Privacy Policy

In force as of September 20, 2026

You talk about your health goals with the My longevity roadmap AI assistant: you deserve to know what we do with them. This page says what is recorded, by whom, where, and what is not in place yet.

1. Data controller

Victori SAS, a French simplified joint-stock company registered with the RCS under number 101259034, registered office at 60 rue François Ier, 75008 Paris, France.

Contact for any question or request about your data: hello@mylongevityroadmap.com.

2. What we record

  • Your conversation with the AI assistant: the text of your messages and the answers received, kept by our API to hold the thread of the exchange.
  • The profile worked out from the conversation: goal, budget tier, and where applicable the sex and constraints you mention, as well as the last plan computed.
  • Your age band: asked at the start of the plan, before any other question. It serves two things: attesting that you are an adult — the service is for adults only (terms of use, section 4) — and adjusting your plan, some levers not applying to every age. It is a band and nothing more: never your exact age, never your date of birth. If you say you are under 18, no plan is built, no conversation is created and nothing is recorded, not even that answer.
  • Your account, if you create one: e-mail address, name if you fill it in, session elements, and, when the sign-up form collects it, the date on which you accepted the terms of use. This data is held by our authentication provider, not in our database. Our database keeps a single thing: the opaque identifier of your account, set on your plans so that you find them again from one visit and one device to the next.
  • Your "emails" setting, if you answer it: whether you accept receiving our e-mails or not, and the date on which you said so. It is set from your account, "Emails" tab, and it is only ever written by our servers: your browser cannot change it. As long as you have not answered, the answer is no. This setting is held on your account, at our authentication provider's, not in our database.
  • The share link, if you create one: a randomly drawn value and the date you created it, set on the plan concerned. Nothing else, and above all nothing about the people who open that link. The details are in section 8.
  • Technical logs: IP address, browser type, request timestamps, produced by the servers that serve the site, for security and diagnostic purposes.
  • Audience measurement: the pages viewed, the page you arrive from, the technical characteristics of your browser, four steps of building a plan (the chosen goal, the computed plan, its saving into an account, and where you stop if you leave before) and four steps of the introduction to a professional, which carry the professional's identifier and not yours. These events are not in our database: they go to PostHog, with no cookie and no data placed on your device. The details are in section 9.

Without an account, a conversation is attached to no one. It can only be reached by its identifier, held by the single tab that opened it, and nothing ties it to another conversation.

With an account, it carries that account's identifier : that is what lets you find your past plans. Your e-mail and your name, on the other hand, are never passed along with your messages. A conversation started while signed out attaches to your account if you sign in while it is open; that attachment is what makes it appear in your recent plans, and it changes how long it is kept (section 7).

3. Health data, given without being asked

We do not ask you for any health data. But a freely written constraint ("fragile right knee") or a sentence in the conversation is health data, and we treat it as such. It is the only place in the service where this kind of data can appear.

By entering it, you explicitly consent to its processing to run the AI assistant (article 9.2.a of the GDPR). You can withdraw that consent at any time by asking for the conversation to be deleted. And you can simply not write any: the service works without it.

Because this data can appear, the database is hosted within a perimeter certified HDS (health data host).

4. Why, and on what legal basis

  • Running the AI assistant and computing your plan : performance of the terms of use you accept by using the service.
  • Processing the health data you write : your explicit consent.
  • Checking that the service is open to you, through your age band : performance of the same terms, which restrict it to adults. The same answer then adjusts your plan.
  • Managing your account, if you create one: performance of the same terms.
  • Publishing a plan behind a link, when you ask for it: performance of the same terms. Nothing is published without that request, and you can undo it (section 8).
  • Sending you our e-mails, if you asked for them in the "Emails" tab of your account: your consent, which you withdraw in the same place, in one click, with no justification to give. Without that yes, nothing goes out.
  • Securing the service and diagnosing outages : our legitimate interest in it staying available and unabused.
  • Measuring the site's audience : our legitimate interest in knowing which pages are read and by how many visitors, in a way that places nothing on your device and does not identify you.

We neither sell nor rent your data, and we do not pass it to anyone for advertising purposes. The only commercial e-mails you may receive are ours, after a yes given in the "Emails" tab, and they are never built from what you wrote in your conversations.

5. Who receives it

  • Scalingo SAS (France): hosting of the API and the database, in the Paris region, on 3DS Outscale infrastructure, within the HDS perimeter. The database is not exposed on the Internet and connections to it are encrypted.
  • Google Cloud (Vertex AI) : the model that writes the AI assistant's answers, called in the europe-west9 region (Paris). See the next section.
  • Clerk, Inc. (United States): authentication and account management, if you create one.
  • Salesforce, Inc. (Heroku): hosting of the web server that serves you the pages. It relays requests to the API and keeps no conversation.
  • PostHog, Inc. : audience measurement. The project is hosted on PostHog's European cloud, in Frankfurt (Germany), and the events stay there. Our code refuses to measure if the configured ingestion host is not that one: it is not an intention, it is a condition checked when the site is built.

Clerk and Salesforce are American companies: these transfers are governed by the European Commission's standard contractual clauses and/or the EU–US Data Privacy Framework. PostHog, Inc. is American too, but the audience-measurement events are stored and processed in its European cloud; its staff can access them to operate the service, like the providers above. The content of your conversations, for its part, stays hosted in France.

6. The AI model and non-retention

Your messages are sent to Vertex AI so the AI assistant can answer them. Processing takes place in the europe-west9 region (Paris): the region is set explicitly and validated when the API starts against a list of European Union regions, which refuses to start with a non-EU region.

Your conversations are not used to train any model. However, the formal "zero data retention" agreement with Google for our project has been requested and is not yet granted: until then, Google may temporarily keep requests for its abuse detection. We will update this page as soon as the agreement is in place, and in the meantime we invite you not to write health details you would rather not share.

7. How long

A conversation is deleted after a period of inactivity, and that deletion is automatic: a job runs every day and erases whatever has passed the deadline. The count starts from your last activity on the conversation, not from its creation: as long as you come back to it, it stays. Simply re-reading it is enough, you do not need to write in it.

  • Conversation without an account: 3 months. It can only be reached by its identifier, held by the tab that opened it: once that tab is closed, nobody can read it any more, including you. Keeping it for years would serve no one and would leave what you wrote lying dormant.
  • Conversation attached to an account: 3 years. It is the history you come back to read, and a longevity plan is judged over years. After 3 years untouched, it goes too.
  • Messages follow their conversation, in the same deletion: the text of your exchanges and the profile worked out from it disappear together.
  • Account: kept as long as the account exists, deleted at our authentication provider's when you delete it. Deleting your account does not by itself erase your conversations: they stop being accessible from the service and are erased at the end of the 3 years. If you want them deleted right away, ask us before deleting the account, at the address in section 10.
  • The acceptance of the terms of use: kept as long as the account, at our authentication provider's, and deleted with it.
  • The "emails" setting: kept the same way, as long as the account. A withdrawal replaces the yes, with its date: we keep your current position, not the history of your changes of mind.
  • Technical logs: kept a few days by the hosts, then overwritten.
  • Audience-measurement events: kept at PostHog. They carry no identifier that designates you: the technical fingerprint used to count visitors is recomputed every day with a random value discarded afterwards, so nothing ties yesterday's events to today's, or to you.

You can ask for your data to be deleted at any time: see section 10.

8. If you share a plan

A plan's menu offers to share it. That creates a link, and that link opens a page readable by anyone who has it, with no account and no password. It is the only thing in the service that lets your data out of your sole access, and it only triggers if you ask for it.

  • The page shows the plan, never the conversation. The board, its introduction and the suggested next steps. Neither your messages, nor the AI assistant's, nor your age, nor your constraints, nor anything you wrote about yourself: what the thread carries does not travel with the link.
  • The address cannot be guessed. It contains a randomly drawn value, long enough that nobody lands on it by trying. But a link is a link: whoever receives it can pass it on, and we have no way to stop them.
  • The page is not indexed by search engines. It would become findable if you pasted the link on a public page, though: it is that page that would become findable.
  • You cut the link whenever you want, from the same menu. It stops working at once, and we keep nothing of it. A new share will produce another address, never the old one. What has already been read or copied, on the other hand, does not come back.
  • We record nothing about readers: no visit counter, no consultation dates, no origin. So we cannot tell you who opened your link, or how many times.
  • Sharing does not extend retention. The plan is erased at its usual deadline (section 7), and its link disappears with it. A link left open in someone else's tab keeps nothing alive.

Deleting the plan deletes its link too. And if you hesitate, the simple rule is this one: only share a plan with people you would agree to show it to — a healthcare professional, someone close to you.

9. Cookies and audience measurement

The service only places cookies strictly necessary to how it works: those of your session if you sign in, and those that protect the forms. They do not require consent.

We measure the site's audience with PostHog, on its European cloud (Frankfurt, Germany), and in cookieless mode: nothing is written on your device, no cookie, no local storage, no session storage. That is why no banner asks for your agreement: there is neither placement nor reading in your browser to authorise. We preferred to do without the question rather than ask it of you.

What is sent, on each page view: the address of the page, the one you come from, the language, the timezone and the dimensions of your browser, its type and that of your system. Your IP address necessarily arrives with the request; PostHog uses it, with the browser type and the site name, to compute on its servers a fingerprint of the day that lets visitors be counted without being recognised. The random value that goes into that calculation changes every day and is deleted, so two visits separated by a night are not tied together. PostHog also works out your country from it, approximately.

What is sent on top of page views: fifteen events, and only fifteen. Four say where one stops in building a plan, eleven say what happens around the introduction to a professional. They only carry values picked one by one, never text.

Building a plan:

  • The chosen goal: which of the catalog's nine goals, and whether you took it from a card or wrote it yourself. Not what you wrote.
  • The computed plan: the goal, the budget tier, the age band you attested, how long the computation took, and whether it succeeded or failed.
  • The saved plan: the fact that a plan has just joined an account. Not which one, not whose.
  • Where you leave: the last step reached when you close the tab (the home page, the goal, the age, the budget, the plan, the conversation) and the number of messages sent. Never their content.

The introduction to a professional:

  • The professional's card was presented to you: once per plan and per tab, with the identifier of the professional concerned.
  • You started the payment, and you came back without paying: two distinct events, the first with the professional's identifier, the second with nothing else.
  • The payment succeeded and the contact details were revealed to you: the professional's identifier. Neither the amount, nor the payment reference, nor anything coming from Stripe.
  • You opened the "I'm interested" step, and you closed it without paying: two distinct events, the first with the professional's identifier, the second with nothing else.
  • You told us your area: your department and how you would like to be supported (in person, video call, either). Never your town, which stays on our servers and does not go into audience measurement: in a village, a town and a health goal name someone. Never an address either, and the service does not ask your browser for your position.
  • The search result: one of three cases — someone near you, nobody near you but someone by video, or nobody. Nothing but the case itself.
  • You asked to be notified when a professional opens near you: your department, and it alone. Your e-mail address arrives elsewhere, to write to you, and never goes into audience measurement.

The identifier in these events designates the professional, not you: it is the short name of their profile in our directory, the one already in their photo's address. We use it to know which profiles draw interest, and how often a presented card converts.

These eight events exist to see where the plan breaks: a plan that takes too long to arrive, a question that puts people off, a step nobody crosses, a card nobody opens. That is what we preferred over recording your screen, which PostHog can do and which we do not enable.

What is never sent, and that is the point that matters here:

  • The content of your conversations. Neither your messages, nor the AI assistant's answers, nor the profile worked out from them. Not even a goal you phrased yourself: only the catalog category it attaches to goes out. An event only carries the page address or the values listed above.
  • Your identity. Even signed in, neither your e-mail nor your account identifier is passed to PostHog, and measurement is never tied to an account.
  • Your clicks and the text of the clicked elements. Automatic interaction capture is disabled, precisely because on this screen the clicked text would be a piece of your conversation.
  • No recording of your screen, no heatmap, no survey, no error report. All of that is switched off in the site's code, not merely unticked in an admin console: PostHog cannot switch it back on remotely.

We use no advertising cookie, no third-party tracker, and these measurements only serve to know which pages are read and where the plan stops. They are neither resold nor crossed with other data. Since nothing in them designates you, we cannot find "your" events to delete them either: that is the trade-off of not identifying you.

10. Your rights

You hold the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw your consent. To exercise them, write to hello@mylongevityroadmap.com. We answer within one month.

If you have an account, write to us from its e-mail address: your plans are attached to it, we will find them and delete them all.

An honest limit on conversations held without an account : nothing ties them to your identity, so we cannot find them from it. In your request, tell us the approximate date and the goal you chose, so that we can identify them. That is the trade-off of asking nothing of you to use the service, and failing that the automatic 3-month deletion takes care of it.

You can also lodge a complaint with the CNIL: www.cnil.fr.

11. Security

Exchanges are encrypted in transit (TLS). The database can only be reached from the host's private network, with TLS mandatory. The browser never talks directly to our API: it goes through our server, the sole holder of the access key, which therefore never leaves the server.

12. Changes

This policy will change with the service. What is new in this version is sharing a plan by link (section 8), which makes possible, at your request alone, what previous versions ruled out: a plan being readable by someone other than you. The retention period is fixed and enforced (section 7); the point still open is non-retention on the model side (section 6). The effective date shown at the top of the page indicates the current version.

13. Contact

For any question about this policy or about your data: hello@mylongevityroadmap.com.