← Back

Privacy Policy

Last updated: June 30, 2026
Plain-language summary: We collect the health and account data you give us to generate your wellness reports. We share it only with the vendors required to run the Service (Google for sign-in, Stripe for billing, Supabase for storage, Anthropic for AI generation) — we do not sell your data to advertisers or data brokers, ever.

1. Who We Are

This Privacy Policy describes how Limitless ("Limitless," "we," "us," "our") collects, uses, discloses, and protects information when you use our website and application (the "Service"). This Policy is incorporated into and should be read alongside our Terms of Service.

2. Information We Collect

2.1 Account Information

When you sign in with Google, we receive your name, email address, and profile picture from Google, which we use to create and identify your account.

2.2 Health and Biomarker Data ("User Health Data")

To generate your personalized wellness reports, we collect information you voluntarily submit through our survey and intake forms, which may include:

  • Demographic information such as age and sex;
  • Body composition data (weight, body fat percentage, lean mass, waist/hip measurements, and similar);
  • Cardiovascular markers (resting and max heart rate, VO2 max, heart rate variability, blood pressure, cholesterol panels, and similar);
  • Hormone panel data (testosterone, thyroid markers, vitamin D, and similar);
  • General bloodwork markers (glucose, HbA1c, liver and kidney markers, and similar);
  • Medications, diagnosed conditions, and supplements you report taking;
  • Your stated health, fitness, and performance goals;
  • Free-text notes you choose to provide.

We collect this information directly from you. You control what you submit, and you are not required to provide any specific data point to use the Service, though incomplete data may result in a less detailed or less accurate Generated Content output.

2.3 Billing Information

If you subscribe to a paid tier, our payment processor Stripe collects and processes your payment card information directly. We do not receive or store your full payment card number. We do receive limited billing metadata from Stripe, such as your subscription tier, billing status, and transaction history, to manage your account.

2.4 Usage and Device Information

We automatically collect certain technical information when you use the Service, including IP address, browser type, device identifiers, pages visited, and timestamps, for the purposes of operating, securing, and improving the Service.

2.5 Generated Content

We store the AI-generated reports, checklists, and spreadsheets created on your behalf so that you can access them later through your account dashboard, subject to the plan history limits of your subscription tier.

3. How We Use Your Information

We use the information described above to:

  • Authenticate your identity and maintain your account;
  • Generate your personalized wellness reports, checklists, and exports via our AI processing pipeline;
  • Process subscription payments and manage billing;
  • Enforce tier-based feature and usage limits;
  • Provide customer support and respond to your requests;
  • Monitor, secure, debug, and improve the Service;
  • Comply with legal obligations and enforce our Terms of Service;
  • With your consent or on a de-identified, aggregated basis, improve and develop our products.

We do not use your User Health Data to make any medical, insurance, employment, or credit decisions, and we do not sell your User Health Data to advertisers, data brokers, or any third party for their own marketing purposes.

4. How We Share Your Information

We share information only as necessary to operate the Service, with the following categories of third-party service providers, each of which is contractually or technically limited to using your data solely to provide their service to us:

ProviderPurposeData Shared
GoogleAuthentication (sign-in)Name, email, profile picture
AnthropicAI processing to generate your reportsThe User Health Data and survey responses needed to generate your specific report
SupabaseDatabase and data storage infrastructureAll account and User Health Data necessary to operate your account
StripePayment processing and subscription billingBilling contact information and payment details (collected directly by Stripe)

We may also disclose information: (a) if required by law, subpoena, or other legal process; (b) to protect the rights, property, or safety of Limitless, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of all or part of our business, in which case your information may be transferred as a business asset, subject to this Policy or a successor policy of materially similar protection; or (d) with your explicit consent.

We do not sell your personal information, as that term is defined under applicable U.S. state privacy laws (such as the CCPA), and we do not share it for cross-context behavioral advertising.

5. AI Processing Disclosure

When you submit User Health Data to generate a report, relevant portions of that data are transmitted to Anthropic's Claude API to produce your Generated Content. This processing occurs via Anthropic's commercial API, which, per Anthropic's standard API terms, does not use API inputs or outputs to train its models. We do not control Anthropic's infrastructure directly, and your use of the Service constitutes acknowledgment that this transmission occurs as a necessary part of generating your reports.

6. Data Retention

We retain your account information and User Health Data for as long as your account remains active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. If you delete your account, we will delete or de-identify your personal information and User Health Data within a commercially reasonable period, except where retention is required by law (for example, billing records required for tax or accounting purposes) or necessary for the purposes described in this Policy.

7. Data Security

We use industry-standard administrative, technical, and physical safeguards designed to protect your information, including encrypted data transmission (TLS), access controls limiting who can view your data, and reliance on reputable infrastructure providers (Supabase, Stripe, Google, Anthropic) that maintain their own security programs. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security of your information.

8. Your Rights and Choices

8.1 Access, Correction, and Deletion

You may access, update, or correct your account and User Health Data at any time through your account dashboard. You may request deletion of your account and associated data by contacting us at privacy@golimitless.app, or through account settings if available. We will honor deletion requests within a reasonable time, subject to the retention exceptions described in Section 6.

8.2 State Privacy Rights

Depending on your state of residence, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA/CPRA) and similar state privacy statutes, including the right to know what personal information we collect, the right to request deletion, the right to correct inaccurate information, and the right to non-discrimination for exercising these rights. To exercise these rights, contact us at privacy@golimitless.app. We will verify your identity before fulfilling your request.

8.3 Health Data-Specific Rights

Some states (such as Washington's My Health My Data Act and similar laws elsewhere) provide specific rights regarding consumer health data. Where applicable, you have the right to withdraw your consent to our collection and processing of your health data at any time by deleting your account, and the right to request a list of third parties with whom we have shared your health data, which is set out in Section 4 of this Policy.

8.4 Not a HIPAA Covered Entity

Limitless is a direct-to-consumer wellness application and is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). HIPAA's protections generally apply to traditional healthcare providers, health plans, and their business associates, and do not apply to the data you submit directly to Limitless as a consumer wellness product. We nonetheless apply meaningful safeguards to your User Health Data as described in this Policy.

9. Children's Privacy

The Service is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly.

10. International Users

The Service is operated from the United States, and your information will be processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your jurisdiction.

11. Cookies and Similar Technologies

We use essential cookies and similar local storage technologies necessary to keep you signed in and to operate the Service. We do not currently use third-party advertising or tracking cookies. If this changes, we will update this Policy accordingly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by posting a notice on the Service or updating the "Last updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at privacy@golimitless.app.