Website cookies and browser storage
The website currently uses essential storage only: Cloudflare security cookies, clinician/admin session storage, and a local cookie-choice record retained for up to 180 days. There are no optional advertising or analytics cookies. Accept all and Reject optional therefore preserve the same essential functions today. These choices do not authorise future trackers.
Use Cookie settings in the footer or the bottom-of-page button to change your choice at any time. Our Cookies & browser storage page, linked in the footer, lists purposes, providers, retention and browser controls. Security logs and doctor-referral link counts are separate from cookie preferences.
Scope and our role
This policy explains how Livadia processes information when you use the mobile application, website, support channels, and related services. Livadia accounts are designed for adults who organize their own information and, where they have legal authority, information for a child in their care.
Before public release, this policy must identify the operating legal entity, its address, applicable representative, and the countries where the service is offered.
Information you provide
We process information you choose to submit so the requested features can work.
- Account information, such as email address, phone number, email-verification records, and authentication credentials.
- Profile information, including display name, date of birth or age, biological sex selection, height, weight, measurement system, time zone, and language.
- Sensitive health information, including laboratory reports, biomarker values, units, laboratory ranges and flags, notes, reminders, and optional menstrual-cycle entries.
- Documents, images, and PDFs you choose to scan or upload.
- To help you check scanned results, Livadia keeps page and line coordinates alongside the saved readings. Reduced-size previews are generated locally from your original files, are not uploaded as separate images, and are cleared when you sign out or delete record files.
- Optional insurance details and front/back card images. Photo text suggestions are processed on-device; the reviewed details and chosen originals are uploaded when you save and stored encrypted on the server.
- An optional doctor referral code used to record who introduced you to Livadia, plus any clinician connection requests and sharing choices you make.
- Messages you exchange with a clinician through an active, patient-approved care connection.
- Care plans you create yourself or receive from a connected clinician, proposed revisions, your acceptance or decline, check-in and measurement answers, educational reading acknowledgements, medicine follow-up and refill requests, and clinician review notes.
- Messages and attachments you send to support.
- Child profile information and vaccination history that a parent or legal guardian chooses to record, including name, date of birth, vaccine, dose, administration date, provider, lot number, next recorded date, and notes.
Doctor referrals
If you open a participating doctor’s referral link or voluntarily enter the doctor’s code during account creation, Livadia may record an aggregate link visit, the referring partner, and the attribution date. This supports referral measurement. The current offer does not pay doctors a patient-referral commission.
Referral attribution does not by itself give a doctor clinical access. It may create a pending connection request, but the doctor receives no health information unless you separately accept that request and choose specific categories to share.
Patient-approved clinician sharing
A Livadia connection QR code contains a short-lived, single-use random token, not your medical or insurance details. Scanning previews a name and role; confirming creates or identifies a connection without granting new sharing permissions. Insurance is a separate category that you must explicitly approve; profile access alone does not include the card.
You may connect with a participating clinician. Before access begins, Livadia shows the clinician name and requested categories. You choose which categories to grant, including profile, records, medicines, reminders, cycle information, children and vaccination history, Apple Health or Android Health Connect summaries, and WHOOP summaries.
While a connection is active, approved categories can refresh in the clinician portal and you may exchange secure messages. Unapproved categories remain hidden. You can revoke the connection in Livadia at any time; the portal then loses access to your current health view. Clinicians remain responsible for their professional obligations and for any information they lawfully retain outside Livadia.
Care plans require separate acceptance before you submit responses. Accepting authorizes sharing those responses with the doctor who offered the plan; it does not grant access to other record categories. You may decline or stop a plan. Stopping retains previous responses in the shared history while the clinical connection remains active. Revoking the clinical connection removes portal access. A refill request does not renew or change a prescription, and check-ins are not continuously monitored.
Information generated through use
The service creates limited operational information needed to keep accounts secure and features reliable.
- Session and device records, notification identifiers, consent history, and important account activity.
- Technical error information, request timing, coarse device characteristics, and security signals. We do not include behavioral advertising trackers.
- Deterministic comparisons and estimates derived from your entries, such as value changes, percentage changes, reminder dates, and estimated cycle dates.
Optional Apple Health connection
On supported Apple devices, you can choose to connect Apple Health. Livadia requests read-only access to today’s step count, walking and running distance, active energy, and the latest height and weight values so it can display or refresh those details in your private profile. Apple presents and controls the permission request.
Apple Health values are normally processed and stored locally. If—and only if—you approve Apple Health for an active clinician connection, Livadia uploads a limited recent summary to its server so that clinician can view it. Livadia does not write to Apple Health, use Health data for advertising or data brokerage, or access any Health category you did not authorize. You can revoke clinician sharing in Livadia and change Health permissions in Apple Health or device Settings.
Optional Android Health Connect connection
On supported Android devices, you can choose to connect Health Connect. Livadia requests read-only access to the activity, exercise, heart, respiratory, height, and weight categories you approve. Android presents and controls the permission request.
Health Connect values are normally processed and stored locally. If—and only if—you approve connected health for an active clinician connection, Livadia uploads a limited recent summary to its server so that clinician can view it. Livadia does not write to Health Connect, use this data for advertising or data brokerage, or access a category you did not authorize. You can revoke clinician sharing in Livadia and change Health Connect permissions in Android settings.
Optional WHOOP connection
When WHOOP access is available, you can choose to connect your WHOOP account through WHOOP’s own permission screen. Livadia requests read-only access to the Recovery, Strain and physiological cycle, Sleep, Workout, basic profile, and body-measurement categories you approve. Livadia also requests offline access so the connection can refresh without asking you to sign in every time.
WHOOP authorization tokens are encrypted and stored on Livadia’s server, linked only to your Livadia account, and are not placed in the mobile application. Disconnecting asks WHOOP to revoke Livadia’s access and deletes Livadia’s stored authorization. Livadia uses these measurements to display a private wellness summary, not to diagnose, treat, or make medical decisions.
Trusted-person file sharing
When you share with a trusted person, the files you select become available through that sharing feature. You can edit the selected files, choose an expiry or leave access open until you revoke it. This is separate from clinician category permissions. Revoking access cannot retrieve copies a recipient has already saved outside Livadia.
Optional Fitbit connection
Fitbit connectivity is currently limited to approved accounts. Connecting is optional and uses the provider’s authorization screen. Review the permissions shown before approving access. Provider processing, supported data categories, and retention details must be confirmed in the final policy before wider availability.
Why we process information
We use information only for defined purposes and an appropriate legal basis.
- Provide the features you request and maintain your account.
- Store, retrieve, and export information supported by Livadia.
- Schedule one-time notifications you enable.
- Protect accounts, enforce user-level access, prevent abuse, and investigate security incidents.
- Respond to support requests and comply with applicable legal obligations.
- Process sensitive health information with explicit consent where required. You can withdraw optional consent, although some features will then stop working.
Document review and automated extraction
When you choose a camera image, photo, or PDF, Livadia sends that selected copy over encrypted transport to Livadia’s server for optical character recognition. The server uses self-hosted OCR to propose biomarker names, values, units, and reference ranges, then discards its temporary extraction copies after the request completes. The app saves a report only after you review the structured result sheet and confirm at least one result.
OCR can be incomplete or wrong. You must compare every proposed field with the source report. Livadia does not send these reports to an external generative-AI provider for extraction, and manual correction remains available.
Sharing and service providers
We do not sell personal or health information, use it for behavioral advertising, or share it with data brokers. Carefully selected providers may process limited information under contract for hosting, private document storage, email delivery, security, customer support, or user-approved document processing.
A completed production policy must list or link to the actual provider categories, processing locations, and international-transfer safeguards. We may disclose information when legally required or necessary to protect users, the service, or others, subject to applicable law.
Storage, security, and retention
Livadia uses encrypted transport, secure password hashing, account-scoped API queries, secure mobile token storage, rate limiting, audit events, a database not exposed to the public internet, and an optional biometric app lock. No service can guarantee absolute security.
Uploaded document files and saved insurance-card details are encrypted on the server. This is not end-to-end encryption: the service holds the keys needed to decrypt these items, and some structured health information is processed and stored in database fields. Encryption does not make records inaccessible to privileged server operators. Clinician access through the portal is limited by your approved sharing categories.
Some health entries are stored locally on the device. When you use in-app account deletion, Livadia deletes the account and linked server-side profile and health records, clears local Livadia state, and cancels reminders scheduled by the app. Limited infrastructure backups may persist temporarily until their normal rotation completes; final backup and retention periods must be disclosed before public release.
Your controls and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information and to withdraw consent. Current in-product controls are listed below.
- Edit or remove cycle entries.
- Create, edit, and remove child profiles and vaccine entries when you are authorized to manage that information.
- Open original blood-test images or PDFs, export a verified result sheet, compare reports, and delete a report together with its locally stored source files.
- Completely hide cycle tracking while keeping its entries on the device.
- Connect Apple Health voluntarily and change that permission in Apple Health or device Settings.
- Connect or disconnect WHOOP voluntarily when the integration is available.
- Approve, limit, deny, or revoke a clinician connection and review the categories currently shared.
- Exchange messages only after a clinician connection becomes active.
- Enable an optional biometric app lock.
- Export locally stored app information through the device share sheet.
- Sign out of the current account.
- Permanently delete your account and linked server-side health data from Profile after entering an explicit confirmation.
Notifications, child profiles, and changes
Push notifications are used only when you enable reminders. You can disable them in Livadia or device settings. Children do not create or operate Livadia accounts. An adult parent, legal guardian, or other legally authorized caregiver may create a child profile and must remove or stop sharing that information if their authority ends. Livadia does not determine guardianship or verify an immunization record.
We will post an updated date and provide appropriate notice before material policy changes. Continued use will not replace fresh consent where the law requires it.
Contact and complaints
Privacy contact placeholder: privacy@example.com. Replace this with a monitored address, the controller’s legal name and mailing address, and any required data-protection representative before release. You may also have the right to complain to your local data-protection authority.
This policy is a product-ready draft, not legal advice. It must be reviewed against the real company, vendors, hosting regions, launch markets, and data flows before accepting users.