Trust & Data Stewardship
Plain answers to the questions people — and, increasingly, their AI agents — ask before trusting a health application. Last updated 2026-08-20. Every statement on this page describes what is deployed today, not what is planned.
Where your health data lives
Your records are stored in HIPAA-eligible Google Cloud services (Firestore, Google Cloud Healthcare API FHIR store, and Cloud Storage) under a signed Google Cloud HIPAA Business Associate Agreement. AI analysis of your records runs on US-pinned Vertex AI endpoints covered by the same agreement.
Your health data is analyzed to produce your report — nothing else. We do not sell your data. We do not use your health records to train AI models; analysis happens at inference time, per request, inside the BAA-covered boundary.
Deletion that actually deletes
Deleting your account runs a single authoritative purge: your Firestore records and subcollections, your FHIR clinical store entries (Patient and Observations), your uploaded files in Cloud Storage, your exports, and your authentication record. Active subscriptions are cancelled as part of the same flow. This is a real mechanism, live in production — not a support-ticket promise.
Your data, exportable in full
You can request a complete export of your account: profile, analyses, the canonical FHIR record, and a manifest of your uploads with time-limited download links. Credentials and tokens are redacted from exports by construction.
AI agents and the PHI boundary
Phi Longevity operates public tool surfaces for AI agents (MCP and A2A). These surfaces accept synthetic or de-identified inputs only and return previews, scores, and methodology. Full reports and real medical records exist exclusively inside the authenticated, BAA-covered application. Protected health information never transits the agent surfaces — the boundary is architectural, not procedural.
Our agent identity is verifiable: the A2A agent card is cryptographically signed (ES256), with the public key served at /.well-known/jwks.json. Agent-readable site orientation lives at /llms.txt.
Telemetry: counts, never content
Our operational analytics are aggregate-only: counts, booleans, and timings. No filenames, no lab values, no diagnoses, no identifiers in logs or analytics — including upload telemetry, which records that an upload leg succeeded or failed and nothing about what was in it.
Clinical honesty
Recommendations carry citations to clinical guidelines and published research. Prescription and controlled therapies are never issued as directives — at most, the report suggests a question to ask your clinician. Physician review of our evidence grading is an ongoing, funded practice, and our reports state confidence and data coverage honestly, including when data is too old or too thin to score.
Payments
Human subscriptions run on Stripe, on our own domain. We are merchant of record; card details never touch our servers.
Questions
Security or privacy questions: support@philongevity.com. See also our Privacy Policy and Terms.