Privacy policy

How Longview handles personal health record data.

Longview Health is designed for source-preserving biomarker intelligence. This policy explains what data we collect, how we use it, and how we handle breach notification obligations for a vendor of personal health records.

Public-site privacy update: September 19, 2026. Health-data processing terms remain version September 8, 2026.

1. Scope

Longview Health provides a personal health record product for individuals who want to organize labs, documents, biomarkers, protocols, and related context. Longview is not a medical provider, health plan, or healthcare clearinghouse.

Longview is intended to operate as a vendor of personal health records for purposes of the FTC Health Breach Notification Rule, 16 CFR Part 318. This policy does not describe HIPAA-covered provider or health-plan practices.

2. Information we collect

  • Account information, including email address, authentication identifiers, subscription state, and support communications.
  • Health record information you provide or upload, including lab reports, biomarker values, vitals, body-composition records, performance metrics, medication or supplement context, symptoms, goals, notes, and document review decisions.
  • Optional wearable and Apple Health records you choose to connect or import. Apple Health access is read-only: you preview available measurements and explicitly select records to save to your Longview account. Selected records and available source application, native record identifiers, original intervals, and normalization history are stored on Longview's server. Apple Health access is not required to use the rest of the product.
  • Optional iOS notification information includes an APNs device token and a stable app-installation identifier when you grant permission. These support generic notifications with no health-record details in their payloads. Token deactivation is requested at sign-out; if it fails, minimal account-scoped retry metadata is retained. Tokens are deactivated when an account deletion request is accepted and removed during permanent product-data deletion.
  • Technical information needed to run the service, including device/browser metadata, IP-derived security signals, audit logs, error logs, and usage events.
  • Payment information handled by our payment processor. We do not intentionally store full payment card numbers on Longview systems.

3. How we use information

We use information to provide the product, authenticate users, normalize biomarker records, preserve source context, generate deterministic summaries, show trends, operate security controls, troubleshoot errors, provide support, and comply with legal obligations.

When Sentry is configured, crash and performance diagnostics support error investigation. Sensitive record content, credentials and private receipt bearers must not be included in diagnostics. Stripe-hosted payment entry handles card information; Longview does not receive or store full payment card details. Subscription state and required audit and billing records may be retained for tax, refund, fraud and legal obligations.

Longview does not sell personal health record data. We do not use uploaded health records for third-party advertising.

4. Sharing and processors

We share information with service providers only as needed to operate Longview, such as hosting, authentication, database, storage, payment, email, analytics, support, or optional model infrastructure. These providers are expected to process data for Longview's service purposes, not for their independent advertising purposes.

Optional online Deep Analysis synthesis requires your saved model route and consent. When enabled, structured evidence drawn from your personal records is sent to the selected model provider to write a narrative constrained by Longview's deterministic findings. The selected provider, configured model and result status are recorded. Turning synthesis off prevents new synthesis requests; it does not erase previously saved reports or information already processed by a provider.

You may configure a supported personal model endpoint and credentials. A hosted endpoint processes requests on that provider's infrastructure under its own data policies. An endpoint described as local must be reachable from the Longview server; it does not automatically run on your phone or laptop. Provider credentials are encrypted when saved and are excluded from your health-data export. Assistant requests also send the context needed to answer to the configured route. Review your provider's retention settings before enabling a route.

We may disclose information if required by law, to protect rights and security, or as part of a business transaction where privacy obligations continue to apply.

Cookies and public-site analytics

Essential browser storage supports sign-in, security, and your saved preferences. The public website stores your cookie preference on this browser for up to 180 days. Rejecting optional analytics does not prevent use of Longview or affect your separate health-data processing choice.

When enabled and only after you accept, Longview counts public-page visits and selected sign-up or pricing clicks in first-party daily totals. These events contain only an approved public page name and event type. They do not contain an account or visitor identifier, health data, search text, query parameters, referrer, IP address, or device fingerprint. The collector does not set an analytics cookie or send these events to a third-party analytics provider. Hosting and security systems may separately process normal network-request information.

Optional analytics does not run inside the app, sign-in journey, or private receipt pages. We respect Global Privacy Control and Do Not Track browser signals by keeping optional analytics off. You can reopen Cookie preferences in the public-site footer and reject optional analytics at any time. This stops future events from this browser; already combined anonymous totals cannot be separated by person. Totals older than 90 days are removed when the collector next records an event. Cookie preferences are specific to each browser and are not synced to your account.

5. Security and retention

Longview uses technical and organizational safeguards appropriate for a production web application, including authenticated access, database isolation controls, transport security, least-privilege runtime credentials, and monitoring. No system can be guaranteed perfectly secure.

We retain information while your account is active or as needed to provide the service, comply with law, resolve disputes, enforce agreements, maintain auditability, and preserve data integrity.

6. Your choices

Before opening health-record features, you separately accept the Terms and choose whether Longview may collect, store and analyze the health information you provide for record organization, comparisons, estimates and review suggestions. We record the policy versions, your choice and its date. These choices do not subscribe you to marketing. Optional online model synthesis retains its separate consent controls.

You can withdraw health-data processing consent in Settings. Withdrawal blocks newly started health processing and health notifications, turns off optional online synthesis, and revokes existing record-sharing grants. Accepting health processing again does not restore those grants. Requests already in progress may finish; information already sent to a provider cannot be recalled by withdrawing consent. Existing records remain stored under this retention policy. You can still export records, request deletion, manage billing or sign out without accepting health processing again. Withdrawal does not itself cancel a subscription or delete records. Minimal consent-decision history may be retained with required billing and security records for accountability and legal obligations.

You can export available structured records and request account deletion in Settings. Deletion has a 30-day grace period and can be cancelled before its deadline. Device notifications are deactivated when the request is accepted. The cleanup worker cancels the subscription, removes stored reports and product health records, and deletes the sign-in identity after the deadline. A request or deadline alone is not confirmation that cleanup has completed; the private receipt shows the confirmed lifecycle status.

Save your private deletion-status link before signing out. It remains usable after sign-in deletion and exposes only request, schedule, purge and completion dates. Anyone who possesses the link can view those dates. Longview stores a hash of its random bearer token with a minimal account tombstone; raw receipt tokens are not stored on the server. A replacement link invalidates the old one. The tombstone, required subscription history and security audit metadata may be retained to prevent stale requests recreating deleted accounts, confirm completion, resolve disputes and meet legal obligations. Retention requirements and backup handling may prevent immediate removal of all legally retained or backup records.

If you used Sign in with Apple, removal of your Longview sign-in identity does not automatically revoke Apple's authorization. Follow Apple's instructions to stop using Sign in with Apple for Longview. Contact us for access, correction, export or deletion assistance.

You control what health documents and biomarkers you upload. You should not upload another person's health information unless you have authority to do so.

7. Health breach notices

If Longview discovers a breach of security involving unsecured personal health record identifiable health information, we will evaluate notice obligations under the FTC Health Breach Notification Rule and applicable state laws.

Where notice is required, we will provide notice using available contact information and include the information required by law.

8. Contact

Questions or privacy requests can be sent to hello@longviewhealth.org.

Website: longviewhealth.org