The Longevity Series · Member space

Privacy

Privacy Policy

What we collect, why we need it, which providers help us, and the choices and rights that remain yours.

Last updated · 6 August 2026Plain-language edition
01

Who is responsible for your data

Longevity & Performance B.V., trading as The Longevity Series, is the controller for the personal data described in this policy. This means we decide why and how that information is used.

Privacy questions and requests can be sent to hello@longevity-series.com. Put “Privacy request” in the subject and use the email address connected to your account where possible.

02

Information we collect

  • Account data: name where provided, email address, authentication identifiers and account status.
  • Purchases and access: product, plan, payment status, Stripe customer and transaction references, invoices and course entitlements. We do not receive your complete card number.
  • Check and report data: answers and progress stored locally in your browser; when submitted, this may include a completion reference, overall score, lowest domain, selected goal and information used to create a personal starting point or report.
  • Course activity: unlocked content, lesson progress and account-linked feedback or reviews.
  • Mobile-app operations: a random installation identifier, user identifier, app and operating-system version, selected app interactions and—only after permission—an Expo push token and notification preferences. We do not collect an advertising identifier for this purpose.
  • Communications: support messages, marketing consent, email engagement, Nora chat messages you choose to send and unsubscribe status.
  • Referral and security data: referral code, referring page, cookie identifiers, logs, approximate technical information, timestamps and information needed to prevent misuse.
04

Why we use information and our legal bases

  • Contract: create accounts, process purchases, unlock content, provide reports, maintain subscriptions and answer service requests.
  • Consent: send optional marketing, process health-related information where explicit consent is required, and use non-essential technologies if introduced.
  • Legitimate interests: secure and improve the platform, diagnose faults, understand aggregate use, prevent fraud, moderate reviews and operate a limited referral programme, where those interests do not override your rights.
  • Legal obligations: keep required financial records, respond to lawful requests and establish or defend legal claims.
05

Scores, recommendations and AI-assisted features

The Longevity Check applies predefined scoring logic to your answers and may recommend domains or courses. These results are educational and do not produce a legal, medical, insurance, employment or similarly significant decision about you.

Nora sends the messages you choose to submit, together with limited course-progress context, through our server to OpenAI to generate a response. We configure the Responses API with response storage disabled and do not save the conversation in our member database as a health record. Provider security and legally required retention may still apply. Do not enter detailed medical records or information you do not want processed for that conversation.

Nora is educational and uses automated processing. Important medical, medication, emergency, insurance, employment and financial decisions must never be based on an automated response from the platform.

06

Service providers and recipients

We share only what is reasonably needed with providers that help us deliver the service. They act under their own terms and/or data-processing obligations.

  • Supabase for authentication, database and protected member records.
  • Stripe for checkout, payments, subscriptions, invoices and billing controls.
  • Vercel for website hosting, delivery, security and technical logs.
  • Resend and email infrastructure for transactional and consented marketing email.
  • OpenAI for generating Nora responses from messages a signed-in member chooses to send.
  • Expo for optional mobile push-token registration and notification delivery.
  • Professional advisers, authorities or another business party where legally required or necessary for a legitimate corporate transaction with appropriate safeguards.
We do not sell personal data. We do not provide identifiable Check results to employers, insurers or advertising data brokers.
07

International transfers

Some providers may process information outside the European Economic Area. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate supplementary safeguards.

You can contact us for more information about the safeguards relevant to your data.

08

Cookies and browser storage

We use strictly necessary authentication cookies to keep members securely signed in. A referral cookie may remember a referral for up to 30 days. Browser local storage may remember Check answers and progress, course position, interface preferences and an anonymous completion reference on that device.

The mobile app uses protected local app storage for the signed-in session, a random installation identifier, Check progress and other on-device preferences. Check answers remain on the device unless a feature clearly asks you to submit them.

At the date of this policy, we do not rely on third-party advertising cookies on the public website. If non-essential analytics or advertising technologies are introduced, we will request consent where required and provide a way to change that choice.

09

Retention and security

We keep information only for as long as reasonably necessary for the purpose collected, an active account or access entitlement, required financial administration, dispute handling and security. Marketing data is suppressed or removed after withdrawal, subject to keeping a minimal suppression record so we do not email you again.

We use access controls, protected authentication, encrypted connections and restricted administrative access. No online system is perfectly secure; contact us promptly if you suspect unauthorised use of your account.

10

Your privacy rights

Depending on the circumstances, the GDPR gives you the following rights:

  • Access your personal data and obtain information about its use.
  • Correct inaccurate or incomplete information.
  • Request deletion or restriction where the legal conditions are met.
  • Receive portable data where processing is automated and based on consent or contract.
  • Object to processing based on legitimate interests and object at any time to direct marketing.
  • Withdraw consent at any time for future consent-based processing.
  • Complain to the Dutch Autoriteit Persoonsgegevens or another competent EEA supervisory authority.
We normally respond within one month. We may ask for proportionate identity verification. You can also unsubscribe from marketing through the link in each marketing email.
11

Children and policy changes

The platform is designed primarily for adults and we do not knowingly create paid accounts for children without appropriate parent or guardian involvement. Contact us if you believe a child supplied personal data without proper permission.

We may update this policy as the platform, providers or law changes. Material changes will be communicated in an appropriate way, and the date at the top identifies the current version.

Policies & member care

Everything in one clear place.