the FDA's openFDA service to check for recalls and adverse event report counts — the name from your question only, never your medication list. MedlinePlus topic pages and NIH fact sheets are downloaded in bulk on a schedule, so those lookups send nothing about you at all.

What we never do

  • We never sell your data, and we never share it for cross-context advertising.
  • We never use your health data for advertising or marketing.
  • We never let anyone train an AI model on your health information.
  • We never share your health data with anyone except the service providers listed here who are needed to run Superlife, or when the law requires it.

Who we share it with

Only the providers that make the app work, each acting on our instructions and bound by their agreements with us:

  • Together AI — processes chat questions, recording transcripts, and document text, as described above. Zero data retention: your request is processed and not kept.
  • OpenAI — names conversations, as described above.
  • Groq — transcribes your recordings, as described above. Zero data retention: the audio is processed and not kept.
  • Google — reads scanned and photographed documents, picks the check-ins a new progress starts with from its name, and stores the document files themselves in Google Cloud Storage. Your scans and photographs are encrypted there, both while they are stored and while they travel, with keys Google manages. That is not the same as end-to-end encryption.
  • Neon — hosts the database holding your account, profile, records, and conversations.
  • Fly.io — runs the servers the app talks to.
  • PostHog — counts how the app is used, so we can see which parts people reach and which they abandon. It receives the screen you opened and the action you took, with an identifier for your account. No health information is ever sent to it, and it does not record your screen.
  • Sentry — receives the technical report when the app crashes or errors, so we can fix it. It receives the fault, the device model, the version of the app, and an identifier for your account. It is configured to send no request contents and no text from the screen. No health information is ever sent to it.
  • Prelude — sends the one-time code to your phone if you sign in with a phone number. It receives your phone number and nothing else. No health information is ever sent to it.
  • RevenueCat — manages subscriptions. It receives your subscription status and an identifier for your account. No health information is ever sent to it.
  • Apple and Google — sign-in, if you use them, and payment processing if you subscribe. Apple also carries our push notifications, and a check-in question written from one of your chats can be the notification text.

We will update this list before adding anyone new who would handle your health information.

Public databases we query

The literature sources named above — PubMed, MedlinePlus, and DailyMed at the National Library of Medicine, the NIH Office of Dietary Supplements, Europe PMC at EMBL-EBI, and the FDA's openFDA service — are a third kind of party, so they do not appear in the list above. They are public databases anyone can query, not providers acting on our instructions, and we have no agreements with them. What reaches them is what Medical literature lookups describes and nothing more: search terms derived from your question, and a medication name if your question contains one — never your name, your account, or anything from your record.

One more service belongs here for the same reason. When your question names a medication, we ask RxNav — also at the National Library of Medicine — to turn that name into the standard identifier the label lookup needs. It receives the medication name and nothing else.

Accounts you connect

Superlife can pull your records in from places that already hold them, so you do not have to type them in. Today that means health systems that use the Epic patient portal — including Kaiser Permanente — and the WHOOP and Oura device accounts. We will name any new one here before it is offered in the app.

These are sources rather than service providers, and the difference is the direction: information flows from them to you. We do not send your Superlife records to any of them.

  • You authorize each account yourself, by signing in on that company’s own page. We never see your password for it.
  • We store an access key, encrypted. The key that lets us fetch your records is encrypted by us before it is saved, so our database never holds it in readable form.
  • You can disconnect at any time in the app, which stops anything further from arriving. Records already in your Superlife record stay there until you delete them, and deleting your account removes them along with everything else.

Where your data lives

Your records are stored in the United States with established cloud infrastructure providers. Connections between the app and our servers are encrypted in transit, and the database is encrypted at rest by our hosting provider. Access within our team is limited to what is needed to operate the service.

When a request is sent to an AI provider, it is processed on that provider’s own infrastructure in the United States. Both your stored records and AI processing remain in the United States.

One more flow leaves our servers: medical literature searches. One of the databases they reach — Europe PMC — is run by EMBL-EBI in the United Kingdom. Those requests carry only the search terms described above; EMBL-EBI logs them the way web servers do, and deletes IP addresses from its web logs after 30 days and from its security logs after 90.

Superlife is not a healthcare provider

We are not a doctor’s office, hospital, insurer, or health plan, and we are not a HIPAA-covered entity. HIPAA governs your providers and their contractors; it does not govern an app you choose to put your own records into. That does not lower the standard we hold ourselves to — it means the protections you have here come from this policy and from the law that applies to consumer health data, and we would rather say so than let you assume otherwise.

Records about other people

Superlife is built for families, so you may end up holding records that belong to someone else — a parent, a partner, a child. If you add another person’s health information, you are telling us you have their permission or the legal authority to do so, and you remain responsible for how you use it. If that person asks us to remove their information, contact us and we will work with you to do it.

Your choices

  • You can delete individual conversations in the app.
  • You can delete an individual recording in the app. The transcript, your notes, and the audio copy on your phone go with it.
  • You can delete your account and everything in it in the app, under Settings, or by emailing us. Deletion is permanent.
  • You can request a copy of your data by emailing us.
  • You can ask us to correct information we hold about you by emailing us.

Two limits worth stating plainly. Deleting a document removes it and the lab values we read out of it, and deleting a recording removes its transcript and notes. Disconnecting is different — it stops new data arriving from that source and leaves what has already come in, which you remove the same way you remove anything else here. And in every case, what the assistant already read stays in the conversation that read it — an answer it gave, a lab value it looked up, or a transcript it opened — until you delete that conversation.

We respond to these requests within 30 days and we do not charge for them. We will never require you to give up any other right in order to exercise these.

Retention

We keep your data for as long as you have an account. When your account is deleted, your records and conversations are removed from our live systems promptly and from encrypted backups within 30 days, except where the law requires us to keep specific records longer.

If something goes wrong

If your health information is ever accessed or disclosed without authorization, we will notify you, and the authorities we are required to notify, without unreasonable delay and within the time limits the law sets. We will tell you what happened, what information was involved, and what we are doing about it.

Children

Superlife is for adults. You must be 18 or older to hold an account, and we do not knowingly collect information directly from children. An adult may hold records belonging to a child in their care, as described above.

Changes

If we make material changes to this policy, we will notify you in the app before they take effect.

Contact

Questions or requests: support@getsuperlife.com.