Laymen
Legal

Privacy Policy.

Effective 2026-07-13
Draft pending attorney review. This page is substantive but not legally final. The version that ships at launch will be reviewed and signed off by a licensed healthcare attorney.

Laymen, Inc. (“Laymen”, “we”, “us”) provides a health information and general wellness service built around your Health State. This policy explains what we collect, why we use it, the services that process it, and the choices you have.

Information we collect

  • Account data: your email address, sign-in provider, provider account identifier, onboarding status, and account preferences.
  • Health State data: information you choose to enter, upload, or connect, such as profile details, health goals, conditions, medications, allergies, family history, symptoms, lab documents and extracted results, wearable summaries, and the questions you ask and answers you receive.
  • Apple Health data: health and fitness categories you separately authorize the iOS app to read through HealthKit. Laymen does not receive Apple Health data unless you grant access, and you can change access in iOS Settings or the Health app.
  • Service data: coarse product events, request identifiers, model and route metadata, error diagnostics, device and browser information, and security signals. Product analytics events are designed not to contain question text or raw health values.
  • Payment data: Stripe processes eligible web payments and Apple processes App Store purchases. Laymen receives customer, transaction, product, and entitlement status needed to provide paid access, but does not receive your full card number from Stripe or Apple.

How we use information

  • Build, update, and explain your Health State and related wellness guidance.
  • Answer your questions using available Health State context and supporting sources.
  • Process labs, reports, subscriptions, account requests, and service messages.
  • Protect the service, enforce limits, investigate failures, monitor freshness, and improve reliability and safety.
  • Evaluate or improve product behavior using de-identified or aggregate information, or identifiable information only when you have given the separate consent required for that evaluation.

Apple Health restrictions

We use data obtained through HealthKit only to provide and improve health and fitness features you request. We do not use Apple Health data for advertising, marketing, or use-based data mining, and we do not sell it or disclose it to data brokers. We do not share it with a third party unless that processing is necessary to provide the feature, you direct the sharing, or the law requires it.

Service providers

We disclose only the information reasonably needed for vendors to perform services for us. Depending on the feature you use, those vendors include:

  • Supabase: authentication, database, and private object storage.
  • OpenAI: language-model and related inference.
  • Apple: sign-in, HealthKit authorization and transfer, and App Store billing.
  • Stripe: web billing and subscription management.
  • Vercel and Sentry: hosting, delivery, reliability, and error monitoring.
  • Resend: transactional email when enabled.
  • Environmental data providers: coarse location context for features such as air quality or weather, when enabled.

How we protect information

Health State records are stored in access-controlled production systems. We use transport encryption, provider-managed encryption at rest, row-level database controls, private object storage, restricted internal diagnostics, and logging designed to exclude raw health values. No security control eliminates all risk. If a reportable breach occurs, we will investigate and provide notices required by applicable law.

What we do not do

  • We do not sell personal information or Health State data.
  • We do not share identifiable health information with advertisers or data brokers.
  • We do not use personal Health State data to train a general-purpose model.
  • We do not disclose personal information to employers, insurers, or law enforcement unless you direct us or a valid legal requirement applies. Where legally permitted, we will notify you of a legal demand before disclosure.

Your choices

  • Access and portability: use an available export tool or contact us for a copy.
  • Correction: update information in the product or contact us.
  • Apple Health: change Laymen's category access in iOS Settings or the Health app. Revoking access stops future collection but does not delete data already imported into Laymen.
  • Deletion: delete your account in the app or follow the instructions on our Data Deletion page.
  • California rights: California residents may request access, correction, or deletion and may exercise other applicable rights without discriminatory treatment. We do not sell or share personal information for cross-context behavioral advertising.

Retention and deletion

We generally retain account and Health State data while your account is active. Account deletion removes user-linked records and private lab files from active production systems, subject to limited security, fraud-prevention, financial, and legal records that must be retained or anonymized. Shorter-lived operational records are automatically pruned on schedules based on their purpose, generally from 30 days to 24 months. Residual copies in provider backups age out under the providers' backup schedules and are not restored except for disaster recovery.

Children

Laymen is intended only for people who are at least 18. We do not knowingly collect personal information from anyone under 18. A parent or guardian who believes a minor created an account should contact us so we can investigate and delete it.

Changes

We may update this policy as the product or law changes. We will post the updated effective date and provide additional notice when required by law or when a change materially affects how we handle Health State data.

Contact

Privacy questions and requests: privacy@laymen.com. Mail: Laymen, Inc., 100 Pine Street, San Francisco, CA 94111.