This Privacy Policy describes how Limitless ("Limitless," "we," "us," "our") collects, uses, discloses, and protects information when you use our website and application (the "Service"). This Policy is incorporated into and should be read alongside our Terms of Service.
When you sign in with Google, we receive your name, email address, and profile picture from Google, which we use to create and identify your account.
To generate your personalized wellness reports, we collect information you voluntarily submit through our survey and intake forms, which may include:
We collect this information directly from you. You control what you submit, and you are not required to provide any specific data point to use the Service, though incomplete data may result in a less detailed or less accurate Generated Content output.
If you subscribe to a paid tier, our payment processor Stripe collects and processes your payment card information directly. We do not receive or store your full payment card number. We do receive limited billing metadata from Stripe, such as your subscription tier, billing status, and transaction history, to manage your account.
We automatically collect certain technical information when you use the Service, including IP address, browser type, device identifiers, pages visited, and timestamps, for the purposes of operating, securing, and improving the Service.
We store the AI-generated reports, checklists, and spreadsheets created on your behalf so that you can access them later through your account dashboard, subject to the plan history limits of your subscription tier.
We use the information described above to:
We do not use your User Health Data to make any medical, insurance, employment, or credit decisions, and we do not sell your User Health Data to advertisers, data brokers, or any third party for their own marketing purposes.
We share information only as necessary to operate the Service, with the following categories of third-party service providers, each of which is contractually or technically limited to using your data solely to provide their service to us:
| Provider | Purpose | Data Shared |
|---|---|---|
| Authentication (sign-in) | Name, email, profile picture | |
| Anthropic | AI processing to generate your reports | The User Health Data and survey responses needed to generate your specific report |
| Supabase | Database and data storage infrastructure | All account and User Health Data necessary to operate your account |
| Stripe | Payment processing and subscription billing | Billing contact information and payment details (collected directly by Stripe) |
We may also disclose information: (a) if required by law, subpoena, or other legal process; (b) to protect the rights, property, or safety of Limitless, our users, or the public; (c) in connection with a merger, acquisition, financing, or sale of all or part of our business, in which case your information may be transferred as a business asset, subject to this Policy or a successor policy of materially similar protection; or (d) with your explicit consent.
We do not sell your personal information, as that term is defined under applicable U.S. state privacy laws (such as the CCPA), and we do not share it for cross-context behavioral advertising.
When you submit User Health Data to generate a report, relevant portions of that data are transmitted to Anthropic's Claude API to produce your Generated Content. This processing occurs via Anthropic's commercial API, which, per Anthropic's standard API terms, does not use API inputs or outputs to train its models. We do not control Anthropic's infrastructure directly, and your use of the Service constitutes acknowledgment that this transmission occurs as a necessary part of generating your reports.
We retain your account information and User Health Data for as long as your account remains active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. If you delete your account, we will delete or de-identify your personal information and User Health Data within a commercially reasonable period, except where retention is required by law (for example, billing records required for tax or accounting purposes) or necessary for the purposes described in this Policy.
We use industry-standard administrative, technical, and physical safeguards designed to protect your information, including encrypted data transmission (TLS), access controls limiting who can view your data, and reliance on reputable infrastructure providers (Supabase, Stripe, Google, Anthropic) that maintain their own security programs. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security of your information.
You may access, update, or correct your account and User Health Data at any time through your account dashboard. You may request deletion of your account and associated data by contacting us at privacy@golimitless.app, or through account settings if available. We will honor deletion requests within a reasonable time, subject to the retention exceptions described in Section 6.
Depending on your state of residence, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA/CPRA) and similar state privacy statutes, including the right to know what personal information we collect, the right to request deletion, the right to correct inaccurate information, and the right to non-discrimination for exercising these rights. To exercise these rights, contact us at privacy@golimitless.app. We will verify your identity before fulfilling your request.
Some states (such as Washington's My Health My Data Act and similar laws elsewhere) provide specific rights regarding consumer health data. Where applicable, you have the right to withdraw your consent to our collection and processing of your health data at any time by deleting your account, and the right to request a list of third parties with whom we have shared your health data, which is set out in Section 4 of this Policy.
Limitless is a direct-to-consumer wellness application and is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). HIPAA's protections generally apply to traditional healthcare providers, health plans, and their business associates, and do not apply to the data you submit directly to Limitless as a consumer wellness product. We nonetheless apply meaningful safeguards to your User Health Data as described in this Policy.
The Service is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
The Service is operated from the United States, and your information will be processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your jurisdiction.
We use essential cookies and similar local storage technologies necessary to keep you signed in and to operate the Service. We do not currently use third-party advertising or tracking cookies. If this changes, we will update this Policy accordingly.
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by posting a notice on the Service or updating the "Last updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
If you have questions about this Privacy Policy or wish to exercise any of your rights, contact us at privacy@golimitless.app.