Privacy Policy
Effective May 3, 2026 · Operator: Lipa Health (the “Service” / “we” / “Lipa”)
- Anonymous-first. You can use Lipa without an account, name, or email.
- No selling. We never sell your health data and never use it to train AI models.
- No tracking. No cross-site pixels, no fingerprinting, no ad networks.
- Encrypted. All data encrypted in transit and at rest. EU-based storage.
- Yours to delete. You can delete saved context, uploads, connected-device data, and your account. Backup copies age out within 30 days.
1. Who we are
Lipa Health (“Lipa”, “we”, “us”) operates lipa.health, my.lipa.health, and related services. This Privacy Policy describes how we collect, use, store, and protect personal information when you use the Service.
For questions or to exercise your rights, contact us at hello@lipa.health.
2. Information we collect
2.1 Anonymous use
By default, you can use Lipa without providing identifying information. We assign a randomly-generated session identifier so the conversation can persist on your device. We collect:
- The text of your conversation with Lipa
- Health information you voluntarily share (symptoms, medications, supplements, bloodwork values, family history, goals)
- Files you upload (e.g., bloodwork PDFs) — see “Bloodwork files” below
- Standard device + connection metadata: browser type, IP address, timestamps (used for security and abuse prevention only)
2.2 Identified use (after you provide email)
If you choose to save your conversation across devices, you provide an email address. We then collect:
- Your email address
- Account creation and last-login timestamps
2.3 Payment information
If you subscribe, our payment processor (Stripe, Inc.) collects your billing details. Lipa never sees or stores your full card number. We retain only a Stripe customer ID, subscription status, and tier.
2.4 Bloodwork files
When you upload a lab report, Lipa may save the file so it can re-open the reading, compare it against future panels, and let you delete the source later. We also keep extracted biomarker values, units, reference ranges, and an audit row recording that an upload occurred. If you delete the upload, Lipa removes the saved file, extracted values tied to that file, and active context derived from it.
2A. Wearable and connected-device data
If you connect a wearable or health-data source, Lipa reads a defined set of daily health signals so it can create a Wearable Health Review and, if you stay connected, watch patterns over time.
Depending on the provider, this may include:
- Sleep duration, sleep stages, sleep timing, and sleep regularity
- Resting heart rate, heart-rate variability, respiratory rate, and temperature trend
- Activity, steps, workouts, recovery, readiness, strain, and similar daily summaries
- Provider metadata needed to operate the connection, such as provider name, connection status, and sync timestamps
Lipa uses wearable data only to produce your wearable review, surface patterns, connect those patterns to other health context you have shared, and support proactive insights when you ask for them. Lipa does not sell wearable data, share it with advertisers, insurers, employers, or data brokers, or use it to train AI models.
You can disconnect a wearable and request deletion of wearable data at any time. Lipa removes the data from active use immediately and revokes the upstream connection through our wearable data processor. Upstream deletion and backup age-out complete within 30 days where technically possible.
3. How we use your information
We use the information described above to:
- Provide, operate, and improve the Service (interpreting your questions, generating responses, analyzing bloodwork)
- Maintain conversation context across your visits
- Process payments, manage subscriptions, and send transactional emails (magic links, receipts)
- Prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not use your conversation data, bloodwork, or any health information to train AI models. We do not sell, rent, or share your data with advertisers, data brokers, or any third party for marketing purposes.
4. Legal basis (GDPR / EU and UK users)
If you are in the EU, EEA, UK, or Switzerland, our legal basis for processing depends on the activity:
- Performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the Service you request, including health-related conversation and analysis
- Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for processing of health data (special category data), where you voluntarily provide health information by using the Service
- Legitimate interest (Art. 6(1)(f) GDPR) — for security, abuse prevention, and Service improvement that does not infringe on your rights
- Legal obligation (Art. 6(1)(c) GDPR) — for record-keeping, tax, and regulatory compliance
By using the Service and voluntarily sharing health information, you consent to our processing of that information for the purposes described in this Policy. You may withdraw consent at any time by deleting your data (see Section 9).
5. Service providers (sub-processors)
We share data only with the third-party providers necessary to operate the Service. We do not sell or share data with any other party.
| Provider | Purpose | Region |
|---|---|---|
| Anthropic, Inc. | AI model inference (Claude) | USA / EU (via AWS Bedrock) |
| Supabase, Inc. | Database, authentication | EU (Frankfurt) |
| Vercel, Inc. | Hosting, edge delivery | USA / Global edge |
| Stripe, Inc. | Payment processing | USA / EU |
| Resend / Postmark | Transactional email (magic links, receipts) | USA / EU |
| OpenAI | Text embedding for research retrieval | USA |
| Junction | Wearable and connected-health-data connection | USA / EU |
Each provider is bound by data processing agreements that restrict use of your data to the purposes described above. Conversation text is processed by Anthropic Claude (via AWS Bedrock for EU residents) on a zero-data-retention basis — prompts are not stored beyond the immediate processing window.
6. International data transfers
We host primary data in the European Union. Some sub-processors (notably Anthropic, Vercel, OpenAI, Stripe) operate in the United States. International transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by technical safeguards (encryption in transit and at rest, zero-data-retention for AI inference where supported).
7. Data retention
- Conversations, saved context, and bloodwork values — retained as long as your account exists, unless you delete specific items earlier. Deleted within 30 days of account deletion, including from automated backups.
- Uploaded files — retained when needed to power a saved reading, source-linked context, or future comparison. Deleted when you delete the upload, the related artifact where applicable, or your account.
- Wearable data — retained while the connection is active. If you disconnect, cancel, or request deletion, live summaries are removed from active use immediately and deleted according to the wearable deletion flow, with backup copies aging out within 30 days.
- Authentication logs and security events — up to 12 months for fraud prevention.
- Payment records — retained as required by tax law (typically 7 years), via Stripe and our accounting systems.
- Anonymous usage metrics (aggregate page views, feature adoption) — indefinitely, but contains no personally identifying information.
8. Security
We implement industry-standard security measures: encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls for our team, audit logging on administrative actions, and routine vulnerability monitoring on our infrastructure.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify affected users without undue delay (and within 72 hours, where required by GDPR Article 33).
9. Your rights
You have the following rights regarding your personal information:
- Access — request a copy of the data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — ask us to erase your data (the “right to be forgotten”)
- Restriction — ask us to limit how we use your data
- Portability — request your data in a portable, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — withdraw consent for processing of health data at any time
To exercise any of these rights, use the Delete everything button in My Lipa, or email hello@lipa.health. We respond within 30 days.
If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority (e.g., the CNIL in France, the Garante in Italy, the Datenschutzbehörde in Austria).
10. Children
Lipa is not intended for users under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it promptly.
11. Cookies and similar technologies
Lipa uses only the cookies and local storage strictly necessary to operate the Service: an authentication session cookie, your active conversation context, your saved facts, and your text-size preference. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile users.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, for material changes, notify users by email or in-app notice. Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes.
13. Contact
Questions, requests, or complaints about this Policy or our data practices: hello@lipa.health.
For our Terms of Service, see lipa.health/terms.
Effective May 3, 2026.