TEMPLATE DOCUMENTS — FOR PRODUCT AND DEMO PURPOSES ONLY. These documents have not been reviewed or finalized by qualified legal counsel. They MUST be reviewed, customized, and approved by a licensed attorney before use in any production environment or with real users. Nothing in these pages constitutes legal advice.

Privacy Policy

Last updated: June 17, 2026

Effective date: June 17, 2026

1. Introduction / Who We Are / Scope

This Privacy Policy (“Policy”) describes how CREBRAL AI, LLC, a Florida limited liability company operating under the trade name Crebral Health (“Crebral Health,” “we,” “us,” or “our”), collects, uses, discloses, and protects information about you when you access or use our platform, website, and related services (collectively, the “Services”).

Scope — what this Policy covers: This Policy applies to Personal Information we collect about Practitioners, authorized staff, and website visitors in our role as a data controller. It applies to information collected through our website, marketing pages, account-registration flows, and sales communications.

What this Policy does NOT cover — PHI processed as a Business Associate: When a Covered Entity Practitioner submits Protected Health Information (PHI) about their patients through the Platform, Crebral Health processes that PHI as a Business Associate under HIPAA pursuant to a Business Associate Agreement (BAA) executed with that Practitioner. PHI processed under a BAA is governed by that BAA and by the Practitioner’s own Notice of Privacy Practices — not by this Policy. Patients whose data has been submitted by a Practitioner should consult their Practitioner’s Notice of Privacy Practices for information about how their health information is used and protected.

2. Definitions

Personal Information
Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual.
PHI
Protected Health Information as defined under HIPAA, 45 C.F.R. Parts 160 and 164.
Consumer Health Data
Personal information that identifies or is reasonably linkable to a consumer and that a regulated entity collects, processes, shares, or sells in connection with a consumer's physical or mental health. Includes data regulated under the Washington My Health My Data Act (WMHMDA) and analogous state statutes.
Sensitive Personal Information
A subset of Personal Information that receives heightened protection under applicable law, including health and medical information, precise geolocation data, racial or ethnic origin, biometric data, and financial information.
De-Identified Data
Data that has been processed such that it no longer identifies or can reasonably be used to identify an individual, in accordance with HIPAA Safe Harbor (45 C.F.R. § 164.514(b)) or Expert Determination methods, or the applicable de-identification standard under state law.
Practitioner
A licensed healthcare or wellness professional who subscribes to the Platform in a professional capacity.
Client / Patient
A patient or client whose health and biomarker data a Practitioner submits to the Platform.
Business Associate
An entity that performs certain functions or activities involving the use or disclosure of PHI on behalf of a Covered Entity, as defined at 45 C.F.R. § 160.103.

3. What Information We Collect

3.1 Information You Provide Directly

  • Account information: Name, email address, phone number, practice name, mailing address, username, and password when you register for an account.
  • Professional credentials: License numbers, specialty, state(s) of licensure, and other credentials required to verify your eligibility to use the Platform.
  • Payment information: Billing address, credit or debit card details (or other payment method details), processed by our payment processor. Crebral Health does not store raw payment card numbers.
  • Biomarker and patient data: Laboratory results, biological-age clock reports, epigenetic data, and other health information you upload on behalf of your patients. Where you are a Covered Entity, this data constitutes PHI and is governed by your BAA.
  • Communications: Support requests, feedback, survey responses, and any other communications you send to us.

3.2 Information Collected Automatically

  • Usage logs: Pages visited, features accessed, timestamps, session duration, and actions taken within the Platform.
  • Device and technical information: IP address, browser type and version, operating system, device identifiers, and referring URL.
  • Cookies and tracking technologies: As described in our Cookie Policy, available at crebral.ai/cookies. Note that marketing and analytics cookies are blocked on authenticated platform pages.

3.3 Information from Third Parties

  • Laboratory integrations: When you connect a laboratory service (e.g., Rupa Health, Quest, LabCorp), we receive the laboratory results you authorize for import into your patient records.
  • EHR/EMR integrations: Where you authorize integration with an electronic health record system, we may receive patient demographic and clinical data as permitted by that integration.
  • Biological-age clock providers: Epigenetic and biological-age clock reports received via connected third-party providers.

4. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Services: Process your account registration, generate AI-Generated Output, run clinic workflow features, and fulfill your subscription.
  • Platform improvement and analytics: Understand usage patterns, troubleshoot issues, improve features, and develop new Services using aggregated and De-Identified Data.
  • Security and fraud prevention: Detect, investigate, and prevent fraudulent, unauthorized, or malicious activity, and protect the integrity of the Platform.
  • Legal compliance: Comply with applicable laws, regulations, court orders, and legal processes, including HIPAA obligations.
  • Communications: Send transactional emails (account confirmations, billing notices, security alerts) and, where you have opted in, product updates and marketing communications.

AI Training Data Use — Important Limitation

CREBRAL HEALTH WILL NOT USE PERSONAL INFORMATION, PHI, OR PATIENT BIOMARKER DATA TO TRAIN, FINE-TUNE, BENCHMARK, OR OTHERWISE DEVELOP ANY ARTIFICIAL-INTELLIGENCE OR MACHINE-LEARNING MODEL WITHOUT YOUR EXPLICIT, SEPARATE WRITTEN CONSENT. Only HIPAA-compliant De-Identified Data (processed in accordance with the Safe Harbor method under 45 C.F.R. § 164.514(b) or the Expert Determination method under 45 C.F.R. § 164.514(b)(1)) may be used to improve our algorithms and Services. No automated decisions with a legal or similarly significant effect on individuals will be made solely by automated means without human review.

5. How We Share / Disclose Your Information

We do not sell your Personal Information. We share information only in the following circumstances:

  • Service providers and subprocessors: We share information with vendors and subprocessors that provide cloud infrastructure, AI model APIs, payment processing, email delivery, customer support, and analytics, under data-processing agreements that restrict their use of the data. See Section 13 for details.
  • Healthcare ecosystem partners: We share information with laboratory networks, EHR systems, and biological-age clock providers you have authorized to integrate with your account, solely to provide the corresponding integration service.
  • Legal requirements and protection of rights: We may disclose information when required by law, court order, subpoena, or government request; to investigate fraud or security threats; or to protect the rights, property, or safety of Crebral Health, our users, or the public.
  • Business transfers: If Crebral Health is involved in a merger, acquisition, financing, or sale of substantially all of its assets, your information may be transferred to the acquirer, subject to equivalent privacy protections. We will notify you of any such change of control.
  • Aggregated and de-identified data: We may share De-Identified Data and aggregated statistics with research partners, academic institutions, or in publications, in a form that cannot reasonably be used to identify you or your patients.

WE NEVER SHARE HEALTH DATA, BIOMARKER DATA, OR PATIENT INFORMATION FOR ADVERTISING PURPOSES, OR WITH DATA BROKERS, AD NETWORKS, OR MARKETING PLATFORMS.

6. HIPAA and PHI

Crebral Health acts as a Business Associate (45 C.F.R. § 160.103) with respect to PHI submitted by Covered Entity Practitioners. PHI processing is governed exclusively by the BAA executed between Crebral Health and the relevant Covered Entity Practitioner, and by HIPAA and applicable state medical-record laws.

This Policy does NOT govern PHI processed for Covered Entities as Business Associate. Patients whose PHI is processed through the Platform should refer to their Practitioner’s Notice of Privacy Practices for information about their rights under HIPAA (including rights to access, amend, and receive an accounting of disclosures of their PHI).

Not all data processed through the Platform constitutes PHI under HIPAA. For example, Practitioner account registration data, payment data, and certain practice-management records may not be PHI even if they relate to health services.

7. Consumer Health Data (Washington My Health My Data Act / Nevada SB 370)

Certain data we process — including biomarker data, biological-age estimates, and health information associated with identifiable individuals in Washington State, Nevada, and comparable jurisdictions — may constitute “Consumer Health Data” (or “consumer health information”) under the Washington My Health My Data Act (WMHMDA, RCW 19.373) and/or Nevada SB 370.

Categories of Consumer Health Data We Process

We may process Consumer Health Data in the following categories as submitted by Practitioners: laboratory and bloodwork results; biological-age clock estimates; body composition and vital sign data; health history information uploaded for program development; and other biomarker data submitted for longevity-program generation.

Purposes

Consumer Health Data is processed solely to provide the Services requested by the Practitioner, to operate and improve the Platform (using De-Identified Data only), and to comply with applicable law. We do not collect, share, or sell Consumer Health Data for advertising purposes.

Consumer Rights Under WMHMDA and Analogous Laws

To the extent applicable law grants individuals rights with respect to Consumer Health Data that Crebral Health controls, you (or, where patient data is involved, the patient through their Practitioner) may have the right to:

  • Know what Consumer Health Data we have collected about you;
  • Access a copy of your Consumer Health Data;
  • Withdraw consent to our collection or sharing of Consumer Health Data; and
  • Request deletion of Consumer Health Data.

To exercise these rights, contact us at team@Crebral.ai. We will respond within the timeframes required by applicable law and will not discriminate against you for exercising your rights. Note: where Consumer Health Data constitutes PHI governed by a BAA, your rights are governed by HIPAA and the BAA rather than this section.

8. International Data Transfers / GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional terms apply to our processing of your Personal Information.

Legal Bases for Processing

We process your Personal Information under the following legal bases (GDPR Art. 6):

  • Contract (Art. 6(1)(b)): Processing necessary to perform our contract with you (e.g., providing the Services, managing your subscription);
  • Legitimate Interests (Art. 6(1)(f)): Processing for security, fraud prevention, platform improvement, and direct marketing to Practitioner accounts (where overridden interests are not present);
  • Legal Obligation (Art. 6(1)(c)): Processing required by applicable law; and
  • Consent (Art. 6(1)(a)): For marketing communications and certain cookie placements where consent is required.

Where we process Special Categories of Personal Data (including health data) under GDPR Article 9, we rely on explicit consent (Art. 9(2)(a)) or, where applicable, on the basis that processing is necessary for the provision of health care or treatment (Art. 9(2)(h)), subject to appropriate safeguards.

Data Transfers

We are based in the United States. If you access the Services from the EEA or UK, your Personal Information may be transferred to and processed in the U.S. or other countries. We use EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework (DPF) to safeguard such transfers. Copies of applicable transfer mechanisms are available upon request to team@Crebral.ai.

Data Subject Rights

EEA and UK individuals have the right to access, rectify, erase, restrict processing of, and port their Personal Information, and to object to processing based on legitimate interests. You may also lodge a complaint with your local supervisory authority. To exercise these rights, contact team@Crebral.ai.

9. U.S. State Privacy Rights

Residents of California, Colorado, Connecticut, Virginia, Texas, Washington, Nevada, and other states with comprehensive privacy laws may have the following rights with respect to their Personal Information:

  • Right to Know / Access: The categories and specific pieces of Personal Information we have collected about you;
  • Right to Correct: Request correction of inaccurate Personal Information;
  • Right to Delete: Request deletion of your Personal Information, subject to certain exceptions;
  • Right to Opt Out of Sale or Sharing: Opt out of the sale or sharing of Personal Information for cross-context behavioral advertising. Crebral Health does not sell Personal Information and does not share Consumer Health Data for cross-context behavioral advertising;
  • Right to Limit Use of Sensitive Personal Information: Limit our use of Sensitive Personal Information to purposes permitted by applicable law; and
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.

To submit a privacy request, contact team@Crebral.ai or 1925 Trade Center Way, Suite 2, Naples, FL 34109. We will respond within forty-five (45) days of receipt of a verifiable request, which we may extend by an additional forty-five (45) days (ninety (90) days total) where reasonably necessary. California residents may designate an authorized agent to submit requests on their behalf; we may require verification of the agent’s authority. If we deny your request, you may appeal by contacting us at the same address with the subject line “Privacy Rights Appeal.”

The California Consumer Privacy Act (CCPA/CPRA) and analogous state statutes may not apply to PHI regulated by HIPAA or to de-identified information. To the extent state privacy rights overlap with HIPAA, HIPAA and the BAA will govern.

10. Data Retention

  • PHI: Retained for the period required by HIPAA and applicable state medical-record retention laws, typically six (6) to ten (10) years from the date of the last service or as required by your state (up to the minor’s age of majority plus applicable years for pediatric records), unless your BAA provides otherwise.
  • Non-PHI account and operational data: Retained for the duration of your active subscription plus seven (7) years thereafter to fulfill legal and contractual obligations, unless you request deletion earlier and deletion is not prohibited by applicable law.
  • De-Identified Data: May be retained indefinitely, as it no longer constitutes Personal Information.
  • Backups: Backup copies of deleted data are typically purged within approximately six (6) months of deletion from active systems, consistent with our backup rotation schedule.

11. Data Security

We implement administrative, technical, and physical safeguards designed to protect your information against unauthorized access, use, alteration, or destruction. These measures include:

  • Encryption of data at rest and in transit using industry-standard protocols (AES-256 and TLS 1.2+);
  • Role-based access controls limiting access to data to authorized personnel with a legitimate need;
  • Regular security assessments, penetration testing, and vulnerability management;
  • Incident response procedures, including breach notification in compliance with HIPAA and applicable state data-breach laws; and
  • Compliance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) with respect to PHI processed under a BAA.

No security system is impenetrable. We cannot guarantee the absolute security of information transmitted to or stored on the Platform. You are responsible for maintaining the security of your account credentials and for promptly notifying us of any suspected security breach.

12. Your Rights and Choices

In addition to the state-specific rights described in Sections 7–9, all users may:

  • Access and update their account information through the Platform’s account settings;
  • Opt out of marketing emails by clicking the “unsubscribe” link in any marketing email or by contacting team@Crebral.ai — note that you cannot opt out of transactional or account-related communications;
  • Manage cookie preferences as described in our Cookie Policy; and
  • Request deletion of your account and associated data by contacting team@Crebral.ai, subject to our data retention obligations.

If you wish to appeal a decision we have made regarding your privacy rights request, please contact team@Crebral.ai with the subject line “Privacy Rights Appeal.” EEA and UK residents may also escalate to their local supervisory authority.

13. Subprocessors / Service Providers

We engage the following categories of subprocessors and service providers to help us deliver the Services:

  • Cloud infrastructure (with BAA): Our primary cloud hosting provider(s) execute a BAA with us for services involving PHI. Data is stored in U.S.-based data centers.
  • AI model provider(s): We use third-party large-language-model API providers to generate AI-Generated Output. Patient-submitted data, including biomarker data and PHI, may transit these APIs. We execute appropriate data processing agreements (and, where applicable, BAAs) with these providers and prohibit them from using submitted data to train their models. Users should be aware of this processing when submitting patient data.
  • Payment processor: We use a PCI-DSS-compliant third-party payment processor. We do not store raw payment card numbers.
  • Analytics providers: For aggregated, non-PHI platform analytics. Analytics cookies are blocked on authenticated platform pages.
  • Email delivery provider: For transactional and marketing email delivery.
  • Customer support tools: For managing support tickets and communications.

A current list of subprocessors is available at crebral.ai/subprocessors. We will provide at least thirty (30) days’ advance notice of the addition of new subprocessors that may process PHI or Sensitive Personal Information (by email or Platform notification), giving you the opportunity to object or terminate if the new subprocessor is unacceptable.

14. Children’s Privacy

The Platform is designed for use by licensed healthcare professionals and is not directed to children under the age of 13 (or such higher age as may be required by applicable law). We do not knowingly collect Personal Information directly from children under 13. If you are a Practitioner who submits health information about minor patients, such data is processed as PHI under the applicable BAA and is subject to applicable state minor-patient privacy laws, including those governing parental access to minors’ medical records.

If we become aware that we have inadvertently collected Personal Information directly from a child under 13, we will promptly take steps to delete such information.

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, legal requirements, or the Services. When we make material changes, we will notify you by email or by a prominent notice on the Platform at least thirty (30) days before the changes take effect (or a shorter period where required by law). The “Last updated” date at the top of this Policy reflects the most recent revision. Your continued use of the Services after the effective date of any update constitutes your acceptance of the revised Policy. If you do not accept the revised Policy, you must stop using the Services.

16. Contact and DPO Information

If you have questions or concerns about this Policy or our data practices, please contact:

Privacy Contact: team@Crebral.ai

Mailing Address: CREBRAL AI, LLC, 1925 Trade Center Way, Suite 2, Naples, FL 34109

EU / UK Representative: Crebral Health is a United States company that directs its Services to practitioners located in the United States. We do not target, market, or offer the Services to individuals in the European Economic Area (EEA) or the United Kingdom, and the Services are not intended for use by EEA or UK residents. Accordingly, we have not appointed a Data Protection Officer or an EU/UK representative under GDPR Article 27. If our practices change, we will update this Policy and appoint a representative where required.

Supervisory Authority Rights: If you are located in the EEA or UK and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or the relevant EU data protection authority).

17. AI and Automated Decision-Making

The Platform uses automated algorithms and artificial intelligence to generate longevity program drafts, evidence grades, and biomarker analyses. These automated processes assist Practitioners but do not make final clinical decisions — all AI-Generated Output is reviewed and approved (or rejected) by the Practitioner before it affects patient care.

Under GDPR Article 22, individuals have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Crebral Health does not make such automated decisions about patients directly — the Practitioner exercises human review and clinical judgment over all AI-Generated Output before it influences care. If you believe an automated decision has been made about you in a manner that produces significant effects and you wish to exercise your Art. 22 rights, please contact team@Crebral.ai.

We monitor developments in the EU AI Act and applicable AI regulations and will update our practices and disclosures as obligations under those frameworks become applicable.