How Longview handles personal health record data.
Longview Health is designed for source-preserving biomarker intelligence. This policy explains what data we collect, how we use it, and how we handle breach notification obligations for a vendor of personal health records.
1. Scope
Longview Health provides a personal health record product for individuals who want to organize labs, documents, biomarkers, protocols, and related context. Longview is not a medical provider, health plan, or healthcare clearinghouse.
Longview is intended to operate as a vendor of personal health records for purposes of the FTC Health Breach Notification Rule, 16 CFR Part 318. This policy does not describe HIPAA-covered provider or health-plan practices.
2. Information we collect
- Account information, including email address, authentication identifiers, subscription state, and support communications.
- Health record information you provide or upload, including lab reports, biomarker values, vitals, body-composition records, performance metrics, medication or supplement context, symptoms, goals, notes, and document review decisions.
- Optional wearable and Apple Health records you choose to connect or import. Apple Health access is read-only: you preview available measurements and explicitly select records to save to your Longview account. Selected records and available source application, native record identifiers, original intervals, and normalization history are stored on Longview's server. Apple Health access is not required to use the rest of the product.
- Optional iOS notification information includes an APNs device token and a stable app-installation identifier when you grant permission. These support generic notifications with no health-record details in their payloads. Token deactivation is requested at sign-out; if it fails, minimal account-scoped retry metadata is retained. Tokens are deactivated when an account deletion request is accepted and removed during permanent product-data deletion.
- Technical information needed to run the service, including device/browser metadata, IP-derived security signals, audit logs, error logs, and usage events.
- Payment information handled by our payment processor. We do not intentionally store full payment card numbers on Longview systems.
3. How we use information
We use information to provide the product, authenticate users, normalize biomarker records, preserve source context, generate deterministic summaries, show trends, operate security controls, troubleshoot errors, provide support, and comply with legal obligations.
When Sentry is configured, crash and performance diagnostics support error investigation. Sensitive record content, credentials and private receipt bearers must not be included in diagnostics. Stripe-hosted payment entry handles card information; Longview does not receive or store full payment card details. Subscription state and required audit and billing records may be retained for tax, refund, fraud and legal obligations.
Longview does not sell personal health record data. We do not use uploaded health records for third-party advertising.
5. Security and retention
Longview uses technical and organizational safeguards appropriate for a production web application, including authenticated access, database isolation controls, transport security, least-privilege runtime credentials, and monitoring. No system can be guaranteed perfectly secure.
We retain information while your account is active or as needed to provide the service, comply with law, resolve disputes, enforce agreements, maintain auditability, and preserve data integrity.
6. Your choices
Before opening health-record features, you separately accept the Terms and choose whether Longview may collect, store and analyze the health information you provide for record organization, comparisons, estimates and review suggestions. We record the policy versions, your choice and its date. These choices do not subscribe you to marketing. Optional online model synthesis retains its separate consent controls.
You can withdraw health-data processing consent in Settings. Withdrawal blocks newly started health processing and health notifications, turns off optional online synthesis, and revokes existing record-sharing grants. Accepting health processing again does not restore those grants. Requests already in progress may finish; information already sent to a provider cannot be recalled by withdrawing consent. Existing records remain stored under this retention policy. You can still export records, request deletion, manage billing or sign out without accepting health processing again. Withdrawal does not itself cancel a subscription or delete records. Minimal consent-decision history may be retained with required billing and security records for accountability and legal obligations.
You can export available structured records and request account deletion in Settings. Deletion has a 30-day grace period and can be cancelled before its deadline. Device notifications are deactivated when the request is accepted. The cleanup worker cancels the subscription, removes stored reports and product health records, and deletes the sign-in identity after the deadline. A request or deadline alone is not confirmation that cleanup has completed; the private receipt shows the confirmed lifecycle status.
Save your private deletion-status link before signing out. It remains usable after sign-in deletion and exposes only request, schedule, purge and completion dates. Anyone who possesses the link can view those dates. Longview stores a hash of its random bearer token with a minimal account tombstone; raw receipt tokens are not stored on the server. A replacement link invalidates the old one. The tombstone, required subscription history and security audit metadata may be retained to prevent stale requests recreating deleted accounts, confirm completion, resolve disputes and meet legal obligations. Retention requirements and backup handling may prevent immediate removal of all legally retained or backup records.
If you used Sign in with Apple, removal of your Longview sign-in identity does not automatically revoke Apple's authorization. Follow Apple's instructions to stop using Sign in with Apple for Longview. Contact us for access, correction, export or deletion assistance.
You control what health documents and biomarkers you upload. You should not upload another person's health information unless you have authority to do so.
7. Health breach notices
If Longview discovers a breach of security involving unsecured personal health record identifiable health information, we will evaluate notice obligations under the FTC Health Breach Notification Rule and applicable state laws.
Where notice is required, we will provide notice using available contact information and include the information required by law.
8. Contact
Questions or privacy requests can be sent to hello@longviewhealth.org.
Website: longviewhealth.org
