Livity LogoLivity
Privacy Policy

Privacy Policy

Last updated: 14 July 2026

This is the authoritative English privacy notice for Livity. It explains how MB Marnar processes personal data when you use the Livity iOS and watchOS apps, our website, and connected-device features. If a translation differs from this notice, this English version controls.

Livity is designed so most Apple Health data is processed on your device. Some optional features—and some service, security, and measurement functions—require personal data to be processed by us or our service providers. We describe those cases plainly below.

1. Controller and contact

MB Marnar, company code 306991895, Kranto g. 12, Paežerių k., LT-70205 Vilkaviškio r., Republic of Lithuania, is the controller of the personal data covered by this notice.

For privacy requests or questions, email team@livity-app.com. Please use the email address associated with your account where possible so we can verify and protect your request.

2. Data we process

Depending on the features you use, we may process:

  • Account and service data: email address, optional name, language, internal account ID, subscription status, RevenueCat app-user ID, and device authentication-token metadata.
  • Device and diagnostic data: push-notification token, app and OS version, device model, crash reports, technical events, and feature-use events. Diagnostic context can include high-level app state and health-score values; it is not a copy of your raw HealthKit sample history.
  • Apple Health data: health, fitness, and wellbeing information you authorize Livity to read or write through Apple Health, such as activity, sleep, heart rate, HRV, workouts, body measurements, nutrition, menstrual-cycle, blood-pressure, and related metrics. This information is primarily stored and calculated locally on your iPhone, Apple Watch, and app storage.
  • Connected wearable data: when you connect Garmin, Fitbit/Google Health, or Oura, the relevant provider sends us the OAuth identifiers and tokens needed to maintain the connection and the health/fitness records needed to transfer data to your device. Tokens are encrypted at rest. We stage records on our servers for delivery to your device; they may include activity, sleep, workout, heart-rate, HRV, stress, respiration, oxygen, body-composition, temperature, nutrition, and related provider-specific data.
  • AI and chat data: chat messages, AI responses, conversation titles, memories or factual notes, and the health summaries or specific data you choose to provide for an AI request. If you attach an image to chat, we store it in Google Cloud Storage so it can be processed and displayed in that conversation.
  • Blood-report data: with your explicit consent, report date, laboratory name, notes, and extracted or manually entered biomarker results. Source images or PDFs are sent for extraction but are not retained by our backend after processing.
  • Feedback and support data: the content of support requests, in-app feedback, diagnostic logs you choose to send, and optional account-deletion feedback.
  • Website and marketing data: IP-address-derived technical information, browser/device information, pages and referral URLs, cookie identifiers, advertising click IDs, and campaign or conversion events.

3. Why we use data and our legal bases

  • Provide and secure Livity—to create and maintain your account, deliver app features, sync connected wearables, send requested notifications, provide support, prevent abuse, and keep the service reliable. This is necessary to perform our contract with you and, where appropriate, for our legitimate interests in operating and securing Livity.
  • Health, AI, and blood-report features—to provide the optional feature you ask us to provide. Where this involves special-category health data, we rely on your explicit consent; you can withdraw it by disabling the feature, deleting the relevant data where the app provides that control, or contacting us.
  • Subscriptions and transactions—to administer access, entitlement, fraud prevention, accounting, and customer support. Our bases are contract performance, legitimate interests, and legal obligations where applicable.
  • Product measurement and marketing—to understand app and website performance, attribution, and campaigns. We use consent where required for cookies, advertising identifiers, or similar technologies, and legitimate interests only where law permits non-consent-based service measurement.

We do not sell health data or use it for interest-based advertising. We do not use your health data to train our own AI models.

4. AI features and Google Cloud

AI Health Insights, food analysis, chat, and blood-report extraction are optional. When you use them, the applicable prompt, health summary, image, report content, and conversation context may be sent to Google Cloud and Vertex AI/Gemini to generate a response or extraction. We use Google Cloud services under applicable contractual data-protection terms; the data is not used to train Google's general-purpose models.

Chat messages, responses, titles, and memories can remain in your account until you delete the conversation or memory, delete the account, or we no longer need them to provide the service. Do not enter information you do not want processed by these AI services, including government-ID numbers or account passwords. AI output is informational and not medical advice.

5. Recipients and service providers

We use processors and partners to operate Livity, including:

  • Apple for App Store purchases, Apple Health, push services, and device-level functionality.
  • Google for Firebase (analytics, crash reporting, remote configuration, messaging, and feedback), Google Cloud, Cloud Storage, and Vertex AI/Gemini.
  • RevenueCat and, where relevant, Stripe for subscription and payment entitlement administration.
  • PostHog, Singular, and Meta for product analytics, attribution, and advertising measurement. The app may share advertising/device identifiers and a hashed or normalized email for attribution where configured and permitted.
  • Garmin, Fitbit/Google Health, and Oura when you choose to connect those accounts. Their separate privacy notices also apply to their processing.
  • MailerSend and email-validation providers for service and marketing emails; Vercel for website hosting and website analytics; and Google Ads and Meta for website advertising measurement where enabled.

We may also disclose data where required by law, to protect rights and safety, or in connection with a corporate transaction. We do not permit service providers to use personal data for their own unrelated purposes.

6. Cookies, advertising, and website analytics

Our website uses necessary technologies and, where enabled, PostHog, Vercel Analytics, Google Ads, and Meta Pixel/Conversions API. These tools may process page visits, referral and campaign information, cookie IDs, click IDs, browser/device details, and conversion events. We ask for consent before enabling optional cookie-based analytics or advertising technologies on locale-based website pages. You can reject or withdraw optional consent through the cookie controls in the site.

Some dedicated campaign pages use advertising measurement. We will update those pages to apply the same consent choice before optional advertising technology runs. Rejecting consent does not affect core site access.

7. Retention and deletion

  • On-device health data remains on your device and in Apple Health according to your device, app, and Apple Health settings. You can revoke Health permissions in iOS Settings.
  • Account, subscription, and service data is kept while your account is active and afterward only as needed for deletion processing, legal obligations, dispute resolution, security, or accounting.
  • Wearable connection tokens are kept while a connection is active and are deleted or deactivated when you disconnect it or delete your account. Staged records are deleted after device confirmation, an applicable cleanup period, or a disconnect/account-deletion request; timing varies by provider and delivery state.
  • Chat, memories, blood reports, and attachments are kept until you delete them, delete your account, withdraw consent where applicable, or they are no longer needed for the feature.
  • Analytics, crash reports, support, and deletion feedback are retained under our and the provider's applicable retention settings for product improvement, security, support, and legal compliance. Optional deletion feedback may be retained separately from an erased account so we can analyze product issues and meet legal obligations.

We are continuing to align every backend data store and storage object with account deletion. If you need deletion from a connected service or have a request that the app cannot complete, contact us directly.

8. International transfers and security

We and our providers may process data in Lithuania, the European Economic Area, the United States, and other countries where our providers operate. Where GDPR applies and data is transferred outside the EEA without an adequacy decision, we use an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required. You may request information about relevant safeguards by contacting us.

We use measures intended to protect data, including encrypted connections, encryption for wearable access tokens at rest, access controls, and provider security controls. No system can guarantee absolute security.

9. Your privacy rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, data portability, and withdrawal of consent. You may also opt out of marketing emails using the unsubscribe link in the message, manage Apple Health permissions in iOS Settings, disconnect a wearable account in the app, delete supported chats, memories, or reports in the app, and request account deletion.

You may lodge a complaint with the State Data Protection Inspectorate of Lithuania or your local data-protection authority. We would appreciate the opportunity to address your concern first.

10. Children and changes to this notice

Livity is not directed to children under the age at which they can independently consent to data processing under applicable law. Do not use Livity if you cannot lawfully provide the required consent.

We may update this policy as our features or legal obligations change. We will publish the revised version here and update the date above; where required, we will provide additional notice or seek consent.