Skip to main content
Language

Read Evidalife in your tongue.

Eight locales at launch. Voice, units and references adapt — not just the words.

Europe

Americas · Asia

Privacy Policy

Last updated: August 2026

This notice informs you, in accordance with Art. 13 GDPR (DSGVO), which personal data we collect, for what purpose, on which legal basis, and how long we store it.

1. Controller

The controller within the meaning of the GDPR (DSGVO) is the entity named in the Legal Notice.

2. Which data we collect

Account data on registration: email address (required), optional country code (mandatory field when registering from the EU/EEA/CH), UI language (NEXT_LOCALE).

Profile data: self-reported information such as age group and biological sex (for biomarker-specific reference ranges). Health data such as blood values, illnesses, or medications only after separate consent (Art. 9 (2) lit. a DSGVO).

Usage data: coach chat histories, habit completions, lesson progress; when using the voice feature, audio transcripts (Art. 9 DSGVO, separate consent).

Payment data: on our side we store only the Stripe customer ID. Credit-card and bank-account details are held by Stripe.

Public league: if — and only if — you switch the public league on in your profile, we publish the following on evidalife.com/league, visible to anyone on the internet, search engines included: your display name and avatar, your country, your sex, your age, the month your blood panel was measured, and four figures derived from that blood work — your Age Quotient, how many years younger it makes you, your Longevity Score and your streak. Your individual blood values and your lab reports are never published.

3. Legal bases

Performance of contract under Art. 6 (1) lit. b DSGVO for the core operation of the service (account, coach, tracking, billing).

Consent under Art. 6 (1) lit. a DSGVO for optional processing (voice feature, research / product-improvement data, marketing emails).

Explicit consent under Art. 9 (2) lit. a DSGVO for the processing of health data (biomarkers, symptoms, illnesses).

Explicit consent under Art. 9 (2) lit. a DSGVO for the public league. The four published figures are derived from your blood work and are therefore health data. The switch in your profile is the consent; it is off by default, and you can switch it off again at any time with effect for the future (Art. 7 (3) DSGVO). Your row then disappears immediately, and our caches are cleared within 24 hours. Honest caveat: copies or screenshots other people made while you were listed are beyond our reach. We record when a consent was given and when it was withdrawn, so that we can prove it.

4. Recipients / processors

We use the following processors. For every transfer to a third country an adequacy decision or a Standard Contractual Clauses agreement (SCC 2021/914) is in place.

  • Stripe Payments Europe, Ltd. — Ireland (EU). Payment processing.
  • Resend — Ireland (EU). Transactional emails (confirmation, withdrawal, password reset).
  • Supabase — eu-central-2 (Zurich, Switzerland). Database, authentication, and storage.
  • Amazon Web Services (AWS) — eu-central-2 (Zurich, Switzerland). Runs, via Amazon Bedrock, the AI models that read uploaded lab reports and that power search (embedding and reranking). Processing takes place in Switzerland.
  • Anthropic PBC — provider of the Claude models used in two places: reading the values out of uploaded lab reports, and the safety check that runs before every coach answer. Both run through AWS Bedrock in eu-central-2 (Zurich, Switzerland); neither inference leaves Switzerland. The safety check receives your most recent message to the coach and the two preceding turns of that conversation — and nothing else, no name, no account identifier, no lab values, no health profile.
  • Cohere — provider of the embedding and reranking models used for research search. Inference runs through AWS Bedrock in eu-central-2 (Zurich).
  • Google Cloud / Vertex AI — the coach's written answers and the classifier that routes them run in Vertex AI's eu multi-region (European Union); the real-time voice coach and speech-to-text run in europe-west4 (Netherlands, EU). Spoken narration of articles and lessons — our own editorial text, never your data — is produced on Google's global endpoint, which is not restricted to the EU; no member data is involved in that step.
  • LiveKit — USA. Real-time voice session transport (only when the voice feature is enabled). SCC note: transfer based on EU SCC 2021/914.
  • OpenAI — USA. Speech synthesis for the narration of articles and lessons (editorial content, no health data). SCC note as above.
  • Vercel — USA. Hosting. SCC note as above.
  • Sentry — application error and performance monitoring. SCC note as above.

5. Storage period

Account data is deleted within 30 days of a confirmed deletion request, provided that no statutory retention obligations prevent this.

Uploaded lab PDFs are deleted 12 months after upload, and 90 days after a report is archived — immediately if you delete your account or withdraw your consent to automated extraction. The values read out of the PDF remain part of your health profile until you delete them or your account. Statutory retention of the original findings rests with the laboratory that performed the analysis, not with Evidalife.

Billing-relevant data (invoices, payment receipts) are retained for 10 years — the accounting-records retention duty of a Swiss stock corporation under Art. 958f CO.

Audit logs (security-relevant events) are stored for 12 months.

6. Your rights

Under the GDPR (DSGVO) you have the right at any time to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and to withdraw any consent previously granted with effect for the future (Art. 7 (3)).

Please send requests to the contact address given in the Legal Notice.

7. Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority — the one for your habitual residence, your place of work, or the place of the alleged infringement. For Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC / EDÖB); in Germany it is the data-protection authority of the federal state in which you reside.

8. Cookies and similar technologies

We use the following cookies:

  • NEXT_LOCALE — stores the interface language you chose (strictly necessary, §25 (2) TDDDG). Lifetime: 12 months.
  • sb-<project>-auth-token — your login session with Supabase (strictly necessary). The actual name carries our Supabase project reference, and the value is split across numbered .0 / .1 cookies when one cookie cannot hold it. A -code-verifier cookie of the same family exists only while a sign-in is in progress.

We do not use any third-party marketing or tracking cookies.

9. Data security

Data is encrypted in transit using TLS 1.2+ and stored at rest in Switzerland, under an EU adequacy decision (Supabase eu-central-2, Zurich, Switzerland). Access to production data is limited to the personnel required for that purpose and is logged.

10. Data protection officer

We are not currently under a statutory obligation to appoint a data protection officer. Please direct data-protection inquiries to privacy@evidalife.com.