frequently asked questions
Last updated: 16 August 2026
about lifelong
What is Lifelong?
Lifelong is a family health app. It keeps one family’s health in one place — medications, symptoms, appointments, records, lab results, and the daily signals from the watches and phones you already use — and lets you share exactly the parts you choose with the people you choose. It reads the documents you upload, builds them into a timeline, and answers questions about them.
Why does Lifelong exist?
For most of human history, health was held by the people around you — the ones who noticed when you weren’t yourself and remembered what you’d recovered from. Modern health became a solitary experience. Families still carry the context, the history and the worry, and have been given almost no tools to share it. More on that in our mission.
Is Lifelong medical care?
No. Lifelong is a health information tool, not a medical device and not a substitute for a clinician. It does not diagnose, treat or prescribe, and nothing in it is a medical opinion.
It is also not a monitoring service. Nobody at Lifelong is watching your family’s data, and the app will not summon help. An alert is a prompt to look at something — it is not a clinical finding and its absence is not reassurance. In an emergency, call emergency services. The full detail is in the Medical Disclaimer.
getting started
What do I need to use Lifelong?
The Lifelong app on your phone, and an account. Setup asks for your name, email, date of birth, gender and height. Ethnicity, a profile photo, your health goals and a note about your household are all optional and you can skip them.
Can I bring in records I already have?
Yes. Upload documents — discharge summaries, lab reports, prescriptions, letters — including photographs and scans. Lifelong reads them with optical character recognition and AI, pulls out conditions, medications, lab values, dates and providers, and places them on a timeline. Suggestions are proposed for you to confirm rather than written in silently.
Can Lifelong request my records from my doctors for me?
Not yet. not yet available
Pulling records directly from providers and health information exchanges — under the 21st Century Cures Act patient access rules and TEFCA Individual Access Services — is something we intend to build, and our Family Sharing Terms already set the rules for it. Today, records get into Lifelong because you put them there. When retrieval ships we will ask for your specific, scoped, revocable authorisation at the moment you use it.
Can I connect my watch or fitness tracker?
Yes, and only if you ask us to. Lifelong reads from Apple Health, Android Health Connect and Samsung Health after you grant permission, and only the categories you approve. You can revoke that permission at any time, in Lifelong or in your phone’s own settings.
family sharing
What can my family actually see?
Only what you have chosen to share with them. When you join a family, the app asks you to choose — per category — what your family can see:
- Daily signals: sleep, activity, heart
- Health records and documents
- Medications, conditions, symptoms and appointments
- Journal entries and notes
Nothing of yours is visible to anyone until you have made that choice and confirmed it. We recommend sharing everything, because a family that can see the whole picture is the point of the product — but it is a recommendation, not a default that happens to you. You can narrow, widen or revoke at any time, per category and per person, and revocation takes effect immediately.
Does whoever created the family get to see everything?
No. The family owner can manage the family’s name and settings, invite and remove members, and end the family. The owner cannot see another member’s health information unless that member has shared it with them. Owning the family is an administrative role, not a privileged view. The same is true of whoever is paying, and of whoever uploaded a document: the person the data is about controls it.
Can I be in more than one family?
Yes — people have parents and in-laws. Your sharing choices are made separately for each family you belong to.
What happens if I leave a family, or someone removes me?
Access ends immediately in both directions: yours to their shared information, and theirs to yours. Content you contributed to a shared family space may remain with the family.
Can I keep records for someone who doesn't use the app?
Yes — a parent, a child, someone you care for. You manage a profile for them from your own account, and in doing so you confirm you are legally authorised to hold and make decisions about that person’s health information. That representation matters: if you do not have that authority, you should not be filing their records. The rules, and the channel for someone to have a profile about them removed, are in the Family Sharing Terms.
alo and ai
What is Alo?
Alo is Lifelong’s assistant. It can read your health overview, recent records, conditions, medications, journal entries, alerts and plans; look things up on the web; remember context about you between conversations; and draft entries for your health record. You can talk to it in the app or from Messages.
Can Alo see things I can't?
No. Alo cannot see what you cannot see. Your family’s sharing permissions govern the assistant exactly as they govern the app.
Can Alo change my health record on its own?
No. Every change Alo proposes is a draft you confirm. The assistant proposes, you decide, and your confirmation is what writes. Everything it does — every message, every tool use, every proposed change — is recorded in an audit trail, so it is always possible to reconstruct what it did and why. You can see and delete your conversations.
What happens if I add Alo to a group chat?
Messages in that conversation are sent to Lifelong, processed and stored — including messages from people who do not use Lifelong. Please tell the people in the chat. Alo will only disclose health information to a participant who is a verified Lifelong user with permission to see it, but the conversation itself is processed either way. And because Alo has to read a message to answer it, message content is not end-to-end encrypted once it reaches us.
What do you send to AI companies?
To produce a result we send the relevant content to a model provider — the text of a document, a set of health values, your question and the context needed to answer it. What we do to keep that tight:
- We send only what the task requires, not your whole record
- Some features run without names in the prompt — visit summaries, actions generated from a visit recording, home insights, and alert explanations. On those paths names are replaced before the prompt is sent and reattached afterwards on our own systems
- Free-text labels you write for recordings are never sent to a model
- Where our own infrastructure can process a document instead, we do that first
Name minimisation is feature-specific, not blanket, so we would rather say where it stops. A conversation with Alo goes out as it is, including your name and account identifier; a document you upload can be sent as the file itself, including page images of a scan; visit audio is sent to a speech-recognition provider as recorded. What protects that content is not anonymity — it is encryption in transit, contracts limiting each provider to processing on our instructions, and a prohibition on training. Full detail in the AI and Alo Disclosure.
Do you train AI models on my health data?
Not on your identifiable health data — not our models, and not a vendor’s. We improve Lifelong using de-identified and aggregated data only, de-identified to a standard equivalent to HIPAA Safe Harbor, with re-identification contractually prohibited for anyone who receives it. We do not sell de-identified health data either. If we publish research or benchmarks, they will describe populations, never people.
How wrong can the AI be?
Wrong enough that you should check. Models misread handwriting and poor scans, transpose numbers and units, attribute a result to the wrong date or the wrong person, miss something that was on the page, and state all of it fluently. Lifelong shows you where information came from so you can go back to the source, and everything AI produces is informational — it never determines your access to healthcare, insurance, employment or credit, and it is never a diagnosis.
recording appointments
Do I need permission to record my appointment?
Usually, yes — and getting it is your responsibility, not ours. In many places the law requires the permission of everyone being recorded. So ask first: “Do you mind if I record this so I can remember it properly?” Most clinicians say yes. If anyone says no, don’t record. Before your first recording the app shows you the Recording Consent Notice and asks you to acknowledge it.
What happens to the audio?
The audio is uploaded and stored securely, then sent to a specialist transcription provider that returns a transcript with speakers separated. We then immediately instruct that provider to delete their copy and record that the deletion succeeded; if it fails, an automated process retries until it doesn’t.
Once the transcript is confirmed, the original audio is deleted. If transcription fails we keep the audio so you don’t lose the appointment, and you can delete it yourself. The transcript, an AI summary and suggested follow-ups are saved to the record of the person the appointment is about, visible to whoever that person has chosen to share with.
Does recording track my location?
When you press record, Lifelong takes a single location reading so the record can show which clinic you were at — the coordinates, place name and address of that one reading. There is no background tracking. Declining the location permission is a completely normal way to use the feature, and everything else still works.
How long can a recording be?
Recordings are capped at 60 minutes. Recordings under a minute don’t count against your allowance, because a mis-tap should not cost you anything.
children and teenagers
Can I keep my child's health records in Lifelong?
Yes, from birth. A child can be the subject of health records in Lifelong at any age on a profile a parent or legal guardian manages from their own account — families coordinate children’s care, and that is a real use case. The child does not have a login. The information is collected from you, not from the child: you type it, upload it or record it.
Can I connect my child's watch or phone to their profile?
No, and this is deliberate. A managed child profile holds information you provide about your child — not information collected from your child’s own device. So no Apple Health, Health Connect, Samsung Health or wearable account belonging to the child can be attached to a profile you manage. Those connections exist only on a person’s own account.
How old do you have to be to have your own account?
Thirteen. Nobody under 13 may hold a Lifelong account. If you are under 18 you need the verifiable permission of a parent or legal guardian, which we record before the account becomes usable; that parent or guardian agrees to the Terms of Service alongside you and is bound by them, including the payment terms. Either of you can end the account.
If my teenager has an account, do I see everything in it?
No. A teenager holds their own account with their own privacy settings, and sharing with the family starts off for every category — a teen chooses what to share, exactly as an adult does. Some categories stay private from a parent unless the teenager decides otherwise. That is not a stylistic choice: in every US state, minors can consent to some care on their own, and for that care a parent would never have had access in the first place.
Teen accounts with their own login are still being built. not yet available Until they ship, under-18s appear in Lifelong as managed profiles as described above.
privacy and security
Do you sell my health data?
No. Not to advertisers, not to data brokers, not to insurers, not to anyone. We do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done either.
We also do not disclose your information to insurers, employers, credit agencies, data brokers or advertising platforms. Full stop. And if any of that ever stops being true, we will tell you before it changes, not after.
How is my data protected?
- Encryption in transit using TLS 1.2 or higher for every connection
- Encryption at rest using AES-256 for stored data and backups
- Authentication operated by a specialist provider; we never store your password in a form we can read
- Access controls limiting which of our staff can reach production data, on a need-to-know basis, with access logged
- Isolated environments, so testing and development never touch real user data
- Audit logging of changes to health records and of assistant activity
- Vendor requirements, including contractual security obligations and, where a vendor offers one, a Business Associate Agreement
Is Lifelong end-to-end encrypted?
No, and we would rather say so than imply otherwise. We can read your data on our servers, because reading it is how the product works — extracting structure from a lab report, generating an insight, answering a question. Any service that does those things can see your data. What we can control is how few people and systems can reach it, that access is logged, and that it is never used for anything outside the Privacy Policy.
Is Lifelong HIPAA compliant?
HIPAA governs healthcare providers, health plans and their business associates. Lifelong is none of those today — we hold your information because you gave it to us, not because a hospital did, so HIPAA does not apply to us the way people often assume. What does apply: Washington’s My Health My Data Act, Nevada SB 370 and Connecticut health-data law (see the Consumer Health Data Privacy Policy), the FTC Health Breach Notification Rule, the state privacy statutes, GDPR and UK GDPR, and the Australian Privacy Act. If Lifelong ever becomes a business associate — for example by integrating directly with a health system — we will sign a Business Associate Agreement and update the policy before that data starts flowing.
How long do you keep my information?
Health records are the point of Lifelong — a timeline that only goes back six months is not a timeline — so records, care information, transcripts, summaries and assistant conversations are kept until you delete them or close your account. Visit audio is deleted automatically once its transcript is confirmed. Usage and analytics data is kept up to 12 months, crash diagnostics up to 90 days, and server logs up to 30 days.
What rights do I have over my data?
The same rights, wherever you live — we did not want a policy where your rights depend on your postcode. You can know what we hold and why, get a copy of it, correct it, delete it and close your account, withdraw consent, object to or restrict processing, and appeal if we say no. We will never give you a worse service or price for asking.
Deletion from our live systems is completed within 45 days of a verified request. Email privacy@trylifelong.com or use the privacy controls in the app’s settings. The full process, including the regulators you can escalate to, is in the Privacy Policy.
Can I download everything I've put into Lifelong?
On request, yes — email privacy@trylifelong.com and we will provide your data in a structured, machine-readable format. A self-service export in the app is being built. not yet available
What if there's a breach?
No system is perfectly secure. If a breach affects your health information we will notify you and the appropriate regulators as required by the FTC Health Breach Notification Rule, GDPR and applicable state laws.
where we operate
Where is my data stored?
Lifelong is operated from the United States, and your personal and health information is stored and processed there, and in the other locations where our service providers operate. If you are outside the United States — in the EEA, the UK, Australia, Canada or New Zealand — your information is transferred to the United States, which may not provide the same legal protection as your home country. For the EEA and the UK those transfers rely on the European Commission’s Standard Contractual Clauses and the UK Addendum; ask privacy@trylifelong.com for a copy.
I'm in Australia. Does anything differ?
The rights are the same; the law describing them is different, so we wrote it down separately. The Australian Privacy Addendum covers how the Privacy Act 1988 and the Australian Privacy Principles apply to us, where your data physically sits, and how to complain to the Office of the Australian Information Commissioner. Australian consumers are also excluded from the arbitration clause in the Terms, as are consumers in the EEA and the UK.
Are some features restricted to one country?
Some may be. Connections to government-operated record systems can be legally required to keep certain data only in a particular country. Where that applies we will say so in the feature itself, and that data will not be transferred elsewhere — and it is excluded from our de-identified data uses.
the company, and how we make money
How does Lifelong make money?
Subscriptions. That is the whole business model, deliberately. Lifelong Premium covers your household, starts with a free trial, and is sold through the Apple App Store — current pricing for your territory is shown in the app and on your App Store listing before you are charged. Because you pay us, we do not have to make money from your health data, and we do not.
How do I cancel?
Because Apple handles the purchase, Apple handles the cancellation: Settings → your name → Subscriptions on your device, at least 24 hours before renewal. We cannot cancel your subscription for you, and deleting your account does not cancel it. Refunds are Apple’s to give, under their policies.
What happens to my data if Lifelong is acquired or shuts down?
If Lifelong is acquired or merges, your information may transfer as part of that transaction — and the acquirer would be bound by this Privacy Policy. We will notify you before your information becomes subject to a different one, with the chance to delete your account first. Your content stays yours throughout; you can take a copy and leave at any time.
Something here is unclear. Who do I tell?
privacy@trylifelong.com. If one of these answers or any of our policies is unclear, that is a defect and we would like to hear about it.
Lifelong is operated by Lifelong Company, a Delaware corporation, 2810 North Church Street, Wilmington, DE 19802, United States. Reach us at privacy@trylifelong.com.