Longenia

Privacy Policy

Important notice: Longenia is strictly informational and educational. Nothing here is a diagnosis, prescription, or medical treatment, and nothing replaces a consultation with a physician or other qualified health professional.

1. What this policy covers

This Privacy Policy explains how Longenia collects, uses, stores, shares, protects and deletes personal data while you use the platform. It's part of Longenia's legal framework and complements the Terms of Service, and was designed following the Privacy by Design principle.

2. Data controller

Longenia is operated by LONGENIA DESENVOLVIMENTO DE SOFTWARE CUSTOMIZAVEL LTDA, registered under Brazilian company ID (CNPJ) no. 68.814.442/0001-05, which acts as the controller of the personal data processed on the platform. Registered address: Rua Visconde do Rio Branco, 1488, Conj. 909, Andar 09, Cond. Universe Life Square, Bloco Com. — Curitiba/PR, Brazil — ZIP 80.420-210.

Data protection officer (DPO): Sérgio Milani. Privacy and data-subject-rights contact: sergio.milani@longenia.app. Other enquiries: suporte@longenia.com.br

3. What we collect

  • Registration data: name, email, encrypted password, country, language, date of birth, self-reported sex, optional profile photo.
  • Technical data: IP address, access timestamps, device identifiers, browser/OS, authentication logs, app version, security logs, cookies.
  • Health data you voluntarily upload: lab results and biomarkers, imaging reports, clinical history, medications, supplements, allergies, prior diagnoses, vital signs, blood pressure, glucose, weight, body composition, vaccination — all treated as sensitive personal data.
  • Wearable data (with your authorization): heart rate, HRV, VO2max, steps, distance, sleep, temperature, stress, calories, SpO2, recovery, and other manufacturer-provided metrics.
  • Genetic data (fully optional): raw DNA files, genetic variants (SNPs — small single-point variations in your DNA), nutrigenomics info, statistical predispositions, and metadata about the files you upload.
  • Data the platform generates: your longitudinal history, charts, trends, indicators, Health Score, metabolic age, reports, AI-generated summaries and informational alerts — also protected by this Policy.

When you connect the mobile app to Apple Health (HealthKit) or Google Health Connect, Longenia accesses that data read-only, under the authorization you grant in the operating system itself, and imports only the following types: workouts and physical activities, steps, resting heart rate, heart rate variability (HRV) and sleep. This data is used solely to build your health history inside the app; it is never used for advertising and is never shared with advertising or third-party analytics platforms. Longenia does not write any data back to Apple Health or Google Health Connect.

As a data-minimization measure, results from sexually transmitted infection (STI) tests — including HIV, syphilis, hepatitis B/C, HPV, gonorrhea, chlamydia and genital herpes — are automatically discarded while we read uploaded files and are never extracted, displayed, or stored as a biomarker.

4. Why we process it and on what legal basis

We use your data for authentication, providing the service, organizing your health history, generating charts and indicators, device integrations, running the AI features, improving the platform, fraud prevention, security, support, legal compliance, and defending legal claims — never for a purpose incompatible with what's disclosed here.

Personal data is processed under contract performance, legal obligation, legitimate interest (where allowed), or consent. Sensitive data is processed mainly on the basis of your specific consent (LGPD art. 11 / GDPR art. 9).

5. Automated processing and AI

Longenia uses automated processing to generate indicators, trends, charts, summaries and informational suggestions, but does not make automated decisions producing legal or similarly significant effects on you, as required by LGPD and GDPR. AI outputs can contain errors, omissions or inadequate interpretations — none of them should be treated as a medical diagnosis, and result quality depends directly on the data you provide.

6. Sharing and sub-processors

Personal data is only shared with third parties when necessary to run the service, for integrations you authorize, hosting, AI processing, cloud storage, authentication, sending communications, payment processing, fraud prevention, legal compliance, or a court/authority order.

Longenia currently uses the following sub-processors, each bound by confidentiality and data-protection obligations appropriate to the data involved:

  • Google Cloud / Firebase (Firestore, Cloud Storage, Authentication, Cloud Run) — hosting, database, file storage and authentication;
  • Anthropic — AI processing (OCR/Claude Vision exam reading and educational analyses/summaries);
  • Google (Gemini) — OCR verification layer for exam reading, when applicable;
  • Resend — transactional email;
  • Expo — mobile app push notifications;
  • Mercado Pago — payment and subscription processing.

This list may be updated as Longenia adds, replaces or discontinues providers; the current version stays available on this page.

When Longenia uses advertising/measurement tools (e.g., Meta, Google, TikTok), only technical metrics — app install, app open, subscription status — are shared with those providers, with consent; health data, exam results, biomarkers, genetic data or any other sensitive data is never shared with advertising platforms.

Longenia does not sell personal data to third parties. In addition, health data, wearable data (including data obtained through Apple Health / HealthKit and Google Health Connect), genetic data, biomarkers, and any data derived from them (Health Score, metabolic age, indices, trends and indicators) are never sold, licensed, transferred or commercialized, nor shared with third parties for advertising, marketing or data-mining purposes, in any form — identified, aggregated or anonymized. This data is shared only with the sub-processors strictly required to operate the service, listed above, or with your specific separate consent.

Longenia may use aggregated and/or anonymized data that is not derived from health data — for example, platform usage metrics — for statistical and product-improvement purposes, always in a way that does not allow re-identification of the data subject through reasonably available means.

7. Your rights

Consistent with LGPD, GDPR (where applicable), and other data-protection laws, you may request: confirmation and access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or non-compliant data; portability, where technically feasible; deletion of consent-based data (subject to legal retention requirements); information about who your data was shared with; withdrawal of consent and objection to processing where the law allows; and review of automated decisions where applicable.

Send requests to suporte@longenia.com.br. We may ask for extra information to confirm your identity before acting on a request.

8. Retention, deletion and portability

We keep personal data only as long as needed to provide the service, fulfil the stated purposes, meet legal/regulatory obligations, prevent fraud, and keep the platform secure. You can request account deletion at any time; once confirmed, personal data is deleted or anonymized within 30 days, except where the law requires longer retention (e.g., to defend a legal claim or investigate a security incident), in which case deletion happens once that legal period ends. We aim to offer data export in a structured, interoperable format whenever technically possible.

9. Security, incidents and international transfers

We use technical and administrative safeguards consistent with current best practice — encryption in transit and at rest, strong authentication, per-user data isolation, least-privilege access control, audit logs, monitoring, backups and vulnerability testing. No system is perfectly secure, and we can't guarantee zero risk of incidents; if a security incident affects personal data, we'll act proportionally to its severity, including notifying Brazil's data protection authority (ANPD) and affected users where required by law.

Some data may be processed or stored on servers outside Brazil, wherever our providers operate; when that happens, we aim to apply appropriate safeguards consistent with LGPD and GDPR.

10. Cookies, minors, and updates

We use cookies and similar technologies for authentication, session handling, security, fraud prevention, performance analysis and UX improvements — detailed in the Cookie Policy. Longenia is not intended for independent use by minors; where local law allows minors to use it, processing their data depends on their legal guardians' involvement or authorization.

This Policy may be updated to reflect legal, technological or operational changes; for materially relevant changes, we may request renewed acceptance or notify you in advance. The official language of this Policy is Portuguese (Brazil) — this English version is a courtesy translation, and in case of conflict the Portuguese version prevails. Read it at /pt/legal/privacy.

Version 1.5

Last updated: 2026-08-31

Questions about this document? Reach us at suporte@longenia.com.br.