FixMyAge
How It WorksWhat We MeasureReviewsBlog

Privacy Policy

Last updated: May 9, 2026

1. Scope and Controller

This Privacy Policy applies to the FixMyAge website (fixmyage.com), the public provider directory at fixmyage.com/providers, the FixMyAge web application, and the FixMyAge iOS application (together, the “Service”). The data controller for personal data processed in connection with the Service is FixMyAge Ltd., established in Sofia, Bulgaria. This policy describes what we collect, how and why we use it, the lawful bases on which we rely under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), and your rights. It is designed to align with the data declarations we publish in the App Store and in the iOS app’s privacy manifest.

2. Information We Collect

Information you provide:

  • Account details — name, email address, phone number (optional), date of birth (optional), sex (optional), and timezone.
  • Authentication credentials — password (for email/password accounts) or a stable identifier from your sign-in provider when you use Sign in with Apple or Sign in with Google. Apple may give us a private relay email address; we treat that as your contact email.
  • Profile photo (avatar) if you choose to upload one.
  • Health and fitness data — biomarker and laboratory results you upload, epigenetic-age results, physical-test results, body measurements, supplements you take, health goals, protocol selections, and notes.
  • Membership and payment metadata — your plan, status, and identifiers from our payment processor (Stripe). We do not store full card numbers; that is handled by Stripe.
  • Support correspondence — messages you send us via email or in-app forms.
  • Submitted Content (provider directory) — reviews you write (rating, title, body, structured fields such as duration, approximate cost, target biomarkers, would-recommend value), suggestions for new providers, helpful/unhelpful votes, reports you file against other content, your public display-name and stable hash suffix as it appears on a review, and, if you choose to link a bloodwork panel to a review, the identifier of that panel and the marker-level before/after delta computed for publication.
  • Provider claim and response data — if you claim a provider listing, the verification evidence you supply (DNS TXT record, email at the domain), the email you use for claim correspondence, and any responses you publish to reviews.

Information collected automatically:

  • Usage analytics — when you open a screen in the iOS app or a page on the web, we record the path you viewed, your account ID, and a timestamp. We use this only to understand which features are used and to debug issues.
  • Logs and security signals — for sign-in attempts and sensitive actions we record the IP address and a short audit log entry to detect abuse. For provider suggestions and review submissions we additionally retain a coarse device fingerprint and IP for anti-spam and astroturfing detection.
  • Standard request metadata — user agent and IP received whenever your client communicates with our servers.

3. No Third-Party Tracking

We do not use third-party tracking SDKs, advertising identifiers, or cross-app/cross-site tracking. The iOS app’s privacy manifest declares no tracking and an empty list of tracking domains. We do not sell your personal data, and we do not share it for behavioural advertising.

4. How We Use Your Information

  • To provide and personalize our biological-age tracking and protocol services, including AI-assisted analysis of the data you provide
  • To create and authenticate your account, including linking multiple sign-in methods (email/password, Apple, Google) to the same account
  • To process your membership and payments
  • To operate the public provider directory: to display reviews you submit, attribute them to your display-name and hash suffix, surface them to readers and search engines, and (if you so consent) attach a data-backed badge with an anonymised before/after delta drawn from a panel you have linked
  • To moderate user-generated content, to investigate notices of illegal or non-compliant content, and to detect spam, fake reviews, and astroturfing
  • To produce aggregated, irreversibly anonymised statistics and research outputs (such as our periodic “State of Longevity Providers” reports)
  • To communicate with you about your account, results, and protocol updates
  • To improve our services, algorithms, and user experience
  • To detect abuse, enforce our Terms, and comply with legal obligations

5. Lawful Bases for Processing (GDPR)

For users in the EU, the UK, and other jurisdictions with comparable laws, we rely on the following lawful bases under Articles 6 and 9 GDPR:

ProcessingArticle 6Article 9 (where health data)
Account, billing, and customer supportContract (Art. 6(1)(b))
AI-assisted protocol generation on uploaded biomarkersContract + explicit consentExplicit consent (Art. 9(2)(a))
Storing the textual review you writeContract (Art. 6(1)(b))
Publishing the textual review on the public webConsent (Art. 6(1)(a)) given on submissionNot applicable unless you choose to disclose health information in the body of the review, which we discourage
Publishing a data-backed badge and before/after marker deltaExplicit, separable consent (Art. 6(1)(a))Explicit, separable consent (Art. 9(2)(a))
Aggregate research and “State of Longevity Providers” reportsLegitimate interests (Art. 6(1)(f)), balancing test on fileScientific or statistical purposes on irreversibly pseudonymised data (Art. 9(2)(j) and Art. 89)
Anti-fraud, anti-spam, astroturfing detection, security loggingLegitimate interests (Art. 6(1)(f))
Provider claim verification and response featureContract / legitimate interests in operating the directory
Marketing and product emails (where applicable)Consent (Art. 6(1)(a))

Where we rely on legitimate interests, we have carried out a balancing test which is available on request from support@fixmyage.com. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

6. Health Data Protection

Your health data is treated with the highest level of care. All biomarker results, epigenetic data, and physical-assessment records are encrypted at rest and in transit. We never sell your health data to third parties. Access is restricted to authorized personnel necessary for providing our services. Health-related information you enter is treated as a special category of personal data under Article 9 GDPR and is processed only on the lawful bases set out in Section 5.

If you choose to link a bloodwork panel to a review, the marker-level before/after delta and the name(s) of the marker(s) become publicly visible alongside your display-name and hash suffix. We surface this on the linking screen and obtain your explicit, separable opt-in consent before publication. Anonymisation in this context is partial: where a provider has few reviewers, where the published delta is unusual, or where you publicly disclose elsewhere that you reviewed that provider, identification may be possible. You may withdraw your data-backed consent at any time, and we will remove the badge and the published delta within 7 days; the underlying textual review remains unless you also delete it.

7. Data Sharing and Public Disclosure

We share personal data only with vendors who help us operate the Service, under contracts that restrict their use of your data:

  • Authentication providers — Apple (Sign in with Apple) and Google (Sign in with Google) when you choose those sign-in methods.
  • Hosting and storage — our cloud provider for application hosting, and S3-compatible object storage for files you upload (avatars, lab-result documents).
  • Payments — Stripe for subscription billing.
  • Email delivery — Resend for transactional email (verification, password reset, approval status, moderation notices).
  • AI features — when you use AI-assisted features, the relevant prompt and context are sent to our model provider to generate a response. We do not allow these providers to train on your data.

Public disclosure through the directory. Reviews, ratings, structured fields, helpful/unhelpful counts, provider responses, and (if consented) data-backed deltas are published on the public web at fixmyage.com/providers and are indexed by search engines. Once published, content is likely to be cached by third parties (including search-engine snippets and the Internet Archive) which we cannot comprehensively purge. Public attribution uses your display-name plus a stable hash suffix; we do not publish your real name unless you choose to include it in the body of a review.

We do not sell personal information to third parties.

8. International Transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as the European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Addendum where relevant) for transfers out of the EEA and the UK. A copy of the relevant transfer mechanism is available on request.

9. Data Retention

We retain your personal and health data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are legally required to keep it longer (for example, financial records).

Reviews you publish remain visible on the public web for as long as your account is active. You may delete an individual review at any time without deleting your account; we will remove it from active services within 7 days. Deletion of a review or of your account does not retroactively remove that review’s contribution to aggregated, irreversibly anonymised statistics computed before deletion (such as provider averages or research-report figures), which may continue to be used and published. Moderation logs and audit logs may be retained for up to 12 months for the purpose of safety, abuse-prevention, and compliance with the DSA.

10. Your Rights

Depending on your jurisdiction, you have the right to:

  • access a copy of the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • delete your account and associated data;
  • delete an individual review without deleting your account;
  • withdraw your consent to publication of a data-backed badge and the associated marker delta, separately from the textual review, at any time;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • port your data to another service;
  • appeal a moderation decision affecting your Submitted Content via our internal complaint-handling system within six (6) months of the decision (Article 20 DSA), and thereafter to refer the matter to an Article 21 DSA out-of-court dispute settlement body in your Member State;
  • lodge a complaint with the data protection authority of your habitual residence. Our supervisory authority is the Bulgarian Commission for Personal Data Protection (cpdp.bg).

To exercise these rights, email support@fixmyage.com from the address associated with your account.

11. Account Deletion

You can delete your account at any time from the in-app Profile screen, or by emailing support@fixmyage.com. Deletion removes your profile, authentication identifiers, uploaded files, the health data associated with your account, and the reviews you have published, subject to the retention rules in Section 9.

12. Age Restriction

The Service is intended for individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, please contact us and we will delete it.

13. Security

We use industry-standard measures including TLS encryption, bcrypt password hashing, HTTP-only refresh-token cookies, optional two-factor authentication, regular security audits, and access controls. While no system is 100% secure, we take every reasonable step to protect your information.

14. Moderation Transparency

When we remove, demote, or restrict a review or other Submitted Content you have published, we will provide you with a Statement of Reasons identifying the action, the legal or contractual ground, the facts relied upon, and any automated means used. You may appeal as described in Section 10. We publish at least an annual transparency report on moderation activity in line with Article 15 DSA.

15. Digital Services Act — Point of Contact

Our single point of contact for users and authorities under Articles 11 and 12 of the Digital Services Act is support@fixmyage.com. The Member State of establishment of FixMyAge Ltd. is Bulgaria. Communications may be addressed in English or Bulgarian.

16. California Residents — Sensitive Personal Information

For California residents, the categories of personal information described in Section 2 include “sensitive personal information” under the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA/CPRA”), specifically health information. We do not “sell” or “share for cross-context behavioural advertising” this information. We use sensitive personal information solely to provide the Service and for the purposes set out in this policy. You have the right to limit our use of your sensitive personal information to those purposes; to know, access, correct, and delete your personal information; to opt out of any sale or sharing (none currently occurs); and to non-discrimination for exercising these rights. To exercise any of these rights, contact support@fixmyage.com.

17. Washington Residents — My Health My Data Act

For Washington State residents, this section serves as the consumer health data privacy notice required by the Washington My Health My Data Act (RCW 19.373). The categories of consumer health data we collect, the purposes for which we collect them, the categories of sources, the categories of third parties with whom we share them, and our retention practices are set out in Sections 2, 4, 5, 6, 7, and 9 of this policy. We do not sell consumer health data. We do not share consumer health data for advertising. You have the right to confirm whether we are collecting, sharing, or selling your consumer health data; to access it; to withdraw consent; to delete it; and to appeal a denial of these rights. To exercise these rights, contact support@fixmyage.com.

18. Changes to This Policy

We may update this policy from time to time. If the changes are material, we will notify you by email and/or via the Service. The “Last updated” date at the top of this page reflects the most recent revision.

19. Contact

For any privacy-related questions or requests, contact us at support@fixmyage.com.