← Back to home

ai and alo disclosure

Effective: 16 August 2026Last updated: 16 August 2026

This disclosure forms part of the Terms of Service and the Privacy Policy.

why we wrote this

Lifelong could not exist without AI. Turning a scanned discharge summary into a structured timeline, noticing that a lab value has drifted, answering "what did the cardiologist say about Dad’s medication in March" — none of that was buildable a few years ago.

But we are asking you to let language models read your family’s medical records. You should know exactly what that means, who sees what, and what the models get wrong. So this document is longer than it strictly needs to be.

1. where ai is used in lifelong

FeatureWhat the AI does
Record understandingReads documents you upload — including scans and photographs, using optical character recognition — and extracts conditions, medications, lab values, dates and providers
Health timelineOrganises extracted information into a longitudinal picture, linking related events and resolving that two documents refer to the same condition
Insights and alertsNotices changes and trends in health signals and explains them in plain language
Appointment preparationAssembles a brief from the family's real history before a visit
Visit transcriptionConverts recorded appointments to text, separating speakers
Visit summariesSummarises a transcript and suggests follow-ups
Member summariesProduces a short picture of how a family member is doing
Alo, the assistantAnswers questions, drafts entries, and helps coordinate, in the app and over iMessage
SuggestionsProposes entries and categorisations for you to confirm

2. alo

Alo is a conversational assistant with access to your family’s health information — the information you are permitted to see, and nothing else. Alo cannot see what you cannot see. Your family’s sharing permissions govern the assistant exactly as they govern the app.

Alo can: read your health overview, recent records, conditions, medications, journal entries, alerts and plans; look things up on the web; remember context about you between conversations; and draft entries for your health record.

Alo cannot: write to your health record on its own. Every change Alo proposes is a draft that you confirm. The assistant proposes; you decide; your confirmation is what writes.

Alo over iMessage. You can talk to Alo from Messages, which is the point — families coordinate where they already talk, not in a fifth app. To do that you verify your phone number or handle with a code.

Group chats. If you bring Alo into a group conversation, messages in that conversation are sent to Lifelong and processed and stored as described in the Privacy Policy — including messages from people who do not use Lifelong. Please tell the people in the chat. Alo will only disclose health information to a participant who is a verified Lifelong user with permission to see it, but the conversation itself is processed either way.

Message content is not encrypted end-to-end once it reaches us — it cannot be, because Alo has to read it to answer.

Everything Alo does is logged. Every message, tool use and proposed change is recorded in an audit trail, so it is always possible to reconstruct what the assistant did and why. You can see and delete your conversations.

3. what we send to ai providers, and what we don't

To generate a result, we send the relevant content to a model provider — the text of a document, a set of health values, your question and the context needed to answer it.

Things we do to keep this tight:

  • We send only what the task requires, not your whole record
  • Some features run without names in the prompt. Name minimisation is applied on specific paths — visit summaries, actions generated from a visit recording, home insights, and alert explanations. On those paths names are replaced before the prompt is sent and reattached afterwards on our own systems
  • Free-text labels you write for recordings are never sent to a model
  • We process on our own infrastructure where the task allows it, rather than sending content to a third-party model

Where content goes out identifiable, stated plainly. Name minimisation is a feature-specific measure, not a blanket one, and we would rather you knew where it stops:

  • Alo. A conversation with Alo is sent to the model provider as it is — your messages, the health context needed to answer, the assistant’s memory, and identifiers including your name, display name, account identifier and messaging handle. Alo cannot answer "what did the cardiologist say about Dad in March" without knowing who Dad is
  • Documents you upload. A document may be sent to a model as the file itself — the PDF or image, not just text extracted from it — and the optical character recognition step may send page images of a scan. Whatever is on the page goes with it
  • Visit audio. Recorded audio is sent to a speech-recognition provider as recorded, including every voice in the room. Audio you speak to Alo is sent to a speech provider the same way, and Alo’s spoken replies are sent to a voice provider to be read aloud

So what actually protects this content? Not anonymity. It is protected by encryption in transit, by written contracts that restrict each provider to processing on our instructions, by the prohibition on training in §4, and by sending as little as the task allows. We would rather say that accurately than imply a de-identification that does not happen.

4. our commitments about ai vendors

Retention at the vendor. Our model vendors are contractually required to process content and retain nothing: content goes in, a result comes back, and the vendor keeps no copy. Transcription works differently and we would rather say so. Visit audio is sent to a transcription provider, held only while the job runs, and deleted as soon as the transcript is returned — we issue the deletion, record that it succeeded, and retry automatically until it does. That is deletion on completion, verified, not a promise that the provider never stored the file at all.

No training. Our AI vendors are contractually prohibited from using anything we send them to train, fine-tune or improve their models. We use zero-data-retention API configurations where the vendor offers them.

No human review. Content sent for processing is not reviewed by vendor staff, except where we specifically authorise it to investigate a problem.

Processors only. Each AI vendor acts as our processor under written contract, may use the data only on our instructions, and may not use it for its own purposes.

Business Associate Agreements are in place where a vendor offers one.

AI processing is performed by contracted AI service providers — large language model, transcription, and voice providers. The current list of third parties that process your consumer health data is available on request to privacy@trylifelong.com.

5. training our own models

We do not train our own models on identifiable user health data.

We improve Lifelong — including training and evaluating our own models — using de-identified and aggregated data only. As described in Privacy Policy §9, that means de-identification to a standard equivalent to HIPAA Safe Harbor, a contractual prohibition on re-identification, and no attempt by us to re-identify.

There is no toggle for this because there is nothing to toggle: your identifiable health data is not training data, for us or for anyone else.

6. what ai gets wrong

We would rather tell you this ourselves than have you find out.

Language models produce confident, fluent, wrong answers. This is not a bug we expect to fix; it is a property of the technology. Specifically, in a health context, the failure modes we see are:

  • Misattribution — a lab value assigned to the wrong family member
  • Date errors — a result placed in the wrong year, which changes what a trend means
  • Dosage and unit errors — reading 5mg as 50mg, or mixing up mmol/L and mg/dL
  • Fabricated specifics — a plausible detail that is not in the source document
  • OCR failure — a scan or photograph read incorrectly, especially handwriting, faint fax copy, or tables
  • Transcription errors — medical terms, drug names and numbers misheard; a dropped "not" reversing the meaning
  • Missing context — an insight that would be different if the model knew something the record does not contain
  • Over-confidence — a definite-sounding statement where the honest answer is "unclear"

A silently wrong medication is a different class of error from a silently wrong search result. We know that, we build and test with it in mind, and we still cannot promise it will not happen.

What this means for you: verify anything that matters against the original document and with your clinician. Do not act on AI output about medication, dosage, interaction or urgency without professional confirmation. See the Medical Disclaimer.

7. what ai in lifelong will never do

  • Diagnose. Alo will not tell you what you have.
  • Prescribe or advise on treatment. It will not tell you to take, stop or change a medication.
  • Decide anything about you. No AI in Lifelong determines your access to any service, price, insurance, employment or credit, and none produces a legal or similarly significant effect. There is no automated decision-making of that kind in the product.
  • Act without you. Nothing is written to your health record, shared with anyone, or sent outside Lifelong without your explicit confirmation.
  • Handle an emergency. Alo is not monitored and will not summon help.

7a. alo and family members under 18

Lifelong accounts start at 13, with a parent or guardian’s permission (see Terms of Service §2). A younger person using an AI assistant about their own health is a situation that deserves more care than a paragraph, so:

Alo says what it is. Alo identifies itself as an AI assistant, not a person, and repeats that to a user under 18 rather than saying it once at the start and never again.

We say plainly that it may not suit everyone. Alo is a general health assistant built for adults and older teenagers. It may not be suitable for every young person, and we say so to the teenager and to the parent who approves the account.

Breaks in long conversations. In an extended session, Alo reminds a user under 18 to take a break, periodically, for as long as the conversation continues.

If something is serious, Alo points to real help. Alo will not produce content that encourages self-harm or suicide. Where a conversation suggests someone may be at risk, Alo stops being an assistant and surfaces crisis and emergency resources for where the person is — in the United States, 988, the Suicide and Crisis Lifeline; in Australia, Lifeline on 13 11 14 — alongside local emergency services. Alo is not monitored by a human and cannot summon help itself; calling is the thing that does.

Alo does not do therapy. This is a hard boundary, not a disclaimer. Alo does not provide therapy, counselling, psychotherapy or mental-health treatment, does not act as a therapist, and will not take the place of one. It can help a family organise information and find their way to care. It cannot treat anyone, of any age.

What a parent is told. Conversations between a teenager and Alo are private from a parent by default. If the safety behaviour above fires, a linked parent is notified that a safety resource was surfaced — they are told there is something to pay attention to, not what was said. We do not send parents transcripts, summaries or excerpts of a teenager’s conversations with Alo.

7b. which parts of lifelong are substantially automated

Set out here so it is findable in one place, and to match Privacy Policy §5.

The things Lifelong works out on its own are: health scores and baselines; trend detection and the alerts that follow from it; the structure built by reading your uploaded documents; and AI-generated summaries, briefs and suggestions, including everything Alo drafts.

Every one of them informs a person. None of them, by itself, makes a decision that has a legal or similarly significant effect on anyone — they do not determine access to care, insurance, employment, credit, or a price. A human is always in the loop for the action: nothing is written to a health record, shared with a family member, or sent outside Lifelong unless a person confirms it. That is §7’s "act without you" rule, stated as a transparency commitment rather than a promise about behaviour.

8. your choices

  • Delete conversations with Alo at any time
  • Disconnect iMessage at any time in Settings
  • Delete generated content — insights, summaries, extractions — like any other content
  • Control what Alo can see through your family sharing settings
  • Turn off AI features you don’t want, where the app offers a setting. Some features cannot function without AI, and we will say so rather than degrade them silently
  • Report a bad output in the app, or to privacy@trylifelong.com. We read these

9. human oversight

Our staff do not routinely read your conversations with Alo or your health records. Access is limited to circumstances where it is necessary — investigating a problem you reported, responding to a safety or security issue, or complying with law — and is restricted to authorised personnel, logged, and purpose-bound.

10. changes

AI moves quickly and this document will change with it. Material changes to how we use AI with your health information will be notified by email and in the app before they take effect.

Questions: privacy@trylifelong.com