Privacy Policy

Last updated: July 13, 2026

Developer notice: set NEXT_PUBLIC_LEGAL_ENTITY_NAME, NEXT_PUBLIC_SUPPORT_EMAIL, and NEXT_PUBLIC_GOVERNING_STATE before a paid public launch. Have counsel review these documents.

1. Overview

This Privacy Policy explains how Enhanced AI (“we,” “us”) collects, uses, and shares information when you use the Service operated by [Your Company LLC].

Some preferences and session flags may be stored in your browser (for example localStorage or sessionStorage) in addition to account data we store on our servers.

2. Information we may collect

Account information: name, email, and credentials when authentication is enabled.

Usage data: pages visited, feature use, device/browser type, and approximate location derived from IP when hosted.

Health-adjacent data you choose to provide: protocol logs, compound notes, lab values/uploads, chat messages, goals, and forum content. Treat this as sensitive.

Age confirmation: a local preference that you confirmed you are 18 or older.

Communications: messages you send to support at support@enhancedai.example.

Payment data: processed by third-party processors when real billing is enabled; we typically do not store full card numbers.

3. How we use information

To operate and improve the Service (chat, protocol, labs, forum, subscriptions).

To personalize AI context when you opt to share protocol or lab data.

To enforce Terms, Acceptable Use, age requirements, and security.

To process payments when real billing is enabled.

To comply with law when required.

To create de-identified or aggregated insights that do not identify you.

4. AI processing

When a live AI provider is connected, prompts and context you provide (including chat and optionally protocol/labs) may be sent to third-party model providers under their terms and privacy policies.

Do not submit information you are not willing to share with those processors. Avoid including identifiers or unnecessary personal details in prompts.

Enhanced AI is not a HIPAA covered entity or business associate. Information you submit is not treated as protected health information under HIPAA.

5. Sharing

We do not sell your personal information.

We may share data with service providers (hosting, analytics, payment, AI APIs) who process data on our behalf.

We may disclose information if required by law or to protect rights, safety, and the integrity of the Service.

Forum content you post is visible to other users as designed.

Business transfers: information may transfer as described in the Terms.

6. Retention and security

We retain information as long as needed to provide the Service and meet legal obligations. Prototype/local data may clear when you clear browser storage or refresh in-memory state.

We use reasonable safeguards appropriate to the stage of the product. No method of transmission or storage is 100% secure.

7. Children

The Service is for users 18+. We do not knowingly collect personal information from anyone under 18.

8. Your choices and rights

You can delete your account in Settings → Delete account (password + typing DELETE). That removes your Firebase Auth user, associated Firestore data we store for the account, and cancels active Stripe subscriptions when Stripe is configured. Some local browser flags can also be cleared via browser storage settings.

Where required by law, you may have additional rights to access, correct, or delete personal data — contact support@enhancedai.example.

9. Changes and contact

We may update this Policy and will revise the “Last updated” date. Contact: support@enhancedai.example. Operator: [Your Company LLC].