Patient Portal & App Privacy Policy
Effective date: October 7, 2026 · Last updated: October 7, 2026
This policy explains how RENEWL Longevity, LLC (“RENEWL,” “we,” “us”) collects, uses, protects and shares information — including health information — when you use the RENEWL patient portal and the RENEWL mobile app. It supplements our general Website Privacy Policy; where the two differ for the portal or app, this policy controls.
Contents
- Scope
- Health information & HIPAA
- Information we collect
- Device permissions
- Apple Health
- How we use information
- Advertising, analytics & tracking
- How we share information
- Messages, texts & notifications
- Security
- Retention & account deletion
- Your rights & choices
- State health-data rights
- Breach notification
- Children & proxy access
- Changes
- Contact us
1. Scope
This policy applies to:
- The RENEWL patient portal, available at app.renewllongevity.com, where you can schedule visits, complete intake forms, view results and message your care team; and
- The RENEWL Patient App for iOS, available on the Apple App Store.
Together we call these the “Patient Services.” This policy does not cover third-party apps, websites or services you choose to connect or visit, which have their own privacy policies.
2. Health Information & HIPAA
RENEWL is a direct-pay wellness and longevity practice. Because we do not bill health insurance electronically, we may not be a “covered entity” under the Health Insurance Portability and Accountability Act (HIPAA). Regardless of that status, we treat the health information in the Patient Services as confidential and protect it with safeguards aligned with HIPAA’s privacy and security principles.
If our status changes — for example, if we begin billing insurance electronically — we will provide a Notice of Privacy Practices, and that notice will govern our use and disclosure of your protected health information. Health information in the Patient Services is also protected by applicable state law and, where it applies, the Federal Trade Commission’s Health Breach Notification Rule.
3. Information We Collect
Account and identity information
- Name, date of birth, sex, email address, mobile number, mailing address, and emergency contact.
- Login credentials. Passwords are stored only in hashed form; we cannot see them.
Health information you provide
- Intake and medical-history forms: conditions, surgeries, medications, supplements, allergies, family history, lifestyle information, and your health goals.
- A photo of your government-issued ID, if you choose to upload it for identity and prescription verification.
- Consent forms and signatures.
Health information created through your care
- Lab results and diagnostic results (such as DEXA, VO₂ max and other testing), which you can view in the app.
- Your treatment protocols and care plans, visit notes, and prescriptions.
- Upcoming appointments, appointment history, and treatment records.
Messages
- Secure messages, attachments and requests you exchange with your care team in the portal or app.
Payment information
- Billing name, address and transaction history. Card details are collected and processed by our payment processor; RENEWL does not store full card numbers.
Device and technical information
- Device type, operating system, app version, language, time zone, IP address, and a push-notification token if you allow notifications.
- Sign-in history and security logs, used to protect your account.
- Crash and performance diagnostics, which do not include the contents of your health record.
We do not collect your precise location, contacts, or browsing activity in other apps. The RENEWL Patient App does not request access to your location or contacts.
4. Device Permissions
The app asks for device permissions only when a feature needs them, and you can change them at any time in your device settings:
- Camera and photos: only to capture or upload a photo of your ID when you choose to. We access only the image you select.
- Notifications: to alert you to appointments, new messages, and results. Notifications are written so they do not display health details on your lock screen.
- Face ID or Touch ID: if you use it to unlock the app, it is handled entirely by iOS. RENEWL never receives or stores your biometric data.
5. Apple Health
The RENEWL Patient App does not connect to Apple Health (HealthKit). It does not read data from or write data to Apple Health. The health information you see in the app — your lab results, treatment protocols, and appointments — comes from your RENEWL patient record.
6. How We Use Information
- To provide, coordinate and manage your care, including evaluations, lab and diagnostic testing, prescriptions, and follow-up;
- To create and maintain your patient record;
- To schedule appointments and send reminders, results notices and care-related messages;
- To process payments and maintain billing records;
- To verify your identity, secure your account, and prevent fraud or misuse;
- To troubleshoot, maintain and improve the Patient Services, using de-identified or aggregated information where possible;
- To meet legal, regulatory, licensing and professional obligations, and to protect the safety of our patients and staff.
We do not use the health information in your patient record to send marketing without your permission.
7. Advertising, Analytics & Tracking
- The Patient Services do not contain third-party advertising.
- We do not place third-party advertising or marketing trackers — such as the Meta Pixel, Google Analytics, or advertising SDKs — inside the portal or the app, and we do not track you across other companies’ apps or websites.
- We do not sell or “share” (for cross-context behavioral advertising) your personal or health information.
- Any analytics or crash-reporting tools we use operate under agreements that limit them to helping us maintain the Patient Services, and they do not receive the contents of your health record.
8. How We Share Information
We share information only as needed to care for you and run the Patient Services, as follows:
- Your care team: RENEWL physicians, nurse practitioners, nurses and authorized staff involved in your care.
- Pharmacies and laboratories: licensed U.S. pharmacies that fill your prescriptions, and the clinical laboratories and testing partners that process your tests.
- Service providers: companies that host and operate the Patient Services on our behalf, such as cloud hosting, our electronic health record and scheduling platform, secure messaging and email or text delivery, and payment processing. They may use information only to provide services to us, and where they handle health information we require written confidentiality and security commitments, including business associate agreements where applicable. The portal and app run on Google Cloud and Firebase, which provide our hosting, database, and secure sign-in.
- Other providers, at your request: such as your primary care physician or a specialist.
- Legal and safety: when required by law, court order or subpoena, for public-health reporting, or to prevent a serious threat to health or safety.
- Business transfers: in connection with a merger, acquisition or sale of assets, in which case the information remains subject to this policy.
- With your authorization: for any other purpose, only with your written permission, which you may revoke.
9. Messages, Texts & Notifications
- Secure messages in the portal or app are for non-urgent questions. Our team responds during business hours, Monday–Friday, 9am–6pm Eastern.
- Text messages: with your consent, we send appointment reminders and care notifications by text. Message and data rates may apply. Reply STOP to opt out or HELP for help. We do not share your mobile number or text-messaging consent with third parties for their marketing.
- Email: we avoid including health details in ordinary email and instead direct you to log in to read sensitive information.
- Push notifications: you can turn these off in your device settings at any time.
10. Security
We use administrative, technical and physical safeguards designed to protect your information, including:
- Encryption in transit (TLS) for all portal and app connections, and encryption at rest for stored records;
- Role-based access, so staff see only what they need for their job;
- Secure sign-in with multi-factor authentication, automatic session time-outs, and audit logging;
- Staff confidentiality training and agreements.
No system is completely secure. Please protect your device with a passcode, keep your password private, and sign out on shared devices.
11. Retention & Account Deletion
Medical records: Michigan law requires health care providers to keep medical records for at least seven years from the date of service, and longer in some circumstances. We retain records for that period even if you close your account, and then securely destroy or de-identify them.
Deleting your account: you can delete your account at any time from the app in your Patient Profile, or by emailing info@renewllongevity.com. When you delete your account we:
- close your login and end portal and app access;
- delete information that is not part of your medical record — such as device tokens, app preferences and connected-app permissions — within 7 days; and
- retain your medical and billing records only as long as the law requires, as described above.
12. Your Rights & Choices
- Access and copies: view your records in the portal, or request a copy, including in electronic form.
- Correction: ask us to correct or amend information you believe is inaccurate or incomplete.
- Deletion: request deletion of your information, subject to the record-retention requirements in Section 11.
- Communications: choose how we contact you, and opt out of non-essential messages at any time.
- Permissions: revoke camera, notification, or health-data permissions in your device settings.
- Accounting of disclosures: ask us which disclosures of your health information we have made outside of care, payment and operations.
To make a request, contact us using the details in Section 17. We will verify your identity before acting on a request and respond within the time the law requires. We will not discriminate against you for exercising your rights.
13. State Health-Data Rights
Some states give residents specific rights over consumer health data, for example Washington’s My Health My Data Act and similar laws in Nevada and Connecticut. These can include the right to know what health data is collected and shared, to withdraw consent, and to request deletion. RENEWL collects and shares consumer health data only to provide the services you request or with your consent, and does not sell it. Residents of these states may submit requests as described in Section 12, and may appeal a decision by replying to our response.
14. Breach Notification
If unsecured health or personal information in the Patient Services is accessed or disclosed without authorization, we will notify affected patients — and regulators where required — without unreasonable delay and as required by applicable law, including the FTC Health Breach Notification Rule where it applies and Michigan’s data breach notification law.
15. Children & Proxy Access
The Patient Services are intended for adults 18 and older. We do not knowingly create accounts for children. An adult may access another adult’s account only with that patient’s written authorization or valid legal authority, such as a health care power of attorney.
16. Changes to This Policy
We may update this policy as the Patient Services change. We will update the “Last updated” date above, and for material changes we will notify you in the app or portal, or by email, before the change takes effect.
17. Contact Us
For questions, privacy requests, or concerns about this policy:
RENEWL Longevity, LLC — Privacy
105 S Main St, Rochester, MI 48307
Email: info@renewllongevity.com
Phone: (248) 930-3535
This policy describes RENEWL Longevity’s current practices for the patient portal and mobile app. For how we handle information on renewllongevity.com, see our Website Privacy Policy.